Tech Support banner
Status
Not open for further replies.
1 - 6 of 6 Posts

·
Registered
Joined
·
4 Posts
Discussion Starter · #1 ·
Hi there, Ive been having problems with my PC, (dell dimension 5000, 2.8ghz,512mb ram,XP Home SP2, any more specs needed?) trying to access a lot of sites on what seems to be incrementing ports from my PC, and always trying to access port 25 on the target IP.

Ive attached a Jpg of peerguardian showing the activity, note that no p2p programs are active at this time, and its after a clean boot, Panda Scan, Ad-AwareSE with addon, Spybot, Prevx1, A2, Symantec AntiVirus scans all in safe mode and to the instructions on the "before posting" page. Symantec AntiVirus found "msasvc.exe" and removed it to my knowledge.

Phew, its been a long day. Needless to say im a bit worried that the owners of the IP addresses may think im attacking them (right term?). Im thinking it must be something rather dodgy like a mailer worm or something similar, so if someone could look into my HJT log, i'd really appreciate it.

Logfile of HijackThis v1.99.1
Scan saved at 00:44:12, on 16/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Burn The Heretic
O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: (no name) - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - (no file)
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [HGTXPEI] C:\WINDOWS\system32\FirstReboot.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgGB2404.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.5.0_05) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} -
O20 - AppInit_DLLs:
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: Nls - C:\WINDOWS\
O20 - Winlogon Notify: RunServices - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winwim32 - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Unknown owner - C:\Program Files\Prevx1\PXAgent.exe" -f (file missing)
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)


Thanks for your time.
 

Attachments

·
Security Manager, Analyst , Rangemaster, TSF Acade
Joined
·
39,538 Posts
Hi and welcome to TSF.

My name is Iain and I will be helping you clean your system.

There's not a great deal showing in your log, so we'll do some cleaning and see what may turn up.

You may wish to Subscribe to this thread (Thread Tools > Subscribe to this thread) so that you are notified when you receive a reply.

Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix. You should not have any open browsers or live internet connections when you are following the procedures below.

Note that the fix may take several posts. Please continue to respond to my instructions until I confirm that your system is clean.

If there is anything you don't understand, please ask BEFORE proceeding with the fixes.

Please ensure that you follow the instructions in the order I have them listed.


Show Hidden Files
Go to My Computer > Tools > Folder Options > View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System files and Folders are showing / visible. Uncheck the Hide protected operating system files option.



Downloads
Please download Cleanup! or use this Alternate Link if the main link does not work and install it. You will use this later.
*NOTE* Cleanup deletes EVERYTHING out of temporary folders and does NOT make backups. If you have any files in any TEMP directory and you need to keep them, then please MOVE THEM NOW!


Download AVG Anti Spyware

Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows"



  • Install AVG Anti Spyware
  • Double-click the icon on Desktop to launch AVG
  • On the top of the main screen click Shield
  • Click the word active to change it to inactive
  • On the top of the main screen click Update.
  • Then click on Start Update. The update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"

When you have finished updating, EXIT AVG Anti Spyware.


Download CWShredder and run it. Click Check for Update. Click on 'Fix' (it will automatically fix anything it finds for you) and then click OK. If it asks if you want to delete a certain random file, choose No and post that filename here. Let it finish the scan and then hit Next and Exit.


Please download combofix.exe to your desktop.

IMPORTANT - You must place combofix on your desktop!!


Double click combofix.exe & follow the prompts.

When finished, the tool will produce a log for you at c:\combofix.txt. Post that log in your next reply.

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall.




Disable Prevx
  • Right click on the Prevx icon in your system tray at the bottom-right corner of your screen and choose "Show Management Console".
  • On the Management Console click the Protection Level drop-down menu. You will see three levels:

    • Maximum
    • Off
    • User Defined
  • To disable all protection set the level to Off. You will receive a prompt asking "You are about to change your security settings. Do you wish to continue?" Click Yes.
  • Click the X on the upper right hand corner to exit the Management console.




Disable SpyBot Tea Timer
While TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent HijackThis from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your HijackThis log is clean.
  • Open Spybot Search & Destroy.
  • In the Mode menu click "Advanced mode" if not already selected.
  • Choose "Yes" at the Warning prompt.
  • Expand the "Tools" menu.
  • Click "Resident".
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • In the File menu click "Exit" to exit Spybot Search & Destroy.




Reboot
Reboot your system in Safe Mode.
  • Restart the computer. The computer begins processing a set of instructions known as BIOS.
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (dependent on your system this may be F5 or another key)
  • Instead of Windows loading as normal, a menu should appear
  • Use the arrow key to highlight Safe Mode and press Enter.



HijackThis Entries
Open Hijack This and click on Scan. Check the following entries (if they still exist) (make sure you do not miss any)

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} -
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/Yazzl...cab?refid=1162
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgGB2404.exe
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -
O16 - DPF: {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.5.0_05) -
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} -
O20 - AppInit_DLLs:
O20 - Winlogon Notify: Nls - C:\WINDOWS\
O20 - Winlogon Notify: RunServices - C:\WINDOWS\


Please remember to close all other windows, including browsers then click Fix checked.




Run CleanUp!
*NOTE* Cleanup deletes EVERYTHING out of temporary folders and does NOT make backups. If you have any files in any TEMP directory and you need to keep them, then please MOVE THEM NOW!

Open Cleanup! by double-clicking the icon on your desktop (or from Start > All Programs). Set the program up as follows:

Click Options
Move the slider button down to Custom CleanUp!
Check the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Cleanup! All Users
  • Click on the “Temporary Files” tab and uncheck the box for “Scan drives for file matching” if it’s checked.

Click OK, Press the CleanUp! button to start the program and DO NOT REBOOT when prompted.
Note: CleanUp! deletes EVERYTHING out of your temp/temporary folders, it does not make backups. If you have any documents or programs that are saved in any Temporary Folders, please make a backup of these BEFORE running CleanUp! If you have a 64 bit Operating System do NOT run Cleanup and let me know as we will use another utility.




Run AVG Anti Spyware
Run AVG with it's updated definitions:(...it's important that all windows must be closed)
  • Click Scanner
  • Click on the Scan tab
  • Click Complete System Scan to begin scanning.
  • When the scan is complete click Recommended Action and change it to Quarantine
  • Then click Apply all actions
Once finished, click the Save report button, then click Save Report As and save it to your desktop.

NOTE: AVG scan may require an hour.



Reboot
Reboot your system in Normal Mode.



Online Scan
Perform an online scan with Internet Explorer with Panda ActiveScan
  1. Click on
    located at the bottom of the page.
  2. A "pop up" window will appear. * Please ensure that your pop up blocker doesn't block it *
  3. Enter your e-mail address, country, and state & click "Free Online Scan" *The download of the 8 MB Panda's ActiveX control will take place*
Begin the scan by selecting

  • If it finds any malware, it will offer you a report.
  • Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
  • Click on
    then click
* You needn't remain online while it's doing the scan but you have to re-connect after it has finished to see the report.
* Turn off the real time scanner of any existing antivirus program while performing the online scan




Logs required
c:\combofix.txt
AVG Log
Panda Log
HijackThis Log


Please also let me know how your system is performing now and if you have any specific problems. In order to provide you with the best possible help, please ensure that HijackThis logs are produced only while in Normal Mode.
 

·
Registered
Joined
·
4 Posts
Discussion Starter · #3 ·
Here we go

Hi Iain, and firstly thank you for taking the time to help.

My Pc has stopped sending out to port 25 (hurrah), and as you will see below, found a couple of nasties during the safe mode tests (it took over 5 hours for AVGAS to scan btw), and a few things from Panda scan. During the HJT scan an error popped up also, not sure if you want to see that, but ill post it just in case. This is that error:

"An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: )
Error #5 - Invalid procedure call or argument

Please email me at [email protected], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 7.0.5730.11
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan."


Startup was slow when returning to "normal mde", but im guessing thats from the prefetch wipe. Otherwise things seem ok. I have since, uninstalled Prevx, and installed Zonealarm (i was relying on the builtin hardware firewall in my router, better to have both?) Here are the results.

ComboFix:

"Ben" - 07-01-17 20:45:04 Service Pack 2
ComboFix 07-01-16.2 - Running from: "C:\Documents and Settings\Ben\Desktop"

((((((((((((((((((((((((((((((((((((((((((((( Look2Me's Log ))))))))))))))))))))))))))))))))))))))))))))))))))


Granting SeDebugPrivilege to Administrators ... successful


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\wnstssu.exe
C:\WINDOWS\system32\drivers\npf.sys
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\Ben
C:\qoobox\purity\DOCUME~1\Ben\Application Data
C:\qoobox\purity\DOCUME~1\Ben\My Documents
C:\qoobox\purity\DOCUME~1\Ben\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\Ben\Application Data\SCURIT~1
C:\qoobox\purity\DOCUME~1\Ben\My Documents\FNTS~1
C:\qoobox\purity\DOCUME~1\Ben\My Documents\FNTS~2
C:\qoobox\purity\DOCUME~1\Ben\My Documents\from.txt
C:\qoobox\purity\DOCUME~1\Ben\My Documents\FNTS~1\F?nts


((((((((((((((((((((((((((((((( Files Created from 2006-12-17 to 2007-01-17 ))))))))))))))))))))))))))))))))))


2007-01-17 20:49 <DIR> d-------- C:\WINDOWS\erdnt
2007-01-17 20:38 3,968 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-01-17 20:38 <DIR> d-------- C:\Program Files\Grisoft
2007-01-17 12:26 <DIR> d-------- C:\DOCUME~1\Ben\Application Data\VisualZone
2007-01-17 12:03 <DIR> d-------- C:\Program Files\VisualZone
2007-01-17 12:03 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\VisualZone
2007-01-17 12:00 75,512 --a------ C:\WINDOWS\zllsputility.exe
2007-01-17 12:00 11,264 --a------ C:\WINDOWS\SYSTEM32\SpOrder.dll
2007-01-17 12:00 1,087,216 --a------ C:\WINDOWS\SYSTEM32\zpeng24.dll
2007-01-17 12:00 <DIR> d-------- C:\WINDOWS\SYSTEM32\ZoneLabs
2007-01-16 04:10 <DIR> d-------- C:\Program Files\Kaspersky Lab
2007-01-16 03:44 <DIR> d-------- C:\DOCUME~1\Ben\.housecall6.6
2007-01-15 23:34 2,560 --a------ C:\WINDOWS\_MSRSTRT.EXE
2007-01-15 23:25 <DIR> d-------- C:\Program Files\Lavasoft
2007-01-15 23:19 <DIR> d-------- C:\hijackthis
2007-01-15 15:56 11,648 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pxscrmbl.sys
2007-01-13 15:29 <DIR> d-------- C:\Program Files\Electronic Arts
2007-01-11 14:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-10 17:10 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Kontiki
2007-01-10 17:08 <DIR> d-------- C:\WINDOWS\ie7updates
2007-01-10 13:21 <DIR> d-------- C:\Program Files\The All-Seeing Eye
2007-01-07 21:13 <DIR> d-------- C:\Program Files\DAP
2007-01-03 19:50 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\nHancer
2007-01-03 18:33 720,896 --------- C:\WINDOWS\SYSTEM32\a3d.dll
2007-01-03 17:09 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\nView_Profiles
2007-01-03 17:04 208,896 --a------ C:\WINDOWS\SYSTEM32\NVUNINST.EXE
2007-01-03 17:04 208,896 --a------ C:\WINDOWS\SYSTEM32\nvudisp.exe
2007-01-03 17:04 <DIR> d-------- C:\WINDOWS\nview
2007-01-03 13:39 <DIR> d-------- C:\Program Files\OpenAL
2007-01-03 04:13 6,094,848 --a------ C:\WINDOWS\SYSTEM32\Skyrocket.scr
2007-01-03 04:13 532,480 --a------ C:\WINDOWS\SYSTEM32\Hyperspace.scr
2007-01-03 04:13 483,328 --a------ C:\WINDOWS\SYSTEM32\Helios.scr
2007-01-03 04:13 450,560 --a------ C:\WINDOWS\SYSTEM32\Euphoria.scr
2007-01-03 04:13 274,432 --a------ C:\WINDOWS\SYSTEM32\Cyclone.scr
2007-01-03 04:13 249,856 --a------ C:\WINDOWS\SYSTEM32\Flocks.scr
2007-01-03 04:13 245,760 --a------ C:\WINDOWS\SYSTEM32\Flux.scr
2007-01-03 04:13 237,568 --a------ C:\WINDOWS\SYSTEM32\SolarWinds.scr
2007-01-03 04:13 237,568 --a------ C:\WINDOWS\SYSTEM32\FieldLines.scr
2007-01-03 04:13 229,376 --a------ C:\WINDOWS\SYSTEM32\Plasma.scr
2007-01-03 04:13 1,908,736 --a------ C:\WINDOWS\SYSTEM32\Lattice.scr
2007-01-03 04:06 409,600 --a------ C:\WINDOWS\SYSTEM32\wrap_oal.dll
2007-01-03 04:06 114,688 --a------ C:\WINDOWS\SYSTEM32\OpenAL32.dll
2006-12-31 14:04 92,208 --a------ C:\WINDOWS\SYSTEM\WING.DLL
2006-12-31 14:04 27,136 --a------ C:\WINDOWS\SYSTEM\WAVMIX16.DLL
2006-12-31 14:04 21,008 --a------ C:\WINDOWS\SYSTEM\CTL3D.DLL
2006-12-31 14:04 188,960 --a------ C:\WINDOWS\SYSTEM\WINGDE.DLL
2006-12-31 14:04 12,800 --a------ C:\WINDOWS\SYSTEM\WING32.DLL
2006-12-31 14:04 <DIR> d-------- C:\SIMTOWER
2006-12-29 20:16 <DIR> d-------- C:\Program Files\Wanadoo Edition
2006-12-25 14:02 309,616 --a------ C:\WINDOWS\SYSTEM32\wmv8dmod.dll
2006-12-25 13:48 <DIR> d-------- C:\Program Files\SEGA
2006-12-20 12:30 68,888 --a------ C:\WINDOWS\SYSTEM32\xinput1_3.dll
2006-12-20 12:30 3,426,072 --a------ C:\WINDOWS\SYSTEM32\d3dx9_32.dll
2006-12-20 12:30 251,672 --a------ C:\WINDOWS\SYSTEM32\xactengine2_5.dll
2006-12-20 12:30 237,848 --a------ C:\WINDOWS\SYSTEM32\xactengine2_4.dll
2006-12-20 12:30 2,414,360 --a------ C:\WINDOWS\SYSTEM32\d3dx9_31.dll
2006-12-20 12:30 15,128 --a------ C:\WINDOWS\SYSTEM32\x3daudio1_1.dll
2006-12-20 11:47 <DIR> d-------- C:\Program Files\a-squared Free
2006-12-19 08:50 62,744 --a------ C:\WINDOWS\SYSTEM32\xinput1_2.dll
2006-12-19 08:50 236,824 --a------ C:\WINDOWS\SYSTEM32\xactengine2_3.dll
2006-12-19 08:37 <DIR> d-------- C:\Program Files\America's Army
2006-12-18 08:33 <DIR> d-------- C:\Program Files\XnView
2006-12-18 08:33 <DIR> d-------- C:\DOCUME~1\Ben\Application Data\XnView
2006-12-18 01:59 <DIR> d-------- C:\Program Files\Bit Che
2006-12-17 03:56 <DIR> d-------- C:\Program Files\PC Wizard 2006


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-17 19:54 -------- d-------- C:\Program Files\mozilla firefox
2007-01-17 12:26 -------- d-------- C:\Documents and Settings\Ben\Application Data\visualzone
2007-01-17 09:48 -------- d-------- C:\Documents and Settings\Ben\Application Data\azureus
2007-01-16 20:14 -------- d-------- C:\Program Files\microsoft games
2007-01-16 18:10 -------- d-------- C:\Program Files\peerguardian2
2007-01-16 05:24 -------- d-------- C:\Documents and Settings\Ben\Application Data\utorrent
2007-01-16 05:23 -------- d-------- C:\Program Files\winmx
2007-01-16 05:23 -------- d-------- C:\Program Files\winmpg videoconvert
2007-01-16 05:23 -------- d-------- C:\Program Files\security task manager
2007-01-16 05:23 -------- d-------- C:\Program Files\maplom
2007-01-16 05:23 -------- d-------- C:\Program Files\irfanview
2007-01-16 05:23 -------- d-------- C:\Program Files\filecomp
2007-01-15 23:34 2560 --a------ C:\WINDOWS\_msrstrt.exe
2007-01-15 23:25 -------- d-------- C:\Documents and Settings\Ben\Application Data\lavasoft
2007-01-15 22:53 -------- d-------- C:\Documents and Settings\Ben\Application Data\registry booster
2007-01-14 22:40 43520 --a------ C:\WINDOWS\SYSTEM32\cmdlineext03.dll
2007-01-14 20:38 -------- d--h----- C:\Program Files\installshield installation information
2007-01-14 20:29 -------- d-------- C:\Program Files\thq
2007-01-11 21:30 -------- d-------- C:\Documents and Settings\Ben\Application Data\vso
2007-01-11 14:41 -------- d-------- C:\Documents and Settings\Ben\Application Data\adobeum
2007-01-08 05:04 -------- d-------- C:\Documents and Settings\Ben\Application Data\adobe
2007-01-07 19:47 -------- d-------- C:\Program Files\warcraft iii
2007-01-07 01:24 -------- d-------- C:\Program Files\dosbox-0.65
2006-12-27 14:33 -------- d-------- C:\Program Files\ea games
2006-12-25 13:48 737280 --a------ C:\WINDOWS\iun6002.exe
2006-12-23 22:05 -------- d-------- C:\Program Files\fraps
2006-12-19 13:26 -------- d-------- C:\Program Files\rockstar games
2006-12-18 08:33 -------- d-------- C:\Documents and Settings\Ben\Application Data\xnview
2006-12-17 20:10 -------- d-------- C:\Documents and Settings\Ben\Application Data\dvdcss
2006-12-16 16:58 -------- d-------- C:\Program Files\virtual mechanics
2006-12-16 16:46 -------- d-------- C:\Program Files\abcwebwizardevaluation
2006-12-15 11:40 -------- d-------- C:\Program Files\tunexp
2006-12-13 17:56 -------- d-------- C:\Program Files\winuae
2006-12-13 16:28 -------- d-------- C:\Program Files\infogrames interactive
2006-12-12 14:02 -------- d-------- C:\Program Files\java
2006-12-12 13:56 -------- d-------- C:\Program Files\zoom player
2006-12-11 14:58 -------- d-------- C:\Program Files\lionhead studios
2006-12-06 23:13 -------- d-------- C:\Program Files\winamp
2006-12-04 17:29 -------- d-------- C:\Program Files\driver cleaner pro
2006-12-04 16:44 -------- d-------- C:\Program Files\Common Files\easyinfo
2006-12-04 13:11 -------- d-------- C:\Program Files\futuremark
2006-12-04 12:57 -------- d-------- C:\Program Files\aquamark3
2006-12-03 03:19 69632 --a--c--- C:\WINDOWS\SYSTEM32\realbap1.dll
2006-12-03 03:19 45568 --a--c--- C:\WINDOWS\SYSTEM32\realbsf1.dll
2006-12-01 11:52 -------- d-------- C:\Program Files\activision value
2006-11-30 17:15 -------- d--h----- C:\Documents and Settings\Ben\Application Data\acv
2006-11-30 11:34 -------- d-------- C:\Program Files\hwinfo32
2006-11-29 10:27 -------- d-------- C:\Program Files\infogrames
2006-11-27 08:15 4096 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\NVStrap.sys
2006-11-26 19:33 -------- d-------- C:\Program Files\bethesda softworks
2006-11-26 05:00 278528 --a------ C:\WINDOWS\SYSTEM32\livesnth.dll
2006-11-26 05:00 203776 --a------ C:\WINDOWS\SYSTEM32\clrviddc.dll
2006-11-26 04:57 176167 --a------ C:\WINDOWS\SYSTEM32\rmocx.dll
2006-11-26 04:56 -------- d-------- C:\Documents and Settings\Ben\Application Data\real
2006-11-26 04:42 -------- d-------- C:\Program Files\firaxis games
2006-11-23 13:37 -------- d-------- C:\Program Files\scorched3d
2006-11-22 09:28 -------- d-------- C:\Program Files\windows media connect 2
2006-11-21 11:14 -------- d-------- C:\Program Files\ubisoft
2006-11-19 17:02 81920 --a------ C:\Documents and Settings\Ben\Application Data\ezpinst.exe
2006-11-19 17:02 7176 --a------ C:\Documents and Settings\Ben\Application Data\pcouffin.cat
2006-11-19 17:02 47360 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\pcouffin.sys
2006-11-19 17:02 47360 --a------ C:\Documents and Settings\Ben\Application Data\pcouffin.sys
2006-11-19 17:02 34 --a------ C:\Documents and Settings\Ben\Application Data\pcouffin.log
2006-11-19 17:02 1144 --a------ C:\Documents and Settings\Ben\Application Data\pcouffin.inf
2006-11-19 17:02 -------- d-------- C:\Program Files\vso
2006-11-19 17:02 -------- d-------- C:\Program Files\super dvd creator 9.25.0
2006-11-18 18:41 -------- d-------- C:\Documents and Settings\Ben\Application Data\river past g5
2006-11-10 14:57 73216 --a------ C:\WINDOWS\st6unst.exe
2006-11-10 14:57 249856 --------- C:\WINDOWS\setup1.exe
2006-11-08 05:06 679424 --a------ C:\WINDOWS\SYSTEM32\inetcomm.dll
2006-11-07 21:03 6049280 --------- C:\WINDOWS\SYSTEM32\ieframe.dll
2006-11-07 21:03 50688 --------- C:\WINDOWS\SYSTEM32\msfeedsbs.dll
2006-11-07 21:03 458752 --------- C:\WINDOWS\SYSTEM32\msfeeds.dll
2006-11-07 21:03 413696 --a------ C:\WINDOWS\SYSTEM32\vbscript.dll
2006-11-07 21:03 231424 --a------ C:\WINDOWS\SYSTEM32\webcheck.dll
2006-11-07 21:03 180736 --------- C:\WINDOWS\SYSTEM32\ieui.dll
2006-11-07 21:03 156160 --a------ C:\WINDOWS\SYSTEM32\msls31.dll
2006-11-07 03:27 382976 --a------ C:\WINDOWS\SYSTEM32\iedkcs32.dll
2006-11-07 03:27 229376 --a------ C:\WINDOWS\SYSTEM32\ieaksie.dll
2006-11-07 03:26 71680 --a------ C:\WINDOWS\SYSTEM32\admparse.dll
2006-11-07 03:26 55296 --a------ C:\WINDOWS\SYSTEM32\iesetup.dll
2006-11-07 03:26 54784 --a------ C:\WINDOWS\SYSTEM32\ie4uinit.exe
2006-11-07 03:26 43008 --a------ C:\WINDOWS\SYSTEM32\iernonce.dll
2006-11-07 03:26 152064 --a------ C:\WINDOWS\SYSTEM32\ieakeng.dll
2006-11-07 03:26 13312 --a------ C:\WINDOWS\SYSTEM32\ieudinit.exe
2006-11-07 03:26 123904 --a------ C:\WINDOWS\SYSTEM32\advpack.dll
2006-11-07 03:25 161792 --a------ C:\WINDOWS\SYSTEM32\ieakui.dll
2006-11-04 14:14 1245696 --a------ C:\WINDOWS\SYSTEM32\msxml4.dll
2006-10-26 13:08 40960 --a------ C:\WINDOWS\SYSTEM32\frapsvid.dll
2006-10-22 12:22 888832 --a------ C:\WINDOWS\SYSTEM32\nvmobls.dll
2006-10-22 12:22 86016 --a------ C:\WINDOWS\SYSTEM32\nvmctray.dll
2006-10-22 12:22 81920 --a------ C:\WINDOWS\SYSTEM32\nvwddi.dll
2006-10-22 12:22 794624 --a------ C:\WINDOWS\SYSTEM32\nvcplui.exe
2006-10-22 12:22 7700480 --a------ C:\WINDOWS\SYSTEM32\nvcpl.dll
2006-10-22 12:22 581632 --a------ C:\WINDOWS\SYSTEM32\nvhwvid.dll
2006-10-22 12:22 5644288 --a------ C:\WINDOWS\SYSTEM32\nvoglnt.dll
2006-10-22 12:22 5619712 --a------ C:\WINDOWS\SYSTEM32\nvdisps.dll
2006-10-22 12:22 5255168 --a------ C:\WINDOWS\SYSTEM32\nvdispsr.dll
2006-10-22 12:22 466944 --a------ C:\WINDOWS\SYSTEM32\nvshell.dll
2006-10-22 12:22 458752 --a------ C:\WINDOWS\SYSTEM32\nvmccssr.dll
2006-10-22 12:22 4527488 --a------ C:\WINDOWS\SYSTEM32\nv4_disp.dll
2006-10-22 12:22 45056 --a------ C:\WINDOWS\SYSTEM32\nvmccsrs.dll
2006-10-22 12:22 442368 --a------ C:\WINDOWS\SYSTEM32\nvappbar.exe
2006-10-22 12:22 425984 --a------ C:\WINDOWS\SYSTEM32\keystone.exe
2006-10-22 12:22 35840 --a------ C:\WINDOWS\SYSTEM32\nvcodins.dll
2006-10-22 12:22 35840 --a------ C:\WINDOWS\SYSTEM32\nvcod.dll
2006-10-22 12:22 3203072 --a------ C:\WINDOWS\SYSTEM32\nvgamesr.dll
2006-10-22 12:22 311296 --a------ C:\WINDOWS\SYSTEM32\nvexpbar.dll
2006-10-22 12:22 3047424 --a------ C:\WINDOWS\SYSTEM32\nvgames.dll
2006-10-22 12:22 2973696 --a------ C:\WINDOWS\SYSTEM32\nvvitvsr.dll
2006-10-22 12:22 2924544 --a------ C:\WINDOWS\SYSTEM32\nvvitvs.dll
2006-10-22 12:22 286720 --a------ C:\WINDOWS\SYSTEM32\nvnt4cpl.dll
2006-10-22 12:22 2859008 --a------ C:\WINDOWS\SYSTEM32\nvmoblsr.dll
2006-10-22 12:22 229376 --a------ C:\WINDOWS\SYSTEM32\nvmccs.dll
2006-10-22 12:22 212992 --a------ C:\WINDOWS\SYSTEM32\nvapi.dll
2006-10-22 12:22 188416 --a------ C:\WINDOWS\SYSTEM32\nvmccss.dll
2006-10-22 12:22 1732608 --a------ C:\WINDOWS\SYSTEM32\nvwssr.dll
2006-10-22 12:22 1662976 --a------ C:\WINDOWS\SYSTEM32\nvwdmcpl.dll
2006-10-22 12:22 1622016 --a------ C:\WINDOWS\SYSTEM32\nwiz.exe
2006-10-22 12:22 159810 --a------ C:\WINDOWS\SYSTEM32\nvsvc32.exe
2006-10-22 12:22 147456 --a------ C:\WINDOWS\SYSTEM32\nvcolor.exe
2006-10-22 12:22 1470464 --a------ C:\WINDOWS\SYSTEM32\nview.dll
2006-10-22 12:22 1339392 --a------ C:\WINDOWS\SYSTEM32\nvdspsch.exe
2006-10-22 12:22 1236992 --a------ C:\WINDOWS\SYSTEM32\nvwss.dll
2006-10-22 12:22 1019904 --a------ C:\WINDOWS\SYSTEM32\nvwimg.dll
2006-10-22 12:22 1011712 --a------ C:\WINDOWS\SYSTEM32\nvcpluir.dll
2006-10-19 13:56 713216 --a------ C:\WINDOWS\SYSTEM32\sxs.dll
2006-10-18 21:58 8704 --a------ C:\WINDOWS\SYSTEM32\wdfmgr.exe
2006-10-18 21:58 8704 --a------ C:\WINDOWS\SYSTEM32\uwdf.exe
2006-10-18 21:47 99840 --a------ C:\WINDOWS\SYSTEM32\wmpshell.dll
2006-10-18 21:47 991744 --a------ C:\WINDOWS\SYSTEM32\drmv2clt.dll
2006-10-18 21:47 937984 --a------ C:\WINDOWS\SYSTEM32\wmnetmgr.dll
2006-10-18 21:47 8231936 --a------ C:\WINDOWS\SYSTEM32\wmploc.dll
2006-10-18 21:47 767488 --------- C:\WINDOWS\SYSTEM32\wmvsencd.dll
2006-10-18 21:47 757248 --a------ C:\WINDOWS\SYSTEM32\wmadmod.dll
2006-10-18 21:47 7168 --a------ C:\WINDOWS\SYSTEM32\asferror.dll
2006-10-18 21:47 656896 --------- C:\WINDOWS\SYSTEM32\wmvxencd.dll
2006-10-18 21:47 63488 --a------ C:\WINDOWS\SYSTEM32\wpdmtpus.dll
2006-10-18 21:47 629760 --a------ C:\WINDOWS\SYSTEM32\wpd_ci.dll
2006-10-18 21:47 613376 --------- C:\WINDOWS\SYSTEM32\wmpmde.dll
2006-10-18 21:47 603648 --a------ C:\WINDOWS\SYSTEM32\wmspdmod.dll
2006-10-18 21:47 542720 --a------ C:\WINDOWS\SYSTEM32\blackbox.dll
2006-10-18 21:47 535040 --------- C:\WINDOWS\SYSTEM32\wmdrmsdk.dll
2006-10-18 21:47 429056 --a------ C:\WINDOWS\SYSTEM32\wmdrmdev.dll
2006-10-18 21:47 414208 --a------ C:\WINDOWS\SYSTEM32\msscp.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wmvdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wmvdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wmvadve.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wmvadvd.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wmsdmoe2.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wmsdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\wdfapi.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\mpg4dmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\mp4sdmod.dll
2006-10-18 21:47 4096 --a------ C:\WINDOWS\SYSTEM32\mp43dmod.dll
2006-10-18 21:47 38400 --------- C:\WINDOWS\SYSTEM32\wpdshextres.dll
2006-10-18 21:47 37376 --a------ C:\WINDOWS\SYSTEM32\wmdmps.dll
2006-10-18 21:47 35840 --a------ C:\WINDOWS\SYSTEM32\wpdconns.dll
2006-10-18 21:47 356352 --a------ C:\WINDOWS\SYSTEM32\wpdsp.dll
2006-10-18 21:47 348672 --a------ C:\WINDOWS\SYSTEM32\wmdrmnet.dll
2006-10-18 21:47 33792 --a------ C:\WINDOWS\SYSTEM32\wmdmlog.dll
2006-10-18 21:47 321536 --a------ C:\WINDOWS\SYSTEM32\mswmdm.dll
2006-10-18 21:47 317440 --------- C:\WINDOWS\SYSTEM32\mp4sdecd.dll
2006-10-18 21:47 314880 --a------ C:\WINDOWS\SYSTEM32\wmpdxm.dll
2006-10-18 21:47 295936 --------- C:\WINDOWS\SYSTEM32\wmpeffects.dll
2006-10-18 21:47 284160 --a------ C:\WINDOWS\SYSTEM32\portabledeviceapi.dll
2006-10-18 21:47 276992 --a------ C:\WINDOWS\SYSTEM32\audiodev.dll
2006-10-18 21:47 27136 --a------ C:\WINDOWS\SYSTEM32\mspmsnsv.dll
2006-10-18 21:47 2603008 --------- C:\WINDOWS\SYSTEM32\wpdshext.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\SYSTEM32\mpg4decd.dll
2006-10-18 21:47 259072 --------- C:\WINDOWS\SYSTEM32\mp43decd.dll
2006-10-18 21:47 2450944 --a------ C:\WINDOWS\SYSTEM32\wmvcore.dll
2006-10-18 21:47 242688 --a------ C:\WINDOWS\SYSTEM32\wmpasf.dll
2006-10-18 21:47 229376 --a------ C:\WINDOWS\SYSTEM32\cewmdm.dll
2006-10-18 21:47 227328 --a------ C:\WINDOWS\SYSTEM32\wmerror.dll
2006-10-18 21:47 222208 --a------ C:\WINDOWS\SYSTEM32\wmasf.dll
2006-10-18 21:47 212992 --------- C:\WINDOWS\SYSTEM32\mfplat.dll
2006-10-18 21:47 211456 --a------ C:\WINDOWS\SYSTEM32\qasf.dll
2006-10-18 21:47 204288 --a------ C:\WINDOWS\SYSTEM32\wmpsrcwp.dll
2006-10-18 21:47 199168 --------- C:\WINDOWS\SYSTEM32\portabledevicewmdrm.dll
2006-10-18 21:47 179712 --a------ C:\WINDOWS\SYSTEM32\msnetobj.dll
2006-10-18 21:47 175616 --a------ C:\WINDOWS\SYSTEM32\mspmsp.dll
2006-10-18 21:47 166912 --a------ C:\WINDOWS\SYSTEM32\portabledevicetypes.dll
2006-10-18 21:47 1661440 --a------ C:\WINDOWS\SYSTEM32\wmpencen.dll
2006-10-18 21:47 1574912 --------- C:\WINDOWS\SYSTEM32\wmvencod.dll
2006-10-18 21:47 157184 --a------ C:\WINDOWS\SYSTEM32\wmidx.dll
2006-10-18 21:47 154624 --a------ C:\WINDOWS\SYSTEM32\wpdmtp.dll
2006-10-18 21:47 1543680 --------- C:\WINDOWS\SYSTEM32\wmvdecod.dll
2006-10-18 21:47 1382912 --------- C:\WINDOWS\SYSTEM32\wmvsdecd.dll
2006-10-18 21:47 133632 --a------ C:\WINDOWS\SYSTEM32\wpdshserviceobj.dll
2006-10-18 21:47 1329152 --a------ C:\WINDOWS\SYSTEM32\wmspdmoe.dll
2006-10-18 21:47 132096 --------- C:\WINDOWS\SYSTEM32\portabledevicewiacompat.dll
2006-10-18 21:47 130048 --------- C:\WINDOWS\SYSTEM32\wmpps.dll
2006-10-18 21:47 11264 --a------ C:\WINDOWS\SYSTEM32\laprxy.dll
2006-10-18 21:47 1117696 --a------ C:\WINDOWS\SYSTEM32\wmadmoe.dll
2006-10-18 21:47 101888 --------- C:\WINDOWS\SYSTEM32\portabledeviceclassextension.dll
2006-10-18 20:03 100864 --a------ C:\WINDOWS\SYSTEM32\logagent.exe
2006-10-18 20:00 249856 --------- C:\WINDOWS\SYSTEM32\drmupgds.exe
2006-10-18 20:00 17408 --------- C:\WINDOWS\SYSTEM32\wpdshextautoplay.exe
2006-10-17 18:06 0 --a------ C:\dllhost32.exe
2006-10-17 18:05 0 --a------ C:\dll6wise.dll
2006-10-17 17:41 53248 --a------ C:\Interop.Shell32.dll
2006-10-17 17:41 23510720 --a------ C:\dotnetfx.exe
2006-10-17 12:06 78336 --a------ C:\WINDOWS\SYSTEM32\ieencode.dll
2006-10-17 12:05 40960 --a------ C:\WINDOWS\SYSTEM32\licmgr10.dll
2006-10-17 12:05 206336 --------- C:\WINDOWS\SYSTEM32\winfxdocobj.exe
2006-10-17 12:05 105984 --a------ C:\WINDOWS\SYSTEM32\url.dll
2006-10-17 12:04 101376 --a------ C:\WINDOWS\SYSTEM32\occache.dll
2006-10-17 12:03 17408 --a------ C:\WINDOWS\SYSTEM32\corpol.dll
2006-10-17 11:58 61952 --------- C:\WINDOWS\SYSTEM32\icardie.dll
2006-10-17 11:58 12288 --------- C:\WINDOWS\SYSTEM32\msfeedssync.exe
2006-10-17 11:57 36352 --a------ C:\WINDOWS\SYSTEM32\imgutil.dll
2006-10-17 11:57 266752 --------- C:\WINDOWS\SYSTEM32\iertutil.dll
2006-10-17 11:56 45568 --a------ C:\WINDOWS\SYSTEM32\mshta.exe
2006-10-17 11:28 48128 --a------ C:\WINDOWS\SYSTEM32\mshtmler.dll
2006-10-17 11:27 380928 --------- C:\WINDOWS\SYSTEM32\ieapfltr.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Logitech Utility"="Logi_MwX.Exe"
"vptray"="C:\\PROGRA~1\\SYMANT~1\\SYMANT~1\\vptray.exe"
"SoundMAXPnP"="C:\\Program Files\\Analog Devices\\Core\\smax4pnp.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"NvMediaCenter"="RunDLL32.exe NvMCTray.dll,NvTaskbarInit"
"ioloDelayModule"="C:\\Program Files\\iolo\\System Mechanic Professional 6\\delay.exe"
"ZoneAlarm Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk.disabled]
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnk.disabledCommon Startup"
"location"="Common Startup"
"item"="Adobe Reader Speed Launch.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"BITS"=dword:00000003
"Spooler"=dword:00000002

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"0aMCPClient"="{F5DF91F9-15E9-416B-A7C3-7519B11ECBFC}"
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=dword:00000001
"NoSaveSettings"=hex:00,00,00,00
"ClearRecentDocsOnExit"=hex:01,00,00,00

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AutorunsDisabled
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winwim32

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0

HKLM\software\Microsoft\Windows NT\CurrentVersion\Svchost *netsvcs*
RpcxSs

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\H]
Shell\AutoRun\command H:\Autorun.exe

[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{910df47c-bf3b-11da-ac5d-806d6172696f}]
Shell\AutoRun\command D:\Autorun.exe
*newlycreated* - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_AVGASCLN

Completion time: 07-01-17 20:52:34


AVGAS Report:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 03:07:07 18/01/2007

+ Scan result:



E:\Apps\Cracks\Windows Keygens\MSKey4in1.exe -> Backdoor.Tagent.e : Cleaned with backup (quarantined).
E:\Apps\Cracks\Windows Keygens\MSKey4in1.rar/MSKey4in1.exe -> Backdoor.Tagent.e : Cleaned with backup (quarantined).
E:\Apps\Net\TCP Uncapper From 10 To 50 Sp2 Only\EvID4226Patch223d-en.zip/EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
E:\Apps\Net\TCP Uncapper From 10 To 50 Sp2 Only\EvID4226Patch223d-en\EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
E:\Apps\Net\TCP Uncapper From 10 To 50 Sp2 Only\EvID4226Patch223d-en\EvID4226Patch223d-en.zip/EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
E:\Apps\Net\winmx354beta4\EvID4226Patch223d-en\EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
E:\Apps\Net\winmx354beta4\EvID4226Patch223d-en\EvID4226Patch223d-en.zip/EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32:lzx32.sys -> Trojan.Rustock.nbh : Cleaned with backup (quarantined).
C:\Program Files\FAST Defrag\close.com -> Worm.Warezov.fh : Cleaned with backup (quarantined).


::Report end

HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 09:02:27, on 18/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Burn The Heretic
O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - (no file)
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (file missing)
O2 - BHO: (no name) - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - (disabled by BHODemon)
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ioloDelayModule] C:\Program Files\iolo\System Mechanic Professional 6\delay.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-gb/4,0,0,90/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-gb/1,0,0,23/mcgdmgr.cab
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winwim32 - C:\WINDOWS\
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Panda Active Scan


Incident Status Location

Adware:adware/ist.istbar Not disinfected Windows Registry
Adware:adware/ncase Not disinfected Windows Registry
Adware:adware/powerstrip Not disinfected Windows Registry


Phew, let me know what you think. Thanks Again.
 

·
Security Manager, Analyst , Rangemaster, TSF Acade
Joined
·
39,538 Posts
Hi again

AVG can take a while but it is very thorough.

I notice you have several cracks and P2P applications. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.

Looking pretty good.


Please delete the following files indicated in RED if they still exist.

C:\ dllhost32.exe
C:\ dll6wise.dll

Note: If they resist, you may have to boot to Safe Mode to delete them.



Please do this online scan.

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky WebScanner

Next Click on Kaspersky Online Scanner


A Welcome screen will appear - click 'Accept' at the bottom. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
Scan using the following Anti-Virus database:
  • Extended
Scan Options:
  • Scan Archives
  • Scan Mail Bases
Click OK

Now under select a target to scan: Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Take note of the name(s) and location(s) of any file(s) it detects but fails to clean.

* Turn off the real time scanner of any existing antivirus program while performing the online scan


Please post back with the Kaspersky Log and a fresh HijackThis Log. Please also let me know how your system is performing now and if you have any specific problems. In order to provide you with the best possible help, please ensure that HijackThis logs are produced only while in Normal Mode.
 

·
Registered
Joined
·
4 Posts
Discussion Starter · #5 ·
Slight problem

Hi Iain, im having trouble getting the kapasky (sp) to run. Ive used Internet explorer, as per their suggestions, but to no avail. It hangs after clicking the scan now button and waiting an hour. No pop up blockers where blocking it and i did allow the activex to run. Was this just to scan the PC again, and if so should i just use a different one, or was it that one specifically for a reason?

Also, i booted up the PC this morning and it crashed after 5-6 minutes, well, i say crashed, but the screen went black and froze. This is the first time this has happenend. This is from the Event Viewer:

Event Type: Error
Event Source: System Error
Event Category: (102)
Event ID: 1003
Date: 19/01/2007
Time: 09:28:15
User: N/A
Computer: DEICIDE_1
Description:
Error code 1000008e, parameter1 c0000006, parameter2 af1a886b, parameter3 f9292440, parameter4 00000000.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
Data:
0000: 53 79 73 74 65 6d 20 45 System E
0008: 72 72 6f 72 20 20 45 72 rror Er
0010: 72 6f 72 20 63 6f 64 65 ror code
0018: 20 31 30 30 30 30 30 38 1000008
0020: 65 20 20 50 61 72 61 6d e Param
0028: 65 74 65 72 73 20 63 30 eters c0
0030: 30 30 30 30 30 36 2c 20 000006,
0038: 61 66 31 61 38 38 36 62 af1a886b
0040: 2c 20 66 39 32 39 32 34 , f92924
0048: 34 30 2c 20 30 30 30 30 40, 0000
0050: 30 30 30 30 0000

Any ideas on that one? Thanks.
 

·
Security Manager, Analyst , Rangemaster, TSF Acade
Joined
·
39,538 Posts
1 - 6 of 6 Posts
Status
Not open for further replies.
Top