This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] GMER Crashes, Apps run CPU @ 50% but do nothing, Google Red

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Any help would be greatly appreciated. A brief history - got snagged into downloading a "software upgrade" to view a holiday greeting card earlier this month. The person it routed through notified me and I ran MBAM (after a reinstall - it was gone from my desktop) and cleaned out some stuff, but since then have had google redirects, some apps (Family Tree Maker, etc) never seem to load but are running the CPU at 50% per session running, etc.

I ran hijackthis (no fixes) before ending up at this site and started to work through "Are You Infected" topic.

I ran ATF Cleaner OK
SysRestorePoint "ran" but no screens displayed - I found it running continuously at 50% CPU until I stopped the process (Via CTR+ALT+DEL)
ERUNT run OK
GMER crashes several minutes into the scan and restarts my computer
MBAM run with latest update and shows clean as it has for 2 weeks or so.

Did not proceed any further until I got some more help!!!

FLWright

**********************Here is the MBAM log from 12-20*************************

Malwarebytes' Anti-Malware 1.42
Database version: 3396
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/20/2009 8:57:25 AM
mbam-log-2009-12-20 (08-57-25).txt

Scan type: Quick Scan
Objects scanned: 137860
Time elapsed: 9 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
C:\WINDOWS\system32\fimp.elo (Backdoor.Bot) -> Delete on reboot.

Registry Keys Infected:
HKEY_CLASSES_ROOT\idid (Trojan.Sasfix) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (Explorer.exe rundll32.exe fimp.elo pufxcp) Good: (Explorer.exe) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\fimp.elo (Backdoor.Bot) -> Delete on reboot.
C:\Documents and Settings\Koller Family\Local Settings\Temp\9DB.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.

************************ Here is MBAM Log today****************************

alwarebytes' Anti-Malware 1.43
Database version: 3485
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/3/2010 1:02:13 AM
mbam-log-2010-01-03 (01-02-13).txt

Scan type: Quick Scan
Objects scanned: 135434
Time elapsed: 6 minute(s), 59 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


****************************************************Hijack This Log from 1/2/2010*********************************************

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:28:15 PM, on 1/2/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\Stopzilla!\Toolbar\SZSG.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1244480103943
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DCS Loader (DCSLoader) - Oki Data Corporation - C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

–
End of file - 7059 bytes
Hi,

Please run the following program:

Please download DDS from LINK 1 or LINK 2
and save it to your desktop.

  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


Please try and rerun GMER:

McAfee will need to be totally disabled:

Open McAfee Security Centre
  • Under Common Tasks click on Home
  • Click Computer Files
  • Click Configure
  • Make sure the following are disabled by ticking the "Off" button.

    Virus protection
    Spyware protection
    System Guards Protection
    Script Scanning Protection (you may have to scroll down to see it)

  • Next, select never for "When to re-enable real time scanning"
  • and click OK.


If it still crashes, try running it in safe mode.
Here's the DDS logs below and a prescan log of GMER. 1st crash of GMER happened when a folder for Battlefield 1942 was open, so I moved the folder to the recycle bin and rescanned again. On the second scan, I forgot to turn off McAffee but the scan went a lot longer (hour or so) and then locked up (no reboot) after all the program files were scanned and it was in c:\tempEI4.

If you want, I will retry in safe mode

Thanks.

DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 10:39:59.23 on Sun 01/03/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3054.2385 [GMT -5:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Koller Family\My Documents\Downloads\dds.com

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll
mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll
BHO: ZILLAbar Browser Helper Object: {1827766b-9f49-4854-8034-f6ee26fcb1ec} - c:\program files\stopzilla!\toolbar\SZSG.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: STOPzilla: {98828ded-a591-462f-83ba-d2f62a68b8b8} - c:\program files\stopzilla!\toolbar\SZSG.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: []
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244480103943
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\koller~1\applic~1\mozilla\firefox\profiles\trf53vvv.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\stopzilla!\toolbar\extension\components\SiteGuardFF.dll
FF - plugin: c:\documents and settings\koller family\application data\mozilla\firefox\profiles\trf53vvv.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\koller family\application data\mozilla\firefox\profiles\trf53vvv.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-6-8 214664]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-6-8 359952]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-6-8 144704]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-6-8 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-8 79816]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-8 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-8 40552]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-9 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-12-20 38224]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-8 34248]

=============== Created Last 30 ================

2010-01-03 04:27:37 0 d—–w- c:\program files\Trend Micro
2009-12-30 09:15:54 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-26 16:37:19 1144 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-26 16:32:02 0 d—–w- c:\docume~1\alluse~1.win\applic~1\SITEguard
2009-12-26 16:31:10 0 d—–w- c:\program files\STOPzilla!
2009-12-26 16:31:07 0 d—–w- c:\program files\common files\iS3
2009-12-26 16:31:07 0 d—–w- c:\docume~1\alluse~1.win\applic~1\STOPzilla!
2009-12-24 04:12:52 0 d—–w- c:\program files\BCL Technologies
2009-12-20 13:41:04 0 d—–w- c:\docume~1\koller~1\applic~1\Malwarebytes
2009-12-20 13:40:59 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-20 13:40:57 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-20 13:40:57 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-20 13:40:57 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes
2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-09 21:01:15 139499 —-a-w- c:\windows\hpoins15.dat
2009-12-09 21:01:15 1039 ——w- c:\windows\hpomdl15.dat
2009-12-09 16:43:12 0 d—–w- c:\program files\common files\HP
2009-12-09 16:05:56 121329 ——w- c:\windows\hpoins15.dat.temp
2009-12-09 16:05:56 1037 ——w- c:\windows\hpomdl15.dat.temp

==================== Find3M ====================

2010-01-01 06:01:57 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2009-12-25 18:13:51 24892 —ha-w- c:\windows\system32\mlfcache.dat
2009-10-29 07:45:38 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 12:34:50 411368 —-a-w- c:\windows\system32\deploytk.dll

============= FINISH: 10:41:46.81 ===============



*************************************************************************Attach file**********************************************************************


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 6/8/2009 11:11:24 AM
System Uptime: 1/3/2010 2:25:03 AM (8 hours ago)

Motherboard: Intel Corporation | | DG965RY
Processor: Intel® Core™2 CPU 6300 @ 1.86GHz | | 1864/266mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 225 GiB total, 46.281 GiB free.
D: is FIXED (NTFS) - 466 GiB total, 189.509 GiB free.
E: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP143: 10/6/2009 1:23:04 AM - System Checkpoint
RP144: 10/7/2009 2:23:05 AM - System Checkpoint
RP145: 10/8/2009 3:18:08 PM - System Checkpoint
RP146: 10/9/2009 4:44:25 PM - System Checkpoint
RP147: 10/10/2009 5:20:06 PM - System Checkpoint
RP148: 10/11/2009 5:58:47 PM - System Checkpoint
RP149: 10/12/2009 8:34:45 AM - Installed Java™ 6 Update 16
RP150: 10/12/2009 2:46:56 PM - Software Distribution Service 3.0
RP151: 10/13/2009 3:46:11 PM - System Checkpoint
RP152: 10/14/2009 4:11:12 PM - System Checkpoint
RP153: 10/14/2009 10:34:11 PM - Software Distribution Service 3.0
RP154: 10/16/2009 7:40:22 AM - System Checkpoint
RP155: 10/17/2009 9:41:52 AM - System Checkpoint
RP156: 10/18/2009 9:44:47 AM - System Checkpoint
RP157: 10/19/2009 10:02:44 AM - System Checkpoint
RP158: 10/20/2009 11:43:11 AM - System Checkpoint
RP159: 10/21/2009 12:24:44 PM - System Checkpoint
RP160: 10/22/2009 12:29:53 PM - System Checkpoint
RP161: 10/23/2009 9:41:41 PM - System Checkpoint
RP162: 10/24/2009 10:35:38 PM - System Checkpoint
RP163: 10/26/2009 9:54:16 AM - System Checkpoint
RP164: 10/27/2009 10:12:45 AM - System Checkpoint
RP165: 10/28/2009 10:43:14 AM - System Checkpoint
RP166: 10/29/2009 11:21:50 AM - System Checkpoint
RP167: 10/29/2009 6:31:43 PM - Installed Compatibility Pack for the 2007 Office system
RP168: 10/30/2009 6:55:58 PM - System Checkpoint
RP169: 10/31/2009 7:23:12 PM - System Checkpoint
RP170: 11/1/2009 8:59:01 PM - System Checkpoint
RP171: 11/2/2009 9:00:28 PM - System Checkpoint
RP172: 11/3/2009 9:31:48 PM - System Checkpoint
RP173: 11/4/2009 10:41:57 PM - System Checkpoint
RP174: 11/5/2009 10:42:28 PM - System Checkpoint
RP175: 11/6/2009 1:19:46 AM - Software Distribution Service 3.0
RP176: 11/7/2009 1:24:57 AM - System Checkpoint
RP177: 11/8/2009 1:26:02 AM - System Checkpoint
RP178: 11/9/2009 7:40:49 AM - System Checkpoint
RP179: 11/10/2009 8:13:11 AM - System Checkpoint
RP180: 11/11/2009 1:18:37 AM - Software Distribution Service 3.0
RP181: 11/12/2009 8:12:24 AM - System Checkpoint
RP182: 11/13/2009 8:18:02 AM - System Checkpoint
RP183: 11/14/2009 9:37:13 AM - System Checkpoint
RP184: 11/15/2009 9:38:20 AM - System Checkpoint
RP185: 11/16/2009 10:30:09 AM - System Checkpoint
RP186: 11/17/2009 10:32:52 AM - System Checkpoint
RP187: 11/18/2009 11:47:41 AM - System Checkpoint
RP188: 11/19/2009 1:02:22 PM - System Checkpoint
RP189: 11/20/2009 4:15:26 PM - System Checkpoint
RP190: 11/21/2009 6:18:29 PM - System Checkpoint
RP191: 11/22/2009 11:28:09 PM - System Checkpoint
RP192: 11/24/2009 6:39:18 AM - System Checkpoint
RP193: 11/25/2009 6:39:41 AM - System Checkpoint
RP194: 11/26/2009 7:27:24 AM - System Checkpoint
RP195: 11/26/2009 9:19:47 AM - Software Distribution Service 3.0
RP196: 11/27/2009 3:50:33 PM - System Checkpoint
RP197: 11/28/2009 4:57:36 PM - System Checkpoint
RP198: 11/29/2009 5:34:20 PM - System Checkpoint
RP199: 11/30/2009 5:51:52 PM - System Checkpoint
RP200: 12/1/2009 6:48:47 PM - System Checkpoint
RP201: 12/2/2009 7:01:27 PM - System Checkpoint
RP202: 12/3/2009 7:28:04 PM - System Checkpoint
RP203: 12/4/2009 7:58:44 PM - System Checkpoint
RP204: 12/5/2009 8:46:26 PM - System Checkpoint
RP205: 12/6/2009 9:46:26 PM - System Checkpoint
RP206: 12/7/2009 9:51:46 PM - System Checkpoint
RP207: 12/8/2009 10:27:28 PM - System Checkpoint
RP208: 12/9/2009 11:44:47 AM - Installed HPSU306Stub
RP209: 12/9/2009 12:16:40 PM - Software Distribution Service 3.0
RP210: 12/10/2009 12:27:53 PM - System Checkpoint
RP211: 12/11/2009 12:59:00 PM - System Checkpoint
RP212: 12/12/2009 1:43:33 PM - System Checkpoint
RP213: 12/13/2009 5:15:35 PM - System Checkpoint
RP214: 12/14/2009 6:04:12 PM - System Checkpoint
RP215: 12/15/2009 6:54:15 PM - System Checkpoint
RP216: 12/16/2009 7:30:04 PM - System Checkpoint
RP217: 12/17/2009 8:15:44 PM - System Checkpoint
RP218: 12/18/2009 9:15:44 PM - System Checkpoint
RP219: 12/19/2009 9:17:55 PM - System Checkpoint
RP220: 12/20/2009 10:06:36 PM - System Checkpoint
RP221: 12/22/2009 8:11:03 AM - System Checkpoint
RP222: 12/23/2009 6:11:06 PM - System Checkpoint
RP223: 12/23/2009 11:08:46 PM - Configured Family Tree Maker 2009
RP224: 12/23/2009 11:09:13 PM - Configured Family Tree Maker 2009
RP225: 12/23/2009 11:12:17 PM - Installed Family Tree Maker 2009
RP226: 12/24/2009 11:46:53 PM - System Checkpoint
RP227: 12/26/2009 12:47:57 AM - System Checkpoint
RP228: 12/26/2009 11:31:00 AM - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP229: 12/26/2009 11:48:17 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
RP230: 12/27/2009 1:53:21 PM - System Checkpoint
RP231: 12/28/2009 2:47:35 PM - System Checkpoint
RP232: 12/29/2009 3:03:01 PM - System Checkpoint
RP233: 12/30/2009 4:21:17 PM - System Checkpoint
RP234: 12/31/2009 5:06:31 PM - System Checkpoint
RP235: 12/31/2009 6:56:38 PM - Installed Nancy Drew: The Creature of Kapu Cave
RP236: 1/1/2010 6:57:39 PM - System Checkpoint
RP237: 1/3/2010 2:40:24 AM - System Checkpoint

==== Installed Programs ======================

32 Bit HP CIO Components Installer
Acrobat.com
Adobe AIR
Adobe Flash Player 10 Plugin
Adobe Reader 9.1.3
AIO_Scan
Amazon MP3 Downloader 1.0.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Audacity 1.3.7 (Unicode)
AVS Update Manager 1.0
AVS Video Converter 6
AVS4YOU Software Navigator 1.3
Bonjour
BufferChm
Compatibility Pack for the 2007 Office system
Copy
Critical Update for Windows Media Player 11 (KB959772)
CustomerResearchQFolder
Desktop Doctor
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DocProc
DocProcQFolder
E.M. PowerPoint Video Converter 2.50
ERUNT 1.1j
eSupportQFolder
Exact Audio Copy 0.99pb5
Family Tree Maker 2009
Far Out Field Trips
GIMP 2.6.6
Google Earth
Google SketchUp 7
Google Update Helper
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
HP Customer Participation Program 9.0
HP Imaging Device Functions 9.0
HP OCR Software 9.0
HP Photosmart All-In-One Software 9.0
HP Photosmart Essential 2.01
HP Photosmart Essential2.01
HP Solution Center 9.0
HP Update
HPProductAssistant
HPSSupply
Intel Audio Studio 2.0
Intel® Active Client Manager 2.0 HECI Driver
Intel® PRO Network Connections
iS3 STOPzilla Toolbar
iTunes
Java™ 6 Update 16
LADSPA_plugins-win-0.4.15
LAME v3.98.2 for Audacity
LightScribe 1.4.89.1
Malwarebytes' Anti-Malware
MarketResearch
McAfee SecurityCenter
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Standard Edition 2003
Microsoft Primary Interoperability Assemblies 2005
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft WSE 3.0
Monopoly Junior
Mozilla Firefox (3.5.6)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
Mystery Club Gadget Games
Nancy Drew: Danger by Design
Nancy Drew: Danger on Deception Island
Nancy Drew: Legend of the Crystal Skull
Nancy Drew: Secret of the Scarlet Hand
Nancy Drew: The Creature of Kapu Cave
Nero Suite
Nikon Scan
NVIDIA Drivers
Pdf995
Picasa 3
PowerVideoMaker Professional 5.0
PS_AIO_Software
PS_AIO_Software_min
PSSWCORE
QuickTime
Scan
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969897)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SigmaTel Audio
SolutionCenter
Sonic & Knuckles Collection Documentation
Sonic & Knuckles Killer !
Sony DVD Architect Studio 4.5
Sony Sound Forge Audio Studio 9.0
Spelling Dictionaries Support For Adobe Reader 9
Status
Toolbox
TrayApp
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Vegas Movie Studio Platinum 9.0
VideoToolkit01
VST Bridge 1.1
Wave Repair 4.9.2
WebFldrs XP
WebReg
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
Zune Desktop Theme

==== Event Viewer Messages From Past Week ========

12/31/2009 7:00:00 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
12/31/2009 6:52:58 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service.
12/27/2009 7:12:55 AM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory.
12/27/2009 7:12:55 AM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.

==== End Of File ===========================





******************************************GMER Prescan Info********************************


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-01-03 10:55:59
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\KOLLER~1\LOCALS~1\Temp\pwldipog.sys


—- System - GMER 1.0.15 —-

Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateFile [0xB111678A]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateKey [0xB1116821]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcess [0xB1116738]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwCreateProcessEx [0xB111674C]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteKey [0xB1116835]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwDeleteValueKey [0xB1116861]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateKey [0xB11168CF]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwEnumerateValueKey [0xB11168B9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwMapViewOfSection [0xB11167CA]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwNotifyChangeKey [0xB11168FB]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenKey [0xB111680D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenProcess [0xB1116710]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwOpenThread [0xB1116724]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwProtectVirtualMemory [0xB111679E]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryKey [0xB1116937]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryMultipleValueKey [0xB11168A3]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwQueryValueKey [0xB111688D]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRenameKey [0xB111684B]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwReplaceKey [0xB1116923]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwRestoreKey [0xB111690F]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetContextThread [0xB1116776]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetInformationProcess [0xB1116762]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwSetValueKey [0xB1116877]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwTerminateProcess [0xB11167F9]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnloadKey [0xB11168E5]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwUnmapViewOfSection [0xB11167E0]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) ZwYieldExecution [0xB11167B4]
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtCreateFile
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtMapViewOfSection
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenProcess
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtOpenThread
Code \SystemRoot\system32\drivers\mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.) NtSetInformationProcess

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs mfehidk.sys (Host Intrusion Detection Link Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp Mpfp.sys (McAfee Personal Firewall Plus Driver/McAfee, Inc.)

Device -> \Driver\atapi \Device\Harddisk0\DR0 8A461618

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Make sure McAfee is totally disabled before running the next tool.

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
OK so I''m a little paranoid about what I download, so my plan was to have McAfee on to download the file and then turn it off and then run the program, which fit your line of "Make sure McAfee is totally disabled before running the next tool." I clicked on the first link and McAfee kicked in and says Artemis!9B230AC5B93A was detected and repaired (removed) so the download failed The second link is in spanish and did not go directly to something indicating ComboFix do you have other links for ComboFix or do you really want me to turn off McAfee before linking on the internet. FLWright
Turned off McAfee, downloaded ComboFix.exe to C:/Desktop double clicked to run from desktop It prompted to install recovery console, which I did. Got a blue window with some verbage about taking 10 minutes to scan computer, maybe longer if your system had lots of malware. computer shut down and restarted. McAffee still off nothing running. I could not find any new .txt files in c:/ or on the desktop Thanks for the help and I can better appreciate what goes into getting to the bottom of these issues.
Hi,

Do you recall a message about preparing a log once your machine rebooted? If not, the program probably did not complete properly.

Please use this method to disable McAfee

Open McAfee Security Centre
  • Under Common Tasks click on Home
  • Click Computer Files
  • Click Configure
  • Make sure the following are disabled by ticking the "Off" button.

    Virus protection
    Spyware protection
    System Guards Protection
    Script Scanning Protection (you may have to scroll down to see it)

  • Next, select never for "When to re-enable real time scanning"
  • and click OK.


Now delete the copy of ComboFix from your desktop and download a fresh copy, close all programs including this one and run Combofix again, allow it to run uninterrupted. Give it at least 20 minutes longer than you think it should take.

See if it produces a log for you this time:

Link 1
Thanks so much for your patience! I did do one other thing recommended at another forum but don't know if it had any effect. I renamed Combofix.exe upon download to Combo-fix.exe. Anyway, it ran fine, no reboots.

Yes, here is the combofix.txt log and I'm glad you can read it

ComboFix 10-01-03.03 - Koller Family 01/03/2010 23:41:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3054.2550 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Koller Family\Application Data\Desktopicon
c:\documents and settings\Koller Family\Application Data\Desktopicon\config.ini
c:\recycler\S-1-5-21-1801674531-515967899-725345543-1004
c:\windows\system32\AutoRun.inf

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :P
.
((((((((((((((((((((((((( Files Created from 2009-12-04 to 2010-01-04 )))))))))))))))))))))))))))))))
.

2010-01-03 05:34 . 2010-01-03 05:34 5061520 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-03 05:31 . 2010-01-03 05:31 ——– d—–w- c:\program files\ERUNT
2010-01-03 04:27 . 2010-01-03 04:27 ——– d—–w- c:\program files\Trend Micro
2010-01-02 00:34 . 2010-01-02 00:34 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-12-30 09:15 . 2010-01-02 00:34 664 —-a-w- c:\windows\system32\d3d9caps.dat
2009-12-26 16:32 . 2009-12-26 16:32 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\SITEguard
2009-12-26 16:31 . 2009-12-26 16:48 ——– d—–w- c:\program files\STOPzilla!
2009-12-26 16:31 . 2009-12-26 16:40 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\STOPzilla!
2009-12-26 16:31 . 2009-12-26 16:31 ——– d—–w- c:\program files\Common Files\iS3
2009-12-24 04:12 . 2009-12-24 04:14 ——– d—–w- c:\program files\BCL Technologies
2009-12-20 13:41 . 2009-12-20 13:41 ——– d—–w- c:\documents and settings\Koller Family\Application Data\Malwarebytes
2009-12-20 13:40 . 2009-12-30 19:55 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-20 13:40 . 2010-01-03 05:35 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-20 13:40 . 2009-12-30 19:54 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-20 13:40 . 2009-12-20 13:40 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-12-20 01:46 . 2009-12-20 01:46 ——– d-sh–w- c:\documents and settings\LocalService.NT AUTHORITY\IETldCache
2009-12-14 19:15 . 2009-12-14 19:15 2146304 —-a-w- c:\windows\system32\GPhotos.scr
2009-12-09 21:02 . 2009-12-09 21:02 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP Product Assistant
2009-12-09 21:01 . 2009-12-09 21:04 139499 —-a-w- c:\windows\hpoins15.dat
2009-12-09 21:01 . 2007-09-21 12:46 1039 ——w- c:\windows\hpomdl15.dat
2009-12-09 17:53 . 2009-12-09 17:53 ——– d—–w- c:\documents and settings\Koller Family\Application Data\HP
2009-12-09 16:44 . 2009-12-09 16:44 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HPSSUPPLY
2009-12-09 16:43 . 2009-12-09 20:50 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\HP
2009-12-09 16:43 . 2009-12-09 16:43 ——– d—–w- c:\program files\Common Files\HP

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-03 16:16 . 2006-12-27 00:34 ——– d—–w- c:\program files\EA GAMES
2010-01-01 06:01 . 2006-02-28 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-01-01 06:01 . 2006-02-28 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.svs
2009-12-28 19:21 . 2009-06-10 23:40 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2009-12-26 16:38 . 2009-12-26 16:37 1144 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg
2009-12-25 18:13 . 2009-06-10 21:11 24892 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-25 16:49 . 2007-06-11 15:32 ——– d—–w- c:\program files\Nancy Drew
2009-12-24 04:14 . 2009-09-23 22:13 ——– d—–w- c:\program files\Family Tree Maker 2009
2009-12-19 02:38 . 2009-06-10 21:05 ——– d—–w- c:\program files\Google
2009-12-09 16:44 . 2009-07-15 12:50 ——– d—–w- c:\program files\HP
2009-11-24 18:52 . 2009-06-10 23:43 ——– d—–w- c:\documents and settings\Koller Family\Application Data\Apple Computer
2009-11-24 14:31 . 2009-11-24 14:30 ——– d—–w- c:\program files\iTunes
2009-11-24 14:31 . 2009-11-24 14:30 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-11-24 14:30 . 2009-11-24 14:30 ——– d—–w- c:\program files\iPod
2009-11-24 14:29 . 2009-11-24 14:28 ——– d—–w- c:\program files\QuickTime
2009-11-24 14:27 . 2008-08-29 01:28 ——– d—–w- c:\program files\Common Files\Apple
2009-11-24 14:24 . 2009-11-24 14:24 79144 —-a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-19 11:49 . 2006-12-26 17:58 ——– d—–w- c:\program files\McAfee
2009-11-15 18:31 . 2009-06-08 16:44 24160 —-a-w- c:\documents and settings\Koller Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-15 12:01 . 2009-11-15 12:01 ——– d—–w- c:\program files\E.M. PowerPoint Video Converter
2009-11-14 20:11 . 2009-11-14 16:17 ——– d—–w- c:\program files\JumpStart
2009-11-14 16:19 . 2009-11-14 16:17 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\Knowledge Adventure
2009-11-14 16:18 . 2008-11-02 19:50 ——– d—–w- c:\program files\Common Files\Knowledge Adventure
2009-11-10 12:12 . 2009-11-10 12:12 ——– d—–w- c:\program files\Presentersoft PowerVideoMaker
2009-11-10 11:50 . 2009-11-10 11:50 ——– d—–w- c:\documents and settings\Koller Family\Application Data\AVS4YOU
2009-11-10 11:50 . 2009-11-10 11:50 ——– d—–w- c:\documents and settings\All Users.WINDOWS\Application Data\AVS4YOU
2009-11-10 11:50 . 2009-11-10 11:49 ——– d—–w- c:\program files\AVS4YOU
2009-11-10 11:50 . 2009-11-10 11:49 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-11-09 02:23 . 2009-11-09 02:23 ——– d—–w- c:\documents and settings\Koller Family\Application Data\Amazon
2009-11-09 02:22 . 2009-11-09 02:22 ——– d—–w- c:\program files\Amazon
2009-10-29 07:45 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2006-02-28 12:00 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2006-02-28 12:00 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2006-02-28 12:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2006-02-28 12:00 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2006-02-28 12:00 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2006-02-28 12:00 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-12 12:34 . 2009-10-12 12:35 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-10-12 12:34 . 2009-10-12 12:34 152576 —-a-w- c:\documents and settings\Koller Family\Application Data\Sun\Java\jre1.6.0_16\lzma.dll
2007-04-20 22:01 . 2007-03-19 03:02 133120 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2009-04-13 15:02 . 2009-04-13 15:02 27976 —-a-w- c:\program files\mozilla firefox\plugins\atgpcdec.dll
2009-04-13 15:02 . 2009-04-13 15:02 125848 —-a-w- c:\program files\mozilla firefox\plugins\atgpcext.dll
2009-04-13 15:02 . 2009-04-13 15:02 46408 —-a-w- c:\program files\mozilla firefox\plugins\atmccli.dll
2009-04-13 15:02 . 2009-04-13 15:02 98712 —-a-w- c:\program files\mozilla firefox\plugins\ieatgpc.dll
2008-02-28 18:30 . 2008-05-09 17:29 8784 —-a-w- c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2008-02-28 18:33 . 2008-05-09 17:29 245408 —-a-w- c:\program files\mozilla firefox\plugins\unicows.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-12 149280]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-18 7561216]

c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/9/2009 8:27 PM 133104]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder

2009-12-29 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 01:27]

2010-01-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-10 01:27]

2009-12-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-08 16:22]

2010-01-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-06-08 16:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Koller Family\Application Data\Mozilla\Firefox\Profiles\trf53vvv.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\program files\Stopzilla!\Toolbar\Extension\components\SiteGuardFF.dll
FF - plugin: c:\documents and settings\Koller Family\Application Data\Mozilla\Firefox\Profiles\trf53vvv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\Koller Family\Application Data\Mozilla\Firefox\Profiles\trf53vvv.default\extensions\[removed]\plugins\npImgCtl.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npRACtrl.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-03 23:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-01-03 23:49:38
ComboFix-quarantined-files.txt 2010-01-04 04:49

Pre-Run: 53,584,613,376 bytes free
Post-Run: 56,980,754,432 bytes free

- - End Of File - - A5CDCBE35E58EE4927A325F4069A9E75
Hi,

Please do the following:


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • MBAM Log
  • Kaspersky report
Here they are. ********************************MBAM Log*********************************** Malwarebytes' Anti-Malware 1.43 Database version: 3491 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 1/4/2010 8:07:20 AM mbam-log-2010-01-04 (08-07-20).txt Scan type: Quick Scan Objects scanned: 135613 Time elapsed: 6 minute(s), 4 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ****************************************Kaspersky report************************************ KASPERSKY ONLINE SCANNER 7.0: scan report Monday, January 4, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, January 04, 2010 20:03:47 Records in database: 3355455 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 176302 Threats found: 3 Infected objects found: 8 Suspicious objects found: 0 Scan duration: 03:06:55 File name / Threat / Threats count C:\Documents and Settings\Koller Family\My Documents\Dads Files\Outlook\Outlook\Pre 2000 Outlook.pst Infected: Virus.MSExcel.Tracker-based 1 C:\Documents and Settings\Koller Family\My Documents\Dads Files\Outlook\Outlook Files\By Category.pst Infected: Virus.MSExcel.Tracker-based 1 C:\Documents and Settings\Koller Family\My Documents\Dads Files\Outlook\Outlook Files\Pre 2000 Outlook.pst Infected: Virus.MSExcel.Tracker-based 1 C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1 C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\cache\6.0\3\12a49b83-543b4efa Infected: Trojan-Downloader.Java.OpenStream.ad 1 D:\Backup\Weekly\Hercules Documents\Dads Files\Backup work files\Backup 022709\Flash Drive\Work\Outlook\Pre 2000 Outlook.pst Infected: Virus.MSExcel.Tracker-based 1 D:\Backup\Weekly\Hercules Documents\Dads Files\Outlook\Outlook Files\By Category.pst Infected: Virus.MSExcel.Tracker-based 1 D:\Backup\Weekly\Hercules Documents\Dads Files\Outlook\Outlook Files\Pre 2000 Outlook.pst Infected: Virus.MSExcel.Tracker-based 1 Selected area has been scanned. ******************************************************************************** ********************************************************************
Hi, The items found by Kaspersky are in Outlook and Outlook backups Unfortunately it cannot identify which particular emails are infected, so you will have to use your best judgment in removing any emails from anyone you don't know or that contain attachments, such as jokes, videos etc. Please post a fresh DDS and Attach.txt and advise how your computer is running now and if there are any outstanding issues.
Thanks so much for getting my computer back from evil people who write stuff like this. I copied the two Outlook files to a CD and shift+deleted the 6 copies on my hard drive. They are old files and I will not open them unless I have the time to locate suspect files and delete. That would just leave the following: C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1 C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\cache\6.0\3\12a49b83-543b4efa Infected: Trojan-Downloader.Java.OpenStream.ad 1 Here are the logs you requested, and thanks so much for your help. DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 23:07:30.04 on Mon 01/04/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_16 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3054.2149 [GMT -5:00] AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE C:\WINDOWS\system32\svchost.exe -k hpdevmgmt C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\McAfee\MPF\MPFSrv.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k HPZ12 C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\iPod\bin\iPodService.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre6\bin\java.exe C:\Documents and Settings\Koller Family\My Documents\Downloads\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uDefault_Search_URL = hxxp://www.google.com/ie uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = *.local uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll mURLSearchHooks: SrchHook Class: {d3f669eb-57ce-4f45-8fbd-e245cbb46366} - c:\program files\stopzilla!\toolbar\SZIESearchHook.dll BHO: ZILLAbar Browser Helper Object: {1827766b-9f49-4854-8034-f6ee26fcb1ec} - c:\program files\stopzilla!\toolbar\SZSG.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: STOPzilla: {98828ded-a591-462f-83ba-d2f62a68b8b8} - c:\program files\stopzilla!\toolbar\SZSG.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244480103943 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\koller~1\applic~1\mozilla\firefox\profiles\trf53vvv.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - component: c:\program files\stopzilla!\toolbar\extension\components\SiteGuardFF.dll FF - plugin: c:\documents and settings\koller family\application data\mozilla\firefox\profiles\trf53vvv.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll FF - plugin: c:\documents and settings\koller family\application data\mozilla\firefox\profiles\trf53vvv.default\extensions\[removed]\plugins\npImgCtl.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npatgpc.dll FF - plugin: c:\program files\mozilla firefox\plugins\npRACtrl.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2009-6-8 214664] R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2009-6-8 359952] R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2009-6-8 144704] R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2009-6-8 79816] R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2009-6-8 35272] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-9 133104] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2009-6-8 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2009-6-8 40552] S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2009-6-8 606736] =============== Created Last 30 ================ 2010-01-03 23:52:54 0 d-sha-r- C:\cmdcons 2010-01-03 23:50:13 98816 —-a-w- c:\windows\sed.exe 2010-01-03 23:50:13 77312 —-a-w- c:\windows\MBR.exe 2010-01-03 23:50:13 261632 —-a-w- c:\windows\PEV.exe 2010-01-03 23:50:13 161792 —-a-w- c:\windows\SWREG.exe 2010-01-03 04:27:37 0 d—–w- c:\program files\Trend Micro 2009-12-30 09:15:54 664 —-a-w- c:\windows\system32\d3d9caps.dat 2009-12-26 16:37:19 1144 —-a-w- c:\windows\system32\drivers\kgpcpy.cfg 2009-12-26 16:32:02 0 d—–w- c:\docume~1\alluse~1.win\applic~1\SITEguard 2009-12-26 16:31:10 0 d—–w- c:\program files\STOPzilla! 2009-12-26 16:31:07 0 d—–w- c:\program files\common files\iS3 2009-12-26 16:31:07 0 d—–w- c:\docume~1\alluse~1.win\applic~1\STOPzilla! 2009-12-24 04:12:52 0 d—–w- c:\program files\BCL Technologies 2009-12-20 13:41:04 0 d—–w- c:\docume~1\koller~1\applic~1\Malwarebytes 2009-12-20 13:40:59 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-12-20 13:40:57 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2009-12-20 13:40:57 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2009-12-20 13:40:57 0 d—–w- c:\docume~1\alluse~1.win\applic~1\Malwarebytes 2009-12-14 19:15:14 2146304 —-a-w- c:\windows\system32\GPhotos.scr 2009-12-09 21:01:15 139499 —-a-w- c:\windows\hpoins15.dat 2009-12-09 21:01:15 1039 ——w- c:\windows\hpomdl15.dat 2009-12-09 16:43:12 0 d—–w- c:\program files\common files\HP 2009-12-09 16:05:56 121329 ——w- c:\windows\hpoins15.dat.temp 2009-12-09 16:05:56 1037 ——w- c:\windows\hpomdl15.dat.temp ==================== Find3M ==================== 2010-01-01 06:01:57 96512 —-a-w- c:\windows\system32\drivers\atapi.svs 2010-01-01 06:01:57 96512 ——w- c:\windows\system32\drivers\atapi.sys 2009-12-25 18:13:51 24892 —ha-w- c:\windows\system32\mlfcache.dat 2009-10-29 07:45:38 916480 ——w- c:\windows\system32\wininet.dll 2009-10-21 05:38:36 75776 —-a-w- c:\windows\system32\strmfilt.dll 2009-10-21 05:38:36 25088 —-a-w- c:\windows\system32\httpapi.dll 2009-10-13 10:30:16 270336 —-a-w- c:\windows\system32\oakley.dll 2009-10-12 13:38:19 149504 —-a-w- c:\windows\system32\rastls.dll 2009-10-12 13:38:18 79872 —-a-w- c:\windows\system32\raschap.dll 2009-10-12 12:34:50 411368 —-a-w- c:\windows\system32\deploytk.dll ============= FINISH: 23:08:01.06 =============== ******************************************************************************** ************************* UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-12-01.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume2 Install Date: 6/8/2009 11:11:24 AM System Uptime: 1/4/2010 7:45:15 AM (16 hours ago) Motherboard: Intel Corporation | | DG965RY Processor: Intel® Core™2 CPU 6300 @ 1.86GHz | | 1864/266mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 225 GiB total, 54.125 GiB free. D: is FIXED (NTFS) - 466 GiB total, 191.084 GiB free. E: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP144: 10/7/2009 2:23:05 AM - System Checkpoint RP145: 10/8/2009 3:18:08 PM - System Checkpoint RP146: 10/9/2009 4:44:25 PM - System Checkpoint RP147: 10/10/2009 5:20:06 PM - System Checkpoint RP148: 10/11/2009 5:58:47 PM - System Checkpoint RP149: 10/12/2009 8:34:45 AM - Installed Java™ 6 Update 16 RP150: 10/12/2009 2:46:56 PM - Software Distribution Service 3.0 RP151: 10/13/2009 3:46:11 PM - System Checkpoint RP152: 10/14/2009 4:11:12 PM - System Checkpoint RP153: 10/14/2009 10:34:11 PM - Software Distribution Service 3.0 RP154: 10/16/2009 7:40:22 AM - System Checkpoint RP155: 10/17/2009 9:41:52 AM - System Checkpoint RP156: 10/18/2009 9:44:47 AM - System Checkpoint RP157: 10/19/2009 10:02:44 AM - System Checkpoint RP158: 10/20/2009 11:43:11 AM - System Checkpoint RP159: 10/21/2009 12:24:44 PM - System Checkpoint RP160: 10/22/2009 12:29:53 PM - System Checkpoint RP161: 10/23/2009 9:41:41 PM - System Checkpoint RP162: 10/24/2009 10:35:38 PM - System Checkpoint RP163: 10/26/2009 9:54:16 AM - System Checkpoint RP164: 10/27/2009 10:12:45 AM - System Checkpoint RP165: 10/28/2009 10:43:14 AM - System Checkpoint RP166: 10/29/2009 11:21:50 AM - System Checkpoint RP167: 10/29/2009 6:31:43 PM - Installed Compatibility Pack for the 2007 Office system RP168: 10/30/2009 6:55:58 PM - System Checkpoint RP169: 10/31/2009 7:23:12 PM - System Checkpoint RP170: 11/1/2009 8:59:01 PM - System Checkpoint RP171: 11/2/2009 9:00:28 PM - System Checkpoint RP172: 11/3/2009 9:31:48 PM - System Checkpoint RP173: 11/4/2009 10:41:57 PM - System Checkpoint RP174: 11/5/2009 10:42:28 PM - System Checkpoint RP175: 11/6/2009 1:19:46 AM - Software Distribution Service 3.0 RP176: 11/7/2009 1:24:57 AM - System Checkpoint RP177: 11/8/2009 1:26:02 AM - System Checkpoint RP178: 11/9/2009 7:40:49 AM - System Checkpoint RP179: 11/10/2009 8:13:11 AM - System Checkpoint RP180: 11/11/2009 1:18:37 AM - Software Distribution Service 3.0 RP181: 11/12/2009 8:12:24 AM - System Checkpoint RP182: 11/13/2009 8:18:02 AM - System Checkpoint RP183: 11/14/2009 9:37:13 AM - System Checkpoint RP184: 11/15/2009 9:38:20 AM - System Checkpoint RP185: 11/16/2009 10:30:09 AM - System Checkpoint RP186: 11/17/2009 10:32:52 AM - System Checkpoint RP187: 11/18/2009 11:47:41 AM - System Checkpoint RP188: 11/19/2009 1:02:22 PM - System Checkpoint RP189: 11/20/2009 4:15:26 PM - System Checkpoint RP190: 11/21/2009 6:18:29 PM - System Checkpoint RP191: 11/22/2009 11:28:09 PM - System Checkpoint RP192: 11/24/2009 6:39:18 AM - System Checkpoint RP193: 11/25/2009 6:39:41 AM - System Checkpoint RP194: 11/26/2009 7:27:24 AM - System Checkpoint RP195: 11/26/2009 9:19:47 AM - Software Distribution Service 3.0 RP196: 11/27/2009 3:50:33 PM - System Checkpoint RP197: 11/28/2009 4:57:36 PM - System Checkpoint RP198: 11/29/2009 5:34:20 PM - System Checkpoint RP199: 11/30/2009 5:51:52 PM - System Checkpoint RP200: 12/1/2009 6:48:47 PM - System Checkpoint RP201: 12/2/2009 7:01:27 PM - System Checkpoint RP202: 12/3/2009 7:28:04 PM - System Checkpoint RP203: 12/4/2009 7:58:44 PM - System Checkpoint RP204: 12/5/2009 8:46:26 PM - System Checkpoint RP205: 12/6/2009 9:46:26 PM - System Checkpoint RP206: 12/7/2009 9:51:46 PM - System Checkpoint RP207: 12/8/2009 10:27:28 PM - System Checkpoint RP208: 12/9/2009 11:44:47 AM - Installed HPSU306Stub RP209: 12/9/2009 12:16:40 PM - Software Distribution Service 3.0 RP210: 12/10/2009 12:27:53 PM - System Checkpoint RP211: 12/11/2009 12:59:00 PM - System Checkpoint RP212: 12/12/2009 1:43:33 PM - System Checkpoint RP213: 12/13/2009 5:15:35 PM - System Checkpoint RP214: 12/14/2009 6:04:12 PM - System Checkpoint RP215: 12/15/2009 6:54:15 PM - System Checkpoint RP216: 12/16/2009 7:30:04 PM - System Checkpoint RP217: 12/17/2009 8:15:44 PM - System Checkpoint RP218: 12/18/2009 9:15:44 PM - System Checkpoint RP219: 12/19/2009 9:17:55 PM - System Checkpoint RP220: 12/20/2009 10:06:36 PM - System Checkpoint RP221: 12/22/2009 8:11:03 AM - System Checkpoint RP222: 12/23/2009 6:11:06 PM - System Checkpoint RP223: 12/23/2009 11:08:46 PM - Configured Family Tree Maker 2009 RP224: 12/23/2009 11:09:13 PM - Configured Family Tree Maker 2009 RP225: 12/23/2009 11:12:17 PM - Installed Family Tree Maker 2009 RP226: 12/24/2009 11:46:53 PM - System Checkpoint RP227: 12/26/2009 12:47:57 AM - System Checkpoint RP228: 12/26/2009 11:31:00 AM - Installed STOPzilla. Available with Windows Installer version 1.2 and later. RP229: 12/26/2009 11:48:17 AM - Removed STOPzilla. Available with Windows Installer version 1.2 and later. RP230: 12/27/2009 1:53:21 PM - System Checkpoint RP231: 12/28/2009 2:47:35 PM - System Checkpoint RP232: 12/29/2009 3:03:01 PM - System Checkpoint RP233: 12/30/2009 4:21:17 PM - System Checkpoint RP234: 12/31/2009 5:06:31 PM - System Checkpoint RP235: 12/31/2009 6:56:38 PM - Installed Nancy Drew: The Creature of Kapu Cave RP236: 1/1/2010 6:57:39 PM - System Checkpoint RP237: 1/3/2010 2:40:24 AM - System Checkpoint RP238: 1/4/2010 8:53:16 AM - System Checkpoint ==== Installed Programs ====================== 32 Bit HP CIO Components Installer Acrobat.com Adobe AIR Adobe Flash Player 10 Plugin Adobe Reader 9.1.3 AIO_Scan Amazon MP3 Downloader 1.0.5 Apple Application Support Apple Mobile Device Support Apple Software Update Audacity 1.3.7 (Unicode) AVS Update Manager 1.0 AVS Video Converter 6 AVS4YOU Software Navigator 1.3 Bonjour BufferChm Compatibility Pack for the 2007 Office system Copy Critical Update for Windows Media Player 11 (KB959772) CustomerResearchQFolder Desktop Doctor Destination Component DeviceDiscovery DeviceManagementQFolder DocProc DocProcQFolder E.M. PowerPoint Video Converter 2.50 ERUNT 1.1j eSupportQFolder Exact Audio Copy 0.99pb5 Family Tree Maker 2009 Far Out Field Trips GIMP 2.6.6 Google Earth Google SketchUp 7 Google Update Helper HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) HP Customer Participation Program 9.0 HP Imaging Device Functions 9.0 HP OCR Software 9.0 HP Photosmart All-In-One Software 9.0 HP Photosmart Essential 2.01 HP Photosmart Essential2.01 HP Solution Center 9.0 HP Update HPProductAssistant HPSSupply Intel Audio Studio 2.0 Intel® Active Client Manager 2.0 HECI Driver Intel® PRO Network Connections iS3 STOPzilla Toolbar iTunes Java™ 6 Update 16 LADSPA_plugins-win-0.4.15 LAME v3.98.2 for Audacity LightScribe 1.4.89.1 Malwarebytes' Anti-Malware MarketResearch McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Standard Edition 2003 Microsoft Primary Interoperability Assemblies 2005 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft WSE 3.0 Monopoly Junior Mozilla Firefox (3.5.6) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 4.0 SP2 Parser and SDK Mystery Club Gadget Games Nancy Drew: Danger by Design Nancy Drew: Danger on Deception Island Nancy Drew: Legend of the Crystal Skull Nancy Drew: Secret of the Scarlet Hand Nancy Drew: The Creature of Kapu Cave Nero Suite Nikon Scan NVIDIA Drivers Pdf995 Picasa 3 PowerVideoMaker Professional 5.0 PS_AIO_Software PS_AIO_Software_min PSSWCORE QuickTime Scan Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) SigmaTel Audio SolutionCenter Sonic & Knuckles Collection Documentation Sonic & Knuckles Killer ! Sony DVD Architect Studio 4.5 Sony Sound Forge Audio Studio 9.0 Spelling Dictionaries Support For Adobe Reader 9 Status Toolbox TrayApp UnloadSupport Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 8 (KB971930) Update for Windows Internet Explorer 8 (KB976749) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Vegas Movie Studio Platinum 9.0 VideoToolkit01 VST Bridge 1.1 Wave Repair 4.9.2 WebFldrs XP WebReg Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 Zune Desktop Theme ==== Event Viewer Messages From Past Week ======== 12/31/2009 7:00:00 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 12/31/2009 6:52:58 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the stisvc service. 12/28/2009 9:57:34 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that is large enough to contain all physical memory. 12/28/2009 9:57:34 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver. ==== End Of File ===========================

That would just leave the following:
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\atapi.sys.vir Infected: Rootkit.Win32.TDSS.y 1
C:\WINDOWS\system32\config\systemprofile\Application Data\Sun\Java\Deployment\cache\6.0\3\12a49b83-543b4efa Infected: Trojan-Downloader.Java.OpenStream.ad 1


quarantine and Java cache, which we will be cleaning up now.

Please do the following:

Visit ADOBEand download the latest version of Acrobat Reader (version 9.2)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 17. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u17-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT



Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]




NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
I have completed the steps in the last post. The only one that did not work was the Combofix /Uninstall. I scanned my PC for any files including "combo" but did not find related files. Thanks again for the fantastic service you provide. Over the holidays we watched The Lord of The Rings and I can now reflect on my own personal, modern day example of good triumphing over evil. God Bless, FLWright

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI