Help - Search - Members - Calendar
Full Version: can not remove virus even in safe mode
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive HijackThis Logs
chefdan
I have the TR/Alureon 215040.1 virus that i can not remove automatically chat support said to post for manual instruction on how remove My pc runs widows xp
Blade81
Hi,

Download DDS and save it to your desktop from here or here or here.
Disable any script blocker, and then double click dds.scr to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt
  • Save both reports to your desktop. Post them back to your topic.

  • Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.
    chefdan
    GMER 1.0.15.15125 - http://www.gmer.net
    Rootkit scan 2009-10-15 12:16:12
    Windows 5.1.2600 Service Pack 3
    Running: k7tbbjcw.exe; Driver: C:\DOCUME~1\CHEFDA~1.VAL\LOCALS~1\Temp\pweoapow.sys


    ---- System - GMER 1.0.15 ----

    Code 86FA0B98 ZwEnumerateKey
    Code 86F7E558 ZwFlushInstructionCache
    Code 86C5DE56 ZwSaveKey
    Code 86C5C9F6 ZwSaveKeyEx
    Code 86C5F666 IofCallDriver
    Code 86C64A2E IofCompleteRequest

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 86C5F66B
    .text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 86C64A33
    PAGE ntoskrnl.exe!ZwEnumerateKey 80578E14 5 Bytes JMP 86FA0B9C
    PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 86F7E55C
    PAGE ntoskrnl.exe!ZwSaveKey 8065616E 5 Bytes JMP 86C5DE5A
    PAGE ntoskrnl.exe!ZwSaveKeyEx 80656259 5 Bytes JMP 86C5C9FA
    .rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF756E780]

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

    Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdePort0 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdePort1 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F7561B3A] atapi.sys[unknown section]
    ---- Processes - GMER 1.0.15 ----

    Library \\?\globalroot\systemroot\system32\kbiwkmwnvxvaln.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [524] 0x00C10000
    Library \\?\globalroot\systemroot\system32\kbiwkmwnvxvaln.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [2524] 0x08DB0000

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\drivers\kbiwkmqkumpmyx.sys (*** hidden *** ) [SYSTEM] kbiwkmsvptpfkq <-- ROOTKIT !!!

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@start 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@type 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@group file system
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@imagepath \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main@aid 10096
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main@sid 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main@cmddelay 14400
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\delete
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\injector
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\injector@* kbiwkmwsp8y.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\tasks
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmobdodhal.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmnqgdiqro.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmyufoaucd.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkm.dat \systemroot\system32\kbiwkmtacpidlu.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8.dll \systemroot\system32\kbiwkmdjolewin.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8x.dll \systemroot\system32\kbiwkmpxnsswwy.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8y.dll \systemroot\system32\kbiwkmwnvxvaln.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@start 1
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@type 1
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@group file system
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@imagepath \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main@aid 10096
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main@sid 0
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main@cmddelay 14400
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\delete (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\injector (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\injector@* kbiwkmwsp8y.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\tasks (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmobdodhal.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmnqgdiqro.dat
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmyufoaucd.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkm.dat \systemroot\system32\kbiwkmtacpidlu.dat
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8.dll \systemroot\system32\kbiwkmdjolewin.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8x.dll \systemroot\system32\kbiwkmpxnsswwy.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8y.dll \systemroot\system32\kbiwkmwnvxvaln.dll

    ---- Files - GMER 1.0.15 ----

    File C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Quarantine\kbiwkmwnvxvaln.dll.1a5a4b2f95939f3d8f28ecc9147636b.aawqff 21508 bytes
    File C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Quarantine\kbiwkmwnvxvaln.dll.80e114e4b08b3738f88f7a5c3b4b708f.1a5a4b2f95939f3d8f28ecc
    9147636b.aawqff 21508 bytes
    File C:\Documents and Settings\All Users\Start Menu\Categories.xml 1257 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Chapter 1_Img.png 9131 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Chapter 1_Tmb.png 137 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Chapter 2_Img.png 5296 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Next_Img.png 1174 bytes
    File C:\RECYCLER\Categories.xml 1261 bytes
    File C:\RECYCLER\DvdThemeDef.dtd 2233 bytes
    File C:\RECYCLER\F.STP 1454994 bytes
    File C:\RECYCLER\M.STP 899602 bytes
    File C:\RECYCLER\MenuGroup_FM.xml 8023 bytes
    File C:\RECYCLER\MenuGroup_FS.xml 8021 bytes
    File C:\RECYCLER\MenuGroup_M.xml 8055 bytes
    File C:\RECYCLER\MenuGroup_P.xml 8053 bytes
    File C:\RECYCLER\MenuGroup_T.xml 4335 bytes
    File C:\RECYCLER\nt-movie6_F_Chapter 1_Img.png 1931 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 017.jpg 2650313 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 034.jpg 2640557 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 051.jpg 1841040 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 068.jpg 2405539 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 083.jpg 1795143 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 101.jpg 2074601 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\AlbumArtSmall.jpg 2302 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Large.jpg 12820 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Small.jpg 2302 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Desktop.ini 512 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Folder.jpg 12820 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\music.asx 768 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\music.bmp 18488 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\music.wma 3497147 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\My Playlists 0 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Sample Music 0 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Sample Playlists 0 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Sync Playlists 0 bytes

    ---- EOF - GMER 1.0.15 ----
    Blade81
    Please post DDS related logs too.
    chefdan
    GMER 1.0.15.15125 - http://www.gmer.net
    Rootkit scan 2009-10-15 12:16:12
    Windows 5.1.2600 Service Pack 3
    Running: k7tbbjcw.exe; Driver: C:\DOCUME~1\CHEFDA~1.VAL\LOCALS~1\Temp\pweoapow.sys


    ---- System - GMER 1.0.15 ----

    Code 86FA0B98 ZwEnumerateKey
    Code 86F7E558 ZwFlushInstructionCache
    Code 86C5DE56 ZwSaveKey
    Code 86C5C9F6 ZwSaveKeyEx
    Code 86C5F666 IofCallDriver
    Code 86C64A2E IofCompleteRequest

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!IofCallDriver 804E13A7 5 Bytes JMP 86C5F66B
    .text ntoskrnl.exe!IofCompleteRequest 804E17BD 5 Bytes JMP 86C64A33
    PAGE ntoskrnl.exe!ZwEnumerateKey 80578E14 5 Bytes JMP 86FA0B9C
    PAGE ntoskrnl.exe!ZwFlushInstructionCache 80587BFB 5 Bytes JMP 86F7E55C
    PAGE ntoskrnl.exe!ZwSaveKey 8065616E 5 Bytes JMP 86C5DE5A
    PAGE ntoskrnl.exe!ZwSaveKeyEx 80656259 5 Bytes JMP 86C5C9FA
    .rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF756E780]

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)

    Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdePort0 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdePort1 [F7561B3A] atapi.sys[unknown section]
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F7561B3A] atapi.sys[unknown section]
    ---- Processes - GMER 1.0.15 ----

    Library \\?\globalroot\systemroot\system32\kbiwkmwnvxvaln.dll (*** hidden *** ) @ C:\WINDOWS\Explorer.EXE [524] 0x00C10000
    Library \\?\globalroot\systemroot\system32\kbiwkmwnvxvaln.dll (*** hidden *** ) @ C:\Program Files\Mozilla Firefox\firefox.exe [2524] 0x08DB0000

    ---- Services - GMER 1.0.15 ----

    Service C:\WINDOWS\system32\drivers\kbiwkmqkumpmyx.sys (*** hidden *** ) [SYSTEM] kbiwkmsvptpfkq <-- ROOTKIT !!!

    ---- Registry - GMER 1.0.15 ----

    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@start 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@type 1
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@group file system
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq@imagepath \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main@aid 10096
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main@sid 0
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main@cmddelay 14400
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\delete
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\injector
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\injector@* kbiwkmwsp8y.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\main\tasks
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmobdodhal.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmnqgdiqro.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmyufoaucd.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkm.dat \systemroot\system32\kbiwkmtacpidlu.dat
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8.dll \systemroot\system32\kbiwkmdjolewin.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8x.dll \systemroot\system32\kbiwkmpxnsswwy.dll
    Reg HKLM\SYSTEM\CurrentControlSet\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8y.dll \systemroot\system32\kbiwkmwnvxvaln.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@start 1
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@type 1
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@group file system
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq@imagepath \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main@aid 10096
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main@sid 0
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main@cmddelay 14400
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\delete (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\injector (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\injector@* kbiwkmwsp8y.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\main\tasks (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules (not active ControlSet)
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmrk.sys \systemroot\system32\drivers\kbiwkmqkumpmyx.sys
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmcmd.dll \systemroot\system32\kbiwkmobdodhal.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmlog.dat \systemroot\system32\kbiwkmnqgdiqro.dat
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp.dll \systemroot\system32\kbiwkmyufoaucd.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkm.dat \systemroot\system32\kbiwkmtacpidlu.dat
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8.dll \systemroot\system32\kbiwkmdjolewin.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8x.dll \systemroot\system32\kbiwkmpxnsswwy.dll
    Reg HKLM\SYSTEM\ControlSet002\Services\kbiwkmsvptpfkq\modules@kbiwkmwsp8y.dll \systemroot\system32\kbiwkmwnvxvaln.dll

    ---- Files - GMER 1.0.15 ----

    File C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Quarantine\kbiwkmwnvxvaln.dll.1a5a4b2f95939f3d8f28ecc9147636b.aawqff 21508 bytes
    File C:\Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\Quarantine\kbiwkmwnvxvaln.dll.80e114e4b08b3738f88f7a5c3b4b708f.1a5a4b2f95939f3d8f28ecc
    9147636b.aawqff 21508 bytes
    File C:\Documents and Settings\All Users\Start Menu\Categories.xml 1257 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Chapter 1_Img.png 9131 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Chapter 1_Tmb.png 137 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Chapter 2_Img.png 5296 bytes
    File C:\Documents and Settings\All Users\Start Menu\cinema-still1_F_Next_Img.png 1174 bytes
    File C:\RECYCLER\Categories.xml 1261 bytes
    File C:\RECYCLER\DvdThemeDef.dtd 2233 bytes
    File C:\RECYCLER\F.STP 1454994 bytes
    File C:\RECYCLER\M.STP 899602 bytes
    File C:\RECYCLER\MenuGroup_FM.xml 8023 bytes
    File C:\RECYCLER\MenuGroup_FS.xml 8021 bytes
    File C:\RECYCLER\MenuGroup_M.xml 8055 bytes
    File C:\RECYCLER\MenuGroup_P.xml 8053 bytes
    File C:\RECYCLER\MenuGroup_T.xml 4335 bytes
    File C:\RECYCLER\nt-movie6_F_Chapter 1_Img.png 1931 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 017.jpg 2650313 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 034.jpg 2640557 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 051.jpg 1841040 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 068.jpg 2405539 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 083.jpg 1795143 bytes
    File C:\System Volume Information\_restore{549DE6A1-CCD3-45E9-A3FB-BD70F79FB4CC}\RP364\2009 house 101.jpg 2074601 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\AlbumArtSmall.jpg 2302 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Large.jpg 12820 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\AlbumArt_{79D3A434-2D93-4194-AD18-F79744B5CF43}_Small.jpg 2302 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Desktop.ini 512 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Folder.jpg 12820 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\music.asx 768 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\music.bmp 18488 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\music.wma 3497147 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\My Playlists 0 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Sample Music 0 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Sample Playlists 0 bytes
    File C:\WINDOWS\$hf_mig$\KB971657\update\Sync Playlists 0 bytes

    ---- EOF - GMER 1.0.15 ----

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-10-13.01)

    Microsoft Windows XP Home Edition
    Boot Device: \Device\HarddiskVolume2
    Install Date: 10/28/2008 4:37:54 PM
    System Uptime: 10/15/2009 7:37:23 AM (4 hours ago)

    Motherboard: ASUSTek Computer Inc. | | P4SD-VL
    Processor: Intel® Pentium® 4 CPU 3.00GHz | CPU 1 | 2992/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 144 GiB total, 129.26 GiB free.
    D: is CDROM (CDFS)
    E: is CDROM ()
    F: is Removable
    G: is Removable
    H: is Removable

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP315: 9/1/2009 7:13:46 PM - System Checkpoint
    RP316: 9/1/2009 7:13:47 PM - System Checkpoint
    RP317: 9/1/2009 7:13:47 PM - System Checkpoint
    RP318: 9/1/2009 7:13:48 PM - System Checkpoint
    RP319: 9/1/2009 7:13:48 PM - System Checkpoint
    RP320: 9/1/2009 7:13:48 PM - System Checkpoint
    RP321: 9/1/2009 7:13:49 PM - Software Distribution Service 3.0
    RP322: 9/1/2009 7:13:49 PM - System Checkpoint
    RP323: 9/1/2009 7:13:49 PM - System Checkpoint
    RP324: 9/1/2009 7:13:49 PM - System Checkpoint
    RP325: 9/1/2009 7:13:49 PM - System Checkpoint
    RP326: 9/1/2009 7:13:50 PM - System Checkpoint
    RP327: 9/1/2009 7:13:50 PM - System Checkpoint
    RP328: 9/1/2009 7:13:50 PM - System Checkpoint
    RP329: 9/1/2009 7:13:50 PM - System Checkpoint
    RP330: 9/1/2009 7:13:51 PM - System Checkpoint
    RP331: 9/1/2009 7:13:51 PM - System Checkpoint
    RP332: 9/1/2009 7:13:51 PM - System Checkpoint
    RP333: 9/1/2009 7:13:51 PM - System Checkpoint
    RP334: 9/1/2009 7:13:51 PM - System Checkpoint
    RP335: 9/1/2009 7:13:52 PM - System Checkpoint
    RP336: 9/1/2009 7:13:52 PM - System Checkpoint
    RP337: 9/1/2009 7:13:52 PM - System Checkpoint
    RP338: 9/1/2009 7:13:52 PM - System Checkpoint
    RP339: 9/1/2009 7:13:53 PM - System Checkpoint
    RP340: 9/1/2009 7:13:53 PM - System Checkpoint
    RP341: 9/1/2009 7:13:53 PM - Software Distribution Service 3.0
    RP342: 9/1/2009 7:13:53 PM - System Checkpoint
    RP343: 9/1/2009 7:13:53 PM - System Checkpoint
    RP344: 9/1/2009 7:13:54 PM - System Checkpoint
    RP345: 9/1/2009 7:13:54 PM - System Checkpoint
    RP346: 9/1/2009 7:13:54 PM - System Checkpoint
    RP347: 9/1/2009 7:13:54 PM - Software Distribution Service 3.0
    RP348: 9/1/2009 7:13:54 PM - System Checkpoint
    RP349: 9/1/2009 7:13:55 PM - System Checkpoint
    RP350: 9/1/2009 7:13:55 PM - System Checkpoint
    RP351: 9/1/2009 7:13:55 PM - System Checkpoint
    RP352: 9/1/2009 7:13:56 PM - Software Distribution Service 3.0
    RP353: 9/1/2009 7:13:57 PM - System Checkpoint
    RP354: 9/1/2009 7:13:58 PM - System Checkpoint
    RP355: 9/1/2009 7:13:58 PM - Software Distribution Service 3.0
    RP356: 9/1/2009 7:13:58 PM - System Checkpoint
    RP357: 9/1/2009 7:13:58 PM - System Checkpoint
    RP358: 9/1/2009 7:13:58 PM - System Checkpoint
    RP359: 9/1/2009 7:13:59 PM - System Checkpoint
    RP360: 9/1/2009 7:13:59 PM - System Checkpoint
    RP361: 9/1/2009 7:13:59 PM - System Checkpoint
    RP362: 9/1/2009 7:13:59 PM - System Checkpoint
    RP363: 9/1/2009 7:13:59 PM - Software Distribution Service 3.0
    RP364: 9/1/2009 7:13:59 PM - Software Distribution Service 3.0
    RP365: 9/1/2009 7:14:00 PM - System Checkpoint
    RP366: 9/1/2009 7:14:00 PM - System Checkpoint
    RP367: 9/1/2009 7:14:00 PM - Ad-Aware Restore Point 2009-08-19 20:54:56
    RP368: 9/1/2009 7:14:00 PM - Software Distribution Service 3.0
    RP369: 9/1/2009 7:14:01 PM - System Checkpoint
    RP370: 9/1/2009 7:14:01 PM - System Checkpoint
    RP371: 9/1/2009 7:14:01 PM - System Checkpoint
    RP372: 9/1/2009 7:14:01 PM - System Checkpoint
    RP373: 9/1/2009 7:14:02 PM - Software Distribution Service 3.0
    RP374: 9/1/2009 7:14:02 PM - System Checkpoint
    RP375: 9/1/2009 7:14:02 PM - System Checkpoint
    RP376: 9/1/2009 7:14:02 PM - System Checkpoint
    RP377: 9/1/2009 7:14:02 PM - System Checkpoint
    RP378: 9/8/2009 12:45:17 PM - System Checkpoint
    RP379: 9/14/2009 8:07:08 PM - System Checkpoint
    RP380: 9/15/2009 9:15:21 PM - System Checkpoint
    RP381: 9/22/2009 11:46:30 AM - System Checkpoint
    RP382: 10/10/2009 1:58:06 PM - System Checkpoint
    RP383: 10/13/2009 8:25:04 AM - System Checkpoint

    ==== Installed Programs ======================


    Ad-Aware
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Reader 6.0.1
    Adobe Shockwave Player
    Agere Systems AC'97 Modem
    AOL Setup
    Apple Mobile Device Support
    Apple Software Update
    ATI - Software Uninstall Utility
    ATI Control Panel
    ATI Display Driver
    Bonjour
    Click to DVD 2.0 Menu Data
    Click to DVD 2.0.02
    CONNECT
    Critical Update for Windows Media Player 11 (KB959772)
    Drag'n Drop CD+DVD
    DVgate Plus
    Garmin Communicator Plugin
    Garmin USB Drivers
    Giga Pocket 5.5
    Giga Pocket Demo Movie
    Giga Pocket Hardware Library 5.5
    Google Toolbar for Internet Explorer
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB970653-v3)
    Intel® Extreme Graphics Driver
    Intel® PRO Network Adapters and Drivers
    InterVideo WinDVD 5 for VAIO
    iTunes
    Java 2 Runtime Environment, SE v1.4.2_01
    Leap Ahead Spelling
    Lexmark 5200 Series
    Lexmark Fax Solutions
    Memory Stick Formatter
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Standard Edition 2003
    Microsoft Silverlight
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Works 7.0
    Mozilla Firefox (3.0.14)
    Netscape (7.02)
    Netscape Internet Service Setup
    OpenMG Limited Patch 3.4-03-12-16-01
    OpenMG Secure Module 3.4.00
    Panda ActiveScan 2.0
    PictureGear Studio 2.0
    Quicken 2004
    QuickTime
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB938127-v2)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB972260)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 9 (KB917734)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973869)
    SonicStage 2.0.02
    Sony Certificate PCH
    Sony Video Shared Library
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB973815)
    VAIO Entertainment Platform
    VAIO Help and Support
    VAIO Media 3.0
    VAIO Media Integrated Server 3.0
    VAIO Media Redistribution 3.0
    VAIO Registration
    VAIO Remote Commander Utility 6.2
    VAIO SLIT-C Screen Saver
    VAIO SLIT Pattern Wallpaper
    VAIO Survey Standalone
    VAIO System Information
    VAIO Update 2
    Viewpoint Media Player
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WebFldrs XP
    Welcome to VAIO life
    Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 7
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3

    ==== Event Viewer Messages From Past Week ========

    10/9/2009 8:42:07 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
    10/9/2009 8:42:07 AM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
    10/8/2009 9:43:58 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
    10/13/2009 9:26:25 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
    10/11/2009 11:39:07 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
    10/11/2009 11:38:15 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    10/11/2009 11:37:58 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DMICall Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
    10/11/2009 11:37:58 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
    10/11/2009 11:37:58 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/11/2009 11:37:58 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/11/2009 11:37:58 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
    10/11/2009 11:37:58 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/11/2009 11:37:58 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
    10/11/2009 11:30:36 AM, error: Print [6161] - The document Optimum Online Webmail owned by CHEFDAN failed to print on printer Lexmark 5200 Series. Data type: LEMF. Size of the spool file in bytes: 921429. Number of bytes printed: 921429. Total number of pages in the document: 3. Number of pages printed: 0. Client machine: \\VALUED-664B84C7. Win32 error code returned by the print processor: 535 (0x217).
    10/10/2009 6:12:16 AM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 00112F0E0E1C has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

    ==== End Of File ===========================
    Blade81
    You posted GMER log again instead of dds.txt log. Could you post the missing one too, please?
    Blade81
    Due to lack of feedback, this topic has been closed.

    If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

    Everyone else please begin a New Topic.

    Thank You !
    This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
    Invision Power Board © 2001-2009 Invision Power Services, Inc.