Jump to content

Recommended Posts

I performed a full update and that freakin' PUP.Optional.WeCare.A virus came back... I knew the never ending Windows update was going to come to people with some sort of price. It's in a registry key and the item is HKCR\CLSID\{D824F0DE-3D60-4F57-9EB1-66033ECD8ABB}

Thank you in advance for any assistance that I can get.

 

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.45.2
Run by Queenie at 20:41:43 on 2013-12-31
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1023.320 [GMT -8:00]
.
AV: AVG Anti-Virus Free Edition 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ================
.
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - <orphaned>
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-ba7e-000000000003}\_SC_Acrobat.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~2.lnk - c:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoDriveTypeAutoRun = dword:145
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

TCP: NameServer = 192.168.10.1
TCP: Interfaces\{39E0C468-C579-4A08-9E64-E3F7D3E50054} : DHCPNameServer = 192.168.10.1
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\queenie\application data\mozilla\firefox\profiles\z8kp6r4o.default\
FF - plugin: c:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.20913.0\npctrlui.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_9_900_170.dll
FF - ExtSQL: 2013-12-17 13:44; {fe272bd1-5f76-4ea4-8501-a05d35d823fc}; c:\documents and settings\queenie\application data\mozilla\firefox\profiles\z8kp6r4o.default\extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi
.
============= SERVICES / DRIVERS ===============
.
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-9-15 418376]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-9-15 701512]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2013-9-15 22856]
S0 cerc6;cerc6; [x]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AndNetDiag;LGE AndroidNet USB Serial Port;c:\windows\system32\drivers\lgandnetdiag.sys --> c:\windows\system32\drivers\lgandnetdiag.sys [?]
S3 ANDNetModem;LGE AndroidNet USB Modem;c:\windows\system32\drivers\lgandnetmodem.sys --> c:\windows\system32\drivers\lgandnetmodem.sys [?]
S3 andnetndis;LGE AndroidNet NDIS Ethernet Adapter;c:\windows\system32\drivers\lgandnetndis.sys --> c:\windows\system32\drivers\lgandnetndis.sys [?]
S3 mbamchameleon;mbamchameleon;c:\windows\system32\drivers\mbamchameleon.sys [2013-12-24 35144]
S3 P1120VID;Creative WebCam NX Ultra;c:\windows\system32\drivers\P1120Vid.sys [2004-1-12 1252474]
S3 V;V;c:\docume~1\queenie\locals~1\temp\v.exe --> c:\docume~1\queenie\locals~1\temp\V.exe [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2013-7-20 754856]
.
=============== Created Last 30 ================
.
2013-12-27 00:23:12    --------    d-sh--w-    c:\documents and settings\queenie\IECompatCache
2013-12-24 15:51:02    35144    ----a-w-    c:\windows\system32\drivers\mbamchameleon.sys
2013-12-20 22:36:33    22370928    ----a-w-    c:\program files\mozilla firefox\xul.dll
2013-12-20 22:36:28    108144    ----a-w-    c:\program files\mozilla firefox\webapprt-stub.exe
2013-12-20 22:36:09    170960    ----a-w-    c:\program files\mozilla firefox\webapp-uninstaller.exe
2013-12-20 22:36:08    276592    ----a-w-    c:\program files\mozilla firefox\updater.exe
2013-12-20 22:36:07    872352    ----a-w-    c:\program files\mozilla firefox\uninstall\helper.exe
2013-12-20 22:36:06    153712    ----a-w-    c:\program files\mozilla firefox\softokn3.dll
2013-12-20 22:36:02    159744    ----a-w-    c:\program files\mozilla firefox\plugins\npqtplugin5.dll
2013-12-20 22:36:02    159744    ----a-w-    c:\program files\mozilla firefox\plugins\npqtplugin4.dll
2013-12-20 22:36:02    159744    ----a-w-    c:\program files\mozilla firefox\plugins\npqtplugin3.dll
2013-12-20 22:36:01    17248    ----a-w-    c:\program files\mozilla firefox\plugins\NPOFFICE.DLL
2013-12-20 22:36:01    159744    ----a-w-    c:\program files\mozilla firefox\plugins\npqtplugin2.dll
2013-12-20 22:36:01    159744    ----a-w-    c:\program files\mozilla firefox\plugins\npqtplugin.dll
2013-12-20 22:34:50    272496    ----a-w-    c:\program files\mozilla firefox\browser\components\browsercomps.dll
2013-12-20 22:34:34    75376    ----a-w-    c:\program files\mozilla firefox\breakpadinjector.dll
2013-12-20 22:34:30    20080    ----a-w-    c:\program files\mozilla firefox\AccessibleMarshal.dll
2013-12-16 20:43:47    25088    -c----w-    c:\windows\system32\dllcache\hidparse.sys
2013-12-16 20:43:47    14976    ----a-w-    c:\windows\system32\drivers\usbscan.sys
2013-12-16 19:43:29    5376    -c----w-    c:\windows\system32\dllcache\usbd.sys
2013-12-16 19:43:29    32384    -c----w-    c:\windows\system32\dllcache\usbccgp.sys
2013-12-16 19:43:29    30336    -c----w-    c:\windows\system32\dllcache\usbehci.sys
2013-12-15 23:44:25    --------    d-----w-    c:\windows\system32\MRT
2013-12-15 21:57:34    --------    d--h--w-    c:\documents and settings\queenie\InstallAnywhere
2013-12-15 20:19:03    12928    -c----w-    c:\windows\system32\dllcache\usb8023x.sys
2013-12-15 19:16:35    --------    d-sh--w-    c:\documents and settings\queenie\PrivacIE
2013-12-08 17:49:54    --------    d-----w-    c:\documents and settings\queenie\application data\Malwarebytes
2013-12-07 22:04:21    --------    d-----w-    c:\documents and settings\queenie\local settings\application data\Mozilla
2013-12-07 21:56:25    --------    d-----w-    c:\documents and settings\queenie\application data\MSNInstaller
2013-12-07 21:44:45    --------    d-----w-    c:\documents and settings\queenie\local settings\application data\Adobe
2013-12-07 21:42:59    --------    d-----w-    c:\documents and settings\queenie\local settings\application data\Apple Computer
2013-12-07 21:36:02    --------    d-sh--w-    c:\documents and settings\queenie\IETldCache
2013-12-03 16:53:19    --------    d-----w-    c:\program files\Smith Micro
.
==================== Find3M  ====================
.
2013-12-27 18:24:21    692616    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2013-12-27 18:22:38    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2013-11-13 02:59:42    150528    ----a-w-    c:\windows\system32\imagehlp.dll
2013-11-07 05:38:51    591360    ----a-w-    c:\windows\system32\rpcrt4.dll
2013-11-06 01:03:31    7168    ----a-w-    c:\windows\system32\xpsp4res.dll
2013-10-30 02:26:17    1879040    ----a-w-    c:\windows\system32\win32k.sys
2013-10-29 07:57:34    920064    ----a-w-    c:\windows\system32\wininet.dll
2013-10-29 07:57:33    43520    ------w-    c:\windows\system32\licmgr10.dll
2013-10-29 07:57:33    18944    ----a-w-    c:\windows\system32\corpol.dll
2013-10-29 07:57:33    1469440    ------w-    c:\windows\system32\inetcpl.cpl
2013-10-29 00:45:02    385024    ------w-    c:\windows\system32\html.iec
2013-10-23 23:45:49    172032    ----a-w-    c:\windows\system32\scrrun.dll
2013-10-12 15:56:19    278528    ----a-w-    c:\windows\system32\oakley.dll
2013-10-09 13:12:48    287744    ----a-w-    c:\windows\system32\gdi32.dll
2013-10-08 14:50:41    94632    ----a-w-    c:\windows\system32\WindowsAccessBridge.dll
2013-10-08 14:29:36    145408    ----a-w-    c:\windows\system32\javacpl.cpl
2013-10-07 10:59:21    603136    ----a-w-    c:\windows\system32\crypt32.dll
.
============= FINISH: 20:45:02.34 ===============

 

 

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume2
Install Date: 12/29/2010 9:52:52 AM
System Uptime: 12/31/2013 9:20:20 AM (11 hours ago)
.
Motherboard: Dell Computer Corp. |  | 0F4491
Processor:               Intel® Pentium® 4 CPU 2.80GHz | Microprocessor | 2793/533mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 74 GiB total, 35.961 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is FIXED (NTFS) - 75 GiB total, 74.455 GiB free.
.
==== Disabled Device Manager Items =============
.
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Linksys Wireless-G PCI Adapter
Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_00551737&REV_00\4&1C660DD6&0&00F0
Manufacturer: Linksys, A Division of Cisco Systems, Inc.
Name: Linksys Wireless-G PCI Adapter
PNP Device ID: PCI\VEN_1814&DEV_0301&SUBSYS_00551737&REV_00\4&1C660DD6&0&00F0
Service: RT61
.
==== System Restore Points ===================
.
RP855: 10/23/2013 9:44:00 PM - System Checkpoint
RP856: 10/25/2013 12:49:05 PM - System Checkpoint
RP857: 10/26/2013 12:56:23 PM - System Checkpoint
RP858: 10/27/2013 1:01:41 PM - System Checkpoint
RP859: 10/28/2013 6:51:47 PM - System Checkpoint
RP860: 11/4/2013 8:21:56 AM - System Checkpoint
RP861: 11/8/2013 11:54:54 AM - System Checkpoint
RP862: 11/9/2013 12:09:23 PM - System Checkpoint
RP863: 11/10/2013 1:02:00 PM - System Checkpoint
RP864: 11/11/2013 1:39:17 PM - System Checkpoint
RP865: 11/13/2013 7:18:58 PM - System Checkpoint
RP866: 11/16/2013 2:07:05 PM - System Checkpoint
RP867: 11/22/2013 8:33:30 AM - System Checkpoint
RP868: 11/23/2013 4:04:39 PM - System Checkpoint
RP869: 11/24/2013 2:39:06 PM - Installed The Sims Deluxe Edition
RP870: 11/26/2013 8:25:36 AM - System Checkpoint
RP871: 11/27/2013 5:56:43 PM - System Checkpoint
RP872: 11/28/2013 8:17:56 PM - System Checkpoint
RP873: 11/30/2013 9:42:24 AM - System Checkpoint
RP874: 12/1/2013 10:28:18 AM - System Checkpoint
RP875: 12/1/2013 9:23:16 PM - Installed The Sims Hot Date
RP876: 12/1/2013 9:36:26 PM - Installed The Sims Vacation
RP877: 12/1/2013 9:49:49 PM - Installed The Sims Unleashed
RP878: 12/3/2013 7:17:01 AM - System Checkpoint
RP879: 12/3/2013 8:53:06 AM - Installed StuffIt Expander 2011.
RP880: 12/9/2013 6:11:13 PM - System Checkpoint
RP881: 12/14/2013 10:43:50 PM - System Checkpoint
RP882: 12/15/2013 12:09:34 PM - Removed Google Earth Plug-in.
RP883: 12/15/2013 3:14:36 PM - Software Distribution Service 3.0
RP884: 12/16/2013 10:09:21 AM - Software Distribution Service 3.0
RP885: 12/16/2013 5:57:06 PM - Software Distribution Service 3.0
RP886: 12/17/2013 8:46:10 AM - Software Distribution Service 3.0
RP887: 12/18/2013 2:30:35 PM - System Checkpoint
RP888: 12/19/2013 9:19:06 PM - System Checkpoint
RP889: 12/20/2013 10:29:27 PM - System Checkpoint
RP890: 12/22/2013 3:07:03 PM - System Checkpoint
RP891: 12/23/2013 3:54:28 PM - System Checkpoint
RP892: 12/26/2013 8:59:58 AM - System Checkpoint
RP893: 12/27/2013 11:45:38 AM - System Checkpoint
RP894: 12/28/2013 12:21:19 PM - System Checkpoint
RP895: 12/29/2013 1:09:17 PM - System Checkpoint
RP896: 12/30/2013 2:09:18 PM - System Checkpoint
RP897: 12/31/2013 2:26:04 PM - System Checkpoint
.
==== Installed Programs ======================
.
Adobe Acrobat  8 Standard
Adobe Acrobat 5.0
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Bonjour
CCleaner
CleanUp!
Compatibility Pack for the 2007 Office system
Creative WebCam NX Ultra Driver (1.01.03.0112)
Creative WebCam NX Ultra User's Guide (English)
Google Update Helper
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB2756822)
Intel® 537EP V9x DF PCI Modem
Intel® PRO Network Adapters and Drivers
iTunes
Java 7 Update 45
Java Auto Updater
K-Lite Codec Pack 3.1.0 Full
Kepler 7.0
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Web Components
Microsoft Office File Validation Add-In
Microsoft Office Small Business Edition 2003
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
MobileMe Control Panel
Mozilla Firefox 26.0 (x86 en-US)
Mozilla Maintenance Service
Network Play System (Patching)
NVIDIA Windows 2000/XP Display Drivers
PhotoImpression
QuickTime
Roxio Creator Audio
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE 10.3
Roxio Creator Tools
Roxio Update Manager
Safari
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2861188)
Security Update for Windows Internet Explorer 7 (KB2544521)
Security Update for Windows Internet Explorer 7 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB2898785)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2803821-v2)
Security Update for Windows Media Player (KB2845142)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761226)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2780091)
Security Update for Windows XP (KB2802968)
Security Update for Windows XP (KB2807986)
Security Update for Windows XP (KB2813345)
Security Update for Windows XP (KB2820917)
Security Update for Windows XP (KB2834886)
Security Update for Windows XP (KB2845187)
Security Update for Windows XP (KB2847311)
Security Update for Windows XP (KB2849470)
Security Update for Windows XP (KB2850869)
Security Update for Windows XP (KB2859537)
Security Update for Windows XP (KB2862152)
Security Update for Windows XP (KB2862330)
Security Update for Windows XP (KB2862335)
Security Update for Windows XP (KB2864063)
Security Update for Windows XP (KB2868626)
Security Update for Windows XP (KB2876217)
Security Update for Windows XP (KB2876331)
Security Update for Windows XP (KB2892075)
Security Update for Windows XP (KB2893294)
Security Update for Windows XP (KB2893984)
Security Update for Windows XP (KB2898715)
Security Update for Windows XP (KB2900986)
Security Update for Windows XP (KB923789)
StuffIt Expander 2011
The Sims Unleashed
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
Update for Windows XP (KB2863058)
Update for Windows XP (KB2904266)
Visual Studio Tools for the Office system 3.0 Runtime
VLC media player 2.0.2
WebFldrs XP
WinDjView 2.0.1
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows PowerShell 1.0
.
==== Event Viewer Messages From Past Week ========
.
12/29/2013 8:10:20 AM, error: Service Control Manager [7011]  - Timeout (30000 milliseconds) waiting for a transaction response from the MBAMService service.
12/29/2013 8:08:28 AM, error: Service Control Manager [7022]  - The Automatic Updates service hung on starting.
12/28/2013 9:51:18 AM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the Windows Image Acquisition (WIA) service to connect.
12/28/2013 9:51:18 AM, error: Service Control Manager [7000]  - The Windows Image Acquisition (WIA) service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
12/27/2013 10:11:39 AM, error: Service Control Manager [7009]  - Timeout (30000 milliseconds) waiting for the Application Layer Gateway Service service to connect.
12/27/2013 10:11:39 AM, error: Service Control Manager [7000]  - The Application Layer Gateway Service service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.
12/27/2013 10:10:25 AM, error: atapi [9]  - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
.
==== End Of File ===========================


 

Link to post
Share on other sites

Welcome to the forum.

Please download and run RogueKiller 32 Bit to your desktop.

RogueKiller 64 Bit <---use this one for 64 bit systems

Which system am I using?

Quit all running programs.

For Windows XP, double-click to start.

For Vista or Windows 7-8, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.

Click Scan to scan the system.

When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

(please don't put logs in code or quotes and use the default font)

General P2P/Piracy Warning:

1. If you're using Peer 2 Peer software such uTorrent, BitTorrent or similar you must either fully uninstall it or completely disable it from running while being assisted here.

Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.

2. If you have illegal/cracked software, cracks, keygens, custom (Adobe) host file, etc. on the system, please remove or uninstall them now and read the policy on Piracy.

Failure to remove such software will result in your topic being closed and no further assistance being provided.

MrC

Note:

Please read all of my instructions completely including these.

Make sure system restore is turned on and running

Make sure you're subscribed to this topic: Click on the Follow This Topic Button (at the top right of this page), make sure that the Receive notification box is checked and that it is set to Instantly

Removing malware can be unpredictable...unlikely but things can go very wrong! Backup any files that cannot be replaced. You can copy them to a CD/DVD, external drive or a pen drive

<+>Please don't run any other scans, download, install or uninstall any programs while I'm working with you.

<+>The removal of malware isn't instantaneous, please be patient.

<+>When we are done, I'll give to instructions on how to cleanup all the tools and logs

<+>Please stick with me until I give you the "all clear" and Please don't waste my time by leaving before that.

------->Your topic will be closed if you haven't replied within 3 days!<--------

(If I don't respond within 24 hours, please send me a PM)

Link to post
Share on other sites

Awesome, MrCharlie! I just ran RogueKiller and BAM! The report was a kick in the pants. I new that something was causing the folders to replicate, but now I know why.

 

Cheers and Happy New Year!  ^_^

 

RogueKiller V8.8.0 [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Queenie [Admin rights]
Mode : Scan -- Date : 01/01/2014 19:04:51
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[HJ POL][PUM] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
[HJ POL][PUM] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0xc0000033] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection :  ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1       localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) IC35L090AVV207-0 +++++
--- User ---
[MBR] 04d5b888218ccabe471e4cfc7cea2e7d
[bSP] c80f110d2a36ad8b30a0a0d9d23ed92e : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 31 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 64260 | Size: 76253 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: (\\.\PHYSICALDRIVE1 @ IDE) WDC WD800BB-00CAA1 +++++
--- User ---
[MBR] c32b1abd5b18f55ffd09bdf71caf8b06
[bSP] 61d1ec1d43e36fabe7e658125f83d76b : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 76308 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_01012014_190451.txt >>



 

Link to post
Share on other sites

Actually the log from RK is clean.

Please run the procedure:

Lets clean out any adware/spyware now: (this will require a reboot so save all your work)

Please download AdwCleaner by Xplode and save to your Desktop.

Make sure you click on download buttons that look similar to this, not "sponsored ad links":

bleep-crop.jpg

  • Double click on AdwCleaner.exe to run the tool.

    Vista/Windows 7/8 users right-click and select Run As Administrator

  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • When it's done you'll see: Pending: Please uncheck elements you don't want removed.
  • Now click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • Look over the log especially under Files/Folders for any program you want to save.
  • If there's a program you may want to save, just uncheck it from AdwCleaner.
  • If you're not sure, post the log for review. (all items found are adware/spyware/foistware)
  • If you're ready to clean it all up.....click the Clean button.
  • After rebooting, a logfile report (AdwCleaner[s0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.
  • Items that are deleted are moved to the Quarantine Folder: C:\AdwCleaner\Quarantine
  • To restore an item that has been deleted:
  • Go to Tools > Quarantine Manager > check what you want restored > now click on Restore.
Then..................

Open up Malwarebytes > Settings Tab > Scanner Settings > Under action for PUP > Select: Show in Results List and Check for removal.

Please Update and run a FULL Scan with Malwarebytes Anti-Malware, post the report.

Make sure that everything is checked, and click Remove Selected.

Please let me know how computer is running now, MrC

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.