This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] redirecting links on google search

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

there are links on google search that redirect me when i click on the site i want to go to. This started happening about a week ago. Here is a logfile of hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:54:34 PM, on 8/22/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file://C:\Program Files\Family Feud 2\Images\stg_drm.ocx
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file://C:\Program Files\Family Feud 2\Images\armhelper.ocx
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe (file missing)
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 7486 bytes
Hi there, welcome to WhatTheTech :)

Let's have a closer look at your system.

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done two logs should open:
  • DDS.txt
  • Attach.txt
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from one of the following locations and save it to your desktop.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • In the Select Scan dialog, check
    [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Please post the contents of this log in your next reply.
Hi, thank you for your time in helping me fix my computer. When I opened RootRepeal it appeared with a message "Error - invalid PE image found!". Also, in the RootRepeal tool, after I selected the boxes in the "select scan dialog" and hit ok, the scan automatically starts without seeing step 7 "Check the box for your main system drive (Usually C:), and press Ok." Here is what I got for the logfiles of DDS and RootRepeal and the attached file.

DDS LOG:

DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 11:52:33.43 on Tue 08/25/2009
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.767.90 [GMT -4:00]


============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Daniel\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: 1 (0x1) - No File
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [nwiz] nwiz.exe /install
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
IE: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
IE: &Windows; Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live; Favorites - http://favorites.live.com/quickadd.aspx
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aol toolbar 2.0\aoltb.dll
DPF: {00000055-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/fhg.CAB
DPF: {00000161-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file://c:\program files\family feud 2\images\stg_drm.ocx
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - hxxp://www.eset.eu/buxus/docs/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file://c:\program files\family feud 2\images\armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\daniel\applic~1\mozilla\firefox\profiles\kqnvipio.default\
FF - prefs.js: browser.search.selectedEngine - Search
FF - component: c:\program files\real\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmozax.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npvirtools.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2004-2-9 301200]
R2 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-5-12 611664]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2004-2-29 242808]
R2 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2004-2-9 37008]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\naveng.sys [2009-8-14 87888]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090814.004\navex15.sys [2009-8-14 875728]
S3 AsAudioDevice_351;AsAudioDevice_351;c:\windows\system32\drivers\AsAudioDevice_351.sys [2009-2-3 16640]
S3 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2004-2-29 255096]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\ccPwdSvc.exe [2004-2-29 87160]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys [2008-5-13 42112]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2004-3-12 169192]
S3 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2004-3-12 1221864]
S3 wsvad_driver;iEffectsoft Audio;c:\windows\system32\drivers\CapAudio.sys [2009-2-3 20480]

=============== Created Last 30 ================

2009-08-23 18:52 –d—– c:\program files\iWin
2009-08-23 18:51 –d—– c:\windows\system32\Adobe
2009-08-17 12:37 54,784 a——- c:\windows\system32\drivers\UACd.sys
2009-08-17 12:36 164,405 a——- c:\windows\system32\net.net
2009-08-16 00:40 –d—– c:\windows\ServicePackFiles

==================== Find3M ====================

2009-08-24 01:57 3,462 a——- c:\windows\system32\PerfStringBackup.TMP
2009-08-18 09:40 34 a——- c:\documents and settings\daniel\jagex_runescape_preferences.dat
2009-08-05 05:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-17 14:55 58,880 a——- c:\windows\system32\atl.dll
2009-07-13 10:08 286,720 a——- c:\windows\system32\wmpdxm.dll
2009-06-26 12:18 659,456 a——- c:\windows\system32\wininet.dll
2009-06-26 12:18 81,920 a——- c:\windows\system32\ieencode.dll
2009-06-25 14:36 661,504 a——- c:\windows\system32\mqqm.dll
2009-06-25 14:36 517,120 a——- c:\windows\system32\mqsnap.dll
2009-06-25 14:36 471,552 a——- c:\windows\system32\mqutil.dll
2009-06-25 14:36 225,280 a——- c:\windows\system32\mqoa.dll
2009-06-25 14:36 186,880 a——- c:\windows\system32\mqtrig.dll
2009-06-25 14:36 177,152 a——- c:\windows\system32\mqrt.dll
2009-06-25 14:36 138,240 a——- c:\windows\system32\mqad.dll
2009-06-25 14:36 123,392 a——- c:\windows\system32\mqrtdep.dll
2009-06-25 14:36 95,744 a——- c:\windows\system32\mqsec.dll
2009-06-25 14:36 48,640 a——- c:\windows\system32\mqupgrd.dll
2009-06-25 14:36 47,104 a——- c:\windows\system32\mqdscli.dll
2009-06-25 14:36 16,896 a——- c:\windows\system32\mqise.dll
2009-06-25 04:44 724,480 a——- c:\windows\system32\lsasrv.dll
2009-06-25 04:44 298,496 a——- c:\windows\system32\kerberos.dll
2009-06-25 04:44 168,448 a——- c:\windows\system32\schannel.dll
2009-06-25 04:44 133,632 a——- c:\windows\system32\msv1_0.dll
2009-06-25 04:44 59,392 a——- c:\windows\system32\wdigest.dll
2009-06-25 04:44 56,320 a——- c:\windows\system32\secur32.dll
2009-06-22 07:49 117,248 a——- c:\windows\system32\mqtgsvc.exe
2009-06-22 07:49 19,968 a——- c:\windows\system32\mqbkup.exe
2009-06-22 07:49 4,608 a——- c:\windows\system32\mqsvc.exe
2009-06-16 10:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-12 07:50 80,896 a——- c:\windows\system32\tlntsess.exe
2009-06-12 07:50 76,288 a——- c:\windows\system32\telnet.exe
2009-06-10 10:21 84,992 a——- c:\windows\system32\avifil32.dll
2009-06-10 02:32 132,096 a——- c:\windows\system32\wkssvc.dll
2009-06-05 03:42 655,872 a——- c:\windows\system32\mstscax.dll
2009-06-03 15:27 1,290,752 a——- c:\windows\system32\quartz.dll
2008-01-15 20:16 22,328 a——- c:\docume~1\daniel\applic~1\PnkBstrK.sys

============= FINISH: 11:55:28.39 ===============

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=–=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=–=-=-=-=-=-=-=-=-=-=-=-=-=–=-=-=-=-=-=-=-=-=-=-=-=

ROOTREPEAL LOG:

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/25 12:02
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
——————-
Name: 00000087
Image Path: \Driver\00000087
Address: 0x00000000 Size: 0 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF4C8F000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7D8C000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB8FDF000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden Services
——————-
Service Name: kbiwkmykwlvnms
Image Path: C:\WINDOWS\system32\drivers\kbiwkmbphxtsrt.sys

==EOF==

Attachments:

Hi,

If you already have a copy of ComboFix, please delete it.

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]

[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on Combo-Fix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

After this, please run RootRepeal again, checking all the boxes this time, and post the log it gives.
Combo-Fix was installing the microsoft windows recovery console, and then the blue screen just disappeared. Here is the RootRepeal Log ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/08/25 13:01 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP2 ================================================== Drivers ——————- Name: 00000087 Image Path: \Driver\00000087 Address: 0x00000000 Size: 0 File Visible: No Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xF4C8F000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7D8C000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB8A0C000 Size: 49152 File Visible: No Signed: - Status: - Hidden/Locked Files ——————- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: C:\WINDOWS\system32\kbiwkmhxwbrntp.dat Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\kbiwkmjkcdeute.dat Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\kbiwkmpbndgglr.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\kbiwkmuaqpapqx.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmcpxdnyqerx.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmgjkadknoyc.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmgwsuppknsv.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmhjsthhaprv.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmidjitddygj.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmrnospjreqp.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\temp\kbiwkmxodavfpuqs.tmp Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\drivers\kbiwkmbphxtsrt.sys Status: Invisible to the Windows API! Stealth Objects ——————- Object: Hidden Module [Name: kbiwkmuaqpapqx.dll] Process: svchost.exe (PID: 824) Address: 0x10000000 Size: 53248 Object: Hidden Module [Name: kbiwkmpbndgglr.dll] Process: Explorer.EXE (PID: 1872) Address: 0x10000000 Size: 28672 Object: Hidden Module [Name: kbiwkmpbndgglr.dll] Process: firefox.exe (PID: 3988) Address: 0x10000000 Size: 28672 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CREATE] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLOSE] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_READ] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_WRITE] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_EA] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_EA] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SHUTDOWN] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_CLEANUP] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_SECURITY] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_SET_QUOTA] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: Ntfs, IRP_MJ_PNP] Process: System Address: 0x83f8dbf8 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_CREATE] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_CLOSE] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_POWER] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: dtscsi, IRP_MJ_PNP] Process: System Address: 0x83c31550 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CREATE] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_CLOSE] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_READ] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_WRITE] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SHUTDOWN] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_POWER] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Cdrom, IRP_MJ_PNP] Process: System Address: 0x83d82c50 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_CREATE] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_CLOSE] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_READ] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_WRITE] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_SHUTDOWN] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_POWER] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: Disk, IRP_MJ_PNP] Process: System Address: 0x83f8deb0 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_CREATE] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_CLOSE] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_READ] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_WRITE] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_SHUTDOWN] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_POWER] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: dmio, IRP_MJ_PNP] Process: System Address: 0x83fd8690 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CREATE] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_READ] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_WRITE] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SHUTDOWN] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_CLEANUP] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_POWER] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: Ftdisk, IRP_MJ_PNP] Process: System Address: 0x83fd8948 Size: 15 Object: Hidden Code [Driver: NetBT, IRP_MJ_CREATE] Process: System Address: 0x83cf5eb0 Size: 15 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLOSE] Process: System Address: 0x83cf5eb0 Size: 15 Object: Hidden Code [Driver: NetBT, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83cf5eb0 Size: 15 Object: Hidden Code [Driver: NetBT, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83cf5eb0 Size: 15 Object: Hidden Code [Driver: NetBT, IRP_MJ_CLEANUP] Process: System Address: 0x83cf5eb0 Size: 15 Object: Hidden Code [Driver: NetBT, IRP_MJ_PNP] Process: System Address: 0x83cf5eb0 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLOSE] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_READ] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_WRITE] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_EA] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_EA] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SHUTDOWN] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_CLEANUP] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_SECURITY] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_POWER] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: Rdbss, IRP_MJ_SET_QUOTA] Process: System Address: 0x83c5a0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLOSE] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_READ] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_WRITE] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_EA] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_EA] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_VOLUME_INFORMATION] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_INTERNAL_DEVICE_CONTROL] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SHUTDOWN] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CLEANUP] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_SECURITY] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_POWER] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SYSTEM_CONTROL] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_DEVICE_CHANGE] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_QUERY_QUOTA] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_SET_QUOTA] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: MRxSmb, IRP_MJ_PNP] Process: System Address: 0x83c3d0e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_CREATE] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_CREATE_NAMED_PIPE] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_CLOSE] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_READ] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_WRITE] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_FLUSH_BUFFERS] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_CLEANUP] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Npfsȅ扏煓ȁం扏楄ᯈ멀菉Ȃ瑎慆, IRP_MJ_SET_SECURITY] Process: System Address: 0x83c580e8 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_CREATE] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_CLOSE] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_READ] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_WRITE] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_CLEANUP] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_CREATE_MAILSLOT] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_QUERY_SECURITY] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Msfsȅః瑎て恀鉨뱂ᣂ<, IRP_MJ_SET_SECURITY] Process: System Address: 0x83e59a00 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_CREATE] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_CLOSE] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_READ] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_QUERY_INFORMATION] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_SET_INFORMATION] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_QUERY_VOLUME_INFORMATION] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_DIRECTORY_CONTROL] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_FILE_SYSTEM_CONTROL] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_DEVICE_CONTROL] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_SHUTDOWN] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_LOCK_CONTROL] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_CLEANUP] Process: System Address: 0x83c5c0e8 Size: 15 Object: Hidden Code [Driver: Cdfsȅ瑎潦ȁః瑎て䶀㼨镽࢒ê, IRP_MJ_PNP] Process: System Address: 0x83c5c0e8 Size: 15 Hidden Services ——————- Service Name: kbiwkmykwlvnms Image Path: C:\WINDOWS\system32\drivers\kbiwkmbphxtsrt.sys ==EOF==
My apologies. Please download this:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Please rename it to svchost.exe as you download it, and save it to your desktop. Please give that a go.

If you have the same problem as before, try clicking Start >> Run and entering:
"%userprofile%\Desktop\svchost.exe" /KillAll

Let me know if you are still having the problem with that.
Right, let's try shifting some of this Rootkit manually first.

1. Please download The Avenger2 by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All…"
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:

Drivers to delete:
kbiwkmykwlvnms

Files to delete:
C:\WINDOWS\system32\kbiwkmhxwbrntp.dat
C:\WINDOWS\system32\kbiwkmjkcdeute.dat
C:\WINDOWS\system32\kbiwkmpbndgglr.dll
C:\WINDOWS\system32\kbiwkmuaqpapqx.dll
C:\WINDOWS\temp\kbiwkmcpxdnyqerx.tmp
C:\WINDOWS\temp\kbiwkmgjkadknoyc.tmp
C:\WINDOWS\temp\kbiwkmgwsuppknsv.tmp
C:\WINDOWS\temp\kbiwkmhjsthhaprv.tmp
C:\WINDOWS\temp\kbiwkmidjitddygj.tmp
C:\WINDOWS\temp\kbiwkmrnospjreqp.tmp
C:\WINDOWS\temp\kbiwkmxodavfpuqs.tmp
C:\WINDOWS\system32\drivers\kbiwkmbphxtsrt.sys

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

3. Now, open the Avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.

Give ComboFix (the renamed one) another try after that.
Combofix is still not working. I notice that svchost automatically changes to combofix after i run it. Here is the avenger log:

Logfile of The Avenger Version 2.0, © by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.
No rootkits found!

Driver "kbiwkmykwlvnms" deleted successfully.

Error: could not delete file "C:\WINDOWS\system32\kbiwkmhxwbrntp.dat"
Deletion of file "C:\WINDOWS\system32\kbiwkmhxwbrntp.dat" failed!
Status: 0xc0000156


Error: could not delete file "C:\WINDOWS\system32\kbiwkmjkcdeute.dat"
Deletion of file "C:\WINDOWS\system32\kbiwkmjkcdeute.dat" failed!
Status: 0xc0000156


Error: could not delete file "C:\WINDOWS\system32\kbiwkmpbndgglr.dll"
Deletion of file "C:\WINDOWS\system32\kbiwkmpbndgglr.dll" failed!
Status: 0xc0000156


Error: could not delete file "C:\WINDOWS\system32\kbiwkmuaqpapqx.dll"
Deletion of file "C:\WINDOWS\system32\kbiwkmuaqpapqx.dll" failed!
Status: 0xc0000156


Error: file "C:\WINDOWS\temp\kbiwkmcpxdnyqerx.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmcpxdnyqerx.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\WINDOWS\temp\kbiwkmgjkadknoyc.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmgjkadknoyc.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\WINDOWS\temp\kbiwkmgwsuppknsv.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmgwsuppknsv.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\WINDOWS\temp\kbiwkmhjsthhaprv.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmhjsthhaprv.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\WINDOWS\temp\kbiwkmidjitddygj.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmidjitddygj.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\WINDOWS\temp\kbiwkmrnospjreqp.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmrnospjreqp.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: file "C:\WINDOWS\temp\kbiwkmxodavfpuqs.tmp" not found!
Deletion of file "C:\WINDOWS\temp\kbiwkmxodavfpuqs.tmp" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
–> the object does not exist


Error: could not delete file "C:\WINDOWS\system32\drivers\kbiwkmbphxtsrt.sys"
Deletion of file "C:\WINDOWS\system32\drivers\kbiwkmbphxtsrt.sys" failed!
Status: 0xc0000156


Completed script processing.

*******************

Finished! Terminate.
Is there a ComboFix or Combo-Fix? Please upload whichever is present. We need to find out what is stopping ComboFix from running, the developer is looking into it, but we need the data.
The only thing i've found is a combofix file and the icon is a computer desktop. Whenever i click on it, I get redirected to my computer. but the directory is C:\ComboFix. I've managed to zip it and am sending it to the page you told me.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI