This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Antispyware pro hijacked my computer

33 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
My computer has been hijacked! I keep getting a popup saying that my computer has been affected with a virus and then another window opens with a program called antispyware pro. I was unable to open any applications, and when I tried to open Internet Explorer, I'd get a message saying "this website may be harmful to you computer", it was trying to get me to purchase Antispyware pro. I was able to temporarly block it so I could run Malwarebytes and Hijack this. Here is my Malwarebytes log and my hijack this log, can somebody tell me how to get rid of this?? Thanks in advance!!!

Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 2

11/29/2009 4:56:11 PM
mbam-log-2009-11-29 (16-56-10).txt

Scan type: Quick Scan
Objects scanned: 103244
Time elapsed: 6 minute(s), 56 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:39:17 PM, on 11/29/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Electronic Arts\EA Downloader\Core.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [aqhmgeuy] C:\Documents and Settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSSoft\RSEDNClient.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EA Downloader\Core.exe -silent
O4 - HKCU\..\Run: [DNA] "C:\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [EPSON Stylus CX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S490.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [aqhmgeuy] C:\Documents and Settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe
O4 - HKUS\S-1-5-18\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q (User 'Default user')
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www1.snapfish.com/SnapfishActivia.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Unknown owner - C:\Program Files\Norton Internet Security\ISSVC.exe (file missing)
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - Unknown owner - C:\Program Files\Spyware Doctor\sdhelp.exe (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 13066 bytes
Hello smp182! Welcome to WTT.

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems. I'd be grateful if you would note the following:
  • Logs from malware removal programs (DDS is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • In Windows Vista and Windows 7, all tools need to be started by right clicking and selecting Run as Administrator!
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together ;)
    Because of this, you must reply within five days
    . I will post a reminder should you seem to fail to do this, however, if you fail to reply within five days then,
    unless I have been notified of your absence in advance, the topic shall be closed!
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I am checking over your log , I will post back shortly with instructions.
Hi Sweettech, Thank you so much for replying. I read and understand all the info you provided. I don't know if this matters or not, but I am running on Windows XP. Thanks!
Run exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Scanning with DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.
[external image: Posted Image]
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by doing the following:
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
Scanning with GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


Please make sure you include the following items in your next post:
1. The log that was produced after running exeHelper.
2. The logs that were produced after running DDS. (DDS.txt & Attach.txt)
3. The log that was produced after running GMER.
Hi SweetTech,
I ran the scans you instructed me to, here are the logs:

Exehelper

exeHelper by Raktor
Build 20091122
Run at 19:34:02exeHelper by Raktor
Build 20091122
Run at 19:35:23 on 11/29/09
Now searching…
Checking for numerical processes…
Checking for sysguard processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–



DDS.txt


DDS (Ver_09-11-29.01) - NTFSx86
Run by [removed] at 19:37:55.78 on Sun 11/29/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.149 [GMT -5:00]

AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\BitTorrent_DNA\dna.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
C:\WINDOWS\explorer.exe
G:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
mURLSearchHooks: H - No File
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: PCTools Site Guard: {5c8b2a36-3db1-42a4-a3cb-d426709bbfeb} - c:\progra~1\spywar~1\tools\iesdsg.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
BHO: CNisExtBho Class: {9ecb9560-04f9-4bbc-943d-298ddf1699e1} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
BHO: PCTools Browser Monitor: {b56a7d7d-6927-48c8-a975-17df180c71ac} - c:\progra~1\spywar~1\tools\iesdpb.dll
BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Norton Internet Security: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: AIM Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [Spyware Doctor] "c:\program files\spyware doctor\swdoctor.exe" /Q
uRun: [RssReader] c:\program files\rssreader\RssReader.exe
uRun: [Red Swoosh EDN Client] c:\program files\rssoft\RSEDNClient.exe
uRun: [EA Core] c:\program files\electronic arts\ea downloader\Core.exe -silent
uRun: [DNA] "c:\program files\bittorrent_dna\dna.exe"
uRun: [EPSON Stylus CX7400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticda.exe /fu "c:\windows\temp\E_S490.tmp" /EF "HKCU"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Aim6] "c:\program files\aim6\aim6.exe" /d locale=en-US ee://aol/imApp
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [aqhmgeuy] c:\documents and settings\sameer\local settings\application data\ngontc\brxcsysguard.exe
mRun: [IntelMeM] c:\program files\intel\modem event monitor\IntelMEM.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Symantec NetDriver Monitor] c:\progra~1\symnet~1\SNDMon.exe /Consumer
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe
mRun: [HPHmon04] c:\windows\system32\hphmon04.exe
mRun: [HPHUPD04] "c:\program files\hp photosmart 11\hphinstall\unipatch\hphupd04.exe"
mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [aqhmgeuy] c:\documents and settings\sameer\local settings\application data\ngontc\brxcsysguard.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
dRun: [Spyware Doctor] "c:\program files\spyware doctor\swdoctor.exe" /Q
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\americ~1.lnk - c:\program files\america online 9.0\aoltray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - c:\program files\winzip\WZQKPICK.EXE
uPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-us\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - {A1EDC4A1-940F-48E0-8DFD-E38F1D501021} - c:\progra~1\spywar~1\tools\iesdpb.dll
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: turbotax.com
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://download.macromedia.com/pub/shockwave/cabs/authorware/awswax70.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www1.snapfish.com/SnapfishActivia.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,
LSA: Notification Packages = scecli

============= SERVICES / DRIVERS ===============

R1 ikhfile;File Security Kernel Anti-Spyware Driver;c:\windows\system32\drivers\ikhfile.sys [2006-4-14 30688]
R1 ikhlayer;Kernel Anti-Spyware Driver;c:\windows\system32\drivers\ikhlayer.sys [2006-4-14 51456]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2006-10-10 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2007-2-27 32256]
R1 SAVRTPEL;SAVRTPEL;c:\program files\norton internet security\norton antivirus\SAVRTPEL.SYS [2005-3-15 53896]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCEVTMGR.EXE [2005-3-15 185704]
R2 ccProxy;Symantec Network Proxy;c:\program files\common files\symantec shared\CCPROXY.EXE [2005-3-15 239264]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSETMGR.EXE [2005-3-15 177512]
R2 navapsvc;Norton AntiVirus Auto-Protect Service;c:\program files\norton internet security\norton antivirus\NAVAPSVC.exe [2005-3-15 128160]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-11-14 24652]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20061213.022\NAVENG.Sys [2006-12-13 79240]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20061213.022\NavEx15.Sys [2006-12-13 831880]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2006-2-16 4096]
R3 SAVRT;SAVRT;c:\program files\norton internet security\norton antivirus\SAVRT.SYS [2005-3-15 334984]
S2 SBService;ScriptBlocking Service;c:\progra~1\common~1\symant~1\script~1\SBServ.exe [2005-3-11 67184]
S3 ccPwdSvc;Symantec Password Validation;c:\program files\common files\symantec shared\CCPWDSVC.EXE [2005-3-15 83304]
S3 SAVScan;SAVScan;c:\program files\norton internet security\norton antivirus\SAVSCAN.EXE [2005-3-15 198368]

============== File Associations ===============

scrfile="%1" %*

=============== Created Last 30 ================

2009-11-29 21:22:48 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 21:22:45 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 19:41:54 0 d—–w- c:\program files\Trend Micro

==================== Find3M ====================

2009-10-20 00:08:13 3063296 —-a-w- c:\windows\system32\dllcache\mshtml.dll
2009-09-18 09:56:10 18432 —-a-w- c:\windows\system32\dllcache\iedw.exe
2009-09-11 14:33:52 133632 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-11 14:33:52 133632 ——w- c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 20:45:26 58880 —-a-w- c:\windows\system32\msasn1.dll
2009-09-04 20:45:26 58880 ——w- c:\windows\system32\dllcache\msasn1.dll

============= FINISH: 19:38:35.51 ===============

Attach.txt - See below

📎Attach.txt


Gmer.txt

GMER 1.0.15.15252 - http://www.gmer.net
Rootkit scan 2009-11-29 19:49:56
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\Sameer\LOCALS~1\Temp\pxtdypoc.sys


—- System - GMER 1.0.15 —-

SSDT 82A24E08 ZwConnectPort

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Ntfs \Ntfs ikhfile.sys (PCTools Research Pty Ltd.)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-



Thanks!!!!
Peer to Peer Program
While reviewing your logs I noticed that you currently have Peer to Peer program(s) installed on your computer.

You currently have the following P2P programs installed:
  • Azureus Vuze
  • BitTorrent 6.0
  • LimeWire 5.1.3
Most of the infections that we see today are through P2P file sharing. By uninstalling the programs that I mentioned above you will be doing yourself a favor. It's impossible to trust the source of what is being downloaded from them and a file may or may not be what it appears to be.

Should you decide to keep these programs installed on your computer PLEASE do not use these programs while we are getting your P.C. cleaned up.

How to Uninstall the P2P Programs:

For Windows XP Users
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):
    Azureus Vuze
    BitTorrent 6.0
    LimeWire 5.1.3
PLEASE NOTE: When your uninstalling the P2P Program(s) some questions are worded in various ways to try and deceive you and keep you from uninstalling their Program.

Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
I just noticed the formatting of the attachment didn't look good. Here is my ComboFix log:

ComboFix 09-12-01.01 - Sameer 12/01/2009 22:26.3.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.140 [GMT -5:00]
Running from: H:\ComboFix.exe
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Sameer\Local Settings\Application Data\ngontc
c:\documents and settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe
c:\documents and settings\Sameer\My Documents\ZbThumbnail.info
c:\program files\RcvSystem
c:\windows\system32\Data
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe

c:\windows\system32\Drivers\atapi.sys . . . is infected!!

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_WSMSPSVC


((((((((((((((((((((((((( Files Created from 2009-11-02 to 2009-12-02 )))))))))))))))))))))))))))))))
.

2009-11-29 21:22 . 2009-09-10 19:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-29 21:22 . 2009-09-10 19:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-29 19:41 . 2009-11-29 19:41 ——– d—–w- c:\program files\Trend Micro
2009-11-26 15:19 . 2009-11-28 15:52 79488 —-a-w- c:\documents and settings\Sameer\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-02 03:18 . 2007-05-13 13:30 ——– d—–w- c:\documents and settings\Sameer\Application Data\DNA
2009-11-29 21:22 . 2008-03-18 02:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-11-29 18:26 . 2008-02-21 23:42 ——– d—–w- c:\program files\SUPERAntiSpyware
2009-11-29 14:08 . 2005-10-20 15:04 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-11-05 12:09 . 2007-11-18 16:28 ——– d—–w- c:\documents and settings\Sameer\Application Data\Azureus
2009-10-11 13:09 . 2009-05-05 19:53 ——– d—–w- c:\documents and settings\Sameer\Application Data\LimeWire
2009-09-25 05:56 . 2004-08-10 17:51 662016 —-a-w- c:\windows\system32\wininet.dll
2009-09-25 05:56 . 2004-08-10 17:51 81920 —-a-w- c:\windows\system32\ieencode.dll
2009-09-11 14:33 . 2009-05-21 00:39 133632 —-a-w- c:\windows\system32\msv1_0.dll
2009-09-07 17:35 . 2005-10-27 03:33 38472 -c–a-w- c:\documents and settings\Sameer\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-04 20:45 . 2004-08-10 17:51 58880 —-a-w- c:\windows\system32\msasn1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Red Swoosh EDN Client"="c:\program files\RSSoft\RSEDNClient.exe" [2006-04-19 117279]
"EA Core"="c:\program files\Electronic Arts\EA Downloader\Core.exe" [2006-08-16 1826816]
"DNA"="c:\program files\BitTorrent_DNA\dna.exe" [2007-05-13 216064]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 1318912]
"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-04 221184]
"CTSysVol"="c:\program files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe" [2003-09-17 57344]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-01-27 86016]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-01-08 49512]
"Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2008-02-16 100056]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-24 188416]
"HPHmon04"="c:\windows\system32\hphmon04.exe" [2002-06-20 339968]
"HPHUPD04"="c:\program files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe" [2002-05-24 49152]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-11-19 180269]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-29 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"P17Helper"="P17.dll" - c:\windows\system32\P17.dll [2004-06-10 60928]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
America Online 9.0 Tray Icon.lnk - c:\program files\America Online 9.0\aoltray.exe [2005-10-20 156784]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 806912]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2005-12-15 122880]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2007-04-19 18:41 294912 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitTorrent_DNA\\dna.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"9420:TCP"= 9420:TCP:Red Swoosh
"5000:UDP"= 5000:UDP:Red Swoosh

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [10/10/2006 1:53 PM 5632]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/27/2007 12:39 PM 32256]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/14/2008 8:44 PM 24652]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/16/2006 5:51 PM 4096]
.
Contents of the 'Scheduled Tasks' folder

2008-12-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 18:57]

2009-03-21 c:\windows\Tasks\Norton AntiVirus - Scan my computer - Sameer.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2005-03-15 19:47]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: &AOL Toolbar Search - c:\program files\aol\aim toolbar 5.0\resources\en-US\local\search.html
IE: &Search
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
Trusted Zone: turbotax.com
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Spyware Doctor - c:\program files\Spyware Doctor\swdoctor.exe
HKCU-Run-RssReader - c:\program files\RssReader\RssReader.exe
HKCU-Run-aqhmgeuy - c:\documents and settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe
HKLM-Run-ISUSScheduler - c:\program files\Common Files\InstallShield\UpdateService\issch.exe
HKLM-Run-aqhmgeuy - c:\documents and settings\Sameer\Local Settings\Application Data\ngontc\brxcsysguard.exe
HKU-Default-Run-Spyware Doctor - c:\program files\Spyware Doctor\swdoctor.exe
Notify-dimsntfy - (no file)
AddRemove-InstallShield_{218BBBE3-FE63-4BB2-81A8-7435575A84FA} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{28291BD5-92D2-4685-82DC-CCA925C53CCA} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{3D047C15-C859-45F7-81CE-F2681778069B} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{45EF4EE3-F591-4B74-A477-0CAE12934CE7} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{4C96958A-6562-4143-B820-FF4890D3B734} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{8AF1E098-1A5C-4336-BBE2-D047ABB401ED} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{91203BD3-6C3E-472F-ADBD-F60FDC7C4010} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{91F1A0D6-23AD-49FE-8D4E-379485652214} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-InstallShield_{C7281207-4AA4-425E-B57A-0E9EF8445635} - c:\program files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
AddRemove-kernel - c:\program files\kernel\kernel.exe
AddRemove-Router - c:\program files\Router\UnInstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-01 22:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3545857805-4264245001-2759532031-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(804)
c:\program files\SUPERAntiSpyware\SASWINLO.dll

- - - - - - - > 'explorer.exe'(7128)
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\progra~1\COMMON~1\AOL\ACS\AOLacsd.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTsvcCDA.EXE
c:\program files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
c:\windows\system32\Rundll32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\MsPMSPSv.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymWSC.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\program files\Common Files\Symantec Shared\Security Center\SymSCUI.exe
.
**************************************************************************
.
Completion time: 2009-12-01 23:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-02 04:04
ComboFix2.txt 2008-03-29 15:49
ComboFix3.txt 2008-03-27 01:27

Pre-Run: 93,093,220,352 bytes free
Post-Run: 94,175,100,928 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 9B31FD1D3DE3A7A9555BD44654995827
Before we continue, I feel the need to remind you of one of my rules that I have. I presented this rule: "Please make sure to carefully read any instruction that I give you. Reading too lightly will cause you to miss important steps, which could have destructive effects." to you in the very beginning. I can't not stress the importance of reading my instructions completely.

I noticed a few things that went wrong when running ComboFix. First thing was that ComboFix was running from an H: Drive. I asked you to download ComboFix to your desktop. According to the log it wasn't. I also asked you to disable any Security software and Norton was shown as being enabled. Many of the tools we use these days to remove malware are extremely powerfully and failure to follow the directions for how to use them properly can result in devastating results.

Please read the instructions fully and carefully before running the tools.

With that said let's continue:

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop itself, not within a folder on the desktop.
  • Go to Start > Run (Or you can hold down your Windows key and press R) and copy and paste the following into the text field. (make sure you include the quote marks) Then press OK.

    "%userprofile%\Desktop\TDSSKiller.exe" -l C:\TDSSKiller.txt -v
  • If it says "Hidden service detected" DO NOT type anything in. Just press Enter on your keyboard to not do anything to the file.
  • When it is done, a log file should be created on your C: drive called "TDSSKiller.txt" please copy and paste the contents of that file here.
SystemLook
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *atapi.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please make sure you include the following items in your next post:
1. The log that was produced after running TDSSKiller.
2. The log that was produced after running SystemLook.
3. An update on how your system is currently running.
HI SweetTech, First off, I apologize for not properly following your directions. Here are my two logs: 19:13:15:498 3204 ForceUnloadDriver: NtUnloadDriver error 2 19:13:15:498 3204 ForceUnloadDriver: NtUnloadDriver error 2 19:13:15:498 3204 ForceUnloadDriver: NtUnloadDriver error 2 19:13:15:530 3204 main: Driver KLMD successfully dropped 19:13:15:545 3204 main: Driver KLMD successfully loaded 19:13:15:545 3204 Scanning Registry … 19:13:15:545 3204 ScanServices: Searching service UACd.sys 19:13:15:545 3204 ScanServices: Open/Create key error 2 19:13:15:545 3204 ScanServices: Searching service TDSSserv.sys 19:13:15:545 3204 ScanServices: Open/Create key error 2 19:13:15:545 3204 ScanServices: Searching service gaopdxserv.sys 19:13:15:545 3204 ScanServices: Open/Create key error 2 19:13:15:545 3204 ScanServices: Searching service gxvxcserv.sys 19:13:15:545 3204 ScanServices: Open/Create key error 2 19:13:15:545 3204 ScanServices: Searching service MSIVXserv.sys 19:13:15:545 3204 ScanServices: Open/Create key error 2 19:13:15:545 3204 UnhookRegistry: Kernel module file name: C:\windows\system32\ntoskrnl.exe, base addr: 804D7000 19:13:15:545 3204 UnhookRegistry: Kernel local addr: A30000 19:13:15:545 3204 UnhookRegistry: KeServiceDescriptorTable addr: ABA500 19:13:15:545 3204 UnhookRegistry: KiServiceTable addr: A3D8B0 19:13:15:545 3204 UnhookRegistry: NtEnumerateKey service number (local): 47 19:13:15:545 3204 UnhookRegistry: NtEnumerateKey local addr: AD13A4 19:13:15:545 3204 KLMD_OpenDevice: Trying to open KLMD device 19:13:15:545 3204 KLMD_GetSystemRoutineAddressA: Trying to get system routine address ZwEnumerateKey 19:13:15:545 3204 KLMD_GetSystemRoutineAddressW: Trying to get system routine address ZwEnumerateKey 19:13:15:545 3204 KLMD_ReadMem: Trying to ReadMemory 0x804E380F[0x4] 19:13:15:545 3204 UnhookRegistry: NtEnumerateKey service number (kernel): 47 19:13:15:545 3204 KLMD_ReadMem: Trying to ReadMemory 0x804E49CC[0x4] 19:13:15:545 3204 UnhookRegistry: NtEnumerateKey real addr: 805783A4 19:13:15:545 3204 UnhookRegistry: NtEnumerateKey calc addr: 805783A4 19:13:15:545 3204 UnhookRegistry: No SDT hooks found on NtEnumerateKey 19:13:15:545 3204 KLMD_ReadMem: Trying to ReadMemory 0x805783A4[0xA] 19:13:15:545 3204 UnhookRegistry: No splicing found on NtEnumerateKey 19:13:15:545 3204 Scanning Kernel memory … 19:13:15:545 3204 KLMD_OpenDevice: Trying to open KLMD device 19:13:15:545 3204 KLMD_GetSystemObjectAddressByNameA: Trying to get system object address by name \Driver\Disk 19:13:15:545 3204 KLMD_GetSystemObjectAddressByNameW: Trying to get system object address by name \Driver\Disk 19:13:15:545 3204 DetectCureTDL3: \Driver\Disk PDRIVER_OBJECT: 82FD7910 19:13:15:545 3204 DetectCureTDL3: KLMD_GetDeviceObjectList returned 6 DevObjects 19:13:15:545 3204 DetectCureTDL3: 0 Curr stack PDEVICE_OBJECT: 81F7F030 19:13:15:545 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 81F7F030 19:13:15:545 3204 KLMD_ReadMem: Trying to ReadMemory 0x81F7F030[0x38] 19:13:15:545 3204 DetectCureTDL3: DRIVER_OBJECT addr: 82FD7910 19:13:15:545 3204 KLMD_ReadMem: Trying to ReadMemory 0x82FD7910[0xA8] 19:13:15:545 3204 KLMD_ReadMem: Trying to ReadMemory 0xE100F3D0[0x208] 19:13:15:545 3204 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk 19:13:15:545 3204 DetectCureTDL3: IrpHandler (0) addr: F863EC30 19:13:15:545 3204 DetectCureTDL3: IrpHandler (1) addr: 804F9709 19:13:15:545 3204 DetectCureTDL3: IrpHandler (2) addr: F863EC30 19:13:15:545 3204 DetectCureTDL3: IrpHandler (3) addr: F8638D9B 19:13:15:545 3204 DetectCureTDL3: IrpHandler (4) addr: F8638D9B 19:13:15:545 3204 DetectCureTDL3: IrpHandler (5) addr: 804F9709 19:13:15:545 3204 DetectCureTDL3: IrpHandler (6) addr: 804F9709 19:13:15:545 3204 DetectCureTDL3: IrpHandler (7) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (8) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (9) addr: F8639366 19:13:15:561 3204 DetectCureTDL3: IrpHandler (10) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (11) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (12) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (13) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (14) addr: F863944D 19:13:15:561 3204 DetectCureTDL3: IrpHandler (15) addr: F863CFC3 19:13:15:561 3204 DetectCureTDL3: IrpHandler (16) addr: F8639366 19:13:15:561 3204 DetectCureTDL3: IrpHandler (17) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (18) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (19) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (20) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (21) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (22) addr: F863AEF3 19:13:15:561 3204 DetectCureTDL3: IrpHandler (23) addr: F863FA24 19:13:15:561 3204 DetectCureTDL3: IrpHandler (24) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (25) addr: 804F9709 19:13:15:561 3204 DetectCureTDL3: IrpHandler (26) addr: 804F9709 19:13:15:561 3204 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:561 3204 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:592 3204 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 81F6D6C8 19:13:15:592 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 81F6D6C8 19:13:15:592 3204 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 82CED618 19:13:15:592 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82CED618 19:13:15:592 3204 DetectCureTDL3: 1 Curr stack PDEVICE_OBJECT: 82D75D08 19:13:15:592 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82D75D08 19:13:15:592 3204 KLMD_ReadMem: Trying to ReadMemory 0x82D75D08[0x38] 19:13:15:592 3204 DetectCureTDL3: DRIVER_OBJECT addr: 82C222C0 19:13:15:592 3204 KLMD_ReadMem: Trying to ReadMemory 0x82C222C0[0xA8] 19:13:15:592 3204 KLMD_ReadMem: Trying to ReadMemory 0xE1B45570[0x208] 19:13:15:592 3204 DetectCureTDL3: DRIVER_OBJECT name: \Driver\USBSTOR, Driver Name: USBSTOR 19:13:15:592 3204 DetectCureTDL3: IrpHandler (0) addr: F89D5218 19:13:15:592 3204 DetectCureTDL3: IrpHandler (1) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (2) addr: F89D5218 19:13:15:592 3204 DetectCureTDL3: IrpHandler (3) addr: F89D523C 19:13:15:592 3204 DetectCureTDL3: IrpHandler (4) addr: F89D523C 19:13:15:592 3204 DetectCureTDL3: IrpHandler (5) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (6) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (7) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (8) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (9) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (10) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (11) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (12) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (13) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (14) addr: F89D5180 19:13:15:592 3204 DetectCureTDL3: IrpHandler (15) addr: F89D09E6 19:13:15:592 3204 DetectCureTDL3: IrpHandler (16) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (17) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (18) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (19) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (20) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (21) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (22) addr: F89D45F0 19:13:15:592 3204 DetectCureTDL3: IrpHandler (23) addr: F89D2A6E 19:13:15:592 3204 DetectCureTDL3: IrpHandler (24) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (25) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (26) addr: 804F9709 19:13:15:592 3204 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\Drivers\USBSTOR.sys 19:13:15:592 3204 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\Drivers\USBSTOR.sys 19:13:15:592 3204 DetectCureTDL3: 2 Curr stack PDEVICE_OBJECT: 82F81C68 19:13:15:592 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F81C68 19:13:15:592 3204 KLMD_ReadMem: Trying to ReadMemory 0x82F81C68[0x38] 19:13:15:592 3204 DetectCureTDL3: DRIVER_OBJECT addr: 82FD7910 19:13:15:592 3204 KLMD_ReadMem: Trying to ReadMemory 0x82FD7910[0xA8] 19:13:15:592 3204 KLMD_ReadMem: Trying to ReadMemory 0xE100F3D0[0x208] 19:13:15:592 3204 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk 19:13:15:592 3204 DetectCureTDL3: IrpHandler (0) addr: F863EC30 19:13:15:592 3204 DetectCureTDL3: IrpHandler (1) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (2) addr: F863EC30 19:13:15:592 3204 DetectCureTDL3: IrpHandler (3) addr: F8638D9B 19:13:15:592 3204 DetectCureTDL3: IrpHandler (4) addr: F8638D9B 19:13:15:592 3204 DetectCureTDL3: IrpHandler (5) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (6) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (7) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (8) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (9) addr: F8639366 19:13:15:592 3204 DetectCureTDL3: IrpHandler (10) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (11) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (12) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (13) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (14) addr: F863944D 19:13:15:592 3204 DetectCureTDL3: IrpHandler (15) addr: F863CFC3 19:13:15:592 3204 DetectCureTDL3: IrpHandler (16) addr: F8639366 19:13:15:592 3204 DetectCureTDL3: IrpHandler (17) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (18) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (19) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (20) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (21) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (22) addr: F863AEF3 19:13:15:592 3204 DetectCureTDL3: IrpHandler (23) addr: F863FA24 19:13:15:592 3204 DetectCureTDL3: IrpHandler (24) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (25) addr: 804F9709 19:13:15:592 3204 DetectCureTDL3: IrpHandler (26) addr: 804F9709 19:13:15:592 3204 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:592 3204 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:608 3204 DetectCureTDL3: 3 Curr stack PDEVICE_OBJECT: 82F8FC68 19:13:15:608 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F8FC68 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0x82F8FC68[0x38] 19:13:15:608 3204 DetectCureTDL3: DRIVER_OBJECT addr: 82FD7910 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0x82FD7910[0xA8] 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0xE100F3D0[0x208] 19:13:15:608 3204 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk 19:13:15:608 3204 DetectCureTDL3: IrpHandler (0) addr: F863EC30 19:13:15:608 3204 DetectCureTDL3: IrpHandler (1) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (2) addr: F863EC30 19:13:15:608 3204 DetectCureTDL3: IrpHandler (3) addr: F8638D9B 19:13:15:608 3204 DetectCureTDL3: IrpHandler (4) addr: F8638D9B 19:13:15:608 3204 DetectCureTDL3: IrpHandler (5) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (6) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (7) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (8) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (9) addr: F8639366 19:13:15:608 3204 DetectCureTDL3: IrpHandler (10) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (11) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (12) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (13) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (14) addr: F863944D 19:13:15:608 3204 DetectCureTDL3: IrpHandler (15) addr: F863CFC3 19:13:15:608 3204 DetectCureTDL3: IrpHandler (16) addr: F8639366 19:13:15:608 3204 DetectCureTDL3: IrpHandler (17) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (18) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (19) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (20) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (21) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (22) addr: F863AEF3 19:13:15:608 3204 DetectCureTDL3: IrpHandler (23) addr: F863FA24 19:13:15:608 3204 DetectCureTDL3: IrpHandler (24) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (25) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (26) addr: 804F9709 19:13:15:608 3204 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:608 3204 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:608 3204 DetectCureTDL3: 4 Curr stack PDEVICE_OBJECT: 82F5EC68 19:13:15:608 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F5EC68 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0x82F5EC68[0x38] 19:13:15:608 3204 DetectCureTDL3: DRIVER_OBJECT addr: 82FD7910 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0x82FD7910[0xA8] 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0xE100F3D0[0x208] 19:13:15:608 3204 DetectCureTDL3: DRIVER_OBJECT name: \Driver\Disk, Driver Name: Disk 19:13:15:608 3204 DetectCureTDL3: IrpHandler (0) addr: F863EC30 19:13:15:608 3204 DetectCureTDL3: IrpHandler (1) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (2) addr: F863EC30 19:13:15:608 3204 DetectCureTDL3: IrpHandler (3) addr: F8638D9B 19:13:15:608 3204 DetectCureTDL3: IrpHandler (4) addr: F8638D9B 19:13:15:608 3204 DetectCureTDL3: IrpHandler (5) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (6) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (7) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (8) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (9) addr: F8639366 19:13:15:608 3204 DetectCureTDL3: IrpHandler (10) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (11) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (12) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (13) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (14) addr: F863944D 19:13:15:608 3204 DetectCureTDL3: IrpHandler (15) addr: F863CFC3 19:13:15:608 3204 DetectCureTDL3: IrpHandler (16) addr: F8639366 19:13:15:608 3204 DetectCureTDL3: IrpHandler (17) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (18) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (19) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (20) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (21) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (22) addr: F863AEF3 19:13:15:608 3204 DetectCureTDL3: IrpHandler (23) addr: F863FA24 19:13:15:608 3204 DetectCureTDL3: IrpHandler (24) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (25) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (26) addr: 804F9709 19:13:15:608 3204 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:608 3204 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\Drivers\Disk.sys 19:13:15:608 3204 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 82F90AB8 19:13:15:608 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82F90AB8 19:13:15:608 3204 DetectCureTDL3: 5 Curr stack PDEVICE_OBJECT: 82FCBD98 19:13:15:608 3204 KLMD_GetLowerDeviceObject: Trying to get lower device object for 82FCBD98 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0x82FCBD98[0x38] 19:13:15:608 3204 DetectCureTDL3: DRIVER_OBJECT addr: 82F94720 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0x82F94720[0xA8] 19:13:15:608 3204 KLMD_ReadMem: Trying to ReadMemory 0xE17B7528[0x208] 19:13:15:608 3204 DetectCureTDL3: DRIVER_OBJECT name: \Driver\atapi, Driver Name: atapi 19:13:15:608 3204 DetectCureTDL3: IrpHandler (0) addr: F856B572 19:13:15:608 3204 DetectCureTDL3: IrpHandler (1) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (2) addr: F856B572 19:13:15:608 3204 DetectCureTDL3: IrpHandler (3) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (4) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (5) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (6) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (7) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (8) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (9) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (10) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (11) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (12) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (13) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (14) addr: F856B592 19:13:15:608 3204 DetectCureTDL3: IrpHandler (15) addr: F85677B4 19:13:15:608 3204 DetectCureTDL3: IrpHandler (16) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (17) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (18) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (19) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (20) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (21) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (22) addr: F856B5BC 19:13:15:608 3204 DetectCureTDL3: IrpHandler (23) addr: F8572164 19:13:15:608 3204 DetectCureTDL3: IrpHandler (24) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (25) addr: 804F9709 19:13:15:608 3204 DetectCureTDL3: IrpHandler (26) addr: 804F9709 19:13:15:608 3204 TDL3_FileDetect: Processing driver file: C:\WINDOWS\system32\Drivers\atapi.sys 19:13:15:608 3204 KLMD_CreateFileW: Trying to open file C:\WINDOWS\system32\Drivers\atapi.sys 19:13:15:639 3204 Completed Results: 19:13:15:639 3204 Infected / Cured drivers in memory: 0 / 0 19:13:15:639 3204 Infected / Cured drivers on disk: 0 / 0 19:13:15:639 3204 Files deleted on next reboot: 0 19:13:15:639 3204 Registry nodes deleted on next reboot: 0 19:13:15:639 3204 SystemLook v1.0 by jpshortstuff (29.08.09) Log created at 19:15 on 03/12/2009 by Sameer (Administrator - Elevation successful) ========== filefind ========== Searching for "*atapi.sys" C:\i386\atapi.sys –a–c 95360 bytes [20:11 02/11/2005] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 C:\WINDOWS\erdnt\cache\atapi.sys –a— 95360 bytes [04:02 02/12/2009] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys –a— 96512 bytes [14:56 13/06/2009] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674 C:\WINDOWS\system32\drivers\atapi.sys —— 95360 bytes [00:39 21/05/2009] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys –a–c 95360 bytes [14:44 20/10/2005] [03:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 -=End Of File=- My system has been running really well, just as fast as before I was infected. Thanks.
ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::
FCopy::
C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = 
Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

Malwarebytes' Anti-Malware

I see that you have Malwarebytes' Anti-Malware installed on your computer could you please do a scan using these settings:

  • Open Malwarebytes' Anti-Malware
  • Select the Update tab
  • Click Check for Updates
  • After the update have been completed, Select the Scanner tab.
  • Select Perform quick scan, then click on Scan
  • Leave the default options as it is and click on Start Scan
  • When done, you will be prompted. Click OK, then click on Show Results
  • Checked (ticked) all items and click on Remove Selected
  • After it has removed the items, Notepad will open. Please post this log in your next reply. You can also find the log in the Logs tab. The bottom most log is the latest
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
1. The log that was produced after running ComboFix.
2. The log that was produced after running MalwareBytes' Anti-Malware.
3. The log that was produced after running the ESET Online Scanner.
4. An update on how your computer is currently running.
HI SweetTech, I disabled norton internet security and ran combofix. It was running fine, but then the screen went blue and I got this windows stop error message, asking me to restart my computer. I was able to restart, everything seems ok. I received this message saying that windows was able to recover, and it gave me an error report. Below is the error report: Error signature: BCCode : 10000050 BCP1 : F89312A4 BCP2 : 00000000 BCP3 : 804DDB57 BCP4 : 00000000 OSVer : 5_1_2600 SP : 2_0 Product : 768_1 THe following files will be included in this error report: C:\DOCUME~1\Sameer\LOCALS~1\Temp\WER3611.dir00\Mini120509-01.dmp C:\DOCUME~1\Sameer\LOCALS~1\Temp\WER3611.dir00\sysdata.xml Should I run combofix again?
Do you remember how far ComboFix got before you encounter the blue screen?

Batch File

Please do the following:

  • Go to Start->Run and type in notepad and hit OK.
  • Then copy and paste the content of the following codebox into Notepad:

    @echo off
    md c:\atapibak
    md C:\atapidll
    copy /y C:\WINDOWS\system32\drivers\atapi.sys c:\atapibak >log.txt
    copy /y C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys C:\atapidll >>log.txt
    copy /y C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys C:\ >>log.txt
    start log.txt
    del %0
  • Save the file to your DESKTOP as "copy.bat". Make sure to save it with the quotes.
  • Once saved, the icon to click should look like this on your desktop:

    [external image: Posted Image]
  • Double click copy.bat. to run it. A small black box should open and close - this is normal.
  • A text file (log.txt) should open. If you see that "one file(s) copied" 3 times is listed then please proceed with the next step. If you do not see "one file(s) copied" 3 times then do not proceed. Post back here and wait for further instructions.

Avenger
1. Please download The Avenger2 by Swandog46 to your Desktop.
  • Right click on the Avenger.zip folder and select "Extract All…"
  • Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):

Begin copying here:

Files to move:
C:\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys
c:\atapidll\atapi.sys | C:\WINDOWS\system32\dllcache\atapi.sys

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, open the avenger folder and start The Avenger program by clicking on its icon.
  • Right click on the window under Input script here:, and select Paste.
  • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V), or click on the third button under the menu to paste it from the clipboard.
  • Click on Execute
  • Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
  • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete" or "Drivers to Disable", The Avenger will actually restart your system twice.)
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.

SystemLook
  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *atapi.sys
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

Please make sure you include the following items in your next post:
1. The log that was produced after running the copy.bat.
2. The log that was produced after running Avenger.
3. The log that was produced after running SystemLook.
4. Any issues that you are still experiencing with your computer.
Hello smp182! It's been several days since I last posted instructions for you to complete. Do you still require assistance in getting your computer cleaned up? Thanks, SweetTech.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI