Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
LinkBack Thread Tools
Old 07-17-2009, 08:04 PM   #1 (permalink)
Registered User
 
Kimi232's Avatar
 
Join Date: Jan 2006
Location: Texas
Posts: 18
OS: Win XP SP3


Send a message via AIM to Kimi232 Send a message via MSN to Kimi232 Send a message via Yahoo to Kimi232
Pencil backdoor bots, virus, and possibly spyware...

I thank you in advanced, and I appreciate all of your help.

Sorry for my earlier post. I have returned with logs.

Quote:
So Here I was... doing nothing but IMing my friend. Then suddenly I get mcafee screaming at me that I have a virus, I try to quarenteen it, nope can't do.. I try to delete it... nope can't do that either.. It says the file is currently in use when I use spybot, or malewarebytes, and when I boot up in safe mode it says the access to delete the file is denied.
That's just one problem.. After that I started getting these strange windows (and icons on my task bar) saying I had a virus, and to scan and remove, and even when I told it cancle and no, it would proceed anyways (I believe these are spyware, because I only have four programs on my computer to help with this stuff and all the other stuff popping up was not from any of them).
Before all this happened, I had problems with something in my proccesses called "a.exe" and suddenly I would hear ads, but see nothing. I got rid of that a good while ago (it was quite simple to get ride of) but now... aye-yie-yie!!
Now I hear IE clicking noises all the time, and the internet wont work (on that computer account) and it slowly stops to a freeze of the computer. Also It's very testy on when I can get my computer, or Control panel to open. I also can't do a system restore. I've tried twice and it attempts it.. reboots and all, then afterwards it says it was not able to restore back to date I chose.
What I want to know... I created another admin account on my computer, and signed into it.. I have none of these problems on it. If I were to delete my other computer account would they all flood over to this account, or would it be better to delet the other account? Or should I leave it there keeping all the cr** in one spot? or would it only leak over to this account? What should I do? what would be better? and how do I get rid of these files and registry files that give access denied, or file in use problems? What's the best safety program or mix of programs out there? (virus, spyware, adware, all of it)
Also as I was scrolling through the "Attach" notpad, I noticed it has morephues on it, the only problem is, I've tried to remove it before and it comes up with a IE looking window and just stays white.

---------


DDS (Ver_09-06-26.01) - NTFSx86
Run by Admin at 17:30:23.40 on Fri 07/17/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.383.63 [GMT -5:00]

AV: avast! antivirus 4.8.1335 [VPS 090717-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\VM_STI.EXE
H:\Program Files\itunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wltray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Dynex G Desktop Card Adapter\DynexWCUI.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
H:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Admin\Desktop\dds.pif

============== Pseudo HJT Report ===============

uSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/verizon/*http://www.yahoo.com/search/ie.html
uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/verizon/*http://www.yahoo.com
uStart Page = hxxp://verizon.yahoo.com
mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html
mWinlogon: UIHost=c:\windows\system32\logonuiX.exe
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - h:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Yahoo! IE Suggest: {5a263cf7-56a6-4d68-a8cf-345be45bc911} - c:\program files\yahoo!\search\YSearchSuggest.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - h:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - h:\progra~1\yahoo!\companion\installs\cpn\yt.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [3c1807pd]
mRun: [USRpdA] c:\windows\system32\usrmlnka.exe runservices \device\3cpipe-USRpdA
mRun: [BigDogPath] c:\windows\VM_STI.EXE ZSMC USB PC Camera
mRun: [iTunesHelper] h:\program files\itunes\iTunesHelper.exe
mRun: [MediaFace Integration] h:\program files\fellowes\mediaface 4.2\SetHook.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Broadcom Wireless Manager] c:\windows\system32\wltray.exe
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\dynexw~1.lnk - c:\program files\dynex g desktop card adapter\DynexWCUI.exe
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\angel\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {44226DFF-747E-4edc-B30C-78752E50CD0C} - {44226DFF-747E-4edc-B30C-78752E50CD0C} - c:\program files\ati multimedia\dtv\EXPLBAR.DLL
IE: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - {4982D40A-C53B-4615-B15B-B5B5E98D167C}
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxps://activatemydsl.verizon.net/sdcCommon/download/DSL/tgctlcm.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {4DD988A3-8A9A-4CC1-A763-F822C09E4315} - hxxp://www.va-sa-ra.co.jp/mgx/win/MGXPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {9122D757-5A4F-4768-82C5-B4171D8556A7} - hxxp://appdirectory.messenger.msn.com/AppDirectory/P4Apps/PhotoSwap/PhtPkMSN.cab
DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: {5077C326-ABFE-4BA3-A6FD-61B80CC7F03F} = 151.164.1.8,151.164.11.201
Filter: application/x-bt2 - {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} -
Handler: bt2 - {1730B77B-F429-498f-9B15-4514D83C8294} -
Notify: AtiExtEvent - Ati2evxx.dll
Notify: WBSrv - c:\progra~1\stardock\object~1\window~1\wbsrv.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL,wbsys.dll
SSODL: 0aMCPClient - {F5DF91F9-15E9-416B-A7C3-7519B11ECBFC} - No File
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-7-14 114768]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-3-25 214024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-7-14 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-7-14 138680]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-7-9 195856]
R3 ATICXCAP;ATI TV Wonder Pro A/V Capture;c:\windows\system32\drivers\aticxcap.sys [2004-12-25 173824]
R3 ATICXTUN;ATI TV Wonder Pro Tuner (Philips 1236 MK3);c:\windows\system32\drivers\aticxtun.sys [2004-12-25 29184]
R3 ATICXXBR;ATI TV Wonder Pro A/V Crossbar;c:\windows\system32\drivers\aticxxbr.sys [2004-12-25 9088]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-7-14 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-7-14 352920]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-7-9 19096]
S2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe --> c:\progra~1\mcafee\viruss~1\mcshield.exe [?]
S2 Norton AntiVirus;Norton AntiVirus;"c:\program files\norton antivirus\engine\16.0.0.125\ccsvchst.exe" /s "norton antivirus" /m "c:\program files\norton antivirus\engine\16.0.0.125\dimaster.dll" /prefetch:1 --> c:\program files\norton antivirus\engine\16.0.0.125\ccSvcHst.exe [?]
S3 BCMWLNPF;Broadcom Netgroup Packet Filter;c:\windows\system32\drivers\bcmwlnpf.sys [2009-4-18 33664]
S3 hamachi_oem;PlayLinc Adapter;c:\windows\system32\drivers\gan_adapter.sys [2006-9-27 10664]
S3 iAimFP8;iAimFP8;c:\windows\system32\drivers\wADV11NT.sys [2004-11-7 11935]
S3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe --> c:\progra~1\mcafee\viruss~1\mcsysmon.exe [?]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-2 79880]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-2 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-2 34216]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-2 40552]
S3 NAVENG;NAVENG;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\naveng.sys --> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\NAVENG.SYS [?]
S3 NAVEX15;NAVEX15;\??\c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\navex15.sys --> c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20080829.024\NAVEX15.SYS [?]
S3 PTDMBus;PANTECH USB Modem Composite Device Driver ;c:\windows\system32\drivers\PTDMBus.sys [2008-7-31 29952]
S3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\PTDMMdm.sys [2008-7-31 41856]
S3 PTDMVsp;PANTECH USB Modem Serial Port ;c:\windows\system32\drivers\PTDMVsp.sys [2008-7-31 39936]
S3 PTDMWWAN;PANTECH USB Modem WWAN Driver;c:\windows\system32\drivers\PTDMWWAN.sys [2008-7-31 59520]
S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [2007-2-17 7548]
S3 SFC4;SFC4;c:\windows\system32\drivers\sfc4.sys --> c:\windows\system32\drivers\SFC4.sys [?]
S4 Dateeddrf;Dateeddrf; [x]

=============== Created Last 30 ================

2009-07-16 22:04 <DIR> --dsh--- c:\documents and settings\admin\IECompatCache
2009-07-16 22:02 <DIR> --dsh--- c:\documents and settings\admin\PrivacIE
2009-07-16 21:35 <DIR> --dsh--- c:\documents and settings\admin\IETldCache
2009-07-16 21:35 <DIR> --d----- c:\documents and settings\Admin
2009-07-16 10:29 <DIR> --dsh--- C:\found.000
2009-07-13 11:51 35,888 a----r-- c:\windows\system32\drivers\SymIM.sys
2009-07-13 11:49 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Norton
2009-07-13 11:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-07-13 11:47 <DIR> --d----- c:\program files\NortonInstaller
2009-07-09 20:27 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-09 20:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-09 20:27 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-07-09 20:27 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-02 12:02 29,184 a------- c:\windows\system32\gdi32lib.dll
2009-06-24 16:58 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-06-24 16:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-06-23 12:22 102,912 -c------ c:\windows\system32\dllcache\iecompat.dll
2009-06-23 12:21 <DIR> --d----- c:\windows\ie8updates
2009-06-23 12:19 12,800 -c------ c:\windows\system32\dllcache\xpshims.dll
2009-06-23 12:19 246,272 -c------ c:\windows\system32\dllcache\ieproxy.dll
2009-06-23 12:15 <DIR> -cd-h--- c:\windows\ie8
2009-06-21 00:42 73,728 a------- c:\windows\system32\javacpl.cpl
2009-06-20 11:43 <DIR> --d----- c:\program files\Peach Princess
2009-06-19 18:08 <DIR> --d----- c:\program files\SEKILALA
2009-06-19 16:12 <DIR> --d----- c:\program files\DO
2009-06-19 16:04 <DIR> --d----- c:\program files\MSECache
2009-06-19 11:41 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro
2009-06-19 11:32 <DIR> --d----- c:\program files\DAEMON Tools Pro

==================== Find3M ====================

2009-07-09 17:58 1,890 ac-sh--- c:\docume~1\alluse~1\applic~1\KGyGaAvL.sys
2009-06-19 10:38 685,816 a------- c:\windows\system32\drivers\sptd.sys
2009-06-10 22:20 3,246 a------- c:\windows\pchealth\helpctr\config\incstore.bin
2009-06-07 17:06 8 ---shr-- c:\docume~1\alluse~1\applic~1\5D18675345.sys
2009-06-07 17:04 88 -c-shr-- c:\docume~1\alluse~1\applic~1\E7C50B7FCE.sys
2009-05-21 17:51 41,808 a------- c:\windows\system32\xfcodec.dll
2009-05-21 11:33 410,984 a------- c:\windows\system32\deploytk.dll
2009-05-17 00:49 2,426,368 a------- c:\windows\system32\logonuiX.exe
2009-05-13 00:15 915,456 a------- c:\windows\system32\wininet.dll
2009-05-07 10:32 345,600 a------- c:\windows\system32\localspl.dll
2005-09-25 11:50 32 ac---r-- c:\documents and settings\all users\hash.dat
2006-05-03 04:06 163,328 ---shr-- c:\windows\system32\flvDX.dll
2007-02-21 05:47 31,232 -c-shr-- c:\windows\system32\msfDX.dll
2008-08-13 21:40 32,768 ac-sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008081320080814\index.dat

============= FINISH: 17:32:34.74 ===============
Attached Files
File Type: zip Attach.zip (7.1 KB, 2 views)
Kimi232 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 08-02-2009, 10:17 AM   #2 (permalink)
Registered User
 
Kimi232's Avatar
 
Join Date: Jan 2006
Location: Texas
Posts: 18
OS: Win XP SP3


Send a message via AIM to Kimi232 Send a message via MSN to Kimi232 Send a message via Yahoo to Kimi232
Re: backdoor bots, virus, and possibly spyware...

I've also started recieving a blue screen of death now.. Talking about driver and BIOS, and saying that there is a physical memory dump.. When I log back on to windows the error report takes me to a page like this "You received this message because a device driver installed on your computer caused Windows to stop unexpectedly. This type of error is referred to as a "stop error." A stop error requires you to restart your computer."
But all of my drivers are up to date (As much as possible, most of my drivers are what came with the computer 7 to 8 years ago)
I've been getting this screen atleast every day now.. but yesterday it just happened out of the blue.. I wasn't doing anything on my computer.

Ps. Bump please
Kimi232 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 08-08-2009, 11:27 PM   #3 (permalink)
Registered User
 
Kimi232's Avatar
 
Join Date: Jan 2006
Location: Texas
Posts: 18
OS: Win XP SP3


Send a message via AIM to Kimi232 Send a message via MSN to Kimi232 Send a message via Yahoo to Kimi232
Re: backdoor bots, virus, and possibly spyware...

Bump, please?
Kimi232 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:44 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85