Multiple problems - underlying cause?


So, after nearly tearing my hair out, I figured I should start looking for help.

For some reasons, in the last week or so, my computer has dissolved in a bunch of problems, the likes of which I have never experienced before. I feel way out of my league!

I am using a HP desktop model a1730n with Vista SP2.

A few days ago, I had a BSoD that took me over 3 hours to fix. I ran Avast in Safe Mode, then again in normal mode, and the following items were moved to the chest:

Virus: Win32:Malwar-gen found in C:\Users\Marie\AppData\Local\Temp
PUP: KillIt.exe found in C:\hp\bin
Virus: Win32:Kryptik-BDL (Tri) found in C:\Users\Marie\AppData\Local\Temp
Virus: JS: Pdfka-gen (Expl) found in C:\Users\Marie\AppData\Local\Temp\plugtmp-33

A day later, it started acting up again, closing my web browser and just acting funky. Avast came clear, but Spybot found Click.GiftLoad. It was successfully removed. Things started working fine again.

Today I got something called Vista Total Security 2011 as I watched a video. I was able to stop the process and ran Malwarebytes’ Anti-Malware. I have pasted the log down bellow, in case. I’m not sure doing the scan was enough though…

Considering this sudden onslaught of problems, I’m wondering if there might be an underlying cause, like a breach created in my system by another deeper rooted program, or something.

Any help in this matter would be very appreciated!

Psych Chick

Malwarebytes’ Anti-Malware

Database version: 6280

Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18928

2011-04-05 15:36:35
mbam-log-2011-04-05 (15-36-35).txt

Scan type: Quick scan
Objects scanned: 157268
Time elapsed: 11 minute , 20 second

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{1A26F07F-0D60-4835-91CF-1E1766A0EC56} (Trojan.Agent) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{37B85A29-692B-4205-9CAD-2626E4993404} (Adware.MyWebSearch) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} (Rogue.WinAntiVirus) → Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Marie\AppData\Local\Temp\0.718423249291581.exe (Trojan.Agent) → Quarantined and deleted successfully.
c:\Users\Marie\AppData\Local\Temp\0.8090568037286583.exe (Trojan.Agent) → Quarantined and deleted successfully.
c:\Users\Marie\local settings\application data\bfb.exe (Trojan.Agent) → Quarantined and deleted successfully.
c:\Users\Marie\local settings\application data\nxk.exe (Trojan.Agent) → Quarantined and deleted successfully.
c:\Users\Marie\local settings\application data\Update.exe (Trojan.Agent) → Quarantined and deleted successfully.

Hi there lets look deeper then

Download OTS to your Desktop and double-click on it to run it

[*]Make sure you close all other programs and don’t use the PC while the scan runs.
[*]Select All Users
[*]Under additional scans select the following
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

[*]Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Please attach the log in your next post.


Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the “Scan” button to start scan

On completion of the scan click save log, save it to your desktop and post in your next reply


First of all, thank you for your help!

I did as instructed, and have attached the log for the OTS. The aswMBR results are pasted below.

I seem to have encountered a new problem too. Following the execution of Malwarebytes’ Anti-Malware scan & fixes, some of the file associations seem to be broken, as I can only run programs if I pick “Run as administrator”. When I try to click on any program normally, it asks me to choose the program to open the file. I’m not sure if it’s related to the registry keys that were infected or another virus…

aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
Run date: 2011-04-05 21:12:12

21:12:12.452 OS Version: Windows 6.0.6002 Service Pack 2
21:12:12.452 Number of processors: 2 586 0x4302
21:12:12.452 ComputerName: MARIE-PC UserName: Marie
21:12:17.163 Initialize success
21:12:55.664 Disk 0 (boot) \Device\Harddisk0\DR0 → \Device\00000067
21:12:55.664 Disk 0 Vendor: WDC_WD32 21.0 Size: 305245MB BusType: 6
21:12:57.708 Disk 0 MBR read successfully
21:12:57.708 Disk 0 MBR scan
21:12:59.736 Disk 0 scanning sectors +625136400
21:12:59.767 Disk 0 scanning C:\Windows\system32\drivers
21:13:09.049 Service scanning
21:13:10.609 Disk 0 trace - called modules:
21:13:10.625 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x8518f1e8]<<
21:13:10.625 1 nt!IofCallDriver → \Device\Harddisk0\DR0[0x865f8ac8]
21:13:10.625 3 CLASSPNP.SYS[88ba38b3] → nt!IofCallDriver → [0x85be5a60]
21:13:10.640 5 acpi.sys[8072d6bc] → nt!IofCallDriver → \Device\00000067[0x85c5ab88]
21:13:10.640 \Driver\nvstor32[0x85ba01c0] → IRP_MJ_CREATE → 0x8518f1e8
21:13:10.640 Scan finished successfully

Hi once this has run then as if by magic the open with problem should disappear ;D

As OTS runs it will kill all processes and you will lose your desktop - this is normal

I see that you have the full suite of Norton drivers still running (about 15) I would recommend that you uninstall Norton and use their removal tool

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Unregister Dlls]
[Registry - Safe List]
< MountPoints2 [HKEY_CURRENT_USER] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2
YN -> \{b75242f5-979c-11dc-82be-001a92255ffe} -> 
YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b75242f5-979c-11dc-82be-001a92255ffe}\shell\AutoRun\command -> 
YN -> \{b75242f5-979c-11dc-82be-001a92255ffe}\shell\AutoRun\command\\"" -> [K:\uottawa.exe]
< Registry Shell Spawning - Select to Repair > -> HKEY_USERS\S-1-5-21-2996808130-2015224822-2870089688-1000_Classes\<key>\shell\[command]\command
YN -> exefile [open] -> "C:\Users\Marie\AppData\Local\bfb.exe" -a "%1" %*
< File Associations - Select to Repair > -> HKEY_USERS\S-1-5-21-2996808130-2015224822-2870089688-1000\SOFTWARE\Classes\<extension>\
YN -> .exe [@ = exefile] -> "C:\Users\Marie\AppData\Local\bfb.exe" -a "%1" %*
[Files/Folders - Modified Within 30 Days]
NY ->  hu320yd24e3ntnlx58jymbus402xl62x5ty -> C:\Users\Marie\AppData\Local\hu320yd24e3ntnlx58jymbus402xl62x5ty
NY ->  hu320yd24e3ntnlx58jymbus402xl62x5ty -> C:\ProgramData\hu320yd24e3ntnlx58jymbus402xl62x5ty
[Files - No Company Name]
NY ->  hu320yd24e3ntnlx58jymbus402xl62x5ty -> C:\Users\Marie\AppData\Local\hu320yd24e3ntnlx58jymbus402xl62x5ty
NY ->  hu320yd24e3ntnlx58jymbus402xl62x5ty -> C:\ProgramData\hu320yd24e3ntnlx58jymbus402xl62x5ty
[Custom Items]
ipconfig /flushdns /c
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.

Hello there,

well, I uninstalled my old Norton and ran the fix on OTS.

However, there were some problems, with it freezing and Windows closing it, but the third time was the charm! ^.^

Here is the log I got when my computer restarted:

All Processes Killed
[Registry - Safe List]
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{b75242f5-979c-11dc-82be-001a92255ffe}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{b75242f5-979c-11dc-82be-001a92255ffe}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{b75242f5-979c-11dc-82be-001a92255ffe}\shell\AutoRun\command\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2{b75242f5-979c-11dc-82be-001a92255ffe}\shell\AutoRun\command not found.
Registry value HKEY_USERS\S-1-5-21-2996808130-2015224822-2870089688-1000_Classes\exefile\shell\open\command\‘’ updated successfully.
Registry key HKEY_USERS\S-1-5-21-2996808130-2015224822-2870089688-1000_classes.exe\ not found.
Registry key HKEY_USERS\S-1-5-21-2996808130-2015224822-2870089688-1000_classes\Reg Error: Key error.\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Classes.exe\shell\open\exefile\‘’ updated successfully.
[Files/Folders - Modified Within 30 Days]
File C:\Users\Marie\AppData\Local\hu320yd24e3ntnlx58jymbus402xl62x5ty not found!
File C:\ProgramData\hu320yd24e3ntnlx58jymbus402xl62x5ty not found!
[Files - No Company Name]
File C:\Users\Marie\AppData\Local\hu320yd24e3ntnlx58jymbus402xl62x5ty not found!
File C:\ProgramData\hu320yd24e3ntnlx58jymbus402xl62x5ty not found!
[Custom Items]
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Marie\Desktop\cmd.bat deleted successfully.
C:\Users\Marie\Desktop\cmd.txt deleted successfully.
File/Folder C:\Users\Marie\AppData\Local\bfb.exe not found.
[Empty Temp Folders]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Marie
->Temp folder emptied: 392828 bytes
->Temporary Internet Files folder emptied: 57257 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 16299454 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Sandra
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1411 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 20140293 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 12130554 bytes
RecycleBin emptied: 9351886234 bytes

Total Files Cleaned = 8 965,00 mb


User: All Users

User: Default

User: Default User

User: Marie
->Flash cache emptied: 0 bytes

User: Public

User: Sandra

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTS Restore Point
< End of fix log >
OTS by OldTimer - Version fix logfile created on 04062011_165958

Files\Folders moved on Reboot…
File move failed. C:\Windows\temp_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…

What problems are evident now ?

Things seemed to be working good, but it seems I got the Vista Total Security 2011 thing again. I’m kinda scared to browse the web now. Ah ah…

I used Malwarebytes again to get rid of it, and it killed my .exe association again. Can I just use the fix you sent me previously?

And is there a way to prevent the Vista total security 2011 from coming back again? I also caught it on my laptop (toshiba, windows 7), but for some reason it did less damage, and everything worked fine after I ran Malwarebytes…

Thanks a lot for your help…

And is there a way to prevent the Vista total security 2011 from coming back again?
Use Malwarebytes PRO that has a protection module, IP block, autoupdate.... Price, a onetime fee for a lifetime lisence

I must admit I have to ask what sites are you going to - to keep picking up the infection

If you get a popup then close your browser down, do not click the redX of the popup or cancel

The malware probably has a different set of file names so the previous fix will probably not work…

Could you run a fresh OTS scan please

Well, I wasn’t visiting I thought was bad, mostly emails, university related websites, and sidereel. The infections seemed to happened when I visited sidereel, and not always when I clicked on external links either. I didn’t think the site was bad, as I had been visiting it for a while without any problem whatsoever…

Malwarebytes came back clean, but I ran Spybot in case, and it detected Fraud Desktop Security 2010, and deleted it. Now the link associations don’t seem to be broken anymore… and hopefully that’s the end of it.

I included the OTS scan, just in case…

I’m sorry for the bother…

What other problems do you have ? I tried for three hours yesterday on my XP VM to get infected and I failed ;D I might go visit sidereel

Just two folders/files to remove

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Unregister Dlls]
[Files/Folders - Modified Within 30 Days]
NY ->  03at6tewtog3u77211ad34 -> C:\Users\Marie\AppData\Local\03at6tewtog3u77211ad34
NY ->  03at6tewtog3u77211ad34 -> C:\ProgramData\03at6tewtog3u77211ad34
[Files - No Company Name]
NY ->  03at6tewtog3u77211ad34 -> C:\Users\Marie\AppData\Local\03at6tewtog3u77211ad34
NY ->  03at6tewtog3u77211ad34 -> C:\ProgramData\03at6tewtog3u77211ad34
[Custom Items]
[Empty Temp Folders]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.


Thanks for the fix! I ran it, as indicated, and got the following log as a result. As far as I know too, I don’t have any other problem with my computer. Still, I guess it’s time for me to invest in some better security options than what I use right now…

All Processes Killed
[Files/Folders - Modified Within 30 Days]
C:\Users\Marie\AppData\Local\03at6tewtog3u77211ad34 moved successfully.
C:\ProgramData\03at6tewtog3u77211ad34 moved successfully.
[Files - No Company Name]
File C:\Users\Marie\AppData\Local\03at6tewtog3u77211ad34 not found!
File C:\ProgramData\03at6tewtog3u77211ad34 not found!
[Custom Items]
========== FILES ==========
File/Folder C:\Users\Marie\AppData\Local\03at6tewtog3u77211ad34 not found.
File/Folder C:\ProgramData\03at6tewtog3u77211ad34 not found.
[Empty Temp Folders]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Marie
->Temp folder emptied: 15917929 bytes
->Temporary Internet Files folder emptied: 5088400 bytes
->Java cache emptied: 226611 bytes
->FireFox cache emptied: 46957865 bytes
->Flash cache emptied: 25203 bytes

User: Public

User: Sandra
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 32178 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
%systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 246010 bytes

Total Files Cleaned = 65,00 mb


User: All Users

User: Default

User: Default User

User: Marie
->Flash cache emptied: 0 bytes

User: Public

User: Sandra

Total Flash Files Cleaned = 0,00 mb

Restore point Set: OTS Restore Point
< End of fix log >
OTS by OldTimer - Version fix logfile created on 04122011_001149

Files\Folders moved on Reboot…
File move failed. C:\Windows\temp_avast5_\Webshlock.txt scheduled to be moved on reboot.

Registry entries deleted on Reboot…

To be honest the only security I use is Avast - If I remember I may run Malwarebytes occasionally

So all is OK now ?

It looks good so far…

Thank you again for your help… and patience… ^.^

No problem - run OTS and hit the cleanup button ;D