This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Windows Protection Suite Removal

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I had a similar problem 1 1/2 yrs ago that you helped fix. I think I got it again! Something called Windows Protection Suite is in my start up tray. It appears to have removed my anti virus program (Symantec) and Windows Defender. I downloaded a trial version of Kapersky that seems to be keeping the problem at bay, but the icon is always there in the start up tray and listed in "all programs". I delete the icons, but they always come back. Before I added Kapersky, the "protection" pop up kept coming up wanting me to buy an av program from them. How do I get rid of this thing?
Hi,

Please do the following:

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.

NEXT


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries



NEXT

We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
I am unable to run the dds.pif tool. When I dbl click it on my desktop and click run, nothing happens. Your instructions state "disable any script blocking" I have no idea what that means. Could that be why I can't get it to run? Sorry, I'm not very tech savvy.
Hi,

script blocking is usually part of your antivirus program.

Try this program instead.

Download OTS to your Desktop

  • Close ALL OTHER PROGRAMS.
  • Double-click on OTS.exe to start the program.
  • Check the box that says Scan All Users
  • Under Additional Scans check the following:
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 10)
    • Reg - File Associations
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please attach the log in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post



Also, did you have any luck getting the GMER program to run. If not try renaming it to MERG.com and run it in safe mode
Catbyte, I am trying to run the OTS.exe program as directed. It starts up fine, but after about 30 seconds, I get an error message in a box with the red X, stating "access violation at address 0053A269 in module 'OTS.exe". Read of address 00000000." I clicked the OK and hit run scan again. It ran for about 10 seconds, then I got another error box, same type of message with the number 00521A5C. I clicked OK, re started the scan, but it keeps stopping at that place with the same error box message.. If I don't hit the "run scan" after I click the OK, it just sits there doing nothing, with no evidence it is scanning anything (no fast running text in the lower left of the window.) Am I just not waiting long enough??? Is it really running, just very slow? Also, to answer your question: "Also, did you have any luck getting the GMER program to run. If not try renaming it to MERG.com and run it in safe mode" I did not try that since I assumed you wanted me to go in order of the instructions, and since the first step failed, I stopped and emailed you. John
It would appear the malware is preventing out tools from running.

Please try the GMER program in safe mode.

Then run this tool (if GMER will not run move on to the next step)

  • Please save Win32kdiag to your desktop.
  • Double-click on it to run a scan.
  • When it's finished, there will be a log called Win32kDiag.txt on your desktop.
  • Please open it with notepad and post the contents here.
Catbyte,

I could not get into safemode either by rapid pressing of F8 or holding it down during start up, so I ran gmer and the Root thing in regular mode. Along the way I got a couple error messages…one was "could not read the boot sector. Try adjusting the disk access level in the _______dialog.(Couldnt read my handwriting)

The othe error was: "Could not read system registry. Please contact the author."

Shown below is what I did get.


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/04 14:15
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
——————-
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\mom\LOCALS~1\Temp\aujasnkj.sys
Address: 0xB6FF7000 Size: 84352 File Visible: No Signed: -
Status: -

Name: dump_diskdump.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_diskdump.sys
Address: 0xF5DFB000 Size: 16384 File Visible: No Signed: -
Status: -

Name: dump_si3112r.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_si3112r.sys
Address: 0xBA515000 Size: 90112 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB748B000 Size: 49152 File Visible: No Signed: -
Status: -

SSDT
——————-
#: 011 Function Name: NtAdjustPrivilegesToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d136e

#: 025 Function Name: NtClose
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1a86

#: 031 Function Name: NtConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d260c

#: 035 Function Name: NtCreateEvent
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2b40

#: 037 Function Name: NtCreateFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1d78

#: 041 Function Name: NtCreateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0460

#: 043 Function Name: NtCreateMutant
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2a18

#: 044 Function Name: NtCreateNamedPipeFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7cfd0a

#: 046 Function Name: NtCreatePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d28d4

#: 050 Function Name: NtCreateSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1102

#: 051 Function Name: NtCreateSemaphore
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2c72

#: 052 Function Name: NtCreateSymbolicLinkObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d440e

#: 053 Function Name: NtCreateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1886

#: 056 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2976

#: 063 Function Name: NtDeleteKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0a20

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0cf8

#: 066 Function Name: NtDeviceIoControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d221c

#: 068 Function Name: NtDuplicateObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d4980

#: 071 Function Name: NtEnumerateKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0e3a

#: 073 Function Name: NtEnumerateValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0ee4

#: 084 Function Name: NtFsControlFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2016

#: 097 Function Name: NtLoadDriver
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d3ea6

#: 098 Function Name: NtLoadKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d043c

#: 099 Function Name: NtLoadKey2
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d044e

#: 111 Function Name: NtNotifyChangeKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1030

#: 114 Function Name: NtOpenEvent
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2be2

#: 116 Function Name: NtOpenFile
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1b08

#: 119 Function Name: NtOpenKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0604

#: 120 Function Name: NtOpenMutant
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2ab0

#: 122 Function Name: NtOpenProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d156e

#: 125 Function Name: NtOpenSection
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d4438

#: 126 Function Name: NtOpenSemaphore
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2d14

#: 128 Function Name: NtOpenThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1492

#: 160 Function Name: NtQueryKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0f8e

#: 161 Function Name: NtQueryMultipleValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0bb6

#: 177 Function Name: NtQueryValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d08bc

#: 180 Function Name: NtQueueApcThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d4128

#: 192 Function Name: NtRenameKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0b34

#: 193 Function Name: NtReplaceKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d00c2

#: 194 Function Name: NtReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d309e

#: 195 Function Name: NtReplyWaitReceivePort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2f64

#: 200 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d3c30

#: 204 Function Name: NtRestoreKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0224

#: 206 Function Name: NtResumeThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d4860

#: 207 Function Name: NtSaveKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7cfec4

#: 210 Function Name: NtSecureConnectPort
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d2312

#: 213 Function Name: NtSetContextThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d1984

#: 230 Function Name: NtSetInformationToken
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d35f2

#: 237 Function Name: NtSetSecurityObject
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d3fa0

#: 240 Function Name: NtSetSystemInformation
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d44c2

#: 247 Function Name: NtSetValueKey
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d0744

#: 253 Function Name: NtSuspendProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d45a6

#: 254 Function Name: NtSuspendThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d46d2

#: 255 Function Name: NtSystemDebugControl
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d3dd2

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d16ea

#: 258 Function Name: NtTerminateThread
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d163c

#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7d17c8

Shadow SSDT
——————-
#: 013 Function Name: NtGdiBitBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e132a

#: 227 Function Name: NtGdiMaskBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e13ee

#: 237 Function Name: NtGdiPlgBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e1454

#: 292 Function Name: NtGdiStretchBlt
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e138a

#: 307 Function Name: NtUserAttachThreadInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0ec4

#: 323 Function Name: NtUserCallOneParam
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e1242

#: 378 Function Name: NtUserFindWindowEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e10b2

#: 383 Function Name: NtUserGetAsyncKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0e2c

#: 414 Function Name: NtUserGetKeyboardState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e117a

#: 416 Function Name: NtUserGetKeyState
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0e78

#: 460 Function Name: NtUserMessageCall
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e1004

#: 475 Function Name: NtUserPostMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0f5a

#: 476 Function Name: NtUserPostThreadMessage
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0fae

#: 491 Function Name: NtUserRegisterRawInputDevices
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e110a

#: 502 Function Name: NtUserSendInput
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e1064

#: 549 Function Name: NtUserSetWindowsHookEx
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0d7c

#: 552 Function Name: NtUserSetWinEventHook
Status: Hooked by "C:\WINDOWS\system32\DRIVERS\klif.sys" at address 0xba7e0dd2

==EOF==


GMER 1.0.15.15077 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-09-04 14:11:32
Windows 5.1.2600 Service Pack 3


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwAdjustPrivilegesToken [0xBA7D136E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwClose [0xBA7D1A86]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwConnectPort [0xBA7D260C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateEvent [0xBA7D2B40]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateFile [0xBA7D1D78]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateKey [0xBA7D0460]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateMutant [0xBA7D2A18]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateNamedPipeFile [0xBA7CFD0A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreatePort [0xBA7D28D4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSection [0xBA7D1102]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSemaphore [0xBA7D2C72]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateSymbolicLinkObject [0xBA7D440E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateThread [0xBA7D1886]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwCreateWaitablePort [0xBA7D2976]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteKey [0xBA7D0A20]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeleteValueKey [0xBA7D0CF8]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDeviceIoControlFile [0xBA7D221C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwDuplicateObject [0xBA7D4980]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateKey [0xBA7D0E3A]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwEnumerateValueKey [0xBA7D0EE4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwFsControlFile [0xBA7D2016]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadDriver [0xBA7D3EA6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey [0xBA7D043C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwLoadKey2 [0xBA7D044E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwNotifyChangeKey [0xBA7D1030]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenEvent [0xBA7D2BE2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenFile [0xBA7D1B08]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenKey [0xBA7D0604]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenMutant [0xBA7D2AB0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenProcess [0xBA7D156E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSection [0xBA7D4438]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenSemaphore [0xBA7D2D14]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwOpenThread [0xBA7D1492]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryKey [0xBA7D0F8E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryMultipleValueKey [0xBA7D0BB6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueryValueKey [0xBA7D08BC]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwQueueApcThread [0xBA7D4128]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRenameKey [0xBA7D0B34]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplaceKey [0xBA7D00C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyPort [0xBA7D309E]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwReplyWaitReceivePort [0xBA7D2F64]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRequestWaitReplyPort [0xBA7D3C30]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwRestoreKey [0xBA7D0224]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwResumeThread [0xBA7D4860]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSaveKey [0xBA7CFEC4]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSecureConnectPort [0xBA7D2312]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetContextThread [0xBA7D1984]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetInformationToken [0xBA7D35F2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSecurityObject [0xBA7D3FA0]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetSystemInformation [0xBA7D44C2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSetValueKey [0xBA7D0744]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendProcess [0xBA7D45A6]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSuspendThread [0xBA7D46D2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwSystemDebugControl [0xBA7D3DD2]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateProcess [0xBA7D16EA]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwTerminateThread [0xBA7D163C]
SSDT \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) ZwWriteVirtualMemory [0xBA7D17C8]

Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \SystemRoot\system32\DRIVERS\klif.sys (Klif Mini-Filter [fre_wnet_x86]/Kaspersky Lab) IoIsOperationSynchronous

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{8B594502-4A75-10D1-C44F-72841608D094}\InprocServer32@ C:\WINDOWS\System32\mstime.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{8B594502-4A75-10D1-C44F-72841608D094}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{8B594502-4A75-10D1-C44F-72841608D094}\ProgID@ MSTIME.TIMEMotionAnimation.1
Reg HKLM\SOFTWARE\Classes\CLSID\{8B594502-4A75-10D1-C44F-72841608D094}\VersionIndependentProgID@ MSTIME.TIMEMotionAnimation

—- EOF - GMER 1.0.15 —-
Hi,


Have you been able to run the Win32KDiag program?


Next


Please download Process Explorer and save it to your desktop.
  • Rename Process Explorer to iexplore.exe.
  • To do this, right-click on the Procexp.exe and select Rename.
  • You can now edit the name of the file > name it to iexplorer.exe
  • Once it is renamed > double-click on the file to launch it.
  • In the "Process column" on the left > expand all the + signs beside the names of the various processes so ALL the trees are expanded.
  • Save a log file > go to File > save as
  • Save the file on your desktop > it will be named WrtProc.exe
  • Copy/paste the content of WrtProc.exe into your next reply
Catbyte, I did not attempt to run win32kdiag, given all the problems I was having running those last two. I will try to run it now and then will try to run Process Explorer. I'll send you what I get. John
Doesn't look like the Win32K thing worked…heres what I got: Log file is located at: C:\Documents and Settings\mom\Desktop\Win32kDiag.txt WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'… Cannot access: C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll [1] 2005-07-26 00:20:23 225792 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrv.dll (Microsoft Corporation) [1] 2008-04-13 20:11:50 226304 C:\WINDOWS\system32\catsrv.dll (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll [1] 2005-07-26 00:20:23 625152 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\catsrvut.dll (Microsoft Corporation) [1] 2005-07-26 00:39:43 625152 C:\WINDOWS\$NtServicePackUninstall$\catsrvut.dll (Microsoft Corporation) [1] 2003-03-31 08:00:00 582656 C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll () [1] 2004-08-04 03:56:41 628224 C:\WINDOWS\$NtUninstallKB902400$\catsrvut.dll (Microsoft Corporation) [1] 2008-04-13 20:11:50 625664 C:\WINDOWS\ServicePackFiles\i386\catsrvut.dll (Microsoft Corporation) [1] 2008-04-13 20:11:50 625664 C:\WINDOWS\system32\catsrvut.dll (Microsoft Corporation) Cannot access: C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll [1] 2005-07-26 00:20:23 110080 C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\clbcatex.dll (Microsoft Corporation) Here is the result of the Process Explorer exercise: Process PID CPU Description Company Name System Idle Process 0 95.38 Interrupts n/a 1.54 Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 smss.exe 920 Windows NT Session Manager Microsoft Corporation csrss.exe 1024 Client Server Runtime Process Microsoft Corporation winlogon.exe 1056 Windows NT Logon Application Microsoft Corporation services.exe 1104 Services and Controller app Microsoft Corporation ati2evxx.exe 1292 ATI External Event Utility EXE Module ATI Technologies Inc. svchost.exe 1316 Generic Host Process for Win32 Services Microsoft Corporation hpoevm08.exe 3272 HP OfficeJet COM Event Manager Hewlett-Packard Co. hposts08.exe 340 HP OfficeJet Status Hewlett-Packard Co. klwtblfs.exe 3888 WebToolBar component Kaspersky Lab svchost.exe 1424 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1552 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1596 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1796 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1972 Generic Host Process for Win32 Services Microsoft Corporation spoolsv.exe 232 Spooler SubSystem App Microsoft Corporation svchost.exe 552 Generic Host Process for Win32 Services Microsoft Corporation AppleMobileDeviceService.exe 660 Apple Mobile Device Service Apple Inc. avp.exe 700 mDNSResponder.exe 728 Bonjour Service Apple Inc. jqs.exe 844 Java™ Quick Starter Service Sun Microsystems, Inc. svchost.exe 3092 Generic Host Process for Win32 Services Microsoft Corporation iPodService.exe 3808 iPodService Module Apple Inc. HPZipm12.exe 2264 PML Driver HP alg.exe 1996 Application Layer Gateway Service Microsoft Corporation lsass.exe 1116 LSA Shell (Export Version) Microsoft Corporation ati2evxx.exe 1656 ATI External Event Utility EXE Module ATI Technologies Inc. explorer.exe 1028 Windows Explorer Microsoft Corporation iTunesHelper.exe 2064 iTunesHelper Module Apple Inc. RIMAutoUpdate.exe 2088 RIM Auto Update Research In Motion Limited pptd40nt.exe 2172 PaperPort Print to Desktop for NT Nuance Communications, Inc. BrMfcWnd.exe 2248 Brother Status Monitor MFC Application Brother Industries, Ltd. BrMfimon.exe 2436 Brother Status Monitor (Network) Brother Industries, Ltd. avp.exe 2272 jusched.exe 2300 Java™ Platform SE binary Sun Microsystems, Inc. TeaTimer.exe 2340 1.54 System settings protector Safer-Networking Ltd. GoogleToolbarNotifier.exe 2364 GoogleToolbarNotifier Google Inc. ctfmon.exe 2396 CTF Loader Microsoft Corporation hpotdd01.exe 2800 hpotdd01 Hewlett-Packard hposol08.exe 2888 HP OfficeJet COM Device Objects Hewlett-Packard Co. iexplore.exe 3624 Internet Explorer Microsoft Corporation svchost.exe 1120 svchost.exe 1560 ieexplorer.exe.exe 332 1.54 Sysinternals Process Explorer Sysinternals - www.sysinternals.com MOM.exe 2112 Catalyst Control Center: Monitoring program Advanced Micro Devices Inc. CCC.exe 2788 Catalyst Control Centre: Host application ATI Technologies Inc. BrccMCtl.exe 2308 Control Center 3 Main Program Brother Industries, Ltd. I am signing out for the night…will check back in the AM John
Hi,

Please try doing the following:

Download Combofix…save it to your desktop

before you save it - rename it to explorer.exe


Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to EXPLORER as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • The picture advises to rename to Combo-Fix…but you must rename yours to EXPLORER


———————————————————–

  • Double click on the renamed EXPLORER & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–


NOTE:If ComboFix asks to install the Recovery Console, please ALLOW it to do so.
Catbyte,

Here you go…the Combofix log:

ComboFix 09-09-04.02 - mom 2009-09-05 14:37.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.576 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\WINSPSys
c:\documents and settings\All Users\Application Data\WINSPSys\winps.cfg
c:\documents and settings\mom\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite.lnk
c:\documents and settings\mom\Application Data\Windows Protection Suite
C:\kmd.exe
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\recycler\S-1-5-21-3767295689-2469820063-725406000-500
c:\windows\BM333f20f1.txt
c:\windows\Installer\1be98d0.msi
c:\windows\Installer\1be98d7.msi
c:\windows\Installer\1be98de.msi
c:\windows\Installer\bf71a4.msi
c:\windows\Installer\e5ec7.msi

.
((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.

2009-09-05 18:44 . 2009-09-05 18:44 ——– d-sh–w- c:\documents and settings\mom\Application Data\Windows Protection Suite
2009-09-05 18:44 . 2009-09-05 18:46 ——– d-sh–w- c:\documents and settings\All Users\Application Data\WINSPSys
2009-09-04 18:13 . 2009-09-04 18:13 0 —-a-w- c:\documents and settings\mom\settings.dat
2009-08-27 19:12 . 2009-08-27 19:12 ——– d—–w- c:\documents and settings\mom\Application Data\ScanSoft
2009-08-24 20:24 . 2009-08-24 20:24 ——– d—–w- c:\documents and settings\mom\Application Data\Obsidium
2009-08-24 19:54 . 2009-08-24 19:54 ——– d—–w- c:\program files\MSECache
2009-08-24 00:40 . 2009-08-24 00:40 604140 –sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-08-24 00:38 . 2009-08-24 00:38 94643 —-a-w- c:\windows\system32\drivers\klick.dat
2009-08-24 00:38 . 2009-08-24 00:38 105395 —-a-w- c:\windows\system32\drivers\klin.dat
2009-08-24 00:37 . 2009-08-24 00:37 ——– d—–w- c:\program files\Kaspersky Lab
2009-08-24 00:28 . 2009-08-24 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-08-22 14:12 . 2009-09-05 18:45 ——– d-sh–w- c:\documents and settings\All Users\Application Data\5be0bd5
2009-08-15 20:01 . 2009-08-15 20:01 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-15 20:01 . 2009-08-15 20:01 ——– d—–w- c:\program files\MSBuild
2009-08-15 20:00 . 2009-08-15 20:00 ——– d—–w- c:\program files\Reference Assemblies
2009-08-15 20:00 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 20:00 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 20:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-15 20:00 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 20:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 20:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-15 20:00 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 20:00 . 2009-08-15 20:00 ——– d—–w- C:\07505760ec7a6afecf4b2d2a750a0271
2009-08-15 20:00 . 2009-08-16 18:17 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-15 17:39 . 2001-08-17 17:53 6784 -c–a-w- c:\windows\system32\dllcache\serscan.sys
2009-08-15 17:39 . 2001-08-17 17:53 6784 —-a-w- c:\windows\system32\drivers\serscan.sys
2009-08-15 17:39 . 2009-08-15 17:39 65 —-a-w- c:\windows\system32\bd7345n.dat
2009-08-15 17:37 . 2007-01-25 21:16 94208 ——w- c:\windows\system32\BrDctF2.dll
2009-08-15 17:37 . 2007-01-16 01:54 12288 ——w- c:\windows\system32\BrDctF2S.dll
2009-08-15 17:37 . 2007-01-15 20:09 12288 ——w- c:\windows\system32\BrDctF2L.dll
2009-08-15 17:37 . 2006-12-21 15:23 176128 —-a-w- c:\windows\system32\BROSNMP.DLL
2009-08-15 17:37 . 2008-01-26 00:36 63488 ——w- c:\windows\system32\BrNetSti.dll
2009-08-15 17:37 . 2007-10-15 23:06 58368 ——w- c:\windows\system32\BrWiaNCp.dll
2009-08-15 17:37 . 2007-10-15 23:06 41472 ——w- c:\windows\system32\Brnsplg.dll
2009-08-15 17:37 . 2009-08-15 17:37 ——– d—–w- C:\Brother
2009-08-15 17:37 . 2007-07-25 05:04 126976 ——w- c:\windows\system32\BrfxD05a.dll
2009-08-15 17:37 . 2003-11-28 22:57 0 —-a-w- c:\windows\brdfxspd.dat
2009-08-15 17:29 . 2009-08-15 17:29 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-08-15 17:29 . 2009-08-15 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-08-13 14:42 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-08 22:13 . 2009-08-08 22:13 ——– d—–r- c:\documents and settings\mom\Application Data\Brother
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\mom\Local Settings\Application Data\Scansoft
2009-08-08 20:53 . 2009-08-08 20:53 ——– d—–w- c:\program files\Nuance
2009-08-08 20:52 . 2009-08-08 20:52 ——– d—–w- c:\program files\ScanSoft
2009-08-08 20:51 . 2009-08-08 20:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 18:44 . 2008-02-26 01:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-09-05 18:13 . 2008-11-27 23:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-01 13:28 . 2005-05-04 05:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-31 20:24 . 2005-05-04 05:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-28 19:45 . 2008-07-29 01:14 ——– d—–w- c:\documents and settings\mom\Application Data\Apple Computer
2009-08-26 18:49 . 2005-05-11 03:17 ——– d—–w- c:\program files\Java
2009-08-25 13:26 . 2006-03-05 21:25 63392 —-a-w- c:\documents and settings\mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 20:23 . 2006-11-10 22:19 ——– d—–w- c:\program files\NetIntellGames
2009-08-24 00:32 . 2005-05-04 02:49 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-24 00:32 . 2008-01-30 02:52 ——– d—–w- c:\program files\Symantec
2009-08-24 00:32 . 2008-01-30 02:52 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-24 00:32 . 2005-05-04 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-15 17:37 . 2009-08-08 20:59 ——– d—–w- c:\program files\Brother
2009-08-15 17:37 . 2005-05-04 03:30 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2003-03-31 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 09:23 . 2008-11-27 02:53 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-18 18:28 . 2007-11-14 02:05 59040 —-a-w- c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 19:01 . 2003-03-31 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 07:56 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:33 . 2005-05-07 00:06 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-03 19:48 . 2009-07-03 19:48 219664 —-a-w- c:\windows\system32\klogon.dll
2009-07-03 19:45 . 2009-07-03 19:45 27507 —-a-w- c:\windows\system32\drivers\klopp.dat
2009-06-29 16:12 . 2005-02-18 20:19 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-03-31 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-16 21:06 . 2009-05-09 22:21 256 —-a-w- c:\windows\system32\pool.bin
2009-06-16 14:36 . 2003-03-31 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-03-31 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 18:01 . 2009-06-15 18:01 128016 —-a-w- c:\windows\system32\drivers\kl1.sys
2009-06-12 12:31 . 2003-03-31 12:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2003-03-31 12:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2003-03-31 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-05-04 02:33 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2003-03-31 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-22 19:41 . 2005-05-04 03:54 67696 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-06-22 19:41 . 2005-05-04 03:54 54376 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-06-22 19:41 . 2006-11-24 01:57 34952 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-06-22 19:41 . 2006-11-24 01:57 46720 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-06-22 19:41 . 2005-05-04 03:54 172144 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-27 39408]
"Windows Protection Suite"="c:\documents and settings\All Users\Application Data\5be0bd5\WI5be0.exe" [2009-08-22 2177536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-06-05 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-11-10 236016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-11-06 741376]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Brother\\Brmfl07b\\FAXRX.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\5be0bd5\\WI5be0.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"54925:UDP"= 54925:UDP:Brother Network Scanner

R0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808]
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [2004-07-01 89749]
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2004-07-01 9600]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-05-13 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-05-16 19472]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-03 33752]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCCFLTR.SYS [2005-05-03 13724]
S3 USBMON;USB Monitor Device Driver;c:\windows\system32\drivers\usbmon.sys [2002-06-24 162540]
S3 z520bus;Sony Ericsson 520 driver (WDM);c:\windows\system32\drivers\z520bus.sys [2005-07-26 57648]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;c:\windows\system32\drivers\z520mdfl.sys [2005-07-26 8336]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;c:\windows\system32\drivers\z520mdm.sys [2005-07-26 93488]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;c:\windows\system32\drivers\z520mgmt.sys [2005-07-26 84928]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\z520obex.sys [2005-07-26 82864]
.
Contents of the 'Scheduled Tasks' folder

2009-08-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2008-12-17 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2008-12-16 22:43]

2009-04-24 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p officejet 6100 series5E771253C1676EBED677BF361FDFC537825E15B8232469525.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 05:52]

2009-09-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-03 18:55]

2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1060284298-725345543-1006Core.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 01:59]

2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1060284298-725345543-1006UA.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 01:59]

2009-09-05 c:\windows\Tasks\User_Feed_Synchronization-{75A8A06E-8F5C-4394-A422-FF1FBEA51F04}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
Notify-NavLogon - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: 66.129.114.121
Trusted Zone: Realfast.com
Trusted Zone: Realfast2.com
Trusted Zone: Realfast2go.com
Trusted Zone: realtytools.com
Trusted Zone: toolkitcma.com
Trusted Zone: toolkitcma2.com
DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - hxxp://www.daviencrod.org/controls/LTOCX14N.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://triad.mlxtempo.com/5.0.05.46/Control/IRCSharc.cab
DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} - hxxp://www.daviencrod.org/controls/prntpro2.CAB
FF - ProfilePath - c:\documents and settings\mom\Application Data\Mozilla\Firefox\Profiles\1a6gcvcl.default\
FF - prefs.js: browser.startup.homepage - google.com/ig
FF - component: c:\progra~1\MOZILL~2\extensions\[removed]\components\KavLinkFilter.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-05 14:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1912)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP3\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Brother\ControlCenter3\BrccMCtl.exe
c:\program files\Brother\Brmfcmon\BrMfimon.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Completion time: 2009-09-05 14:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-05 18:49
ComboFix2.txt 2008-03-01 02:42

Pre-Run: 50,907,176,960 bytes free
Post-Run: 51,031,715,840 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

289 — E O F — 2009-09-02 00:19


Are we getting anywhere?

John
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Windows_Protection_Suite_Removal_t106666.html&view=findpost&p=593500#entry593500

Collect::
c:\documents and settings\All Users\Application Data\5be0bd5\WI5be0.exe

Folder::
c:\documents and settings\mom\Application Data\Windows Protection Suite
c:\documents and settings\All Users\Application Data\WINSPSys

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Protection Suite"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT



Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix log
  • MBAM Log
  • Kaspersky report
Catbyte,

Here are the firs two logs. I finished the Kapersky scan but couldnt find a bottom screen that looked like your example. When I started looking for it, I got away from and somehow lost the %&*^#@!! scan results! I will re-run the scan today and send it to you later.

Thanx,

John


combofix log

ComboFix 09-09-04.02 - mom 2009-09-05 14:37.4.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.576 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated) {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\WINSPSys
c:\documents and settings\All Users\Application Data\WINSPSys\winps.cfg
c:\documents and settings\mom\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Protection Suite.lnk
c:\documents and settings\mom\Application Data\Windows Protection Suite
C:\kmd.exe
c:\program files\Mozilla Firefox\searchplugins\search.xml
c:\recycler\S-1-5-21-3767295689-2469820063-725406000-500
c:\windows\BM333f20f1.txt
c:\windows\Installer\1be98d0.msi
c:\windows\Installer\1be98d7.msi
c:\windows\Installer\1be98de.msi
c:\windows\Installer\bf71a4.msi
c:\windows\Installer\e5ec7.msi

.
((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
.

2009-09-05 18:44 . 2009-09-05 18:44 ——– d-sh–w- c:\documents and settings\mom\Application Data\Windows Protection Suite
2009-09-05 18:44 . 2009-09-05 18:46 ——– d-sh–w- c:\documents and settings\All Users\Application Data\WINSPSys
2009-09-04 18:13 . 2009-09-04 18:13 0 —-a-w- c:\documents and settings\mom\settings.dat
2009-08-27 19:12 . 2009-08-27 19:12 ——– d—–w- c:\documents and settings\mom\Application Data\ScanSoft
2009-08-24 20:24 . 2009-08-24 20:24 ——– d—–w- c:\documents and settings\mom\Application Data\Obsidium
2009-08-24 19:54 . 2009-08-24 19:54 ——– d—–w- c:\program files\MSECache
2009-08-24 00:40 . 2009-08-24 00:40 604140 –sha-w- c:\windows\system32\drivers\ISwift3.dat
2009-08-24 00:38 . 2009-08-24 00:38 94643 —-a-w- c:\windows\system32\drivers\klick.dat
2009-08-24 00:38 . 2009-08-24 00:38 105395 —-a-w- c:\windows\system32\drivers\klin.dat
2009-08-24 00:37 . 2009-08-24 00:37 ——– d—–w- c:\program files\Kaspersky Lab
2009-08-24 00:28 . 2009-08-24 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-08-22 14:12 . 2009-09-05 18:45 ——– d-sh–w- c:\documents and settings\All Users\Application Data\5be0bd5
2009-08-15 20:01 . 2009-08-15 20:01 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-15 20:01 . 2009-08-15 20:01 ——– d—–w- c:\program files\MSBuild
2009-08-15 20:00 . 2009-08-15 20:00 ——– d—–w- c:\program files\Reference Assemblies
2009-08-15 20:00 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-15 20:00 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-15 20:00 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-15 20:00 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-15 20:00 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 20:00 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-15 20:00 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-15 20:00 . 2009-08-15 20:00 ——– d—–w- C:\07505760ec7a6afecf4b2d2a750a0271
2009-08-15 20:00 . 2009-08-16 18:17 ——– d—–w- c:\windows\SxsCaPendDel
2009-08-15 17:39 . 2001-08-17 17:53 6784 -c–a-w- c:\windows\system32\dllcache\serscan.sys
2009-08-15 17:39 . 2001-08-17 17:53 6784 —-a-w- c:\windows\system32\drivers\serscan.sys
2009-08-15 17:39 . 2009-08-15 17:39 65 —-a-w- c:\windows\system32\bd7345n.dat
2009-08-15 17:37 . 2007-01-25 21:16 94208 ——w- c:\windows\system32\BrDctF2.dll
2009-08-15 17:37 . 2007-01-16 01:54 12288 ——w- c:\windows\system32\BrDctF2S.dll
2009-08-15 17:37 . 2007-01-15 20:09 12288 ——w- c:\windows\system32\BrDctF2L.dll
2009-08-15 17:37 . 2006-12-21 15:23 176128 —-a-w- c:\windows\system32\BROSNMP.DLL
2009-08-15 17:37 . 2008-01-26 00:36 63488 ——w- c:\windows\system32\BrNetSti.dll
2009-08-15 17:37 . 2007-10-15 23:06 58368 ——w- c:\windows\system32\BrWiaNCp.dll
2009-08-15 17:37 . 2007-10-15 23:06 41472 ——w- c:\windows\system32\Brnsplg.dll
2009-08-15 17:37 . 2009-08-15 17:37 ——– d—–w- C:\Brother
2009-08-15 17:37 . 2007-07-25 05:04 126976 ——w- c:\windows\system32\BrfxD05a.dll
2009-08-15 17:37 . 2003-11-28 22:57 0 —-a-w- c:\windows\brdfxspd.dat
2009-08-15 17:29 . 2009-08-15 17:29 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2009-08-15 17:29 . 2009-08-15 17:30 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2009-08-13 14:42 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-08 22:13 . 2009-08-08 22:13 ——– d—–r- c:\documents and settings\mom\Application Data\Brother
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\mom\Local Settings\Application Data\Scansoft
2009-08-08 20:53 . 2009-08-08 20:53 ——– d—–w- c:\program files\Nuance
2009-08-08 20:52 . 2009-08-08 20:52 ——– d—–w- c:\program files\ScanSoft
2009-08-08 20:51 . 2009-08-08 20:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Brother

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-05 18:44 . 2008-02-26 01:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-09-05 18:13 . 2008-11-27 23:17 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2009-09-01 13:28 . 2005-05-04 05:15 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-08-31 20:24 . 2005-05-04 05:15 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-28 19:45 . 2008-07-29 01:14 ——– d—–w- c:\documents and settings\mom\Application Data\Apple Computer
2009-08-26 18:49 . 2005-05-11 03:17 ——– d—–w- c:\program files\Java
2009-08-25 13:26 . 2006-03-05 21:25 63392 —-a-w- c:\documents and settings\mom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-24 20:23 . 2006-11-10 22:19 ——– d—–w- c:\program files\NetIntellGames
2009-08-24 00:32 . 2005-05-04 02:49 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-08-24 00:32 . 2008-01-30 02:52 ——– d—–w- c:\program files\Symantec
2009-08-24 00:32 . 2008-01-30 02:52 ——– d—–w- c:\program files\Symantec AntiVirus
2009-08-24 00:32 . 2005-05-04 02:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-15 17:37 . 2009-08-08 20:59 ——– d—–w- c:\program files\Brother
2009-08-15 17:37 . 2005-05-04 03:30 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-05 09:01 . 2003-03-31 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 09:23 . 2008-11-27 02:53 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-07-18 18:28 . 2007-11-14 02:05 59040 —-a-w- c:\documents and settings\Dad\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-17 19:01 . 2003-03-31 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-14 03:43 . 2004-08-04 07:56 286208 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-09 17:33 . 2005-05-07 00:06 ——– d—–w- c:\program files\Common Files\Adobe
2009-07-03 19:48 . 2009-07-03 19:48 219664 —-a-w- c:\windows\system32\klogon.dll
2009-07-03 19:45 . 2009-07-03 19:45 27507 —-a-w- c:\windows\system32\drivers\klopp.dat
2009-06-29 16:12 . 2005-02-18 20:19 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2003-03-31 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2009-06-16 21:06 . 2009-05-09 22:21 256 —-a-w- c:\windows\system32\pool.bin
2009-06-16 14:36 . 2003-03-31 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2003-03-31 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-15 18:01 . 2009-06-15 18:01 128016 —-a-w- c:\windows\system32\drivers\kl1.sys
2009-06-12 12:31 . 2003-03-31 12:00 80896 —-a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2003-03-31 12:00 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2003-03-31 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2005-05-04 02:33 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2003-03-31 12:00 132096 —-a-w- c:\windows\system32\wkssvc.dll
2009-06-22 19:41 . 2005-05-04 03:54 67696 —-a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-06-22 19:41 . 2005-05-04 03:54 54376 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-06-22 19:41 . 2006-11-24 01:57 34952 —-a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-06-22 19:41 . 2006-11-24 01:57 46720 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-06-22 19:41 . 2005-05-04 03:54 172144 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-27 39408]
"Windows Protection Suite"="c:\documents and settings\All Users\Application Data\5be0bd5\WI5be0.exe" [2009-08-22 2177536]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-06-05 615696]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-11-10 236016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-10-11 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-10-11 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-11-06 741376]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-10-30 77824]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe" [2009-07-03 303376]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 39264]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@=""

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Brother\\Brmfl07b\\FAXRX.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\5be0bd5\\WI5be0.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"54925:UDP"= 54925:UDP:Brother Network Scanner

R0 BootScreen;BootScreen;\SystemRoot\\SystemRoot\System32\drivers\vidstub.sys –> \SystemRoot\\SystemRoot\System32\drivers\vidstub.sys [?]
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-12-15 33808]
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\drivers\SI3112r.sys [2004-07-01 89749]
R0 SiWinAcc;SiWinAcc;c:\windows\system32\drivers\SiWinAcc.sys [2004-07-01 9600]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2009-05-13 31760]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-05-16 19472]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-03 33752]
S3 LCcfltr;Logitech USB Filter Driver;c:\windows\system32\drivers\LCCFLTR.SYS [2005-05-03 13724]
S3 USBMON;USB Monitor Device Driver;c:\windows\system32\drivers\usbmon.sys [2002-06-24 162540]
S3 z520bus;Sony Ericsson 520 driver (WDM);c:\windows\system32\drivers\z520bus.sys [2005-07-26 57648]
S3 z520mdfl;Sony Ericsson 520 USB WMC Modem Filter;c:\windows\system32\drivers\z520mdfl.sys [2005-07-26 8336]
S3 z520mdm;Sony Ericsson 520 USB WMC Modem Drivers;c:\windows\system32\drivers\z520mdm.sys [2005-07-26 93488]
S3 z520mgmt;Sony Ericsson 520 USB WMC Device Management Drivers;c:\windows\system32\drivers\z520mgmt.sys [2005-07-26 84928]
S3 z520obex;Sony Ericsson 520 USB WMC OBEX Interface Drivers;c:\windows\system32\drivers\z520obex.sys [2005-07-26 82864]
.
Contents of the 'Scheduled Tasks' folder

2009-08-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2008-12-17 c:\windows\Tasks\DriverRobot.job
- c:\program files\Driver Robot\DriverRobot.exe [2008-12-16 22:43]

2009-04-24 c:\windows\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p officejet 6100 series5E771253C1676EBED677BF361FDFC537825E15B8232469525.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 05:52]

2009-09-05 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-03 18:55]

2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1060284298-725345543-1006Core.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 01:59]

2009-09-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-839522115-1060284298-725345543-1006UA.job
- c:\documents and settings\Dad\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-11-27 01:59]

2009-09-05 c:\windows\Tasks\User_Feed_Synchronization-{75A8A06E-8F5C-4394-A422-FF1FBEA51F04}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 23:36]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
Notify-NavLogon - (no file)


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/ig?hl=en
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: 66.129.114.121
Trusted Zone: Realfast.com
Trusted Zone: Realfast2.com
Trusted Zone: Realfast2go.com
Trusted Zone: realtytools.com
Trusted Zone: toolkitcma.com
Trusted Zone: toolkitcma2.com
DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - hxxp://www.daviencrod.org/controls/LTOCX14N.cab
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://triad.mlxtempo.com/5.0.05.46/Control/IRCSharc.cab
DPF: {9841D1AE-9C0B-11D3-9452-00105A098C21} - hxxp://www.daviencrod.org/controls/prntpro2.CAB
FF - ProfilePath - c:\documents and settings\mom\Application Data\Mozilla\Firefox\Profiles\1a6gcvcl.default\
FF - prefs.js: browser.startup.homepage - google.com/ig
FF - component: c:\progra~1\MOZILL~2\extensions\[removed]\components\KavLinkFilter.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-05 14:46
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1060)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(1912)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP3\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Brother\ControlCenter3\BrccMCtl.exe
c:\program files\Brother\Brmfcmon\BrMfimon.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposol08.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Completion time: 2009-09-05 14:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-05 18:49
ComboFix2.txt 2008-03-01 02:42

Pre-Run: 50,907,176,960 bytes free
Post-Run: 51,031,715,840 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn

289 — E O F — 2009-09-02 00:19

MBAM log:

Malwarebytes' Anti-Malware 1.40
Database version: 2745
Windows 5.1.2600 Service Pack 3

2009-09-05 16:11:41
mbam-log-2009-09-05 (16-11-41).txt

Scan type: Quick Scan
Objects scanned: 109243
Time elapsed: 4 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 5
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3ba4271e-5c1e-48e2-b432-d8bf420dd31d} (Rogue.DeusCleaner) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-19\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-20\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://search-gala.com/?&uid=157&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi, That was the same ComboFix log as before the script i gave you. can you please search for the latest log which resulted after the ComboFix script…it will be located here: C:\ComboFix folder and will have the latest date and time stamp. Could you also post a fresh DDS Log and Attach.txt along with the latest ComboFix log and Kaspersky report thanks ~CB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI