I have an ASUS M2V box with 2GB RAM and two 640GB SATA drives.
Note well: I have two Windows XP 640GB hard drives mirrored (backed up) every week.
The other day I suddenly got a spew of pop up error windows too fast to read and I lost Explorer so tried to reboot via Task Manager.
From then on however I could only get into Safe Mode regardless of what choice I made when booting via F8. i.e. boot 'normally' end up in safe mode _but_ with a Microsoft(?) warning about repairing the hard drive and downloading the program below - no program link BTW.
Uh. Oh! I thought ... a virus. Maybe.
So since I couldn't do anything I tried a repair from the Master CD.
First time I got a constant BSOD with dumping memory message.
Second time repair froze half way through installing hardware.
Copy of Master CD - maybe the original is broken.
Repair .. auto reboot then I get a constant loop of Windows loading bar, blank screen, reboot...
So I ran a hard drive surface check, all 640GB of it. No bad sectors found.
The mirror copy hard drive works fine. No hardware issues, (where am I writing this from?).
However this drive has the locked in Google Redirect virus plus possibly more. Maybe why my 'first' hard drive failed?
Note the redirect virus is not there in Safe mode.
So to attack one(?) problem at a time I followed the "UPDATED-8" instructions.
First the MalwareBytes log:
====================== Malwarebytes Log begin ===================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6001
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
09/03/2011 18:00:08
mbam-log-2011-03-09 (18-00-02).txt
Scan type: Full scan (C:\|D:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|M:\|N:\|)
Objects scanned: 681199
Time elapsed: 1 hour(s), 7 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 34
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
f:\documents and settings\Ye Boss\application data\thinstall\microsoft office professional edition 2003\1000000600002i\svchost.exe (Rootkit.Dropper) -> No action taken.
f:\documents and settings\Ye Boss\application data\thinstall\microsoft office professional edition 2003\1000000b00002i\rundll32.exe (Rootkit.Dropper) -> No action taken.
i:\program files\webposition\upgrade\damn_wpgold1309.exe (Trojan.Agent.CK) -> No action taken.
k:\documents and settings\Ye Boss\start menu\Programs\Startup\igfxtray.exe (Spyware.Passwords.XGen) -> No action taken.
k:\documents and settings\Ye Boss\application data\ntuser.dat (VirTool.Obfuscator) -> No action taken.
k:\documents and settings\Ye Boss\local settings\Temp\cdfss (Rootkit.Agent) -> No action taken.
k:\documents and settings\Ye Boss\local settings\Temp\internetexplorerupdate.exe (Trojan.Dropper) -> No action taken.
k:\documents and settings\Ye Boss\local settings\Temp\Lfz.exe (Trojan.Agent) -> No action taken.
====================== Malwarebytes Log end ===================
I'm puzzled with the "no action taken" and where some of the programs appeared from.
Now, GMER. Could not get it to complete. This morning after three hours I had a bunch of identical window pop up and the system almost locked up - no mouse but Tab still worked though screen capture would not or the "window" key. The messages were to the effect that the system was out of resources. Because I asked it to scan both hard drives?
BTW this was my second attempt - yesterday I ran in Safe mode without networking with the same result.
So I hand copied the screen messages:
====================== GMER messages begin ====================
SSDT pxsecsys(Prevx Realtime Analysis)\Prevx ZwTerminateProcess (0xB8 10A680)
.text F:\Windows\system32\DRIVERS\nv4_mini.sys Section is writeable (oxB6C82830, 0x5 ...
Device ACPI.sys(ACPI Driver for NT\mocroso ...
AttachedD.. \Filesystem\Fastfat\Fat fltmgr.sys(Microsoft Filesystem Filter ...
Reg HKCU\Software\Microsoft\Windows\CurretnVersion\Shell Extensio ...
Reg HKCU\Software\Microsoft\Windows\CurretnVersion\Shell Extensio ... 0x6A 0x61 0x6D 0x67 ...
Reg HKCU\Software\Microsoft\Windows\CurretnVersion\Shell Extensio ... 0x6A 0x61 0x6D 0x67 ...
====================== GMER messages end ====================
Then, whilst copying the above another window popped up:
(X) Windows was unable to save all the data for the file \Device\HarddiskVolume2\$mft. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere. [OK]
* Could not [OK] * Tab wouldn't highlight this icon.
And. Another window behind this one popped up telling me this "computer is locked..."
OK. Now the dds.scr logs:
1) DDS.TXT
.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by Ye Boss at 14:27:22.67 on 10/03/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1520 [GMT 0:00]
.
AV: Prevx 3.0 *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D901}
AV: Prevx 2.0 *Disabled/Updated* {557C3342-BC52-4508-AC25-4441BDF5C04C}
.
============== Running Processes ===============
.
F:\WINDOWS\system32\savedump.exe
F:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
F:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Mozilla Firefox\plugin-container.exe
G:\Program Files\KeePass Password Safe 2\KeePass.exe
F:\Documents and Settings\Ye Boss\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
mWinlogon: SFCDisable=-99 (0xffffff9d)
BHO: URLDetector Class: {55ea1964-f5e4-4d6a-b9b2-125b37655fcb} - f:\documents and settings\all users\application data\prevx\pxbho.dll
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {C6CEAC32-D45C-11D4-94AF-0050BABD5FD6} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{d593de91-7b41-45c2-830e-e9a99ab142aa}
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [SarbyxTrayClock] f:\program files\sarbyxtrayclock\trayclock.exe
mRun: [ClocX] f:\program files\clocx\ClocX.exe
mRun: [Atomic Time Synchronizer] "g:\program files\atsync\TimeSync.exe" /auto
mRun: [NvCplDaemon] RUNDLL32.EXE f:\windows\system32\NvCpl.dll,NvStartup
mRun: [KeePass 2 PreLoad] "g:\program files\keepass password safe 2\KeePass.exe" --preload
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: f:\docume~1\yeboss~1\startm~1\programs\startup\mailwa~1.lnk - f:\program files\mailwasher\MailWasher.exe
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: E&xport to Microsoft Excel - f:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: En&queue current page with Bulk Image Downloader - file://f:\program files\bulk image downloader\iemenu\iebidqueue.htm
IE: Enqueue link target with Bulk Ima&ge Downloader - file://f:\program files\bulk image downloader\iemenu\iebidlinkqueue.htm
IE: Open &link target with Bulk Image Downloader - file://f:\program files\bulk image downloader\iemenu\iebidlink.htm
IE: Open current page with Bulk I&mage Downloader - file://f:\program files\bulk image downloader\iemenu\iebid.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - f:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {00000161-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaud.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {0927A573-845C-4B80-9108-9BD2FA005E1D} = 195.74.113.58,195.74.113.62
TCP: {72049C5E-31B0-4E24-A4F7-527C9EED1463} = 8.8.8.8,8.8.4.4,154.32.109.18,154.32.105.18
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - f:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - f:\program files\coreftp\pftpns.dll
AppInit_DLLs: f:\progra~1\dvdgho~1\DVDGHO~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - f:\windows\system32\wpdshserviceobj.dll
LSA: Notification Packages = scecli wiesal.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "f:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC} - f:\program files\pixiepack codec pack\InstallerHelper.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - f:\docume~1\yeboss~1\applic~1\mozilla\firefox\profiles\b1gs52tz.default\
FF - prefs.js: browser.search.selectedEngine - Chambers (UK)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: f:\documents and settings\ye boss\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: f:\documents and settings\ye boss\local settings\application data\yahoo!\browserplus\2.9.2\plugins\npybrowserplus_2.9.2.dll
FF - plugin: f:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: f:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: f:\program files\logitech\harmony remote driver\NprtHarmonyPlugin.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npBBCPlugin.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: g:\program files\netscape6\nppl3260.dll
FF - plugin: g:\program files\netscape6\nprjplug.dll
FF - plugin: g:\program files\netscape6\nprpjplug.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - f:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - f:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Adblock Plus Pop-up Addon: adblockpopups@jessehakanen.net - %profile%\extensions\adblockpopups@jessehakanen.net
FF - Ext: Element Hiding Helper for Adblock Plus: elemhidehelper@adblockplus.org - %profile%\extensions\elemhidehelper@adblockplus.org
FF - Ext: KeeFox: keefox@chris.tomlinson - %profile%\extensions\keefox@chris.tomlinson
FF - Ext: MozRepl: mozrepl@hyperstruct.net - %profile%\extensions\mozrepl@hyperstruct.net
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com
.
============= SERVICES / DRIVERS ===============
.
R0 pxscan;pxscan;f:\windows\system32\drivers\pxscan.sys [2009-5-21 22024]
R0 pxsec;pxsec;f:\windows\system32\drivers\pxsec.sys [2009-5-21 27656]
R0 xfilt;VIA SATA IDE Hot-plug Driver;f:\windows\system32\drivers\xfilt.sys [2007-1-27 11264]
R1 Ext2fs;Ext2fs;f:\windows\system32\drivers\ext2fs.sys [2007-1-30 132736]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;f:\windows\system32\drivers\atl01_xp.sys [2007-1-27 35712]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;f:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248]
S1 IfsDrives;IfsDrives;f:\windows\system32\drivers\IfsDrives.sys [2007-1-30 4608]
S2 AtSync;Atomic Time Synchronizer;g:\program files\atsync\ats.exe [2009-11-6 433152]
S2 CSIScanner;CSIScanner;f:\program files\prevx\prevx.exe [2009-5-21 4368952]
S2 gupdate;Google Update Service (gupdate);f:\program files\google\update\GoogleUpdate.exe [2009-7-30 133104]
S2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;f:\windows\system32\plcndis5.sys [2004-5-17 17280]
S2 SSPORT;SSPORT;\??\f:\windows\system32\drivers\ssport.sys --> f:\windows\system32\drivers\SSPORT.sys [?]
S3 Asushwio;Asushwio;f:\windows\system32\drivers\ASUSHWIO.SYS [2006-11-2 5824]
S3 ATICDSDr;ATICDSDr;\??\f:\docume~1\yeboss~1\locals~1\temp\aticdsdr.sys --> f:\docume~1\yeboss~1\locals~1\temp\ATICDSDr.sys [?]
S3 AtiDCM;AtiDCM;\??\f:\documents and settings\ye boss\local settings\temp\atidcmxx.sys --> f:\documents and settings\ye boss\local settings\temp\atidcmxx.sys [?]
S3 GenericMount;Generic Mount Driver;f:\windows\system32\drivers\genericmount.sys --> f:\windows\system32\drivers\GenericMount.sys [?]
S3 NPF;NetGroup Packet Filter Driver;f:\windows\system32\drivers\npf.sys [2007-6-21 32512]
S3 PAC207;Trust WB-1200p Mini Webcam;f:\windows\system32\drivers\PFC027.sys [2005-2-24 162176]
S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;\??\f:\windows\system32\plcmpr5.sys --> f:\windows\system32\PLCMPR5.SYS [?]
S3 PsSdk30;PsSdk30;\??\f:\windows\system32\drivers\pssdk30.drv --> f:\windows\system32\drivers\PsSdk30.drv [?]
S3 SiwvidStart;SiwvidStart;\??\f:\docume~1\yeboss~1\locals~1\temp\_istmp4.dir\_istmp0.dir\siwvid.sys --> f:\docume~1\yeboss~1\locals~1\temp\_istmp4.dir\_istmp0.dir\siwvid.sys [?]
.
=============== File Associations ===============
.
JSEFile=NOTEPAD.EXE %1
txtfile="f:\program files\notepadbdv\Notepad.exe" "%1"
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2011-03-08 12:37:00 114944 ----a-r- f:\windows\system32\drivers\viamraid.sys
2011-03-08 09:17:42 12872 ----a-w- f:\windows\system32\bootdelete.exe
2011-03-08 09:12:14 16968 ----a-w- f:\windows\system32\drivers\hitmanpro35.sys
2011-03-08 09:12:03 -------- d-----w- f:\docume~1\alluse~1\applic~1\Hitman Pro
.
==================== Find3M ====================
.
2011-01-26 15:54:42 79360 --sha-r- f:\windows\system32\wmsdmoeu.dll
2011-01-26 15:49:47 74703 ----a-w- f:\windows\system32\mfc45.dll
2011-01-15 16:54:32 33019 ----a-w- f:\windows\system32\CoreAAC-uninstall.exe
2011-01-15 15:09:08 389120 ----a-w- f:\windows\system32\ACTSKN43.OCX
.
============= FINISH: 14:27:38.56 ===============
2) ATTACH.TXT but it says at the top:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
I have run previously TFC, Goored & HitmanPro in that order without success.
Note well: I have two Windows XP 640GB hard drives mirrored (backed up) every week.
The other day I suddenly got a spew of pop up error windows too fast to read and I lost Explorer so tried to reboot via Task Manager.
From then on however I could only get into Safe Mode regardless of what choice I made when booting via F8. i.e. boot 'normally' end up in safe mode _but_ with a Microsoft(?) warning about repairing the hard drive and downloading the program below - no program link BTW.
Uh. Oh! I thought ... a virus. Maybe.
So since I couldn't do anything I tried a repair from the Master CD.
First time I got a constant BSOD with dumping memory message.
Second time repair froze half way through installing hardware.
Copy of Master CD - maybe the original is broken.
Repair .. auto reboot then I get a constant loop of Windows loading bar, blank screen, reboot...
So I ran a hard drive surface check, all 640GB of it. No bad sectors found.
The mirror copy hard drive works fine. No hardware issues, (where am I writing this from?).
However this drive has the locked in Google Redirect virus plus possibly more. Maybe why my 'first' hard drive failed?
Note the redirect virus is not there in Safe mode.
So to attack one(?) problem at a time I followed the "UPDATED-8" instructions.
First the MalwareBytes log:
====================== Malwarebytes Log begin ===================
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6001
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
09/03/2011 18:00:08
mbam-log-2011-03-09 (18-00-02).txt
Scan type: Full scan (C:\|D:\|F:\|G:\|H:\|I:\|J:\|K:\|L:\|M:\|N:\|)
Objects scanned: 681199
Time elapsed: 1 hour(s), 7 minute(s), 37 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 34
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} (PUP.Dealio) -> No action taken.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
f:\documents and settings\Ye Boss\application data\thinstall\microsoft office professional edition 2003\1000000600002i\svchost.exe (Rootkit.Dropper) -> No action taken.
f:\documents and settings\Ye Boss\application data\thinstall\microsoft office professional edition 2003\1000000b00002i\rundll32.exe (Rootkit.Dropper) -> No action taken.
i:\program files\webposition\upgrade\damn_wpgold1309.exe (Trojan.Agent.CK) -> No action taken.
k:\documents and settings\Ye Boss\start menu\Programs\Startup\igfxtray.exe (Spyware.Passwords.XGen) -> No action taken.
k:\documents and settings\Ye Boss\application data\ntuser.dat (VirTool.Obfuscator) -> No action taken.
k:\documents and settings\Ye Boss\local settings\Temp\cdfss (Rootkit.Agent) -> No action taken.
k:\documents and settings\Ye Boss\local settings\Temp\internetexplorerupdate.exe (Trojan.Dropper) -> No action taken.
k:\documents and settings\Ye Boss\local settings\Temp\Lfz.exe (Trojan.Agent) -> No action taken.
====================== Malwarebytes Log end ===================
I'm puzzled with the "no action taken" and where some of the programs appeared from.
Now, GMER. Could not get it to complete. This morning after three hours I had a bunch of identical window pop up and the system almost locked up - no mouse but Tab still worked though screen capture would not or the "window" key. The messages were to the effect that the system was out of resources. Because I asked it to scan both hard drives?
BTW this was my second attempt - yesterday I ran in Safe mode without networking with the same result.
So I hand copied the screen messages:
====================== GMER messages begin ====================
SSDT pxsecsys(Prevx Realtime Analysis)\Prevx ZwTerminateProcess (0xB8 10A680)
.text F:\Windows\system32\DRIVERS\nv4_mini.sys Section is writeable (oxB6C82830, 0x5 ...
Device ACPI.sys(ACPI Driver for NT\mocroso ...
AttachedD.. \Filesystem\Fastfat\Fat fltmgr.sys(Microsoft Filesystem Filter ...
Reg HKCU\Software\Microsoft\Windows\CurretnVersion\Shell Extensio ...
Reg HKCU\Software\Microsoft\Windows\CurretnVersion\Shell Extensio ... 0x6A 0x61 0x6D 0x67 ...
Reg HKCU\Software\Microsoft\Windows\CurretnVersion\Shell Extensio ... 0x6A 0x61 0x6D 0x67 ...
====================== GMER messages end ====================
Then, whilst copying the above another window popped up:
(X) Windows was unable to save all the data for the file \Device\HarddiskVolume2\$mft. This error may be caused by a failure of your computer hardware or network connection. Please try to save this file elsewhere. [OK]
* Could not [OK] * Tab wouldn't highlight this icon.
And. Another window behind this one popped up telling me this "computer is locked..."
OK. Now the dds.scr logs:
1) DDS.TXT
.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by Ye Boss at 14:27:22.67 on 10/03/2011
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1520 [GMT 0:00]
.
AV: Prevx 3.0 *Enabled/Updated* {D486329C-1488-4CEB-9CC8-D662B732D901}
AV: Prevx 2.0 *Disabled/Updated* {557C3342-BC52-4508-AC25-4441BDF5C04C}
.
============== Running Processes ===============
.
F:\WINDOWS\system32\savedump.exe
F:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
F:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\Mozilla Firefox\plugin-container.exe
G:\Program Files\KeePass Password Safe 2\KeePass.exe
F:\Documents and Settings\Ye Boss\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
mWinlogon: SFCDisable=-99 (0xffffff9d)
BHO: URLDetector Class: {55ea1964-f5e4-4d6a-b9b2-125b37655fcb} - f:\documents and settings\all users\application data\prevx\pxbho.dll
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {C6CEAC32-D45C-11D4-94AF-0050BABD5FD6} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - f:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - f:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
{d593de91-7b41-45c2-830e-e9a99ab142aa}
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [SarbyxTrayClock] f:\program files\sarbyxtrayclock\trayclock.exe
mRun: [ClocX] f:\program files\clocx\ClocX.exe
mRun: [Atomic Time Synchronizer] "g:\program files\atsync\TimeSync.exe" /auto
mRun: [NvCplDaemon] RUNDLL32.EXE f:\windows\system32\NvCpl.dll,NvStartup
mRun: [KeePass 2 PreLoad] "g:\program files\keepass password safe 2\KeePass.exe" --preload
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRunOnce: [_nltide_2] regsvr32 /s /n /i:U shell32
dRunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe
StartupFolder: f:\docume~1\yeboss~1\startm~1\programs\startup\mailwa~1.lnk - f:\program files\mailwasher\MailWasher.exe
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: E&xport to Microsoft Excel - f:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: En&queue current page with Bulk Image Downloader - file://f:\program files\bulk image downloader\iemenu\iebidqueue.htm
IE: Enqueue link target with Bulk Ima&ge Downloader - file://f:\program files\bulk image downloader\iemenu\iebidlinkqueue.htm
IE: Open &link target with Bulk Image Downloader - file://f:\program files\bulk image downloader\iemenu\iebidlink.htm
IE: Open current page with Bulk I&mage Downloader - file://f:\program files\bulk image downloader\iemenu\iebid.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - f:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - f:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {00000161-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaud.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: {0927A573-845C-4B80-9108-9BD2FA005E1D} = 195.74.113.58,195.74.113.62
TCP: {72049C5E-31B0-4E24-A4F7-527C9EED1463} = 8.8.8.8,8.8.4.4,154.32.109.18,154.32.105.18
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - f:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - f:\program files\coreftp\pftpns.dll
AppInit_DLLs: f:\progra~1\dvdgho~1\DVDGHO~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - f:\windows\system32\wpdshserviceobj.dll
LSA: Notification Packages = scecli wiesal.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "f:\program files\common files\lightscribe\LSRunOnce.exe"
mASetup: {B2C3BB6B-E005-4246-B8E5-DF0A4D073CDC} - f:\program files\pixiepack codec pack\InstallerHelper.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - f:\docume~1\yeboss~1\applic~1\mozilla\firefox\profiles\b1gs52tz.default\
FF - prefs.js: browser.search.selectedEngine - Chambers (UK)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - plugin: f:\documents and settings\ye boss\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: f:\documents and settings\ye boss\local settings\application data\yahoo!\browserplus\2.9.2\plugins\npybrowserplus_2.9.2.dll
FF - plugin: f:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: f:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: f:\program files\logitech\harmony remote driver\NprtHarmonyPlugin.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npagent.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npBBCPlugin.dll
FF - plugin: f:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - plugin: g:\program files\netscape6\nppl3260.dll
FF - plugin: g:\program files\netscape6\nprjplug.dll
FF - plugin: g:\program files\netscape6\nprpjplug.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - f:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - f:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - f:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Adblock Plus Pop-up Addon: adblockpopups@jessehakanen.net - %profile%\extensions\adblockpopups@jessehakanen.net
FF - Ext: Element Hiding Helper for Adblock Plus: elemhidehelper@adblockplus.org - %profile%\extensions\elemhidehelper@adblockplus.org
FF - Ext: KeeFox: keefox@chris.tomlinson - %profile%\extensions\keefox@chris.tomlinson
FF - Ext: MozRepl: mozrepl@hyperstruct.net - %profile%\extensions\mozrepl@hyperstruct.net
FF - Ext: British English Dictionary: en-GB@dictionaries.addons.mozilla.org - %profile%\extensions\en-GB@dictionaries.addons.mozilla.org
FF - Ext: FastestFox: smarterwiki@wikiatic.com - %profile%\extensions\smarterwiki@wikiatic.com
.
============= SERVICES / DRIVERS ===============
.
R0 pxscan;pxscan;f:\windows\system32\drivers\pxscan.sys [2009-5-21 22024]
R0 pxsec;pxsec;f:\windows\system32\drivers\pxsec.sys [2009-5-21 27656]
R0 xfilt;VIA SATA IDE Hot-plug Driver;f:\windows\system32\drivers\xfilt.sys [2007-1-27 11264]
R1 Ext2fs;Ext2fs;f:\windows\system32\drivers\ext2fs.sys [2007-1-30 132736]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;f:\windows\system32\drivers\atl01_xp.sys [2007-1-27 35712]
R3 nvoclock;NVIDIA Enthusiasts Platform KDM;f:\windows\system32\drivers\nvoclock.sys [2009-9-15 38248]
S1 IfsDrives;IfsDrives;f:\windows\system32\drivers\IfsDrives.sys [2007-1-30 4608]
S2 AtSync;Atomic Time Synchronizer;g:\program files\atsync\ats.exe [2009-11-6 433152]
S2 CSIScanner;CSIScanner;f:\program files\prevx\prevx.exe [2009-5-21 4368952]
S2 gupdate;Google Update Service (gupdate);f:\program files\google\update\GoogleUpdate.exe [2009-7-30 133104]
S2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;f:\windows\system32\plcndis5.sys [2004-5-17 17280]
S2 SSPORT;SSPORT;\??\f:\windows\system32\drivers\ssport.sys --> f:\windows\system32\drivers\SSPORT.sys [?]
S3 Asushwio;Asushwio;f:\windows\system32\drivers\ASUSHWIO.SYS [2006-11-2 5824]
S3 ATICDSDr;ATICDSDr;\??\f:\docume~1\yeboss~1\locals~1\temp\aticdsdr.sys --> f:\docume~1\yeboss~1\locals~1\temp\ATICDSDr.sys [?]
S3 AtiDCM;AtiDCM;\??\f:\documents and settings\ye boss\local settings\temp\atidcmxx.sys --> f:\documents and settings\ye boss\local settings\temp\atidcmxx.sys [?]
S3 GenericMount;Generic Mount Driver;f:\windows\system32\drivers\genericmount.sys --> f:\windows\system32\drivers\GenericMount.sys [?]
S3 NPF;NetGroup Packet Filter Driver;f:\windows\system32\drivers\npf.sys [2007-6-21 32512]
S3 PAC207;Trust WB-1200p Mini Webcam;f:\windows\system32\drivers\PFC027.sys [2005-2-24 162176]
S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;\??\f:\windows\system32\plcmpr5.sys --> f:\windows\system32\PLCMPR5.SYS [?]
S3 PsSdk30;PsSdk30;\??\f:\windows\system32\drivers\pssdk30.drv --> f:\windows\system32\drivers\PsSdk30.drv [?]
S3 SiwvidStart;SiwvidStart;\??\f:\docume~1\yeboss~1\locals~1\temp\_istmp4.dir\_istmp0.dir\siwvid.sys --> f:\docume~1\yeboss~1\locals~1\temp\_istmp4.dir\_istmp0.dir\siwvid.sys [?]
.
=============== File Associations ===============
.
JSEFile=NOTEPAD.EXE %1
txtfile="f:\program files\notepadbdv\Notepad.exe" "%1"
VBEFile=NOTEPAD.EXE %1
VBSFile=NOTEPAD.EXE %1
regfile\shell\edit\command=%SystemRoot%\system32\NOTEPAD.EXE %1
.
=============== Created Last 30 ================
.
2011-03-08 12:37:00 114944 ----a-r- f:\windows\system32\drivers\viamraid.sys
2011-03-08 09:17:42 12872 ----a-w- f:\windows\system32\bootdelete.exe
2011-03-08 09:12:14 16968 ----a-w- f:\windows\system32\drivers\hitmanpro35.sys
2011-03-08 09:12:03 -------- d-----w- f:\docume~1\alluse~1\applic~1\Hitman Pro
.
==================== Find3M ====================
.
2011-01-26 15:54:42 79360 --sha-r- f:\windows\system32\wmsdmoeu.dll
2011-01-26 15:49:47 74703 ----a-w- f:\windows\system32\mfc45.dll
2011-01-15 16:54:32 33019 ----a-w- f:\windows\system32\CoreAAC-uninstall.exe
2011-01-15 15:09:08 389120 ----a-w- f:\windows\system32\ACTSKN43.OCX
.
============= FINISH: 14:27:38.56 ===============
2) ATTACH.TXT but it says at the top:
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
I have run previously TFC, Goored & HitmanPro in that order without success.