Jump to content

redirect problem


Recommended Posts

Hi,

I have scanned a machine dwith a number of services but still get redirects. I am unable to get windows updates and I was unable to post to this forum so I had to go to another system to send this.

I really would appreciate some help this is a tough one. Normally your service will fix anything.

Thanks,

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:25:23 AM, on 6/20/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\Lexmark\ErrorApp\LMab1err.exe

C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [LMab1err] "C:\Program Files\Lexmark\ErrorApp\LMab1err.exe"

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Fweyip] rundll32.exe "C:\WINDOWS\kSouinab.dll",Startup

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O15 - Trusted Zone: http://download.windowsupdate.com

O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://dcode.support.microsoft.com/dcode/A...veX/MSDcode.cab

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab

O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...018/mcfscan.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe

O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

O23 - Service: SmartWiService - Sony Electronics, Inc - C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe

O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe

O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe

O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe

O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

--

End of file - 6699 bytes

Link to post
Share on other sites

Have I done something wrong that I have not received any reply?

Hi,

I have scanned a machine dwith a number of services but still get redirects. I am unable to get windows updates and I was unable to post to this forum so I had to go to another system to send this.

I really would appreciate some help this is a tough one. Normally your service will fix anything.

Thanks,

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 9:25:23 AM, on 6/20/2010

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Intel\Wireless\Bin\EvtEng.exe

C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

C:\Program Files\AVG\AVG9\avgchsvx.exe

C:\Program Files\AVG\AVG9\avgrsx.exe

C:\Program Files\AVG\AVG9\avgcsrvx.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\AVG\AVG9\avgwdsvc.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\AVG\AVG9\avgnsx.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe

C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe

C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\AVG\AVG9\avgtray.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Program Files\Lexmark\ErrorApp\LMab1err.exe

C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [LMab1err] "C:\Program Files\Lexmark\ErrorApp\LMab1err.exe"

O4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Fweyip] rundll32.exe "C:\WINDOWS\kSouinab.dll",Startup

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O15 - Trusted Zone: http://download.windowsupdate.com

O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://dcode.support.microsoft.com/dcode/A...veX/MSDcode.cab

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase6087.cab

O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/...018/mcfscan.cab

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll

O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe

O23 - Service: Intel

Link to post
Share on other sites

Hi diver dan,

Welcome to the forum.

My nickname is deltalima and I will be helping you with your computer problems.

The logs can take some time to research, so please be patient with me.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Please note the following:

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.

  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized

    [*]Please post the contents of these 2 Notepad files in your next reply.

Please download GMER Rootkit Scanner from here.

  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
  • Run Gmer again and click on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the "Scan" and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE

Important! Please do not select the "Show all" checkbox during the scan..

Please post the GMER log along with OTL.txt and Extras.txt from the OTL scan into your next reply.

Link to post
Share on other sites

Hi,

here are the first two logs. The third one was still running after 13 hours. I will have it to you tonight

OTL Extras logfile created on: 6/20/2010 9:12:57 PM - Run 1

OTL by OldTimer - Version 3.2.6.1 Folder = C:\Documents and Settings\Hannah Holmes\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free

4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 105.78 Gb Total Space | 66.72 Gb Free Space | 63.07% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

Drive F: | 61.83 Mb Total Space | 1.06 Mb Free Space | 1.72% Space Free | Partition Type: FAT

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: F52F2867C1364CC

Current User Name: Hannah Holmes

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.pif [@ = piffile] -- "%1" %*"

.scr [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-663187590-1649255284-3763627834-1006\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

piffile [open] -- "%1" %*"

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- Reg Error: Key error.

scrfile [install] -- Reg Error: Key error.

scrfile [open] -- Reg Error: Key error.

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"UacDisableNotify" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)

"C:\WINDOWS\system32\LMabcoms.exe" = C:\WINDOWS\system32\LMabcoms.exe:*:Enabled:Lexmark Enhanced TCP/IP -- ( )

"C:\Program Files\Lexmark\ErrorApp\LMab1err.EXE" = C:\Program Files\Lexmark\ErrorApp\LMab1err.EXE:*:Enabled:Lexmark Status Messenger -- ( )

"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Disabled:AIM -- File not found

"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Disabled:AOL Loader -- File not found

"C:\Program Files\Common Files\AOL\1161282955\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1161282955\ee\aolsoftware.exe:*:Disabled:AOL Services -- File not found

"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library

"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour

"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306

"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility

"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView

"{11204BA5-626B-498F-BBA3-8412DAEC99B2}" = Bear Access Fall 2007

"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1AC38EA5-454C-4443-834F-6B34106581E1}" = Sony DVD Architect 4.0a

"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00

"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe

"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 15

"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter

"{2D6ED011-055B-4041-B198-BB903827EBFB}" = Safari

"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint

"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper

"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration

"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0

"{3248F0A8-6813-11D6-A77B-00B0D0150070}" = J2SE Runtime Environment 5.0 Update 7

"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01

"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA

"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant

"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2

"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central

"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0

"{565286F6-CE28-45D5-A64B-DCDCD3130881}" = Sony Media Manager 2.2

"{565F04D0-11FA-487E-8A92-F9D11CC011B3}" = VAIO Power Management

"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0

"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series

"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility

"{5960AB07-B02F-4158-8C97-3E13B85B2324}" = PyMOL (32 bit)

"{5B82682E-C555-45DA-8E2C-CE6525427AC9}" = Click to DVD 2.5.30

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype

Link to post
Share on other sites

Hi diver dan,

Welcome to the forum.

My nickname is deltalima and I will be helping you with your computer problems.

The logs can take some time to research, so please be patient with me.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Please note the following:

  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.

  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized

    [*]Please post the contents of these 2 Notepad files in your next reply.

Please download GMER Rootkit Scanner from here.

  • Double click the .exe file. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
  • Run Gmer again and click on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the "Scan" and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE

Important! Please do not select the "Show all" checkbox during the scan..

Please post the GMER log along with OTL.txt and Extras.txt from the OTL scan into your next reply.

OTL Extras logfile created on: 6/20/2010 9:12:57 PM - Run 1

OTL by OldTimer - Version 3.2.6.1 Folder = C:\Documents and Settings\Hannah Holmes\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free

4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 105.78 Gb Total Space | 66.72 Gb Free Space | 63.07% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

Drive F: | 61.83 Mb Total Space | 1.06 Mb Free Space | 1.72% Space Free | Partition Type: FAT

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: F52F2867C1364CC

Current User Name: Hannah Holmes

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.pif [@ = piffile] -- "%1" %*"

.scr [@ = Reg Error: Key error.] -- Reg Error: Key error. File not found

[HKEY_USERS\S-1-5-21-663187590-1649255284-3763627834-1006\SOFTWARE\Classes\<extension>]

.html [@ = htmlfile] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

piffile [open] -- "%1" %*"

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- Reg Error: Key error.

scrfile [install] -- Reg Error: Key error.

scrfile [open] -- Reg Error: Key error.

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"UpdatesDisableNotify" = 0

"AntiVirusOverride" = 0

"FirewallOverride" = 0

"UacDisableNotify" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 1

"DoNotAllowExceptions" = 0

"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Player Network Sharing Service

"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004

"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005

"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001

"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes -- (Apple Inc.)

"C:\WINDOWS\system32\LMabcoms.exe" = C:\WINDOWS\system32\LMabcoms.exe:*:Enabled:Lexmark Enhanced TCP/IP -- ( )

"C:\Program Files\Lexmark\ErrorApp\LMab1err.EXE" = C:\Program Files\Lexmark\ErrorApp\LMab1err.EXE:*:Enabled:Lexmark Status Messenger -- ( )

"C:\Program Files\AIM6\aim6.exe" = C:\Program Files\AIM6\aim6.exe:*:Disabled:AIM -- File not found

"C:\Program Files\Common Files\AOL\Loader\aolload.exe" = C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Disabled:AOL Loader -- File not found

"C:\Program Files\Common Files\AOL\1161282955\ee\aolsoftware.exe" = C:\Program Files\Common Files\AOL\1161282955\ee\aolsoftware.exe:*:Disabled:AOL Services -- File not found

"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.)

"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.)

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR

"{01FDC9FC-4D4F-4DB0-ACD1-D3E8E1D52902}" = Sony MP4 Shared Library

"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour

"{08C5815C-2C6E-44f8-8748-0E61BC9AFB68}" = Symantec KB-DocID:2003093015493306

"{0DF00135-D5A7-476A-BFB3-EDFF2840076A}" = VAIO Wireless LAN Setup Utility

"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView

"{11204BA5-626B-498F-BBA3-8412DAEC99B2}" = Bear Access Fall 2007

"{1417F599-1DBD-4499-9375-B2813E9F890C}" = VAIO Camera Utility

"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer

"{1AC38EA5-454C-4443-834F-6B34106581E1}" = Sony DVD Architect 4.0a

"{2063C2E8-3812-4BBD-9998-6610F80C1DD4}" = VAIO Media AC3 Decoder 1.0

"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer

"{23BE930B-6AC4-4D0D-B5C3-03062A2BF2A3}" = OpenMG AAC Add-on Module 1.0.00

"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe

"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java 6 Update 15

"{27337663-2619-11D4-99DC-0000F49094C7}" = Memory Stick Formatter

"{2D6ED011-055B-4041-B198-BB903827EBFB}" = Safari

"{2E8EAC71-BFE4-417A-88F0-5A1BDFBCF5D3}" = Logitech SetPoint

"{2EA7CF7E-0C76-44A5-B0CF-A1D171476E42}" = VAIO Breeze Wallpaper

"{315BA29D-2644-4760-B5FD-5AC04A52B8C5}" = VAIO Registration

"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0

"{3248F0A8-6813-11D6-A77B-00B0D0150070}" = J2SE Runtime Environment 5.0 Update 7

"{338F08AB-C262-42C7-B000-34DE1A475273}" = Ad-Aware Email Scanner for Outlook

"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP

"{3633BA28-67CE-4AC8-A677-3406CA84C3D8}" = OpenMG Secure Module 4.5.01

"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA

"{47D2103B-FD51-4017-9C20-DD408B17D726}" = Office 2003 Trial Assistant

"{48820099-ED7D-424B-890C-9A82EF00656D}" = VAIO Update 2

"{4E993095-28F2-4060-9101-99C1FD1195C0}" = VAIO Central

"{560F6B2E-F0DF-44E5-8190-A4A161F0E205}" = VAIO Media 5.0

"{565286F6-CE28-45D5-A64B-DCDCD3130881}" = Sony Media Manager 2.2

"{565F04D0-11FA-487E-8A92-F9D11CC011B3}" = VAIO Power Management

"{5855C127-1F20-404D-B7FB-1FD84D7EAB5E}" = VAIO Media Redistribution 5.0

"{59452470-A902-477F-9338-9B88101681BD}" = Setting Utility Series

"{5958CAC6-373E-402F-84FE-0A699AA920B9}" = LAN Setting Utility

"{5960AB07-B02F-4158-8C97-3E13B85B2324}" = PyMOL (32 bit)

"{5B82682E-C555-45DA-8E2C-CE6525427AC9}" = Click to DVD 2.5.30

"{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}" = Skype

Link to post
Share on other sites

Hi diver dan,

You posted Extras.txt twice.

Please post OTL.txt .

OTL logfile created on: 6/20/2010 9:12:57 PM - Run 1

OTL by OldTimer - Version 3.2.6.1 Folder = C:\Documents and Settings\Hannah Holmes\Desktop

Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.6001.18702)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 70.00% Memory free

4.00 Gb Paging File | 3.00 Gb Available in Paging File | 86.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 105.78 Gb Total Space | 66.72 Gb Free Space | 63.07% Space Free | Partition Type: NTFS

D: Drive not present or media not loaded

E: Drive not present or media not loaded

Drive F: | 61.83 Mb Total Space | 1.06 Mb Free Space | 1.72% Space Free | Partition Type: FAT

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: F52F2867C1364CC

Current User Name: Hannah Holmes

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: All users

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Hannah Holmes\Desktop\OTL.exe (OldTimer Tools)

PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)

PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)

PRC - C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

PRC - C:\Program Files\Lexmark\ErrorApp\LMab1err.EXE ( )

PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)

PRC - C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (Macrovision Corporation)

PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)

PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )

PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)

PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)

PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)

PRC - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)

========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Hannah Holmes\Desktop\OTL.exe (OldTimer Tools)

MOD - C:\WINDOWS\uliyukejubetov.dll ()

MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)

========== Win32 Services (SafeList) ==========

SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)

SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)

SRV - (lmab_device) -- C:\WINDOWS\System32\LMabcoms.exe ( )

SRV - (Symantec Core LC) -- C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()

SRV - (Viewpoint Manager Service) -- C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)

SRV - (VAIOMediaPlatform-IntegratedServer-AppServer) -- C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe (Sony Corporation)

SRV - (VAIOMediaPlatform-Mobile-Gateway) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe (Sony Corporation)

SRV - (VAIOMediaPlatform-IntegratedServer-UPnP) VAIO Media Integrated Server (UPnP) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe (Sony Corporation)

SRV - (VAIOMediaPlatform-IntegratedServer-HTTP) VAIO Media Integrated Server (HTTP) -- C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe (Sony Corporation)

SRV - (MSCSPTISRV) -- C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)

SRV - (PACSPTISVR) -- C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)

SRV - (SPTISRV) -- C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)

SRV - (VAIO Event Service) -- C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (Sony Corporation)

SRV - (Vcsw) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (Sony Corporation)

SRV - (S24EventMonitor) Intel® -- C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )

SRV - (EvtEng) Intel® -- C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)

SRV - (RegSrvc) Intel® -- C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)

SRV - (SmartWiService) -- C:\Program Files\Sony\SmartWi Connection Utility\SmartWiService.exe (Sony Electronics, Inc)

SRV - (VzFw) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (Sony Corporation)

SRV - (VzCdbSvc) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (Sony Corporation)

SRV - (VAIO Entertainment TV Device Arbitration Service) -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe (Sony Corporation)

SRV - (Image Converter video recording monitor for VAIO Entertainment) -- C:\Program Files\Sony\Image Converter 2\IcVzMon.exe (Sony Corporation)

SRV - (MSSQL$SONY_MEDIAMGR) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)

SRV - (SQLAgent$SONY_MEDIAMGR) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation)

========== Driver Services (SafeList) ==========

DRV - (AvgTdiX) -- C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)

DRV - (AvgMfx86) -- C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)

DRV - (AvgLdx86) -- C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)

DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)

DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)

DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)

DRV - (usbaudio) USB Audio Driver (WDM) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)

DRV - (HDAudBus) -- C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)

DRV - (LHidFilt) -- C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)

DRV - (LMouFilt) -- C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)

DRV - (symlcbrd) -- C:\WINDOWS\system32\drivers\symlcbrd.sys (Symantec Corporation)

DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)

DRV - (STHDA) -- C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)

DRV - (Tosrfbd) -- C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)

DRV - (Tosrfbnp) -- C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)

DRV - (TosRfSnd) Bluetooth Audio Device (WDM) -- C:\WINDOWS\system32\drivers\tosrfsnd.sys (TOSHIBA Corporation)

DRV - (SonyImgF) -- C:\WINDOWS\system32\drivers\SonyImgF.sys (Sony Corporation)

DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)

DRV - (w39n51) Intel® -- C:\WINDOWS\system32\drivers\w39n51.sys (Intel

Link to post
Share on other sites

Hi diver dan,

If the GMER scan fails to complete then please run this alternative scan.

Scan With RKUnHooker

  • Please Download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in a reply here.

Link to post
Share on other sites

Hi diver dan,

If the GMER scan fails to complete then please run this alternative scan.

Scan With RKUnHooker

  • Please Download Rootkit Unhooker Save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers, Stealth, Files, Code Hooks. Uncheck the rest. then Click OK.
  • Wait till the scanner has finished and then click File, Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in a reply here.

Hi,

I finally got the scan to run

GMER 1.0.15.15281 - http://www.gmer.net

Rootkit scan 2010-06-23 21:18:11

Windows 5.1.2600 Service Pack 3

Running: 7u086ve0.exe; Driver: C:\DOCUME~1\HANNAH~1\LOCALS~1\Temp\uxxyipog.sys

---- System - GMER 1.0.15 ----

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA11887E]

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA118BFE]

SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xB2487620]

---- Kernel code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\drivers\isapnp.sys entry point in ".rsrc" section [0xBA0B0014]

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB8542360, 0x22117D, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\WINDOWS\System32\svchost.exe[1256] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009A000A

.text C:\WINDOWS\System32\svchost.exe[1256] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009B000A

.text C:\WINDOWS\System32\svchost.exe[1256] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0099000C

.text C:\WINDOWS\System32\svchost.exe[1256] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00E0000A

.text C:\WINDOWS\system32\wuauclt.exe[2708] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 009A000A

.text C:\WINDOWS\system32\wuauclt.exe[2708] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009B000A

.text C:\WINDOWS\system32\wuauclt.exe[2708] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0099000C

.text C:\WINDOWS\Explorer.EXE[3696] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B7000A

.text C:\WINDOWS\Explorer.EXE[3696] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C1000A

.text C:\WINDOWS\Explorer.EXE[3696] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B6000C

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)

AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

AttachedDevice \Driver\Tcpip \Device\RawIp Lbd.sys (Boot Driver/Lavasoft AB)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)

Device Fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 8A860EC5

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp@LLInterface WANARP

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp@IpConfig Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}?Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\NdisWanIp@NumInterfaces 2

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@LLInterface

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@IpConfig Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0FCBA05C-5791-4205-A51B-7F98893153D1}@LLInterface

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{0FCBA05C-5791-4205-A51B-7F98893153D1}@IpConfig Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@LLInterface ARP1394

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@IpConfig Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@LLInterface ARP1394

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@IpConfig Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{48941C1B-94DD-4C18-86ED-171F051B51E5}@LLInterface

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{48941C1B-94DD-4C18-86ED-171F051B51E5}@IpConfig Tcpip\Parameters\Interfaces\{48941C1B-94DD-4C18-86ED-171F051B51E5}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{91EE9F29-0952-443D-8372-EC9550F5CE05}@LLInterface

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{91EE9F29-0952-443D-8372-EC9550F5CE05}@IpConfig Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{C95B3087-ECED-4B02-816C-E61B0F82BFE4}@LLInterface

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{C95B3087-ECED-4B02-816C-E61B0F82BFE4}@IpConfig Tcpip\Parameters\Interfaces\{C95B3087-ECED-4B02-816C-E61B0F82BFE4}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{D8317698-7046-4AF5-959E-817280B7E983}@LLInterface

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\{D8317698-7046-4AF5-959E-817280B7E983}@IpConfig Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@EnableDHCP 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@DefaultGatewayMetric

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@NameServer

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@Domain

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@RegistrationEnabled 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@RegisterAdapterName 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@TCPWindowSize 42300

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@NTEContextList

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@EnableDHCP 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@DefaultGatewayMetric

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@NameServer

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@Domain

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@RegistrationEnabled 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@RegisterAdapterName 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@NTEContextList 0x00000002?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@EnableDHCP 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@DefaultGatewayMetric

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@NameServer

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@Domain

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@RegistrationEnabled 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@RegisterAdapterName 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@EnableDHCP 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@DefaultGatewayMetric

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@NameServer

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@Domain

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@RegistrationEnabled 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@RegisterAdapterName 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@EnableDHCP 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@DefaultGatewayMetric

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@NameServer

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@Domain

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@RegistrationEnabled 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@RegisterAdapterName 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@NTEContextList 0x00000004?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@EnableDHCP 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@DontAddDefaultGateway 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@EnableDHCP 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@DefaultGatewayMetric

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@NameServer

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@Domain

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@RegistrationEnabled 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@RegisterAdapterName 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@NTEContextList

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@EnableDHCP 0

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@DefaultGateway

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@DontAddDefaultGateway 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\NdisWanIp@LLInterface WANARP

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\NdisWanIp@IpConfig Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}?Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\NdisWanIp@NumInterfaces 2

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@LLInterface

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@IpConfig Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{0FCBA05C-5791-4205-A51B-7F98893153D1}@LLInterface

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{0FCBA05C-5791-4205-A51B-7F98893153D1}@IpConfig Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@LLInterface ARP1394

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@IpConfig Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@LLInterface ARP1394

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@IpConfig Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{48941C1B-94DD-4C18-86ED-171F051B51E5}@LLInterface

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{48941C1B-94DD-4C18-86ED-171F051B51E5}@IpConfig Tcpip\Parameters\Interfaces\{48941C1B-94DD-4C18-86ED-171F051B51E5}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{91EE9F29-0952-443D-8372-EC9550F5CE05}@LLInterface

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{91EE9F29-0952-443D-8372-EC9550F5CE05}@IpConfig Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{C95B3087-ECED-4B02-816C-E61B0F82BFE4}@LLInterface

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{C95B3087-ECED-4B02-816C-E61B0F82BFE4}@IpConfig Tcpip\Parameters\Interfaces\{C95B3087-ECED-4B02-816C-E61B0F82BFE4}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{D8317698-7046-4AF5-959E-817280B7E983}@LLInterface

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Adapters\{D8317698-7046-4AF5-959E-817280B7E983}@IpConfig Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@EnableDHCP 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@DefaultGatewayMetric

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@NameServer

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@Domain

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@RegistrationEnabled 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@RegisterAdapterName 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@TCPWindowSize 42300

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0A0F2943-357B-47BD-9E33-6380CF6AE8E5}@NTEContextList

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@EnableDHCP 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@DefaultGatewayMetric

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@NameServer

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@Domain

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@RegistrationEnabled 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@RegisterAdapterName 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{0FCBA05C-5791-4205-A51B-7F98893153D1}@NTEContextList 0x00000002?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@EnableDHCP 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@DefaultGatewayMetric

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@NameServer

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@Domain

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@RegistrationEnabled 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@RegisterAdapterName 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{2773C201-AA10-436C-A25A-7FC3BBD9F3DC}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@EnableDHCP 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@DefaultGatewayMetric

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@NameServer

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@Domain

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@RegistrationEnabled 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@RegisterAdapterName 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{46655EF4-2254-4EF1-8258-2EE5234F4CBE}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@EnableDHCP 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@DefaultGatewayMetric

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@NameServer

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@Domain

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@RegistrationEnabled 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@RegisterAdapterName 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{91EE9F29-0952-443D-8372-EC9550F5CE05}@NTEContextList 0x00000004?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@EnableDHCP 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{C2EFDA04-24EC-4EE0-BD5D-C45CC8E1544A}@DontAddDefaultGateway 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@EnableDHCP 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@DefaultGatewayMetric

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@NameServer

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@Domain

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@RegistrationEnabled 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@RegisterAdapterName 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@TCPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@UDPAllowedPorts 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@RawIPAllowedProtocols 0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{D8317698-7046-4AF5-959E-817280B7E983}@NTEContextList

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@UseZeroBroadcast 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@EnableDHCP 0

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@IPAddress 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@SubnetMask 0.0.0.0?

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@DefaultGateway

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@EnableDeadGWDetect 1

Reg HKLM\SYSTEM\ControlSet003\Services\Tcpip\Parameters\Interfaces\{ED8775E3-4C9F-4583-84A4-0DACAAB18435}@DontAddDefaultGateway 0

Reg HKLM\SOFTWARE\Classes\.xaml\bootstrap@ bootstrap.xaml.1

Reg HKLM\SOFTWARE\Classes\.xbap\bootstrap@ bootstrap.xbap.1

Reg HKLM\SOFTWARE\Classes\.xps\bootstrap@ bootstrap.xps.1

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\drivers\isapnp.sys suspicious modification

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----

Link to post
Share on other sites

Hi diver dan,

TDSSKiller

  • Please Download TDSSKiller.exe and save it on your desktop.
  • Important!: only run this fix once.
  • Double click TDSSKiller.exe to run it.
  • a log file should be created on your C: drive named something like TDSSKiller.2.3.2.0 13.06.2010
  • To find the log click Start > Computer > C:.
  • Please post the contents of that log in your next reply.

Please let me know how the computer is running now.

Link to post
Share on other sites

Hi diver dan,

TDSSKiller

  • Please Download TDSSKiller.exe and save it on your desktop.
  • Important!: only run this fix once.
  • Double click TDSSKiller.exe to run it.
  • a log file should be created on your C: drive named something like TDSSKiller.2.3.2.0 13.06.2010
  • To find the log click Start > Computer > C:.
  • Please post the contents of that log in your next reply.

Please let me know how the computer is running now.

Hi,

I was just about to download tdsskiller and I am getting an error and I can not get onto the internet "Error running c:windows ksouinab.dll.

any ideas?

avg has quaranteened it

Link to post
Share on other sites

Hi,

I was just about to download tdsskiller and I am getting an error and I can not get onto the internet "Error running c:windows ksouinab.dll.

any ideas?

avg has quaranteened it

my bad iwas able to get on the internet and run tdsskiller and i can now get to windows updates which are now updating.

i will send you the log tonight.

thanks

Link to post
Share on other sites

Hi diver dan,

OK, good.

Thanks for the update.

Deltalima,

Can you show me what rootkit you identified.

I would like to learn for myself.

My business of computer repair is more of a hobby.

How does one get involved in Malwarebytes University or other such organizations.

The computer you were helping me with was a friends that I was working on at no charge.

that is how I originally started the business.

Thanks again,

Link to post
Share on other sites

Hi diver dan,

OK, good.

Thanks for the update.

Deltalima,

Can you show me what rootkit you identified.

I would like to learn for myself.

My business of computer repair is more of a hobby.

How does one get involved in Malwarebytes University or other such organizations.

The computer you were helping me with was a friends that I was working on at no charge.

that is how I originally started the business.

Thanks again,

Link to post
Share on other sites

Hi diver dan,

Before I answer your questions I would like to do a few further checks to make sure everything is clean.

Please re-open HijackThis and select Scan. Check the boxes next to all the entries listed below (if present):

O4 - HKCU\..\Run: [Fweyip] rundll32.exe "C:\WINDOWS\kSouinab.dll",Startup

Now close all other open windows and then click on Fix Checked. Close HijackThis.

Now reboot.

Malwarebytes Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and select then follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post that log in your next reply.

The log can also be found here:

  1. Launch Malwarebytes' Anti-Malware
  2. Click on the Logs radio tab.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Can you show me what rootkit you identified.

The rootkit is known as TDL3 or TDSS

See here for more information.

How does one get involved in Malwarebytes University or other such organizations.

There are several ways, please click on the UNITE link in my signature and follow the link to UNITE schools.

Link to post
Share on other sites

Hi diver dan,

Before I answer your questions I would like to do a few further checks to make sure everything is clean.

Please re-open HijackThis and select Scan. Check the boxes next to all the entries listed below (if present):

O4 - HKCU\..\Run: [Fweyip] rundll32.exe "C:\WINDOWS\kSouinab.dll",Startup

Now close all other open windows and then click on Fix Checked. Close HijackThis.

Now reboot.

Malwarebytes Anti-Malware

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and select then follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please post that log in your next reply.

The log can also be found here:

  1. Launch Malwarebytes' Anti-Malware
  2. Click on the Logs radio tab.

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

The rootkit is known as TDL3 or TDSS

See here for more information.

There are several ways, please click on the UNITE link in my signature and follow the link to UNITE schools.

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4235

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

6/24/2010 6:38:31 PM

mbam-log-2010-06-24 (18-38-31).txt

Scan type: Quick scan

Objects scanned: 140703

Time elapsed: 9 minute(s), 42 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 1

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

C:\Documents and Settings\Hannah Holmes\Local Settings\Temp\wzhtqeDHMa.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.

Link to post
Share on other sites

Hi diver dan,

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure

Remove GMER

Delete the GMER icon from your desktop, it will be named 7u086ve0.exe

Clean up with OTL

  • Double-click OTL.exe to start the program. This will remove all the tools we used to clean your pc.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CleanUp! button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Create a new, clean System Restore point which you can use in case of future system problems:

  • Press Start >> All Programs >> Accessories >>System Tools >> System Restore
  • Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close
  • Now remove old, infected System Restore points:
  • Next click Start >> Run and type cleanmgr in the box and press OK
  • Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
  • Select the More Options tab, under System Restore press Clean up... and say Yes to the prompt
  • Press OK and Yes to confirm

Update your AntiVirus Software and keep your other programs up-to-date

Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

You can use one of these sites to check if any updates are needed for your pc.

Secunia Software Inspector

F-secure Health Check

Security Updates for Windows, Internet Explorer & Microsoft Office

Whenever a security problem in its software is found, Microsoft will usually create a patch so that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC. Keeping up with these patches will help to prevent malicious software being installed on your PC. Ensure you are registered for Windows updates via Start > right-click on My Computer > Properties > Automatic Updates tab or visit the Microsoft Update site on a regular basis.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

Happy surfing and stay clean!

Link to post
Share on other sites

Hi diver dan,

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure

Remove GMER

Delete the GMER icon from your desktop, it will be named 7u086ve0.exe

Clean up with OTL

  • Double-click OTL.exe to start the program. This will remove all the tools we used to clean your pc.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CleanUp! button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Create a new, clean System Restore point which you can use in case of future system problems:

  • Press Start >> All Programs >> Accessories >>System Tools >> System Restore
  • Select Create a restore point, then Next, type a name like All Clean then press the Create button and once it's done press Close
  • Now remove old, infected System Restore points:
  • Next click Start >> Run and type cleanmgr in the box and press OK
  • Ensure the boxes for Recycle Bin, Temporary Files and Temporary Internet Files are checked, you can choose to check other boxes if you wish but they are not required.
  • Select the More Options tab, under System Restore press Clean up... and say Yes to the prompt
  • Press OK and Yes to confirm

Update your AntiVirus Software and keep your other programs up-to-date

Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

You can use one of these sites to check if any updates are needed for your pc.

Secunia Software Inspector

F-secure Health Check

Security Updates for Windows, Internet Explorer & Microsoft Office

Whenever a security problem in its software is found, Microsoft will usually create a patch so that after the patch is installed, attackers can't use the vulnerability to install malicious software on your PC. Keeping up with these patches will help to prevent malicious software being installed on your PC. Ensure you are registered for Windows updates via Start > right-click on My Computer > Properties > Automatic Updates tab or visit the Microsoft Update site on a regular basis.

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware

Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

Happy surfing and stay clean!

Deltalima,

I ran the microsoft pc scanner which found and could not remove the following.

trojian win32/hiloti.genid

c:\windows\uliyukejubetov.dll

do you know how to remove it?

thanks

Link to post
Share on other sites

Hi diver dan,

I ran the microsoft pc scanner which found and could not remove the following.

trojian win32/hiloti.genid

c:\windows\uliyukejubetov.dll

do you know how to remove it?

Run OTL Script

  • Double-click OTL.exe to start the program.
  • Copy and Paste the following code into the customFix.png textbox. Do not include the word Code
    :files
    c:\windows\uliyukejubetov.dll


  • Then click the Run Fix button at the top.
  • Click btnOK.png.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.