Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Win32:Ramnit-E & ExeDropper - blocking access to Malwarebytes upda


  • This topic is locked This topic is locked

#1
figurer

figurer

    Member

  • Member
  • PipPip
  • 23 posts
Please Help! The infections won't allow me to access certain websites (Avast forum, Malwarebytes etc.) but luckily I've found that I can access geekstogo.com

Last night I stopped being able to access my website for which I have a Filezilla client shortcut on my desktop, although any other computer could acces it fine. That was the first problem

Then a few hours later I started getting tons of Avast warnings for ExeDropper and Win32:Ramnit every few seconds.

Then when I tried running Malwarebytes, I kept getting an error message when I tried to update the definitions. Avast had frequent problems connecting to the server when I would try to update.

Then I stopped being able to access the Avast forum domain on IE, although other websites worked. Same with sites to download MWB again.

I set the max size of my virus chest in Avast to 0 as was suggested on the Avast forum (which I was browsing on a borrowed computer). However, whenever I try a boot time scan, it can't complete because when trying to move files to chest it says that the disk is full (which it is not).

I run the Free version of Avast.

I would be very grateful if someone could help me; I run my business from my infected computer and am lost without it.

Thanks,

Jason

Here is the OTL.txt:
OTL logfile created on: 03/11/2010 2:01:52 PM - Run 1
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 68.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): D:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 4.50 Gb Total Space | 3.00 Gb Free Space | 66.66% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 0.98 Gb Free Space | 6.53% Space Free | Partition Type: NTFS
Drive E: | 67.25 Gb Total Space | 13.38 Gb Free Space | 19.89% Space Free | Partition Type: NTFS
Drive F: | 5.00 Gb Total Space | 4.32 Gb Free Space | 86.46% Space Free | Partition Type: NTFS

Computer Name: RONSOCO | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/09/07 08:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/05/18 13:23:54 | 000,389,120 | R--- | M] (Teleca) -- D:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
PRC - [2010/04/29 15:39:32 | 001,090,952 | ---- | M] (Malwarebytes Corporation) -- D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2010/03/17 16:22:52 | 001,019,904 | R--- | M] (Teleca Sweden AB) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
PRC - [2010/03/17 16:08:22 | 000,253,952 | R--- | M] (TODO: <Company name>) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
PRC - [2010/03/17 16:08:04 | 000,462,848 | R--- | M] (Teleca AB) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
PRC - [2009/12/11 15:50:34 | 000,557,056 | R--- | M] (Teleca AB) -- D:\Program Files\Common Files\Teleca Shared\Generic.exe
PRC - [2009/11/19 17:19:48 | 000,598,016 | R--- | M] (Teleca Sweden AB) -- D:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
PRC - [2009/06/03 10:25:16 | 000,106,496 | R--- | M] (Popwire AB) -- D:\Program Files\Common Files\Teleca Shared\logger.exe
PRC - [2009/04/14 13:14:26 | 000,139,264 | ---- | M] (Teleca Sweden AB) -- D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2006/03/24 17:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- D:\WINDOWS\stsystra.exe
PRC - [2005/11/07 05:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- D:\WINDOWS\system32\DLA\DLACTRLW.EXE


========== Modules (SafeList) ==========

MOD - [2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Unknown | Stopped] -- -- (Macromedia Licensing Service)
SRV - File not found [On_Demand | Stopped] -- D:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - File not found [Unknown | Stopped] -- -- (Adobe LM Service)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\drivers\UIUSys.sys -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\DRIVERS\ctpdusb.sys -- (Jukebox3)
DRV - [2010/09/07 07:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 07:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 07:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 07:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 07:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 07:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2009/06/10 00:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2008/04/13 11:46:20 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008/04/13 11:46:20 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/15 22:15:44 | 000,033,824 | ---- | M] () [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\oreans32.sys -- (oreans32)
DRV - [2006/10/12 23:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006/03/24 17:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 12:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005/11/18 12:02:50 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- D:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/11/18 12:02:10 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- D:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/11/07 05:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/11/07 05:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/11/07 05:20:00 | 000,086,652 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/11/07 05:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/11/07 05:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/11/07 05:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/11/07 05:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/09/12 03:30:00 | 000,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- D:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2005/08/12 05:20:00 | 000,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2005/08/05 11:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 11:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 11:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 11:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/07/14 18:58:14 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/07/14 17:28:38 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/07/12 19:00:30 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2004/10/14 15:33:26 | 000,024,576 | ---- | M] (BridgeCo AG) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ps_avs.sys -- (ps_avs)
DRV - [2004/10/14 15:33:22 | 000,097,152 | ---- | M] (BridgeCo AG) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ps_1394.sys -- (ps_1394)
DRV - [2004/03/11 17:19:36 | 000,346,560 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\PRISMA02.sys -- (PRISM_A02) D-Link Wireless 802.11b/g Driver (USB)
DRV - [2003/05/05 19:25:48 | 000,028,205 | ---- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] -- D:\WINDOWS\system32\ANIO.sys -- (ANIO)
DRV - [2001/08/22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- D:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/06/01 20:14:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/06/02 06:47:37 | 000,000,000 | ---D | M]

[2010/04/30 21:49:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/09/22 23:37:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\rkentt2s.default\extensions
[2010/05/02 09:04:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\rkentt2s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/22 23:37:18 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - D:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O4 - HKLM..\Run: [avast5] D:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] D:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DLA] D:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [Mobile Connectivity Suite] D:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKLM..\Run: [SigmatelSysTrayApp] D:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Lookup on Merriam Webster - D:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - D:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll File not found
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll File not found
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?LinkID=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://westmap.westv...er/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1263243885500 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1271281110234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.128,93.188.160.208
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - D:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/14 00:26:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{3319cc92-b74b-11dc-8674-0015c5b8b783}\Shell - "" = AutoRun
O33 - MountPoints2\{3319cc92-b74b-11dc-8674-0015c5b8b783}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (aswBoot.exe /M:121cc0430) - D:\WINDOWS\System32\aswBoot.exe (AVAST Software)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/03 14:00:45 | 000,576,000 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/03 10:07:16 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/11/03 10:06:57 | 000,000,000 | ---D | C] -- D:\WINDOWS\LMI15.tmp
[2010/11/02 21:39:42 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft
[2010/10/19 08:01:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Desktop\Tree at Ryan and Karens
[2010/10/16 18:44:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Application Data\Teleca
[2010/10/16 18:44:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Local Settings\Application Data\HTC
[2010/10/16 18:44:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\HTC
[2010/10/16 18:43:58 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Teleca Shared
[2010/10/16 18:43:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Teleca
[2010/10/16 18:43:21 | 000,024,576 | ---- | C] (HTC, Corporation) -- D:\WINDOWS\System32\drivers\ANDROIDUSB.sys
[2010/10/16 18:43:16 | 000,000,000 | ---D | C] -- D:\Program Files\Spirent Communications
[2010/10/16 18:43:12 | 000,000,000 | ---D | C] -- D:\Program Files\HTC
[2010/10/16 18:41:30 | 000,000,000 | ---D | C] -- D:\WINDOWS\Downloaded Installations
[2010/10/04 21:52:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Desktop\longboard craigslist
[2006/12/07 10:30:44 | 000,017,920 | ---- | C] ( ) -- D:\WINDOWS\System32\ShellLnk.dll
[2006/12/07 10:30:43 | 000,018,944 | ---- | C] ( ) -- D:\WINDOWS\System32\Implode.dll
[8 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/11/03 14:03:00 | 000,000,422 | -H-- | M] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{60208E93-38E5-48D3-87A5-A4ABA6A99286}.job
[2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/03 13:41:46 | 000,436,470 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010/11/03 13:41:46 | 000,069,008 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010/11/03 13:38:03 | 000,000,880 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/03 13:37:35 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010/11/03 13:19:40 | 000,002,626 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2010/11/03 11:32:00 | 000,000,884 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 11:12:00 | 000,000,978 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003UA.job
[2010/11/03 10:52:41 | 000,000,016 | ---- | M] () -- D:\WINDOWS\System32\dmlconf.dat
[2010/11/02 19:28:00 | 000,000,926 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003Core1cb668fc6642740.job
[2010/10/19 08:06:27 | 001,197,118 | ---- | M] () -- D:\Documents and Settings\Owner\Desktop\greenhouse window.jpg
[2010/10/17 18:07:47 | 000,002,513 | ---- | M] () -- D:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2010/10/17 00:17:05 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/10/17 00:17:04 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/10/11 07:30:59 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[8 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[1 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/11/02 21:39:42 | 000,000,016 | ---- | C] () -- D:\WINDOWS\System32\dmlconf.dat
[2010/10/19 08:06:27 | 001,197,118 | ---- | C] () -- D:\Documents and Settings\Owner\Desktop\greenhouse window.jpg
[2010/10/17 00:17:05 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/10/17 00:17:04 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/10/07 19:23:20 | 000,000,926 | ---- | C] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003Core1cb668fc6642740.job
[2010/09/11 23:13:10 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\Owner\Application Data\AVSDVDPlayer.m3u
[2010/02/04 19:49:03 | 000,176,235 | ---- | C] () -- D:\WINDOWS\System32\Primomonnt.dll
[2009/08/03 12:17:56 | 000,000,101 | ---- | C] () -- D:\WINDOWS\lexstat.ini
[2009/08/03 12:17:29 | 000,077,824 | ---- | C] () -- D:\WINDOWS\System32\LXBKLCNP.DLL
[2009/08/03 12:17:29 | 000,040,960 | ---- | C] () -- D:\WINDOWS\System32\lxbkvs.dll
[2009/08/03 12:17:10 | 000,000,266 | ---- | C] () -- D:\WINDOWS\System32\lxbkcoin.ini
[2009/07/30 18:58:42 | 000,000,314 | ---- | C] () -- D:\WINDOWS\primopdf.ini
[2007/02/20 23:37:50 | 000,006,656 | ---- | C] () -- D:\WINDOWS\System32\CNMVS58.DLL
[2007/01/22 21:29:38 | 000,777,728 | ---- | C] () -- D:\WINDOWS\System32\SSLSVC.DLL
[2007/01/22 21:29:38 | 000,069,632 | ---- | C] () -- D:\WINDOWS\System32\xmltok.dll
[2007/01/22 21:29:38 | 000,040,960 | ---- | C] () -- D:\WINDOWS\System32\cfmsg.dll
[2007/01/22 21:29:38 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\xmlparse.dll
[2007/01/22 21:29:37 | 000,114,688 | ---- | C] () -- D:\WINDOWS\System32\lang_cfml.dll
[2007/01/22 21:29:37 | 000,028,672 | ---- | C] () -- D:\WINDOWS\System32\xml_datagrove.dll
[2006/12/07 11:58:43 | 000,210,944 | ---- | C] () -- D:\WINDOWS\System32\MSVCRT10.DLL
[2006/11/26 00:25:17 | 000,000,112 | ---- | C] () -- D:\WINDOWS\ActiveSkin.INI
[2006/11/17 22:58:08 | 000,000,032 | ---- | C] () -- D:\WINDOWS\CD_Start.INI
[2006/11/08 21:25:42 | 000,001,376 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/15 22:15:44 | 000,033,824 | ---- | C] () -- D:\WINDOWS\System32\drivers\oreans32.sys
[2006/10/15 22:15:22 | 000,524,288 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2006/10/15 22:15:22 | 000,139,264 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll
[2006/10/15 20:08:35 | 000,068,608 | ---- | C] () -- D:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/10/15 10:24:30 | 000,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2006/10/14 10:39:48 | 000,000,000 | ---- | C] () -- D:\WINDOWS\iPlayer.INI
[2006/10/14 10:28:04 | 000,000,698 | ---- | C] () -- D:\WINDOWS\wininit.ini
[2006/10/14 10:06:21 | 000,016,480 | ---- | C] () -- D:\WINDOWS\System32\rixdicon.dll
[2006/10/14 09:52:24 | 000,757,760 | ---- | C] () -- D:\WINDOWS\System32\bcm1xsup.dll
[2006/10/14 09:52:23 | 000,086,016 | ---- | C] () -- D:\WINDOWS\System32\preflib.dll
[2006/10/13 17:14:03 | 000,004,161 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2005/11/28 17:11:07 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\px.ini
[2003/01/07 07:05:08 | 000,002,695 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI
[2001/11/27 17:59:52 | 000,483,405 | ---- | C] () -- D:\WINDOWS\System32\Taper.dll

========== LOP Check ==========

[2010/05/15 09:55:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/10/30 22:01:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2010/10/16 18:44:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\HTC
[2006/10/14 19:58:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/10/16 18:44:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Teleca
[2009/04/29 18:50:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/11/20 23:28:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Cycling '74
[2010/05/04 21:17:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\FileZilla
[2010/05/20 12:13:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\ieSpell
[2010/10/27 21:27:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\PrimoPDF
[2010/02/04 19:57:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Softland
[2006/10/16 21:18:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Steinberg
[2010/10/17 00:17:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Teleca
[2010/11/03 14:03:00 | 000,000,422 | -H-- | M] () -- D:\WINDOWS\Tasks\User_Feed_Synchronization-{60208E93-38E5-48D3-87A5-A4ABA6A99286}.job

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there this is a pretty virulent infection and may take a few runs to clean

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 93.188.164.128,93.188.160.208
    [2010/11/03 10:06:57 | 000,000,000 | ---D | C] -- D:\WINDOWS\LMI15.tmp

    :Files
    ipconfig /flushdns /c

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download Dr Web from here http://www.freedrweb.com/?lng=en link on the top right of the page, tick the EULA and then download

It will download as an 8 digit file save it to your desktop

Restart in safe mode and run
Accept the enhanced version
Then run the quick scan
About halfway through you will be prompted to buy - just X the box closed
Once finished it will generate a log please attach that
  • 0

#3
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
About to run DrWeb. Here are the results of the last OTL run in the meantime....

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\\NameServer| /E : value set successfully!
D:\WINDOWS\LMI15.tmp folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
D:\Documents and Settings\Owner\Desktop\cmd.bat deleted successfully.
D:\Documents and Settings\Owner\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
D:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: El Musico
->Temp folder emptied: 5570475 bytes
->Temporary Internet Files folder emptied: 5707302 bytes
->Java cache emptied: 7140 bytes
->FireFox cache emptied: 5283113 bytes
->Flash cache emptied: 348 bytes

User: LocalService
->Temp folder emptied: 67865 bytes
->Temporary Internet Files folder emptied: 75640 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67787 bytes

User: Owner
->Temp folder emptied: 392312326 bytes
->Temporary Internet Files folder emptied: 10553807 bytes
->Java cache emptied: 34769175 bytes
->FireFox cache emptied: 85545234 bytes
->Flash cache emptied: 101185 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2214750 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 51421218 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 133819643 bytes

Total Files Cleaned = 694.00 mb


[EMPTYFLASH]

User: All Users

User: Default User

User: El Musico
->Flash cache emptied: 0 bytes

User: LocalService

User: NetworkService

User: Owner
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point (0)

OTL by OldTimer - Version 3.2.17.2 log created on 11032010_151508

Files\Folders moved on Reboot...
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\NU80JGON\ads[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\NU80JGON\xd_proxy[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\KBSSGD7D\ads[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\KBSSGD7D\index[2].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\KBSSGD7D\like[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\JH93JHP9\ads[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\EMVON0RL\289581-win32ramnit-e-exedropper-blocking-access-to-malwarebytes-update-avast-forum[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. D:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Here is OTL.Txt:

OTL logfile created on: 03/11/2010 3:19:21 PM - Run 2
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 88.00% Paging File free
Paging file location(s): D:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 4.50 Gb Total Space | 3.00 Gb Free Space | 66.66% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 2.33 Gb Free Space | 15.50% Space Free | Partition Type: NTFS
Drive E: | 67.25 Gb Total Space | 13.38 Gb Free Space | 19.89% Space Free | Partition Type: NTFS
Drive F: | 5.00 Gb Total Space | 4.38 Gb Free Space | 87.48% Space Free | Partition Type: NTFS

Computer Name: RONSOCO | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/09/07 08:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/05/18 13:23:54 | 000,389,120 | R--- | M] (Teleca) -- D:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
PRC - [2010/03/17 16:22:52 | 001,019,904 | R--- | M] (Teleca Sweden AB) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
PRC - [2010/03/17 16:08:22 | 000,253,952 | R--- | M] (TODO: <Company name>) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
PRC - [2010/03/17 16:08:04 | 000,462,848 | R--- | M] (Teleca AB) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
PRC - [2009/12/11 15:50:34 | 000,557,056 | R--- | M] (Teleca AB) -- D:\Program Files\Common Files\Teleca Shared\Generic.exe
PRC - [2009/11/19 17:19:48 | 000,598,016 | R--- | M] (Teleca Sweden AB) -- D:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
PRC - [2009/06/03 10:25:16 | 000,106,496 | R--- | M] (Popwire AB) -- D:\Program Files\Common Files\Teleca Shared\logger.exe
PRC - [2009/04/14 13:14:26 | 000,139,264 | ---- | M] (Teleca Sweden AB) -- D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
PRC - [2008/04/23 03:38:16 | 000,029,696 | ---- | M] (Adobe Systems Incorporated) -- D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2006/03/24 17:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- D:\WINDOWS\stsystra.exe
PRC - [2005/11/07 05:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- D:\WINDOWS\system32\DLA\DLACTRLW.EXE


========== Modules (SafeList) ==========

MOD - [2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- D:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\drivers\UIUSys.sys -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\DRIVERS\ctpdusb.sys -- (Jukebox3)
DRV - [2010/09/07 07:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 07:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 07:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 07:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 07:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 07:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/06/10 00:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2008/04/13 11:46:20 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008/04/13 11:46:20 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/15 22:15:44 | 000,033,824 | ---- | M] () [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\oreans32.sys -- (oreans32)
DRV - [2006/10/12 23:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006/03/24 17:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 12:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005/11/18 12:02:50 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- D:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/11/18 12:02:10 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- D:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/11/07 05:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/11/07 05:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/11/07 05:20:00 | 000,086,652 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/11/07 05:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/11/07 05:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/11/07 05:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/11/07 05:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/09/12 03:30:00 | 000,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- D:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2005/08/12 05:20:00 | 000,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2005/08/05 11:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 11:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 11:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 11:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/07/14 18:58:14 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/07/14 17:28:38 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/07/12 19:00:30 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2004/10/14 15:33:26 | 000,024,576 | ---- | M] (BridgeCo AG) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ps_avs.sys -- (ps_avs)
DRV - [2004/10/14 15:33:22 | 000,097,152 | ---- | M] (BridgeCo AG) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ps_1394.sys -- (ps_1394)
DRV - [2004/03/11 17:19:36 | 000,346,560 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\PRISMA02.sys -- (PRISM_A02) D-Link Wireless 802.11b/g Driver (USB)
DRV - [2003/05/05 19:25:48 | 000,028,205 | ---- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] -- D:\WINDOWS\system32\ANIO.sys -- (ANIO)
DRV - [2001/08/22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- D:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/06/01 20:14:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/11/03 14:02:15 | 000,000,000 | ---D | M]

[2010/04/30 21:49:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/09/22 23:37:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\rkentt2s.default\extensions
[2010/05/02 09:04:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\rkentt2s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/22 23:37:18 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/11/03 15:15:10 | 000,000,098 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - D:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O4 - HKLM..\Run: [avast5] D:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] D:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DLA] D:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [Mobile Connectivity Suite] D:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKLM..\Run: [SigmatelSysTrayApp] D:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Lookup on Merriam Webster - D:\Program Files\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - D:\Program Files\ieSpell\wikipedia.HTM ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll File not found
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll File not found
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?LinkID=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://westmap.westv...er/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1263243885500 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1271281110234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - D:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/14 00:26:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{3319cc92-b74b-11dc-8674-0015c5b8b783}\Shell - "" = AutoRun
O33 - MountPoints2\{3319cc92-b74b-11dc-8674-0015c5b8b783}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (aswBoot.exe /M:121cc0430) - D:\WINDOWS\System32\aswBoot.exe (AVAST Software)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/03 15:15:08 | 000,000,000 | ---D | C] -- D:\_OTL
[2010/11/03 14:00:45 | 000,576,000 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/03 10:07:16 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/11/02 21:39:42 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft
[2010/10/19 08:01:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Desktop\Tree at Ryan and Karens
[2010/10/16 18:44:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Application Data\Teleca
[2010/10/16 18:44:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Local Settings\Application Data\HTC
[2010/10/16 18:44:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\HTC
[2010/10/16 18:43:58 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Teleca Shared
[2010/10/16 18:43:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Teleca
[2010/10/16 18:43:21 | 000,024,576 | ---- | C] (HTC, Corporation) -- D:\WINDOWS\System32\drivers\ANDROIDUSB.sys
[2010/10/16 18:43:16 | 000,000,000 | ---D | C] -- D:\Program Files\Spirent Communications
[2010/10/16 18:43:12 | 000,000,000 | ---D | C] -- D:\Program Files\HTC
[2010/10/16 18:41:30 | 000,000,000 | ---D | C] -- D:\WINDOWS\Downloaded Installations
[2010/10/04 21:52:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Desktop\longboard craigslist
[2006/12/07 10:30:44 | 000,017,920 | ---- | C] ( ) -- D:\WINDOWS\System32\ShellLnk.dll
[2006/12/07 10:30:43 | 000,018,944 | ---- | C] ( ) -- D:\WINDOWS\System32\Implode.dll

========== Files - Modified Within 30 Days ==========

[2010/11/03 15:18:00 | 000,000,422 | -H-- | M] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{60208E93-38E5-48D3-87A5-A4ABA6A99286}.job
[2010/11/03 15:17:55 | 000,000,880 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/03 15:17:32 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010/11/03 15:15:10 | 000,000,098 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\Hosts
[2010/11/03 15:12:00 | 000,000,978 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003UA.job
[2010/11/03 15:07:04 | 051,541,576 | ---- | M] () -- D:\Documents and Settings\Owner\Desktop\2lyyuf64.exe
[2010/11/03 14:55:01 | 000,436,470 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010/11/03 14:55:01 | 000,069,008 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010/11/03 14:32:01 | 000,000,884 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/03 13:19:40 | 000,002,626 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2010/11/03 10:52:41 | 000,000,016 | ---- | M] () -- D:\WINDOWS\System32\dmlconf.dat
[2010/11/02 19:28:00 | 000,000,926 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003Core1cb668fc6642740.job
[2010/10/19 08:06:27 | 001,197,118 | ---- | M] () -- D:\Documents and Settings\Owner\Desktop\greenhouse window.jpg
[2010/10/17 18:07:47 | 000,002,513 | ---- | M] () -- D:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2010/10/17 00:17:05 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/10/17 00:17:04 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/10/11 07:30:59 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2010/11/03 15:07:03 | 051,541,576 | ---- | C] () -- D:\Documents and Settings\Owner\Desktop\2lyyuf64.exe
[2010/11/02 21:39:42 | 000,000,016 | ---- | C] () -- D:\WINDOWS\System32\dmlconf.dat
[2010/10/19 08:06:27 | 001,197,118 | ---- | C] () -- D:\Documents and Settings\Owner\Desktop\greenhouse window.jpg
[2010/10/17 00:17:05 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/10/17 00:17:04 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/10/07 19:23:20 | 000,000,926 | ---- | C] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003Core1cb668fc6642740.job
[2010/09/11 23:13:10 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\Owner\Application Data\AVSDVDPlayer.m3u
[2010/02/04 19:49:03 | 000,176,235 | ---- | C] () -- D:\WINDOWS\System32\Primomonnt.dll
[2009/08/03 12:17:56 | 000,000,101 | ---- | C] () -- D:\WINDOWS\lexstat.ini
[2009/08/03 12:17:29 | 000,077,824 | ---- | C] () -- D:\WINDOWS\System32\LXBKLCNP.DLL
[2009/08/03 12:17:29 | 000,040,960 | ---- | C] () -- D:\WINDOWS\System32\lxbkvs.dll
[2009/08/03 12:17:10 | 000,000,266 | ---- | C] () -- D:\WINDOWS\System32\lxbkcoin.ini
[2009/07/30 18:58:42 | 000,000,314 | ---- | C] () -- D:\WINDOWS\primopdf.ini
[2007/02/20 23:37:50 | 000,006,656 | ---- | C] () -- D:\WINDOWS\System32\CNMVS58.DLL
[2007/01/22 21:29:38 | 000,777,728 | ---- | C] () -- D:\WINDOWS\System32\SSLSVC.DLL
[2007/01/22 21:29:38 | 000,069,632 | ---- | C] () -- D:\WINDOWS\System32\xmltok.dll
[2007/01/22 21:29:38 | 000,040,960 | ---- | C] () -- D:\WINDOWS\System32\cfmsg.dll
[2007/01/22 21:29:38 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\xmlparse.dll
[2007/01/22 21:29:37 | 000,114,688 | ---- | C] () -- D:\WINDOWS\System32\lang_cfml.dll
[2007/01/22 21:29:37 | 000,028,672 | ---- | C] () -- D:\WINDOWS\System32\xml_datagrove.dll
[2006/12/07 11:58:43 | 000,210,944 | ---- | C] () -- D:\WINDOWS\System32\MSVCRT10.DLL
[2006/11/26 00:25:17 | 000,000,112 | ---- | C] () -- D:\WINDOWS\ActiveSkin.INI
[2006/11/17 22:58:08 | 000,000,032 | ---- | C] () -- D:\WINDOWS\CD_Start.INI
[2006/11/08 21:25:42 | 000,001,376 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/15 22:15:44 | 000,033,824 | ---- | C] () -- D:\WINDOWS\System32\drivers\oreans32.sys
[2006/10/15 22:15:22 | 000,524,288 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2006/10/15 22:15:22 | 000,139,264 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll
[2006/10/15 20:08:35 | 000,068,608 | ---- | C] () -- D:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/10/15 10:24:30 | 000,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2006/10/14 10:39:48 | 000,000,000 | ---- | C] () -- D:\WINDOWS\iPlayer.INI
[2006/10/14 10:28:04 | 000,000,698 | ---- | C] () -- D:\WINDOWS\wininit.ini
[2006/10/14 10:06:21 | 000,016,480 | ---- | C] () -- D:\WINDOWS\System32\rixdicon.dll
[2006/10/14 09:52:24 | 000,757,760 | ---- | C] () -- D:\WINDOWS\System32\bcm1xsup.dll
[2006/10/14 09:52:23 | 000,086,016 | ---- | C] () -- D:\WINDOWS\System32\preflib.dll
[2006/10/13 17:14:03 | 000,004,161 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2005/11/28 17:11:07 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\px.ini
[2003/01/07 07:05:08 | 000,002,695 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI
[2001/11/27 17:59:52 | 000,483,405 | ---- | C] () -- D:\WINDOWS\System32\Taper.dll

========== LOP Check ==========

[2010/05/15 09:55:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/10/30 22:01:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2010/10/16 18:44:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\HTC
[2006/10/14 19:58:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/10/16 18:44:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Teleca
[2009/04/29 18:50:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/11/20 23:28:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Cycling '74
[2010/05/04 21:17:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\FileZilla
[2010/05/20 12:13:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\ieSpell
[2010/10/27 21:27:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\PrimoPDF
[2010/02/04 19:57:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Softland
[2006/10/16 21:18:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Steinberg
[2010/10/17 00:17:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Teleca
[2010/11/03 15:18:00 | 000,000,422 | -H-- | M] () -- D:\WINDOWS\Tasks\User_Feed_Synchronization-{60208E93-38E5-48D3-87A5-A4ABA6A99286}.job

========== Purity Check ==========



< End of report >
  • 0

#4
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
You may be able to access security sites now
  • 0

#5
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I can now update Malwarebytes and access the Avast forum.

DrWeb scan is just finishing and a popup came up saying "the HOSTS file modified". I allowed it to restore the default HOSTS file.

Edited by figurer, 03 November 2010 - 07:41 PM.

  • 0

#6
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
It won't let me attach the .log file, so i've changed it to a .txt file...

Things seem to be running better now, however, I have noticed that a window now opens on startup with my "my documents" folder. Is that suspicious?

*UPDATE* - I updated malwarebytes and ran a full scan, it detected no threats.

After that, I did a full scan with Avast Free, and it detected something like 1700 infected files...

I clicked "apply" for the action of moving all files to the chest. It took a long time.

Thanks for all your help so far. Here is the log from DrWeb (CureIt), and from Avast (Full System Scan):

Attached Files


Edited by figurer, 03 November 2010 - 07:40 PM.

  • 0

#7
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
HELP!

I'm just running the OTL scan with the "Custom Scans/Fixes" rules pasted in again, and as it was creating the restore point an error message came up. I clicked ok, and now the program is stuck at creating the restore point. It says DO NOT INTERRUPT.... Can I close it and restart the system, or will that screw everything up? Not sure what to do, please help....
  • 0

#8
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
I've since closed OTL and reset the system. Seems to be working.
Here is the log:
Files\Folders moved on Reboot...
File\Folder D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\J7UTEII1\forum[2].txt not found!
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\J7UTEII1\like[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\J7UTEII1\xd_proxy[1].htm moved successfully.
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\IDAIGQ88\ads[8].htm moved successfully.
File\Folder D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\IDAIGQ88\index[3].php not found!
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\0NHN79Y6\ads[4].htm moved successfully.
File\Folder D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\0NHN79Y6\page__gopid__1921487[2].txt not found!
D:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.
File move failed. D:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot...
  • 0

#9
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Just did another OTL quick scan after reboot... Here is the log:

OTL logfile created on: 04/11/2010 11:31:17 AM - Run 3
OTL by OldTimer - Version 3.2.17.2 Folder = D:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 72.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): D:\pagefile.sys 1024 1024 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 4.50 Gb Total Space | 3.00 Gb Free Space | 66.66% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 1.18 Gb Free Space | 7.88% Space Free | Partition Type: NTFS
Drive E: | 67.25 Gb Total Space | 13.38 Gb Free Space | 19.90% Space Free | Partition Type: NTFS
Drive F: | 5.00 Gb Total Space | 4.38 Gb Free Space | 87.57% Space Free | Partition Type: NTFS

Computer Name: RONSOCO | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2010/09/07 08:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/05/18 13:23:54 | 000,389,120 | R--- | M] (Teleca) -- D:\Program Files\HTC\HTC Sync\ClientInitiatedStarter\ClientInitiatedStarter.exe
PRC - [2010/03/17 16:22:52 | 001,019,904 | R--- | M] (Teleca Sweden AB) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\epmworker.exe
PRC - [2010/03/17 16:08:22 | 000,253,952 | R--- | M] (TODO: <Company name>) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\FsynSrvStarter.exe
PRC - [2010/03/17 16:08:04 | 000,462,848 | R--- | M] (Teleca AB) -- D:\Program Files\HTC\HTC Sync\Mobile Phone Monitor\HTCVBTServer.exe
PRC - [2009/12/11 15:50:34 | 000,557,056 | R--- | M] (Teleca AB) -- D:\Program Files\Common Files\Teleca Shared\Generic.exe
PRC - [2009/11/19 17:19:48 | 000,598,016 | R--- | M] (Teleca Sweden AB) -- D:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe
PRC - [2009/06/03 10:25:16 | 000,106,496 | R--- | M] (Popwire AB) -- D:\Program Files\Common Files\Teleca Shared\logger.exe
PRC - [2009/04/14 13:14:26 | 000,139,264 | ---- | M] (Teleca Sweden AB) -- D:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
PRC - [2008/04/23 03:38:16 | 000,029,696 | ---- | M] (Adobe Systems Incorporated) -- D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
PRC - [2008/04/13 17:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\explorer.exe
PRC - [2006/03/24 17:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- D:\WINDOWS\stsystra.exe
PRC - [2005/11/07 05:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- D:\WINDOWS\system32\DLA\DLACTRLW.EXE


========== Modules (SafeList) ==========

MOD - [2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- D:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- D:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 08:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- D:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\drivers\UIUSys.sys -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\WINDOWS\System32\DRIVERS\ctpdusb.sys -- (Jukebox3)
DRV - [2010/09/07 07:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 07:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 07:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- D:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 07:47:19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010/09/07 07:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- D:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/09/07 07:46:51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- D:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2009/06/10 00:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2008/04/13 11:46:20 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\61883.sys -- (61883)
DRV - [2008/04/13 11:46:20 | 000,038,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\avc.sys -- (Avc)
DRV - [2008/04/13 09:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2006/10/15 22:15:44 | 000,033,824 | ---- | M] () [Kernel | System | Running] -- D:\WINDOWS\system32\drivers\oreans32.sys -- (oreans32)
DRV - [2006/10/12 23:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006/03/24 17:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 12:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005/11/18 12:02:50 | 000,005,660 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- D:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/11/18 12:02:10 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- D:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/11/07 05:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/11/07 05:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/11/07 05:20:00 | 000,086,652 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/11/07 05:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/11/07 05:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/11/07 05:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/11/07 05:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/09/12 03:30:00 | 000,089,264 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- D:\WINDOWS\System32\Drivers\DRVMCDB.SYS -- (DRVMCDB)
DRV - [2005/08/12 05:20:00 | 000,040,544 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- D:\WINDOWS\system32\drivers\DRVNDDM.SYS -- (DRVNDDM)
DRV - [2005/08/05 11:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2005/07/22 11:02:12 | 001,035,008 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_DPV.sys -- (HSF_DPV)
DRV - [2005/07/22 11:01:08 | 000,201,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSFHWAZL.sys -- (HSFHWAZL)
DRV - [2005/07/22 11:01:00 | 000,717,952 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2005/07/14 18:58:14 | 000,028,544 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2005/07/14 17:28:38 | 000,307,968 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/07/12 19:00:30 | 000,051,328 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- D:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2004/10/14 15:33:26 | 000,024,576 | ---- | M] (BridgeCo AG) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ps_avs.sys -- (ps_avs)
DRV - [2004/10/14 15:33:22 | 000,097,152 | ---- | M] (BridgeCo AG) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\ps_1394.sys -- (ps_1394)
DRV - [2004/03/11 17:19:36 | 000,346,560 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- D:\WINDOWS\system32\drivers\PRISMA02.sys -- (PRISM_A02) D-Link Wireless 802.11b/g Driver (USB)
DRV - [2003/05/05 19:25:48 | 000,028,205 | ---- | M] (Alpha Networks Inc.) [Kernel | Auto | Running] -- D:\WINDOWS\system32\ANIO.sys -- (ANIO)
DRV - [2001/08/22 08:42:58 | 000,013,632 | ---- | M] (Dell Computer Corporation) [Kernel | System | Running] -- D:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS -- (OMCI)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2010/06/01 20:14:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2010/11/03 14:02:15 | 000,000,000 | ---D | M]

[2010/04/30 21:49:52 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2010/09/22 23:37:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\rkentt2s.default\extensions
[2010/05/02 09:04:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- D:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\rkentt2s.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/09/22 23:37:18 | 000,000,000 | ---D | M] -- D:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/11/04 08:25:58 | 000,000,098 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - D:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O4 - HKLM..\Run: [avast5] D:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] D:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DLA] D:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [Mobile Connectivity Suite] D:\Program Files\HTC\HTC Sync\Application Launcher\Application Launcher.exe (Teleca Sweden AB)
O4 - HKLM..\Run: [SigmatelSysTrayApp] D:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll File not found
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - D:\Program Files\ieSpell\iespell.dll File not found
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - D:\Program Files\ieSpell\iespell.dll File not found
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?LinkID=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase6087.cab (Windows Live Safety Center Base Module)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://westmap.westv...er/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1263243885500 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1271281110234 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - D:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O24 - Desktop WallPaper: D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: D:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/10/14 00:26:28 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{3319cc92-b74b-11dc-8674-0015c5b8b783}\Shell - "" = AutoRun
O33 - MountPoints2\{3319cc92-b74b-11dc-8674-0015c5b8b783}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/11/03 19:29:21 | 000,000,000 | -HSD | C] -- D:\Config.Msi
[2010/11/03 15:34:19 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\DoctorWeb
[2010/11/03 15:15:08 | 000,000,000 | ---D | C] -- D:\_OTL
[2010/11/03 14:00:45 | 000,576,000 | ---- | C] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/03 10:07:16 | 000,000,000 | ---D | C] -- D:\Documents and Settings\LocalService\Local Settings\Application Data\ICS
[2010/11/02 21:39:42 | 000,000,000 | ---D | C] -- D:\Program Files\Microsoft
[2010/10/19 08:01:24 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Desktop\Tree at Ryan and Karens
[2010/10/16 18:44:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Application Data\Teleca
[2010/10/16 18:44:22 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Owner\Local Settings\Application Data\HTC
[2010/10/16 18:44:04 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\HTC
[2010/10/16 18:43:58 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Teleca Shared
[2010/10/16 18:43:58 | 000,000,000 | ---D | C] -- D:\Documents and Settings\All Users\Application Data\Teleca
[2010/10/16 18:43:21 | 000,024,576 | ---- | C] (HTC, Corporation) -- D:\WINDOWS\System32\drivers\ANDROIDUSB.sys
[2010/10/16 18:43:16 | 000,000,000 | ---D | C] -- D:\Program Files\Spirent Communications
[2010/10/16 18:43:12 | 000,000,000 | ---D | C] -- D:\Program Files\HTC
[2010/10/16 18:41:30 | 000,000,000 | ---D | C] -- D:\WINDOWS\Downloaded Installations
[2006/12/07 10:30:44 | 000,017,920 | ---- | C] ( ) -- D:\WINDOWS\System32\ShellLnk.dll
[2006/12/07 10:30:43 | 000,018,944 | ---- | C] ( ) -- D:\WINDOWS\System32\Implode.dll

========== Files - Modified Within 30 Days ==========

[2010/11/04 11:33:00 | 000,000,422 | -H-- | M] () -- D:\WINDOWS\tasks\User_Feed_Synchronization-{60208E93-38E5-48D3-87A5-A4ABA6A99286}.job
[2010/11/04 11:32:00 | 000,000,884 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/11/04 11:30:18 | 000,436,470 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2010/11/04 11:30:18 | 000,069,008 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2010/11/04 11:25:55 | 000,000,880 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/11/04 11:25:41 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2010/11/04 11:12:02 | 000,000,978 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003UA.job
[2010/11/04 08:25:58 | 000,000,098 | ---- | M] () -- D:\WINDOWS\System32\drivers\etc\Hosts
[2010/11/03 19:41:56 | 000,343,424 | ---- | M] () -- D:\WINDOWS\System32\FNTCACHE.DAT
[2010/11/03 19:38:14 | 000,001,374 | ---- | M] () -- D:\WINDOWS\imsins.BAK
[2010/11/03 19:28:00 | 000,000,926 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003Core1cb668fc6642740.job
[2010/11/03 15:07:04 | 051,541,576 | ---- | M] () -- D:\Documents and Settings\Owner\Desktop\2lyyuf64.exe
[2010/11/03 14:00:48 | 000,576,000 | ---- | M] (OldTimer Tools) -- D:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/11/03 13:19:40 | 000,002,626 | ---- | M] () -- D:\WINDOWS\System32\CONFIG.NT
[2010/11/03 10:52:41 | 000,000,016 | ---- | M] () -- D:\WINDOWS\System32\dmlconf.dat
[2010/10/19 08:06:27 | 001,197,118 | ---- | M] () -- D:\Documents and Settings\Owner\Desktop\greenhouse window.jpg
[2010/10/17 18:07:47 | 000,002,513 | ---- | M] () -- D:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2010/10/17 00:17:05 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/10/17 00:17:04 | 000,000,000 | -H-- | M] () -- D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/10/11 07:30:59 | 000,002,206 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2010/11/03 15:07:03 | 051,541,576 | ---- | C] () -- D:\Documents and Settings\Owner\Desktop\2lyyuf64.exe
[2010/11/02 21:39:42 | 000,000,016 | ---- | C] () -- D:\WINDOWS\System32\dmlconf.dat
[2010/10/19 08:06:27 | 001,197,118 | ---- | C] () -- D:\Documents and Settings\Owner\Desktop\greenhouse window.jpg
[2010/10/17 00:17:05 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2010/10/17 00:17:04 | 000,000,000 | -H-- | C] () -- D:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2010/10/07 19:23:20 | 000,000,926 | ---- | C] () -- D:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1275210071-789336058-725345543-1003Core1cb668fc6642740.job
[2010/09/11 23:13:10 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\Owner\Application Data\AVSDVDPlayer.m3u
[2010/02/04 19:49:03 | 000,176,235 | ---- | C] () -- D:\WINDOWS\System32\Primomonnt.dll
[2009/08/03 12:17:56 | 000,000,101 | ---- | C] () -- D:\WINDOWS\lexstat.ini
[2009/08/03 12:17:29 | 000,077,824 | ---- | C] () -- D:\WINDOWS\System32\LXBKLCNP.DLL
[2009/08/03 12:17:29 | 000,040,960 | ---- | C] () -- D:\WINDOWS\System32\lxbkvs.dll
[2009/08/03 12:17:10 | 000,000,266 | ---- | C] () -- D:\WINDOWS\System32\lxbkcoin.ini
[2009/07/30 18:58:42 | 000,000,314 | ---- | C] () -- D:\WINDOWS\primopdf.ini
[2007/02/20 23:37:50 | 000,006,656 | ---- | C] () -- D:\WINDOWS\System32\CNMVS58.DLL
[2007/01/22 21:29:38 | 000,777,728 | ---- | C] () -- D:\WINDOWS\System32\SSLSVC.DLL
[2007/01/22 21:29:38 | 000,069,632 | ---- | C] () -- D:\WINDOWS\System32\xmltok.dll
[2007/01/22 21:29:38 | 000,040,960 | ---- | C] () -- D:\WINDOWS\System32\cfmsg.dll
[2007/01/22 21:29:38 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\xmlparse.dll
[2007/01/22 21:29:37 | 000,114,688 | ---- | C] () -- D:\WINDOWS\System32\lang_cfml.dll
[2007/01/22 21:29:37 | 000,028,672 | ---- | C] () -- D:\WINDOWS\System32\xml_datagrove.dll
[2006/12/07 11:58:43 | 000,210,944 | ---- | C] () -- D:\WINDOWS\System32\MSVCRT10.DLL
[2006/11/26 00:25:17 | 000,000,112 | ---- | C] () -- D:\WINDOWS\ActiveSkin.INI
[2006/11/17 22:58:08 | 000,000,032 | ---- | C] () -- D:\WINDOWS\CD_Start.INI
[2006/11/08 21:25:42 | 000,001,376 | ---- | C] () -- D:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/10/15 22:15:44 | 000,033,824 | ---- | C] () -- D:\WINDOWS\System32\drivers\oreans32.sys
[2006/10/15 22:15:22 | 000,524,288 | ---- | C] () -- D:\WINDOWS\System32\xvidcore.dll
[2006/10/15 22:15:22 | 000,139,264 | ---- | C] () -- D:\WINDOWS\System32\xvidvfw.dll
[2006/10/15 20:08:35 | 000,068,608 | ---- | C] () -- D:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/10/15 10:24:30 | 000,000,376 | ---- | C] () -- D:\WINDOWS\ODBC.INI
[2006/10/14 10:39:48 | 000,000,000 | ---- | C] () -- D:\WINDOWS\iPlayer.INI
[2006/10/14 10:28:04 | 000,000,698 | ---- | C] () -- D:\WINDOWS\wininit.ini
[2006/10/14 10:06:21 | 000,016,480 | ---- | C] () -- D:\WINDOWS\System32\rixdicon.dll
[2006/10/14 09:52:24 | 000,757,760 | ---- | C] () -- D:\WINDOWS\System32\bcm1xsup.dll
[2006/10/14 09:52:23 | 000,086,016 | ---- | C] () -- D:\WINDOWS\System32\preflib.dll
[2006/10/13 17:14:03 | 000,004,161 | ---- | C] () -- D:\WINDOWS\ODBCINST.INI
[2005/11/28 17:11:07 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\px.ini
[2003/01/07 07:05:08 | 000,002,695 | ---- | C] () -- D:\WINDOWS\System32\OUTLPERF.INI
[2001/11/27 17:59:52 | 000,483,405 | ---- | C] () -- D:\WINDOWS\System32\Taper.dll

========== LOP Check ==========

[2010/05/15 09:55:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Alwil Software
[2007/10/30 22:01:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\GlobalSCAPE
[2010/10/16 18:44:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\HTC
[2006/10/14 19:58:10 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Pinnacle
[2010/10/16 18:44:01 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Teleca
[2009/04/29 18:50:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2006/11/20 23:28:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Cycling '74
[2010/05/04 21:17:09 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\FileZilla
[2010/05/20 12:13:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\ieSpell
[2010/10/27 21:27:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\PrimoPDF
[2010/02/04 19:57:58 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Softland
[2006/10/16 21:18:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Steinberg
[2010/10/17 00:17:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Owner\Application Data\Teleca
[2010/11/04 11:33:00 | 000,000,422 | -H-- | M] () -- D:\WINDOWS\Tasks\User_Feed_Synchronization-{60208E93-38E5-48D3-87A5-A4ABA6A99286}.job

========== Purity Check ==========



< End of report >
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Nice .. What problems do you have now ? Anything unusual ?
  • 0

Advertisements


#11
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Seems to be working ok, though I'm a little worried about the Avast full scan I did last night showing thousands of infected files. I posted the log above (post at5:40 pm)... is there anything else I can do to make sure my system is clean?
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Those were all within Adobe files - so you may need to re-instal the programmes anew

I do not feel there is anything else but we can check it out

Download ComboFix from one of these locations:


Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


Posted Image



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • 0

#13
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Thanks.... I'm about to download Combofix. I had just finished another run of DrWeb.

Again it said "Hosts file modified"... Is that unusual?

I've attached the log file, in case it helps, it's much bigger this time....

Attached Files


  • 0

#14
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Uh-oh....

Just ran ComboFix. It seemed to be running OK. Before restarting computer, I noticed it was deleting a lot of files. After restart, A blue screen came up saying:
"A problem has been detected and Windows has ben shut down to prevent damage to your computer. If this is the first time you've seen this Stop error screen, restart your computer. If this screenappears again, follow these steps:

Check to be sure you have adequate disk space. If a driver is identified in the Stop message, disable the driver or check with the manufacturer for driver updates. Try changing video adapters.

Check with your hardware vendor for any BIOS updates. Disable BIOS memory options such as caching or shadowing. If you need to use Safe Mode to remove or disable components, restart your computer, press F8 to select Advanced Startup Options, and then select Safe Mode.

Technical information
*** STOP: 0x0000008E (0x80000004, 0x805BBC53, 0xA81C98F4, 0x00000000)

Beginning dump of physical memory
Physical memory dump complete.
Contact your systm administrator or technical support group for further assistance"

That sounds ominous. I am about to restart the computer but just wanted to write all that down on this second computer before I do...
  • 0

#15
figurer

figurer

    Member

  • Topic Starter
  • Member
  • PipPip
  • 23 posts
Well, I powered off and restarted, and the computer seems to be working. The only ComboFix.txt file I could find was in the combofix directory and I've attached it here. It is a very tiny file....

Anything else I should do to make sure my computer is clean?

Thanks so much for your help.

Attached Files


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP