GeekPolice
Welcome to GeekPolice.net!

From "wow" to "whoa" - we're teaching practical technology and helping others with tech support. Join our family here!

You are viewing the forum as a "Guest" which doesn't give you member privileges to ask questions or post comments.

Take 30 seconds to register or log in below and unlock the limitations of this website to discover new computer knowledge!

what's the problem

View previous topic View next topic Go down

Solved what's the problem

Post by bongring on Thu Feb 19, 2009 1:57 am

i cant access the command promt, eset nod32 wont open, windows security says that there's no antivirus installed, d windows folder wont open also.

here's its hjt log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:55:45 AM, on 2/19/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\DisplayMonitor.exe
C:\WINDOWS\cmd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\SSC Service Utility\ssc_serv.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE
C:\Program Files\Net Studio\USB_FW.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Setup.exe
C:\Program Files\AnalogX\MaxMem\maxmem.exe
C:\WINDOWS\system\reg32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Bandoo\Bandoo.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsEditor.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Owner\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [You must be registered and logged in to see this link.]
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [You must be registered and logged in to see this link.]
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = [You must be registered and logged in to see this link.]
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
F2 - REG:system.ini: Shell=explorer.exe, C:\WINDOWS\cmd.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\DisplayMonitor.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - D:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [egui] "D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [NVIDIA Display] C:\WINDOWS\DisplayMonitor.exe
O4 - HKLM\..\Run: [Win32 Console] C:\WINDOWS\cmd.exe
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [EPSON Stylus Photo R230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /FU "C:\DOCUME~1\Owner\LOCALS~1\Temp\E_S5D3.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
O4 - HKCU\..\Run: [USB_FW] C:\Program Files\Net Studio\USB_FW.exe
O4 - HKUS\S-1-5-21-507921405-1801674531-722791865-1003\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User '?')
O4 - HKUS\S-1-5-21-507921405-1801674531-722791865-1003\..\Run: [EPSON Stylus Photo R230 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAIP.EXE /FU "C:\DOCUME~1\Owner\LOCALS~1\Temp\E_S5D3.tmp" /EF "HKCU" (User '?')
O4 - HKUS\S-1-5-21-507921405-1801674531-722791865-1003\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe (User '?')
O4 - HKUS\S-1-5-21-507921405-1801674531-722791865-1003\..\Run: [USB_FW] C:\Program Files\Net Studio\USB_FW.exe (User '?')
O4 - S-1-5-21-507921405-1801674531-722791865-1003 Startup: MaxMem.lnk = C:\Program Files\AnalogX\MaxMem\maxmem.exe (User '?')
O4 - Startup: MaxMem.lnk = C:\Program Files\AnalogX\MaxMem\maxmem.exe
O4 - Global Startup: Setup.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [You must be registered and logged in to see this link.]
O17 - HKLM\System\CCS\Services\Tcpip\..\{4E8A75CC-311B-4B9A-9FE2-1F9D36E5877F}: NameServer = 192.168.10.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\DOCUME~1\Owner\LOCALS~1\Temp\woqnomi.dll c:\progra~1\bandoo\bndhook.dll
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 8276 bytes
Smile Cheesy Grin (sparkly Cheesy Grin (sparkly

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by Belahzur on Thu Feb 19, 2009 2:07 am

Moving to malware removal.

Hello.

  • Open HijackThis
  • Choose "Do a system scan only"
  • Check the boxes in front of these lines:


    F2 - REG:system.ini: Shell=explorer.exe, C:\WINDOWS\cmd.exe
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\DisplayMonitor.exe
    O4 - HKLM\..\Run: [NVIDIA Display] C:\WINDOWS\DisplayMonitor.exe
    O4 - HKLM\..\Run: [Win32 Console] C:\WINDOWS\cmd.exe
    O4 - HKCU\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe
    O4 - HKUS\S-1-5-21-507921405-1801674531-722791865-1003\..\Run: [cdoosoft] C:\WINDOWS\system32\olhrwef.exe (User '?')
    O4 - Global Startup: Setup.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O20 - AppInit_DLLs: C:\DOCUME~1\Owner\LOCALS~1\Temp\woqnomi.dll c:\progra~1\bandoo\bndhook.dll



  • Press "Fix Checked"
  • Close Hijack This.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245029
# Likes : 1

View user profile

Back to top Go down

Solved Re: what's the problem

Post by bongring on Thu Feb 19, 2009 4:01 am

still the windows security tells that antivirus is not installed.

Malwarebytes' Anti-Malware 1.34
Database version: 1778
Windows 5.1.2600 Service Pack 2

2/19/2009 11:54:34 AM
mbam-log-2009-02-19 (11-54-34).txt

Scan type: Quick Scan
Objects scanned: 67493
Time elapsed: 6 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\olhrwef.exe (Trojan.Agent) -> Quarantined and deleted successfully.
Let me think :hmm:

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by Belahzur on Thu Feb 19, 2009 1:53 pm


  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run
  • When complete, DDS.txt will open.
  • Save the report to your Desktop.
  • Copy and paste DDS.txt back here, I don't need to see attach.txt.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245029
# Likes : 1

View user profile

Back to top Go down

Solved Re: what's the problem

Post by bongring on Fri Feb 20, 2009 5:16 am

sorry for taking so much time to reply.
here's the DDS.txt




DDS (Ver_09-02-01.01) - NTFSx86
Run by Owner at 13:13:20.34 on Fri 02/20/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_07

============== Running Processes ===============


============== Pseudo HJT Report ===============

uStart Page = [You must be registered and logged in to see this link.]
uSearch Page = [You must be registered and logged in to see this link.]
mSearchAssistant = [You must be registered and logged in to see this link.]
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - d:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: NoExplorer - No File
BHO: Adobe PDF Link Helper: {8df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Click-to-Call BHO: {5c255c8a-e604-49b4-9d64-90988571cecb} - c:\program files\windows live\messenger\wlchtc.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - d:\progra~1\yahoo!\companion\installs\cpn\yt.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [EPSON Stylus Photo R230 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiaip.exe /fu "c:\docume~1\owner\locals~1\temp\E_S5D3.tmp" /EF "HKCU"
uRun: [USB_FW] c:\program files\net studio\USB_FW.exe
mRun: [egui] "d:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
mRun: [SSC Service Utility] c:\program files\ssc service utility\ssc_serv.exe /s
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\maxmem.lnk - c:\program files\analogx\maxmem\maxmem.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - [You must be registered and logged in to see this link.]
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
TCP: {20F74DB4-0489-41CD-AE43-34703FF51869} = 208.67.222.222,208.67.220.220
TCP: {4E8A75CC-311B-4B9A-9FE2-1F9D36E5877F} = 208.67.222.222,208.67.220.220
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxsrvc.dll
AppInit_DLLs: c:\progra~1\bandoo\bndhook.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\v3q2m710.default\
FF - prefs.js: browser.startup.homepage - [You must be registered and logged in to see this link.]
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: d:\program files\adobe\reader 9.0\reader\browser\nppdf32.dll

============= SERVICES / DRIVERS ===============


============== File Associations ===============

inifile=c:\smss.exe

=============== Created Last 30 ================

2009-02-19 21:50 --d----- c:\program files\Faronics
2009-02-19 11:43 --d----- c:\docume~1\owner\applic~1\Malwarebytes
2009-02-19 11:42 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-19 11:42 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-19 11:42 --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-19 11:42 --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-18 14:46 5,248 a------- c:\windows\system32\giveio.sys
2009-02-17 14:50 --d----- c:\program files\Net Studio
2009-02-13 19:29 109,724 ---shr-- C:\ur0.com
2009-02-13 19:29 95,744 ---shr-- c:\windows\system32\nmdfgds1.dll
2009-02-13 19:28 109,724 ---shr-- C:\opgde.exe
2009-02-13 19:28 160 ---shr-- C:\autorun.inf
2009-02-13 19:28 95,744 ---shr-- c:\windows\system32\nmdfgds0.dll
2009-02-07 12:26 9,366 a------- c:\windows\DjVuDoc.ico
2009-01-31 10:16 --d----- c:\program files\AmitySource
2009-01-30 16:11 --d----- c:\program files\GetData
2009-01-30 16:11 --d-h--- c:\windows\PIF
2009-01-28 12:22 --d----- c:\docume~1\alluse~1\applic~1\Bandoo
2009-01-28 12:21 --d----- c:\program files\Bandoo
2009-01-27 11:51 --d----- c:\program files\XemiComputers
2009-01-24 14:06 --d----- c:\program files\IVT Corporation
2009-01-24 13:10 664 a------- c:\windows\system32\d3d9caps.dat
2009-01-24 12:06 0 a------- c:\windows\system32\SETB6.tmp
2009-01-24 12:06 208 a----r-- c:\windows\system32\drivers\vssver.scc

==================== Find3M ====================

2009-02-20 11:56 34 a------- c:\documents and settings\owner\jagex_runescape_preferences.dat
2009-02-18 10:50 86,016 a------- c:\windows\DisplayMonitor.exe
2009-02-18 10:50 86,016 a------- c:\windows\cmd.exe
2009-02-18 10:50 86,016 a------- C:\calculator.exe
2008-12-04 22:55 307,560 a------- c:\windows\WLXPGSS.SCR
2008-12-02 22:37 49,480 a------- c:\windows\system32\sirenacm.dll

============= FINISH: 13:13:52.89 ===============
Awesome (sparkly) Evil or enraged

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by darshan20183 on Fri Feb 20, 2009 5:22 am

Removed.

darshan20183
Beginner
Beginner

Status :
Online
Offline

Posts : 2
Joined : 2009-02-19
OS : Windows XP SP3
Points : 28430
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by bongring on Fri Feb 20, 2009 2:06 pm

huh?! but its the malware thats giving me problem not my antivirus, and i still would prefer to use eset or sophos than any other anti virus. Awesome (sparkly) Awesome (sparkly) Shocking Whoa Shocking Whoa

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by Belahzur on Fri Feb 20, 2009 2:49 pm

Please don't take advice from someone who is not part of our staff.

Hello.
Please upload these three files in bold
c:\windows\system32\giveio.sys
c:\windows\DjVuDoc.ico
c:\windows\system32\drivers\vssver.scc
To this site for a scan.
[You must be registered and logged in to see this link.]
Copy and paste the results back here.

Note: if their server is busy, upload to this site instead:
[You must be registered and logged in to see this link.]

Once you've done that.

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    C:\ur0.com
    c:\windows\system32\nmdfgds1.dll
    C:\opgde.exe
    C:\autorun.inf
    c:\windows\system32\nmdfgds0.dll
    c:\windows\DjVuDoc.ico
    c:\windows\system32\SETB6.tmp
    c:\windows\DisplayMonitor.exe
    c:\windows\cmd.exe
    C:\calculator.exe

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""
    [HKEY_CLASSES_ROOT\inifile\shell\open\command]
    @=hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,\
    00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4e,00,4f,00,\
    54,00,45,00,50,00,41,00,44,00,2e,00,45,00,58,00,45,00,20,00,25,00,31,00,00,\
    00


  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245029
# Likes : 1

View user profile

Back to top Go down

Solved Re: what's the problem

Post by bongring on Sat Feb 21, 2009 5:32 am

virscan found nothing, doing the otmoveit. :howdy: :howdy:

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by bongring on Sat Feb 21, 2009 5:41 am

here's the otmoveit log.


C:\ur0.com moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\nmdfgds1.dll
c:\windows\system32\nmdfgds1.dll NOT unregistered.
c:\windows\system32\nmdfgds1.dll moved successfully.
C:\opgde.exe moved successfully.
C:\autorun.inf moved successfully.
DllUnregisterServer procedure not found in c:\windows\system32\nmdfgds0.dll
c:\windows\system32\nmdfgds0.dll NOT unregistered.
c:\windows\system32\nmdfgds0.dll moved successfully.
c:\windows\DjVuDoc.ico moved successfully.
c:\windows\system32\SETB6.tmp moved successfully.
c:\windows\DisplayMonitor.exe moved successfully.
c:\windows\cmd.exe moved successfully.
C:\calculator.exe moved successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLs"|"" /E : value set successfully!
HKEY_CLASSES_ROOT\inifile\shell\open\command\\@|hex(2):25,00,53,00,79,00,73,00,74,00,65,00,6d,00,52,00,6f,00,6f,00,74,00,25,00,5c,00,53,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,4e,00,4f,00,54,00,45,00,50,00,41,00,44,00,2e,00,45,00,58,00,45,00,20,00,25,00,31,00,00,00 /E : value set successfully!

OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02212009_133725
Cheesy Grin (sparkly

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by Belahzur on Sat Feb 21, 2009 1:55 pm

Hello.
It found nothing on this file? giveio.sys

I was expecting malware, but it could be legit.
Let me know how the machine is running now.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Status :
Online
Offline

Posts : 34916
Joined : 2008-08-03
Gender : Male
OS : XP SP3 Media Centre
Points : 245029
# Likes : 1

View user profile

Back to top Go down

Solved Re: what's the problem

Post by bongring on Sun Feb 22, 2009 3:56 am

its fine now but the windows security still cant detect eset, i think i'd try reinstalling it. thanks Hooray! Thank You! Thank You!

bongring
Intermediate
Intermediate

Status :
Online
Offline

Posts : 95
Joined : 2008-10-20
Gender : Male
OS : windows xp sp3
Points : 29750
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by Doctor Inferno on Mon Jul 06, 2009 3:42 am

Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a [You must be registered and logged in to see this link.] for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Status :
Online
Offline

Posts : 12017
Joined : 2007-12-26
Gender : Male
OS : Windows 7 Home Premium and Ultimate X64
Points : 104564
# Likes : 0

View user profile

Back to top Go down

Solved Re: what's the problem

Post by Doctor Inferno on Mon Jul 06, 2009 3:43 am

Since this issue has been addressed, a "solved" tag will be added and this topic will be closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a [You must be registered and logged in to see this link.] for your questions.


Please be a GeekPolice fan on [You must be registered and logged in to see this link.]



Have we helped you? [You must be registered and logged in to see this link.] | Doctor by day, ninja by night.

Doctor Inferno
Administrator
Administrator

Status :
Online
Offline

Posts : 12017
Joined : 2007-12-26
Gender : Male
OS : Windows 7 Home Premium and Ultimate X64
Points : 104564
# Likes : 0

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum