I've browsed a lot on the net and seen a lot of people with similar problems but nothing has worked for me.
My room mate had 11 virus's on his laptop that I removed using Avast BART CD cause I was unable to install any kind of anti-virus cause it would close automaticly after it loaded or even browse to their website cause browser would close by itself any time I went to anti-virus page.
Now that virus's are removed though I can't browse at all. I am connected to my AP, and my AP works fine for my laptop that I'm on now but all I get is a error saying "Internet explorer cannot display the webpage". I tried safe mode with networking and I can surf just fine with no problems at all, and fast too! WTF is going on, I've never encountered anything like this. Here's my virus scan log as well as my Hijack This log file. PLEASE HELP ME!
Thank you in advance.
;******
;Scan header
;VPS file version: August 10, 2009 - [90810-0]
;Params: C:\ Scan: Full files, All files, Ignore targeting, Archive: All packers,
;Columns: File name TAB Status [OK,INFECTED,ERROR]
;******
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch2.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch2.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch3.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch3.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch4.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch4.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch5.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch5.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch6.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch6.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch7.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch7.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC1.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC1.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0001.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0003.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0004.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0005.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0006.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0007.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0008.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0009.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0010.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0011.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0012.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0002.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0004.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0005.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0006.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0007.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0008.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0010.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0011.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0012.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0015.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0016.bin ERROR: Installer archive is corrupted.
C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.exe\Inno0001.bin ERROR: Installer archive is corrupted.
C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.zip\teatimer166.exe\Inno0001.bin ERROR: Installer archive is corrupted.
C:\System Volume Information\_restore{038A8374-84ED-471A-BD6C-515C293BC485}\RP66\A0057402.exe INFECTED: Win32:FakeAlert-BD [Trj]
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP166\A0036934.exe\%AppFolder%\ATI Omega Drivers Forum XP.url ERROR: Installer archive is corrupted.
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP179\A0040476.dll INFECTED: Win32:Trojan-gen {Other}
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP183\A0045684.dll INFECTED: Win32:Trojan-gen {Other}
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052151.dll INFECTED: Win32:Trojan-gen {Other}
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052152.dll INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\14792F59EFDEE8A9E012D874433D36DA.exe INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\2C80F13399DF4DC7665B09C1C8A954.exe INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\0690eb47f9e6b7c04f891475049b0979.TMP INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\73999330c8a42d6957246a4d6e68c698.tmp INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\acabeecfebad.dll INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\mukmil.dll INFECTED: Win32:Trojan-gen {Other}
;--------------------------
;Files: 211222
;Folders: 9136
;Files size: 43221792905
;Infected files: 11
;--------------------------
;******
;Scan footer
;Scan completed with return code: 0
;******
;******
;Command header
;Columns: File name TAB Command TAB Returned code TAB Custom parameter 1 TAB Custom parameter 2
;******
C:\System Volume Information\_restore{038A8374-84ED-471A-BD6C-515C293BC485}\RP66\A0057402.exe DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP179\A0040476.dll DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP183\A0045684.dll DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052151.dll DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052152.dll DELETE OK 1 0
C:\WINDOWS\14792F59EFDEE8A9E012D874433D36DA.exe DELETE OK 1 0
C:\WINDOWS\2C80F13399DF4DC7665B09C1C8A954.exe DELETE OK 1 0
C:\WINDOWS\system32\0690eb47f9e6b7c04f891475049b0979.TMP DELETE OK 1 0
C:\WINDOWS\system32\73999330c8a42d6957246a4d6e68c698.tmp DELETE OK 1 0
C:\WINDOWS\system32\acabeecfebad.dll DELETE OK 1 0
C:\WINDOWS\system32\mukmil.dll DELETE OK 1 0
;******
;Command footer
;******
And my Hijack This report....
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:29:10, on 8/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Nick\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: KODAK Software Updater.lnk.disabled
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.beatport.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1217613984154
O20 - Winlogon Notify: acabeecfebad - C:\WINDOWS\system32\acabeecfebad.dll (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
--
End of file - 5221 bytes
My room mate had 11 virus's on his laptop that I removed using Avast BART CD cause I was unable to install any kind of anti-virus cause it would close automaticly after it loaded or even browse to their website cause browser would close by itself any time I went to anti-virus page.
Now that virus's are removed though I can't browse at all. I am connected to my AP, and my AP works fine for my laptop that I'm on now but all I get is a error saying "Internet explorer cannot display the webpage". I tried safe mode with networking and I can surf just fine with no problems at all, and fast too! WTF is going on, I've never encountered anything like this. Here's my virus scan log as well as my Hijack This log file. PLEASE HELP ME!
Thank you in advance.
;******
;Scan header
;VPS file version: August 10, 2009 - [90810-0]
;Params: C:\ Scan: Full files, All files, Ignore targeting, Archive: All packers,
;Columns: File name TAB Status [OK,INFECTED,ERROR]
;******
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch1.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch2.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch2.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch3.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch3.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch4.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch4.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch5.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch5.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch6.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch6.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch7.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MyWayMyWebSearch7.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC1.zip\sbRecovery.reg ERROR: Archive is password protected.
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TinyBarC1.zip\sbRecovery.ini ERROR: Archive is password protected.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0001.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0003.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0004.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0005.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0006.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0007.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0008.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0009.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0010.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0011.bin ERROR: Installer archive is corrupted.
C:\Documents and Settings\Nick\Desktop\tfinstall.exe\Inno0012.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0002.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0004.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0005.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0006.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0007.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0008.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0010.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0011.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0012.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0015.bin ERROR: Installer archive is corrupted.
C:\Program Files\COMODO\COMODO Internet Security\s1.tmp\Inno0016.bin ERROR: Installer archive is corrupted.
C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.exe\Inno0001.bin ERROR: Installer archive is corrupted.
C:\Program Files\Spybot - Search & Destroy\Updates\teatimer166.zip\teatimer166.exe\Inno0001.bin ERROR: Installer archive is corrupted.
C:\System Volume Information\_restore{038A8374-84ED-471A-BD6C-515C293BC485}\RP66\A0057402.exe INFECTED: Win32:FakeAlert-BD [Trj]
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP166\A0036934.exe\%AppFolder%\ATI Omega Drivers Forum XP.url ERROR: Installer archive is corrupted.
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP179\A0040476.dll INFECTED: Win32:Trojan-gen {Other}
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP183\A0045684.dll INFECTED: Win32:Trojan-gen {Other}
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052151.dll INFECTED: Win32:Trojan-gen {Other}
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052152.dll INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\14792F59EFDEE8A9E012D874433D36DA.exe INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\2C80F13399DF4DC7665B09C1C8A954.exe INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\0690eb47f9e6b7c04f891475049b0979.TMP INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\73999330c8a42d6957246a4d6e68c698.tmp INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\acabeecfebad.dll INFECTED: Win32:Trojan-gen {Other}
C:\WINDOWS\system32\mukmil.dll INFECTED: Win32:Trojan-gen {Other}
;--------------------------
;Files: 211222
;Folders: 9136
;Files size: 43221792905
;Infected files: 11
;--------------------------
;******
;Scan footer
;Scan completed with return code: 0
;******
;******
;Command header
;Columns: File name TAB Command TAB Returned code TAB Custom parameter 1 TAB Custom parameter 2
;******
C:\System Volume Information\_restore{038A8374-84ED-471A-BD6C-515C293BC485}\RP66\A0057402.exe DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP179\A0040476.dll DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP183\A0045684.dll DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052151.dll DELETE OK 1 0
C:\System Volume Information\_restore{2F22428A-F041-4A47-8953-B12283DE2970}\RP217\A0052152.dll DELETE OK 1 0
C:\WINDOWS\14792F59EFDEE8A9E012D874433D36DA.exe DELETE OK 1 0
C:\WINDOWS\2C80F13399DF4DC7665B09C1C8A954.exe DELETE OK 1 0
C:\WINDOWS\system32\0690eb47f9e6b7c04f891475049b0979.TMP DELETE OK 1 0
C:\WINDOWS\system32\73999330c8a42d6957246a4d6e68c698.tmp DELETE OK 1 0
C:\WINDOWS\system32\acabeecfebad.dll DELETE OK 1 0
C:\WINDOWS\system32\mukmil.dll DELETE OK 1 0
;******
;Command footer
;******
And my Hijack This report....
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:29:10, on 8/11/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Sync\SyncServices.exe
C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Nick\Desktop\HiJackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O3 - Toolbar: (no name) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - (no file)
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [M-Audio Taskbar Icon] C:\WINDOWS\System32\M-AudioTaskBarIcon.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Kodak EasyShare software.lnk.disabled
O4 - Global Startup: KODAK Software Updater.lnk.disabled
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.beatport.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1217613984154
O20 - Winlogon Notify: acabeecfebad - C:\WINDOWS\system32\acabeecfebad.dll (file missing)
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: Maxtor Service (Maxtor Sync Service) - Seagate Technology LLC - C:\Program Files\Maxtor\Sync\SyncServices.exe
--
End of file - 5221 bytes