Hi,
I have been infected with the Alueron Trjan/virus and keep getting the windows xp restore pop up. Everything seems to have vanished and can only operate in safe mode
Thanks
here's the dds:-
.
DDS (Ver_2011-06-12.02) - NTFSx86 NETWORK
Internet Explorer: 7.0.5730.11
Run by David Roberts at 20:03:39 on 2011-06-14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2038.1634 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: PC Tools Firewall Plus *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.talktalk.co.uk/
mStart Page = hxxp://www.tiscali.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9A928341-D366-4032-A471-6EC120CD9B73} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: {E4F3F5D3-847E-4970-8754-9165E77EEE13} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Spyware Doctor] c:\documents and settings\david roberts\desktop\sdsetup_revwire207[1].exe -min
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [VmBaxAOpYwYFlj] c:\documents and settings\all users\application data\VmBaxAOpYwYFlj.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [EPSON Stylus CX6600 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
mRun: [EPSON Stylus CX6600 Series (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9EE.EXE /P35 "EPSON Stylus CX6600 Series (Copy 1)" /O6 "USB001" /M "Stylus CX6600"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [\BEDROOM\EPSON] c:\windows\system32\spool\drivers\w32x86\3\e_fati9ee.exe /p15 "\\bedroom\epson" /o15 "\\bedroom\EPSON" /M "Stylus CX6600"
mRun: [\BEDROOM\EPSON CX6600] c:\windows\system32\spool\drivers\w32x86\3\e_fati9ee.exe /p22 "\\bedroom\epson cx6600" /o22 "\\bedroom\EPSON CX6600" /M "Stylus CX6600"
mRun: [\BEDROOM\CX6600] c:\windows\system32\spool\drivers\w32x86\3\e_fati9ee.exe /p16 "\\bedroom\cx6600" /o16 "\\bedroom\CX6600" /M "Stylus CX6600"
mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\davidr~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktop = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INETREPL.DLL
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INETREPL.DLL
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: autotrader.co.uk\www
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1B735B98-8010-11D5-AD0B-00500463D885} - hxxp://www.partsarena.co.uk/baxi/Plugins/IMIESRCH.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {36C17E9B-3354-11D1-95CF-0000B4530F04} - hxxp://www.partsarena.com/baxi/Plugins/GFXVIEW.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240350071421
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1240349950203
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B34BFC41-E537-4228-9B3F-122328D1DE14} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{EBEEF6E2-734D-4AF5-9215-60EE3DB9F381} : DhcpNameServer = 192.168.0.1
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\AATP.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\CENETFLT.DLL
Notify: igfxcui - igfxsrvc.dll
.
============= SERVICES / DRIVERS ===============
.
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2011-5-16 249616]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2011-5-16 57536]
S1 jithgnya;jithgnya;\??\c:\windows\system32\drivers\jithgnya.sys --> c:\windows\system32\drivers\jithgnya.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
S1 MpKsl2004902f;MpKsl2004902f; [x]
S1 MpKsl308703cc;MpKsl308703cc;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c081f68b-fd3e-463b-9d8f-f1e0c734bced}\mpksl308703cc.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c081f68b-fd3e-463b-9d8f-f1e0c734bced}\MpKsl308703cc.sys [?]
S1 MpKsl7ad872e7;MpKsl7ad872e7; [x]
S1 MpKslefb49274;MpKslefb49274; [x]
S1 MpKslfe0c0255;MpKslfe0c0255;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{672d87bb-77b6-47dc-85d9-98416537d8f3}\mpkslfe0c0255.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{672d87bb-77b6-47dc-85d9-98416537d8f3}\MpKslfe0c0255.sys [?]
S1 npsxufoa;npsxufoa; [x]
S1 vdhiikvh;vdhiikvh; [x]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-1-5 54752]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-10-19 217088]
S2 gupdate1c9f5f043aa6e2e;Google Update Service (gupdate1c9f5f043aa6e2e);c:\program files\google\update\GoogleUpdate.exe [2009-6-26 133104]
S2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2011-5-16 160448]
S2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2011-5-16 287024]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2009-12-22 18136]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-10-19 36640]
S3 G3GRUMDM;G3G R USB Modem;c:\windows\system32\drivers\g3grumdm.sys [2006-5-29 26496]
S3 G3GRUSER;G3G R USB Serial;c:\windows\system32\drivers\g3gruser.sys [2006-5-29 23296]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-6-26 133104]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2008-1-28 40832]
S3 nokiackx;Nokia CK USB Driver;c:\windows\system32\drivers\nokiackx.sys [2011-3-23 27264]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2011-5-16 89192]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2011-5-16 57536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2011-5-16 124992]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-8-19 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-8-19 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-8-19 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [2010-8-19 100224]
.
=============== Created Last 30 ================
.
2011-06-14 06:46:34 386048 ----a-w- c:\documents and settings\all users\application data\17030948.exe
2011-06-13 19:45:32 41680 ----a-w- c:\windows\system32\drivers\shkjagao.sys
2011-06-13 19:33:23 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c94a2655-f1d7-4a3c-89ff-7e9ee91f8b4a}\MpKsl4e1598df.sys
2011-06-12 23:40:26 4224 ----a-w- c:\windows\system32\beep.sys
2011-06-12 23:38:59 492544 ---ha-w- c:\documents and settings\all users\application data\VmBaxAOpYwYFlj.exe
2011-06-12 11:20:40 6962000 ---ha-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c94a2655-f1d7-4a3c-89ff-7e9ee91f8b4a}\mpengine.dll
2011-06-03 21:52:30 0 ---ha-w- c:\documents and settings\david roberts\local settings\application data\BIT14.tmp
2011-05-18 22:25:21 -------- d-----w- C:\_OTL
2011-05-17 21:32:40 6962000 ---ha-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-05-16 21:01:07 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-16 20:55:04 -------- d--h--w- c:\program files\Microsoft Security Client
2011-05-15 23:54:25 -------- d--h--w- c:\documents and settings\david roberts\application data\PCToolsFirewallPlus
2011-05-15 23:53:48 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-05-15 23:53:47 160448 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-05-15 23:53:46 249616 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-05-15 23:52:14 89192 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2011-05-15 23:52:14 57536 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2011-05-15 23:52:14 32808 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2011-05-15 23:52:14 -------- d--h--w- c:\program files\common files\PC Tools
2011-05-15 23:52:12 124992 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2011-05-15 23:52:11 -------- d--h--w- c:\program files\PC Tools Firewall Plus
2011-05-15 23:35:35 -------- d--h--w- c:\program files\SpywareBlaster
.
==================== Find3M ====================
.
.
============= FINISH: 20:05:28.96 ===============
Edit: Merged Admin query and response.
Hi,
You are correct, it is the same PC. It has had little use for a few weeks due to vacation. It has now been in use by the kids and has picked up another virus so that is why I have posted here.
Had fantastic assistance from Ken previously and was hoping I could get some more help.
Thanks
Dave:thanks:
I have been infected with the Alueron Trjan/virus and keep getting the windows xp restore pop up. Everything seems to have vanished and can only operate in safe mode
Thanks
here's the dds:-
.
DDS (Ver_2011-06-12.02) - NTFSx86 NETWORK
Internet Explorer: 7.0.5730.11
Run by David Roberts at 20:03:39 on 2011-06-14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.2038.1634 [GMT 1:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: PC Tools Firewall Plus *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.talktalk.co.uk/
mStart Page = hxxp://www.tiscali.co.uk/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {9A928341-D366-4032-A471-6EC120CD9B73} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: {E4F3F5D3-847E-4970-8754-9165E77EEE13} - No File
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Spyware Doctor] c:\documents and settings\david roberts\desktop\sdsetup_revwire207[1].exe -min
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [VmBaxAOpYwYFlj] c:\documents and settings\all users\application data\VmBaxAOpYwYFlj.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [AGRSMMSG] AGRSMMSG.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [hpWirelessAssistant] c:\program files\hpq\hp wireless assistant\HP Wireless Assistant.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
mRun: [eabconfg.cpl] c:\program files\hpq\quick launch buttons\EabServr.exe /Start
mRun: [Cpqset] c:\program files\hpq\default settings\cpqset.exe
mRun: [EPSON Stylus CX6600 Series] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
mRun: [EPSON Stylus CX6600 Series (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_FATI9EE.EXE /P35 "EPSON Stylus CX6600 Series (Copy 1)" /O6 "USB001" /M "Stylus CX6600"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [\BEDROOM\EPSON] c:\windows\system32\spool\drivers\w32x86\3\e_fati9ee.exe /p15 "\\bedroom\epson" /o15 "\\bedroom\EPSON" /M "Stylus CX6600"
mRun: [\BEDROOM\EPSON CX6600] c:\windows\system32\spool\drivers\w32x86\3\e_fati9ee.exe /p22 "\\bedroom\epson cx6600" /o22 "\\bedroom\EPSON CX6600" /M "Stylus CX6600"
mRun: [\BEDROOM\CX6600] c:\windows\system32\spool\drivers\w32x86\3\e_fati9ee.exe /p16 "\\bedroom\cx6600" /o16 "\\bedroom\CX6600" /M "Stylus CX6600"
mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\davidr~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
uPolicies-explorer: NoDesktop = 1 (0x1)
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INETREPL.DLL
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\INETREPL.DLL
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: autotrader.co.uk\www
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.3.0/GarminAxControl.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {1B735B98-8010-11D5-AD0B-00500463D885} - hxxp://www.partsarena.co.uk/baxi/Plugins/IMIESRCH.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {36C17E9B-3354-11D1-95CF-0000B4530F04} - hxxp://www.partsarena.com/baxi/Plugins/GFXVIEW.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537}
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1240350071421
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1240349950203
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{B34BFC41-E537-4228-9B3F-122328D1DE14} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{EBEEF6E2-734D-4AF5-9215-60EE3DB9F381} : DhcpNameServer = 192.168.0.1
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\AATP.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\CENETFLT.DLL
WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\CENETFLT.DLL
Notify: igfxcui - igfxsrvc.dll
.
============= SERVICES / DRIVERS ===============
.
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2011-5-16 249616]
R3 pctNdisMP;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2011-5-16 57536]
S1 jithgnya;jithgnya;\??\c:\windows\system32\drivers\jithgnya.sys --> c:\windows\system32\drivers\jithgnya.sys [?]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
S1 MpKsl2004902f;MpKsl2004902f; [x]
S1 MpKsl308703cc;MpKsl308703cc;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c081f68b-fd3e-463b-9d8f-f1e0c734bced}\mpksl308703cc.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c081f68b-fd3e-463b-9d8f-f1e0c734bced}\MpKsl308703cc.sys [?]
S1 MpKsl7ad872e7;MpKsl7ad872e7; [x]
S1 MpKslefb49274;MpKslefb49274; [x]
S1 MpKslfe0c0255;MpKslfe0c0255;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{672d87bb-77b6-47dc-85d9-98416537d8f3}\mpkslfe0c0255.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{672d87bb-77b6-47dc-85d9-98416537d8f3}\MpKslfe0c0255.sys [?]
S1 npsxufoa;npsxufoa; [x]
S1 vdhiikvh;vdhiikvh; [x]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-1-5 54752]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-10-19 217088]
S2 gupdate1c9f5f043aa6e2e;Google Update Service (gupdate1c9f5f043aa6e2e);c:\program files\google\update\GoogleUpdate.exe [2009-6-26 133104]
S2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2011-5-16 160448]
S2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2011-5-16 287024]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2009-12-22 18136]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2009-10-19 36640]
S3 G3GRUMDM;G3G R USB Modem;c:\windows\system32\drivers\g3grumdm.sys [2006-5-29 26496]
S3 G3GRUSER;G3G R USB Serial;c:\windows\system32\drivers\g3gruser.sys [2006-5-29 23296]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-6-26 133104]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2008-1-28 40832]
S3 nokiackx;Nokia CK USB Driver;c:\windows\system32\drivers\nokiackx.sys [2011-3-23 27264]
S3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2011-5-16 89192]
S3 pctNdis;PC Tools Firewall Intermediate Filter Service;c:\windows\system32\drivers\pctNdis.sys [2011-5-16 57536]
S3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2011-5-16 124992]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM);c:\windows\system32\drivers\ss_bbus.sys [2010-8-19 98432]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter);c:\windows\system32\drivers\ss_bmdfl.sys [2010-8-19 14848]
S3 ss_bmdm;SAMSUNG USB Mobile Modem;c:\windows\system32\drivers\ss_bmdm.sys [2010-8-19 123648]
S3 ss_bserd;SAMSUNG USB Mobile Logging Driver;c:\windows\system32\drivers\ss_bserd.sys [2010-8-19 100224]
.
=============== Created Last 30 ================
.
2011-06-14 06:46:34 386048 ----a-w- c:\documents and settings\all users\application data\17030948.exe
2011-06-13 19:45:32 41680 ----a-w- c:\windows\system32\drivers\shkjagao.sys
2011-06-13 19:33:23 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c94a2655-f1d7-4a3c-89ff-7e9ee91f8b4a}\MpKsl4e1598df.sys
2011-06-12 23:40:26 4224 ----a-w- c:\windows\system32\beep.sys
2011-06-12 23:38:59 492544 ---ha-w- c:\documents and settings\all users\application data\VmBaxAOpYwYFlj.exe
2011-06-12 11:20:40 6962000 ---ha-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c94a2655-f1d7-4a3c-89ff-7e9ee91f8b4a}\mpengine.dll
2011-06-03 21:52:30 0 ---ha-w- c:\documents and settings\david roberts\local settings\application data\BIT14.tmp
2011-05-18 22:25:21 -------- d-----w- C:\_OTL
2011-05-17 21:32:40 6962000 ---ha-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-05-16 21:01:07 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-05-16 20:55:04 -------- d--h--w- c:\program files\Microsoft Security Client
2011-05-15 23:54:25 -------- d--h--w- c:\documents and settings\david roberts\application data\PCToolsFirewallPlus
2011-05-15 23:53:48 218592 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2011-05-15 23:53:47 160448 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-05-15 23:53:46 249616 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-05-15 23:52:14 89192 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2011-05-15 23:52:14 57536 ----a-w- c:\windows\system32\drivers\pctNdis.sys
2011-05-15 23:52:14 32808 ----a-w- c:\windows\system32\drivers\pctNdis-DNS.sys
2011-05-15 23:52:14 -------- d--h--w- c:\program files\common files\PC Tools
2011-05-15 23:52:12 124992 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2011-05-15 23:52:11 -------- d--h--w- c:\program files\PC Tools Firewall Plus
2011-05-15 23:35:35 -------- d--h--w- c:\program files\SpywareBlaster
.
==================== Find3M ====================
.
.
============= FINISH: 20:05:28.96 ===============
Edit: Merged Admin query and response.
------------------------------------------Hello dgr228,
Is this the same computer: Click.GiftLoad Help needed
http://forums.spybot.info/showthread.php?p=406447#post406447
Also,
Lets do this as it may be a windows issue.
I would like you to post here, you can link them to this thread if you wish as all us forums work together, explain your problem, it may be just things in your start up are messing things up.
http://forums.whatthetech.com/index.php?showforum=119
I will leave this thread open for you for a few days , please post back and let me know what they said or did and if they still feel its malware we can dig deeper, keep in mind that we cleaned some nasty infections on this system and sometimes they could have left some damage.I'm not seeing a topic posted at WTT?post back and let me know if they fixed it
Best regards.
Hi,
You are correct, it is the same PC. It has had little use for a few weeks due to vacation. It has now been in use by the kids and has picked up another virus so that is why I have posted here.
Had fantastic assistance from Ken previously and was hoping I could get some more help.
Thanks
Dave:thanks:
Last edited by a moderator: