Jump to content


[RESOLVED] friends pc is sick


71 replies to this topic

#1 Man'n'Black-4xp

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 14 February 2011 - 09:15 PM

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5764

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

2/14/2011 3:09:55 PM
mbam-log-2011-02-14 (15-09-46).txt

Scan type: Quick scan
Objects scanned: 160328
Time elapsed: 9 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\TimeSink, Inc. (AdWare.TimeSink) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\TimeSink, Inc. (AdWare.TimeSink) -> No action taken.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
c:\program files\TimeSink (AdWare.Cydoor) -> No action taken.
c:\program files\TimeSink\adgateway (AdWare.Cydoor) -> No action taken.

Files Infected:
c:\program files\TimeSink\adgateway\TSADBOT.EXE (AdWare.Cydoor) -> No action taken.
Posted Image

#2 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 14 February 2011 - 09:32 PM

GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-14 15:29:44
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 SAMSUNG_SP0802N rev.TK200-04
Running: tnm7pync.exe; Driver: C:\DOCUME~1\WABETH~1\LOCALS~1\Temp\pgldqpoc.sys


---- Devices - GMER 1.0.15 ----

Device Fastfat.sys (Fast FAT File System Driver/Microsoft Corporation)
Device \Driver\Tcpip \Device\Ip avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Tcp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\Udp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\RawIp avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)
Device \Driver\Tcpip \Device\IPMULTICAST avgtdi.sys (AVG Network connection watcher/GRISOFT, s.r.o.)

---- EOF - GMER 1.0.15 ----
Posted Image

#3 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 14 February 2011 - 09:36 PM

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows XP Professional
Windows Information: Service Pack 2 (build 2600)
Logical Drives Mask: 0x0000001d

Kernel Drivers (total 123):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806CE000 \WINDOWS\system32\hal.dll
0xF9E67000 \WINDOWS\system32\KDCOM.DLL
0xF9D77000 \WINDOWS\system32\BOOTVID.dll
0xF9838000 ACPI.sys
0xF9E69000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF9827000 pci.sys
0xF9967000 isapnp.sys
0xF9F2F000 pciide.sys
0xF9BE7000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF9977000 MountMgr.sys
0xF9808000 ftdisk.sys
0xF9E6B000 dmload.sys
0xF97E2000 dmio.sys
0xF9BEF000 PartMgr.sys
0xF9987000 VolSnap.sys
0xF97CA000 atapi.sys
0xF9997000 disk.sys
0xF99A7000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS
0xF97AA000 fltmgr.sys
0xF9798000 sr.sys
0xF9775000 Fastfat.sys
0xF975E000 KSecDD.sys
0xF9731000 NDIS.sys
0xF9BF7000 nv_agp.sys
0xF9D7B000 nvp2p.sys
0xF9716000 Mup.sys
0xF99D7000 \SystemRoot\System32\DRIVERS\processr.sys
0xF9C27000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF96AB000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF9C2F000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF9DF7000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
0xF99E7000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
0xF967C000 \SystemRoot\system32\DRIVERS\NVSNPU.SYS
0xF9447000 \SystemRoot\system32\drivers\ALCXWDM.SYS
0xF9423000 \SystemRoot\system32\drivers\portcls.sys
0xF99F7000 \SystemRoot\system32\drivers\drmk.sys
0xF9400000 \SystemRoot\system32\drivers\ks.sys
0xF9A07000 \SystemRoot\System32\DRIVERS\imapi.sys
0xF9A17000 \SystemRoot\System32\DRIVERS\cdrom.sys
0xF9A27000 \SystemRoot\System32\DRIVERS\redbook.sys
0xF9C37000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0xF9230000 \SystemRoot\System32\DRIVERS\nv4_mini.sys
0xF921C000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS
0xF9109000 \SystemRoot\system32\DRIVERS\AGRSM.sys
0xF9E6D000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF9C3F000 \SystemRoot\System32\Drivers\Modem.SYS
0xF9C47000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF9A37000 \SystemRoot\system32\DRIVERS\serial.sys
0xF9E07000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF90F5000 \SystemRoot\System32\DRIVERS\parport.sys
0xF9A47000 \SystemRoot\System32\DRIVERS\i8042prt.sys
0xF9C4F000 \SystemRoot\System32\DRIVERS\mouclass.sys
0xF9C57000 \SystemRoot\System32\DRIVERS\kbdclass.sys
0xF9FF5000 \SystemRoot\System32\DRIVERS\audstub.sys
0xF9A57000 \SystemRoot\System32\DRIVERS\rasl2tp.sys
0xF9E0B000 \SystemRoot\System32\DRIVERS\ndistapi.sys
0xF90DE000 \SystemRoot\System32\DRIVERS\ndiswan.sys
0xF9A67000 \SystemRoot\System32\DRIVERS\raspppoe.sys
0xF9A77000 \SystemRoot\System32\DRIVERS\raspptp.sys
0xF9C5F000 \SystemRoot\System32\DRIVERS\TDI.SYS
0xF9C67000 \SystemRoot\System32\DRIVERS\ptilink.sys
0xF9C6F000 \SystemRoot\System32\DRIVERS\raspti.sys
0xF9C77000 \SystemRoot\system32\DRIVERS\wanatw4.sys
0xF9085000 \SystemRoot\System32\DRIVERS\rdpdr.sys
0xF9A87000 \SystemRoot\System32\DRIVERS\termdd.sys
0xF9E6F000 \SystemRoot\System32\DRIVERS\swenum.sys
0xF9051000 \SystemRoot\System32\DRIVERS\update.sys
0xF9E23000 \SystemRoot\System32\DRIVERS\mssmbios.sys
0xF9A97000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF9AA7000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF9AB7000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
0xF9CAF000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF9E77000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF9F70000 \SystemRoot\System32\Drivers\Null.SYS
0xF9E79000 \SystemRoot\System32\Drivers\Beep.SYS
0xF9F71000 \SystemRoot\System32\Drivers\avgclean.sys
0xF9CBF000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0xF9CC7000 \SystemRoot\System32\drivers\vga.sys
0xF9E7B000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF9E7D000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF9CCF000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF9CD7000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF9E5B000 \SystemRoot\System32\DRIVERS\rasacd.sys
0xF7E56000 \SystemRoot\System32\DRIVERS\ipsec.sys
0xF9B07000 \SystemRoot\System32\DRIVERS\msgpc.sys
0xF7DFE000 \SystemRoot\System32\DRIVERS\tcpip.sys
0xF7DD6000 \SystemRoot\System32\DRIVERS\netbt.sys
0xF7DB4000 \SystemRoot\System32\drivers\afd.sys
0xF9B17000 \SystemRoot\System32\Drivers\Fips.SYS
0xF7D93000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF9B27000 \SystemRoot\System32\DRIVERS\wanarp.sys
0xF7D35000 \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
0xF96EE000 \??\C:\WINDOWS\system32\drivers\BIOS.sys
0xF7C44000 \SystemRoot\System32\Drivers\avg7core.sys
0xF9E7F000 \SystemRoot\System32\Drivers\avg7rsw.sys
0xF9CDF000 \SystemRoot\System32\Drivers\avg7rsxp.sys
0xF9CE7000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0xF90D2000 \SystemRoot\system32\DRIVERS\usbscan.sys
0xF9CEF000 \SystemRoot\system32\DRIVERS\usbprint.sys
0xF9CF7000 \SystemRoot\system32\DRIVERS\HPZius12.sys
0xF9B37000 \SystemRoot\system32\DRIVERS\HPZid412.sys
0xF90C6000 \SystemRoot\system32\DRIVERS\HPZipr12.sys
0xF9B47000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xF7B14000 \SystemRoot\System32\Drivers\dump_atapi.sys
0xF9E85000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF8FA1000 \SystemRoot\System32\drivers\Dxapi.sys
0xF9CFF000 \SystemRoot\System32\watchdog.sys
0xBF000000 \SystemRoot\System32\drivers\dxg.sys
0xF9FB4000 \SystemRoot\System32\drivers\dxgthk.sys
0xBF012000 \SystemRoot\System32\nv4_disp.dll
0xF6B08000 \SystemRoot\System32\DRIVERS\ndisuio.sys
0xF60A0000 \SystemRoot\System32\DRIVERS\mrxdav.sys
0xF9EA3000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xF9EA7000 \SystemRoot\System32\Drivers\avgtdi.sys
0xF5D51000 \SystemRoot\System32\DRIVERS\srv.sys
0xF5ABC000 \SystemRoot\system32\drivers\wdmaud.sys
0xF5B61000 \SystemRoot\system32\drivers\sysaudio.sys
0xF56E3000 \SystemRoot\System32\Drivers\HTTP.sys
0xF4D9E000 \SystemRoot\system32\drivers\kmixer.sys
0xF4D86000 \??\C:\DOCUME~1\WABETH~1\LOCALS~1\Temp\pgldqpoc.sys
0x7C900000 \WINDOWS\System32\ntdll.dll

Processes (total 36):
0 System Idle Process
4 System
376 C:\WINDOWS\System32\SMSS.EXE
424 CSRSS.EXE
448 C:\WINDOWS\System32\WINLOGON.EXE
492 C:\WINDOWS\System32\SERVICES.EXE
504 C:\WINDOWS\System32\LSASS.EXE
648 C:\WINDOWS\System32\SVCHOST.EXE
724 SVCHOST.EXE
796 C:\WINDOWS\System32\SVCHOST.EXE
872 SVCHOST.EXE
988 SVCHOST.EXE
1116 C:\WINDOWS\System32\SPOOLSV.EXE
1180 SVCHOST.EXE
1208 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
1236 C:\Program Files\Grisoft\AVG Free\AVGAMSVR.EXE
1248 C:\Program Files\Grisoft\AVG Free\AVGUPSVC.EXE
1284 C:\Program Files\Grisoft\AVG Free\AVGEMC.EXE
1308 C:\Program Files\Bonjour\mDNSResponder.exe
1348 C:\WINDOWS\System32\SVCHOST.EXE
1364 C:\WINDOWS\System32\SVCHOST.EXE
1400 C:\WINDOWS\System32\SVCHOST.EXE
1484 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
1592 C:\WINDOWS\System32\SVCHOST.EXE
1652 C:\WINDOWS\wanmpsvc.exe
308 ALG.EXE
2684 C:\Program Files\iPod\bin\iPodService.exe
1904 C:\WINDOWS\System32\wscntfy.exe
1752 C:\WINDOWS\Explorer.EXE
2176 C:\Program Files\iTunes\iTunesHelper.exe
2032 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
588 C:\WINDOWS\System32\wuauclt.exe
2664 C:\Program Files\HP\Digital Imaging\BIN\hpqtra08.exe
3760 C:\Program Files\HP\Digital Imaging\BIN\hpqste08.exe
412 C:\Program Files\Mozilla Firefox\firefox.exe
1412 C:\Documents and Settings\wabethoffman\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (FAT32)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000f`e8246200 (FAT32)

PhysicalDrive0 Model Number: SAMSUNGSP0802N, Rev: TK200-04

Size Device Name MBR Status
--------------------------------------------
74 GB \\.\PhysicalDrive0 Unknown MBR code
SHA1: 707619F08ECFB6678AAA617DB24D2CEE2D2EE1DB


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice: Enter the physical disk number to dump (0-99, -1 to exit):
Posted Image

#4 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 14 February 2011 - 09:37 PM

DDS (Ver_10-12-12.02) - FAT32x86
Run by wabethoffman at 15:35:24.06 on Mon 02/14/2011
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.22 [GMT -6:00]

AV: AVG 7.5.526 *Enabled/Outdated* {41564737-3200-1071-989B-0000E87B4FB1}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
SVCHOST.EXE
C:\WINDOWS\System32\svchost.exe -k netsvcs
SVCHOST.EXE
SVCHOST.EXE
C:\WINDOWS\system32\spoolsv.exe
SVCHOST.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\wabethoffman\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.cnn.com/
uDefault_Page_URL = hxxp://desktop.presario.net/scripts/redirectors/presario/deskredir.dll?c=3c00&s=consumer&LC=0409
uWindow Title = Microsoft Internet Explorer
mSearch Bar = hxxp://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c00&s=searchbar&LC=0409
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = *.local
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: CPrintEnhancer Object: {ae84a6aa-a333-4b92-b276-c11e2212e4fe} - c:\program files\hp\smart web printing\SmartWebPrinting.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\SHDOCVW.DLL
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [MoneyAgent] "c:\program files\microsoft money\system\Money Express.exe"
uRun: [MsnMsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [MoneyAgent] "c:\program files\microsoft money\system\Money Express.exe"
dRun: [AVG7_Run] c:\progra~1\grisoft\avgfre~1\avgw.exe /RUNONCE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
IE: Open in new background tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/229?d97ef0dfefda44518dfbfdf0dbb54486
IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/230?d97ef0dfefda44518dfbfdf0dbb54486
IE: {06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {06FE5D04-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\SHDOCVW.DLL
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} - hxxp://www.addictivetechnologies.net/DM0/cab/pdfzzy.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {32564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8ax.cab
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - hxxp://aolcc.aol.com/computercheckup/qdiagcc.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178125145671
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1178125134187
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R868/V31Controls/x86/mil/en/actsetup.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: ComPlusSetup - c:\windows\system32\catsrvut.dll
mASetup: {9EF0045A-CDD9-438e-95E6-02B9AFEC8E11} - c:\windows\system32\updcrl.exe -e -u c:\windows\system\verisignpub1.crl

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\wabeth~1\applic~1\mozilla\firefox\profiles\2st0tgg9.default\
FF - prefs.js: browser.startup.homepage - cnn.com
FF - plugin: c:\program files\netscape\communicator\program\plugins\np32dsw.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npaudio.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npavi32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPBeatSP.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npdrmv2.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npdsplay.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nphppi.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPMAsst2_3.02.01.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\NPMetaStream3.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npnul32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppdf32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\nppl3260.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npstm32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npswf32.dll
FF - plugin: c:\program files\netscape\communicator\program\plugins\npwmsdrm.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 nvp2p;NVIDIA PCI to PCI Bridge Filter;c:\windows\system32\drivers\nvp2p.sys [2007-4-30 8576]
R1 Avg7Core;AVG7 Kernel;c:\windows\system32\drivers\avg7core.sys [2007-4-30 821856]
R1 Avg7RsW;AVG7 Wrap Driver;c:\windows\system32\drivers\avg7rsw.sys [2007-4-30 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP;c:\windows\system32\drivers\avg7rsxp.sys [2007-4-30 27776]
R1 AvgClean;AVG7 Clean Driver;c:\windows\system32\drivers\avgclean.sys [2007-4-30 10760]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2007-4-30 13696]
R2 Avg7Alrt;AVG7 Alert Manager Server;c:\progra~1\grisoft\avgfre~1\avgamsvr.exe [2007-5-2 418816]
R2 Avg7UpdSvc;AVG7 Update Service;c:\progra~1\grisoft\avgfre~1\avgupsvc.exe [2007-5-2 49664]
R2 AVGEMS;AVG E-mail Scanner;c:\progra~1\grisoft\avgfre~1\avgemc.exe [2007-5-2 406528]
R2 AvgTdi;AVG Network Redirector;c:\windows\system32\drivers\avgtdi.sys [2007-4-30 4960]

=============== Created Last 30 ================

2011-02-14 20:51:43 -------- d-----w- c:\docume~1\wabeth~1\applic~1\Malwarebytes
2011-02-14 20:51:43 -------- d-----w- c:\docume~1\wabeth~1\applic~1\Malwarebytes
2011-02-14 20:51:29 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-14 20:51:29 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-02-14 20:51:25 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-14 20:51:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-14 20:14:09 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-02-14 20:14:09 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-14 20:11:22 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-02-11 19:18:31 -------- d-----w- c:\windows\system32\scripting
2011-02-11 19:18:30 -------- d-----w- c:\windows\l2schemas
2011-02-11 19:13:32 -------- d-----w- c:\windows\network diagnostic
2011-01-31 22:05:48 -------- d-----w- c:\windows\system32\drivers\nss\0300010.008
2011-01-31 22:05:48 -------- d-----w- c:\windows\system32\drivers\NSS
2011-01-30 20:24:19 -------- d-----w- c:\docume~1\wabeth~1\applic~1\Apple
2011-01-30 20:24:19 -------- d-----w- c:\docume~1\wabeth~1\applic~1\Apple
2011-01-27 00:57:50 -------- d-----w- c:\docume~1\alluse~1\applic~1\MSNDynFiles

==================== Find3M ====================

2010-12-20 15:30:30 369664 ----a-w- c:\windows\system32\html.iec

============= FINISH: 15:36:20.37 ===============
Posted Image

#5 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 14 February 2011 - 09:38 PM

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 5/1/2007 3:20:04 PM
System Uptime: 2/14/2011 2:19:18 PM (1 hours ago)

Motherboard: | | nForce
Processor: AMD Sempron™ Processor 3000+ | Socket 940 | 1808/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (FAT32) - 64 GiB total, 45.621 GiB free.
D: is FIXED (FAT32) - 11 GiB total, 9.809 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP189: 2/11/2011 12:58:33 PM - Software Distribution Service 3.0
RP190: 2/12/2011 2:05:44 PM - Software Distribution Service 3.0
RP191: 2/14/2011 2:09:29 PM - Restore Operation

==== Installed Programs ======================

1.1.81
123 Free Solitaire
32 Bit HP CIO Components Installer
Actiontec Gateway
Adobe Acrobat 4.0
Adobe Flash Player 10 Plugin
Adobe Flash Player ActiveX
Adobe Shockwave Player
Adventures with Chickens
Agere Systems PCI Soft Modem
AIO_Scan
Al Unser Jr Arcade Racing Ver 2.004
All American Gin Rummy
Amazon Trail 3rd Edition
America Online (Choose which version to remove)
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Setup
Apple Application Support
Apple Mobile Device Support
Apple Software Update
AppleWorks 5
ATI Display Driver
AVG Free Edition
Balloon Pop Special Edition
Battleboard
Blast Thru Special Edition
Bonjour
Bonkerz
BufferChm
Carbon Copy 32
Card Games
Compaq Digital Dashboard LED
Compaq Hardware Discovery
Compaq IE5 Custom US v1.0.0.4
Compaq IJ300 Electronic Registration
Compaq Knowledge Center
Compaq Wizard Host Online
Compton's Interactive Encyclopedia 1998
Copy
CustomerResearchQFolder
Deer Hunt Challenge SE
Destinations
DeviceManagementQFolder
DIGOpt
DJ_AIO_ProductContext
DJ_AIO_Software
DJ_AIO_Software_min
Drone
EA Network Play System
Easy Access Button Support
eGames Collector's Edition
Encarta Online
ESPN Digital Games XGames Pro Boarder
eSupportQFolder
Event Planner
F4100
F4100_Help
Family Game Pack® Royale
Family Tree Maker
Form Fill (Windows Live Toolbar)
Fran's Frog Hop Special Edition
Galactic Patrol Lite Edition
Great Pyramid
Hallmark Card Studio 2 Standard
High Roller
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Customer Participation Program 8.0
HP Deskjet All-In-One Software 8.0
HP Imaging Device Functions 8.0
HP Photosmart Essential
HP PrecisionScan LTX
HP Share-to-Web
HP Smart Web Printing 1.0
HP Solution Center 8.0
HP Update
HPProductAssistant
HPSSupply
HSP56 MicroModem Drivers
Hyperball
Intergalactic Exterminator Special Edition
iTunes
Java™ 6 Update 3
Junk Mail filter update
Juxto
Kodak EasyShare software
Learn2 Player (Uninstall Only)
Lexicon Special Edition
Madden NFL ™ 99
Malwarebytes' Anti-Malware
MarketResearch
Memory Match
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft Age of Empires Gold
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Money 2000 Standard Edition
Microsoft Office 2000 SR-1 Standard
Microsoft Search Enhancement Pack
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works 2000
Mozilla Firefox (3.0.19)
MSN
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NASCAR 2000
NCAA Football 98
Need For Speed III
Netscape Communicator 4.7
Norton Security Scan
NVIDIA Drivers
OneCare Advisor (Windows Live Toolbar)
Penny's Arcade
Popup Blocker (Windows Live Toolbar)
QuickConnect
QuickTime
Qwest eChat Support Tools
RealPlayer Basic
Realtek AC'97 Audio
Rhapsody Player Engine
RoadRash
Scan
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB941693)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944338)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB947864)
Security Update for Windows XP (KB948590)
Security Update for Windows XP (KB948881)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972260)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB976325)
Security Update for Windows XP (KB977165-v2)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
Segoe UI
Service Connection
SideWinder Precision 2
Solitaire 25
Solitaire 25 Volume 2
SolutionCenter
SoundMAXWDM
Space Solitaire
Spooky Castle
Status
Strata Poker
Symantec AntiVirus Client
Tabbed Browsing (Windows Live Toolbar)
Toolbox
Total Recall
TrayApp
TrueSwitch Wizard MSN
Tunnel Blaster Special Edition
Turkey Hunt Challenge
UnloadSupport
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
Update for Windows XP (KB978207)
Update for Windows XP (KB980182)
Viewpoint Media Player
WebFldrs XP
WebReg
Who Wants To Be A Millionaire 2nd Edition
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Favorites for Windows Live Toolbar
Windows Live Mail
Windows Live Messenger
Windows Live Outlook Toolbar (Windows Live Toolbar)
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar Extension (Windows Live Toolbar)
Windows Live Toolbar Feed Detector (Windows Live Toolbar)
Windows Live Upload Tool
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Uninstall
WMP7 Customizations
Word Connect Special Edition
Word Skramble
Zulu Assault

==== Event Viewer Messages From Past Week ========

2/14/2011 2:24:51 PM, error: BITS [16391] - The BITS job list is not in a recognized format. It may have been created by a different version of BITS. The job list has been cleared.
2/14/2011 2:20:01 PM, error: Service Control Manager [7023] - The IPSEC Services service terminated with the following error: The authentication service is unknown.
2/14/2011 2:20:01 PM, error: Service Control Manager [7000] - The ASCTRM service failed to start due to the following error: The system cannot find the file specified.
2/14/2011 2:09:30 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/14/2011 2:08:59 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avg7Core Avg7RsW Avg7RsXP BIOS eeCtrl Fips Processor
2/14/2011 2:08:25 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
2/14/2011 2:04:43 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service Avg7Alrt with arguments "-Service" in order to run the server: {3486DF65-1D90-406A-A072-30629910F113}

==== End Of File ===========================
Posted Image

#6 Broni Re: [RESOLVED] friends pc is sick

    Malware Annihilator

  • 24,879 posts
  • Joined: October 04, 2004
  • 1,859 topics
  • Age: 57
  • Skin: IPBoard wide
  • Local time: 05:23 AM
  • Zodiac:Virgo
  • Gender:Male
  • Location:Daly City, CA
  • OS:Windows Vista
  • Country:
Offline
  • Time Online: 57d 9h 13m 9s

Posted 15 February 2011 - 12:27 AM

You're really not saying what are computer's problems.

Your MBAM log says "No action taken" after each line.
Re-run ti, fix ALL issues and post new log.

AVG 7.5 is a very outdated AV program.
I suggest, you uninstall it and install one of these:
- Avast! free antivirus: http://www.avast.com...avast-home.html
- Avira free antivirus: http://www.free-av.c..._antivirus.html

Now...

Download Bootkit Remover to your Desktop.

  • You then need to extract the remover.exe file from the RAR using a program capable of extracing RAR compressed files. If you don't have an extraction program, you can use 7-Zip: http://www.7-zip.org/
  • After extracing remover.exe to your Desktop, double-click on remover.exe to run the program (Vista/7 users,right click on remover.exe and click Run As Administrator).
  • It will show a Black screen with some data on it.
  • Right click on the screen and click Select All.
  • Press CTRL+C
  • Open a Notepad and press CTRL+V
  • Post the output back here.

=======================================================================================================

Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Please, never rename Combofix unless instructed.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG users: ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first.
Use AppRemover to uninstall it: http://www.appremover.com/
We can reinstall it when we're done with CF.
**Note 3: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion", restart computer to fix the issue.



Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try one of the following:

1. Run Combofix from Safe Mode.

2. Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.

Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

Rkill.com
Rkill.scr
Rkill.exe

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!

#7 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 12:34 AM

Thanks for the response Mr B. It might be a day or two, due to being in a different town and all..
I will try to rerun mwb.
Posted Image

#8 Broni Re: [RESOLVED] friends pc is sick

    Malware Annihilator

  • 24,879 posts
  • Joined: October 04, 2004
  • 1,859 topics
  • Age: 57
  • Skin: IPBoard wide
  • Local time: 05:23 AM
  • Zodiac:Virgo
  • Gender:Male
  • Location:Daly City, CA
  • OS:Windows Vista
  • Country:
Offline
  • Time Online: 57d 9h 13m 9s

Posted 15 February 2011 - 12:59 AM

No problem :)

#9 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 05:49 AM

I arranged to work on it tomorrow, and maybe bring it back to my lair if need be.
Thanks for your patintenc.....
Posted Image

#10 Broni Re: [RESOLVED] friends pc is sick

    Malware Annihilator

  • 24,879 posts
  • Joined: October 04, 2004
  • 1,859 topics
  • Age: 57
  • Skin: IPBoard wide
  • Local time: 05:23 AM
  • Zodiac:Virgo
  • Gender:Male
  • Location:Daly City, CA
  • OS:Windows Vista
  • Country:
Offline
  • Time Online: 57d 9h 13m 9s

Posted 15 February 2011 - 06:07 AM

Sure thing :)

#11 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 06:12 PM

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5764

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

2/14/2011 7:13:38 PM
mbam-log-2011-02-14 (19-13-38).txt

Scan type: Quick scan
Objects scanned: 160344
Time elapsed: 9 minute(s), 25 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\TimeSink, Inc. (AdWare.TimeSink) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\TimeSink, Inc. (AdWare.TimeSink) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
c:\program files\TimeSink (AdWare.Cydoor) -> Quarantined and deleted successfully.
c:\program files\TimeSink\adgateway (AdWare.Cydoor) -> Quarantined and deleted successfully.

Files Infected:
c:\program files\TimeSink\adgateway\TSADBOT.EXE (AdWare.Cydoor) -> Quarantined and deleted successfully.
Posted Image

#12 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 06:16 PM

Quote

You're really not saying what are computer's problems.
Slower than molasses up hill in januarary, bad updates caused me to restore to earlier time{due to boot failure, eractic mouse.etc
PC is set up as fat 32 not ntfs if that matters
Posted Image

#13 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 06:33 PM

RAR will not work... skipping for now
Posted Image

#14 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 07:20 PM

ComboFix 11-02-15.01 - wabethoffman 02/15/2011 13:03:22.1.1 - FAT32x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.255.127 [GMT -6:00]
Running from: c:\documents and settings\wabethoffman\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\wabethoffman\Recent\www.mayyoubeblessedmovie.com.url
C:\Logo.sys
c:\windows\inf\internet
c:\windows\MailSwitch.ocx
c:\windows\start.exe
c:\windows\TSAd.dll
c:\windows\VcpDLL.dll
c:\windows\Web\default.htt

.
((((((((((((((((((((((((( Files Created from 2011-01-15 to 2011-02-15 )))))))))))))))))))))))))))))))
.

2011-02-15 18:26 . 2011-02-15 18:26 -------- d-----w- c:\program files\7-Zip
2011-02-14 20:51 . 2011-02-14 20:51 -------- d-----w- c:\documents and settings\wabethoffman\Application Data\Malwarebytes
2011-02-14 20:51 . 2011-02-14 20:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-14 20:51 . 2010-12-21 00:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-14 20:51 . 2010-12-21 00:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-02-14 20:51 . 2011-02-14 20:51 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-02-14 20:14 . 2011-02-14 20:14 -------- d-----w- c:\windows\system32\wbem\Repository
2011-02-14 20:11 . 2011-02-14 20:11 -------- d-----w- c:\windows\system32\CatRoot_bak
2011-02-14 19:16 . 2011-02-14 19:16 -------- d-s---w- c:\documents and settings\Administrator
2011-02-11 19:18 . 2011-02-11 19:18 -------- d-----w- c:\windows\system32\scripting
2011-02-11 19:18 . 2011-02-11 19:18 -------- d-----w- c:\windows\l2schemas
2011-01-30 20:24 . 2011-01-30 20:24 -------- d-----w- c:\documents and settings\wabethoffman\Application Data\Apple
2011-01-27 00:57 . 2011-01-27 00:57 -------- d-----w- c:\documents and settings\All Users\Application Data\MSNDynFiles

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 15:30 . 2004-08-04 18:00 369664 ----a-w- c:\windows\system32\html.iec
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [1999-08-04 122940]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-11-11 421160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MoneyAgent"="c:\program files\Microsoft Money\System\Money Express.exe" [1999-08-04 122940]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2003-9-17 65588]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ComPlusSetup]
2005-07-26 05:39 625152 ----a-w- c:\windows\SYSTEM32\CATSRVUT.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"Hidserv"=Hidserv.exe run
"CPQInet"=c:\compaq\CPQInet\CpqInet.exe
"Digital Dashboard"=c:\program files\Compaq\Digital Dashboard\DevGulp.exe
"Service Connection"=c:\cpqs\bwtools\sccenter.exe
"CountrySelection"=pctptt.exe
"PCTVOICE"=pctvoice.exe
"LexStart"=Lexstart.exe
"LexmarkPrinTray"=PrinTray.exe
"MotiveMonitor"=c:\program files\Motive\motmon.exe
"SideWinderTrayV4"=c:\progra~1\MICROS~4\GAMECO~1\COMMON\SWTRAYV4.EXE
"TimeSink Ad Client"="c:\program files\TimeSink\AdGateway\TSADBOT.EXE"
"<NO NAME>"=
"Dcfssvc"=c:\windows\System32\Drivers\dcfssvc.exe
"vptray"=c:\progra~1\SYMANT~1\SYMANT~1\vptray.exe
"SoundMan"=SOUNDMAN.EXE
"OWCCardbusTray"=ocbtray.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\System32\\dpvsetup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 nvp2p;NVIDIA PCI to PCI Bridge Filter;c:\windows\SYSTEM32\DRIVERS\nvp2p.sys [4/30/2007 3:16 PM 8576]
R1 BIOS;BIOS;c:\windows\SYSTEM32\DRIVERS\BIOS.sys [4/30/2007 3:16 PM 13696]

--- Other Services/Drivers In Memory ---

*Deregistered* - Avg7Core
*Deregistered* - Avg7RsXP
*Deregistered* - AvgClean
*Deregistered* - AvgTdi

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
2001-03-23 22:17 7168 ----a-r- c:\windows\SYSTEM32\updcrl.exe
.
Contents of the 'Scheduled Tasks' folder

2001-12-09 c:\windows\Tasks\Synchronize Time.job
- c:\program files\Compaq\Digital Dashboard\SyncClk.exe [2000-08-03 03:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.cnn.com/
mSearch Bar = hxxp://search.presario.net/scripts/redirectors/presario/srchredir.dll?c=3c00&s=searchbar&LC=0409
mWindow Title = Microsoft Internet Explorer
uInternet Settings,ProxyOverride = *.local
IE: Add to Windows &Live Favorites - http://favorites.liv...m/quickadd.aspx
IE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?d97ef0dfefda44518dfbfdf0dbb54486
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?d97ef0dfefda44518dfbfdf0dbb54486
IE: {{06FE5D02-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {{06FE5D03-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {{06FE5D04-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
IE: {{06FE5D05-8F11-11d2-804F-00105A133818} - http://search.presar...&c=3c00&LC=0409
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\wabethoffman\Application Data\Mozilla\Firefox\Profiles\2st0tgg9.default\
FF - prefs.js: browser.startup.homepage - cnn.com
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-15 13:10
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2011-02-15 13:12:13
ComboFix-quarantined-files.txt 2011-02-15 19:12

Pre-Run: 49,000,677,376 bytes free
Post-Run: 49,632,870,400 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin

- - End Of File - - 58F032525FDDF26C725264F25A5528EB
Posted Image

#15 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 15 February 2011 - 07:24 PM

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 02/15/2011 at 13:22:53.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:



Rkill completed on 02/15/2011 at 13:23:00.


second try


This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 02/15/2011 at 13:26:44.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:

C:\WINDOWS\System32\rundll32.exe


Rkill completed on 02/15/2011 at 13:26:48.
Posted Image

#16 Broni Re: [RESOLVED] friends pc is sick

    Malware Annihilator

  • 24,879 posts
  • Joined: October 04, 2004
  • 1,859 topics
  • Age: 57
  • Skin: IPBoard wide
  • Local time: 05:23 AM
  • Zodiac:Virgo
  • Gender:Male
  • Location:Daly City, CA
  • OS:Windows Vista
  • Country:
Offline
  • Time Online: 57d 9h 13m 9s

Posted 16 February 2011 - 02:49 AM

Quote

RAR will not work... skipping for now
I need to know what exactly happens.

Combofix looks fine.

If you uninstalled AVG already, I need you to install Avast, or Avira, update it and run full scan.
Report on any findings.

When done....

Download OTL to your Desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in:


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /i " " /c
dir /b "%systemroot%\*.exe" | find /i " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
/md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.


#17 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 16 February 2011 - 04:21 AM

Quote

I need to know what exactly happens.
Abolutly nothing, Win 7 is not compatable with XP, I have tried to use it on several pc on several occanions to no avail.


Quote

If you uninstalled AVG already, I need you to install Avast, or Avira, update it and run full scan.
Report on any findings.
Avira is installed and updated when I go back I will post its log.
Posted Image

#18 Broni Re: [RESOLVED] friends pc is sick

    Malware Annihilator

  • 24,879 posts
  • Joined: October 04, 2004
  • 1,859 topics
  • Age: 57
  • Skin: IPBoard wide
  • Local time: 05:23 AM
  • Zodiac:Virgo
  • Gender:Male
  • Location:Daly City, CA
  • OS:Windows Vista
  • Country:
Offline
  • Time Online: 57d 9h 13m 9s

Posted 16 February 2011 - 04:24 AM

Quote

Abolutly nothing, Win 7 is not compatable with XP, I have tried to use it on several pc on several occanions to no avail.
I don't understand.
You tried what?

#19 Man'n'Black-4xp Re: [RESOLVED] friends pc is sick

    The XP In The Ointment

  • 1,848 posts
  • Joined: November 28, 2010
  • 308 topics
  • Skin: Paradox
  • Local time: 07:23 AM
  • Zodiac:Aquarius
  • Gender:Male
  • Location:Midwest
  • OS:Windows XP
  • Country:
Offline
  • Time Online: 8d 23h 38m 54s

Posted 16 February 2011 - 04:28 AM

Quote

Abolutly nothing, Win 7 is not compatable with XP, I have tried to use it on several pc on several occanions to no avail.
Sorry ,I think ten times faster than I type. I meant Win ZIP 7
Posted Image

#20 Broni Re: [RESOLVED] friends pc is sick

    Malware Annihilator

  • 24,879 posts
  • Joined: October 04, 2004
  • 1,859 topics
  • Age: 57
  • Skin: IPBoard wide
  • Local time: 05:23 AM
  • Zodiac:Virgo
  • Gender:Male
  • Location:Daly City, CA
  • OS:Windows Vista
  • Country:
Offline
  • Time Online: 57d 9h 13m 9s

Posted 16 February 2011 - 04:35 AM

I just emailed you straight files (gmail address).





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users


This topic has been visited by 0 user(s)