TechSpot

[Incurable- Ramnit]W32/infector.gen2 - help please

Resolved
By jms
Oct 19, 2010
  1. My laptop is badly infected with what Avira says is w32/infector.gen2. Loads of files are coming up infected and when I delete they just seem to come back. I think another computer of mine has been infected also by using a USB stick - but will start with this computer!

    As per instuctions I have run TFC and then Malware bytes. Please find Malware bytes log below although it didn't seem to detect much.

    I was unable to run GMER scan in normal of safe mode. When I tried the computer just kept freezing.

    I ran DDS and will post files in next post.

    Many thanks for your help in advance - this has been driving me crazy.

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Database version: 4880

    Windows 5.1.2600 Service Pack 2
    Internet Explorer 8.0.6001.18702

    19/10/2010 20:59:58
    mbam-log-2010-10-19 (20-59-58).txt

    Scan type: Quick scan
    Objects scanned: 155725
    Time elapsed: 30 minute(s), 44 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 2
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\program files\microsoft\desktoplayer.exe -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Program Files\Microsoft\desktoplayer.exe (Trojan.Agent) -> Delete on reboot.
     
  2. jms

    jms TS Rookie Topic Starter

    DDS.text log:

    DDS (Ver_10-10-10.03) - NTFSx86
    Run by TRISH at 22:13:21.64 on 19/10/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.759.391 [GMT 1:00]

    AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\system32\svchost -k rpcss
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\system32\svchost.exe -k NetworkService
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir Desktop\sched.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\system32\svchost.exe -k LocalService
    C:\Program Files\Avira\AntiVir Desktop\avguard.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Program Files\O2\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Documents and Settings\TRISH\Desktop\dds.scr
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.google.com/
    mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\program files\microsoft\desktoplayer.exe
    BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 6.0\acrobat\activex\AcroIEHelper.dll
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
    BHO: Bing Bar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: @c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll,-100: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\5.0.1423.0\npwinext.dll
    TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 6.0\acrobat\AcroIEFavClient.dll
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
    TB: {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [ZumoCast] c:\program files\zecter\zumocast\ZumoLauncher.lnk
    uRun: [{AE2C0284-B143-82F2-F8FC-47A0386F36E3}] "c:\documents and settings\trish\application data\qyegax\atsei.exe"
    mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
    mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
    mRun: [Bing Bar] "c:\program files\msn toolbar\platform\5.0.1423.0\mswinext.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    dRun: [Picasa Media Detector] c:\program files\picasa2\PicasaMediaDetector.exe
    StartupFolder: c:\docume~1\trish\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\trish\application data\dropbox\bin\Dropbox.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\adobe acrobat 6.0\distillr\acrotray.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.keepandshare.com/imageuploader5.7.24/ImageUploader5.cab
    DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1195314469937
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://mymicron.webex.com/client/T26L/support/ieatgpc.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
    DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: igfxcui - igfxdev.dll
    Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SecurityProviders: msapsspc.dll, schannel.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\trish\applic~1\mozilla\firefox\profiles\4tillcx1.default\
    FF - prefs.js: browser.search.selectedEngine - Google
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: network.cookie.cookieBehavior - 0
    FF - user.js: privacy.clearOnShutdown.cookies - false
    FF - user.js: security.warn_viewing_mixed - false
    FF - user.js: security.warn_viewing_mixed.show_once - false
    FF - user.js: security.warn_submit_insecure - false
    FF - user.js: security.warn_submit_insecure.show_once - false
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

    ============= SERVICES / DRIVERS ===============

    R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-10-19 11608]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-10-19 135336]
    R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-10-19 267432]
    R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-10-19 60936]
    R2 sprtsvc_O2;SupportSoft Sprocket Service (O2);c:\program files\o2\bin\sprtsvc.exe [2009-3-4 202016]
    S3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-10-30 819352]
    S4 W3s4avadtn;W3s4avadtn; [x]

    =============== Created Last 30 ================

    2010-10-19 18:08:50 -------- d-----w- c:\windows\system32\NtmsData
    2010-10-19 12:50:47 -------- d-----w- c:\docume~1\trish\applic~1\Avira
    2010-10-19 12:25:07 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
    2010-10-19 12:24:10 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
    2010-10-19 12:24:09 -------- d-----w- c:\program files\Avira
    2010-10-15 08:23:22 -------- d-----w- c:\program files\Glary Utilities
    2010-10-15 08:10:23 -------- d-----w- c:\program files\ParetoLogic
    2010-10-14 22:42:39 -------- d-----w- C:\2f1ce92aa3cd00ef711f64a73573ac13
    2010-10-14 15:20:36 -------- d-sh--w- c:\documents and settings\trish\PrivacIE
    2010-10-14 14:38:27 -------- d-sh--w- c:\documents and settings\trish\IETldCache
    2010-10-14 14:31:36 -------- dc-h--w- c:\windows\ie8
    2010-10-14 14:11:30 -------- d-----w- C:\20952e15856179802d
    2010-10-14 12:26:19 10129408 ----a-w- c:\windows\system32\dllcache\hwxkor.dll
    2010-10-14 12:25:47 13463552 ----a-w- c:\windows\system32\dllcache\hwxjpn.dll
    2010-10-14 12:25:16 10096640 ----a-w- c:\windows\system32\dllcache\hwxcht.dll
    2010-10-13 18:26:28 -------- d-----w- C:\6a7ab4c99f45b7dad4d939
    2010-10-13 18:11:21 -------- d-----w- C:\7530b664779eb3c04f7fcd0ac87d
    2010-10-13 10:21:25 -------- d-----w- c:\docume~1\trish\locals~1\applic~1\Help
    2010-10-13 09:48:41 388608 ----a-w- c:\windows\system32\CF27382.exe
    2010-10-12 11:31:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-10-12 11:31:42 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-10-12 11:31:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-10-12 10:49:31 1033216 ----a-w- c:\windows\alex.exe
    2010-10-12 09:59:42 -------- d-----w- c:\program files\msn gaming zone
    2010-10-11 13:20:05 -------- d-----w- c:\program files\MSN Toolbar
    2010-10-11 13:18:06 -------- d-----w- c:\program files\Unlocker
    2010-10-11 13:17:56 -------- d-----w- c:\program files\Bing Bar Installer
    2010-10-11 09:37:08 -------- d-----w- c:\program files\CCleaner
    2010-10-11 06:49:03 -------- d-----w- c:\program files\Defraggler
    2010-10-10 20:20:02 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
    2010-10-10 20:19:57 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
    2010-10-10 20:19:51 17408 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
    2010-10-10 20:19:46 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
    2010-10-10 20:19:37 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
    2010-10-10 20:19:18 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
    2010-10-10 20:18:29 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
    2010-10-10 20:18:25 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
    2010-10-10 20:18:12 19328 ----a-w- c:\windows\system32\dllcache\wstcodec.sys
    2010-10-10 20:18:00 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
    2010-10-10 20:17:58 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
    2010-10-10 20:16:31 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
    2010-10-10 20:16:23 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
    2010-10-10 20:16:18 34890 ----a-w- c:\windows\system32\dllcache\wlandrv2.sys
    2010-10-10 20:15:42 771581 ----a-w- c:\windows\system32\dllcache\winacisa.sys
    2010-10-10 20:15:22 53760 ----a-w- c:\windows\system32\dllcache\wiamsmud.dll
    2010-10-10 20:15:15 87040 ----a-w- c:\windows\system32\dllcache\wiafbdrv.dll
    2010-10-10 20:15:13 31232 ----a-w- c:\windows\system32\dllcache\weitekp9.sys
    2010-10-10 20:15:12 41600 ----a-w- c:\windows\system32\dllcache\weitekp9.dll
    2010-10-10 20:15:01 701386 ----a-w- c:\windows\system32\dllcache\wdhaalba.sys
    2010-10-10 20:13:55 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
    2010-10-10 20:13:54 86073 ----a-w- c:\windows\system32\dllcache\voicesub.dll
    2010-10-10 20:13:52 426041 ----a-w- c:\windows\system32\dllcache\voicepad.dll
    2010-10-10 20:13:47 604253 ----a-w- c:\windows\system32\dllcache\vmodem.sys
    2010-10-10 20:13:39 249402 ----a-w- c:\windows\system32\dllcache\vinwm.sys
    2010-10-10 20:13:31 24576 ----a-w- c:\windows\system32\dllcache\viairda.sys
    2010-10-10 20:13:25 53760 ----a-w- c:\windows\system32\dllcache\vfwwdm32.dll
    2010-10-10 20:13:20 11325 ----a-w- c:\windows\system32\dllcache\vchnt5.dll
    2010-10-10 20:13:11 687999 ----a-w- c:\windows\system32\dllcache\usrwdxjs.sys
    2010-10-10 20:13:03 765884 ----a-w- c:\windows\system32\dllcache\usrti.sys
    2010-10-10 20:12:55 113762 ----a-w- c:\windows\system32\dllcache\usrpda.sys
    2010-10-10 20:12:49 7556 ----a-w- c:\windows\system32\dllcache\usroslba.sys
    2010-10-10 20:12:38 224802 ----a-w- c:\windows\system32\dllcache\usr1807a.sys
    2010-10-10 20:12:32 794399 ----a-w- c:\windows\system32\dllcache\usr1806v.sys
    2010-10-10 20:12:25 793598 ----a-w- c:\windows\system32\dllcache\usr1806.sys
    2010-10-10 20:12:19 794654 ----a-w- c:\windows\system32\dllcache\usr1801.sys
    2010-10-10 20:12:13 78464 ----a-w- c:\windows\system32\dllcache\usbvideo.sys
    2010-10-10 20:12:11 25600 ----a-w- c:\windows\system32\dllcache\usbser.sys
    2010-10-10 20:12:07 17024 ----a-w- c:\windows\system32\dllcache\usbohci.sys
    2010-10-10 20:12:06 31616 ----a-w- c:\windows\system32\dllcache\usbccgp.sys
    2010-10-10 20:12:03 59264 ----a-w- c:\windows\system32\dllcache\usbaudio.sys
    2010-10-10 20:12:01 12672 ----a-w- c:\windows\system32\dllcache\usb8023x.sys
    2010-10-10 20:11:59 32384 ----a-w- c:\windows\system32\dllcache\usb101et.sys
    2010-10-10 20:11:48 76288 ----a-w- c:\windows\system32\dllcache\uniime.dll
    2010-10-10 20:11:40 94720 ----a-w- c:\windows\system32\dllcache\umaxud32.dll
    2010-10-10 20:11:35 28160 ----a-w- c:\windows\system32\dllcache\umaxu40.dll
    2010-10-10 20:11:30 26624 ----a-w- c:\windows\system32\dllcache\umaxu22.dll
    2010-10-10 20:11:24 69632 ----a-w- c:\windows\system32\dllcache\umaxu12.dll
    2010-10-10 20:11:18 50688 ----a-w- c:\windows\system32\dllcache\umaxscan.dll
    2010-10-10 20:11:13 22912 ----a-w- c:\windows\system32\dllcache\umaxpcls.sys
    2010-10-10 20:11:08 50176 ----a-w- c:\windows\system32\dllcache\umaxp60.dll
    2010-10-10 20:11:02 47616 ----a-w- c:\windows\system32\dllcache\umaxcam.dll
    2010-10-10 20:10:55 211968 ----a-w- c:\windows\system32\dllcache\um54scan.dll
    2010-10-10 20:10:49 216064 ----a-w- c:\windows\system32\dllcache\um34scan.dll
    2010-10-10 20:10:41 44672 ----a-w- c:\windows\system32\dllcache\uagp35.sys
    2010-10-10 20:10:34 11520 ----a-w- c:\windows\system32\dllcache\twotrack.sys
    2010-10-10 20:10:31 14336 ----a-w- c:\windows\system32\dllcache\tsprof.exe
    2010-10-10 20:10:16 166784 ----a-w- c:\windows\system32\dllcache\tridxpm.sys
    2010-10-10 20:10:11 525568 ----a-w- c:\windows\system32\dllcache\tridxp.dll
    2010-10-10 20:10:04 159232 ----a-w- c:\windows\system32\dllcache\tridkbm.sys
    2010-10-10 20:09:58 440576 ----a-w- c:\windows\system32\dllcache\tridkb.dll
    2010-10-10 20:09:53 222336 ----a-w- c:\windows\system32\dllcache\trid3dm.sys
    2010-10-10 20:09:47 315520 ----a-w- c:\windows\system32\dllcache\trid3d.dll
    2010-10-10 20:09:40 34375 ----a-w- c:\windows\system32\dllcache\tpro4.sys
    2010-10-10 20:09:35 42496 ----a-w- c:\windows\system32\dllcache\tp4res.dll
    2010-10-10 20:09:33 82432 ----a-w- c:\windows\system32\dllcache\tp4mon.exe
    2010-10-10 20:09:28 31744 ----a-w- c:\windows\system32\dllcache\tp4.dll
    2010-10-10 20:09:10 230912 ----a-w- c:\windows\system32\dllcache\tosdvd03.sys
    2010-10-10 20:09:04 241664 ----a-w- c:\windows\system32\dllcache\tosdvd02.sys
    2010-10-10 20:07:51 30464 ----a-w- c:\windows\system32\dllcache\tbatm155.sys
    2010-10-10 20:07:39 7040 ----a-w- c:\windows\system32\dllcache\tandqic.sys
    2010-10-10 20:07:34 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
    2010-10-10 20:07:28 172768 ----a-w- c:\windows\system32\dllcache\t2r4disp.dll
    2010-10-10 20:07:07 94293 ----a-w- c:\windows\system32\dllcache\sxports.dll
    2010-10-10 20:07:03 103936 ----a-w- c:\windows\system32\dllcache\sx.sys
    2010-10-10 20:06:58 3968 ----a-w- c:\windows\system32\dllcache\swusbflt.sys
    2010-10-10 20:06:53 10240 ----a-w- c:\windows\system32\dllcache\swpidflt.dll
    2010-10-10 20:06:48 10240 ----a-w- c:\windows\system32\dllcache\swpdflt2.dll
    2010-10-10 20:06:43 53760 ----a-w- c:\windows\system32\dllcache\sw_wheel.dll
    2010-10-10 20:06:38 41472 ----a-w- c:\windows\system32\dllcache\sw_effct.dll
    2010-10-10 20:06:30 15360 ----a-w- c:\windows\system32\dllcache\streamip.sys
    2010-10-10 20:06:23 155648 ----a-w- c:\windows\system32\dllcache\stlnprop.dll
    2010-10-10 20:06:17 53248 ----a-w- c:\windows\system32\dllcache\stlncoin.dll
    2010-10-10 20:06:12 285760 ----a-w- c:\windows\system32\dllcache\stlnata.sys
    2010-10-10 20:05:30 16896 ----a-w- c:\windows\system32\dllcache\stcusb.sys
    2010-10-10 20:04:39 48736 ----a-w- c:\windows\system32\dllcache\srwlnd5.sys
    2010-10-10 20:03:51 99328 ----a-w- c:\windows\system32\dllcache\srusd.dll
    2010-10-10 20:03:49 101376 ----a-w- c:\windows\system32\dllcache\srusbusd.dll
    2010-10-10 20:03:02 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
    2010-10-10 20:02:09 61824 ----a-w- c:\windows\system32\dllcache\speed.sys
    2010-10-10 20:01:33 106584 ----a-w- c:\windows\system32\dllcache\spdports.dll
    2010-10-10 20:00:55 7552 ----a-w- c:\windows\system32\dllcache\sonypvu1.sys
    2010-10-10 20:00:19 37040 ----a-w- c:\windows\system32\dllcache\sonypi.sys
    2010-10-10 19:59:42 114688 ----a-w- c:\windows\system32\dllcache\sonypi.dll
    2010-10-10 19:59:05 20752 ----a-w- c:\windows\system32\dllcache\sonync.sys
    2010-10-10 19:58:29 9600 ----a-w- c:\windows\system32\dllcache\sonymc.sys
    2010-10-10 19:58:26 7552 ----a-w- c:\windows\system32\dllcache\sonyait.sys
    2010-10-10 19:58:25 143422 ----a-w- c:\windows\system32\dllcache\softkey.dll
    2010-10-10 19:56:29 147200 ----a-w- c:\windows\system32\dllcache\smidispb.dll
    2010-10-10 19:56:27 236544 ----a-w- c:\windows\system32\dllcache\smi2smir.exe
    2010-10-10 19:55:52 25034 ----a-w- c:\windows\system32\dllcache\smcpwr2n.sys
    2010-10-10 19:55:16 35913 ----a-w- c:\windows\system32\dllcache\smcirda.sys
    2010-10-10 19:54:40 24576 ----a-w- c:\windows\system32\dllcache\smc8000n.sys
    2010-10-10 19:54:04 6784 ----a-w- c:\windows\system32\dllcache\smbhc.sys
    2010-10-10 19:54:00 6912 ----a-w- c:\windows\system32\dllcache\smbclass.sys
    2010-10-10 19:53:59 16128 ----a-w- c:\windows\system32\dllcache\smbbatt.sys
    2010-10-10 19:53:54 6016 ----a-w- c:\windows\system32\dllcache\smbali.sys
    2010-10-10 19:53:54 31744 ----a-w- c:\windows\system32\dllcache\smb6w.dll
    2010-10-10 19:53:10 45568 ----a-w- c:\windows\system32\dllcache\smb3w.dll
    2010-10-10 19:52:25 33792 ----a-w- c:\windows\system32\dllcache\smb0w.dll
    2010-10-10 19:52:24 31744 ----a-w- c:\windows\system32\dllcache\sma3w.dll
    2010-10-10 19:51:43 28672 ----a-w- c:\windows\system32\dllcache\sma0w.dll
    2010-10-10 19:51:42 38912 ----a-w- c:\windows\system32\dllcache\sm9aw.dll
    2010-10-10 19:51:41 26624 ----a-w- c:\windows\system32\dllcache\sm93w.dll
    2010-10-10 19:51:41 26624 ----a-w- c:\windows\system32\dllcache\sm92w.dll
    2010-10-10 19:51:01 28160 ----a-w- c:\windows\system32\dllcache\sm91w.dll
    2010-10-10 19:51:00 26112 ----a-w- c:\windows\system32\dllcache\sm90w.dll
    2010-10-10 19:51:00 26112 ----a-w- c:\windows\system32\dllcache\sm8dw.dll
    2010-10-10 19:49:43 50432 ----a-w- c:\windows\system32\dllcache\sisv.sys
    2010-10-10 19:49:32 32768 ----a-w- c:\windows\system32\dllcache\sisnic.sys
    2010-10-10 19:49:27 238592 ----a-w- c:\windows\system32\dllcache\sisgrv.dll
    2010-10-10 19:49:23 104064 ----a-w- c:\windows\system32\dllcache\sisgrp.sys
    2010-10-10 19:49:19 150144 ----a-w- c:\windows\system32\dllcache\sis6306v.dll
    2010-10-10 19:49:15 68608 ----a-w- c:\windows\system32\dllcache\sis6306p.sys
    2010-10-10 19:49:11 252032 ----a-w- c:\windows\system32\dllcache\sis300iv.dll
    2010-10-10 19:48:31 101760 ----a-w- c:\windows\system32\dllcache\sis300ip.sys
    2010-10-10 19:48:30 18944 ----a-w- c:\windows\system32\dllcache\simptcp.dll
    2010-10-10 19:48:24 3901 ----a-w- c:\windows\system32\dllcache\siint5.dll
    2010-10-10 19:47:36 161568 ----a-w- c:\windows\system32\dllcache\sgsmusb.sys
    2010-10-10 19:47:32 18400 ----a-w- c:\windows\system32\dllcache\sgsmld.sys
    2010-10-10 19:47:28 98080 ----a-w- c:\windows\system32\dllcache\sgiulnt5.sys
    2010-10-10 19:47:24 386560 ----a-w- c:\windows\system32\dllcache\sgiul50.dll
    2010-10-10 19:47:19 36480 ----a-w- c:\windows\system32\dllcache\sfmanm.sys
    2010-10-10 19:47:08 6784 ----a-w- c:\windows\system32\dllcache\serscan.sys
    2010-10-10 19:47:04 17664 ----a-w- c:\windows\system32\dllcache\sermouse.sys
    2010-10-10 19:47:02 26112 ----a-w- c:\windows\system32\dllcache\EXCH_seos.dll
    2010-10-10 19:45:58 198400 ----a-w- c:\windows\system32\dllcache\s3sav4.dll
    2010-10-10 19:44:56 30720 ----a-w- c:\windows\system32\dllcache\rthwcls.sys
    2010-10-10 19:44:50 9216 ----a-w- c:\windows\system32\dllcache\rsmgrstr.dll
    2010-10-10 19:44:45 3840 ----a-w- c:\windows\system32\dllcache\rpfun.sys
    2010-10-10 19:44:40 79104 ----a-w- c:\windows\system32\dllcache\rocket.sys
    2010-10-10 19:44:39 30080 ----a-w- c:\windows\system32\dllcache\rndismpx.sys
    2010-10-10 19:44:34 37563 ----a-w- c:\windows\system32\dllcache\rlnet5.sys
    2010-10-10 19:44:27 59648 ----a-w- c:\windows\system32\dllcache\rfcomm.sys
    2010-10-10 19:44:23 86097 ----a-w- c:\windows\system32\dllcache\reslog32.dll
    2010-10-10 19:44:20 23040 ----a-w- c:\windows\system32\dllcache\EXCH_regtrace.exe
    2010-10-10 19:44:19 14848 ----a-w- c:\windows\system32\dllcache\register.exe
    2010-10-10 19:44:10 13776 ----a-w- c:\windows\system32\dllcache\recagent.sys
    2010-10-10 19:43:56 19584 ----a-w- c:\windows\system32\dllcache\rasirda.sys
    2010-10-10 19:43:52 20736 ----a-w- c:\windows\system32\dllcache\ramdisk.sys
    2010-10-10 19:43:47 714762 ----a-w- c:\windows\system32\dllcache\r2mdmkxx.sys
    2010-10-10 19:43:41 899146 ----a-w- c:\windows\system32\dllcache\r2mdkxga.sys
    2010-10-10 19:43:35 41472 ----a-w- c:\windows\system32\dllcache\qvusd.dll
    2010-10-10 19:43:24 3328 ----a-w- c:\windows\system32\dllcache\qv2kux.sys
    2010-10-10 19:43:22 16384 ----a-w- c:\windows\system32\dllcache\quser.exe
    2010-10-10 19:43:19 9728 ----a-w- c:\windows\system32\dllcache\query.exe
    2010-10-10 19:43:04 6016 ----a-w- c:\windows\system32\dllcache\qic157.sys
    2010-10-10 19:42:53 130942 ----a-w- c:\windows\system32\dllcache\ptserlv.sys
    2010-10-10 19:42:48 112574 ----a-w- c:\windows\system32\dllcache\ptserlp.sys
    2010-10-10 19:42:44 128286 ----a-w- c:\windows\system32\dllcache\ptserli.sys
    2010-10-10 19:42:38 159232 ----a-w- c:\windows\system32\dllcache\ptpusd.dll
    2010-10-10 19:42:33 5632 ----a-w- c:\windows\system32\dllcache\ptpusb.dll
    2010-10-10 19:42:27 35328 ----a-w- c:\windows\system32\dllcache\psisload.dll
    2010-10-10 19:42:19 363520 ----a-w- c:\windows\system32\dllcache\psisdecd.dll
    2010-10-10 19:42:14 16128 ----a-w- c:\windows\system32\dllcache\pscr.sys
    2010-10-10 19:42:07 17664 ----a-w- c:\windows\system32\dllcache\ppa3.sys
    2010-10-10 19:42:03 17792 ----a-w- c:\windows\system32\dllcache\ppa.sys
    2010-10-10 19:40:57 86016 ----a-w- c:\windows\system32\dllcache\pctspk.exe
    2010-10-10 19:39:59 116736 ----a-w- c:\windows\system32\dllcache\ovcodec2.dll
    2010-10-10 19:39:55 31872 ----a-w- c:\windows\system32\dllcache\ovce.sys
    2010-10-10 19:39:51 28032 ----a-w- c:\windows\system32\dllcache\ovcd.sys
    2010-10-10 19:39:47 48000 ----a-w- c:\windows\system32\dllcache\ovcam2.sys
    2010-10-10 19:39:44 25088 ----a-w- c:\windows\system32\dllcache\ovca.sys
    2010-10-10 19:39:39 54186 ----a-w- c:\windows\system32\dllcache\otcsercb.sys
    2010-10-10 19:39:36 43689 ----a-w- c:\windows\system32\dllcache\otceth5.sys
    2010-10-10 19:39:31 27209 ----a-w- c:\windows\system32\dllcache\otc06x5.sys
    2010-10-10 19:39:25 54528 ----a-w- c:\windows\system32\dllcache\opl3sax.sys
    2010-10-10 19:38:53 198144 ----a-w- c:\windows\system32\dllcache\nv3.sys
    2010-10-10 19:38:49 123776 ----a-w- c:\windows\system32\dllcache\nv3.dll
    2010-10-10 19:38:45 180360 ----a-w- c:\windows\system32\dllcache\ntmtlfax.sys
    2010-10-10 19:38:20 51552 ----a-w- c:\windows\system32\dllcache\ntgrip.sys
    2010-10-10 19:38:20 38912 ----a-w- c:\windows\system32\dllcache\EXCH_ntfsdrv.dll
    2010-10-10 19:38:12 9344 ----a-w- c:\windows\system32\dllcache\ntapm.sys
    2010-10-10 19:38:07 7552 ----a-w- c:\windows\system32\dllcache\nsmmc.sys
    2010-10-10 19:38:01 28672 ----a-w- c:\windows\system32\dllcache\nscirda.sys
    2010-10-10 19:37:49 87040 ----a-w- c:\windows\system32\dllcache\nm6wdm.sys
    2010-10-10 19:37:44 126080 ----a-w- c:\windows\system32\dllcache\nm5a2wdm.sys
    2010-10-10 19:37:23 32840 ----a-w- c:\windows\system32\dllcache\ngrpci.sys
    2010-10-10 19:37:09 132695 ----a-w- c:\windows\system32\dllcache\netwlan5.sys
    2010-10-10 19:35:56 75520 ----a-w- c:\windows\system32\dllcache\mxport.sys
    2010-10-10 19:35:53 7168 ----a-w- c:\windows\system32\dllcache\mxport.dll
    2010-10-10 19:35:49 19968 ----a-w- c:\windows\system32\dllcache\mxnic.sys
    2010-10-10 19:35:46 19968 ----a-w- c:\windows\system32\dllcache\mxicfg.dll
    2010-10-10 19:35:42 21888 ----a-w- c:\windows\system32\dllcache\mxcard.sys
    2010-10-10 19:35:41 12672 ----a-w- c:\windows\system32\dllcache\mutohpen.sys
    2010-10-10 19:35:40 229439 ----a-w- c:\windows\system32\dllcache\multibox.dll
    2010-10-10 19:35:01 103296 ----a-w- c:\windows\system32\dllcache\mtxvideo.sys
    2010-10-10 19:35:00 452736 ----a-w- c:\windows\system32\dllcache\mtxparhm.sys
    2010-10-10 19:34:59 1737856 ----a-w- c:\windows\system32\dllcache\mtxparhd.dll
    2010-10-10 19:34:56 111104 ----a-w- c:\windows\system32\dllcache\mtstocom.exe
    2010-10-10 19:34:53 1309184 ----a-w- c:\windows\system32\dllcache\mtlstrm.sys
    2010-10-10 19:34:52 126686 ----a-w- c:\windows\system32\dllcache\mtlmnt5.sys
    2010-10-10 19:34:23 5504 ----a-w- c:\windows\system32\dllcache\mstee.sys
    2010-10-10 19:34:10 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
    2010-10-10 19:34:01 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
    2010-10-10 19:33:40 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
    2010-10-10 19:33:35 40960 ----a-w- c:\windows\system32\dllcache\msiregmv.exe
    2010-10-10 19:33:34 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
    2010-10-10 19:33:32 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
    2010-10-10 19:32:54 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
    2010-10-10 19:32:45 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
    2010-10-10 19:32:30 51328 ----a-w- c:\windows\system32\dllcache\msdv.sys
    2010-10-10 19:32:02 15360 ----a-w- c:\windows\system32\dllcache\mpe.sys
    2010-10-10 19:31:43 16128 ----a-w- c:\windows\system32\dllcache\modemcsa.sys
    2010-10-10 19:31:27 6528 ----a-w- c:\windows\system32\dllcache\miniqic.sys
    2010-10-10 19:31:24 7680 ----a-w- c:\windows\system32\dllcache\migregdb.exe
    2010-10-10 19:31:20 34304 ----a-w- c:\windows\system32\dllcache\migisol.exe
    2010-10-10 19:31:13 320384 ----a-w- c:\windows\system32\dllcache\mgaum.sys
    2010-10-10 19:31:08 92416 ----a-w- c:\windows\system32\dllcache\mga.sys
    2010-10-10 19:31:08 235648 ----a-w- c:\windows\system32\dllcache\mgaud.dll
    2010-10-10 19:31:07 92032 ----a-w- c:\windows\system32\dllcache\mga.dll
    2010-10-10 19:31:05 26112 ----a-w- c:\windows\system32\dllcache\memstpci.sys
    2010-10-10 19:31:01 47616 ----a-w- c:\windows\system32\dllcache\memgrp.dll
    2010-10-10 19:29:56 727786 ----a-w- c:\windows\system32\dllcache\ltck000c.sys
    2010-10-10 19:28:54 242176 ----a-w- c:\windows\system32\dllcache\kdsusd.dll
    2010-10-10 19:27:58 18688 ----a-w- c:\windows\system32\dllcache\irsir.sys
    2010-10-10 19:27:52 23552 ----a-w- c:\windows\system32\dllcache\irmk7.sys
    2010-10-10 19:27:51 152576 ----a-w- c:\windows\system32\dllcache\irftp.exe
    2010-10-10 19:27:48 87424 ----a-w- c:\windows\system32\dllcache\irda.sys
    2010-10-10 19:27:34 35328 ----a-w- c:\windows\system32\dllcache\iprip.dll
    2010-10-10 19:27:26 45632 ----a-w- c:\windows\system32\dllcache\ip5515.sys
    2010-10-10 19:27:21 90200 ----a-w- c:\windows\system32\dllcache\io8ports.dll
    2010-10-10 19:27:18 38784 ----a-w- c:\windows\system32\dllcache\io8.sys
    2010-10-10 19:25:19 372824 ----a-w- c:\windows\system32\dllcache\iconf32.dll
    2010-10-10 19:25:09 100992 ----a-w- c:\windows\system32\dllcache\icam5usb.sys
    2010-10-10 19:25:06 20480 ----a-w- c:\windows\system32\dllcache\icam5ext.dll
    2010-10-10 19:25:03 45056 ----a-w- c:\windows\system32\dllcache\icam5com.dll
    2010-10-10 19:23:34 353184 ----a-w- c:\windows\system32\dllcache\i740dnt5.dll
    2010-10-10 19:23:02 1041536 ----a-w- c:\windows\system32\dllcache\hsfdpsp2.sys
    2010-10-10 19:23:00 685056 ----a-w- c:\windows\system32\dllcache\hsfcxts2.sys
    2010-10-10 19:21:58 32768 ----a-w- c:\windows\system32\dllcache\hpgtmcro.dll
    2010-10-10 19:20:59 907456 ----a-w- c:\windows\system32\dllcache\hcf_msft.sys
    2010-10-10 19:19:58 6144 ----a-w- c:\windows\system32\dllcache\ftlx041e.dll
    2010-10-10 19:18:59 24064 ----a-w- c:\windows\system32\dllcache\evntcmd.exe
    2010-10-10 19:17:58 18503 ----a-w- c:\windows\system32\dllcache\epro4.sys
    2010-10-10 19:16:44 334208 ----a-w- c:\windows\system32\dllcache\ds1wdm.sys
    2010-10-10 19:16:29 28062 ----a-w- c:\windows\system32\dllcache\dp83820.sys
    2010-10-10 19:16:27 23808 ----a-w- c:\windows\system32\dllcache\dot4usb.sys
    2010-10-10 19:16:25 8704 ----a-w- c:\windows\system32\dllcache\dot4scan.sys
    2010-10-10 19:16:24 12928 ----a-w- c:\windows\system32\dllcache\dot4prt.sys
    2010-10-10 19:16:23 207360 ----a-w- c:\windows\system32\dllcache\dot4.sys
    2010-10-10 19:16:04 29696 ----a-w- c:\windows\system32\dllcache\dm9pci5.sys
    2010-10-10 19:14:56 419357 ----a-w- c:\windows\system32\dllcache\dgconfig.dll
    2010-10-10 19:13:58 50176 ----a-w- c:\windows\system32\dllcache\cyyport.sys
    2010-10-10 19:12:50 20736 ----a-w- c:\windows\system32\dllcache\cmbp0wdm.sys
    2010-10-10 19:11:57 17024 ----a-w- c:\windows\system32\dllcache\ccdecode.sys
    2010-10-10 19:10:49 13824 ----a-w- c:\windows\system32\dllcache\bulltlp3.sys
    2010-10-10 19:09:59 87552 ----a-w- c:\windows\system32\dllcache\avmcoxp.dll
    2010-10-10 19:08:59 34735 ----a-w- c:\windows\system32\dllcache\ati1xsxx.sys
    2010-10-10 19:07:58 5632 ----a-w- c:\windows\system32\dllcache\EXCH_adsiisex.dll
    2010-10-10 19:05:41 32827 ----a-w- c:\windows\system32\dllcache\tcptest.exe
    2010-10-10 19:05:41 16384 ----a-w- c:\windows\system32\dllcache\tcptsat.dll
    2010-10-10 19:05:34 16437 ----a-w- c:\windows\system32\dllcache\shtml.exe
    2010-10-10 19:05:32 20536 ----a-w- c:\windows\system32\dllcache\shtml.dll
    2010-10-10 19:04:22 66048 ----a-w- c:\windows\system32\dllcache\s3legacy.dll
    2010-10-10 19:03:04 20538 ----a-w- c:\windows\system32\dllcache\fpremadm.exe
    2010-10-10 19:03:03 598071 ----a-w- c:\windows\system32\dllcache\fpmmc.dll
    2010-10-10 19:03:03 208896 ----a-w- c:\windows\system32\dllcache\fpmmcsat.dll
    2010-10-10 19:03:02 20541 ----a-w- c:\windows\system32\dllcache\fpexedll.dll
    2010-10-10 19:03:02 188494 ----a-w- c:\windows\system32\dllcache\fpcount.exe
    2010-10-10 19:03:01 109328 ----a-w- c:\windows\system32\dllcache\fp98swin.exe
    2010-10-10 19:03:00 876653 ----a-w- c:\windows\system32\dllcache\fp4awel.dll
    2010-10-10 19:03:00 14608 ----a-w- c:\windows\system32\dllcache\fp98sadm.exe
    2010-10-10 17:56:27 -------- d-----w- C:\8e0b5838359c27decb5ff159a1f9f8
    2010-10-10 16:49:27 -------- d--h--w- c:\windows\$hf_mig$
    2010-10-10 16:26:11 -------- d-----w- C:\783723f28d8cf4928e
    2010-10-10 09:52:16 -------- d-----w- C:\e467c5eaa018275d9246c991e0
    2010-10-10 09:46:54 -------- d-----w- C:\8268df37ed3c6ab4fcdd7a
    2010-10-10 08:33:47 -------- d-----w- C:\d67f11350e56d1bd070279148ece44
    2010-10-10 08:33:13 -------- d-----w- C:\6e6acf76262512dac36a1015ff412d
    2010-10-10 08:27:05 -------- d-----w- C:\b614c172a7d040215e0392b8bba4df
    2010-10-10 08:17:57 -------- d-----w- C:\temp
    2010-10-09 22:03:09 -------- d-----w- c:\docume~1\trish\applic~1\DriverCure
    2010-10-09 22:03:07 -------- d-----w- c:\docume~1\trish\applic~1\ParetoLogic
    2010-10-09 22:02:36 -------- d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
    2010-10-09 11:31:58 -------- d-----w- c:\program files\win
    2010-10-08 18:28:27 -------- d-----w- c:\documents and settings\trish\Sun
    2010-10-08 18:12:27 -------- d-----w- c:\program files\windows
    2010-10-08 18:12:17 -------- d-----w- c:\program files\tmp
    2010-10-08 18:12:00 -------- d-----w- c:\program files\Microsoft
    2010-10-04 13:01:59 -------- d-----w- c:\docume~1\trish\applic~1\AnvSoft
    2010-10-04 13:01:26 -------- d-----w- c:\program files\AnvSoft
    2010-10-03 12:53:22 -------- d-----w- c:\docume~1\trish\locals~1\applic~1\Cranium
    2010-10-02 16:27:08 -------- d-----w- c:\program files\RADVideo
    2010-10-02 16:10:16 -------- d-----w- c:\program files\Movie Rotator
    2010-10-02 15:01:14 -------- d-----w- c:\docume~1\trish\locals~1\applic~1\Cranium_Consulting_and_Cu
    2010-10-02 14:58:37 -------- d-----w- c:\program files\iPhoneBrowser
    2010-10-02 14:40:51 -------- d-----w- c:\program files\iPod
    2010-10-02 14:40:27 -------- d-----w- c:\program files\iTunes
    2010-10-02 14:35:10 41984 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2010-10-02 14:35:10 3062048 ----a-w- c:\windows\system32\usbaaplrc.dll

    ==================== Find3M ====================

    2010-09-08 10:17:46 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-09-08 10:17:46 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2010-07-27 17:44:10 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-07-27 17:44:10 75040 ----a-w- c:\windows\system32\jdns_sd.dll
    2010-07-27 17:44:10 197920 ----a-w- c:\windows\system32\dnssdX.dll
    2010-07-27 17:44:10 107808 ----a-w- c:\windows\system32\dns-sd.exe

    ============= FINISH: 22:16:30.18 ===============
     
  3. jms

    jms TS Rookie Topic Starter

    DDS (Ver_10-10-10.03)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 26/12/2005 09:22:41
    System Uptime: 19/10/2010 22:03:47 (0 hours ago)

    Motherboard: Dell Inc. | | 0WF351
    Processor: Intel(R) Pentium(R) M processor 1.60GHz | Microprocessor | 1596/133mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 53 GiB total, 11.389 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================
    DDS Attach.text log


    No restore point in system.

    ==== Installed Programs ======================


    Adobe Acrobat 6.0 Professional
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Shockwave Player
    ALPS Touch Pad Driver
    Any Video Converter 3.0.7
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Avira AntiVir Personal - Free Antivirus
    AviSynth 2.5
    Bing Bar
    Bing Bar Platform
    Bonjour
    Broadcom Management Programs 2
    Canon G.726 WMP-Decoder
    CCleaner
    Compatibility Pack for the 2007 Office system
    Conexant D110 MDC V.92 Modem
    Convert AVI to MP4 1.3
    Defraggler
    Dell Driver Reset Tool
    DivX Setup
    Dropbox
    Glary Utilities 2.28.0.1011
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows XP (KB954550-v5)
    Intel(R) Graphics Media Accelerator Driver for Mobile
    Intel(R) PROSet/Wireless Software
    Internal Network Card Power Management
    Internet Explorer Default Page
    iPhoneBrowser
    iTunes
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2_03
    Java Auto Updater
    Java(TM) 6 Update 20
    Lexmark Z600 Series
    localhostr uploadr 1.2.2
    Malwarebytes' Anti-Malware
    mCore
    MCU
    mDrWiFi
    mHlpDell
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Default Manager
    Microsoft Office Basic Edition 2003
    Microsoft Search Enhancement Pack
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    mIWA
    mIWCA
    mLogView
    mMHouse
    Movie Rotator 1.2
    Mozilla ActiveX Control v1.7.12
    Mozilla Firefox (3.6.10)
    MP3 CD Doctor
    mPfMgr
    mPfWiz
    mProSafe
    mSSO
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6 Service Pack 2 (KB954459)
    mToolkit
    mWlsSafe
    mXML
    mZConfig
    NetWaiting
    O2 Broadband Assistant
    O2InstV3Win7UpdateV1
    Picasa 2
    PodLift
    Power Tab Editor 1.7
    PowerDVD 5.5
    PrimoPDF -- brought to you by Nitro PDF Software
    QuickTime
    RAD Video Tools
    RealPlayer Basic
    Rightmove Desktop
    Sage Instant Accounts
    Sage Instant Accounts V12.00
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows XP (KB896422)
    Security Update for Windows XP (KB896423)
    Security Update for Windows XP (KB899588)
    Security Update for Windows XP (KB899591)
    Security Update for Windows XP (KB901214)
    Security Update for Windows XP (KB944338-v2)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB978542)
    Skype™ 4.2
    SopCast 3.0.3
    Spotify
    Update for Windows XP (KB896727)
    VC80CRTRedist - 8.0.50727.4053
    VLC media player 1.0.1
    WebEx
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 8
    Windows Live ID Sign-in Assistant
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Hotfix - KB873339
    Windows XP Hotfix - KB885250
    Windows XP Hotfix - KB885835
    Windows XP Hotfix - KB885855
    Windows XP Hotfix - KB887472
    Windows XP Hotfix - KB888113
    Windows XP Hotfix - KB888310
    Windows XP Hotfix - KB890175
    Windows XP Hotfix - KB891781
    Windows XP Hotfix - KB892627
    Windows XP Hotfix - KB893056
    WinRAR archiver
    ZumoCast

    ==== Event Viewer Messages From Past Week ========

    19/10/2010 21:51:38, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss ssmdrv Tcpip
    19/10/2010 21:07:00, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
    19/10/2010 21:07:00, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    19/10/2010 20:17:17, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 20:17:14, error: Service Control Manager [7031] - The Windows Live ID Sign-in Assistant service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
    19/10/2010 20:17:11, error: Service Control Manager [7034] - The SeaPort service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 20:17:10, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 20:17:10, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 20:17:10, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
    19/10/2010 19:20:09, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.3664.
    19/10/2010 19:20:05, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\common files\system\wab32.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 6.0.2900.3138.
    19/10/2010 19:19:51, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msadox.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 2.81.1128.0.
    19/10/2010 19:13:58, error: VolSnap [12] - The shadow copy of volume C: became low on diff area space before it was properly installed.
    19/10/2010 18:43:18, error: Dhcp [1002] - The IP address lease 192.168.2.9 for the Network Card with network address 0013CED831B6 has been denied by the DHCP server 192.168.1.254 (The DHCP Server sent a DHCPNACK message).
    19/10/2010 16:39:30, error: atapi [9] - The device, \Device\Ide\IdePort1, did not respond within the timeout period.
    19/10/2010 16:33:55, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
    19/10/2010 16:33:55, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    19/10/2010 16:33:55, error: atapi [9] - The device, \Device\Ide\IdePort0, did not respond within the timeout period.
    19/10/2010 16:33:53, error: DCOM [10005] - DCOM got error "%1053" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
    19/10/2010 16:32:34, error: Service Control Manager [7022] - The Avira AntiVir Guard service hung on starting.
    19/10/2010 16:23:23, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD avgio avipbb Fips IntelIde intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 RasAcd Rdbss ssmdrv Tcpip
    19/10/2010 16:03:19, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avgio avipbb Fips intelppm ssmdrv
    19/10/2010 15:44:35, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: avgio AvgLdx86 AvgMfx86 avipbb Fips intelppm ssmdrv
    19/10/2010 15:34:33, error: Service Control Manager [7001] - The WLANKEEPER service depends on the EvtEng service which failed to start because of the following error: The system cannot find the file specified.
    19/10/2010 15:34:33, error: Service Control Manager [7001] - The Spectrum24 Event Monitor service depends on the EvtEng service which failed to start because of the following error: The system cannot find the file specified.
    19/10/2010 15:34:33, error: Service Control Manager [7000] - The RegSrvc service failed to start due to the following error: The system cannot find the file specified.
    19/10/2010 15:34:33, error: Service Control Manager [7000] - The NICCONFIGSVC service failed to start due to the following error: The system cannot find the file specified.
    19/10/2010 15:34:33, error: Service Control Manager [7000] - The EvtEng service failed to start due to the following error: The system cannot find the file specified.
    19/10/2010 15:28:05, information: Windows File Protection [64002] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msado15.dll. This file was restored to the original version to maintain system stability. The file version of the system file is 2.81.1128.0.
    19/10/2010 15:28:03, error: Service Control Manager [7034] - The SupportSoft Sprocket Service (O2) service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 15:28:03, error: Service Control Manager [7034] - The RegSrvc service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 15:28:03, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 15:28:03, error: Service Control Manager [7034] - The NICCONFIGSVC service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 15:28:03, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 15:28:03, error: Service Control Manager [7034] - The EvtEng service terminated unexpectedly. It has done this 1 time(s).
    19/10/2010 13:40:25, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the AntiVirSchedulerService service.
    19/10/2010 13:20:14, error: SideBySide [59] - Resolve Partial Assembly failed for Microsoft.VC90.CRT. Reference error message: The referenced assembly is not installed on your system. .
    19/10/2010 13:20:14, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\TRISH\LOCALS~1\Temp\RarSFX0\redist.dll. Reference error message: The operation completed successfully. .
    19/10/2010 13:20:14, error: SideBySide [32] - Dependent Assembly Microsoft.VC90.CRT could not be found and Last Error was The referenced assembly is not installed on your system.
    19/10/2010 13:02:30, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: IntelIde
    19/10/2010 13:02:03, error: Print [19] - Sharing printer failed + 1722, Printer WebEx Document Loader share name Printer.
    19/10/2010 12:36:22, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips IntelIde intelppm IPSec MRxSmb NetBIOS NetBT ohci1394 RasAcd Rdbss Tcpip
    19/10/2010 12:14:34, error: Dhcp [1002] - The IP address lease 192.168.1.66 for the Network Card with network address 0013CED831B6 has been denied by the DHCP server 192.168.2.1 (The DHCP Server sent a DHCPNACK message).
    19/10/2010 09:13:39, error: Service Control Manager [7000] - The Application Layer Gateway Service service failed to start due to the following error: Access is denied.
    15/10/2010 22:28:16, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
    15/10/2010 09:10:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MDM with arguments "" in order to run the server: {0C0A3666-30C9-11D0-8F20-00805F2CD064}
    15/10/2010 05:52:49, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3664, the version of the system file is 6.0.2900.3664.
    15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\wab32.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3138, the version of the system file is 6.0.2900.3138.
    15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\directdb.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3138, the version of the system file is 6.0.2900.3138.
    15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msjro.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
    15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msadox.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
    15/10/2010 05:48:09, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msadomd.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
    15/10/2010 05:29:02, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\wabimp.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3138, the version of the system file is 6.0.2900.3138.
    14/10/2010 18:27:24, error: DCOM [10000] - Unable to start a DCOM Server: {078AEF33-C48A-49F7-AFF3-A0EE810BFE7C}. The error: "%5" Happened while starting this command: C:\WINDOWS\system32\igfxsrvc.exe -Embedding
    14/10/2010 18:25:50, error: Service Control Manager [7023] - The HID Input Service service terminated with the following error: The specified module could not be found.
    14/10/2010 18:23:27, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    14/10/2010 18:23:18, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
    14/10/2010 17:57:45, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 AvgMfx86 Fips intelppm
    14/10/2010 17:54:29, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
    14/10/2010 17:43:05, error: Dhcp [1002] - The IP address lease 10.132.248.227 for the Network Card with network address 0013CED831B6 has been denied by the DHCP server 10.144.10.9 (The DHCP Server sent a DHCPNACK message).
    14/10/2010 15:51:35, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is TRISH.
    14/10/2010 15:51:17, information: Windows File Protection [64016] - Windows File Protection file scan was started.
    14/10/2010 15:22:32, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {9B1F122C-2982-4E91-AA8B-E071D54F2A4D}
    14/10/2010 15:17:11, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\outlook express\msoe.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 6.0.2900.3598, the version of the system file is 6.0.2900.3598.
    14/10/2010 14:03:41, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\program files\common files\system\ado\msado15.dll. This file was restored to the original version to maintain system stability. The file version of the bad file is 2.81.1128.0, the version of the system file is 2.81.1128.0.
    14/10/2010 14:00:52, information: Windows File Protection [64017] - Windows File Protection file scan completed successfully.
    14/10/2010 09:39:43, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
    14/10/2010 09:17:28, error: DCOM [10000] - Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}. The error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
    13/10/2010 18:36:57, error: PSched [14103] - QoS [Adapter {EDE620B1-E5E5-4796-9C47-913B87A8842F}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
    13/10/2010 18:18:49, error: Service Control Manager [7000] - The AVG Free8 E-mail Scanner service failed to start due to the following error: Access is denied.
    13/10/2010 18:08:08, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: Access is denied.
    13/10/2010 18:08:08, error: DCOM [10005] - DCOM got error "%5" attempting to start the service iPod Service with arguments "" in order to run the server: {063D34A4-BF84-4B8D-B699-E8CA06504DDE}
    13/10/2010 10:38:52, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
    12/10/2010 14:29:47, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
    12/10/2010 14:29:47, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
    12/10/2010 14:29:47, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    12/10/2010 14:29:47, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    12/10/2010 14:29:47, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    12/10/2010 14:29:47, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    12/10/2010 14:29:47, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.

    ==== End Of File ===========================


    Thank you.
     
  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Welcome to TechSpot! But I won't have good news for you. From what entries I'm seeing, it appears that you have the file infector Ramnit. Before I give you the bad news, let's be sure:


    Run Eset NOD32 Online AntiVirus scan HERE
    1. Tick the box next to YES, I accept the Terms of Use.
    2. Click Start
    3. When asked, allow the Active X control to install
    4. Disable your current Antivirus software. You can usually do this with its Notification Tray icon near the clock.
    5. Click Start
    6. Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is checked
    7. Click Scan
    8. Wait for the scan to finish
    9. Re-enable your Antivirus software.
    10. A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please include this on your post.

    Don't try doing any more scans or downloading any more programs at this point. If it is Ramnit, you will have to reformat/reinstall.
     
  5. jms

    jms TS Rookie Topic Starter

    Hi Bobbye

    Many thanks for your help. I thought it might be bad news. I've run ESET, although it would only run in Safe mode and unfortunately when the scan got to 99% after over an hour I got the blue screen of death and the log didn't save. However it had reported over 2000 infected files with the Ramnit virus as you thought.

    However I also ran it on my home PC (the other one is my laptop) which I thought might also be infected. This one was even worse with over 8000 infected files with Ramnit! I will try paste the log in the next post as I've had a few problems inserting it into this post and am having to rewrite it again.

    So I think I must have passed the virus from my home pc onto my laptop with a USB stick drive - so I now have 2 infected computers and 2 infected USB stick drives.

    Obviously I need to reformat both PC's but can you please help me with how to do this and more importantly how I can save required files without then infecting another computer when I transfer them. I don't have an external hard drive - if I buy a new USB drive is there any way I can transfer files from the 2 pcs and other USB sticks - but how can I be sure the files aren't infected?!

    Also is there any way of reformatting the computers without the original disks? They are both Dell computers running XP - I believe the laptop didn't come with back up disk but apparently I can do a PC restore as I have Dell PC Restore by Symantec which can restore to original factory state as back up is stored on the hard drive - or will these files be infected?

    I have spoken to Dell and they can send backup disks and drivers but these will cost £25 each. I can get an XP disk from another family member from one of their computers - will that work if I use the right key code from the infected PC's?

    Sorry for so many questions - I just want to be able to backup my files and then not infected any more computers!

    I'll try and post the log again in the next post. Thanks again for your help.
     
  6. jms

    jms TS Rookie Topic Starter

    I've tried to post the log again but it's far too big - will have to separate it into loads of different posts if you want to see it - or I can attach it.

    But the result is defintely conclusive - that both my PC's are badly infected with Ramnit - so I don't think I have many options.

    Thanks - let me know if you want me to attach log
     
  7. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    If you see that much evidence of Ramnit, here's what you need to know about it:

    Win32/Ramnit.A is a file infector with IRCBot functionality which infects .exe, and .HTML/HTM files, and opens a back door that compromises your computer. Using this backdoor, a remote attacker can access and instruct the infected computer to download and execute more malicious files. The infected .HTML or .HTM files may be detected as Virus:VBS/Ramnit.A. Win32/Ramnit.A!dll is a related file infector often seen with this infection. It too has IRCBot functionality which infects .exe, .dll and .HTML/HTM files and opens a back door that compromises your computer. This component is injected into the default web browser by Worm:Win32/Ramnit.A which is dropped by a Ramnit infected executable file.

    -- Note: As with most malware infections, the threat name may be different depending on the anti-virus or anti-malware program which detected it. Each security vendor uses their own naming conventions to identify various types of malware.
    With this particular infection the safest solution and only sure way to remove it effectively is to reformat and reinstall the OS.

    Why? The malware injects code in legitimate files similar to the Virut virus and in many cases the infected files (which could number in the thousands) cannot be disinfected properly by your anti-virus. When disinfection is attempted, the files often become corrupted and the system may become unstable or irreparable. The longer Ramnit.A remains on a computer, the more files it infects and corrupts so the degree of infection can vary.

    Ramnit is commonly spread via a flash drive (usb, pen, thumb, jump) infection where it copies Worm:Win32/Ramnit.A with a random file name. The infection is often contracted by visiting remote, crack and keygen sites. These type of sites are infested with a smörgåsbord of malware and a major source of system infection.

    In my opinion, Ramnit.A is not effectively disinfectable, so your best option is to perform a full reformat as there is no guarantee this infection can be completely removed. In most instances it may have caused so much damage to your system files that it cannot be completely cleaned or repaired. Further, your machine has likely been compromised by the backdoor Trojan and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume the computer is secure even if your anti-virus reports that the malware appears to have been removed.

    Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read:
    Backdoors and What They Mean to You

    This is what Jesper M. Johansson at Microsoft TechNet has to say: Help: I Got Hacked. Now What Do I Do?.

    Important Note:: If your computer was used for online banking, has credit card information or other sensitive data on it, you should disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to to include those used for banking, email, eBay, paypal and any online activities which require a username and password. You should consider them to be compromised. You should change each password using a clean computer and not the infected one. If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach. Failure to notify your financial institution and local law enforcement can result in refusal to reimburse funds lost due to fraud or similar criminal activity.

    Ramnit Tutorial Courtesy Broni.
     
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.