I'm sorry but i am still getting the same problems with the downloaded programs.
I haved them to the following places:- OTM C:\Documents and Settings\Diana\Desktop
size on disc 508KB
error signature AppName: otm.exe AppVer: 3.1.17.2 ModName: kernel32.dll
ModVer: 5.1.2600.5781 Offset: 00012afb
and
HostsXpert C:\Documents and Settings\Diana\Desktop
size on disc 364KB
not getting make host writable in the corner and when run restore files I am getting
error can't create file c:\windows\system32\drivers\etc\hosts
i have not yet tried to download combofix because the others haven't worked and i'm not sure if they need to be done in a certain order.
Thanks for your patience.If you can point out where i'm going wrong i would be grateful
Thank you I have run Compofix and the log is below:-
ComboFix 11-01-14.01 - Diana 14/01/2011 17:07:33.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2047.1659 [GMT 0:00]
Running from: c:\documents and settings\Diana\Desktop\ComboFix.exe
FW: AVG Firewall *Disabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\8e8669\71.mof
c:\documents and settings\All Users\Application Data\8e8669\BackUp\HP Digital Imaging Monitor.lnk
c:\documents and settings\All Users\Application Data\8e8669\BackUp\HP Image Zone Fast Start.lnk
c:\documents and settings\All Users\Application Data\8e8669\BackUp\Symantec Fax Starter Edition Port.lnk
c:\documents and settings\All Users\Application Data\8e8669\BackUp\VIA RAID TOOL.lnk
c:\documents and settings\All Users\Application Data\8e8669\BackUp\Windows Search.lnk
c:\documents and settings\All Users\Application Data\8e8669\MSS.ico
c:\documents and settings\All Users\Application Data\8e8669\MSSSys\vd952342.bd
c:\documents and settings\Diana\Recent\ANTIGEN.dll
c:\documents and settings\Diana\Recent\ANTIGEN.drv
c:\documents and settings\Diana\Recent\ANTIGEN.exe
c:\documents and settings\Diana\Recent\ANTIGEN.sys
c:\documents and settings\Diana\Recent\ANTIGEN.tmp
c:\documents and settings\Diana\Recent\cb.dll
c:\documents and settings\Diana\Recent\cb.exe
c:\documents and settings\Diana\Recent\cb.tmp
c:\documents and settings\Diana\Recent\cid.dll
c:\documents and settings\Diana\Recent\cid.exe
c:\documents and settings\Diana\Recent\cid.tmp
c:\documents and settings\Diana\Recent\CLSV.dll
c:\documents and settings\Diana\Recent\CLSV.drv
c:\documents and settings\Diana\Recent\CLSV.sys
c:\documents and settings\Diana\Recent\CLSV.tmp
c:\documents and settings\Diana\Recent\DBOLE.dll
c:\documents and settings\Diana\Recent\DBOLE.drv
c:\documents and settings\Diana\Recent\DBOLE.exe
c:\documents and settings\Diana\Recent\DBOLE.sys
c:\documents and settings\Diana\Recent\DBOLE.tmp
c:\documents and settings\Diana\Recent\ddv.dll
c:\documents and settings\Diana\Recent\ddv.exe
c:\documents and settings\Diana\Recent\ddv.sys
c:\documents and settings\Diana\Recent\delfile.dll
c:\documents and settings\Diana\Recent\delfile.drv
c:\documents and settings\Diana\Recent\delfile.exe
c:\documents and settings\Diana\Recent\delfile.sys
c:\documents and settings\Diana\Recent\dudl.exe
c:\documents and settings\Diana\Recent\dudl.tmp
c:\documents and settings\Diana\Recent\eb.dll
c:\documents and settings\Diana\Recent\eb.drv
c:\documents and settings\Diana\Recent\eb.exe
c:\documents and settings\Diana\Recent\eb.sys
c:\documents and settings\Diana\Recent\eb.tmp
c:\documents and settings\Diana\Recent\energy.dll
c:\documents and settings\Diana\Recent\energy.drv
c:\documents and settings\Diana\Recent\energy.exe
c:\documents and settings\Diana\Recent\energy.sys
c:\documents and settings\Diana\Recent\energy.tmp
c:\documents and settings\Diana\Recent\exec.dll
c:\documents and settings\Diana\Recent\exec.drv
c:\documents and settings\Diana\Recent\exec.exe
c:\documents and settings\Diana\Recent\exec.sys
c:\documents and settings\Diana\Recent\exec.tmp
c:\documents and settings\Diana\Recent\fan.dll
c:\documents and settings\Diana\Recent\fan.exe
c:\documents and settings\Diana\Recent\fan.sys
c:\documents and settings\Diana\Recent\fan.tmp
c:\documents and settings\Diana\Recent\fix.drv
c:\documents and settings\Diana\Recent\fix.exe
c:\documents and settings\Diana\Recent\fix.sys
c:\documents and settings\Diana\Recent\FS.exe
c:\documents and settings\Diana\Recent\FS.tmp
c:\documents and settings\Diana\Recent\FW.drv
c:\documents and settings\Diana\Recent\FW.sys
c:\documents and settings\Diana\Recent\FW.tmp
c:\documents and settings\Diana\Recent\gid.sys
c:\documents and settings\Diana\Recent\gid.tmp
c:\documents and settings\Diana\Recent\grid.dll
c:\documents and settings\Diana\Recent\grid.drv
c:\documents and settings\Diana\Recent\grid.tmp
c:\documents and settings\Diana\Recent\hymt.dll
c:\documents and settings\Diana\Recent\hymt.sys
c:\documents and settings\Diana\Recent\hymt.tmp
c:\documents and settings\Diana\Recent\kernel32.dll
c:\documents and settings\Diana\Recent\kernel32.drv
c:\documents and settings\Diana\Recent\kernel32.exe
c:\documents and settings\Diana\Recent\kernel32.sys
c:\documents and settings\Diana\Recent\kernel32.tmp
c:\documents and settings\Diana\Recent\pal.dll
c:\documents and settings\Diana\Recent\pal.drv
c:\documents and settings\Diana\Recent\pal.exe
c:\documents and settings\Diana\Recent\pal.tmp
c:\documents and settings\Diana\Recent\PE.dll
c:\documents and settings\Diana\Recent\PE.drv
c:\documents and settings\Diana\Recent\PE.exe
c:\documents and settings\Diana\Recent\PE.sys
c:\documents and settings\Diana\Recent\PE.tmp
c:\documents and settings\Diana\Recent\ppal.drv
c:\documents and settings\Diana\Recent\ppal.sys
c:\documents and settings\Diana\Recent\ppal.tmp
c:\documents and settings\Diana\Recent\runddl.tmp
c:\documents and settings\Diana\Recent\runddlkey.dll
c:\documents and settings\Diana\Recent\runddlkey.drv
c:\documents and settings\Diana\Recent\SICKBOY.drv
c:\documents and settings\Diana\Recent\SICKBOY.exe
c:\documents and settings\Diana\Recent\SICKBOY.sys
c:\documents and settings\Diana\Recent\SICKBOY.tmp
c:\documents and settings\Diana\Recent\sld.dll
c:\documents and settings\Diana\Recent\sld.drv
c:\documents and settings\Diana\Recent\sld.sys
c:\documents and settings\Diana\Recent\SM.dll
c:\documents and settings\Diana\Recent\SM.drv
c:\documents and settings\Diana\Recent\SM.tmp
c:\documents and settings\Diana\Recent\snl2w.dll
c:\documents and settings\Diana\Recent\snl2w.drv
c:\documents and settings\Diana\Recent\snl2w.exe
c:\documents and settings\Diana\Recent\snl2w.sys
c:\documents and settings\Diana\Recent\std.dll
c:\documents and settings\Diana\Recent\std.drv
c:\documents and settings\Diana\Recent\std.exe
c:\documents and settings\Diana\Recent\std.tmp
c:\documents and settings\Diana\Recent\tempdoc.dll
c:\documents and settings\Diana\Recent\tempdoc.drv
c:\documents and settings\Diana\Recent\tempdoc.exe
c:\documents and settings\Diana\Recent\tempdoc.tmp
c:\documents and settings\Diana\Recent\tjd.dll
c:\documents and settings\Diana\Recent\tjd.drv
c:\documents and settings\Diana\Recent\tjd.exe
c:\documents and settings\Diana\Recent\tjd.tmp
.
((((((((((((((((((((((((( Files Created from 2010-12-14 to 2011-01-14 )))))))))))))))))))))))))))))))
.
2011-01-13 17:28 . 2011-01-13 17:28 -------- d-----w- C:\HostXpert
2011-01-13 17:26 . 2011-01-13 17:26 -------- d-----w- C:\.HostsXpert[1]
2011-01-12 16:54 . 2011-01-12 16:54 602112 ----a-w- c:\temp\OTL.exe
2011-01-07 18:16 . 2011-01-07 18:16 -------- d-----w- c:\program files\ERUNT
2010-12-19 15:30 . 2010-12-19 15:30 -------- d-----w- C:\$AVG
2010-12-19 14:01 . 2010-12-19 14:01 -------- d-----w- c:\documents and settings\Diana\Application Data\AVG10
2010-12-19 14:00 . 2010-12-19 14:00 -------- d--h--w- c:\documents and settings\All Users\Application Data\Common Files
2010-12-19 13:58 . 2011-01-06 16:31 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG10
2010-12-19 13:56 . 2010-12-19 13:56 -------- d-----w- c:\program files\AVG
2010-12-19 13:49 . 2010-12-19 14:52 -------- d-----w- c:\documents and settings\All Users\Application Data\MFAData
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 18:09 . 2010-09-20 12:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 18:08 . 2010-09-20 12:38 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-11-19 15:18 . 2010-11-19 15:18 2026 ----a-w- C:\cc_20101119_151835.reg
2010-11-19 15:18 . 2010-11-19 15:17 91930 ----a-w- C:\cc_20101119_151753.reg
2010-11-18 18:12 . 2004-07-27 07:51 81920 ----a-w- c:\windows\system32\isign32.dll
2010-11-09 14:52 . 2003-10-27 19:09 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:26 . 2004-02-06 18:05 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:26 . 2003-03-31 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:26 . 2003-03-31 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:25 . 2004-08-04 05:59 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2003-03-31 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2003-03-31 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-10-26 13:25 . 2003-03-31 12:00 1853312 ----a-w- c:\windows\system32\win32k.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-20 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-11-17 3022848]
"nwiz"="nwiz.exe" [2003-11-17 753664]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2006-01-13 188416]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-07 185896]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Diana\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-24 304128]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VIA RAID TOOL.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VIA RAID TOOL.lnk
backup=c:\windows\pss\VIA RAID TOOL.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-20 22:07 932288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-06 23:46 57344 ----a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 03:47 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2003-06-25 10:24 49152 -c--a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2008-03-30 09:36 267048 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-03-28 22:37 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 10:44 248552 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-06-20 08:51 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\WINDOWS\\ServicePackFiles\\i386\\iexplore.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [27/07/2004 09:25 77056]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [15/02/2010 11:25 135664]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files\LogMeIn\x86\LMIGuardianSvc.exe [01/10/2010 14:26 374152]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2010-12-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2011-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-15 11:25]
2011-01-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-15 11:25]
2011-01-14 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
MSConfigStartUp-CPU Thermometer - c:\program files\CPU Thermometer\CPUThermometer.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-01-14 17:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@DACL=(02 0010)
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@DACL=(02 0010)
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@DACL=(02 0010)
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(1984)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-01-14 17:18:36
ComboFix-quarantined-files.txt 2011-01-14 17:18
Pre-Run: 22,188,318,720 bytes free
Post-Run: 22,148,616,192 bytes free
- - End Of File - - 94B81638CB3EB6CE28EF9C3CAC2AC99E
I hope this helps