System Guard 2009/ Win32/nuqel.e Help Me Please

Page 1 of 2 1, 2  Next

View previous topic View next topic Go down

System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Wed 03 Mar 2010, 1:42 pm

I'm new at this posting and I may have posted this elsewhere so if so i apologize .
I ran Malwarebytes removed 2 trojans and even ran Tuneup utilities which found 41 issues. So as I remove them they come back. After reading other post I'll show my last scan log from hijack this as others have in hopes of some help.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:09:00 PM, on 3/2/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\WINDOWS\Explorer.EXE
D:\mozilla firefox\firefox.exe
D:\Hijack This\winlogon.scr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [You must be registered and logged in to see this link.]
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: 69.253.151.209 idenupdate.motorola.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [LogMeIn GUI] "D:\Logmein\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [UnlockerAssistant] "D:\Unlocker\UnlockerAssistant.exe" -H
O4 - HKLM\..\Run: [HP Software Update] D:\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [CPMonitor] "D:\Roxio\Roxio 2010\5.0\CPMonitor.exe"
O4 - HKLM\..\Run: [Desktop Disc Tool] "D:\Roxio\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe"
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe"
O4 - HKLM\..\Run: [QuickTime Task] "D:\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "D:\ItUNES\iTunesHelper.exe"
O4 - HKLM\..\Run: [sesbneds] C:\Documents and Settings\Potters Trucking\Local Settings\Application Data\ksnbae\vnkksftav.exe
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\SpyBot\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [sesbneds] C:\Documents and Settings\Potters Trucking\Local Settings\Application Data\ksnbae\vnkksftav.exe
O4 - Global Startup: InterVideo WinScheduler.lnk = D:\WinDVR3\SchSvr.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = D:\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = D:\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = D:\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\SpyBot\SPYBOT~1\SDHelper.dll
O9 - Extra button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra 'Tools' menuitem: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: [You must be registered and logged in to see this link.]
O15 - Trusted Zone: [You must be registered and logged in to see this link.]
O15 - Trusted Zone: [You must be registered and logged in to see this link.]
O15 - Trusted Zone: [You must be registered and logged in to see this link.]
O15 - Trusted Zone: [You must be registered and logged in to see this link.]
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - [You must be registered and logged in to see this link.]
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - [You must be registered and logged in to see this link.]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [You must be registered and logged in to see this link.]
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - [You must be registered and logged in to see this link.]
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Roxio SAIB Service (9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269) - Unknown owner - C:\Program Files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CinemaNow Service - CinemaNow, Inc. - C:\Program Files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - D:\Logmein\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - D:\Logmein\x86\LogMeIn.exe
O23 - Service: Office Source Engine (ose) - Unknown owner - C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RoxMediaDB12 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe
O23 - Service: Roxio Hard Drive Watcher 12 (RoxWatch12) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\WINDOWS\System32\TuneUpDefragService.exe
O23 - Service: TuneUp Program Statistics Service (TuneUp.ProgramStatisticsSvc) - TuneUp Software - C:\WINDOWS\System32\TUProgSt.exe

--
End of file - 9728 bytes
PLEASE HELP!!!! me remove this worm or whatever it is...

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Wed 03 Mar 2010, 4:35 pm

Please download [You must be registered and logged in to see this link.], and save to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.zip, and extract the file to your Desktop.
  • Double-click on Cheetah-Anti-Rogue.cmd to start.
  • It will finish quickly and launch a log.
  • Post the contents of it in your next reply.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Fri 05 Mar 2010, 10:20 am

Thank you so much for responding.
Cheetah-Anti-Rogue v1.3.11
by DragonMaster Jay

Microsoft Windows XP [Version 5.1.2600]
Date: 03/04/2010 - Time: 18:19:48 - Arch.: x86


-- Malware removal tools check --


-- Known infection --



Extra message: Detection only.


EOF

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Fri 05 Mar 2010, 12:09 pm

Malwarebytes' Anti-Malware 1.44
Database version: 3740
Windows 5.1.2600 Service Pack 2 (Safe Mode)
Internet Explorer 7.0.5730.11

3/4/2010 8:06:21 PM
mbam-log-2010-03-04 (20-06-21).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 254338
Time elapsed: 34 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Fri 05 Mar 2010, 12:25 pm

After I ran Tuneup Utilities i get 41 problems and when I clean them they come back.
{434EFE25-2944-4196-B6EA-22D001F277B2}
--------------------------------------
The key HKEY_CLASSES_ROOT\CLSID\{434EFE25-2944-4196-B6EA-22D001F277B2}\TreatAs points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{4AD5597A-2B0F-4479-97B6-C514DEC41EA1}.
Add Content Source Wizard
-------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:wizard/addsearchcontentlocation\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12461. The reference should be deleted so that Windows does not try to find the icon.
Additional Content Source Settings
----------------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:catalog-settings\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12471. The reference should be deleted so that Windows does not try to find the icon.
AIFF Audio File
---------------
The key HKEY_CLASSES_ROOT\iTunes.aifc\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
AIFF Audio File
---------------
The key HKEY_CLASSES_ROOT\iTunes.aiff\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
AIFF Audio File
---------------
The key HKEY_CLASSES_ROOT\iTunes.aif\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
AtWorkRendering
---------------
The file type points to the missing program 0 in the key HKEY_CLASSES_ROOT\AtWorkRendering\shell\PrintTo\command.
Content Sources Folder
----------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:catalog\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,15. The reference should be deleted so that Windows does not try to find the icon.
Database Content Source
-----------------------
The key HKEY_CLASSES_ROOT\dcsfile\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,11. The reference should be deleted so that Windows does not try to find the icon.
Exchange Server 2000 Content Source
-----------------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:exchangestartaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12451. The reference should be deleted so that Windows does not try to find the icon.
Exchange Server 5.5 Content Source
----------------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:exchange55startaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12451. The reference should be deleted so that Windows does not try to find the icon.
Exchange Server Content Source
------------------------------
The key HKEY_CLASSES_ROOT\ecsfile\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,10. The reference should be deleted so that Windows does not try to find the icon.
File Share Content Source
-------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:filestartaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12453. The reference should be deleted so that Windows does not try to find the icon.
File Share Content Source
-------------------------
The key HKEY_CLASSES_ROOT\fcsfile\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,12. The reference should be deleted so that Windows does not try to find the icon.
Lotus Notes Content Source
--------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:notesstartaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12456. The reference should be deleted so that Windows does not try to find the icon.
Lotus Notes Content Source
--------------------------
The key HKEY_CLASSES_ROOT\ncsfile\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,14. The reference should be deleted so that Windows does not try to find the icon.
Management Folder
-----------------
The key HKEY_CLASSES_ROOT\urn:content-classes:management\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,20. The reference should be deleted so that Windows does not try to find the icon.
Movie File
----------
The key HKEY_CLASSES_ROOT\iTunes.mov\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
MPEG File
---------
The key HKEY_CLASSES_ROOT\iTunes.mpg\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
MPEG File
---------
The key HKEY_CLASSES_ROOT\iTunes.mpeg\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
MPEG Layer 3 Audio
------------------
The key HKEY_CLASSES_ROOT\iTunes.mp3\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
MPEG-4 Audio File
-----------------
The key HKEY_CLASSES_ROOT\iTunes.m4a\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
MPEG-4 Video File
-----------------
The key HKEY_CLASSES_ROOT\iTunes.m4v\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
OISbmpfile
----------
The key HKEY_CLASSES_ROOT\OISbmpfile is empty. The associated file type is useless and can be deleted.
OISemffile
----------
The key HKEY_CLASSES_ROOT\OISemffile is empty. The associated file type is useless and can be deleted.
OISgiffile
----------
The key HKEY_CLASSES_ROOT\OISgiffile is empty. The associated file type is useless and can be deleted.
OISjpegfile
-----------
The key HKEY_CLASSES_ROOT\OISjpegfile is empty. The associated file type is useless and can be deleted.
OISpngfile
----------
The key HKEY_CLASSES_ROOT\OISpngfile is empty. The associated file type is useless and can be deleted.
OIStiffile
----------
The key HKEY_CLASSES_ROOT\OIStiffile is empty. The associated file type is useless and can be deleted.
OISwmffile
----------
The key HKEY_CLASSES_ROOT\OISwmffile is empty. The associated file type is useless and can be deleted.
Tahoe Server Content Source
---------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:remoteworkspacestartaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12454. The reference should be deleted so that Windows does not try to find the icon.
Tahoe Server Content Source
---------------------------
The key HKEY_CLASSES_ROOT\tcsfile\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,13. The reference should be deleted so that Windows does not try to find the icon.
urn:content-classes:contentclassdef
-----------------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:contentclassdef\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-13101. The reference should be deleted so that Windows does not try to find the icon.
urn:content-classes:wizard/addcontentclass
------------------------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:wizard/addcontentclass\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-13100. The reference should be deleted so that Windows does not try to find the icon.
WAVE Audio File
---------------
The key HKEY_CLASSES_ROOT\iTunes.wav\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
WAVE Audio File
---------------
The key HKEY_CLASSES_ROOT\iTunes.wave\ShellEx\{8895b1c6-b41f-4c1c-a562-0d564250836f} points to the missing CLSID HKEY_CLASSES_ROOT\CLSID\{031EE060-67BC-460d-8847-E4A7C5E45A27}.
Web Site Content Source
-----------------------
The key HKEY_CLASSES_ROOT\wcsfile\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,9. The reference should be deleted so that Windows does not try to find the icon.
Web Site Content Source
-----------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:webstartaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12450. The reference should be deleted so that Windows does not try to find the icon.
Workspace Configuration
-----------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:workspaceconfiguration\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12476. The reference should be deleted so that Windows does not try to find the icon.
Workspace Content Source
------------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:workspacestartaddress\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12454. The reference should be deleted so that Windows does not try to find the icon.
Workspace Settings
------------------
The key HKEY_CLASSES_ROOT\urn:content-classes:workspace-settings\DefaultIcon points to the missing icon C:\Program Files\Common Files\Microsoft Shared\Web Folders\pkmres.dll,-12472. The reference should be deleted so that Windows does not try to find the icon.

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Sat 06 Mar 2010, 2:17 am

We need to do some diagnostics.

1. Please download Profiles by noahdfear.
  • Save it to your desktop.
  • Double-click profiles.exe and post its log when you reply


2. Download Win32kDiag by ad13 and save it to your Desktop.
  • Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
  • When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
  • Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.


3. In your next reply, please post the following logs for my review:
  • Profiles log (1)
  • Win32kDiag log (2)


Thanks!


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sat 06 Mar 2010, 9:04 am

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1747484371-3063578883-1927391205-1005
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Potters Trucking

SystemRoot REG_SZ C:\WINDOWS

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sat 06 Mar 2010, 9:05 am

Running from: C:\Documents and Settings\Potters Trucking\Desktop\Win32kDiag.exe

Log file at : C:\Documents and Settings\Potters Trucking\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...





Finished!

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Sat 06 Mar 2010, 2:43 pm

Please visit this webpage for a tutorial on downloading and running ComboFix:

[You must be registered and logged in to see this link.]

See the area: Using ComboFix, and when done, post the log back here.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sat 06 Mar 2010, 4:16 pm

ComboFix 10-03-05.01 - Potters Trucking 03/05/2010 23:34:39.1.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.703.331 [GMT -5:00]
Running from: c:\documents and settings\Potters Trucking\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Start Menu\HP Image Zone .lnk
c:\documents and settings\Potters Trucking\Local Settings\Application Data\ksnbae
c:\documents and settings\Potters Trucking\Local Settings\Application Data\ksnbae\vnkksftav.exe
c:\windows\system32\twain_32.dll
c:\windows\Uninstall.ini
D:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2010-02-06 to 2010-03-06 )))))))))))))))))))))))))))))))
.

2010-03-06 02:54 . 2010-03-06 02:54 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Grisoft
2010-03-06 02:54 . 2007-05-30 12:10 10872 ----a-w- c:\windows\system32\drivers\AvgAsCln.sys
2010-03-06 02:54 . 2010-03-06 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2010-03-03 00:20 . 2010-03-03 00:20 -------- d-----w- C:\FOUND.013
2010-03-02 23:46 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 23:46 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 02:25 . 2010-03-02 02:25 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Malwarebytes
2010-03-02 02:25 . 2010-03-02 02:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-02 01:28 . 2010-03-02 01:28 -------- d-----w- C:\FOUND.012
2010-02-28 21:08 . 2010-02-28 21:08 -------- d-----w- C:\FOUND.011
2010-02-28 19:34 . 2010-02-28 19:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-28 19:34 . 2010-02-28 19:34 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-28 19:34 . 2010-02-28 19:34 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-28 19:34 . 2010-02-28 19:34 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-28 19:33 . 2010-02-28 19:33 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-28 19:33 . 2010-02-28 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-20 19:30 . 2010-02-20 19:30 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\vlc
2010-02-20 05:46 . 2010-02-20 05:46 623152 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-20 00:10 . 2004-02-22 15:11 719872 ----a-w- c:\windows\system32\devil.dll
2010-02-20 00:10 . 2007-05-17 22:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2010-02-20 00:10 . 2006-04-05 13:09 66560 ----a-w- c:\windows\MOTA113.exe
2010-02-20 00:10 . 2005-07-14 17:31 27648 ----a-w- c:\windows\system32\AVSredirect.dll
2010-02-20 00:10 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-02-20 00:10 . 2004-01-25 05:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2010-02-20 00:10 . 2005-02-28 18:16 240128 ----a-w- c:\windows\system32\x.264.exe
2010-02-20 00:10 . 2006-10-07 22:43 502784 ----a-w- c:\windows\x2.64.exe
2010-02-20 00:10 . 2006-04-12 14:47 217073 ----a-w- c:\windows\meta4.exe
2010-02-20 00:10 . 2004-09-15 22:29 -------- d-----w- c:\program files\AviSynth 2.5
2010-02-20 00:09 . 2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2010-02-17 03:11 . 2010-02-17 03:11 -------- d-----w- C:\FOUND.009
2010-02-16 15:30 . 2010-02-16 15:30 -------- d-----w- C:\FOUND.008
2010-02-13 14:00 . 2010-02-13 14:00 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-02-07 18:50 . 2010-02-07 18:50 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Leadertech
2010-02-07 18:39 . 2010-02-07 18:39 -------- d-----w- C:\Profiles
2010-02-06 04:04 . 2010-02-09 23:14 664 ----a-w- c:\windows\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-06 04:54 . 2009-10-11 02:19 13440 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-02-20 15:20 . 2010-02-20 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-09 00:16 . 2006-12-22 12:35 116664 ----a-w- c:\documents and settings\Potters Trucking\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-02 18:00 . 2010-02-20 15:20 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-02-02 02:57 . 2010-02-02 02:57 -------- d-----w- c:\program files\iPod
2010-02-02 02:57 . 2010-02-02 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-31 14:18 . 2010-01-31 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-01-24 00:59 . 2010-01-24 00:59 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\MozillaControl
2010-01-24 00:59 . 2010-01-24 00:59 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-17 17:02 . 2009-10-12 20:15 112354 ----a-w- c:\windows\hpoins07.dat
2010-01-17 07:56 . 2010-01-17 07:56 -------- d-----w- c:\documents and settings\LocalService\Application Data\Roxio
2010-01-17 07:52 . 2010-01-17 07:51 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Macrovision
2010-01-17 07:41 . 2010-01-17 07:41 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Roxio
2010-01-17 01:43 . 2010-01-17 01:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Uninstall
2010-01-17 01:39 . 2010-01-17 01:39 -------- d-----w- c:\documents and settings\All Users\Application Data\CinemaNow
2010-01-17 01:39 . 2010-01-17 01:39 -------- d-----w- c:\program files\CinemaNow
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Simple Star
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoShow Shared Assets
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\program files\Roxio
2010-01-16 21:22 . 2010-01-16 21:22 -------- d-----w- c:\program files\SmartSound Software
2010-01-16 21:22 . 2010-01-16 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2010-01-16 21:08 . 2010-01-16 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2010-01-16 21:08 . 2010-01-16 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2010-01-16 21:07 . 2010-01-16 21:07 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-01-16 21:00 . 2010-01-16 21:00 -------- d-----w- c:\program files\MSBuild
2010-01-16 21:00 . 2010-01-16 21:00 -------- d-----w- c:\program files\Reference Assemblies
2010-01-16 20:51 . 2010-01-16 20:51 -------- d-----w- c:\program files\MSXML 6.0
2010-01-16 19:15 . 2010-01-16 19:15 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Roxio Log Files
2010-01-12 00:52 . 2010-01-12 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo
2009-12-12 14:15 . 2010-02-20 15:20 178176 ----a-w- c:\windows\system32\unrar.dll
2006-05-03 09:06 . 2010-02-20 00:09 163328 --sh--r- c:\windows\system32\flvDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-15 68856]
"AlcoholAutomount"="d:\alcohol 120\axcmd.exe" [2008-05-20 4608]
"SpybotSD TeaTimer"="d:\spybot\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 67584]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 536576]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-16 339968]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2004-09-03 495616]
"Dit"="Dit.exe" [2003-12-30 94208]
"LogMeIn GUI"="d:\logmein\x86\LogMeInSystray.exe" [2007-04-17 63048]
"UnlockerAssistant"="d:\unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"HP Software Update"="d:\hp software update\HPWuSchd2.exe" [2005-05-12 49152]
"CPMonitor"="d:\roxio\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="d:\roxio\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"QuickTime Task"="d:\quicktime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-01-23 141608]
"!AVG Anti-Spyware"="d:\installs\AVG Antispyware\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinScheduler.lnk - d:\windvr3\SchSvr.exe [2010-1-11 155648]
InterVideo WinCinema Manager.lnk - d:\common\Bin\WinCinemaMgr.exe [2010-1-11 131072]
HP Image Zone Fast Start.lnk - d:\digital imaging\bin\hpqthb08.exe [2005-5-11 73728]
HP Digital Imaging Monitor.lnk - d:\digital imaging\bin\hpqtra08.exe [2005-5-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-28 19:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-05 15:12 87352 ------w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"\\\\acer-d3e20d0d7f\\d drive (d)\\LimeWire\\LimeWire.exe"=
"d:\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Digital Imaging\\bin\\hpofxm08.exe"=
"d:\\Digital Imaging\\bin\\hposfx08.exe"=
"d:\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Digital Imaging\\bin\\hpqCopy.exe"=
"d:\\Digital Imaging\\bin\\hpfccopy.exe"=
"d:\\Digital Imaging\\bin\\hpzwiz01.exe"=
"d:\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"d:\\Digital Imaging\\Unload\\HpqDIA.exe"=
"d:\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\UTorrents\\uTorrent.exe"=
"\\\\Acer-d3e20d0d7f\\d drive (d)\\VLC Media Player\\VLC\\vlc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"d:\\Roxio\\Roxio 2010\\Venue\\Venue.exe"=
"c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
"d:\\VLC Media Player\\VLC\\vlc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\ItUNES\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [12/22/2006 7:27 AM 5632]
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [1/16/2010 8:40 PM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [1/16/2010 8:40 PM 15856]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/4/2008 5:21 PM 716272]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/28/2010 2:34 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/28/2010 2:34 PM 360584]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [1/16/2010 8:40 PM 25584]
R2 LMIInfo;LogMeIn Kernel Information Provider;d:\logmein\x86\rainfo.sys [6/19/2007 8:00 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/19/2007 9:00 PM 47640]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [1/1/1980 160896]
S3 AVC2310F;AVC-2310/AVC-2210 USB Loader;c:\windows\system32\drivers\avcuwfl.sys [1/11/2010 7:25 PM 18580]
S3 AvcUWilo;Adaptec AVC-2210/2310 USB Device;c:\windows\system32\drivers\avcuwilo.sys [1/11/2010 7:47 PM 50258]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [10/10/2009 9:19 PM 13440]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [11/4/2007 10:02 AM 42112]
S3 vaxscsi;vaxscsi;c:\windows\system32\Drivers\vaxscsi.sys --> c:\windows\system32\Drivers\vaxscsi.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-03-06 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 21:28]

2010-02-21 c:\windows\Tasks\Roxio PhotoShow Updater.job
- c:\program files\Roxio\PhotoShow\auto_updater_shim.exe [2009-06-24 02:21]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
Trusted Zone: cinemanow.com
Trusted Zone: motorola.com\idenupdate
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
FF - ProfilePath - c:\documents and settings\Potters Trucking\Application Data\Mozilla\Firefox\Profiles\9rt3sa2b.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin7.dll
FF - plugin: d:\vlc media player\VLC\npvlc.dll
.
- - - - ORPHANS REMOVED - - - -

Notify-dimsntfy - (no file)
SafeBoot-AVG Anti-Spyware Driver



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-03-05 23:53
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys SahdIa32.sys ACPI.sys hal.dll >>UNKNOWN [0x83B6F1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7f78fc3
\Driver\ACPI -> ACPI.sys @ 0xf7dd6cb8
\Driver\atapi -> 0x83b6f1f8
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0094
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0094
NDIS: acer IPN2220 Wireless LAN Card -> SendCompleteHandler -> NDIS.sys @ 0xf7ce6ba0
PacketIndicateHandler -> NDIS.sys @ 0xf7cd5a0b
SendHandler -> NDIS.sys @ 0xf7ce9b31
Warning: possible MBR rootkit infection !
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(1048)
d:\unlocker\UnlockerHook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
d:\installs\AVG Antispyware\AVG Anti-Spyware 7.5\guard.exe
c:\program files\AVG\AVG9\avgwdsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\CinemaNow\CinemaNow Media Manager\CinemanowSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
d:\logmein\x86\RaMaint.exe
d:\logmein\x86\LogMeIn.exe
c:\program files\AVG\AVG9\avgnsx.exe
d:\logmein\x86\LMIGuardian.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
d:\logmein\x86\LMIGuardian.exe
d:\alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\System32\TUProgSt.exe
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\windows\Dit.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\Macromed\Flash\NPSWF32_FlashUtil.exe
d:\digital imaging\bin\hpqSTE08.exe
d:\digital imaging\Product Assistant\bin\hprblog.exe
d:\digital imaging\bin\hpqimzone.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
.
**************************************************************************
.
Completion time: 2010-03-06 00:11:00 - machine was rebooted
ComboFix-quarantined-files.txt 2010-03-06 05:10

Pre-Run: 2,493,087,744 bytes free
Post-Run: 2,406,006,784 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - D598468EEDAB6E89B9DA4B7876364851

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sat 06 Mar 2010, 4:28 pm

Everything seems to be working fine again I did notice i program trying to install (Document Viewer) and wants me to click OK to this path
C:\DOCUME~1\POTTER~1\LOCALS~1\Temp\7zS104E\setup\DocumentViewer\
Going to end the process with the task manager until I hear back from you.
I'm also going to update all of my anti virus and run further scans as they have all been locked out from helping.

DRAGON MASTER JAY YOU ARE THE MAN!!!!!
I will be posting a link in my website and any other sites that I'll host in the future.
What a great service you folks provide.
Thank You Thank You Thank You

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Sat 06 Mar 2010, 7:01 pm

Your system's not clean. And if the current problem does not get fixed, your system will no longer boot.

This scan:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys SahdIa32.sys ACPI.sys hal.dll >>UNKNOWN [0x83B6F1F8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf7f78fc3
\Driver\ACPI -> ACPI.sys @ 0xf7dd6cb8
\Driver\atapi -> 0x83b6f1f8
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0094
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0094
NDIS: acer IPN2220 Wireless LAN Card -> SendCompleteHandler -> NDIS.sys @ 0xf7ce6ba0
PacketIndicateHandler -> NDIS.sys @ 0xf7cd5a0b
SendHandler -> NDIS.sys @ 0xf7ce9b31
Warning: possible MBR rootkit infection !
user & kernel MBR OK

In the blue, is the infection I am talking about.

Do you want to continue diagnostics?


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 2:00 am

I want to end this when you say I'm Clean.
I ran some scans after combofix and here are some results.
The first scan found malware and for the first time all week I was able to update AVG9 and ran it as well.
I also run a program called removeitpro and it to found stuff including combofix.
I know I can reinstall combofix but after this weeks events being able to click and fix is an immediate reaction.
Tuneup Utilities has found the same 41 problems in the registry but after cleaning they return so I know there still are issues.
So yes I want to continue diagnostics.


Malwarebytes' Anti-Malware 1.44
Database version: 3828
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11

3/6/2010 9:32:27 AM
mbam-log-2010-03-06 (09-32-27).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 258940
Time elapsed: 1 hour(s), 41 minute(s), 51 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Sun 07 Mar 2010, 2:09 am

1. Please download Profiles by noahdfear.
  • Save it to your desktop.
  • Double-click profiles.exe and post its log when you reply


2. Download Win32kDiag by ad13 and save it to your Desktop.
  • Double-click Win32kDiag.exe to run Win32kDiag and let it finish.
  • When it states "Finished! Press any key to exit...", press any key on your keyboard to close the program.
  • Double-click on the Win32kDiag.txt file that is located on your Desktop and post the entire contents of that log as a reply to this topic.


3. Please download Stealth MBR Rootkit Detector by GMER from GMER.net, and save to your Desktop.
  • Double-click mbr.exe to start the program.
  • When done scanning, it will save a log on the Desktop called mbr.log.
  • Please post the contents of that log in your next reply.


4. In your next reply, please post the following logs for my review:
  • Profiles log (1)
  • Win32kDiag log (2)
  • MBR log (3)


Thanks!


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 3:36 am

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList
DefaultUserProfile REG_SZ Default User
AllUsersProfile REG_SZ All Users

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18
ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\LocalService

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\NetworkService

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1747484371-3063578883-1927391205-1005
ProfileImagePath REG_EXPAND_SZ %SystemDrive%\Documents and Settings\Potters Trucking

SystemRoot REG_SZ C:\WINDOWS

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 3:37 am

Running from: C:\Documents and Settings\Potters Trucking\Desktop\Win32kDiag.exe

Log file at : C:\Documents and Settings\Potters Trucking\Desktop\Win32kDiag.txt

WARNING: Could not get backup privileges!

Searching 'C:\WINDOWS'...





Finished!

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 3:38 am

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Sun 07 Mar 2010, 5:45 am

Please open Command Prompt (Start > Run and type CMD and press OK [Vista/7: Start search: CMD and press enter])
Enter the following in to the black box, pressing enter after each line:

Code:
cd desktop

mbr.exe -f

exit

Post a log (MBR.log).


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 12:06 pm

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Sun 07 Mar 2010, 1:51 pm

Please re-run ComboFix and post a log, for the final check.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 2:32 pm

ComboFix 10-03-06.03 - Potters Trucking 03/06/2010 22:08:48.2.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.703.356 [GMT -5:00]
Running from: c:\documents and settings\Potters Trucking\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-02-07 to 2010-03-07 )))))))))))))))))))))))))))))))
.

2010-03-06 08:40 . 2010-03-06 08:40 -------- d-----w- C:\$AVG
2010-03-06 06:12 . 2010-02-28 19:33 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-03-06 06:12 . 2010-02-28 19:33 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-03-06 02:54 . 2010-03-06 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2010-03-03 00:20 . 2010-03-03 00:20 -------- d-----w- C:\FOUND.013
2010-03-02 23:46 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 23:46 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 02:25 . 2010-03-02 02:25 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Malwarebytes
2010-03-02 02:25 . 2010-03-02 02:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-02 01:28 . 2010-03-02 01:28 -------- d-----w- C:\FOUND.012
2010-02-28 21:08 . 2010-02-28 21:08 -------- d-----w- C:\FOUND.011
2010-02-28 19:34 . 2010-02-28 19:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-28 19:34 . 2010-02-28 19:34 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-28 19:34 . 2010-02-28 19:34 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-28 19:34 . 2010-02-28 19:34 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-28 19:33 . 2010-02-28 19:33 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-28 19:33 . 2010-02-28 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-20 19:30 . 2010-02-20 19:30 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\vlc
2010-02-20 05:46 . 2010-02-20 05:46 623152 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-20 00:10 . 2004-02-22 15:11 719872 ----a-w- c:\windows\system32\devil.dll
2010-02-20 00:10 . 2007-05-17 22:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2010-02-20 00:10 . 2006-04-05 13:09 66560 ----a-w- c:\windows\MOTA113.exe
2010-02-20 00:10 . 2005-07-14 17:31 27648 ----a-w- c:\windows\system32\AVSredirect.dll
2010-02-20 00:10 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-02-20 00:10 . 2004-01-25 05:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2010-02-20 00:10 . 2005-02-28 18:16 240128 ----a-w- c:\windows\system32\x.264.exe
2010-02-20 00:10 . 2006-10-07 22:43 502784 ----a-w- c:\windows\x2.64.exe
2010-02-20 00:10 . 2006-04-12 14:47 217073 ----a-w- c:\windows\meta4.exe
2010-02-20 00:10 . 2004-09-15 22:29 -------- d-----w- c:\program files\AviSynth 2.5
2010-02-20 00:09 . 2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2010-02-17 03:11 . 2010-02-17 03:11 -------- d-----w- C:\FOUND.009
2010-02-16 15:30 . 2010-02-16 15:30 -------- d-----w- C:\FOUND.008
2010-02-13 14:00 . 2010-02-13 14:00 3584 ----a-r- c:\documents and settings\Potters Trucking\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-02-13 14:00 . 2010-02-13 14:00 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-02-07 18:50 . 2010-02-07 18:50 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Leadertech
2010-02-07 18:39 . 2010-02-07 18:39 -------- d-----w- C:\Profiles
2010-02-06 04:04 . 2010-02-09 23:14 664 ----a-w- c:\windows\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-06 12:35 . 2009-10-11 02:19 13440 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-02-20 15:20 . 2010-02-20 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-09 00:16 . 2006-12-22 12:35 116664 ----a-w- c:\documents and settings\Potters Trucking\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-02 18:00 . 2010-02-20 15:20 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-02-02 02:57 . 2010-02-02 02:57 -------- d-----w- c:\program files\iPod
2010-02-02 02:57 . 2010-02-02 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-31 14:18 . 2010-01-31 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-01-24 00:59 . 2010-01-24 00:59 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\MozillaControl
2010-01-24 00:59 . 2010-01-24 00:59 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-23 00:51 . 2010-01-23 00:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-17 17:02 . 2009-10-12 20:15 112354 ----a-w- c:\windows\hpoins07.dat
2010-01-17 07:56 . 2010-01-17 07:56 -------- d-----w- c:\documents and settings\LocalService\Application Data\Roxio
2010-01-17 07:52 . 2010-01-17 07:51 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Macrovision
2010-01-17 07:41 . 2010-01-17 07:41 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Roxio
2010-01-17 01:43 . 2010-01-17 01:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Uninstall
2010-01-17 01:39 . 2010-01-17 01:39 -------- d-----w- c:\documents and settings\All Users\Application Data\CinemaNow
2010-01-17 01:39 . 2010-01-17 01:39 -------- d-----w- c:\program files\CinemaNow
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Simple Star
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoShow Shared Assets
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\program files\Roxio
2010-01-17 01:22 . 2010-01-17 01:22 10134 ----a-r- c:\documents and settings\Potters Trucking\Application Data\Microsoft\Installer\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}\ARPPRODUCTICON.exe
2010-01-16 21:22 . 2010-01-16 21:22 -------- d-----w- c:\program files\SmartSound Software
2010-01-16 21:22 . 2010-01-16 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2010-01-16 21:08 . 2010-01-16 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2010-01-16 21:08 . 2010-01-16 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2010-01-16 21:07 . 2010-01-16 21:07 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-01-16 21:00 . 2010-01-16 21:00 -------- d-----w- c:\program files\MSBuild
2010-01-16 21:00 . 2010-01-16 21:00 -------- d-----w- c:\program files\Reference Assemblies
2010-01-16 20:51 . 2010-01-16 20:51 -------- d-----w- c:\program files\MSXML 6.0
2010-01-16 19:15 . 2010-01-16 19:15 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Roxio Log Files
2010-01-12 00:52 . 2010-01-12 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo
2009-12-20 14:23 . 2009-12-20 14:22 152576 ----a-w- c:\documents and settings\Potters Trucking\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-20 14:22 . 2009-12-20 14:22 79488 ----a-w- c:\documents and settings\Potters Trucking\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-12 14:15 . 2010-02-20 15:20 178176 ----a-w- c:\windows\system32\unrar.dll
2006-05-03 09:06 . 2010-02-20 00:09 163328 --sh--r- c:\windows\system32\flvDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-15 68856]
"AlcoholAutomount"="d:\alcohol 120\axcmd.exe" [2008-05-20 4608]
"SpybotSD TeaTimer"="d:\spybot\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 67584]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 536576]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-16 339968]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2004-09-03 495616]
"Dit"="Dit.exe" [2003-12-30 94208]
"LogMeIn GUI"="d:\logmein\x86\LogMeInSystray.exe" [2007-04-17 63048]
"UnlockerAssistant"="d:\unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"HP Software Update"="d:\hp software update\HPWuSchd2.exe" [2005-05-12 49152]
"CPMonitor"="d:\roxio\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="d:\roxio\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"QuickTime Task"="d:\quicktime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinScheduler.lnk - d:\windvr3\SchSvr.exe [2010-1-11 155648]
InterVideo WinCinema Manager.lnk - d:\common\Bin\WinCinemaMgr.exe [2010-1-11 131072]
HP Image Zone Fast Start.lnk - d:\digital imaging\bin\hpqthb08.exe [2005-5-11 73728]
HP Digital Imaging Monitor.lnk - d:\digital imaging\bin\hpqtra08.exe [2005-5-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-28 19:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-05 15:12 87352 ------w- c:\windows\system32\LMIinit.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"\\\\acer-d3e20d0d7f\\d drive (d)\\LimeWire\\LimeWire.exe"=
"d:\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Digital Imaging\\bin\\hpofxm08.exe"=
"d:\\Digital Imaging\\bin\\hposfx08.exe"=
"d:\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Digital Imaging\\bin\\hpqCopy.exe"=
"d:\\Digital Imaging\\bin\\hpfccopy.exe"=
"d:\\Digital Imaging\\bin\\hpzwiz01.exe"=
"d:\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"d:\\Digital Imaging\\Unload\\HpqDIA.exe"=
"d:\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\UTorrents\\uTorrent.exe"=
"\\\\Acer-d3e20d0d7f\\d drive (d)\\VLC Media Player\\VLC\\vlc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"d:\\Roxio\\Roxio 2010\\Venue\\Venue.exe"=
"c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
"d:\\VLC Media Player\\VLC\\vlc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\ItUNES\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [12/22/2006 7:27 AM 5632]
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [1/16/2010 8:40 PM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [1/16/2010 8:40 PM 15856]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/28/2010 2:34 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/28/2010 2:34 PM 360584]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [1/16/2010 8:40 PM 25584]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 7:05 PM 457200]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2/28/2010 2:33 PM 285392]
R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 5:40 PM 127352]
R2 LMIInfo;LogMeIn Kernel Information Provider;d:\logmein\x86\rainfo.sys [6/19/2007 8:00 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/19/2007 9:00 PM 47640]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [1/1/1980 160896]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/4/2008 5:21 PM 716272]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 8:33 AM 219632]
S3 AVC2310F;AVC-2310/AVC-2210 USB Loader;c:\windows\system32\drivers\avcuwfl.sys [1/11/2010 7:25 PM 18580]
S3 AvcUWilo;Adaptec AVC-2210/2310 USB Device;c:\windows\system32\drivers\avcuwilo.sys [1/11/2010 7:47 PM 50258]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [10/10/2009 9:19 PM 13440]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [11/4/2007 10:02 AM 42112]
S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 8:33 AM 1116656]
S3 vaxscsi;vaxscsi;c:\windows\system32\Drivers\vaxscsi.sys --> c:\windows\system32\Drivers\vaxscsi.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-03-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 21:28]

2010-02-21 c:\windows\Tasks\Roxio PhotoShow Updater.job
- c:\program files\Roxio\PhotoShow\auto_updater_shim.exe [2009-06-24 02:21]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
Trusted Zone: cinemanow.com
Trusted Zone: motorola.com\idenupdate
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
FF - ProfilePath - c:\documents and settings\Potters Trucking\Application Data\Mozilla\Firefox\Profiles\9rt3sa2b.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin7.dll
FF - plugin: d:\vlc media player\VLC\npvlc.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-03-06 22:17
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(3740)
d:\unlocker\UnlockerHook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
d:\microsoft office\OFFICE11\msohev.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2010-03-06 22:23:36
ComboFix-quarantined-files.txt 2010-03-07 03:23
ComboFix2.txt 2010-03-06 05:11

Pre-Run: 2,275,540,992 bytes free
Post-Run: 2,238,660,608 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - F41F023B30D2504D9B0036E54240DEEF

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Sun 07 Mar 2010, 4:22 pm

I wasn't able to completely shut down AVG last scan so I finally shut it down and re scanned
ComboFix 10-03-06.04 - Potters Trucking 03/07/2010 0:06.3.1 - FAT32x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.703.470 [GMT -5:00]
Running from: c:\documents and settings\Potters Trucking\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-02-07 to 2010-03-07 )))))))))))))))))))))))))))))))
.

2010-03-06 08:40 . 2010-03-06 08:40 -------- d-----w- C:\$AVG
2010-03-06 06:12 . 2010-02-28 19:33 3777280 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2010-03-06 06:12 . 2010-02-28 19:33 1260800 ----a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgfrw.exe
2010-03-06 02:54 . 2010-03-06 02:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Grisoft
2010-03-03 00:20 . 2010-03-03 00:20 -------- d-----w- C:\FOUND.013
2010-03-02 23:46 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 23:46 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 02:25 . 2010-03-02 02:25 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Malwarebytes
2010-03-02 02:25 . 2010-03-02 02:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-02 01:28 . 2010-03-02 01:28 -------- d-----w- C:\FOUND.012
2010-02-28 21:08 . 2010-02-28 21:08 -------- d-----w- C:\FOUND.011
2010-02-28 19:34 . 2010-02-28 19:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-28 19:34 . 2010-02-28 19:34 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-28 19:34 . 2010-02-28 19:34 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-28 19:34 . 2010-02-28 19:34 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-02-28 19:33 . 2010-02-28 19:33 -------- d-----w- c:\windows\system32\drivers\Avg
2010-02-28 19:33 . 2010-02-28 19:33 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-02-20 19:30 . 2010-02-20 19:30 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\vlc
2010-02-20 05:46 . 2010-02-20 05:46 623152 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-20 00:10 . 2004-02-22 15:11 719872 ----a-w- c:\windows\system32\devil.dll
2010-02-20 00:10 . 2007-05-17 22:30 318976 ----a-w- c:\windows\system32\avisynth.dll
2010-02-20 00:10 . 2006-04-05 13:09 66560 ----a-w- c:\windows\MOTA113.exe
2010-02-20 00:10 . 2005-07-14 17:31 27648 ----a-w- c:\windows\system32\AVSredirect.dll
2010-02-20 00:10 . 2004-01-25 16:18 217088 ----a-w- c:\windows\system32\yv12vfw.dll
2010-02-20 00:10 . 2004-01-25 05:00 70656 ----a-w- c:\windows\system32\i420vfw.dll
2010-02-20 00:10 . 2005-02-28 18:16 240128 ----a-w- c:\windows\system32\x.264.exe
2010-02-20 00:10 . 2006-10-07 22:43 502784 ----a-w- c:\windows\x2.64.exe
2010-02-20 00:10 . 2006-04-12 14:47 217073 ----a-w- c:\windows\meta4.exe
2010-02-20 00:10 . 2004-09-15 22:29 -------- d-----w- c:\program files\AviSynth 2.5
2010-02-20 00:09 . 2006-05-03 09:06 163328 --sh--r- c:\windows\system32\flvDX.dll
2010-02-17 03:11 . 2010-02-17 03:11 -------- d-----w- C:\FOUND.009
2010-02-16 15:30 . 2010-02-16 15:30 -------- d-----w- C:\FOUND.008
2010-02-13 14:00 . 2010-02-13 14:00 3584 ----a-r- c:\documents and settings\Potters Trucking\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-02-13 14:00 . 2010-02-13 14:00 -------- d-----w- c:\program files\Windows Installer Clean Up
2010-02-07 18:50 . 2010-02-07 18:50 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Leadertech
2010-02-07 18:39 . 2010-02-07 18:39 -------- d-----w- C:\Profiles
2010-02-06 04:04 . 2010-02-09 23:14 664 ----a-w- c:\windows\system32\d3d9caps.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-07 03:18 . 2009-10-11 02:19 13440 ----a-w- c:\windows\system32\drivers\USBCRFT.SYS
2010-02-20 15:20 . 2010-02-20 15:20 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-02-09 00:16 . 2006-12-22 12:35 116664 ----a-w- c:\documents and settings\Potters Trucking\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-02-02 18:00 . 2010-02-20 15:20 85504 ----a-w- c:\windows\system32\ff_vfw.dll
2010-02-02 02:57 . 2010-02-02 02:57 -------- d-----w- c:\program files\iPod
2010-02-02 02:57 . 2010-02-02 02:57 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2010-01-31 14:18 . 2010-01-31 14:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Driver Whiz
2010-01-24 00:59 . 2010-01-24 00:59 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\MozillaControl
2010-01-24 00:59 . 2010-01-24 00:59 -------- d-----w- c:\program files\Mozilla ActiveX Control v1.7.12
2010-01-23 00:51 . 2010-01-23 00:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
2010-01-17 17:02 . 2009-10-12 20:15 112354 ----a-w- c:\windows\hpoins07.dat
2010-01-17 07:56 . 2010-01-17 07:56 -------- d-----w- c:\documents and settings\LocalService\Application Data\Roxio
2010-01-17 07:52 . 2010-01-17 07:51 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Macrovision
2010-01-17 07:41 . 2010-01-17 07:41 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Roxio
2010-01-17 01:43 . 2010-01-17 01:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Uninstall
2010-01-17 01:39 . 2010-01-17 01:39 -------- d-----w- c:\documents and settings\All Users\Application Data\CinemaNow
2010-01-17 01:39 . 2010-01-17 01:39 -------- d-----w- c:\program files\CinemaNow
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Simple Star
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\documents and settings\All Users\Application Data\PhotoShow Shared Assets
2010-01-17 01:37 . 2010-01-17 01:37 -------- d-----w- c:\program files\Roxio
2010-01-17 01:22 . 2010-01-17 01:22 10134 ----a-r- c:\documents and settings\Potters Trucking\Application Data\Microsoft\Installer\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}\ARPPRODUCTICON.exe
2010-01-16 21:22 . 2010-01-16 21:22 -------- d-----w- c:\program files\SmartSound Software
2010-01-16 21:22 . 2010-01-16 21:22 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2010-01-16 21:08 . 2010-01-16 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Roxio
2010-01-16 21:08 . 2010-01-16 21:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Macrovision
2010-01-16 21:07 . 2010-01-16 21:07 -------- d-----w- c:\program files\Common Files\Roxio Shared
2010-01-16 21:00 . 2010-01-16 21:00 -------- d-----w- c:\program files\MSBuild
2010-01-16 21:00 . 2010-01-16 21:00 -------- d-----w- c:\program files\Reference Assemblies
2010-01-16 20:51 . 2010-01-16 20:51 -------- d-----w- c:\program files\MSXML 6.0
2010-01-16 19:15 . 2010-01-16 19:15 -------- d-----w- c:\documents and settings\Potters Trucking\Application Data\Roxio Log Files
2010-01-12 00:52 . 2010-01-12 00:52 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo
2009-12-20 14:23 . 2009-12-20 14:22 152576 ----a-w- c:\documents and settings\Potters Trucking\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-20 14:22 . 2009-12-20 14:22 79488 ----a-w- c:\documents and settings\Potters Trucking\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-12 14:15 . 2010-02-20 15:20 178176 ----a-w- c:\windows\system32\unrar.dll
2006-05-03 09:06 . 2010-02-20 00:09 163328 --sh--r- c:\windows\system32\flvDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Location Finder"="c:\program files\Microsoft Location Finder\LocationFinder.exe" [2005-08-24 101080]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-08-15 68856]
"AlcoholAutomount"="d:\alcohol 120\axcmd.exe" [2008-05-20 4608]
"SpybotSD TeaTimer"="d:\spybot\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 67584]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 88363]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 536576]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-16 339968]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2004-09-03 495616]
"Dit"="Dit.exe" [2003-12-30 94208]
"LogMeIn GUI"="d:\logmein\x86\LogMeInSystray.exe" [2007-04-17 63048]
"UnlockerAssistant"="d:\unlocker\UnlockerAssistant.exe" [2006-09-07 15872]
"HP Software Update"="d:\hp software update\HPWuSchd2.exe" [2005-05-12 49152]
"CPMonitor"="d:\roxio\Roxio 2010\5.0\CPMonitor.exe" [2009-07-21 84464]
"Desktop Disc Tool"="d:\roxio\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe" [2009-06-23 494064]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe" [2009-07-24 240112]
"QuickTime Task"="d:\quicktime\QTTask.exe" [2009-11-11 417792]
"iTunesHelper"="d:\itunes\iTunesHelper.exe" [2010-01-23 141608]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
InterVideo WinScheduler.lnk - d:\windvr3\SchSvr.exe [2010-1-11 155648]
InterVideo WinCinema Manager.lnk - d:\common\Bin\WinCinemaMgr.exe [2010-1-11 131072]
HP Image Zone Fast Start.lnk - d:\digital imaging\bin\hpqthb08.exe [2005-5-11 73728]
HP Digital Imaging Monitor.lnk - d:\digital imaging\bin\hpqtra08.exe [2005-5-11 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-02-28 19:34 12464 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
[BU]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2009-10-05 15:12 87352 ------w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"\\\\acer-d3e20d0d7f\\d drive (d)\\LimeWire\\LimeWire.exe"=
"d:\\Digital Imaging\\bin\\hpqtra08.exe"=
"d:\\Digital Imaging\\bin\\hpqste08.exe"=
"d:\\Digital Imaging\\bin\\hpofxm08.exe"=
"d:\\Digital Imaging\\bin\\hposfx08.exe"=
"d:\\Digital Imaging\\bin\\hposid01.exe"=
"d:\\Digital Imaging\\bin\\hpqscnvw.exe"=
"d:\\Digital Imaging\\bin\\hpqkygrp.exe"=
"d:\\Digital Imaging\\bin\\hpqCopy.exe"=
"d:\\Digital Imaging\\bin\\hpfccopy.exe"=
"d:\\Digital Imaging\\bin\\hpzwiz01.exe"=
"d:\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"d:\\Digital Imaging\\Unload\\HpqDIA.exe"=
"d:\\Digital Imaging\\bin\\hpoews01.exe"=
"d:\\UTorrents\\uTorrent.exe"=
"\\\\Acer-d3e20d0d7f\\d drive (d)\\VLC Media Player\\VLC\\vlc.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"d:\\Roxio\\Roxio 2010\\Venue\\Venue.exe"=
"c:\\Program Files\\CinemaNow\\CinemaNow Media Manager\\CinemaNowShell.exe"=
"d:\\VLC Media Player\\VLC\\vlc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\ItUNES\\iTunes.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [12/22/2006 7:27 AM 5632]
R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [1/16/2010 8:40 PM 21488]
R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [1/16/2010 8:40 PM 15856]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2/28/2010 2:34 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2/28/2010 2:34 PM 360584]
R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [1/16/2010 8:40 PM 25584]
R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [6/2/2009 7:05 PM 457200]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [2/28/2010 2:33 PM 285392]
R2 CinemaNow Service;CinemaNow Service;c:\program files\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe [6/23/2009 5:40 PM 127352]
R2 LMIInfo;LogMeIn Kernel Information Provider;d:\logmein\x86\rainfo.sys [6/19/2007 8:00 PM 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [6/19/2007 9:00 PM 47640]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [1/1/1980 160896]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [5/4/2008 5:21 PM 716272]
S2 RoxWatch12;Roxio Hard Drive Watcher 12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatch12.exe [7/24/2009 8:33 AM 219632]
S3 AVC2310F;AVC-2310/AVC-2210 USB Loader;c:\windows\system32\drivers\avcuwfl.sys [1/11/2010 7:25 PM 18580]
S3 AvcUWilo;Adaptec AVC-2210/2310 USB Device;c:\windows\system32\drivers\avcuwilo.sys [1/11/2010 7:47 PM 50258]
S3 CardReaderFilter;Card Reader Filter;c:\windows\system32\drivers\USBCRFT.SYS [10/10/2009 9:19 PM 13440]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [11/4/2007 10:02 AM 42112]
S3 RoxMediaDB12;RoxMediaDB12;c:\program files\Common Files\Roxio Shared\12.0\SharedCOM\RoxMediaDB12.exe [7/24/2009 8:33 AM 1116656]
S3 vaxscsi;vaxscsi;c:\windows\system32\Drivers\vaxscsi.sys --> c:\windows\system32\Drivers\vaxscsi.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder

2010-03-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-20 21:28]

2010-02-21 c:\windows\Tasks\Roxio PhotoShow Updater.job
- c:\program files\Roxio\PhotoShow\auto_updater_shim.exe [2009-06-24 02:21]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = [You must be registered and logged in to see this link.]
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = [You must be registered and logged in to see this link.]
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
Trusted Zone: cinemanow.com
Trusted Zone: motorola.com\idenupdate
Trusted Zone: qflix.com
Trusted Zone: roxio.com
Trusted Zone: sonic.com\redirect
Trusted Zone: sonic.com\redirect2
FF - ProfilePath - c:\documents and settings\Potters Trucking\Application Data\Mozilla\Firefox\Profiles\9rt3sa2b.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: d:\itunes\Mozilla Plugins\npitunes.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin2.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin3.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin4.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin5.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin6.dll
FF - plugin: d:\quicktime\Plugins\npqtplugin7.dll
FF - plugin: d:\vlc media player\VLC\npvlc.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2010-03-07 00:14
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\LMIinit.dll

- - - - - - - > 'explorer.exe'(1128)
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
d:\microsoft office\OFFICE11\msohev.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2010-03-07 00:17:37
ComboFix-quarantined-files.txt 2010-03-07 05:17
ComboFix2.txt 2010-03-07 03:23
ComboFix3.txt 2010-03-06 05:11

Pre-Run: 2,247,180,288 bytes free
Post-Run: 2,233,384,960 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - 015A8CE385A2852BB5FE14CEAA8F1745

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Mon 08 Mar 2010, 3:19 pm

Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE

You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:

  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

==

Please download TFC by OldTimer to your desktop
  • Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • It will close all programs when run, so make sure you have saved all your work before you begin.
  • Click the Start
    button to begin the process. Depending on how often you clean temp
    files, execution time should be anywhere from a few seconds to a minute
    or two. Let it run uninterrupted to completion.
  • Once it's finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.


==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by yadad on Tue 09 Mar 2010, 10:47 am

FOR THOSE OF YOU VIEWING THIS POST CHECK OUT THE RESULTS
Results of screen317's Security Check version 0.99.1
Windows XP Service Pack 2
Out of date service pack!!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
AVG Free 9.0
``````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
TuneUp Utilities 2009
Java(TM) 6 Update 17
Adobe Flash Player 10
Adobe Reader 8.1.2
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````
Thank you DragonMaster Jay and the whole team at GeekPolice.

yadad

Newbie Surfer
Newbie Surfer

Posts : 20
Joined : 2010-03-03
Operating System : windows xp home

View user profile

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by DragonMaster Jay on Tue 09 Mar 2010, 12:57 pm

Please upgrade to Windows XP SP3, because it includes all previously released updates. It also includes a small number of new functionalities. Some of the updates that Service Pack 3 provides, you may not have. It is now available via Windows Update.

More info about SP3: [You must be registered and logged in to see this link.]

===

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

====

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

Firewall

  • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
  • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
  • PC Tools Firewall Plus: free and excellent firewall.


AntiSpyware

  • SpywareBlaster
    SpywareBlaster is a program that prevents spyware from installing on your computer. A tutorial on using SpywareBlaster may be found here.
  • Spybot - Search & Destroy.
    Spybot - Search & Destroy is a spyware and adware removal program. It also has realtime protection, TeaTimer to help safeguard your computer against spyware. (The link for Spybot - Search & Destroy contains a tutorial that will help you download, install, and begin using Spybot).


NOTE: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
[You must be registered and logged in to see this link.]

Securing your computer

  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.


Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:


See [You must be registered and logged in to see this link.] for more info about malware and prevention.

Thank you for choosing GeekPolice. Please see [You must be registered and logged in to see this link.] if you would like to leave feedback or contribute to our site. Do you have any more questions?


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: System Guard 2009/ Win32/nuqel.e Help Me Please

Post by Sponsored content Today at 1:06 am


Sponsored content


Back to top Go down

Page 1 of 2 1, 2  Next

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum