This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] recycler problem

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi ALL, Hope some one out there can help me ? ive a small prob all of a sudden if i double click on any of my hard drives in my computer they no longer open just give me the message " windows cant find recyclers \5-4-8-63-100010688-100003219-100007990-5561.com. i can open them by using explore but not by double clicking any more . its not a major just annoying . is there a quick fix ? and how do i stop it from doing again . ive obviously pressed something wrong . THANKS phil c IVE originally posted this in "windows help" section , but " ZTRUCKER" thought i may have a virus or malewre . I think this is a bit unlikeley as its an edit suite and an internet virgin, ie its not connected to net and if ineed something put on there i always scan first and virus check anything that goes on there!! can anyone suggest what i may be doing wrong THANKS phil c
Hi,

It does sound like an Autorun Infection, likely transferred to this machine via USB.



Prior to using a USB to transfer the program I am going to have you run, we need to disinfect your USB

Please do the following:

Download Flash_Disinfector.exe from HERE and save it to your desktop.

  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.

NEXT

Download this program onto USB and transfer it to the infected pc and run it.

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
Many thanks Catbyte, i shall do exactly as you say tomorrow and post then , reason being the mc is in my office and im at home now. will post results tom if thats ok thank you so much . you are right i was having the same message off my usb stick and had to reformat . regards phil c
HI CATBYTE , PLEASE FIND LOG as asked for i have carried out all your instructions to the letter. Malwarebytes' Anti-Malware 1.36 Database version: 1945 Windows 5.1.2600 Service Pack 2 02/05/2009 16:55:28 mbam-log-2009-05-02 (16-55-28).txt Scan type: Quick Scan Objects scanned: 63388 Time elapsed: 2 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) thanks for your help so far regards phil c
Hi,

Please do the following:

From a machine that has internet access, download the following program and transfer it to your machine.
Post the resulting logs:


Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
thanks catbyte, im running an edit suite programme called grass valley edius , i presume these programmes wont interfer with my edit suite and change any settings and therefore stop it running ??? regards phil c
Hi, This tool shouldn't interfere with legitimate programs on your computer. Just make sure all your programs are closed when you run the tool. Make sure any AV or Antispyware programs you may have are disabled. Combofix makes backups should any accidental deletions occur, that can easily be recovered.
thanks catbyte , always better to check first i think
heres the log you want

ComboFix 09-05-02.4 - P Compton 02/05/2009 17:41.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.2046.1578 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
c:\docume~1\PCOMPT~1\LOCALS~1\Temp\tmp2.tmp
D:\Autorun.inf
E:\Autorun.inf

.
((((((((((((((((((((((((( Files Created from 2009-04-02 to 2009-05-02 )))))))))))))))))))))))))))))))
.

2009-05-02 16:21 . 2009-05-02 16:36 ——– d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-02 16:20 . 2005-08-25 18:18 118784 —-a-w c:\windows\system32\MSSTDFMT.DLL
2009-05-02 16:20 . 2009-05-02 16:20 ——– d—–w c:\program files\SpywareBlaster
2009-05-02 16:19 . 2009-05-02 16:19 ——– d—–w c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-05-02 16:19 . 2009-05-02 16:19 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-02 16:19 . 2009-05-02 16:19 ——– d—–w c:\documents and settings\P Compton\Application Data\SUPERAntiSpyware.com
2009-05-02 16:18 . 2009-05-02 16:18 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-02 15:39 . 2009-05-02 15:39 ——– d—–w c:\documents and settings\P Compton\Application Data\Malwarebytes
2009-05-02 15:39 . 2009-04-06 14:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-05-02 15:39 . 2009-04-06 14:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-02 15:39 . 2009-05-02 15:39 ——– d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-02 15:39 . 2009-05-02 15:39 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 17:47 . 2009-04-30 17:47 ——– d—–w c:\documents and settings\All Users\Application Data\FLEXnet
2009-04-30 15:55 . 2009-04-30 17:02 ——– d—–w c:\program files\Adobe Media Player
2009-04-30 15:54 . 2009-04-30 15:54 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-04-30 15:51 . 2009-04-30 15:51 ——– d—–w c:\program files\Common Files\Macrovision Shared
2009-04-25 17:30 . 2009-04-25 17:30 ——– d—–w c:\program files\NewBlue

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-02 16:41 . 2006-03-17 17:20 6 —ha-w c:\windows\Tasks\SA.DAT
2009-05-02 15:56 . 2006-03-20 11:55 101 —-a-w c:\windows\hptuser.dat
2009-04-30 16:03 . 2006-03-20 09:40 99992 —-a-w c:\documents and settings\P Compton\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-30 15:57 . 2006-03-20 11:17 ——– d—–w c:\program files\Common Files\Adobe
2009-03-16 19:03 . 2006-03-21 10:03 372 —-a-w c:\windows\Tasks\Symantec NetDetect.job
2009-03-13 15:02 . 2006-03-21 14:28 ——– d—–w c:\program files\Common Files\Canopus Shared
2009-03-13 15:02 . 2006-03-20 09:53 ——– d–h–w c:\program files\InstallShield Installation Information
2006-03-22 09:54 . 2006-03-22 09:54 848 –sha-w c:\windows\system32\KGyGaAvL.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-03-23 1830128]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NexusServer"="c:\program files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe" [2008-08-05 520192]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 —-a-w c:\program files\SUPERAntiSpyware\SASWINLO.dll

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave1"= serwvdrv.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R1 TSIRCINK;Traveling Software Install Driver; [x]
S0 AACMgt;AACMgt; [x]
S0 hptmv;hptmv;c:\windows\system32\DRIVERS\hptmv.sys [2004-09-06 168041]
S1 cdrblock;cdrblock;c:\windows\system32\DRIVERS\cdrblock.sys [2007-05-31 20864]
S1 cdrport;cdrport;c:\windows\system32\DRIVERS\cdrport.sys [2005-03-11 4608]
S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2009-03-23 9968]
S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2009-03-23 72944]
S1 tsircmir;LapLink Mirror Driver Miniport;c:\windows\system32\Drivers\tsircmir.sys [2004-09-29 2816]
S2 hptsvr;HighPoint RAID Management Service;c:\program files\HighPoint Technologies, Inc.\HighPoint RAID Management Software\service\hptsvr.exe [2004-06-07 53248]
S2 TSISER;TSISER; [x]
S2 TSISTRMX;Traveling Software Stream Driver; [x]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-03-23 7408]
S3 TSIKBF5;Traveling Software Keyboard Filter Driver; [x]
S3 TSIMSF5;Traveling Software Mouse Filter Driver; [x]
S3 zskrnl;zskrnl;c:\windows\system32\DRIVERS\zskrnl.sys [2007-08-30 29952]


— Other Services/Drivers In Memory —

*NewlyCreated* - SASDIFSV
*NewlyCreated* - SASENUM
*NewlyCreated* - SASKUTIL

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{12c21efc-11c7-11db-a057-00304886ea83}]
\Shell\AutoRun\command - g:\jdlightning\Windows\JDLightning.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{32d43dd1-b5d6-11da-bca6-806d6172696f}]
\rem shell\readme\command - notepad \readme.txt
.
Contents of the 'Scheduled Tasks' folder

2009-03-16 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2006-03-21 12:24]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-AdobeBridge - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dvc.uk.com/index.php
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-02 17:42
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-05-02 17:43
ComboFix-quarantined-files.txt 2009-05-02 16:43

Pre-Run: 2,317,369,344 bytes free
Post-Run: 3,144,024,064 bytes free

110
regards phil c
Hi,


Can you describe how your computer is running now and if you still have any outstanding issues.



If you are still having problems, then we need a further diagnosis.

Please download the following program and transfer to your PC - post the resulting log


Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.
Hi Catbyte, my mc is ok now its doing all things as normal now thanks for that , what was it and how do i not do it again here are the two logs asked for UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-03-16.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 17/03/2006 17:18:59 System Uptime: 05/02/2009 16:56:33 (2066 hours ago) Motherboard: Supermicro | | PDSG4 Processor: Intel® Pentium® D CPU 3.20GHz | Socket 775 | 3192/200mhz Processor: Intel® Pentium® D CPU 3.20GHz | Socket 775 | 3192/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 40 GiB total, 2.933 GiB free. D: is FIXED (NTFS) - 466 GiB total, 384.065 GiB free. E: is FIXED (NTFS) - 37 GiB total, 36.621 GiB free. F: is Removable K: is CDROM () ==== Disabled Device Manager Items ============= Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: Intel® PRO/1000 PM Network Connection Device ID: PCI\VEN_8086&DEV_108C&SUBSYS_108C15D9&REV_00\4&A74A70D&0&00E5 Manufacturer: Intel Name: Intel® PRO/1000 PM Network Connection PNP Device ID: PCI\VEN_8086&DEV_108C&SUBSYS_108C15D9&REV_00\4&A74A70D&0&00E5 Service: e1express Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\16000DC6201101 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\16000DC6201101 Service: NIC1394 Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\13439660050C5 Manufacturer: Microsoft Name: 1394 Net Adapter #2 PNP Device ID: V1394\NIC1394\13439660050C5 Service: NIC1394 Class GUID: {4D36E96F-E325-11CE-BFC1-08002BE10318} Description: PS/2 Compatible Mouse Device ID: ACPI\PNP0F13\4&1E5E1293&0 Manufacturer: Microsoft Name: PS/2 Compatible Mouse PNP Device ID: ACPI\PNP0F13\4&1E5E1293&0 Service: i8042prt ==== System Restore Points =================== RP216: 20/02/2009 18:08:31 - System Checkpoint RP217: 25/02/2009 19:29:42 - System Checkpoint RP218: 27/02/2009 13:15:06 - System Checkpoint RP219: 07/03/2009 10:15:23 - System Checkpoint RP220: 08/03/2009 15:38:25 - System Checkpoint RP221: 13/03/2009 14:57:31 - Installed Canopus Codec Option RP222: 13/03/2009 14:58:18 - Installed Windows Media Format Runtime RP223: 13/03/2009 14:58:41 - Installed Windows XP Wudf01000. RP224: 13/03/2009 14:59:40 - Installed Windows XP KB926239. RP225: 13/03/2009 15:02:43 - Installed ProCoder 3 RP226: 16/03/2009 13:53:43 - System Checkpoint RP227: 09/04/2009 21:16:27 - System Checkpoint RP228: 30/04/2009 15:41:36 - System Checkpoint RP229: 30/04/2009 18:01:58 - Restore Operation RP230: 30/04/2009 18:43:38 - Restore Operation RP231: 02/05/2009 17:19:04 - Installed SUPERAntiSpyware Free Edition ==== Installed Programs ====================== Ad-Aware SE Personal Adaptec Storage Manager Adobe After Effects CS4 Adobe After Effects CS4 Presets Adobe After Effects CS4 Third Party Content Adobe AIR Adobe Anchor Service CS4 Adobe Bridge CS4 Adobe CMaps CS4 Adobe Color Video Profiles AE CS4 Adobe Default Language CS4 Adobe Device Central CS4 Adobe Dynamiclink Support Adobe ExtendScript Toolkit CS4 Adobe Extension Manager CS4 Adobe Fonts All Adobe Media Encoder CS4 Adobe Media Encoder CS4 Additional Exporter Adobe Media Encoder CS4 Exporter Adobe Media Encoder CS4 Importer Adobe Media Player Adobe MotionPicture Color Files CS4 Adobe Output Module Adobe PDF Library Files CS4 Adobe Photoshop 7.0 Adobe Reader 7.0 Adobe Setup Adobe Type Support CS4 Adobe Update Manager CS4 Adobe XMP Panels CS4 AdobeColorCommonSetRGB AVCHD converter Canopus Bonus Video Out Plug-ins Canopus Codec Option Canopus DV Driver Canopus DV File Converter Canopus GXF SpeedEncoder 1.3 Canopus ProCoder 2 Canopus ProCoder Express For EDIUS Creative Modem Blaster V.92 DI5733 DivX Player DVCapture EDIUS BP OPTION EDIUS Core EDIUS SoundSoap VST Plugin EDIUS4 Settings EDIUS4(SetupManager) EDIUS4(XplodePro) HighPoint RAID Management Software Hotfix for Windows Media Format SDK (KB902344) Hotfix for Windows XP (KB896344) Hotfix for Windows XP (KB912475) Hotfix for Windows XP (KB926239) HX-E1 Intel Matrix Storage Manager Intel® PRO Network Connections Drivers J2SE Runtime Environment 5.0 Update 2 J2SE Runtime Environment 5.0 Update 6 K-Lite Mega Codec Pack 4.1.7 Laplink Gold 12.0 Host LiveReg (Symantec Corporation) LiveUpdate 2.6 (Symantec Corporation) Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft .NET Framework 2.0 Microsoft Base Smart Card Cryptographic Service Provider Package Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable MPEGcapture MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 Parser and SDK Nero OEM NewBlue Free Effects for Windows Norton Ghost 10.0 NVIDIA Drivers Photoshop Camera Raw Pixel Bender Toolkit PowerDVD ProCoder 3 QuickTime Realtek AC'97 Audio Remove DivX Pro Codec RX-E1 Screenblast ACID 4.0 Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Setup Sonic Foundry Sound Forge 6.0b Spybot - Search & Destroy 1.4 SpywareBlaster 4.2 Suite Shared Configuration CS4 SUPERAntiSpyware Free Edition Tweak UI Ulead DVD Workshop 2 SE Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900930) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB912945) VideoLAN VLC media player 0.8.6a WebFldrs XP Windows Genuine Advantage Validation Tool Windows Installer 3.1 (KB893803) Windows Media Connect Windows Media Encoder 9 Series Windows Media Format 11 runtime Windows Media Format SDK Hotfix - KB891122 Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB887797 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinZip ==== End Of File =========================== DDS (Ver_09-03-16.01) - NTFSx86 Run by [removed] at 18:19:20.09 on 02/05/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Professional 5.1.2600.2.1252.44.1033.18.2046.1572 [GMT 1:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Adaptec\Adaptec Storage Manager\StorServ.exe C:\WINDOWS\System32\GEARSec.exe C:\Program Files\HighPoint Technologies, Inc\HighPoint RAID Management Software\service\hptsvr.exe C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe C:\Program Files\HighPoint Technologies, Inc\HighPoint RAID Management Software\service\drvinst.exe C:\Program Files\Norton Ghost\Agent\VProSvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\System32\TSIRCSRV.EXE C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe C:\WINDOWS\TSI32\tsircusr.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Grass Valley\ProCoder 3\Kernel\PNXSERVR.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\freecell.exe C:\Documents and Settings\P Compton\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.dvc.uk.com/index.php BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [NexusServer] "c:\program files\common files\grass valley\procoder 3\kernel\PNXSERVR.exe" -SelfLaunch IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142868554687 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R0 AACMgt;AACMgt;c:\windows\system32\drivers\aacmgt.sys [2005-7-14 93331] R0 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys [2004-9-16 168041] R1 cdrblock;cdrblock;c:\windows\system32\drivers\cdrblock.sys [2006-3-21 20864] R1 cdrport;cdrport;c:\windows\system32\drivers\cdrport.sys [2006-3-21 4608] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-3-23 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-3-23 72944] R1 tsircmir;LapLink Mirror Driver Miniport;c:\windows\system32\drivers\tsircmir.sys [2006-3-20 2816] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCEVTMGR.EXE [2004-12-13 198304] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSETMGR.EXE [2004-12-13 181920] R2 hptsvr;HighPoint RAID Management Service;c:\program files\highpoint technologies, inc\highpoint raid management software\service\hptsvr.exe [2006-3-20 53248] R2 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-3-21 822424] R2 TSISER;TSISER;c:\windows\system32\drivers\tsiser.sys [2006-3-20 43040] R2 TSISTRMX;Traveling Software Stream Driver;c:\windows\system32\drivers\TSISTRMX.SYS [2006-3-20 5120] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-3-23 7408] R3 TSIKBF5;Traveling Software Keyboard Filter Driver;c:\windows\system32\drivers\TSIKBF5.sys [2006-3-20 9728] R3 TSIMSF5;Traveling Software Mouse Filter Driver;c:\windows\system32\drivers\TSIMSF5.sys [2006-3-20 5632] R3 zskrnl;zskrnl;c:\windows\system32\drivers\zskrnl.sys [2007-2-9 29952] S1 TSIRCINK;Traveling Software Install Driver;c:\windows\system32\drivers\TSIRCINK.SYS [2006-3-20 9216] S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\CCPWDSVC.EXE [2004-12-13 79520] =============== Created Last 30 ================ 2009-05-02 17:41 161,792 a——- c:\windows\SWREG.exe 2009-05-02 17:41 98,816 a——- c:\windows\sed.exe 2009-05-02 17:40 –d—– C:\ComboFix 2009-05-02 17:20 1,071,088 a——- c:\windows\system32\MSCOMCTL.OCX 2009-05-02 17:20 118,784 a——- c:\windows\system32\MSSTDFMT.DLL 2009-05-02 17:20 –d—– c:\program files\SpywareBlaster 2009-05-02 17:19 –d—– c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-05-02 17:19 –d—– c:\program files\SUPERAntiSpyware 2009-05-02 17:19 –d—– c:\docume~1\pcompt~1\applic~1\SUPERAntiSpyware.com 2009-05-02 17:18 –d—– c:\program files\common files\Wise Installation Wizard 2009-05-02 16:39 –d—– c:\docume~1\pcompt~1\applic~1\Malwarebytes 2009-05-02 16:39 15,504 a——- c:\windows\system32\drivers\mbam.sys 2009-05-02 16:39 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-02 16:39 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-05-02 16:39 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-05-02 16:36 54,156 a—h— c:\windows\QTFont.qfn 2009-05-02 16:36 1,409 a——- c:\windows\QTFont.for 2009-04-30 16:51 –d—– c:\program files\common files\Macrovision Shared 2009-04-25 18:30 –d—– c:\program files\NewBlue ==================== Find3M ==================== 2006-03-22 10:54 848 a–sh— c:\windows\system32\KGyGaAvL.sys ============= FINISH: 18:19:26.62 =============== regards phil c
Hi,

It was an autorun.inf infection - transferred to your pc by an infected USB.

Your java is out of date, you may wish to download the most uptodate version - version 6 update 13, then remove all the outdated versions through add/remove programs.

http://www.java.com/en/download/manual.jsp


Now we need to clean up our tools:


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


MalwareBytes can be uninstalled via add/remove programs and you can just delete the DDS folder from your desktop.

then you should be good to go.

As this computer doesn't connect to the internet the only way to infect it - is by transferring through removable media.

Use the flash disinfector program I gave you to clean up all your removable media, get into the habit of reformatting them once you no longer need the data contained on them or replacing them fairly frequently as they are fairly cheap now to replace.

Hopefully things will be OK now.

Stay safe :wavey:

CB
I should advise you that your autorun feature has now been disabled - the programs can be started manually. You do not want the autorun feature - especially in your situation. If set to autorun - the USB or other attached media will open automatically - allowing any infections to enter your computer automatically. Its safer if you choose to run the program manually. Hopefully this is not an inconvenience to you as it is a safer practice.
BIG THANKS CATBYTE, YOU GUYS ROCK. done all yove asked and took all on board. have a nice rest of the weekend !! phil c

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI