This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help possible rootkit

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So today I noticed I had two services.exe running So I did a malwarebytes scan but uacinit.dll kept coming back. Now I did a Combo-Fix and a gmer and I think is gone but I was wondering if someone can tell me for sure.

Here's the gmer log

GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-02 17:48:25
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT spoa.sys ZwCreateKey [0xF84150E0]
SSDT spoa.sys ZwEnumerateKey [0xF8433CA4]
SSDT spoa.sys ZwEnumerateValueKey [0xF8434032]
SSDT spoa.sys ZwOpenKey [0xF84150C0]
SSDT spoa.sys ZwQueryKey [0xF843410A]
SSDT spoa.sys ZwQueryValueKey [0xF8433F8A]
SSDT spoa.sys ZwSetValueKey [0xF843419C]

INT 0x35 ? 8207DF00
INT 0x39 ? 82372BF8
INT 0x39 ? 8207DF00
INT 0x3E ? 8236FBF8
INT 0x3F ? 8236FBF8

—- Kernel code sections - GMER 1.0.15 —-

? spoa.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F73E962C 5 Bytes JMP 8207D4E0
.text asexhw52.SYS F7399386 35 Bytes [00, 00, 00, 00, 00, 00, 20, …]
.text asexhw52.SYS F73993AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, …]
.text asexhw52.SYS F73993C4 3 Bytes [00, 70, 02] {ADD [EAX+0x2], DH}
.text asexhw52.SYS F73993C9 1 Byte [30]
.text asexhw52.SYS F73993C9 11 Bytes [30, 00, 00, 00, 5C, 02, 00, …] {XOR [EAX], AL; ADD [EAX], AL; POP ESP; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text …

—- Kernel IAT/EAT - GMER 1.0.15 —-

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 823722D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F8446C4C] spoa.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F8446CA0] spoa.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F8416042] spoa.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F841613E] spoa.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F84160C0] spoa.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F8416800] spoa.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F84166D6] spoa.sys
IAT \SystemRoot\System32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F8425E9C] spoa.sys
IAT \SystemRoot\System32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8207D5E0
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlInitUnicodeString] 00021083
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!swprintf] 01B05E00
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeSetEvent] 5DE58B5B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 7E8366C3
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 0F740028
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 89320C8D
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmFreeMappingAddress] 0002288B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 46B70F00
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 66D00328
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmUnmapIoSpace] 002A7E83
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 0C8D1574
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IofCompleteRequest] 248B8932
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlCompareUnicodeString] 0F000002
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IofCallDriver] 832A46B7
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmAllocateMappingAddress] E08303C0
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] 66D003FC
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoConnectInterrupt] 002C7E83
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoDetachDevice] 0C8D1E74
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeWaitForSingleObject] 208B8932
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeInitializeEvent] 8A000002
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] 83880846
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlInitAnsiString] 000001C0
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] 2C4EB70F
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoQueueWorkItem] 8303C183
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmMapIoSpace] D103FCE1
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 2E7E8366
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoReportDetectedDevice] 8D1C7400
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoReportResourceForDetection] 83893204
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 00000218
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!NlsMbCodePageTag] 2E4EB70F
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!PoRequestPowerIrp] 021C8B89
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] B70F0000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] E0C12E46
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!sprintf] 03D00304
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 0CB389F2
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ObfDereferenceObject] 80000002
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 0975013E
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 1B42E853
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ZwClose] C4830000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] B05E5F04
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] E58B5B01
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] CCCCC35D
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!PoStartNextPowerIrp] CCCCCCCC
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!PoCallDriver] 53EC8B55
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoCreateDevice] 08758B56
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 0214BE83
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlQueryRegistryValues] 57000000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ZwOpenKey] 45C60674
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlFreeUnicodeString] 1EEB010B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoStartTimer] 020C868B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeInitializeTimer] C0850000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoInitializeTimer] 808A1074
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeInitializeDpc] 00000804
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeInitializeSpinLock] A03CF024
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoInitializeIrp] 0B45950F
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ZwCreateKey] 45C604EB
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlAppendUnicodeStringToString] 458A000B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlIntegerToUnicodeString] 88C0840B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ZwSetValueKey] 840F0946
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeInsertQueueDpc] 000000C1
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KefAcquireSpinLockAtDpcLevel] 14B30E8B
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoStartPacket] 1C8286C6
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KefReleaseSpinLockFromDpcLevel] 88010000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoBuildAsynchronousFsdRequest] 001C859E
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoFreeMdl] A19E8800
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmUnlockPages] C600001C
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoWriteErrorLogEntry] 001C8686
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeRemoveByKeyDeviceQueue] 86C60100
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmMapLockedPagesWithReservedMapping] 00001CA2
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmUnmapReservedMapping] 70518B01
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeSynchronizeExecution] 8D52006A
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoStartNextPacket] 001C8886
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeBugCheckEx] 55E85000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeRemoveDeviceQueue] 8B000023
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeSetTimer] 70518B0E
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeCancelTimer] 8D52016A
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!_allmul] 001CA486
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmProbeAndLockPages] 41E85000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!_except_handler3] 8B000023
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!PoSetPowerState] 18C4830E
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoOpenDeviceRegistryKey] 1C8D9E88
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlWriteRegistryValue] 9E880000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!_aulldiv] 00001CA9
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!strstr] 0E798366
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!_strupr] 74AAB000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeQuerySystemTime] 8186C636
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoWMIRegistrationControl] 1A00001C
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!KeTickCount] 1C8386C6
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoAttachDeviceToDeviceStack] C6020000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoDeleteDevice] 001C8E86
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ExAllocatePoolWithTag] 86C60200
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoAllocateWorkItem] 00001CAA
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoAllocateIrp] 959E8802
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoAllocateMdl] 8800001C
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmBuildMdlForNonPagedPool] 001CB19E
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmLockPagableDataSection] 96868800
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoGetDriverObjectExtension] 8800001C
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmUnlockPagableImageSection] 001CB286
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!ExFreePoolWithTag] C61AEB00
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoFreeIrp] 001C8186
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!IoFreeWorkItem] 86C61200
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!InitSafeBootMode] 00001C83
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlCompareMemory] 8E868801
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!memmove] 001CAA86
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[ntoskrnl.exe!MmHighestUserAddress] 80968B00
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!KfAcquireSpinLock] 0C8D1C46
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!READ_PORT_UCHAR] B08B8932
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!KeGetCurrentIrql] 89000001
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!KfRaiseIrql] 0001BC83
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!KfLowerIrql] 24468B00
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!HalGetInterruptVector] 89820C8D
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!HalTranslateBusAddress] D18BF84D
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!KeStallExecutionProcessor] 860F1639
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!KfReleaseSpinLock] 000000BD
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 0208B389
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 7400067E
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[HAL.dll!WRITE_PORT_UCHAR] 89D60320
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[WMILIB.SYS!WmiSystemControl] 8D168B00
IAT \SystemRoot\System32\Drivers\asexhw52.SYS[WMILIB.SYS!WmiCompleteRequest] F0003284

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8236E1F8
Device \Driver\usbuhci \Device\USBPDO-0 82095500
Device \Driver\dmio \Device\DmControl\DmIoDaemon 823DE1F8
Device \Driver\dmio \Device\DmControl\DmConfig 823DE1F8
Device \Driver\dmio \Device\DmControl\DmPnP 823DE1F8
Device \Driver\dmio \Device\DmControl\DmInfo 823DE1F8
Device \Driver\usbuhci \Device\USBPDO-1 82095500
Device \Driver\PCI_PNP0704 \Device\00000046 spoa.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 823701F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 823701F8
Device \Driver\Cdrom \Device\CdRom0 8217B1F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 823701F8
Device \Driver\atapi \Device\Ide\IdePort0 8236F1F8
Device \Driver\atapi \Device\Ide\IdePort1 8236F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 8236F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 8236F1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 8236F1F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 82130500
Device \Driver\NetBT \Device\NetbiosSmb 82130500
Device \Driver\sptd \Device\2179532288 spoa.sys
Device \Driver\usbuhci \Device\USBFDO-0 82095500
Device \Driver\usbuhci \Device\USBFDO-1 82095500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8212E500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8212E500
Device \Driver\Ftdisk \Device\FtControl 823701F8
Device \Driver\asexhw52 \Device\Scsi\asexhw521 82164500
Device \FileSystem\Cdfs \Cdfs 821091F8

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xB0 0x07 0xD7 0xC2 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA0 0x72 0xEA 0x3E …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x76 0xE4 0x53 0x34 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x5B 0x45 0x83 0x34 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x06 0x9B 0xBF 0x82 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCC 0x27 0x73 0x0D …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 1
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xB0 0x07 0xD7 0xC2 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 2
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xA0 0x72 0xEA 0x3E …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0x76 0xE4 0x53 0x34 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x5B 0x45 0x83 0x34 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0x06 0x9B 0xBF 0x82 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0xCC 0x27 0x73 0x0D …
Reg HKLM\SOFTWARE\Classes\.application\bootstrap@ bootstrap.application.1

—- EOF - GMER 1.0.15 —-

Let me know if you need anymore logs
thanks
Hi shaggy187,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please drag your version of ComboFix to the recycle bin and then download a clean one.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
I know I don't have recovery console installed but I own the xp and I can just run it off the cd.



ComboFix 09-08-10.06 - Shags 08/15/2009 17:09.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.231 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090802-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Installer\1ef4a79.msi
c:\windows\Installer\1ef4aac.msi

.
((((((((((((((((((((((((( Files Created from 2009-07-15 to 2009-08-15 )))))))))))))))))))))))))))))))
.

2009-08-04 23:06 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 23:06 . 2009-08-04 23:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 23:06 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 00:12 . 2009-02-05 20:06 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-03 00:12 . 2009-02-05 20:06 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-03 00:12 . 2009-02-05 20:05 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-03 00:12 . 2009-02-05 20:04 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-03 00:12 . 2009-02-05 20:08 93296 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-03 00:12 . 2009-02-05 20:08 94032 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-03 00:12 . 2009-02-05 20:07 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-03 00:12 . 2009-02-05 20:07 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-03 00:12 . 2009-02-05 20:11 1256296 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-03 00:12 . 2009-08-03 00:12 ——– d—–w- c:\program files\Alwil Software
2009-08-02 05:24 . 2009-08-02 05:24 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-08-02 05:24 . 2009-08-02 05:24 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-02 05:23 . 2009-08-02 05:23 152576 —-a-w- c:\documents and settings\Shags\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-08-02 04:37 . 2009-08-02 04:37 ——– d—–w- c:\program files\Trend Micro
2009-08-01 23:45 . 2009-08-01 23:45 ——– d—–w- c:\documents and settings\Shags\Application Data\Logs
2009-08-01 23:17 . 2009-08-01 23:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-17 03:27 . 2009-08-01 23:16 ——– d—–w- c:\program files\RocketDock

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-13 20:56 . 2008-06-05 21:17 49152 —-a-w- c:\windows\system32\PIE_DUMP.DAT
2009-08-11 22:45 . 2006-05-05 17:22 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-08-11 21:21 . 2009-06-29 04:36 74 —-a-w- C:\mc2xml.dat
2009-08-02 23:57 . 2006-04-04 20:52 93824 —-a-w- c:\documents and settings\Shags\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-02 23:47 . 2009-05-21 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Roxio
2009-08-02 23:21 . 2006-05-08 05:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-02 05:24 . 2006-04-14 08:21 ——– d—–w- c:\program files\Java
2009-07-11 23:01 . 2009-07-11 23:00 ——– d—–w- c:\documents and settings\Shags\Application Data\Roxio
2009-07-08 23:11 . 2009-07-08 23:00 ——– d—–w- c:\program files\RCT3
2009-07-08 23:10 . 2009-07-08 23:10 ——– d—–w- c:\documents and settings\Shags\Application Data\Atari
2009-07-08 23:08 . 2009-07-08 23:08 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2009-07-08 23:07 . 2009-07-08 23:07 ——– d—–w- c:\documents and settings\Shags\Application Data\Leadertech
2009-07-08 23:01 . 2006-04-04 19:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-03 06:37 . 2009-07-03 06:19 ——– d—–w- c:\program files\Free FLV Converter
2009-07-02 05:08 . 2009-07-02 05:08 ——– d—–w- c:\program files\SlySoft
2009-07-02 05:06 . 2007-12-11 00:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SlySoft
2009-06-30 05:28 . 2009-06-30 05:28 ——– d—–w- c:\program files\MSBuild
2009-06-30 05:28 . 2009-06-30 05:28 ——– d—–w- c:\program files\Reference Assemblies
2009-06-30 05:22 . 2009-06-30 05:22 ——– d—–w- c:\program files\MSXML 6.0
2009-06-29 22:54 . 2009-06-29 21:35 ——– d—–w- c:\documents and settings\Shags\Application Data\WinFF
2009-06-29 21:41 . 2009-06-29 21:41 486 —-a-w- c:\documents and settings\Shags\Application Data\WinFF\ff090629164116.bat
2009-06-20 00:58 . 2009-07-03 06:19 299008 —-a-w- c:\windows\system32\TubeFinder.exe
2009-06-20 00:51 . 2009-07-03 06:19 9728 —-a-w- c:\windows\system32\PCCLPFR.DLL
2009-06-20 00:51 . 2009-07-03 06:19 119568 —-a-w- c:\windows\system32\VB6FR.DLL
2009-06-20 00:51 . 2009-07-03 06:19 101888 —-a-w- c:\windows\system32\VB6STKIT.DLL
2009-06-20 00:51 . 2009-07-03 06:19 32768 —-a-w- c:\windows\system32\CMDLGFR.DLL
2009-06-20 00:51 . 2009-07-03 06:19 141312 —-a-w- c:\windows\system32\MSCMCFR.DLL
2009-06-11 20:33 . 2009-06-11 20:33 104512 —-a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-05-25 12:01 . 2009-05-25 12:01 89256 —-a-w- c:\windows\system32\ElbyCDIO.dll
2009-05-21 16:33 . 2009-05-21 01:34 256 —-a-w- c:\windows\system32\pool.bin
2007-12-11 00:09 . 2007-12-10 23:45 24 –sh–w- c:\windows\SBA325BDD.tmp
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
BTVAgent2.lnk - c:\d drive\Program Files\Beyond TV 3\BTVAgent2.exe [2004-12-21 184320]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Beyond TV.lnk - c:\d drive\Program Files\Beyond TV 3\BTVAgent2.exe [2004-12-21 184320]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoRecentDocsNetHood"= 01000000
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
"NoNetworkConnections"= 01000000

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVGuideDataLoader.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\PVSLibraryAppService.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVRecordingEngine.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\PVSConfigService.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVD3DShell.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVWebServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/2/2009 7:12 PM 114768]
R1 CXAVSAUD;ADS PTV 305 Audio Capture;c:\windows\system32\drivers\cxavsaud.sys [4/13/2006 1:32 PM 9984]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/2/2009 7:12 PM 20560]
R3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\windows\system32\drivers\FTD2XX.sys [4/13/2006 1:37 PM 25573]
S2 WiRNS;WiRNS;e:\wirns.exe –> e:\wirns.exe [?]
S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [3/26/2007 11:26 PM 7548]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
FF - ProfilePath - c:\documents and settings\Shags\Application Data\Mozilla\Firefox\Profiles\yzdnc8ny.default\
FF - prefs.js: browser.search.selectedEngine - swagbucks.com
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\d drive\Program Files\Real Alternative\browser\plugins\nppl3260.dll
FF - plugin: c:\d drive\Program Files\Real Alternative\browser\plugins\nprpjplug.dll
FF - plugin: c:\documents and settings\Shags\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-15 17:15
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
@DACL=(02 0000)
@="bootstrap.application.1"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(484)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-08-15 17:18
ComboFix-quarantined-files.txt 2009-08-15 22:18

Pre-Run: 38,300,381,184 bytes free
Post-Run: 38,190,903,296 bytes free

199
shaggy187,

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    File::
    c:\windows\SBA325BDD.tmp
    
    Reglock::
    [HKEY_LOCAL_MACHINE\software\Classes\.application\bootstrap]
    
    Driver::
    WiRNS
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Here's the combofix log I will post the Kaspersky log when it is finished.

ComboFix 09-08-10.06 - Shags 08/15/2009 21:18.3.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.276 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Shags\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090802-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
"c:\windows\SBA325BDD.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\SBA325BDD.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_WIRNS
——-\Service_WiRNS


((((((((((((((((((((((((( Files Created from 2009-07-16 to 2009-08-16 )))))))))))))))))))))))))))))))
.

2009-08-04 23:06 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-04 23:06 . 2009-08-04 23:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-04 23:06 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-03 00:12 . 2009-02-05 20:06 51376 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-03 00:12 . 2009-02-05 20:06 23152 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-03 00:12 . 2009-02-05 20:05 26944 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-03 00:12 . 2009-02-05 20:04 97480 —-a-w- c:\windows\system32\AvastSS.scr
2009-08-03 00:12 . 2009-02-05 20:08 93296 —-a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-03 00:12 . 2009-02-05 20:08 94032 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-03 00:12 . 2009-02-05 20:07 114768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-03 00:12 . 2009-02-05 20:07 20560 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-03 00:12 . 2009-02-05 20:11 1256296 —-a-w- c:\windows\system32\aswBoot.exe
2009-08-03 00:12 . 2009-08-03 00:12 ——– d—–w- c:\program files\Alwil Software
2009-08-02 05:24 . 2009-08-02 05:24 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-08-02 05:24 . 2009-08-02 05:24 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2009-08-02 05:23 . 2009-08-02 05:23 152576 —-a-w- c:\documents and settings\Shags\Application Data\Sun\Java\jre1.6.0_14\lzma.dll
2009-08-02 04:37 . 2009-08-02 04:37 ——– d—–w- c:\program files\Trend Micro
2009-08-01 23:45 . 2009-08-01 23:45 ——– d—–w- c:\documents and settings\Shags\Application Data\Logs
2009-08-01 23:17 . 2009-08-01 23:17 ——– d-sh–w- c:\windows\system32\config\systemprofile\IETldCache
2009-07-17 03:27 . 2009-08-01 23:16 ——– d—–w- c:\program files\RocketDock

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-13 20:56 . 2008-06-05 21:17 49152 —-a-w- c:\windows\system32\PIE_DUMP.DAT
2009-08-11 22:45 . 2006-05-05 17:22 ——– d—–w- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-08-11 21:21 . 2009-06-29 04:36 74 —-a-w- C:\mc2xml.dat
2009-08-02 23:57 . 2006-04-04 20:52 93824 —-a-w- c:\documents and settings\Shags\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-02 23:47 . 2009-05-21 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Roxio
2009-08-02 23:21 . 2006-05-08 05:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-02 05:24 . 2006-04-14 08:21 ——– d—–w- c:\program files\Java
2009-07-11 23:01 . 2009-07-11 23:00 ——– d—–w- c:\documents and settings\Shags\Application Data\Roxio
2009-07-08 23:11 . 2009-07-08 23:00 ——– d—–w- c:\program files\RCT3
2009-07-08 23:10 . 2009-07-08 23:10 ——– d—–w- c:\documents and settings\Shags\Application Data\Atari
2009-07-08 23:08 . 2009-07-08 23:08 43520 —-a-w- c:\windows\system32\CmdLineExt03.dll
2009-07-08 23:07 . 2009-07-08 23:07 ——– d—–w- c:\documents and settings\Shags\Application Data\Leadertech
2009-07-08 23:01 . 2006-04-04 19:13 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-07-03 06:37 . 2009-07-03 06:19 ——– d—–w- c:\program files\Free FLV Converter
2009-07-02 05:08 . 2009-07-02 05:08 ——– d—–w- c:\program files\SlySoft
2009-07-02 05:06 . 2007-12-11 00:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SlySoft
2009-06-30 05:28 . 2009-06-30 05:28 ——– d—–w- c:\program files\MSBuild
2009-06-30 05:28 . 2009-06-30 05:28 ——– d—–w- c:\program files\Reference Assemblies
2009-06-30 05:22 . 2009-06-30 05:22 ——– d—–w- c:\program files\MSXML 6.0
2009-06-29 22:54 . 2009-06-29 21:35 ——– d—–w- c:\documents and settings\Shags\Application Data\WinFF
2009-06-29 21:41 . 2009-06-29 21:41 486 —-a-w- c:\documents and settings\Shags\Application Data\WinFF\ff090629164116.bat
2009-06-20 00:58 . 2009-07-03 06:19 299008 —-a-w- c:\windows\system32\TubeFinder.exe
2009-06-20 00:51 . 2009-07-03 06:19 9728 —-a-w- c:\windows\system32\PCCLPFR.DLL
2009-06-20 00:51 . 2009-07-03 06:19 119568 —-a-w- c:\windows\system32\VB6FR.DLL
2009-06-20 00:51 . 2009-07-03 06:19 101888 —-a-w- c:\windows\system32\VB6STKIT.DLL
2009-06-20 00:51 . 2009-07-03 06:19 32768 —-a-w- c:\windows\system32\CMDLGFR.DLL
2009-06-20 00:51 . 2009-07-03 06:19 141312 —-a-w- c:\windows\system32\MSCMCFR.DLL
2009-06-11 20:33 . 2009-06-11 20:33 104512 —-a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-05-25 12:01 . 2009-05-25 12:01 89256 —-a-w- c:\windows\system32\ElbyCDIO.dll
2009-05-21 16:33 . 2009-05-21 01:34 256 —-a-w- c:\windows\system32\pool.bin
.

((((((((((((((((((((((((((((( SnapShot@2009-08-15_22.15.53 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-08-16 02:26 . 2009-08-16 02:26 16384 c:\windows\temp\Perflib_Perfdata_494.dat
+ 2009-08-16 02:24 . 2009-08-16 02:24 8192 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
+ 2009-08-16 02:24 . 2009-08-16 02:24 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
+ 2009-08-16 02:24 . 2009-08-16 02:24 233472 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
+ 2009-08-16 02:24 . 2009-08-16 02:24 212992 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
+ 2009-08-16 02:24 . 2009-08-16 02:24 233472 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
+ 2009-08-16 02:24 . 2009-08-16 02:24 7458816 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]

c:\documents and settings\Default User\Start Menu\Programs\Startup\
BTVAgent2.lnk - c:\d drive\Program Files\Beyond TV 3\BTVAgent2.exe [2004-12-21 184320]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Beyond TV.lnk - c:\d drive\Program Files\Beyond TV 3\BTVAgent2.exe [2004-12-21 184320]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoRecentDocsNetHood"= 01000000
"NoSMMyDocs"= 01000000
"NoSMMyPictures"= 01000000
"NoNetworkConnections"= 01000000

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Desktop Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Desktop Manager.lnk
backup=c:\windows\pss\Desktop Manager.lnkCommon Startup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVGuideDataLoader.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\PVSLibraryAppService.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVRecordingEngine.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\PVSConfigService.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVD3DShell.exe"=
"c:\\D Drive\\Program Files\\Beyond TV 3\\BTVWebServer.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [8/2/2009 7:12 PM 114768]
R1 CXAVSAUD;ADS PTV 305 Audio Capture;c:\windows\system32\drivers\cxavsaud.sys [4/13/2006 1:32 PM 9984]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [8/2/2009 7:12 PM 20560]
R3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\windows\system32\drivers\FTD2XX.sys [4/13/2006 1:37 PM 25573]
S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [3/26/2007 11:26 PM 7548]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uSearchURL,(Default) = hxxp://my.netzero.net/s/search?r=minisearch
FF - ProfilePath - c:\documents and settings\Shags\Application Data\Mozilla\Firefox\Profiles\yzdnc8ny.default\
FF - prefs.js: browser.search.selectedEngine - swagbucks.com
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\d drive\Program Files\Real Alternative\browser\plugins\nppl3260.dll
FF - plugin: c:\d drive\Program Files\Real Alternative\browser\plugins\nprpjplug.dll
FF - plugin: c:\documents and settings\Shags\Application Data\Move Networks\plugins\npqmp071500000347.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-15 21:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(488)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(3852)
c:\windows\system32\WININET.dll
c:\program files\RocketDock\RocketDock.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-08-16 21:32 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-16 02:31
ComboFix2.txt 2009-08-15 22:18

Pre-Run: 38,219,227,136 bytes free
Post-Run: 38,117,371,904 bytes free

228
It didn't find anything buy here's the report. ——————————————————————————- KASPERSKY ONLINE SCANNER 7.0: scan report Sunday, August 16, 2009 Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Sunday, August 16, 2009 05:38:44 Records in database: 2633963 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 122612 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 02:34:19 No threats found. Scanned area is clean. Selected area has been scanned.
shaggy187,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
  • [external image: Posted Image]
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Please re-enable any security that was disabled.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI