Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Internet being directed through "smscut"?


  • Please log in to reply
8 replies to this topic

#1 Maeby

Maeby

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:07:15 PM

Posted 12 July 2012 - 02:19 PM

Alright, I've recently had a lot of trouble with running game launchers/updaters that require an internet connection. They are fine on my laptop, but when trying to run them from my desktop I hit all sorts of errors.

I noticed from my desktop's firewall that almost everything that wants to connect to the internet is trying to go through "www.smscut.com [174.142.75.249]". I looked up www.smscut.com and it appears to be some sort of proxy program--I've never installed this. I googled the IP address and found some unsavory things; apparently it's been linked to spamming and such (not surprising for a proxy).

I already went into about:config on firefox to look for anything related to "smscut", but found nothing. My virus scanner (MBAM) found nothing.

BC AdBot (Login to Remove)

 


#2 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:15 PM

Posted 12 July 2012 - 04:47 PM

Download Security Check from HERE, and save it to your Desktop.

* Double-click SecurityCheck.exe
* Follow the onscreen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=============================================================================

Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center/Action Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

====================================================================================

Please download MiniToolBox and run it.

Checkmark following boxes:
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices (do NOT change any settings here)
  • List Users, Partitions and Memory size
Click Go and post the result.

=============================================================================

Download Malwarebytes' Anti-Malware (aka MBAM): https://www.bleepingcomputer.com/download/malwarebytes-anti-malware/ to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

=============================================================================

Download aswMBR to your desktop.
Double click the aswMBR.exe to run it.
If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
Click the "Scan" button to start scan.
On completion of the scan click "Save log", save it to your desktop and post in your next reply.

NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#3 Maeby

Maeby
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:07:15 PM

Posted 12 July 2012 - 08:04 PM

Security Check:

Results of screen317's Security Check version 0.99.24
Windows XP Service Pack 3 x86
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Sygate Personal Firewall
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
HijackThis 2.0.2
JavaFX 2.1.1
Java™ 6 Update 20
Java™ 7 Update 5
Java™ 6 Update 6
Out of date Java installed!
Adobe Flash Player ( 10.1.53.64) Flash Player Out of Date!
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

``````````End of Log````````````





Farbar Service Scanner:

Farbar Service Scanner Version: 08-07-2012
Ran by Silver (administrator) on 12-07-2012 at 20:59:39
Running from "C:\Documents and Settings\Silver\Desktop"
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall"=DWORD:0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Security Center:
============

Windows Update:
============
wuauserv Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wuauserv registry key. The service key does not exist.


Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
AegisP(9) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4) wpsdrvnt(10)
0x0C00000005000000010000000200000003000000040000000A000000080000000600000007000000090000000B0000000C000000
IpSec Tag value is correct.

**** End of log ****





Mini Toolbox:

MiniToolBox by Farbar Version: 25-06-2012
Ran by Silver (administrator) on 12-07-2012 at 21:01:56
Microsoft Windows XP Professional Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

========================= FF Proxy Settings: ==============================

"network.proxy.type", 4
========================= Hosts content: =================================


192.168.254.2 mykillernic

127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com

There are 13105 more lines starting with "127.0.0.1"

========================= IP Configuration: ================================

Killer NIC NDIS EDGE Interface = Local Area Connection (Disconnected)
1394 Net Adapter = 1394 Connection (Connected)
NETGEAR WNA1100 Wireless-N 150 USB Adapter = Wireless Network Connection 2 (Connected)
NVIDIA nForce Networking Controller = Local Area Connection 4 (Media disconnected)
NVIDIA nForce 10/100/1000 Mbps Ethernet = Local Area Connection 6 (Media disconnected)


# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Local Area Connection 6"

set address name="Local Area Connection 6" source=dhcp
set dns name="Local Area Connection 6" source=dhcp register=PRIMARY
set wins name="Local Area Connection 6" source=dhcp

# Interface IP Configuration for "Local Area Connection 4"

set address name="Local Area Connection 4" source=dhcp
set dns name="Local Area Connection 4" source=dhcp register=PRIMARY
set wins name="Local Area Connection 4" source=dhcp

# Interface IP Configuration for "Wireless Network Connection 2"

set address name="Wireless Network Connection 2" source=dhcp
set dns name="Wireless Network Connection 2" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection 2" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : GLaDOS

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection 6:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : NVIDIA nForce 10/100/1000 Mbps Ethernet #2

Physical Address. . . . . . . . . : 00-04-4B-0A-5C-51



Ethernet adapter Local Area Connection 4:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : NVIDIA nForce 10/100/1000 Mbps Ethernet

Physical Address. . . . . . . . . : 00-04-4B-0A-5C-50



Ethernet adapter Wireless Network Connection 2:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : NETGEAR WNA1100 Wireless-N 150 USB Adapter

Physical Address. . . . . . . . . : E0-91-F5-4D-99-F2

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.9

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.1

DHCP Server . . . . . . . . . . . : 192.168.1.1

DNS Servers . . . . . . . . . . . : 192.168.1.1

Lease Obtained. . . . . . . . . . : Thursday, July 12, 2012 1:48:53 PM

Lease Expires . . . . . . . . . . : Friday, July 13, 2012 1:48:53 PM

Server: UnKnown
Address: 192.168.1.1

Name: google.com
Addresses: 74.125.225.64, 74.125.225.65, 74.125.225.66, 74.125.225.67
74.125.225.68, 74.125.225.69, 74.125.225.70, 74.125.225.71, 74.125.225.72
74.125.225.73, 74.125.225.78



Pinging google.com [74.125.225.64] with 32 bytes of data:



Reply from 74.125.225.64: bytes=32 time=27ms TTL=55

Reply from 74.125.225.64: bytes=32 time=36ms TTL=55



Ping statistics for 74.125.225.64:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 27ms, Maximum = 36ms, Average = 31ms

Server: UnKnown
Address: 192.168.1.1

Name: yahoo.com
Addresses: 98.139.183.24, 209.191.122.70, 72.30.38.140



Pinging yahoo.com [209.191.122.70] with 32 bytes of data:



Reply from 209.191.122.70: bytes=32 time=56ms TTL=53

Reply from 209.191.122.70: bytes=32 time=48ms TTL=53



Ping statistics for 209.191.122.70:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 48ms, Maximum = 56ms, Average = 52ms

Server: UnKnown
Address: 192.168.1.1

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



Reply from 208.43.87.2: Destination host unreachable.

Reply from 208.43.87.2: Destination host unreachable.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 04 4b 0a 5c 51 ...... NVIDIA nForce Networking Controller #2 - Packet Scheduler Miniport
0x10004 ...00 04 4b 0a 5c 50 ...... NVIDIA nForce Networking Controller - Packet Scheduler Miniport
0x20005 ...e0 91 f5 4d 99 f2 ...... NETGEAR WNA1100 Wireless-N 150 USB Adapter - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.9 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.9 192.168.1.9 25
192.168.1.9 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.1.255 255.255.255.255 192.168.1.9 192.168.1.9 25
224.0.0.0 240.0.0.0 192.168.1.9 192.168.1.9 25
255.255.255.255 255.255.255.255 192.168.1.9 2 1
255.255.255.255 255.255.255.255 192.168.1.9 10004 1
255.255.255.255 255.255.255.255 192.168.1.9 192.168.1.9 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 01 C:\Windows\system32\BfLLR.dll [121376] (Bigfoot Networks, Inc.)
Catalog9 02 C:\Windows\system32\BfLLR.dll [121376] (Bigfoot Networks, Inc.)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\BfLLR.dll [121376] (Bigfoot Networks, Inc.)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 18 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 19 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 20 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 21 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 22 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 23 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 24 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 25 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 26 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 27 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 28 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 29 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 30 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (07/12/2012 08:40:29 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 08:40:29 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 07:29:40 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 07:29:40 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 06:41:29 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 06:41:29 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 05:54:40 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 05:54:40 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 04:59:29 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D} and it will not be loaded. This is most likely caused by a faulty registration.

Error: (07/12/2012 04:59:29 PM) (Source: Userenv) (User: NT AUTHORITY)NT AUTHORITY
Description: Windows cannot query DllName registry entry for {7B849a69-220F-451E-B3FE-2CB811AF94AE} and it will not be loaded. This is most likely caused by a faulty registration.


System errors:
=============
Error: (07/12/2012 00:35:38 PM) (Source: Service Control Manager) (User: )
Description: The Taepsflbuks service failed to start due to the following error:
%%2

Error: (07/12/2012 00:35:38 PM) (Source: Service Control Manager) (User: )
Description: The Pveppprmnse service failed to start due to the following error:
%%3

Error: (07/12/2012 00:35:38 PM) (Source: Service Control Manager) (User: )
Description: The Mrxnum service failed to start due to the following error:
%%123

Error: (07/12/2012 11:47:32 AM) (Source: Service Control Manager) (User: )
Description: The Taepsflbuks service failed to start due to the following error:
%%2

Error: (07/12/2012 11:47:32 AM) (Source: Service Control Manager) (User: )
Description: The Pveppprmnse service failed to start due to the following error:
%%3

Error: (07/12/2012 11:47:32 AM) (Source: Service Control Manager) (User: )
Description: The Mrxnum service failed to start due to the following error:
%%123

Error: (07/12/2012 11:39:27 AM) (Source: Service Control Manager) (User: )
Description: The Taepsflbuks service failed to start due to the following error:
%%2

Error: (07/12/2012 11:39:27 AM) (Source: Service Control Manager) (User: )
Description: The Pveppprmnse service failed to start due to the following error:
%%3

Error: (07/12/2012 11:39:27 AM) (Source: Service Control Manager) (User: )
Description: The Mrxnum service failed to start due to the following error:
%%123

Error: (07/12/2012 11:35:51 AM) (Source: Service Control Manager) (User: )
Description: The Taepsflbuks service failed to start due to the following error:
%%2


Microsoft Office Sessions:
=========================
Error: (07/12/2012 08:40:29 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

Error: (07/12/2012 08:40:29 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {7B849a69-220F-451E-B3FE-2CB811AF94AE}

Error: (07/12/2012 07:29:40 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

Error: (07/12/2012 07:29:40 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {7B849a69-220F-451E-B3FE-2CB811AF94AE}

Error: (07/12/2012 06:41:29 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

Error: (07/12/2012 06:41:29 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {7B849a69-220F-451E-B3FE-2CB811AF94AE}

Error: (07/12/2012 05:54:40 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

Error: (07/12/2012 05:54:40 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {7B849a69-220F-451E-B3FE-2CB811AF94AE}

Error: (07/12/2012 04:59:29 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}

Error: (07/12/2012 04:59:29 PM) (Source: Userenv)(User: NT AUTHORITY)NT AUTHORITY
Description: {7B849a69-220F-451E-B3FE-2CB811AF94AE}


=========================== Installed Programs ============================

7-Zip 4.57
Adobe AIR (Version: 2.0.4.13090)
Adobe Flash Player 10 ActiveX (Version: 10.0.22.87)
Adobe Flash Player 10 Plugin (Version: 10.1.53.64)
Adobe Illustrator CS (Version: 11)
Adobe InDesign CS2 (Version: 004.000.000)
Adobe Photoshop CS (Version: CS)
Adobe Reader 7.1.0 (Version: 7.1.0)
Adobe Shockwave Player 11.5 (Version: 11.5.2.602)
Adobe SVG Viewer 3.0 (Version: 3.0)
AlienGUIse Theme Manager
Amazon MP3 Downloader 1.0.12 (Version: 1.0.12)
AOL Instant Messenger
Apple Software Update (Version: 2.0.2.92)
BioShock (Version: 2.5.0000)
Black & White® 2 (Version: 1.00.0000)
Braid
Cabela's African Safari (Version: 1.0.0)
calibre (Version: 0.7.59)
Canon IJ Network Tool
Canon MP Navigator EX 4.0
Canon MP495 series MP Drivers
Canon MP495 series User Registration
Canon My Printer
Catz 5
City of Heroes (remove only)
Color Efex Pro 3.0 Complete (Version: 3.0)
Combined Community Codec Pack 2010-10-10 (Version: 2010.10.10.0)
Compact Wireless-G USB Network Adapter with SpeedBooster
Critical Update for Windows Media Player 11 (KB959772)
CutePDF Writer 2.8
Dante
DebugMode Wax 2.0
Deer Hunter - The 2005 Season
DEMISE
Dev-C++ 5 beta 9 release (4.9.9.2)
Diablo II
Diablo III (Version: 1.0.3.10485)
Disney Mixit Plugin (Version: 1.2)
DivX Version Checker (Version: 7.1.0.9)
Dragon Age: Origins (Version: 1.00)
Driver Checker v2.7.4 (Version: 2.7.4)
DVD Flick 1.3.0.7 (Version: 1.3.0.7)
EA Download Manager (Version: 4.0.0.462)
EA Download Manager (Version: 7.0.0.59)
EVE Online (remove only)
EVEMon (Version: 1.6.1.3611)
EZ MPEG TO AVI Converter 3.00
Fallout 3 - The Garden of Eden Creation Kit (Version: 1.00.0000)
Fallout 3 (Version: 1.00.0000)
Fallout Mod Manager 0.12.3
Fallout New Vegas
Façade (Version: 1.1.2)
Flash Card Manager (Version: 3.0.3)
Free Audio CD Burner version 1.4.8
Free YouTube to MP3 Converter version 3.9.37.426
GenoPro 2.0.1.6
Google Earth (Version: 6.1.0.5001)
Google Update Helper (Version: 1.3.21.111)
Greyhound Manager 2
High Definition Audio Driver Package - KB888111 (Version: 20040219.000000)
Highlight Viewer (Windows Live Toolbar) (Version: 03.01.0144)
HijackThis 2.0.2 (Version: 2.0.2)
HP Deskjet 9800 (Version: 1.00.0000)
HP Deskjet 9800 Series
Impressive Title version 0.7
Java Auto Updater (Version: 2.1.6.0)
Java™ 6 Update 20 (Version: 6.0.200)
Java™ 6 Update 6 (Version: 1.6.0.60)
Java™ 7 Update 5 (Version: 7.0.50)
JavaFX 2.1.1 (Version: 2.1.1)
Killer Driver (Version: 2.00.0000)
Left 4 Dead 2
LightScribe System Software (Version: 1.18.10.2)
LightScribe Template Labeler (Version: 1.18.5.1)
Linksys Wireless Manager (Version: 4.9.9047.0)
Lone Survivor
Macromedia Dreamweaver 8 (Version: 8.0.0.2734)
Macromedia Extension Manager (Version: 1.7.240)
MagicDisc 2.7.106
Malwarebytes Anti-Malware version 1.62.0.1300 (Version: 1.62.0.1300)
Map Button (Windows Live Toolbar) (Version: 03.01.0144)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Age of Empires Gold
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Compression Client Pack 1.0 for Windows XP (Version: 1)
Microsoft Games for Windows - LIVE (Version: 2.0.675.0)
Microsoft Games for Windows - LIVE Redistributable (Version: 2.0.673.0)
Microsoft IntelliPoint 7.1 (Version: 7.10.344.0)
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional (Version: 10.0.2627.01)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Visual J# 2.0 Redistributable Package (Version: 2.0.50727)
Microsoft WSE 3.0 Runtime (Version: 3.0.5305.0)
Mount & Blade: Warband
Mount & Blade: With Fire and Sword
Mount&Blade
Mount&Blade Warband
Mozilla Firefox 13.0.1 (x86 en-US) (Version: 13.0.1)
Mozilla Maintenance Service (Version: 13.0.1)
MSN Music Assistant
MSXML 6 Service Pack 2 (KB973686) (Version: 6.20.2003.0)
Nero 7 Essentials (Version: 7.02.4457)
nHancer (Version: 2.5.0900)
NVIDIA Control Panel 296.10 (Version: 296.10)
NVIDIA Display Control Panel (Version: 6.14.12.5721)
NVIDIA Drivers (Version: 1.5)
NVIDIA Graphics Driver 296.10 (Version: 296.10)
NVIDIA Install Application (Version: 2.1002.62.312)
NVIDIA nView Desktop Manager (Version: 6.14.10.13518)
NVIDIA Photoshop Plug-ins (Version: 1.00.000)
NVIDIA PhysX (Version: 9.11.0621)
Oblivion (Version: 1.00.0000)
Oblivion mod manager 1.1.12
Oregon Trail 3
Oregon Trail 5
oZone3D.Net FurMark v1.8.2
Paint By Numbers 2005 (Version: 2.0.016)
PC Searc h- SR21 (Version: 1.00.0000)
PCStitch 9 (Version: 9.01.08)
Planescape - Torment
Portal
Portal 2
Portal 2 Authoring Tools - Beta
PowerDVD (Version: 7.0.2414.0)
Psychonauts
Pure Networks Platform (Version: 11.1.9044.0)
QuickTime (Version: 7.4.5.67)
RCT3 Soaked (Version: 1.00.000)
Realtek High Definition Audio Driver (Version: 5.10.0.5296)
Registry Mechanic 9.0 (Version: 9.0)
RollerCoaster Tycoon® 3 (Version: 1.00.000)
SES Driver (Version: 1.0.0)
SimCity™ Societies (Version: 1.0.0.0)
Sims2Pack Clean Installer
Smart Menus (Windows Live Toolbar) (Version: 03.01.0144)
SolveigMM AVI Trimmer (Version: 1.6.912.18)
Sparkplayer (Beta)
SPORE™ (Version: 1.05.0001)
SPORE™ Creepy & Cute Parts Pack (Version: 1.00.0000)
Spybot - Search & Destroy (Version: 1.6.2)
Star Wars®: Knights of the Old Republic ™
Starters Orders 3
Steam (Version: 1.0.0.0)
Stitch ERA 10 (Version: 10.0)
Super Meat Boy
Sygate Personal Firewall (Version: 5.6.2808)
System Requirements Lab
TableSmith (Version: 5.1.0)
Team Fortress 2
The Elder Scrolls V: Skyrim
The Sims Medieval (Version: 1.0.0)
The Sims™ 3 (Version: 1.31.118)
The Sims™ 3 Ambitions (Version: 4.0.87)
The Sims™ 3 Fast Lane Stuff (Version: 5.0.44)
The Sims™ 3 Generations (Version: 8.0.152)
The Sims™ 3 High-End Loft Stuff (Version: 3.0.38)
The Sims™ 3 Late Night (Version: 6.0.81)
The Sims™ 3 Master Suite Stuff (Version: 11.0.84)
The Sims™ 3 Outdoor Living Stuff (Version: 7.0.55)
The Sims™ 3 Pets (Version: 10.0.96)
The Sims™ 3 Showtime (Version: 12.0.273)
The Sims™ 3 Town Life Stuff (Version: 9.0.73)
The Sims™ 3 World Adventures (Version: 2.0.86)
The Witcher (Version: 1.00.0000)
theHunter (remove only)
Tropico 3 1.00 (Version: 1.00)
Tropico 4
TS3 Install Helper Monkey
UltraISO Premium V9.36
Uninstall 1.0.0.1
Unity Web Player (Version: 2.5.5b4_50)
Universe Sandbox
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Windows Internet Explorer 7 (KB976749) (Version: 1)
Update for Windows Internet Explorer 7 (KB980182) (Version: 1)
Update for Windows XP (KB951072-v2) (Version: 2)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB955839) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
Viewpoint Media Player
Visual C++ 8.0 Runtime Setup Package (Version: 1.0.0.0)
WebFldrs XP (Version: 9.50.7523)
Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0)
Windows Imaging Component (Version: 3.0.0.0)
Windows Internet Explorer 7 (Version: 20070813.185237)
Windows Live Favorites for Windows Live Toolbar (Version: 03.01.0144)
Windows Live Toolbar (Version: 03.01.0130)
Windows Live Toolbar Extension (Windows Live Toolbar) (Version: 03.01.0144)
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series (Version: 9.00.2980)
Windows Media Format 11 runtime
Windows Presentation Foundation (Version: 3.0.6920.0)
Windows XP Service Pack 3 (Version: 20080414.031525)
WinRAR archiver
WolfQuest (Version: 2.0.3)
World of Warcraft (Version: 4.1.0.14007)
XML Paper Specification Shared Components Pack 1.0
Zoo Tycoon 2 - Ultimate Collection (Version: 1.00.0000)
ZooEasy v9 (Version: 9.03)

========================= Devices: ================================

Name: Killer NIC NDIS EDGE Interface
Description: Killer NIC NDIS EDGE Interface
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: Bigfoot
Service: NetbEdge
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: WAN Miniport (IPX) #2
Description: WAN Miniport (IPX)
Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318}
Manufacturer: Microsoft
Service: NdisWan
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver


========================= Memory info: ===================================

Percentage of memory in use: 56%
Total physical RAM: 2558.46 MB
Available physical RAM: 1122.8 MB
Total Pagefile: 4447.02 MB
Available Pagefile: 3059.76 MB
Total Virtual: 2047.88 MB
Available Virtual: 1977.89 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:1863.02 GB) (Free:526.15 GB) NTFS
2 Drive d: (D3C1.0.0) (CDROM) (Total:7.6 GB) (Free:0 GB) UDF
3 Drive e: (KOTOR_4) (CDROM) (Total:0.48 GB) (Free:0 GB) CDFS

========================= Users: ========================================

User accounts for \\GLADOS

Administrator ASPNET Guest
HelpAssistant Silver SUPPORT_388945a0
UpdatusUser


**** End of log ****





The MBAM log will follow shortly.

#4 Maeby

Maeby
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:07:15 PM

Posted 12 July 2012 - 08:45 PM

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.07.12.08

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 7.0.5730.13
Silver :: GLADOS [administrator]

7/12/2012 9:11:24 PM
mbam-log-2012-07-12 (21-11-24).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 247850
Time elapsed: 11 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\RECYCLER\S-1-5-21-1435755707-3103492254-1992489929-1005\Dc3169.exe (PUP.BundleInstaller.OI) -> Quarantined and deleted successfully.

(end)








aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-12 21:27:32
-----------------------------
21:27:32.578 OS Version: Windows 5.1.2600 Service Pack 3
21:27:32.578 Number of processors: 4 586 0xF0B
21:27:32.578 ComputerName: GLADOS UserName: Silver
21:27:37.531 Initialize success
21:29:16.171 AVAST engine defs: 12071201
21:36:00.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007f
21:36:00.406 Disk 0 Vendor: NVIDIA__ Size: 1907739MB BusType: 8
21:36:00.406 Disk 0 MBR read successfully
21:36:00.406 Disk 0 MBR scan
21:36:00.484 Disk 0 Windows XP default MBR code
21:36:00.484 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907734 MB offset 63
21:36:00.484 Disk 0 scanning sectors +3907040130
21:36:00.562 Disk 0 scanning C:\WINDOWS\system32\drivers
21:36:13.703 Service scanning
21:36:28.953 Modules scanning
21:36:36.437 Disk 0 trace - called modules:
21:36:36.453 ntkrnlpa.exe CLASSPNP.SYS disk.sys nvrd32.sys hal.dll ACPI.sys SCSIPORT.SYS

nvgts.sys
21:36:36.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b09c030]
21:36:36.500 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> \Device\0000007f[0x8b083d50]
21:36:36.500 5 nvrd32.sys[b7eab29e] -> nt!IofCallDriver -> \Device\0000007d[0x8b061920]
21:36:36.500 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver ->

\Device\Scsi\nvgts1Port3Path0Target0Lun0[0x8b061a38]
21:36:39.328 AVAST engine scan C:\WINDOWS
21:37:10.453 AVAST engine scan C:\WINDOWS\system32
21:44:53.000 Disk 0 MBR has been saved successfully to "C:\Documents and

Settings\Silver\Desktop\MBR.dat"
21:44:53.000 The log file has been saved successfully to "C:\Documents and

Settings\Silver\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-12 21:27:32
-----------------------------
21:27:32.578 OS Version: Windows 5.1.2600 Service Pack 3
21:27:32.578 Number of processors: 4 586 0xF0B
21:27:32.578 ComputerName: GLADOS UserName: Silver
21:27:37.531 Initialize success
21:29:16.171 AVAST engine defs: 12071201
21:36:00.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007f
21:36:00.406 Disk 0 Vendor: NVIDIA__ Size: 1907739MB BusType: 8
21:36:00.406 Disk 0 MBR read successfully
21:36:00.406 Disk 0 MBR scan
21:36:00.484 Disk 0 Windows XP default MBR code
21:36:00.484 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907734 MB offset 63
21:36:00.484 Disk 0 scanning sectors +3907040130
21:36:00.562 Disk 0 scanning C:\WINDOWS\system32\drivers
21:36:13.703 Service scanning
21:36:28.953 Modules scanning
21:36:36.437 Disk 0 trace - called modules:
21:36:36.453 ntkrnlpa.exe CLASSPNP.SYS disk.sys nvrd32.sys hal.dll ACPI.sys SCSIPORT.SYS

nvgts.sys
21:36:36.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b09c030]
21:36:36.500 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> \Device\0000007f[0x8b083d50]
21:36:36.500 5 nvrd32.sys[b7eab29e] -> nt!IofCallDriver -> \Device\0000007d[0x8b061920]
21:36:36.500 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver ->

\Device\Scsi\nvgts1Port3Path0Target0Lun0[0x8b061a38]
21:36:39.328 AVAST engine scan C:\WINDOWS
21:37:10.453 AVAST engine scan C:\WINDOWS\system32
21:44:53.000 Disk 0 MBR has been saved successfully to "C:\Documents and

Settings\Silver\Desktop\MBR.dat"
21:44:53.000 The log file has been saved successfully to "C:\Documents and

Settings\Silver\Desktop\aswMBR.txt"
21:47:43.703 AVAST engine scan C:\WINDOWS\system32\drivers
21:52:16.156 AVAST engine scan C:\Documents and Settings\Silver
21:52:45.437 File: C:\Documents and Settings\Silver\Application Data\0Q11SIUAOM.exe

**INFECTED** Win32:Dropper-GBA [Drp]
21:54:21.312 Disk 0 MBR has been saved successfully to "C:\Documents and

Settings\Silver\Desktop\MBR.dat"
21:54:21.312 The log file has been saved successfully to "C:\Documents and

Settings\Silver\Desktop\aswMBR.txt"

Edited by Maeby, 12 July 2012 - 08:55 PM.


#5 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:15 PM

Posted 12 July 2012 - 09:09 PM

There is some infection there.

You're not running any AV program.
Install ONE of these:
- Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html
- free Microsoft Security Essentials: http://windows.microsoft.com/en-GB/windows/products/security-essentials
- free Comodo Antivirus: http://www.comodo.com/home/internet-security/antivirus.php
Update, run full scan, report on any findings.

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#6 Maeby

Maeby
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:07:15 PM

Posted 13 July 2012 - 03:34 PM

I installed Avast and ran a boot scan. It detected/deleted several threats, most of them were in Java's folder, the one main exception being Win32:Dropper-GBA, which was found in System volume information (and also deleted).

#7 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:15 PM

Posted 13 July 2012 - 06:55 PM

Please post new aswMBR log.

NOTE.
Disable "word wrap" in Notepad because some logs are hard to read.

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 


#8 Maeby

Maeby
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:07:15 PM

Posted 14 July 2012 - 10:51 AM

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-12 21:27:32
-----------------------------
21:27:32.578 OS Version: Windows 5.1.2600 Service Pack 3
21:27:32.578 Number of processors: 4 586 0xF0B
21:27:32.578 ComputerName: GLADOS UserName: Silver
21:27:37.531 Initialize success
21:29:16.171 AVAST engine defs: 12071201
21:36:00.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007f
21:36:00.406 Disk 0 Vendor: NVIDIA__ Size: 1907739MB BusType: 8
21:36:00.406 Disk 0 MBR read successfully
21:36:00.406 Disk 0 MBR scan
21:36:00.484 Disk 0 Windows XP default MBR code
21:36:00.484 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907734 MB offset 63
21:36:00.484 Disk 0 scanning sectors +3907040130
21:36:00.562 Disk 0 scanning C:\WINDOWS\system32\drivers
21:36:13.703 Service scanning
21:36:28.953 Modules scanning
21:36:36.437 Disk 0 trace - called modules:
21:36:36.453 ntkrnlpa.exe CLASSPNP.SYS disk.sys nvrd32.sys hal.dll ACPI.sys SCSIPORT.SYS nvgts.sys
21:36:36.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b09c030]
21:36:36.500 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> \Device\0000007f[0x8b083d50]
21:36:36.500 5 nvrd32.sys[b7eab29e] -> nt!IofCallDriver -> \Device\0000007d[0x8b061920]
21:36:36.500 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port3Path0Target0Lun0[0x8b061a38]
21:36:39.328 AVAST engine scan C:\WINDOWS
21:37:10.453 AVAST engine scan C:\WINDOWS\system32
21:44:53.000 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Silver\Desktop\MBR.dat"
21:44:53.000 The log file has been saved successfully to "C:\Documents and Settings\Silver\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-12 21:27:32
-----------------------------
21:27:32.578 OS Version: Windows 5.1.2600 Service Pack 3
21:27:32.578 Number of processors: 4 586 0xF0B
21:27:32.578 ComputerName: GLADOS UserName: Silver
21:27:37.531 Initialize success
21:29:16.171 AVAST engine defs: 12071201
21:36:00.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000007f
21:36:00.406 Disk 0 Vendor: NVIDIA__ Size: 1907739MB BusType: 8
21:36:00.406 Disk 0 MBR read successfully
21:36:00.406 Disk 0 MBR scan
21:36:00.484 Disk 0 Windows XP default MBR code
21:36:00.484 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907734 MB offset 63
21:36:00.484 Disk 0 scanning sectors +3907040130
21:36:00.562 Disk 0 scanning C:\WINDOWS\system32\drivers
21:36:13.703 Service scanning
21:36:28.953 Modules scanning
21:36:36.437 Disk 0 trace - called modules:
21:36:36.453 ntkrnlpa.exe CLASSPNP.SYS disk.sys nvrd32.sys hal.dll ACPI.sys SCSIPORT.SYS nvgts.sys
21:36:36.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b09c030]
21:36:36.500 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> \Device\0000007f[0x8b083d50]
21:36:36.500 5 nvrd32.sys[b7eab29e] -> nt!IofCallDriver -> \Device\0000007d[0x8b061920]
21:36:36.500 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port3Path0Target0Lun0[0x8b061a38]
21:36:39.328 AVAST engine scan C:\WINDOWS
21:37:10.453 AVAST engine scan C:\WINDOWS\system32
21:44:53.000 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Silver\Desktop\MBR.dat"
21:44:53.000 The log file has been saved successfully to "C:\Documents and Settings\Silver\Desktop\aswMBR.txt"
21:47:43.703 AVAST engine scan C:\WINDOWS\system32\drivers
21:52:16.156 AVAST engine scan C:\Documents and Settings\Silver
21:52:45.437 File: C:\Documents and Settings\Silver\Application Data\0Q11SIUAOM.exe **INFECTED** Win32:Dropper-GBA [Drp]
21:54:21.312 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Silver\Desktop\MBR.dat"
21:54:21.312 The log file has been saved successfully to "C:\Documents and Settings\Silver\Desktop\aswMBR.txt"
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-13 21:46:23
-----------------------------
21:46:23.500 OS Version: Windows 5.1.2600 Service Pack 3
21:46:23.500 Number of processors: 4 586 0xF0B
21:46:23.500 ComputerName: GLADOS UserName: Silver
21:46:26.625 Initialize success
21:46:27.281 AVAST engine defs: 12071301
21:46:51.750 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000083
21:46:51.750 Disk 0 Vendor: NVIDIA__ Size: 1907739MB BusType: 8
21:46:51.765 Disk 0 MBR read successfully
21:46:51.765 Disk 0 MBR scan
21:46:51.765 Disk 0 Windows XP default MBR code
21:46:51.765 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1907734 MB offset 63
21:46:51.781 Disk 0 scanning sectors +3907040130
21:46:51.843 Disk 0 scanning C:\WINDOWS\system32\drivers
21:47:03.468 Service scanning
21:47:15.046 Modules scanning
21:47:21.718 Disk 0 trace - called modules:
21:47:21.750 ntkrnlpa.exe CLASSPNP.SYS disk.sys nvrd32.sys hal.dll ACPI.sys SCSIPORT.SYS nvgts.sys
21:47:21.750 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b0dc8c8]
21:47:21.750 3 CLASSPNP.SYS[b80e8fd7] -> nt!IofCallDriver -> \Device\00000083[0x8b0de6c0]
21:47:21.750 5 nvrd32.sys[b7eab29e] -> nt!IofCallDriver -> \Device\00000081[0x8b0a6880]
21:47:21.750 7 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port3Path0Target0Lun0[0x8b0a6a38]
21:47:24.796 AVAST engine scan C:\WINDOWS
21:48:08.500 AVAST engine scan C:\WINDOWS\system32
22:00:05.359 AVAST engine scan C:\WINDOWS\system32\drivers
22:05:08.531 AVAST engine scan C:\Documents and Settings\Silver
00:39:09.359 AVAST engine scan C:\Documents and Settings\All Users
00:56:07.875 Scan finished successfully
01:13:28.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Silver\Desktop\MBR.dat"
01:13:29.015 The log file has been saved successfully to "C:\Documents and Settings\Silver\Desktop\aswMBR.txt"

#9 Broni

Broni

    The Coolest BC Computer


  • BC Advisor
  • 42,754 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Daly City, CA
  • Local time:04:15 PM

Posted 14 July 2012 - 11:45 AM

Good :)

How is computer doing?

Download Temp File Cleaner (TFC)
Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.

=============================================================================

Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    NOTE. If Eset doesn't find any threats it'll NOT produce any log.

My Website

My help doesn't cost a penny, but if you'd like to consider a donation, click DONATE

 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users