Windows 7 Support
Become a Fan of PCHF on Facebook!
User Reviews - Add Yours!
The PCHF Lounge
Go Back   PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs
Register for a Free Account

[Fixed] Hijackthis! Logs - Heavily Infected! Virut posted in the Security & Safety forums; Help! I cannot open a web browser in either Firefox or IE. The virus keeps disabling my firewall & I get popups galore. I am unable to run ComboFix, I ...

Advertisement
Advertisement

Reply
Recommended Driver Scanner
Old 10-20-2009   #1
Bronze Member
 
Join Date: Dec 2008
Posts: 19
PC Experience: Experienced
Default Heavily Infected! Virut

Help! I cannot open a web browser in either Firefox or IE. The virus keeps disabling my firewall & I get popups galore.

I am unable to run ComboFix, I get a message that the program has been compromised & I may have a virus called Virut.

Malwarebytes & Spybot both find numerous infections & can remove most, but they are back again after re-boot.

Root Repeal Log:
==================================================
Scan Start Time: 2009/10/20 08:38
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xA7D77000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xBA5DE000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xA7413000 Size: 49152 File Visible: No Signed: -
Status: -
Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!
Path: c:\windows\i386\netsetup.exe
Status: Allocation size mismatch (API: 352256, Raw: 331776)
Path: c:\windows\i386\ntsd.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\windows\i386\regedit.exe
Status: Allocation size mismatch (API: 167936, Raw: 147456)
Path: c:\windows\i386\spnpinst.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\windows\i386\sysparse.exe
Status: Allocation size mismatch (API: 266240, Raw: 245760)
Path: c:\windows\i386\telnet.exe
Status: Allocation size mismatch (API: 98304, Raw: 77824)
Path: c:\windows\i386\winnt32.exe
Status: Allocation size mismatch (API: 69632, Raw: 49152)
Path: C:\WINDOWS\system32\lowsec
Status: Invisible to the Windows API!
Path: C:\WINDOWS\system32\sdra64.exe
Status: Invisible to the Windows API!
Path: c:\windows\temp\~df1843.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df191e.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df1ce3.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df3cb0.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df52c7.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df72e4.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df789f.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~df7fe1.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\windows\temp\~dff796.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007916.exe
Status: Allocation size mismatch (API: 278528, Raw: 258048)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007917.exe
Status: Allocation size mismatch (API: 790528, Raw: 770048)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007918.exe
Status: Allocation size mismatch (API: 122880, Raw: 102400)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007919.exe
Status: Allocation size mismatch (API: 765952, Raw: 745472)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007920.exe
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007921.exe
Status: Allocation size mismatch (API: 192512, Raw: 172032)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007922.exe
Status: Allocation size mismatch (API: 57344, Raw: 36864)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007923.exe
Status: Allocation size mismatch (API: 172032, Raw: 151552)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007926.exe
Status: Allocation size mismatch (API: 204800, Raw: 184320)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007927.exe
Status: Allocation size mismatch (API: 196608, Raw: 176128)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007928.exe
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007930.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007931.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007932.exe
Status: Allocation size mismatch (API: 45056, Raw: 28672)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007933.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007934.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007935.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007936.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007937.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007938.exe
Status: Allocation size mismatch (API: 77824, Raw: 57344)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007939.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007940.exe
Status: Allocation size mismatch (API: 86016, Raw: 65536)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007941.exe
Status: Allocation size mismatch (API: 122880, Raw: 106496)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007942.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007943.exe
Status: Allocation size mismatch (API: 45056, Raw: 28672)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007944.exe
Status: Allocation size mismatch (API: 106496, Raw: 86016)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007945.exe
Status: Allocation size mismatch (API: 126976, Raw: 106496)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007946.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007948.exe
Status: Allocation size mismatch (API: 61440, Raw: 40960)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007949.exe
Status: Allocation size mismatch (API: 212992, Raw: 196608)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007950.exe
Status: Allocation size mismatch (API: 73728, Raw: 53248)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007951.exe
Status: Allocation size mismatch (API: 106496, Raw: 86016)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007952.exe
Status: Allocation size mismatch (API: 28672, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007953.exe
Status: Allocation size mismatch (API: 352256, Raw: 331776)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007954.exe
Status: Allocation size mismatch (API: 106496, Raw: 86016)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007955.exe
Status: Allocation size mismatch (API: 57344, Raw: 36864)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007956.exe
Status: Allocation size mismatch (API: 65536, Raw: 45056)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007957.exe
Status: Allocation size mismatch (API: 73728, Raw: 53248)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007958.exe
Status: Allocation size mismatch (API: 45056, Raw: 24576)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007959.exe
Status: Allocation size mismatch (API: 81920, Raw: 61440)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007960.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007961.scr
Status: Allocation size mismatch (API: 241664, Raw: 221184)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007962.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007963.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007964.exe
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007966.exe
Status: Allocation size mismatch (API: 65536, Raw: 49152)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007967.exe
Status: Allocation size mismatch (API: 90112, Raw: 69632)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007968.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007969.exe
Status: Allocation size mismatch (API: 53248, Raw: 36864)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007970.exe
Status: Allocation size mismatch (API: 131072, Raw: 110592)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007971.exe
Status: Allocation size mismatch (API: 73728, Raw: 53248)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007972.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007973.exe
Status: Allocation size mismatch (API: 36864, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007974.exe
Status: Allocation size mismatch (API: 57344, Raw: 36864)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007975.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007976.exe
Status: Allocation size mismatch (API: 24576, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007977.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007978.exe
Status: Allocation size mismatch (API: 32768, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007979.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007980.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007981.exe
Status: Allocation size mismatch (API: 98304, Raw: 77824)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007982.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007984.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007985.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007986.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007987.exe
Status: Allocation size mismatch (API: 65536, Raw: 45056)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007988.exe
Status: Allocation size mismatch (API: 98304, Raw: 77824)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007989.scr
Status: Allocation size mismatch (API: 724992, Raw: 704512)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007990.scr
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007991.scr
Status: Allocation size mismatch (API: 413696, Raw: 393216)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007992.scr
Status: Allocation size mismatch (API: 40960, Raw: 24576)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007993.scr
Status: Allocation size mismatch (API: 69632, Raw: 49152)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007994.scr
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007995.scr
Status: Allocation size mismatch (API: 630784, Raw: 610304)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007996.scr
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007997.exe
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007998.exe
Status: Allocation size mismatch (API: 98304, Raw: 77824)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007999.exe
Status: Allocation size mismatch (API: 36864, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008000.exe
Status: Allocation size mismatch (API: 81920, Raw: 61440)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008002.exe
Status: Allocation size mismatch (API: 282624, Raw: 262144)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008003.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008004.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008005.exe
Status: Allocation size mismatch (API: 98304, Raw: 81920)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008006.exe
Status: Allocation size mismatch (API: 81920, Raw: 65536)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008007.exe
Status: Allocation size mismatch (API: 90112, Raw: 73728)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008008.exe
Status: Allocation size mismatch (API: 73728, Raw: 53248)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008009.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008010.exe
Status: Allocation size mismatch (API: 143360, Raw: 122880)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008011.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008012.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008013.exe
Status: Allocation size mismatch (API: 118784, Raw: 98304)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008014.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008015.exe
Status: Allocation size mismatch (API: 40960, Raw: 20480)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008016.exe
Status: Allocation size mismatch (API: 49152, Raw: 28672)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008017.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008018.exe
Status: Allocation size mismatch (API: 40960, Raw: 24576)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008020.exe
Status: Allocation size mismatch (API: 77824, Raw: 57344)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008021.exe
Status: Allocation size mismatch (API: 212992, Raw: 196608)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008022.exe
Status: Allocation size mismatch (API: 77824, Raw: 57344)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008023.exe
Status: Allocation size mismatch (API: 65536, Raw: 45056)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008024.exe
Status: Allocation size mismatch (API: 81920, Raw: 61440)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008025.exe
Status: Allocation size mismatch (API: 163840, Raw: 143360)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008026.exe
Status: Allocation size mismatch (API: 24576, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008027.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008028.exe
Status: Allocation size mismatch (API: 110592, Raw: 90112)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008029.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008030.exe
Status: Allocation size mismatch (API: 36864, Raw: 16384)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008031.exe
Status: Allocation size mismatch (API: 57344, Raw: 36864)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007929.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007947.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007965.exe
Status: Allocation size mismatch (API: 40960, Raw: 24576)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0007983.exe
Status: Allocation size mismatch (API: 45056, Raw: 24576)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008001.exe
Status: Allocation size mismatch (API: 102400, Raw: 81920)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0008019.exe
Status: Allocation size mismatch (API: 28672, Raw: 8192)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010114.exe
Status: Allocation size mismatch (API: 151552, Raw: 131072)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010115.exe
Status: Allocation size mismatch (API: 151552, Raw: 131072)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010128.exe
Status: Allocation size mismatch (API: 352256, Raw: 331776)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010129.exe
Status: Allocation size mismatch (API: 53248, Raw: 32768)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010130.exe
Status: Allocation size mismatch (API: 167936, Raw: 147456)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010131.exe
Status: Allocation size mismatch (API: 32768, Raw: 12288)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010132.exe
Status: Allocation size mismatch (API: 266240, Raw: 245760)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010133.exe
Status: Allocation size mismatch (API: 98304, Raw: 77824)
Path: c:\system volume information\_restore{fe5d2ebd-f87a-4a15-90ad-84a37fab1395}\rp56\a0010134.exe
Status: Allocation size mismatch (API: 69632, Raw: 49152)
==EOF==
FF947 is offline   Reply With Quote
Old 10-20-2009   #2
Bronze Member
 
Join Date: Dec 2008
Posts: 19
PC Experience: Experienced
Default Re: Heavily Infected! Virut

DDS (Ver_09-10-13.01) - NTFSx86
Run by Fred at 8:46:27.03 on Tue 10/20/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2036.1304 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\FastNetSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Linksys EasyLink Advisor\LinksysAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iPod\bin\iPodService.exe
svchost.exe C:\WINDOWS\TEMP\VRT1.tmp
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Fred\Application Data\mjusbsp\magicJack.exe
C:\WINDOWS\svchost.exe
C:\WINDOWS\svchust.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\Program Files\WinRAR\WinRAR.exe
K:\virus scan stuff\dds.scr
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windo ws\system32\drivers\smss.exe,c:\windows\system32\s dra64.exe,
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [EasyLinkAdvisor] "c:\program files\linksys easylink advisor\LinksysAgent.exe" /startup
uRun: [cdloader] "c:\documents and settings\fred\application data\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\fred\applic~1\mozilla\firefox\profiles \isvhfc1t.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - HiddenExtension: XUL Cache: {C6D6E26D-0E9E-4ABB-BACE-D71D6E5FB7D9} - c:\documents and settings\fred\local settings\application data\{c6d6e26d-0e9e-4abb-bace-d71d6e5fb7d9}\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-4 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-4 108552]
R2 BtwSrv;BtwSrv;c:\windows\system32\svchost.exe -k netsvcs [2009-2-11 14336]
R2 fastnetsrv;fastnetsrv Service;c:\windows\system32\FastNetSrv.exe [2008-4-14 114688]
R2 Net_Login;Net_Login;c:\windows\svchust.exe [2009-10-19 745436]
R2 NetLogin;Net Login;c:\windows\svchost.exe [2009-10-20 1168384]
S2 aswiphf;aswiphf;c:\windows\system32\drivers\dnzdd. sys --> c:\windows\system32\drivers\dnzdd.sys [?]
S3 daqdrv;daqdrv;c:\windows\system32\daqdrv.sys [2009-2-11 2304]
S3 Diag69xpiag69xp;c:\windows\system32\drivers\diag 69xp.sys --> c:\windows\system32\drivers\Diag69xp.sys [?]
S3 rt2870;Ralink 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-11-16 550272]
S3 WebSTARNdis;WebSTAR DPX USB Cable Modem Adapter;c:\windows\system32\drivers\WebSTAR.sys [2009-4-15 15417]
S4 avg8wd;avg8wd;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-4 297752]
=============== Created Last 30 ================
2009-10-20 08:32 1,168,384 a------- c:\windows\svchost.exe
2009-10-20 08:31 88,576 a------- c:\windows\system32\15.tmp
2009-10-20 08:31 93,696 a------- c:\windows\system32\F.tmp
2009-10-20 08:31 1 a------- c:\windows\system32\C.tmp
2009-10-20 08:31 156 a------- c:\windows\system32\7.tmp
2009-10-20 08:26 40,960 a------- c:\windows\sv4.exe
2009-10-20 08:24 1 a------- c:\windows\system32\xd.dat
2009-10-20 08:24 1 a------- c:\windows\system32\q1.dat
2009-10-20 08:24 1 a------- c:\windows\system32\idm.dat
2009-10-20 08:24 1 a------- c:\windows\system32\c2d.dat
2009-10-20 08:22 88,576 a------- c:\windows\system32\6.tmp
2009-10-20 08:22 47,104 a------- c:\windows\system32\kadg0.dll
2009-10-20 08:22 1 a------- c:\windows\system32\4.tmp
2009-10-20 08:22 152 a------- c:\windows\system32\2.tmp
2009-10-20 08:12 47,104 a------- c:\windows\system32\kapg1.dll
2009-10-20 08:12 36,133 a------- c:\windows\system32\klkg
2009-10-20 08:12 88,576 a------- c:\windows\system32\E.tmp
2009-10-20 08:12 1 a------- c:\windows\system32\D.tmp
2009-10-20 08:12 152 a------- c:\windows\system32\B.tmp
2009-10-20 08:12 71,168 a------- c:\windows\system32\drivers\smss.exe
2009-10-20 08:11 0 a------- c:\windows\sc.exe
2009-10-20 08:11 <DIR> --d----- c:\program files\Protection System
2009-10-19 16:44 312,800 a------- c:\windows\sv3.exe
2009-10-19 16:44 307,168 a------- c:\windows\sv2.exe
2009-10-19 16:42 745,436 a------- c:\windows\svchust.exe
2009-10-19 16:40 88,576 -------- c:\windows\system32\5.tmp
2009-10-19 16:33 600,026 a------- c:\windows\isvchost.exe
2009-10-19 15:47 88,576 a------- c:\windows\system32\14.tmp
2009-10-19 15:38 409,088 a------- c:\windows\system32\cmd.execf
2009-10-19 15:16 88,576 a------- c:\windows\system32\13.tmp
2009-10-19 15:16 52 a------- c:\windows\system32\12.tmp
2009-10-19 13:38 <DIR> --ds---- C:\ComboFix
2009-10-19 13:37 409,088 a------- c:\windows\system32\CF21067.exe
2009-10-19 13:11 88,576 a------- c:\windows\system32\11.tmp
2009-10-19 13:11 52 a------- c:\windows\system32\10.tmp
2009-10-19 11:00 133,632 a------- c:\windows\SC.INS
2009-10-19 10:56 361,600 a------- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
==================== Find3M ====================
2009-10-19 11:38 32,768 a------- c:\windows\system32\msdtc.exe
2009-09-11 09:18 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-09-04 16:03 58,880 a------- c:\windows\system32\msasn1.dll
2009-08-29 03:08 916,480 a------- c:\windows\system32\wininet.dll
2009-08-26 03:00 247,326 a------- c:\windows\system32\strmdll.dll
2009-08-23 03:09 249,344 a------- c:\windows\PEV.exe
2009-08-05 04:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-04 10:13 2,145,280 -------- c:\windows\system32\ntoskrnl.exe
2009-08-04 09:20 2,023,936 -------- c:\windows\system32\ntkrnlpa.exe
2009-08-04 08:05 11,952 a------- c:\windows\system32\avgrsstx.dll
============= FINISH: 8:47:52.76 ===============
FF947 is offline   Reply With Quote
Old 10-20-2009   #3
Bronze Member
 
Join Date: Dec 2008
Posts: 19
PC Experience: Experienced
Default Re: Heavily Infected! Virut

Results of screen317's Security Check version 0.99.0
Windows XP Service Pack 3
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
AVG Free 8.5
Antivirus up to date!
``````````````````````````````
Anti-malware/Other Utilities Check:

Spybot - Search & Destroy
HijackThis 2.0.2
CCleaner (remove only)
Java(TM) 6 Update 7
Out of date Java installed!
Adobe Flash Player 10
Adobe Reader 9
``````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgtray.exe
SecurityCheck.exe
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)
`````````End of Log```````````
FF947 is offline   Reply With Quote
Old 10-20-2009   #4
Bronze Member
 
Join Date: Dec 2008
Posts: 19
PC Experience: Experienced
Default Re: Heavily Infected! Virut

I can't post the attach document from DDS, the attachment is too large & the text is also too many characters to post.
FF947 is offline   Reply With Quote
Old 10-20-2009   #5
Tech Team Leader
 
DCiAdmin's Avatar
 
Join Date: Sep 2008
Location: Heart of the US Midwest
Posts: 7,496
PC Experience: Perpetual Student
Default Re: Heavily Infected! Virut

Hello FF947,

You can break your DDS log into multiple posts and put it up that way. Best of luck to you
__________________
DCiAdmin
PCHF Rules / PreWork / AfterWork / PCHF Downloads / System File Checker
Thank you for entrusting your system to PCHF!
DCiAdmin is online now   Reply With Quote
Old 10-20-2009   #6
Bronze Member
 
Join Date: Dec 2008
Posts: 19
PC Experience: Experienced
Default Re: Heavily Infected! Virut

DDS (Ver_09-10-13.01)
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 4/15/2009 10:07:39 PM
System Uptime: 10/20/2009 8:30:00 AM (0 hours ago)
Motherboard: Intel Corporation | | DG31PR
Processor: Intel Pentium III Xeon processor | J3E1 | 2499/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 233 GiB total, 177.149 GiB free.
D: is CDROM ()
E: is Removable
F: is Removable
G: is Removable
H: is Removable
I: is CDROM (CDFS)
J: is Removable
K: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
2007 Microsoft Office system
Acrobat.com
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9
Apple Mobile Device Support
Apple Software Update
AVG Free 8.5
Bonjour
CCleaner (remove only)
Critical Update for Windows Media Player 11 (KB959772)
Drivers Install For Linksys Easylink Advisor
EPSON Printer Software
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Intel(R) Graphics Media Accelerator Driver
iTunes
Java(TM) 6 Update 7
Linksys EasyLink Advisor 1.6 (0032)
Logitech iTouch Software
Macromedia Flash Player 8
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional Hybrid 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Windows Journal Viewer
Mozilla Firefox (3.0.14)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Nero 7 Essentials
neroxml
Noderator
OpenOffice.org 3.0
QuickTime
Reader Rabbit Toddler
Realtek High Definition Audio Driver
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953155)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Spybot - Search & Destroy
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Office 2007 (KB934528)
Update for Office System 2007 Setup (KB929722)
Update for Windows XP (KB898461)
Update for Windows XP (KB942763)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951618-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
VLC media player 0.9.9
WebFldrs XP
WebSTAR DPX USB Cable Modem Adapter
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
WinRAR archiver
FF947 is offline   Reply With Quote
Old 10-20-2009   #7
Bronze Member
 
Join Date: Dec 2008
Posts: 19
PC Experience: Experienced
Default Re: Heavily Infected! Virut

==== Event Viewer Messages From Past Week ========
10/19/2009 4:19:45 PM, error: Service Control Manager [7034] - The Net Login service terminated unexpectedly. It has done this 1 time(s).
10/19/2009 12:34:32 PM, error: Service Control Manager [7000] - The RasMan service failed to start due to the following error: The system cannot find the file specified.
10/19/2009 12:34:02 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the RasMan service to connect.
10/19/2009 12:34:02 PM, error: Service Control Manager [7000] - The RasMan service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 12:33:08 PM, error: DCOM [10000] - Unable to start a DCOM Server: {1F87137D-0E7C-44D5-8C73-4EFFB68962F2}. The error: "%5" Happened while starting this command: C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding
10/19/2009 12:32:41 PM, error: Service Control Manager [7000] - The aswiphf service failed to start due to the following error: The system cannot find the file specified.
10/19/2009 11:49:16 AM, information: Windows File Protection [64004] - The protected system file regedit.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:48:41 AM, information: Windows File Protection [64004] - The protected system file userinit.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:46:16 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the RasAuto service to connect.
10/19/2009 11:46:16 AM, error: Service Control Manager [7000] - The RasAuto service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:45:41 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the ProtectedStorage service to connect.
10/19/2009 11:45:41 AM, error: Service Control Manager [7000] - The ProtectedStorage service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:45:11 AM, information: Windows File Protection [64004] - The protected system file unregmp2.exe could not be restored to its original, valid version. The file version of the bad file is 11.0.5721.5235 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:45:11 AM, information: Windows File Protection [64004] - The protected system file muisetup.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:45:07 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PolicyAgent service to connect.
10/19/2009 11:45:07 AM, error: Service Control Manager [7000] - The PolicyAgent service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:44:29 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the ose service to connect.
10/19/2009 11:44:29 AM, error: Service Control Manager [7000] - The ose service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:43:55 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the odserv service to connect.
10/19/2009 11:43:55 AM, error: Service Control Manager [7000] - The odserv service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:43:21 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the NtmsSvc service to connect.
10/19/2009 11:43:21 AM, error: Service Control Manager [7000] - The NtmsSvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:42:47 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the NtLmSsp service to connect.
10/19/2009 11:42:47 AM, error: Service Control Manager [7000] - The NtLmSsp service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:42:22 AM, information: Windows File Protection [64004] - The protected system file nppagent.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:42:22 AM, information: Windows File Protection [64004] - The protected system file comrereg.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:42:22 AM, information: Windows File Protection [64004] - The protected system file comrepl.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:42:09 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Nla service to connect.
10/19/2009 11:42:09 AM, error: Service Control Manager [7000] - The Nla service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:41:31 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Netlogon service to connect.
10/19/2009 11:41:31 AM, error: Service Control Manager [7000] - The Netlogon service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:40:51 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the NBService service to connect.
10/19/2009 11:40:51 AM, error: Service Control Manager [7000] - The NBService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:39:41 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the napagent service to connect.
10/19/2009 11:39:41 AM, error: Service Control Manager [7000] - The napagent service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:39:06 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the MSIServer service to connect.
10/19/2009 11:39:06 AM, error: Service Control Manager [7000] - The MSIServer service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:38:34 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Distributed Transaction Coordinator service to connect.
10/19/2009 11:38:34 AM, error: Service Control Manager [7000] - The Distributed Transaction Coordinator service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:38:22 AM, information: Windows File Protection [64004] - The protected system file msdtc.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:38:12 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the mnmsrvc service to connect.
10/19/2009 11:38:12 AM, error: Service Control Manager [7000] - The mnmsrvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:37:25 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the iPod Service service to connect.
10/19/2009 11:37:25 AM, error: Service Control Manager [7000] - The iPod Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:36:49 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the ImapiService service to connect.
10/19/2009 11:36:49 AM, error: Service Control Manager [7000] - The ImapiService service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:36:15 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HTTPFilter service to connect.
10/19/2009 11:36:15 AM, error: Service Control Manager [7000] - The HTTPFilter service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:35:40 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the hkmsvc service to connect.
10/19/2009 11:35:40 AM, error: Service Control Manager [7000] - The hkmsvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:35:05 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the HidServ service to connect.
10/19/2009 11:35:05 AM, error: Service Control Manager [7000] - The HidServ service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:34:31 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the helpsvc service to connect.
10/19/2009 11:34:31 AM, error: Service Control Manager [7000] - The helpsvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:34:00 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Windows Presentation Foundation Font Cache 3.0.0.0 service to connect.
10/19/2009 11:34:00 AM, error: Service Control Manager [7000] - The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:33:35 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the FastUserSwitchingCompatibility service to connect.
10/19/2009 11:33:35 AM, error: Service Control Manager [7000] - The FastUserSwitchingCompatibility service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:33:10 AM, information: Windows File Protection [64004] - The protected system file wmiprvse.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:10 AM, information: Windows File Protection [64004] - The protected system file wmic.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:10 AM, information: Windows File Protection [64004] - The protected system file wmiapsrv.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:10 AM, information: Windows File Protection [64004] - The protected system file wbemtest.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:10 AM, information: Windows File Protection [64004] - The protected system file unsecapp.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:10 AM, information: Windows File Protection [64004] - The protected system file scrcons.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:03 AM, information: Windows File Protection [64004] - The protected system file wmiadap.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:03 AM, information: Windows File Protection [64004] - The protected system file winmgmt.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:33:02 AM, information: Windows File Protection [64004] - The protected system file mofcomp.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:57 AM, information: Windows File Protection [64004] - The protected system file migwiza.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:57 AM, information: Windows File Protection [64004] - The protected system file migwiz.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:57 AM, information: Windows File Protection [64004] - The protected system file migload.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:52 AM, information: Windows File Protection [64004] - The protected system file srdiag.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:52 AM, information: Windows File Protection [64004] - The protected system file rstrui.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:52 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the ERSvc service to connect.
10/19/2009 11:32:46 AM, information: Windows File Protection [64004] - The protected system file sethc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:46 AM, information: Windows File Protection [64004] - The protected system file qprocess.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:46 AM, information: Windows File Protection [64004] - The protected system file print.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:46 AM, information: Windows File Protection [64004] - The protected system file oobebaln.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:46 AM, information: Windows File Protection [64004] - The protected system file msoobe.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:41 AM, information: Windows File Protection [64004] - The protected system file mpnotify.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:41 AM, information: Windows File Protection [64004] - The protected system file dxdiag.exe could not be restored to its original, valid version. The file version of the bad file is 5.3.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:39 AM, information: Windows File Protection [64004] - The protected system file typeperf.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:39 AM, information: Windows File Protection [64004] - The protected system file logagent.exe could not be restored to its original, valid version. The file version of the bad file is 11.0.5721.5251 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:39 AM, information: Windows File Protection [64004] - The protected system file lodctr.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:37 AM, information: Windows File Protection [64004] - The protected system file locator.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:36 AM, information: Windows File Protection [64004] - The protected system file lnkstub.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:36 AM, information: Windows File Protection [64004] - The protected system file lights.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:30 AM, information: Windows File Protection [64004] - The protected system file wupdmgr.exe could not be restored to its original, valid version. The file version of the bad file is 5.4.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:30 AM, information: Windows File Protection [64004] - The protected system file stimon.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:30 AM, information: Windows File Protection [64004] - The protected system file mstsc.exe could not be restored to its original, valid version. The file version of the bad file is 6.0.6001.18000 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:30 AM, information: Windows File Protection [64004] - The protected system file mstinit.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:25 AM, information: Windows File Protection [64004] - The protected system file w32tm.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:25 AM, information: Windows File Protection [64004] - The protected system file vssvc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:25 AM, information: Windows File Protection [64004] - The protected system file vssadmin.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:25 AM, information: Windows File Protection [64004] - The protected system file msswchx.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:23 AM, information: Windows File Protection [64004] - The protected system file makecab.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:23 AM, information: Windows File Protection [64004] - The protected system file magnify.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:19 AM, information: Windows File Protection [64004] - The protected system file hostname.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:19 AM, information: Windows File Protection [64004] - The protected system file help.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:18 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the EapHost service to connect.
10/19/2009 11:32:18 AM, error: Service Control Manager [7000] - The EapHost service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:32:17 AM, information: Windows File Protection [64004] - The protected system file expand.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:14 AM, information: Windows File Protection [64004] - The protected system file imapi.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:11 AM, information: Windows File Protection [64004] - The protected system file rsvp.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:08 AM, information: Windows File Protection [64004] - The protected system file rsopprov.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:08 AM, information: Windows File Protection [64004] - The protected system file rsnotify.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:08 AM, information: Windows File Protection [64004] - The protected system file rsmui.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2400.1 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:08 AM, information: Windows File Protection [64004] - The protected system file rsmsink.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2400.1 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:05 AM, information: Windows File Protection [64004] - The protected system file rsm.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:05 AM, information: Windows File Protection [64004] - The protected system file rsh.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:02 AM, information: Windows File Protection [64004] - The protected system file wscript.exe could not be restored to its original, valid version. The file version of the bad file is 5.7.0.18066 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:02 AM, information: Windows File Protection [64004] - The protected system file write.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:02 AM, information: Windows File Protection [64004] - The protected system file wpnpinst.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:32:02 AM, information: Windows File Protection [64004] - The protected system file routemon.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:58 AM, information: Windows File Protection [64004] - The protected system file wpabaln.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:55 AM, information: Windows File Protection [64004] - The protected system file xcopy.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:53 AM, information: Windows File Protection [64004] - The protected system file msiexec.exe could not be restored to its original, valid version. The file version of the bad file is 3.1.4001.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:49 AM, information: Windows File Protection [64004] - The protected system file netdde.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:48 AM, information: Windows File Protection [64004] - The protected system file wuauclt1.exe could not be restored to its original, valid version. The file version of the bad file is 5.4.3790.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:48 AM, information: Windows File Protection [64004] - The protected system file net1.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:48 AM, information: Windows File Protection [64004] - The protected system file net.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:48 AM, information: Windows File Protection [64004] - The protected system file nddeapir.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:48 AM, information: Windows File Protection [64004] - The protected system file fltmc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:43 AM, information: Windows File Protection [64004] - The protected system file fixmapi.exe could not be restored to its original, valid version. The file version of the bad file is 5.5.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:41 AM, information: Windows File Protection [64004] - The protected system file finger.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:40 AM, information: Windows File Protection [64004] - The protected system file findstr.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:40 AM, information: Windows File Protection [64004] - The protected system file find.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:40 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Dot3svc service to connect.
10/19/2009 11:31:40 AM, error: Service Control Manager [7000] - The Dot3svc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:31:38 AM, information: Windows File Protection [64004] - The protected system file fc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:38 AM, information: Windows File Protection [64004] - The protected system file extrac32.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:35 AM, information: Windows File Protection [64004] - The protected system file mplay32.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:33 AM, information: Windows File Protection [64004] - The protected system file mountvol.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:31 AM, information: Windows File Protection [64004] - The protected system file mobsync.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:29 AM, information: Windows File Protection [64004] - The protected system file mnmsrvc.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:29 AM, information: Windows File Protection [64004] - The protected system file ipconfig.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:26 AM, information: Windows File Protection [64004] - The protected system file spnpinst.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:26 AM, information: Windows File Protection [64004] - The protected system file spiisupd.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:26 AM, information: Windows File Protection [64004] - The protected system file spider.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:24 AM, information: Windows File Protection [64004] - The protected system file sort.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:23 AM, information: Windows File Protection [64004] - The protected system file sol.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:20 AM, information: Windows File Protection [64004] - The protected system file ups.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:19 AM, information: Windows File Protection [64004] - The protected system file upnpcont.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:19 AM, information: Windows File Protection [64004] - The protected system file unlodctr.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:16 AM, information: Windows File Protection [64004] - The protected system file wextract.exe could not be restored to its original, valid version. The file version of the bad file is 6.0.2900.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:15 AM, information: Windows File Protection [64004] - The protected system file tcmsetup.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:15 AM, information: Windows File Protection [64004] - The protected system file subst.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:15 AM, information: Windows File Protection [64004] - The protected system file sstext3d.scr could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:11 AM, information: Windows File Protection [64004] - The protected system file sessmgr.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:09 AM, information: Windows File Protection [64004] - The protected system file route.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:09 AM, information: Windows File Protection [64004] - The protected system file regedt32.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:09 AM, information: Windows File Protection [64004] - The protected system file reg.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:05 AM, information: Windows File Protection [64004] - The protected system file recover.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:05 AM, information: Windows File Protection [64004] - The protected system file rdshost.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:05 AM, information: Windows File Protection [64004] - The protected system file rdsaddin.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:05 AM, information: Windows File Protection [64004] - The protected system file rdpclip.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:03 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the dmserver service to connect.
10/19/2009 11:31:03 AM, error: Service Control Manager [7000] - The dmserver service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:31:01 AM, information: Windows File Protection [64004] - The protected system file rcp.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:31:00 AM, information: Windows File Protection [64004] - The protected system file rcimlby.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:57 AM, information: Windows File Protection [64004] - The protected system file msdtc.exe could not be restored to its original, valid version. The file version of the bad file is 2001.12.4414.700 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:56 AM, information: Windows File Protection [64004] - The protected system file cmstp.exe could not be restored to its original, valid version. The file version of the bad file is 7.2.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:53 AM, information: Windows File Protection [64004] - The protected system file dcomcnfg.exe could not be restored to its original, valid version. The file version of the bad file is 2001.12.4414.700 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:53 AM, information: Windows File Protection [64004] - The protected system file cscript.exe could not be restored to its original, valid version. The file version of the bad file is 5.7.0.18066 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:53 AM, information: Windows File Protection [64004] - The protected system file cmmon32.exe could not be restored to its original, valid version. The file version of the bad file is 7.2.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:53 AM, information: Windows File Protection [64004] - The protected system file cmdl32.exe could not be restored to its original, valid version. The file version of the bad file is 7.2.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:53 AM, information: Windows File Protection [64004] - The protected system file cmd.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:48 AM, information: Windows File Protection [64004] - The protected system file charmap.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:46 AM, information: Windows File Protection [64004] - The protected system file calc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:46 AM, information: Windows File Protection [64004] - The protected system file cacls.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:42 AM, information: Windows File Protection [64004] - The protected system file wiaacmgr.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:42 AM, information: Windows File Protection [64004] - The protected system file powercfg.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:42 AM, information: Windows File Protection [64004] - The protected system file dpnsvr.exe could not be restored to its original, valid version. The file version of the bad file is 5.3.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:36 AM, information: Windows File Protection [64004] - The protected system file dplaysvr.exe could not be restored to its original, valid version. The file version of the bad file is 5.3.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:36 AM, information: Windows File Protection [64004] - The protected system file ahui.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:33 AM, information: Windows File Protection [64004] - The protected system file actmovie.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:29 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the dmadmin service to connect.
10/19/2009 11:30:29 AM, error: Service Control Manager [7000] - The dmadmin service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:30:18 AM, information: Windows File Protection [64004] - The protected system file tsshutdn.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:18 AM, information: Windows File Protection [64004] - The protected system file tskill.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:18 AM, information: Windows File Protection [64004] - The protected system file tsdiscon.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:18 AM, information: Windows File Protection [64004] - The protected system file tscon.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:18 AM, information: Windows File Protection [64004] - The protected system file taskmgr.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:18 AM, information: Windows File Protection [64004] - The protected system file tasklist.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:12 AM, information: Windows File Protection [64004] - The protected system file taskkill.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:09 AM, information: Windows File Protection [64004] - The protected system file systray.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:09 AM, information: Windows File Protection [64004] - The protected system file systeminfo.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:04 AM, information: Windows File Protection [64004] - The protected system file sysocmgr.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:02 AM, information: Windows File Protection [64004] - The protected system file syskey.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:30:02 AM, information: Windows File Protection [64004] - The protected system file syncapp.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:58 AM, information: Windows File Protection [64004] - The protected system file sndvol32.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:56 AM, information: Windows File Protection [64004] - The protected system file sndrec32.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:56 AM, information: Windows File Protection [64004] - The protected system file smlogsvc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:56 AM, information: Windows File Protection [64004] - The protected system file smbinst.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:56 AM, information: Windows File Protection [64004] - The protected system file skeys.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:54 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Dhcp service to connect.
10/19/2009 11:29:54 AM, error: Service Control Manager [7000] - The Dhcp service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:29:52 AM, information: Windows File Protection [64004] - The protected system file sigverif.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:52 AM, information: Windows File Protection [64004] - The protected system file shutdown.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:52 AM, information: Windows File Protection [64004] - The protected system file secedit.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:49 AM, information: Windows File Protection [64004] - The protected system file sdbinst.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:47 AM, information: Windows File Protection [64004] - The protected system file scrnsave.scr could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:47 AM, information: Windows File Protection [64004] - The protected system file schtasks.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:47 AM, information: Windows File Protection [64004] - The protected system file rasphone.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:44 AM, information: Windows File Protection [64004] - The protected system file rasdial.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:42 AM, information: Windows File Protection [64004] - The protected system file rasautou.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:42 AM, information: Windows File Protection [64004] - The protected system file qwinsta.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:39 AM, information: Windows File Protection [64004] - The protected system file pentnt.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:39 AM, information: Windows File Protection [64004] - The protected system file pathping.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:39 AM, information: Windows File Protection [64004] - The protected system file packager.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:36 AM, information: Windows File Protection [64004] - The protected system file osuninst.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:34 AM, information: Windows File Protection [64004] - The protected system file odbcconf.exe could not be restored to its original, valid version. The file version of the bad file is 3.525.1132.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:33 AM, information: Windows File Protection [64004] - The protected system file odbcad32.exe could not be restored to its original, valid version. The file version of the bad file is 3.525.1132.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:33 AM, information: Windows File Protection [64004] - The protected system file nwscript.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:29 AM, information: Windows File Protection [64004] - The protected system file ntvdm.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:29 AM, information: Windows File Protection [64004] - The protected system file ntsd.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:29 AM, information: Windows File Protection [64004] - The protected system file ntbackup.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:29 AM, information: Windows File Protection [64004] - The protected system file nslookup.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:29 AM, information: Windows File Protection [64004] - The protected system file notepad.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:21 AM, information: Windows File Protection [64004] - The protected system file nbtstat.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:21 AM, information: Windows File Protection [64004] - The protected system file narrator.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:20 AM, information: Windows File Protection [64004] - The protected system file napstat.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:18 AM, information: Windows File Protection [64004] - The protected system file mspaint.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:15 AM, information: Windows File Protection [64004] - The protected system file mrinfo.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:15 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the CryptSvc service to connect.
10/19/2009 11:29:15 AM, error: Service Control Manager [7000] - The CryptSvc service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
10/19/2009 11:29:12 AM, information: Windows File Protection [64004] - The protected system file mqtgsvc.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:12 AM, information: Windows File Protection [64004] - The protected system file mqsvc.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.0.1110 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:12 AM, information: Windows File Protection [64004] - The protected system file mmcperf.exe could not be restored to its original, valid version. The file version of the bad file is 5.2.3790.4136 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:09 AM, information: Windows File Protection [64004] - The protected system file mmc.exe could not be restored to its original, valid version. The file version of the bad file is 5.2.3790.4136 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:09 AM, information: Windows File Protection [64004] - The protected system file label.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:09 AM, information: Windows File Protection [64004] - The protected system file iexpress.exe could not be restored to its original, valid version. The file version of the bad file is 6.0.2900.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:05 AM, information: Windows File Protection [64004] - The protected system file grpconv.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:04 AM, information: Windows File Protection [64004] - The protected system file gpupdate.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:29:02 AM, information: Windows File Protection [64004] - The protected system file gpresult.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:58 AM, information: Windows File Protection [64004] - The protected system file dwwin.exe could not be restored to its original, valid version. The file version of the bad file is 10.0.5815.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:58 AM, information: Windows File Protection [64004] - The protected system file dvdupgrd.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:57 AM, information: Windows File Protection [64004] - The protected system file osk.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:57 AM, information: Windows File Protection [64004] - The protected system file dvdplay.exe could not be restored to its original, valid version. The file version of the bad file is 1.0.0.2 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:57 AM, information: Windows File Protection [64004] - The protected system file dumprep.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:53 AM, information: Windows File Protection [64004] - The protected system file drwtsn32.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:52 AM, information: Windows File Protection [64004] - The protected system file driverquery.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:48 AM, information: Windows File Protection [64004] - The protected system file dpvsetup.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:48 AM, information: Windows File Protection [64004] - The protected system file dmadmin.exe could not be restored to its original, valid version. The file version of the bad file is 2600.5512.503.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:48 AM, information: Windows File Protection [64004] - The protected system file diantz.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file dllhst3g.exe could not be restored to its original, valid version. The file version of the bad file is unknown The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file dllhost.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file diskperf.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file diskpart.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.3565.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file bootvrfy.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file bootok.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.0 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:46 AM, information: Windows File Protection [64004] - The protected system file bootcfg.exe could not be restored to its original, valid version. The file version of the bad file is 5.1.2600.5512 The specific error code is 0x000006b5 [The interface is unknown. ].
10/19/2009 11:28:42 AM, information: Windows File Protection [64001] - File replacement was attempted on the protected system file c:\windows\system32\diantz.exe. This file was restored to the original version to maintain system stability. The file version of the bad file is 5.1.2600.5512, the version of the system file is 5.1.2600.5512.
10/19/2009 11:28:40 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the COMSysApp service to connect.
FF947 is offline   Reply With Quote

Reply

Bookmarks

Tags
heavily, infected, virut
Similar discussions...
Thread Thread Starter Forum Replies Last Post
Solved: AVG reports Virut after using usb vaccine cdpaul [Fixed] Hijackthis! Logs 7 06-27-2009 10:27 PM
Win32/virut.NBM virus... Please help! jan019 [Fixed] Hijackthis! Logs 3 04-20-2009 10:38 PM
Restarts When heavily in use- about 15 mins later AW_3_3 Windows XP/2000 4 06-23-2007 01:06 AM
<News> Nigerian Scammers Profiting Heavily in Australia Newsie IT News 0 05-24-2007 07:38 AM

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On




All times are GMT. The time now is 04:52 PM.
Powered by vBulletin
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2