Hello, everyone.

Well, the title is pretty self-explanatory. when I turn on m PC, it freezes 2 or 3 minutes after entering WinXP. Completely freezes: the mouse doesn't move, keyboard does nothing, C-A-D does nothing, etc etc. Safe Mode works fine, BUT Safe Mode with networking also freezes after a while.

Now, i've followed this page as well as I could, but couldn't use GMER. I got the first GMER log just fine (which was totally empty, btw), then did the scan, and when i went to save the second log, it froze. Tried about 10 times, always the same result.

Here are the MBAM log, the GMER log (first) and DDS.


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 5363

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

26-12-2010 21:14:54
mbam-log-2010-12-26 (21-14-54).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 544161
Time elapsed: 2 hour(s), 13 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\RJ\Os meus documentos\Downloads\v11_flash_AV.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{55C9F6F0-8626-4444-88E3-4EFAC4C2C676}\RP996\A0190596.exe (Trojan.FakeAV) -> Quarantined and deleted successfully.
E:\D\GoldWave 5.52 audio editor + keygen\keygen.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.


DDS (Ver_10-12-12.02) - NTFSx86 MINIMAL
Run by RJ at 17:30:41,42 on 27-12-2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.351.2070.18.2047.1753 [GMT 0:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\RJ\Ambiente de trabalho\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\programas\ficheiros comuns\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Mediafour XPlay Explorer notifications: {4907c0ad-874d-44d9-b13e-7b0a4d8b9d3e} - c:\programas\mediafour\xplay 3\XPBHO.DLL
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\programas\yahoo!\companion\installs\cpn\yt.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: 127.0.0.1 www.spywareinfo.com

============= SERVICES / DRIVERS ===============

R0 mrdd;Marvell Removable Disk Control Driver;c:\windows\system32\drivers\mrdd.sys [2009-12-29 18984]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2008-6-10 152616]
S0 MDFSYSNT;MacDrive file system driver;c:\windows\system32\drivers\MDFSYSNT.SYS [2009-9-28 259176]
S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-4 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\programas\logmein hamachi\hamachi-2.exe [2010-12-6 1238408]
S2 M4iPodWPDService;M4iPodWPDService;c:\programas\ficheiros comuns\mediafour\ipod\M4iPodWPDService.exe [2010-6-18 223232]
S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys --> c:\windows\system32\drivers\SSPORT.sys [?]
S2 UltraMonUtility;UltraMon Utility Driver;c:\programas\ficheiros comuns\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2008-11-14 17184]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-12-29 1684736]
S3 ndisrd;WinpkFilter Service;c:\windows\system32\drivers\ndisrd.sys [2009-11-3 20480]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2009-6-13 0]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\programas\dragon age\bin_ship\daupdatersvc.service.exe [2009-11-4 25832]

=============== Created Last 30 ================

2010-12-26 16:02:08 -------- d-----w- c:\windows\system32\wbem\repository\FS
2010-12-26 16:02:08 -------- d-----w- c:\windows\system32\wbem\Repository
2010-12-21 23:00:05 -------- d-----w- c:\docume~1\rj\defini~1\applic~1\LogMeIn Hamachi
2010-12-21 22:59:44 -------- d-----w- c:\programas\LogMeIn Hamachi
2010-12-21 22:58:04 26176 ---ha-w- c:\windows\system32\hamachi.sys
2010-12-11 19:07:01 83661160 ----a-w- c:\programas\ficheiros comuns\windows live\.cache\wlc907.tmp
2010-11-29 01:27:47 -------- d-----w- c:\docume~1\rj\applic~1\.minecraft

==================== Find3M ====================


============= FINISH: 17:31:43,78 ===============

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 12-10-2008 2:37:20
System Uptime: 27-12-2010 17:25:51 (0 hours ago)

Motherboard: ASUSTeK Computer INC. | | P5K PRO
Processor: Processador Intel Pentium III Xeon | LGA775 | 3005/333mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 75 GiB total, 5,9 GiB free.
D: is FIXED (NTFS) - 298 GiB total, 12,06 GiB free.
E: is FIXED (NTFS) - 932 GiB total, 1,776 GiB free.
F: is CDROM ()
I: is CDROM (CDFS)
K: is Removable

==== Disabled Device Manager Items =============

Class GUID:
Description:
Device ID: ROOT\{140FD12F-CBAE-408D-9942-F919A7CB22CC}\0000
Manufacturer:
Name:
PNP Device ID: ROOT\{140FD12F-CBAE-408D-9942-F919A7CB22CC}\0000
Service:

Class GUID:
Description:
Device ID: ROOT\{140FD12F-CBAE-408D-9942-F919A7CB22CC}\0001
Manufacturer:
Name:
PNP Device ID: ROOT\{140FD12F-CBAE-408D-9942-F919A7CB22CC}\0001
Service:

==== System Restore Points ===================

RP982: 11-11-2010 18:21:20 - Ponto de verificaÁ„o do sistema
RP983: 12-11-2010 19:21:48 - Ponto de verificaÁ„o do sistema
RP984: 13-11-2010 2:45:14 - Actualizar para um controlador n„o assinado
RP985: 14-11-2010 5:05:13 - Ponto de verificaÁ„o do sistema
RP986: 14-11-2010 22:06:15 - Removed Age of Empires III - The Asian Dynasties
RP987: 14-11-2010 22:09:16 - Removed Age of Empires III - The WarChiefs
RP988: 14-11-2010 22:11:45 - Removed Age of Empires III
RP989: 15-11-2010 23:05:03 - Ponto de verificaÁ„o do sistema
RP990: 17-11-2010 0:00:43 - Ponto de verificaÁ„o do sistema
RP991: 17-11-2010 20:10:14 - SPTD setup V1.62
RP992: 18-11-2010 2:06:45 - Actualizar para um controlador n„o assinado
RP993: 19-11-2010 4:45:10 - Ponto de verificaÁ„o do sistema
RP994: 19-11-2010 15:44:25 - Actualizar para um controlador n„o assinado
RP995: 19-11-2010 17:50:53 - Actualizar para um controlador n„o assinado
RP996: 20-11-2010 15:45:04 - Actualizar para um controlador n„o assinado
RP997: 21-11-2010 15:59:25 - Ponto de verificaÁ„o do sistema
RP998: 22-11-2010 22:13:08 - Ponto de verificaÁ„o do sistema
RP999: 22-11-2010 22:21:08 - Actualizar para um controlador n„o assinado
RP1000: 23-11-2010 23:10:30 - Ponto de verificaÁ„o do sistema
RP1001: 25-11-2010 1:21:11 - Ponto de verificaÁ„o do sistema
RP1002: 26-11-2010 5:06:54 - Ponto de verificaÁ„o do sistema
RP1003: 27-11-2010 7:45:52 - Ponto de verificaÁ„o do sistema
RP1004: 28-11-2010 8:23:05 - Ponto de verificaÁ„o do sistema
RP1005: 29-11-2010 8:43:05 - Ponto de verificaÁ„o do sistema
RP1006: 30-11-2010 3:10:13 - Actualizar para um controlador n„o assinado
RP1007: 01-12-2010 7:24:05 - Ponto de verificaÁ„o do sistema
RP1008: 02-12-2010 2:36:12 - Actualizar para um controlador n„o assinado
RP1009: 03-12-2010 7:11:05 - Ponto de verificaÁ„o do sistema
RP1010: 04-12-2010 2:24:43 - Actualizar para um controlador n„o assinado
RP1011: 05-12-2010 5:34:29 - Ponto de verificaÁ„o do sistema
RP1012: 06-12-2010 6:00:02 - Ponto de verificaÁ„o do sistema
RP1013: 06-12-2010 11:23:50 - Actualizar para um controlador n„o assinado
RP1014: 07-12-2010 11:29:16 - Ponto de verificaÁ„o do sistema
RP1015: 08-12-2010 12:25:55 - Ponto de verificaÁ„o do sistema
RP1016: 08-12-2010 14:58:09 - Actualizar para um controlador n„o assinado
RP1017: 09-12-2010 14:59:45 - Ponto de verificaÁ„o do sistema
RP1018: 10-12-2010 17:36:00 - Ponto de verificaÁ„o do sistema
RP1019: 11-12-2010 0:30:08 - Actualizar para um controlador n„o assinado
RP1020: 12-12-2010 6:41:42 - Ponto de verificaÁ„o do sistema
RP1021: 13-12-2010 7:29:13 - Ponto de verificaÁ„o do sistema
RP1022: 14-12-2010 8:03:13 - Ponto de verificaÁ„o do sistema
RP1023: 15-12-2010 9:02:01 - Ponto de verificaÁ„o do sistema
RP1024: 16-12-2010 9:56:13 - Ponto de verificaÁ„o do sistema
RP1025: 16-12-2010 15:44:40 - Actualizar para um controlador n„o assinado
RP1026: 16-12-2010 18:44:26 - Actualizar para um controlador n„o assinado
RP1027: 17-12-2010 18:47:08 - Ponto de verificaÁ„o do sistema
RP1028: 18-12-2010 18:49:26 - Ponto de verificaÁ„o do sistema
RP1029: 18-12-2010 19:59:20 - Actualizar para um controlador n„o assinado
RP1030: 18-12-2010 20:52:20 - Actualizar para um controlador n„o assinado
RP1031: 19-12-2010 23:11:30 - Ponto de verificaÁ„o do sistema
RP1032: 20-12-2010 23:55:14 - Ponto de verificaÁ„o do sistema
RP1033: 21-12-2010 20:12:24 - Actualizar para um controlador n„o assinado
RP1034: 22-12-2010 22:09:30 - Ponto de verificaÁ„o do sistema
RP1035: 24-12-2010 0:26:58 - Ponto de verificaÁ„o do sistema
RP1036: 24-12-2010 13:17:27 - Actualizar para um controlador n„o assinado
RP1037: 26-12-2010 16:01:06 - Restore Operation

==== Installed Programs ======================

7-Zip 9.20
ActualizaÁ„o CrÌtica para o Windows Media Player 11 (KB959772)
ActualizaÁ„o de SeguranÁa para o Windows Media Player (KB952069)
ActualizaÁ„o de SeguranÁa para o Windows Media Player (KB954155)
ActualizaÁ„o de SeguranÁa para o Windows Media Player (KB973540)
ActualizaÁ„o de SeguranÁa para o Windows Media Player (KB978695)
ActualizaÁ„o de SeguranÁa para o Windows Media Player 11 (KB936782)
ActualizaÁ„o de SeguranÁa para o Windows Media Player 11 (KB954154)
ActualizaÁ„o de seguranÁa para Windows Internet Explorer 8 (KB971961)
ActualizaÁ„o de seguranÁa para Windows Internet Explorer 8 (KB981332)
ActualizaÁ„o de seguranÁa para Windows Internet Explorer 8 (KB982381)
ActualizaÁ„o de seguranÁa para Windows XP (KB923561)
ActualizaÁ„o de seguranÁa para Windows XP (KB938464)
ActualizaÁ„o de SeguranÁa para Windows XP (KB941569)
ActualizaÁ„o de seguranÁa para Windows XP (KB946648)
ActualizaÁ„o de seguranÁa para Windows XP (KB950762)
ActualizaÁ„o de seguranÁa para Windows XP (KB950974)
ActualizaÁ„o de seguranÁa para Windows XP (KB951066)
ActualizaÁ„o de seguranÁa para Windows XP (KB951376-v2)
ActualizaÁ„o de seguranÁa para Windows XP (KB951698)
ActualizaÁ„o de seguranÁa para Windows XP (KB951748)
ActualizaÁ„o de seguranÁa para Windows XP (KB952004)
ActualizaÁ„o de seguranÁa para Windows XP (KB952954)
ActualizaÁ„o de seguranÁa para Windows XP (KB953838)
ActualizaÁ„o de seguranÁa para Windows XP (KB953839)
ActualizaÁ„o de seguranÁa para Windows XP (KB954211)
ActualizaÁ„o de seguranÁa para Windows XP (KB954459)
ActualizaÁ„o de seguranÁa para Windows XP (KB954600)
ActualizaÁ„o de seguranÁa para Windows XP (KB955069)
ActualizaÁ„o de seguranÁa para Windows XP (KB956390)
ActualizaÁ„o de seguranÁa para Windows XP (KB956391)
ActualizaÁ„o de seguranÁa para Windows XP (KB956572)
ActualizaÁ„o de seguranÁa para Windows XP (KB956744)
ActualizaÁ„o de seguranÁa para Windows XP (KB956802)
ActualizaÁ„o de seguranÁa para Windows XP (KB956803)
ActualizaÁ„o de seguranÁa para Windows XP (KB956841)
ActualizaÁ„o de seguranÁa para Windows XP (KB956844)
ActualizaÁ„o de seguranÁa para Windows XP (KB957095)
ActualizaÁ„o de seguranÁa para Windows XP (KB957097)
ActualizaÁ„o de seguranÁa para Windows XP (KB958215)
ActualizaÁ„o de seguranÁa para Windows XP (KB958644)
ActualizaÁ„o de seguranÁa para Windows XP (KB958687)
ActualizaÁ„o de seguranÁa para Windows XP (KB958690)
ActualizaÁ„o de seguranÁa para Windows XP (KB958869)
ActualizaÁ„o de seguranÁa para Windows XP (KB959426)
ActualizaÁ„o de seguranÁa para Windows XP (KB960225)
ActualizaÁ„o de seguranÁa para Windows XP (KB960714)
ActualizaÁ„o de seguranÁa para Windows XP (KB960715)
ActualizaÁ„o de seguranÁa para Windows XP (KB960803)
ActualizaÁ„o de seguranÁa para Windows XP (KB960859)
ActualizaÁ„o de seguranÁa para Windows XP (KB961373)
ActualizaÁ„o de seguranÁa para Windows XP (KB961501)
ActualizaÁ„o de seguranÁa para Windows XP (KB963027)
ActualizaÁ„o de seguranÁa para Windows XP (KB968537)
ActualizaÁ„o de seguranÁa para Windows XP (KB969059)
ActualizaÁ„o de seguranÁa para Windows XP (KB969897)
ActualizaÁ„o de seguranÁa para Windows XP (KB969898)
ActualizaÁ„o de seguranÁa para Windows XP (KB970238)
ActualizaÁ„o de seguranÁa para Windows XP (KB971468)
ActualizaÁ„o de seguranÁa para Windows XP (KB971657)
ActualizaÁ„o de seguranÁa para Windows XP (KB972270)
ActualizaÁ„o de seguranÁa para Windows XP (KB973507)
ActualizaÁ„o de seguranÁa para Windows XP (KB973869)
ActualizaÁ„o de seguranÁa para Windows XP (KB973904)
ActualizaÁ„o de seguranÁa para Windows XP (KB974112)
ActualizaÁ„o de seguranÁa para Windows XP (KB974318)
ActualizaÁ„o de seguranÁa para Windows XP (KB974392)
ActualizaÁ„o de seguranÁa para Windows XP (KB974571)
ActualizaÁ„o de seguranÁa para Windows XP (KB975025)
ActualizaÁ„o de seguranÁa para Windows XP (KB975467)
ActualizaÁ„o de seguranÁa para Windows XP (KB975560)
ActualizaÁ„o de seguranÁa para Windows XP (KB975561)
ActualizaÁ„o de seguranÁa para Windows XP (KB975562)
ActualizaÁ„o de seguranÁa para Windows XP (KB975713)
ActualizaÁ„o de seguranÁa para Windows XP (KB977816)
ActualizaÁ„o de seguranÁa para Windows XP (KB977914)
ActualizaÁ„o de seguranÁa para Windows XP (KB978037)
ActualizaÁ„o de seguranÁa para Windows XP (KB978338)
ActualizaÁ„o de seguranÁa para Windows XP (KB978542)
ActualizaÁ„o de seguranÁa para Windows XP (KB978601)
ActualizaÁ„o de seguranÁa para Windows XP (KB978706)
ActualizaÁ„o de seguranÁa para Windows XP (KB979309)
ActualizaÁ„o de seguranÁa para Windows XP (KB979482)
ActualizaÁ„o de seguranÁa para Windows XP (KB979559)
ActualizaÁ„o de seguranÁa para Windows XP (KB979683)
ActualizaÁ„o de seguranÁa para Windows XP (KB980195)
ActualizaÁ„o de seguranÁa para Windows XP (KB980218)
ActualizaÁ„o de seguranÁa para Windows XP (KB980232)
ActualizaÁ„o para Windows Internet Explorer 8 (KB976662)
ActualizaÁ„o para Windows XP (KB951072-v2)
ActualizaÁ„o para Windows XP (KB951978)
ActualizaÁ„o para Windows XP (KB955759)
ActualizaÁ„o para Windows XP (KB955839)
ActualizaÁ„o para Windows XP (KB961503)
ActualizaÁ„o para Windows XP (KB967715)
ActualizaÁ„o para Windows XP (KB968389)
ActualizaÁ„o para Windows XP (KB973687)
ActualizaÁ„o para Windows XP (KB973815)
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.3.4
Adobe Reader for Pocket PC 2.0
Adobe Shockwave Player 11.5
AI Suite
Akamai NetSession Interface
Alien Swarm
Apple Mobile Device Support
Apple Software Update
Assistente de InÌcio de Sess„o do Windows Live
µTorrent
AusLogics BoostSpeed
AusLogics Disk Defrag
AviSynth 2.5
Bonjour
Borderlands
BTNext Evolution
BTS Extended v1.6
bwin Poker (remove only)
CCleaner
CDisplay 1.8
CorrecÁ„o para o Windows Media Player 11 (KB939683)
Crayon Physics Deluxe - release 51
DeathSpank
Diablo II
DivX Web Player
Dragon Age: Origins
Dropbox
Fallout New Vegas
Ferramenta de Carregamento do Windows Live
Football Manager 2011
Fraps (remove only)
GameRanger
GoldWave v5.52
Google Chrome
Hero Editor V0.96
High Definition Audio Driver Package - KB888111
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB976002-v5)
Hotfix para Windows XP (KB952287)
Hotfix para Windows XP (KB961118)
Hotfix para Windows XP (KB981793)
Impulse
ISI ResearchSoft - Export Helper
iTunes
Java Auto Updater
Java(TM) 6 Update 20
Java(TM) 6 Update 7
JDownloader
K-Lite Codec Pack 4.1.7 (Full)
LogMeIn Hamachi
Machinarium
Magic ISO Maker v5.4 (build 0239)
Malwarebytes' Anti-Malware
marvell 61xx
Marvell Miniport Driver
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PTG
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PTG
Microsoft .NET Framework 3.5 Language Pack SP1 - PTG
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile PTG Language Pack
Microsoft .NET Framework 4 Extended
Microsoft .NET Framework 4 Extended PTG Language Pack
Microsoft ActiveSync
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.9
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual J# .NET Redistributable Package 1.1
Moyea FLV Downloader version 1.15.0.15
Moyea FLV Player version 1.5.2.7
MSVCRT
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB925673)
Nero 7 Demo
NVIDIA Drivers
NVIDIA nView Desktop Manager
NVIDIA PhysX
Ogg Codecs 0.81.15562
Open File para Patch Liga Zon Sagres
OpenAL
OpenOffice.org 3.1
Pacote de controladores do Windows - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0)
Patch Liga Zon Sagres/Orangina by-famm_02 e estica
Phun beta 4.22
PowerISO
Pro Evolution Soccer 2011
PunkBuster Services
Puzzle Quest 2
QuickTime
Rapidshare Auto Downloader 4.1
RealPlayer
Realtek High Definition Audio Driver
Runes of Magic
Segoe UI
Sins of a Solar Empire
Sins of a Solar Empire - Entrenchment
SoulSeek 157 NS 13e
StarCraft II
Steam
STREET FIGHTER IV
System Requirements Lab
TeamSpeak 2 RC2
Testes Tem·ticos
The Witcher Enhanced Edition
Torchlight
Trine
UltraEdit v14.00+1
UltraMon
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Outlook 2007 Junk Email Filter (kb983486)
USB Dual Vibration Joystick - Twin
VC80CRTRedist - 8.0.50727.762
Veetle TV 0.9.17
Videora iPod Converter 4.01
Virtua Tennis(TM) 2009
VLC media player 1.0.5
WebFldrs XP
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Media Format 11 runtime
Windows Media Player 11
Windows Presentation Foundation
Windows XP Service Pack 3
WinRAR archiver
Worms Reloaded
XML Paper Specification Shared Components Language Pack 1.0
XML Paper Specification Shared Components Pack 1.0
XPlay 3
Yahoo! Toolbar

==== End Of File ===========================

Sorry for the long post, but the "Read Me before posting" page said that I should copy-paste these logs.

Anyway, I hope you can help me out, if you need any more info, just say so.

Cheers!

Recommended Answers

All 21 Replies

Well couple of things I see, NO anti-virus program installed on the computer. You are lucky you haven't gotten a severe infection before this. Especially because of the use of programs like this one, µTorrent.
Your Hosts file has been changed so we need to get that corrected
Do the following from bleepingcomputer:
download the following batch file and save it to your desktop:

http://download.bleepingcomputer.com/bats/hosts-perm.bat

delete the C:\Windows\System32\Drivers\etc\HOSTS file. Once it is deleted, download the following HOSTS file that corresponds to your version of Windows and save it in the C:\Windows\System32\Drivers\etc folder. If the contents of the HOSTS file opens in your browser when you click on a link below then right-click on the appropriate link and select Save Target As..., if in Internet Explorer, or Save Link As.., if in Firefox, to download the file.

http://download.bleepingcomputer.com/misc/host-files/windows-xp/hosts

Your Windows HOSTS file should now be back to the default one from when Windows was first installed.

Reboot and see if you can go online without freezing. If so, do the following:
Please Run the ESET Online Scanner

http://www.eset.com/onlinescan/scanner.php?i_agree=14
* You can use Internet Explorer or you may use Firefox to complete this scan and you will need to allow an Active X to be installed
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt.
Post back with that log.

thank you very much for your quick reply. this is my brother's computer, i had no idea he didn't have an AV. that will change, now.

Unfortunately, when i tried using Safe mode with network, the pc froze after 2 mintues, no time to do the scan.

Btw, what am I to do with that batch file I downloaded (apart from putting it in my desktop)?

Sorry! part of my instructions didn't paste!!!
Let's try that again. You now have the batch file on the desktop, correct?
Do this with it:
When the file has finished downloading, double-click on the hosts-perm.bat file that is now on your desktop. If Windows asks if you if you are sure you want to run it, please allow it to run. Once it starts you will see a small black window that opens and then quickly goes away. This is normal and is nothing to be worried about. You should now be able to access your HOSTS file.

delete the C:\Windows\System32\Drivers\etc\HOSTS file. Once it is deleted, download the following HOSTS file that corresponds to your version of Windows and save it in the C:\Windows\System32\Drivers\etc folder. If the contents of the HOSTS file opens in your browser when you click on a link below then right-click on the appropriate link and select Save Target As..., if in Internet Explorer, or Save Link As.., if in Firefox, to download the file.

http://download.bleepingcomputer.com...ndows-xp/hosts

Your Windows HOSTS file should now be back to the default one from when Windows was first installed.

Thanks for the reply.

Sadly, in Safe Mode with Network it froze as I was about to start the scan.

What is drive E?

It's a hard drive

Internal or External?

Internal. SATA.

How did you get MBA-M onto the computer?

He already had it installed, funnily enough. I just updated it, via the manual method (i'm posting in this site on my laptop)

Ok, once it's updated then run it again. Have it fix all it finds. Reboot and post the log here.

The MBAM log i posted on the OP was with an updated MBAM. I downloaded the manual updater on this laptop and used a USB drive to transfer it over. Should i update it again now and run another full scan?

That version on there is the old version, the newest one is 1.50.1 and it has been available since Dec. 21 but version 1.50 was released earlier than that. If you can get the new version on there then I would try.

Will do!

Okay, it finally finished. here's the log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5363

Windows 5.1.2600 Service Pack 3 (Safe Mode)
Internet Explorer 8.0.6001.18702

28-12-2010 1:21:43
mbam-log-2010-12-28 (01-21-43).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 544250
Time elapsed: 2 hour(s), 26 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
e:\system volume information\_restore{55c9f6f0-8626-4444-88e3-4efac4c2c676}\RP1037\A0219124.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.

That was in system restore. Database is still out of date. Did you do the update of version manually or via the internet?

manually, because the infected pc freezes in Safe Mode with network. Maybe the most up to date database is not available manually...?

Go to Control Panel, Internet Options, Connections, LAN settings. Make sure there is NO check mark in Use a Proxy Server for your LAN connection if there is one, take it out.

There isn't one, no.

To be 100% honest, I believe we are at a stand still here. I honestly don't see anything else that can be attempted. We have no clear picture of what is going on there because nothing can be run in normal mode and nothing can be done while the computer is online, even in safe mode.

There have been no security programs used on the computer, except an out of date MBA-M program and it obviously hasn't been used until now. There is no firewall on there and obviously P2P has been done with the computer with none of those files scanned by anything before installing them on the computer. MBA-M did find and remove 4 items but in safe mode. That is not enough. MBA-M is designed to be run in Normal Mode, it does not scan all necessary files in Safe Mode. The usual course of action in cases like this is run it in Safe Mode, do the removals and then reboot to Normal Mode, update again and do another Full Scan. But this cannot be done in this case. Online scans cannot be run because it is impossible to go online, even in safe mode.

My advice is reformat the computer and reload it. In "normal" cases like this a person should back up all they want to save because a reformat of course will delete everything on the computer. That is not possible here because it cannot be fully accessed. Plus since no clear and full scans can be done there is no way to assure that files and programs being backed up would be infection free, and I sincerely doubt that they are, they couldn't be without security programs installed to assure that and of course there are none. An out of date MBA-M program wouldn't count as security.

I hope that he obtained the operating system disk and driver disk when the computer was purchased, if he didn't then I would hope that he created restore disks when he bought it. If he has none of these then the only recourse would be to take it to a computer shop and pay to have the computer reformatted and reloaded.

If nothing else it will be a lesson learned, a costly one, but a lesson learned. You absolutely cannot run a computer today without good security programs on the computer, fully updated and used 100% of the time. There are three hard drives on there and I wouldn't trust any of them to be clean. This looks like a very expensive computer but it has had no care or safety precautions used with it whatsoever.
I really am sorry but I don't believe there is any other solution but a total reformat of the entire computer.

As expected.

OK, thanks very much for your time.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.