Resolved [Incurable- Ramnit]W32/infector.gen2 - help please

Status
Not open for further replies.
My laptop is badly infected with what Avira says is w32/infector.gen2. Loads of files are coming up infected and when I delete they just seem to come back. I think another computer of mine has been infected also by using a USB stick - but will start with this computer!

As per instuctions I have run TFC and then Malware bytes. Please find Malware bytes log below although it didn't seem to detect much.

I was unable to run GMER scan in normal of safe mode. When I tried the computer just kept freezing.

I ran DDS and will post files in next post.

Many thanks for your help in advance - this has been driving me crazy.

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4880

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

19/10/2010 20:59:58
mbam-log-2010-10-19 (20-59-58).txt

Scan type: Quick scan
Objects scanned: 155725
Time elapsed: 30 minute(s), 44 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\program files\microsoft\desktoplayer.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Program Files\Microsoft\desktoplayer.exe (Trojan.Agent) -> Delete on reboot.
 
DDS.text log:

DDS (Ver_10-10-10.03) - NTFSx86
Run by TRISH at 22:13:21.64 on 19/10/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.759.391 [GMT 1:00]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\O2\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\TRISH\Desktop\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 6.0\acrobat\activex\AcroIEHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: @c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ZumoCast] c:\program files\zecter\zumocast\ZumoLauncher.lnk
uRun: [{AE2C0284-B143-82F2-F8FC-47A0386F36E3}] "c:\documents and settings\trish\application data\qyegax\atsei.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1423.0\mswinext.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
dRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
StartupFolder: c:\docume~1\trish\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\trish\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\adobe acrobat 6.0\distillr\acrotray.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.keepandshare.com/imageuploader5.7.24/ImageUploader5.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195314469937
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://mymicron.webex.com/client/T26L/support/ieatgpc.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SecurityProviders: msapsspc.dll, schannel.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\trish\applic~1\mozilla\firefox\profiles\4tillcx1.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-10-19 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-10-19 135336]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-10-19 267432]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-10-19 60936]
R2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\o2\bin\sprtsvc.exe [2009-3-4 202016]
S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-10-30 819352]
S4 W3s4avadtn;W3s4avadtn; [x]

=============== Created Last 30 ================

2010-10-19 18:08:50 -------- d-----w- c:\windows\system32\NtmsData
2010-10-19 12:50:47 -------- d-----w- c:\docume~1\trish\applic~1\Avira
2010-10-19 12:25:07 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-10-19 12:24:10 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2010-10-19 12:24:09 -------- d-----w- c:\program files\Avira
2010-10-15 08:23:22 -------- d-----w- c:\program files\Glary Utilities
2010-10-15 08:10:23 -------- d-----w- c:\program files\ParetoLogic
2010-10-14 22:42:39 -------- d-----w- C:\2f1ce92aa3cd00ef711f64a73573ac13
2010-10-14 15:20:36 -------- d-sh--w- c:\documents and settings\trish\PrivacIE
2010-10-14 14:38:27 -------- d-sh--w- c:\documents and settings\trish\IETldCache
2010-10-14 14:31:36 -------- dc-h--w- c:\windows\ie8
2010-10-14 14:11:30 -------- d-----w- C:\20952e15856179802d
2010-10-14 12:26:19 10129408 ----a-w- c:\windows\system32\dllcache\hwxkor.dll
2010-10-14 12:25:47 13463552 ----a-w- c:\windows\system32\dllcache\hwxjpn.dll
2010-10-14 12:25:16 10096640 ----a-w- c:\windows\system32\dllcache\hwxcht.dll
2010-10-13 18:26:28 -------- d-----w- C:\6a7ab4c99f45b7dad4d939
2010-10-13 18:11:21 -------- d-----w- C:\7530b664779eb3c04f7fcd0ac87d
2010-10-13 10:21:25 -------- d-----w- c:\docume~1\trish\locals~1\applic~1\Help
2010-10-13 09:48:41 388608 ----a-w- c:\windows\system32\CF27382.exe
2010-10-12 11:31:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-10-12 11:31:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-10-12 11:31:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-10-12 10:49:31 1033216 ----a-w- c:\windows\alex.exe
2010-10-12 09:59:42 -------- d-----w- c:\program files\msn gaming zone
2010-10-11 13:20:05 -------- d-----w- c:\program files\MSN Toolbar
2010-10-11 13:18:06 -------- d-----w- c:\program files\Unlocker
2010-10-11 13:17:56 -------- d-----w- c:\program files\Bing Bar Installer
2010-10-11 09:37:08 -------- d-----w- c:\program files\CCleaner
2010-10-11 06:49:03 -------- d-----w- c:\program files\Defraggler
2010-10-10 20:20:02 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2010-10-10 20:19:57 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2010-10-10 20:19:51 17408 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2010-10-10 20:19:46 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2010-10-10 20:19:37 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2010-10-10 20:19:18 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2010-10-10 20:18:29 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2010-10-10 20:18:25 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2010-10-10 20:18:12 19328 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
2010-10-10 20:18:00 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2010-10-10 20:17:58 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2010-10-10 20:16:31 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2010-10-10 20:16:23 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2010-10-10 20:16:18 34890 ----a-w- c:\windows\system32\dllcache\wlandrv2.sys
2010-10-10 20:15:42 771581 ----a-w- c:\windows\system32\dllcache\winacisa.sys
2010-10-10 20:15:22 53760 ----a-w- c:\windows\system32\dllcache\wiamsmud.dll
2010-10-10 20:15:15 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
2010-10-10 20:15:13 31232 ----a-w- c:\windows\system32\dllcache\weitekp9.sys
2010-10-10 20:15:12 41600 ----a-w- c:\windows\system32\dllcache\weitekp9.dll
2010-10-10 20:15:01 701386 ----a-w- c:\windows\system32\dllcache\wdhaalba.sys
2010-10-10 20:13:55 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
2010-10-10 20:13:54 86073 ----a-w- c:\windows\system32\dllcache\voicesub.dll
2010-10-10 20:13:52 426041 ----a-w- c:\windows\system32\dllcache\voicepad.dll
2010-10-10 20:13:47 604253 ----a-w- c:\windows\system32\dllcache\vmodem.sys
2010-10-10 20:13:39 249402 ----a-w- c:\windows\system32\dllcache\vinwm.sys
2010-10-10 20:13:31 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
2010-10-10 20:13:25 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
2010-10-10 20:13:20 11325 ----a-w- c:\windows\system32\dllcache\vchnt5.dll
2010-10-10 20:13:11 687999 ----a-w- c:\windows\system32\dllcache\usrwdxjs.sys
2010-10-10 20:13:03 765884 ----a-w- c:\windows\system32\dllcache\usrti.sys
2010-10-10 20:12:55 113762 ----a-w- c:\windows\system32\dllcache\usrpda.sys
2010-10-10 20:12:49 7556 ----a-w- c:\windows\system32\dllcache\usroslba.sys
2010-10-10 20:12:38 224802 ----a-w- c:\windows\system32\dllcache\usr1807a.sys
2010-10-10 20:12:32 794399 ----a-w- c:\windows\system32\dllcache\usr1806v.sys
2010-10-10 20:12:25 793598 ----a-w- c:\windows\system32\dllcache\usr1806.sys
2010-10-10 20:12:19 794654 ----a-w- c:\windows\system32\dllcache\usr1801.sys
2010-10-10 20:12:13 78464 ----a-w- c:\windows\system32\dllcache\usbvideo.sys
2010-10-10 20:12:11 25600 ----a-w- c:\windows\system32\dllcache\usbser.sys
2010-10-10 20:12:07 17024 ----a-w- c:\windows\system32\dllcache\usbohci.sys
2010-10-10 20:12:06 31616 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
2010-10-10 20:12:03 59264 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-10-10 20:12:01 12672 ----a-w- c:\windows\system32\dllcache\usb8023x.sys
2010-10-10 20:11:59 32384 ----a-w- c:\windows\system32\dllcache\usb101et.sys
2010-10-10 20:11:48 76288 ----a-w- c:\windows\system32\dllcache\uniime.dll
2010-10-10 20:11:40 94720 ----a-w- c:\windows\system32\dllcache\umaxud32.dll
2010-10-10 20:11:35 28160 ----a-w- c:\windows\system32\dllcache\umaxu40.dll
2010-10-10 20:11:30 26624 ----a-w- c:\windows\system32\dllcache\umaxu22.dll
2010-10-10 20:11:24 69632 ----a-w- c:\windows\system32\dllcache\umaxu12.dll
2010-10-10 20:11:18 50688 ----a-w- c:\windows\system32\dllcache\umaxscan.dll
2010-10-10 20:11:13 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys
2010-10-10 20:11:08 50176 ----a-w- c:\windows\system32\dllcache\umaxp60.dll
2010-10-10 20:11:02 47616 ----a-w- c:\windows\system32\dllcache\umaxcam.dll
2010-10-10 20:10:55 211968 ----a-w- c:\windows\system32\dllcache\um54scan.dll
2010-10-10 20:10:49 216064 ----a-w- c:\windows\system32\dllcache\um34scan.dll
2010-10-10 20:10:41 44672 ----a-w- c:\windows\system32\dllcache\uagp35.sys
2010-10-10 20:10:34 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
2010-10-10 20:10:31 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
2010-10-10 20:10:16 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys
2010-10-10 20:10:11 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
2010-10-10 20:10:04 159232 ----a-w- c:\windows\system32\dllcache\tridkbm.sys
2010-10-10 20:09:58 440576 ----a-w- c:\windows\system32\dllcache\tridkb.dll
2010-10-10 20:09:53 222336 ----a-w- c:\windows\system32\dllcache\trid3dm.sys
2010-10-10 20:09:47 315520 ----a-w- c:\windows\system32\dllcache\trid3d.dll
2010-10-10 20:09:40 34375 ----a-w- c:\windows\system32\dllcache\tpro4.sys
2010-10-10 20:09:35 42496 ----a-w- c:\windows\system32\dllcache\tp4res.dll
2010-10-10 20:09:33 82432 ----a-w- c:\windows\system32\dllcache\tp4mon.exe
2010-10-10 20:09:28 31744 ----a-w- c:\windows\system32\dllcache\tp4.dll
2010-10-10 20:09:10 230912 ----a-w- c:\windows\system32\dllcache\tosdvd03.sys
2010-10-10 20:09:04 241664 ----a-w- c:\windows\system32\dllcache\tosdvd02.sys
2010-10-10 20:07:51 30464 ----a-w- c:\windows\system32\dllcache\tbatm155.sys
2010-10-10 20:07:39 7040 ----a-w- c:\windows\system32\dllcache\tandqic.sys
2010-10-10 20:07:34 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
2010-10-10 20:07:28 172768 ----a-w- c:\windows\system32\dllcache\t2r4disp.dll
2010-10-10 20:07:07 94293 ----a-w- c:\windows\system32\dllcache\sxports.dll
2010-10-10 20:07:03 103936 ----a-w- c:\windows\system32\dllcache\sx.sys
2010-10-10 20:06:58 3968 ----a-w- c:\windows\system32\dllcache\swusbflt.sys
2010-10-10 20:06:53 10240 ----a-w- c:\windows\system32\dllcache\swpidflt.dll
2010-10-10 20:06:48 10240 ----a-w- c:\windows\system32\dllcache\swpdflt2.dll
2010-10-10 20:06:43 53760 ----a-w- c:\windows\system32\dllcache\sw_wheel.dll
2010-10-10 20:06:38 41472 ----a-w- c:\windows\system32\dllcache\sw_effct.dll
2010-10-10 20:06:30 15360 ----a-w- c:\windows\system32\dllcache\streamip.sys
2010-10-10 20:06:23 155648 ----a-w- c:\windows\system32\dllcache\stlnprop.dll
2010-10-10 20:06:17 53248 ----a-w- c:\windows\system32\dllcache\stlncoin.dll
2010-10-10 20:06:12 285760 ----a-w- c:\windows\system32\dllcache\stlnata.sys
2010-10-10 20:05:30 16896 ----a-w- c:\windows\system32\dllcache\stcusb.sys
2010-10-10 20:04:39 48736 ----a-w- c:\windows\system32\dllcache\srwlnd5.sys
2010-10-10 20:03:51 99328 ----a-w- c:\windows\system32\dllcache\srusd.dll
2010-10-10 20:03:49 101376 ----a-w- c:\windows\system32\dllcache\srusbusd.dll
2010-10-10 20:03:02 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2010-10-10 20:02:09 61824 ----a-w- c:\windows\system32\dllcache\speed.sys
2010-10-10 20:01:33 106584 ----a-w- c:\windows\system32\dllcache\spdports.dll
2010-10-10 20:00:55 7552 ----a-w- c:\windows\system32\dllcache\sonypvu1.sys
2010-10-10 20:00:19 37040 ----a-w- c:\windows\system32\dllcache\sonypi.sys
2010-10-10 19:59:42 114688 ----a-w- c:\windows\system32\dllcache\sonypi.dll
2010-10-10 19:59:05 20752 ----a-w- c:\windows\system32\dllcache\sonync.sys
2010-10-10 19:58:29 9600 ----a-w- c:\windows\system32\dllcache\sonymc.sys
2010-10-10 19:58:26 7552 ----a-w- c:\windows\system32\dllcache\sonyait.sys
2010-10-10 19:58:25 143422 ----a-w- c:\windows\system32\dllcache\softkey.dll
2010-10-10 19:56:29 147200 ----a-w- c:\windows\system32\dllcache\smidispb.dll
2010-10-10 19:56:27 236544 ----a-w- c:\windows\system32\dllcache\smi2smir.exe
2010-10-10 19:55:52 25034 ----a-w- c:\windows\system32\dllcache\smcpwr2n.sys
2010-10-10 19:55:16 35913 ----a-w- c:\windows\system32\dllcache\smcirda.sys
2010-10-10 19:54:40 24576 ----a-w- c:\windows\system32\dllcache\smc8000n.sys
2010-10-10 19:54:04 6784 ----a-w- c:\windows\system32\dllcache\smbhc.sys
2010-10-10 19:54:00 6912 ----a-w- c:\windows\system32\dllcache\smbclass.sys
2010-10-10 19:53:59 16128 ----a-w- c:\windows\system32\dllcache\smbbatt.sys
2010-10-10 19:53:54 6016 ----a-w- c:\windows\system32\dllcache\smbali.sys
2010-10-10 19:53:54 31744 ----a-w- c:\windows\system32\dllcache\smb6w.dll
2010-10-10 19:53:10 45568 ----a-w- c:\windows\system32\dllcache\smb3w.dll
2010-10-10 19:52:25 33792 ----a-w- c:\windows\system32\dllcache\smb0w.dll
2010-10-10 19:52:24 31744 ----a-w- c:\windows\system32\dllcache\sma3w.dll
2010-10-10 19:51:43 28672 ----a-w- c:\windows\system32\dllcache\sma0w.dll
2010-10-10 19:51:42 38912 ----a-w- c:\windows\system32\dllcache\sm9aw.dll
2010-10-10 19:51:41 26624 ----a-w- c:\windows\system32\dllcache\sm93w.dll
2010-10-10 19:51:41 26624 ----a-w- c:\windows\system32\dllcache\sm92w.dll
2010-10-10 19:51:01 28160 ----a-w- c:\windows\system32\dllcache\sm91w.dll
2010-10-10 19:51:00 26112 ----a-w- c:\windows\system32\dllcache\sm90w.dll
2010-10-10 19:51:00 26112 ----a-w- c:\windows\system32\dllcache\sm8dw.dll
2010-10-10 19:49:43 50432 ----a-w- c:\windows\system32\dllcache\sisv.sys
2010-10-10 19:49:32 32768 ----a-w- c:\windows\system32\dllcache\sisnic.sys
2010-10-10 19:49:27 238592 ----a-w- c:\windows\system32\dllcache\sisgrv.dll
2010-10-10 19:49:23 104064 ----a-w- c:\windows\system32\dllcache\sisgrp.sys
2010-10-10 19:49:19 150144 ----a-w- c:\windows\system32\dllcache\sis6306v.dll
2010-10-10 19:49:15 68608 ----a-w- c:\windows\system32\dllcache\sis6306p.sys
2010-10-10 19:49:11 252032 ----a-w- c:\windows\system32\dllcache\sis300iv.dll
2010-10-10 19:48:31 101760 ----a-w- c:\windows\system32\dllcache\sis300ip.sys
2010-10-10 19:48:30 18944 ----a-w- c:\windows\system32\dllcache\simptcp.dll
2010-10-10 19:48:24 3901 ----a-w- c:\windows\system32\dllcache\siint5.dll
2010-10-10 19:47:36 161568 ----a-w- c:\windows\system32\dllcache\sgsmusb.sys
2010-10-10 19:47:32 18400 ----a-w- c:\windows\system32\dllcache\sgsmld.sys
2010-10-10 19:47:28 98080 ----a-w- c:\windows\system32\dllcache\sgiulnt5.sys
2010-10-10 19:47:24 386560 ----a-w- c:\windows\system32\dllcache\sgiul50.dll
2010-10-10 19:47:19 36480 ----a-w- c:\windows\system32\dllcache\sfmanm.sys
2010-10-10 19:47:08 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
2010-10-10 19:47:04 17664 ----a-w- c:\windows\system32\dllcache\sermouse.sys
2010-10-10 19:47:02 26112 ----a-w- c:\windows\system32\dllcache\EXCH_seos.dll
2010-10-10 19:45:58 198400 ----a-w- c:\windows\system32\dllcache\s3sav4.dll
2010-10-10 19:44:56 30720 ----a-w- c:\windows\system32\dllcache\rthwcls.sys
2010-10-10 19:44:50 9216 ----a-w- c:\windows\system32\dllcache\rsmgrstr.dll
2010-10-10 19:44:45 3840 ----a-w- c:\windows\system32\dllcache\rpfun.sys
2010-10-10 19:44:40 79104 ----a-w- c:\windows\system32\dllcache\rocket.sys
2010-10-10 19:44:39 30080 ----a-w- c:\windows\system32\dllcache\rndismpx.sys
2010-10-10 19:44:34 37563 ----a-w- c:\windows\system32\dllcache\rlnet5.sys
2010-10-10 19:44:27 59648 ----a-w- c:\windows\system32\dllcache\rfcomm.sys
2010-10-10 19:44:23 86097 ----a-w- c:\windows\system32\dllcache\reslog32.dll
2010-10-10 19:44:20 23040 ----a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
2010-10-10 19:44:19 14848 ----a-w- c:\windows\system32\dllcache\register.exe
2010-10-10 19:44:10 13776 ----a-w- c:\windows\system32\dllcache\recagent.sys
2010-10-10 19:43:56 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys
2010-10-10 19:43:52 20736 ----a-w- c:\windows\system32\dllcache\ramdisk.sys
2010-10-10 19:43:47 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
2010-10-10 19:43:41 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
2010-10-10 19:43:35 41472 ----a-w- c:\windows\system32\dllcache\qvusd.dll
2010-10-10 19:43:24 3328 ----a-w- c:\windows\system32\dllcache\qv2kux.sys
2010-10-10 19:43:22 16384 ----a-w- c:\windows\system32\dllcache\quser.exe
2010-10-10 19:43:19 9728 ----a-w- c:\windows\system32\dllcache\query.exe
2010-10-10 19:43:04 6016 ----a-w- c:\windows\system32\dllcache\qic157.sys
2010-10-10 19:42:53 130942 ----a-w- c:\windows\system32\dllcache\ptserlv.sys
2010-10-10 19:42:48 112574 ----a-w- c:\windows\system32\dllcache\ptserlp.sys
2010-10-10 19:42:44 128286 ----a-w- c:\windows\system32\dllcache\ptserli.sys
2010-10-10 19:42:38 159232 ----a-w- c:\windows\system32\dllcache\ptpusd.dll
2010-10-10 19:42:33 5632 ----a-w- c:\windows\system32\dllcache\ptpusb.dll
2010-10-10 19:42:27 35328 ----a-w- c:\windows\system32\dllcache\psisload.dll
2010-10-10 19:42:19 363520 ----a-w- c:\windows\system32\dllcache\psisdecd.dll
2010-10-10 19:42:14 16128 ----a-w- c:\windows\system32\dllcache\pscr.sys
2010-10-10 19:42:07 17664 ----a-w- c:\windows\system32\dllcache\ppa3.sys
2010-10-10 19:42:03 17792 ----a-w- c:\windows\system32\dllcache\ppa.sys
2010-10-10 19:40:57 86016 ----a-w- c:\windows\system32\dllcache\pctspk.exe
2010-10-10 19:39:59 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
2010-10-10 19:39:55 31872 ----a-w- c:\windows\system32\dllcache\ovce.sys
2010-10-10 19:39:51 28032 ----a-w- c:\windows\system32\dllcache\ovcd.sys
2010-10-10 19:39:47 48000 ----a-w- c:\windows\system32\dllcache\ovcam2.sys
2010-10-10 19:39:44 25088 ----a-w- c:\windows\system32\dllcache\ovca.sys
2010-10-10 19:39:39 54186 ----a-w- c:\windows\system32\dllcache\otcsercb.sys
2010-10-10 19:39:36 43689 ----a-w- c:\windows\system32\dllcache\otceth5.sys
2010-10-10 19:39:31 27209 ----a-w- c:\windows\system32\dllcache\otc06x5.sys
2010-10-10 19:39:25 54528 ----a-w- c:\windows\system32\dllcache\opl3sax.sys
2010-10-10 19:38:53 198144 ----a-w- c:\windows\system32\dllcache\nv3.sys
2010-10-10 19:38:49 123776 ----a-w- c:\windows\system32\dllcache\nv3.dll
2010-10-10 19:38:45 180360 ----a-w- c:\windows\system32\dllcache\ntmtlfax.sys
2010-10-10 19:38:20 51552 ----a-w- c:\windows\system32\dllcache\ntgrip.sys
2010-10-10 19:38:20 38912 ----a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
2010-10-10 19:38:12 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
2010-10-10 19:38:07 7552 ----a-w- c:\windows\system32\dllcache\nsmmc.sys
2010-10-10 19:38:01 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
2010-10-10 19:37:49 87040 ----a-w- c:\windows\system32\dllcache\nm6wdm.sys
2010-10-10 19:37:44 126080 ----a-w- c:\windows\system32\dllcache\nm5a2wdm.sys
2010-10-10 19:37:23 32840 ----a-w- c:\windows\system32\dllcache\ngrpci.sys
2010-10-10 19:37:09 132695 ----a-w- c:\windows\system32\dllcache\netwlan5.sys
2010-10-10 19:35:56 75520 ----a-w- c:\windows\system32\dllcache\mxport.sys
2010-10-10 19:35:53 7168 ----a-w- c:\windows\system32\dllcache\mxport.dll
2010-10-10 19:35:49 19968 ----a-w- c:\windows\system32\dllcache\mxnic.sys
2010-10-10 19:35:46 19968 ----a-w- c:\windows\system32\dllcache\mxicfg.dll
2010-10-10 19:35:42 21888 ----a-w- c:\windows\system32\dllcache\mxcard.sys
2010-10-10 19:35:41 12672 ----a-w- c:\windows\system32\dllcache\mutohpen.sys
2010-10-10 19:35:40 229439 ----a-w- c:\windows\system32\dllcache\multibox.dll
2010-10-10 19:35:01 103296 ----a-w- c:\windows\system32\dllcache\mtxvideo.sys
2010-10-10 19:35:00 452736 ----a-w- c:\windows\system32\dllcache\mtxparhm.sys
2010-10-10 19:34:59 1737856 ----a-w- c:\windows\system32\dllcache\mtxparhd.dll
2010-10-10 19:34:56 111104 ----a-w- c:\windows\system32\dllcache\mtstocom.exe
2010-10-10 19:34:53 1309184 ----a-w- c:\windows\system32\dllcache\mtlstrm.sys
2010-10-10 19:34:52 126686 ----a-w- c:\windows\system32\dllcache\mtlmnt5.sys
2010-10-10 19:34:23 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
2010-10-10 19:34:10 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2010-10-10 19:34:01 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2010-10-10 19:33:40 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2010-10-10 19:33:35 40960 ----a-w- c:\windows\system32\dllcache\msiregmv.exe
2010-10-10 19:33:34 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2010-10-10 19:33:32 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
2010-10-10 19:32:54 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2010-10-10 19:32:45 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
2010-10-10 19:32:30 51328 ----a-w- c:\windows\system32\dllcache\msdv.sys
2010-10-10 19:32:02 15360 ----a-w- c:\windows\system32\dllcache\mpe.sys
2010-10-10 19:31:43 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
2010-10-10 19:31:27 6528 ----a-w- c:\windows\system32\dllcache\miniqic.sys
2010-10-10 19:31:24 7680 ----a-w- c:\windows\system32\dllcache\migregdb.exe
2010-10-10 19:31:20 34304 ----a-w- c:\windows\system32\dllcache\migisol.exe
2010-10-10 19:31:13 320384 ----a-w- c:\windows\system32\dllcache\mgaum.sys
2010-10-10 19:31:08 92416 ----a-w- c:\windows\system32\dllcache\mga.sys
2010-10-10 19:31:08 235648 ----a-w- c:\windows\system32\dllcache\mgaud.dll
2010-10-10 19:31:07 92032 ----a-w- c:\windows\system32\dllcache\mga.dll
2010-10-10 19:31:05 26112 ----a-w- c:\windows\system32\dllcache\memstpci.sys
2010-10-10 19:31:01 47616 ----a-w- c:\windows\system32\dllcache\memgrp.dll
2010-10-10 19:29:56 727786 ----a-w- c:\windows\system32\dllcache\ltck000c.sys
2010-10-10 19:28:54 242176 ----a-w- c:\windows\system32\dllcache\kdsusd.dll
2010-10-10 19:27:58 18688 ----a-w- c:\windows\system32\dllcache\irsir.sys
2010-10-10 19:27:52 23552 ----a-w- c:\windows\system32\dllcache\irmk7.sys
2010-10-10 19:27:51 152576 ----a-w- c:\windows\system32\dllcache\irftp.exe
2010-10-10 19:27:48 87424 ----a-w- c:\windows\system32\dllcache\irda.sys
2010-10-10 19:27:34 35328 ----a-w- c:\windows\system32\dllcache\iprip.dll
2010-10-10 19:27:26 45632 ----a-w- c:\windows\system32\dllcache\ip5515.sys
2010-10-10 19:27:21 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
2010-10-10 19:27:18 38784 ----a-w- c:\windows\system32\dllcache\io8.sys
2010-10-10 19:25:19 372824 ----a-w- c:\windows\system32\dllcache\iconf32.dll
2010-10-10 19:25:09 100992 ----a-w- c:\windows\system32\dllcache\icam5usb.sys
2010-10-10 19:25:06 20480 ----a-w- c:\windows\system32\dllcache\icam5ext.dll
2010-10-10 19:25:03 45056 ----a-w- c:\windows\system32\dllcache\icam5com.dll
2010-10-10 19:23:34 353184 ----a-w- c:\windows\system32\dllcache\i740dnt5.dll
2010-10-10 19:23:02 1041536 ----a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
2010-10-10 19:23:00 685056 ----a-w- c:\windows\system32\dllcache\hsfcxts2.sys
2010-10-10 19:21:58 32768 ----a-w- c:\windows\system32\dllcache\hpgtmcro.dll
2010-10-10 19:20:59 907456 ----a-w- c:\windows\system32\dllcache\hcf_msft.sys
2010-10-10 19:19:58 6144 ----a-w- c:\windows\system32\dllcache\ftlx041e.dll
2010-10-10 19:18:59 24064 ----a-w- c:\windows\system32\dllcache\evntcmd.exe
2010-10-10 19:17:58 18503 ----a-w- c:\windows\system32\dllcache\epro4.sys
2010-10-10 19:16:44 334208 ----a-w- c:\windows\system32\dllcache\ds1wdm.sys
2010-10-10 19:16:29 28062 ----a-w- c:\windows\system32\dllcache\dp83820.sys
2010-10-10 19:16:27 23808 ----a-w- c:\windows\system32\dllcache\dot4usb.sys
2010-10-10 19:16:25 8704 ----a-w- c:\windows\system32\dllcache\dot4scan.sys
2010-10-10 19:16:24 12928 ----a-w- c:\windows\system32\dllcache\dot4prt.sys
2010-10-10 19:16:23 207360 ----a-w- c:\windows\system32\dllcache\dot4.sys
2010-10-10 19:16:04 29696 ----a-w- c:\windows\system32\dllcache\dm9pci5.sys
2010-10-10 19:14:56 419357 ----a-w- c:\windows\system32\dllcache\dgconfig.dll
2010-10-10 19:13:58 50176 ----a-w- c:\windows\system32\dllcache\cyyport.sys
2010-10-10 19:12:50 20736 ----a-w- c:\windows\system32\dllcache\cmbp0wdm.sys
2010-10-10 19:11:57 17024 ----a-w- c:\windows\system32\dllcache\ccdecode.sys
2010-10-10 19:10:49 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
2010-10-10 19:09:59 87552 ----a-w- c:\windows\system32\dllcache\avmcoxp.dll
2010-10-10 19:08:59 34735 ----a-w- c:\windows\system32\dllcache\ati1xsxx.sys
2010-10-10 19:07:58 5632 ----a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
2010-10-10 19:05:41 32827 ----a-w- c:\windows\system32\dllcache\tcptest.exe
2010-10-10 19:05:41 16384 ----a-w- c:\windows\system32\dllcache\tcptsat.dll
2010-10-10 19:05:34 16437 ----a-w- c:\windows\system32\dllcache\shtml.exe
2010-10-10 19:05:32 20536 ----a-w- c:\windows\system32\dllcache\shtml.dll
2010-10-10 19:04:22 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
2010-10-10 19:03:04 20538 ----a-w- c:\windows\system32\dllcache\fpremadm.exe
2010-10-10 19:03:03 598071 ----a-w- c:\windows\system32\dllcache\fpmmc.dll
2010-10-10 19:03:03 208896 ----a-w- c:\windows\system32\dllcache\fpmmcsat.dll
2010-10-10 19:03:02 20541 ----a-w- c:\windows\system32\dllcache\fpexedll.dll
2010-10-10 19:03:02 188494 ----a-w- c:\windows\system32\dllcache\fpcount.exe
2010-10-10 19:03:01 109328 ----a-w- c:\windows\system32\dllcache\fp98swin.exe
2010-10-10 19:03:00 876653 ----a-w- c:\windows\system32\dllcache\fp4awel.dll
2010-10-10 19:03:00 14608 ----a-w- c:\windows\system32\dllcache\fp98sadm.exe
2010-10-10 17:56:27 -------- d-----w- C:\8e0b5838359c27decb5ff159a1f9f8
2010-10-10 16:49:27 -------- d--h--w- c:\windows\$hf_mig$
2010-10-10 16:26:11 -------- d-----w- C:\783723f28d8cf4928e
2010-10-10 09:52:16 -------- d-----w- C:\e467c5eaa018275d9246c991e0
2010-10-10 09:46:54 -------- d-----w- C:\8268df37ed3c6ab4fcdd7a
2010-10-10 08:33:47 -------- d-----w- C:\d67f11350e56d1bd070279148ece44
2010-10-10 08:33:13 -------- d-----w- C:\6e6acf76262512dac36a1015ff412d
2010-10-10 08:27:05 -------- d-----w- C:\b614c172a7d040215e0392b8bba4df
2010-10-10 08:17:57 -------- d-----w- C:\temp
2010-10-09 22:03:09 -------- d-----w- c:\docume~1\trish\applic~1\DriverCure
2010-10-09 22:03:07 -------- d-----w- c:\docume~1\trish\applic~1\ParetoLogic
2010-10-09 22:02:36 -------- d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2010-10-09 11:31:58 -------- d-----w- c:\program files\win
2010-10-08 18:28:27 -------- d-----w- c:\documents and settings\trish\Sun
2010-10-08 18:12:27 -------- d-----w- c:\program files\windows
2010-10-08 18:12:17 -------- d-----w- c:\program files\tmp
2010-10-08 18:12:00 -------- d-----w- c:\program files\Microsoft
2010-10-04 13:01:59 -------- d-----w- c:\docume~1\trish\applic~1\AnvSoft
2010-10-04 13:01:26 -------- d-----w- c:\program files\AnvSoft
2010-10-03 12:53:22 -------- d-----w- c:\docume~1\trish\locals~1\applic~1\Cranium
2010-10-02 16:27:08 -------- d-----w- c:\program files\RADVideo
2010-10-02 16:10:16 -------- d-----w- c:\program files\Movie Rotator
2010-10-02 15:01:14 -------- d-----w- c:\docume~1\trish\locals~1\applic~1\Cranium_Consulting_and_Cu
2010-10-02 14:58:37 -------- d-----w- c:\program files\iPhoneBrowser
2010-10-02 14:40:51 -------- d-----w- c:\program files\iPod
2010-10-02 14:40:27 -------- d-----w- c:\program files\iTunes
2010-10-02 14:35:10 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2010-10-02 14:35:10 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll

==================== Find3M ====================

2010-09-08 10:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-09-08 10:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-07-27 17:44:10 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-07-27 17:44:10 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2010-07-27 17:44:10 197920 ----a-w- c:\windows\system32\dnssdX.dll
2010-07-27 17:44:10 107808 ----a-w- c:\windows\system32\dns-sd.exe

============= FINISH: 22:16:30.18 ===============
 
DDS (Ver_10-10-10.03)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 26/12/2005 09:22:41
System Uptime: 19/10/2010 22:03:47 (0 hours ago)

Motherboard: Dell Inc. | | 0WF351
Processor: Intel(R) Pentium(R) M processor 1.60GHz | Microprocessor | 1596/133mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 53 GiB total, 11.389 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================
DDS Attach.text log


No restore point in system.

==== Installed Programs ======================


Adobe Acrobat 6.0 Professional
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Shockwave Player
ALPS Touch Pad Driver
Any Video Converter 3.0.7
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Avira AntiVir Personal - Free Antivirus
AviSynth 2.5
Bing Bar
Bing Bar Platform
Bonjour
Broadcom Management Programs 2
Canon G.726 WMP-Decoder
CCleaner
Compatibility Pack for the 2007 Office system
Conexant D110 MDC V.92 Modem
Convert AVI to MP4 1.3
Defraggler
Dell Driver Reset Tool
DivX Setup
Dropbox
Glary Utilities 2.28.0.1011
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows XP (KB954550-v5)
Intel(R) Graphics Media Accelerator Driver for Mobile
Intel(R) PROSet/Wireless Software
Internal Network Card Power Management
Internet Explorer Default Page
iPhoneBrowser
iTunes
J2SE Runtime Environment 5.0 Update 3
Java 2 Runtime Environment, SE v1.4.2_03
Java Auto Updater
Java(TM) 6 Update 20
Lexmark Z600 Series
localhostr uploadr 1.2.2
Malwarebytes' Anti-Malware
mCore
MCU
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Default Manager
Microsoft Office Basic Edition 2003
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
mIWA
mIWCA
mLogView
mMHouse
Movie Rotator 1.2
Mozilla ActiveX Control v1.7.12
Mozilla Firefox (3.6.10)
MP3 CD Doctor
mPfMgr
mPfWiz
mProSafe
mSSO
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6 Service Pack 2 (KB954459)
mToolkit
mWlsSafe
mXML
mZConfig
NetWaiting
O2 Broadband Assistant
O2InstV3Win7UpdateV1
Picasa 2
PodLift
Power Tab Editor 1.7
PowerDVD 5.5
PrimoPDF -- brought to you by Nitro PDF Software
QuickTime
RAD Video Tools
RealPlayer Basic
Rightmove Desktop
Sage Instant Accounts
Sage Instant Accounts V12.00
Security Update for Windows Media Player (KB978695)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB978542)
Skype™ 4.2
SopCast 3.0.3
Spotify
Update for Windows XP (KB896727)
VC80CRTRedist - 8.0.50727.4053
VLC media player 1.0.1
WebEx
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Live ID Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888310
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892627
Windows XP Hotfix - KB893056
WinRAR archiver
ZumoCast

==== Event Viewer Messages From Past Week ========

19/10/2010 21:51:38, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ssmdrv Tcpip
19/10/2010 21:07:00, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
19/10/2010 21:07:00, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
19/10/2010 20:17:17, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 20:17:14, error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
19/10/2010 20:17:11, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 20:17:10, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 20:17:10, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 20:17:10, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
19/10/2010 19:20:09, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.3664.
19/10/2010 19:20:05, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\common files\system\wab32.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.3138.
19/10/2010 19:19:51, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msadox.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 2.81.1128.0.
19/10/2010 19:13:58, error: VolSnap [12] - The shadow copy of volume C: became low on diff area space before it was properly installed.
19/10/2010 18:43:18, error: Dhcp [1002] - The IP address lease 192.168.2.9 for the Network Card with network address 0013CED831B6 has been denied by the DHCP server 192.168.1.254 (The DHCP Server sent a DHCPNACK message).
19/10/2010 16:39:30, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
19/10/2010 16:33:55, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
19/10/2010 16:33:55, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
19/10/2010 16:33:55, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
19/10/2010 16:33:53, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
19/10/2010 16:32:34, error: Service Control Manager [7022] - The Avira AntiVir Guard service hung on starting.
19/10/2010 16:23:23, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips IntelIde intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 RasAcd Rdbss ssmdrv Tcpip
19/10/2010 16:03:19, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avgio avipbb Fips intelppm ssmdrv
19/10/2010 15:44:35, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avgio AvgLdx86 AvgMfx86 avipbb Fips intelppm ssmdrv
19/10/2010 15:34:33, error: Service Control Manager [7001] - The WLANKEEPER service depends on the EvtEng service which failed to start because of the following error: The system cannot find the file specified.
19/10/2010 15:34:33, error: Service Control Manager [7001] - The Spectrum24 Event Monitor service depends on the EvtEng service which failed to start because of the following error: The system cannot find the file specified.
19/10/2010 15:34:33, error: Service Control Manager [7000] - The RegSrvc service failed to start due to the following error: The system cannot find the file specified.
19/10/2010 15:34:33, error: Service Control Manager [7000] - The NICCONFIGSVC service failed to start due to the following error: The system cannot find the file specified.
19/10/2010 15:34:33, error: Service Control Manager [7000] - The EvtEng service failed to start due to the following error: The system cannot find the file specified.
19/10/2010 15:28:05, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msado15.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 2.81.1128.0.
19/10/2010 15:28:03, error: Service Control Manager [7034] - The SupportSoft Sprocket Service (O2) service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 15:28:03, error: Service Control Manager [7034] - The RegSrvc service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 15:28:03, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 15:28:03, error: Service Control Manager [7034] - The NICCONFIGSVC service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 15:28:03, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 15:28:03, error: Service Control Manager [7034] - The EvtEng service terminated unexpectedly. It has done this 1 time(s).
19/10/2010 13:40:25, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the AntiVirSchedulerService service.
19/10/2010 13:20:14, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
19/10/2010 13:20:14, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\TRISH\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
19/10/2010 13:20:14, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
19/10/2010 13:02:30, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IntelIde
19/10/2010 13:02:03, error: Print [19] - Sharing printer failed + 1722, Printer WebEx Document Loader share name Printer.
19/10/2010 12:36:22, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips IntelIde intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 RasAcd Rdbss Tcpip
19/10/2010 12:14:34, error: Dhcp [1002] - The IP address lease 192.168.1.66 for the Network Card with network address 0013CED831B6 has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
19/10/2010 09:13:39, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: Access is denied.
15/10/2010 22:28:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
15/10/2010 09:10:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}
15/10/2010 05:52:49, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3664, the version of the system file is 6.0.2900.3664.
15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\wab32.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3138, the version of the system file is 6.0.2900.3138.
15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\directdb.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3138, the version of the system file is 6.0.2900.3138.
15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msjro.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msadox.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msadomd.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
15/10/2010 05:29:02, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\wabimp.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3138, the version of the system file is 6.0.2900.3138.
14/10/2010 18:27:24, error: DCOM [10000] - Unable to start a DCOM Server: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}. The error: "%5" Happened while starting this command: C:\WINDOWS\system32\igfxsrvc.exe -Embedding
14/10/2010 18:25:50, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
14/10/2010 18:23:27, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
14/10/2010 18:23:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
14/10/2010 17:57:45, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 Fips intelppm
14/10/2010 17:54:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
14/10/2010 17:43:05, error: Dhcp [1002] - The IP address lease 10.132.248.227 for the Network Card with network address 0013CED831B6 has been denied by the DHCP server 10.144.10.9 (The DHCP Server sent a DHCPNACK message).
14/10/2010 15:51:35, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is TRISH.
14/10/2010 15:51:17, information: Windows File Protection [64016] - Windows File Protection file scan was started.
14/10/2010 15:22:32, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}
14/10/2010 15:17:11, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3598, the version of the system file is 6.0.2900.3598.
14/10/2010 14:03:41, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msado15.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
14/10/2010 14:00:52, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.
14/10/2010 09:39:43, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
14/10/2010 09:17:28, error: DCOM [10000] - Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}. The error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
13/10/2010 18:36:57, error: PSched [14103] - QoS [Adapter {EDE620B1-E5E5-4796-9C47-913B87A8842F}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
13/10/2010 18:18:49, error: Service Control Manager [7000] - The AVG Free8 E-mail Scanner service failed to start due to the following error: Access is denied.
13/10/2010 18:08:08, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: Access is denied.
13/10/2010 18:08:08, error: DCOM [10005] - DCOM got error "%5" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
13/10/2010 10:38:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
12/10/2010 14:29:47, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
12/10/2010 14:29:47, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2010 14:29:47, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2010 14:29:47, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2010 14:29:47, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2010 14:29:47, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
12/10/2010 14:29:47, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

==== End Of File ===========================


Thank you.
 
Welcome to TechSpot! But I won't have good news for you. From what entries I'm seeing, it appears that you have the file infector Ramnit. Before I give you the bad news, let's be sure:


Run Eset NOD32 Online AntiVirus scan HEREhttp://www.eset.eu/online-scanner
  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the Active X control to install
  4. Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
  5. Click Start
  6. Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
  7. Click Scan
  8. Wait for the scan to finish
  9. Re-enable your Antivirus software.
  10. A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.

Don't try doing any more scans or downloading any more programs at this point. If it is Ramnit, you will have to reformat/reinstall.
 
Hi Bobbye

Many thanks for your help. I thought it might be bad news. I've run ESET, although it would only run in Safe mode and unfortunately when the scan got to 99% after over an hour I got the blue screen of death and the log didn't save. However it had reported over 2000 infected files with the Ramnit virus as you thought.

However I also ran it on my home PC (the other one is my laptop) which I thought might also be infected. This one was even worse with over 8000 infected files with Ramnit! I will try paste the log in the next post as I've had a few problems inserting it into this post and am having to rewrite it again.

So I think I must have passed the virus from my home pc onto my laptop with a USB stick drive - so I now have 2 infected computers and 2 infected USB stick drives.

Obviously I need to reformat both PC's but can you please help me with how to do this and more importantly how I can save required files without then infecting another computer when I transfer them. I don't have an external hard drive - if I buy a new USB drive is there any way I can transfer files from the 2 pcs and other USB sticks - but how can I be sure the files aren't infected?!

Also is there any way of reformatting the computers without the original disks? They are both Dell computers running XP - I believe the laptop didn't come with back up disk but apparently I can do a PC restore as I have Dell PC Restore by Symantec which can restore to original factory state as back up is stored on the hard drive - or will these files be infected?

I have spoken to Dell and they can send backup disks and drivers but these will cost £25 each. I can get an XP disk from another family member from one of their computers - will that work if I use the right key code from the infected PC's?

Sorry for so many questions - I just want to be able to backup my files and then not infected any more computers!

I'll try and post the log again in the next post. Thanks again for your help.
 
I've tried to post the log again but it's far too big - will have to separate it into loads of different posts if you want to see it - or I can attach it.

But the result is defintely conclusive - that both my PC's are badly infected with Ramnit - so I don't think I have many options.

Thanks - let me know if you want me to attach log
 
If you see that much evidence of Ramnit, here's what you need to know about it:

Win32/Ramnit.A is a file infector with IRCBot functionality which infects .exe, and .HTML/HTM files, and opens a back door that compromises your computer. Using this backdoor, a remote attacker can access and instruct the infected computer to download and execute more malicious files. The infected .HTML or .HTM files may be detected as Virus:VBS/Ramnit.A. Win32/Ramnit.A!dll is a related file infector often seen with this infection. It too has IRCBot functionality which infects .exe, .dll and .HTML/HTM files and opens a back door that compromises your computer. This component is injected into the default web browser by Worm:Win32/Ramnit.A which is dropped by a Ramnit infected executable file.

-- Note: As with most malware infections, the threat name may be different depending on the anti-virus or anti-malware program which detected it. Each security vendor uses their own naming conventions to identify various types of malware.
With this particular infection the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

Why? The malware injects code in legitimate files similar to the Virut virus and in many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files often become corrupted and the system may become unstable or irreparable. The longer Ramnit.A remains on a computer, the more files it infects and corrupts so the degree of infection can vary.

Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies Worm:Win32/Ramnit.A with a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and a major source of system infection.

In my opinion, Ramnit.A is not effectively disinfectable, so your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. Further, your machine has likely been compromised by the backdoor Trojan and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if your anti-virus reports that the malware appears to have been removed.

Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:
Whenever a system has been compromised by a backdoor payload, it is impossible to know if or how much the backdoor has been used to affect your system...There are only a few ways to return a compromised system to a confident security configuration. These include:
• Reimaging the system
• Restoring the entire system using a full system backup from before the backdoor infection
• Reformatting and reinstalling the system
Backdoors and What They Mean to You

This is what Jesper M. Johansson at Microsoft TechNet has to say: Help: I Got Hacked. Now What Do I Do?.
The only way to clean a compromised system is to flatten and rebuild. That’s right. If you have a system that has been completely compromised, the only thing you can do is to flatten the system (reformat the system disk) and rebuild it from scratch (reinstall Windows and your applications).


Important Note:: If your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to to include those used for banking, email, eBay, paypal and any online activities which require a username and password. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity.

Ramnit Tutorial Courtesy Broni.
 
Status
Not open for further replies.
Back