This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] HiJackThis Log

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:24:44 PM, on 3/7/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D4CE743-A9FD-4C88-86F7-DC289838F413}: NameServer = 10.106.128.1
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Scheduler (antivirschedulerservice) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (antivirservice) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 4823 bytes

Thanks
:welcome:

Nothing jumping out at me as bad.

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report and also a new HJT log please
Malwarebytes' Anti-Malware 1.44
Database version: 3831
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

3/10/2010 11:29:40 PM
mbam-log-2010-03-10 (23-29-40).txt

Scan type: Full Scan (C:\|)
Objects scanned: 203543
Time elapsed: 1 hour(s), 13 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:31:31 PM, on 3/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16981)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) - http://simcity.ea.com/play/classic/SimCityX.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0D4CE743-A9FD-4C88-86F7-DC289838F413}: NameServer = 10.106.128.1
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O23 - Service: Avira AntiVir Scheduler (antivirschedulerservice) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (antivirservice) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 4825 bytes
Good Morning,

Nothing really jumping out at me as dangerous. It looks like Malwarebytes took over an hour to run, most times it will only take 15 min or so, lets dig deeper.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe



Go to your Add Remove Programs in the Control Panel and uninstall Viewpoint, it installs without your knowledge or consent, is considered Adware, uses system resources and is not needed for anything.





Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.





Next:

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.



To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-11 19:54:19
Windows 5.1.2600 Service Pack 3
Running: xe9xrfs0.exe; Driver: C:\DOCUME~1\Paul\LOCALS~1\Temp\pxtdapod.sys


—- System - GMER 1.0.15 —-

SSDT FA22F2DE ZwCreateKey
SSDT FA22F2D4 ZwCreateThread
SSDT FA22F2E3 ZwDeleteKey
SSDT FA22F2ED ZwDeleteValueKey
SSDT FA22F2F2 ZwLoadKey
SSDT FA22F2C0 ZwOpenProcess
SSDT FA22F2C5 ZwOpenThread
SSDT FA22F2FC ZwReplaceKey
SSDT FA22F2F7 ZwRestoreKey
SSDT FA22F2E8 ZwSetValueKey
SSDT FA22F2CF ZwTerminateProcess

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + 428 804E2A94 4 Bytes CALL 90484D8B

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[364] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 015F28B1
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[364] WS2_32.dll!send 71AB4C27 5 Bytes JMP 015F273D
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[364] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 015F282F
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[364] WS2_32.dll!recv 71AB676F 5 Bytes JMP 015F2775
.text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[364] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 015F27AD
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[376] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 007028B1
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[376] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0070273D
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[376] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0070282F
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[376] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00702775
.text C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe[376] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 007027AD
.text C:\Program Files\Bonjour\mDNSResponder.exe[400] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 007D28B1
.text C:\Program Files\Bonjour\mDNSResponder.exe[400] WS2_32.dll!send 71AB4C27 5 Bytes JMP 007D273D
.text C:\Program Files\Bonjour\mDNSResponder.exe[400] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 007D282F
.text C:\Program Files\Bonjour\mDNSResponder.exe[400] WS2_32.dll!recv 71AB676F 5 Bytes JMP 007D2775
.text C:\Program Files\Bonjour\mDNSResponder.exe[400] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 007D27AD
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1704] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 019528B1
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1704] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0195273D
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1704] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0195282F
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1704] WS2_32.dll!recv 71AB676F 5 Bytes JMP 01952775
.text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1704] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 019527AD
.text C:\WINDOWS\System32\alg.exe[2476] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C228B1
.text C:\WINDOWS\System32\alg.exe[2476] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C2273D
.text C:\WINDOWS\System32\alg.exe[2476] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00C2282F
.text C:\WINDOWS\System32\alg.exe[2476] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C22775
.text C:\WINDOWS\System32\alg.exe[2476] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00C227AD
.text C:\WINDOWS\Explorer.EXE[2956] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E728B1
.text C:\WINDOWS\Explorer.EXE[2956] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E7273D
.text C:\WINDOWS\Explorer.EXE[2956] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E7282F
.text C:\WINDOWS\Explorer.EXE[2956] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E72775
.text C:\WINDOWS\Explorer.EXE[2956] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E727AD
.text C:\Program Files\Java\jre6\bin\jusched.exe[3596] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00E228B1
.text C:\Program Files\Java\jre6\bin\jusched.exe[3596] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00E2273D
.text C:\Program Files\Java\jre6\bin\jusched.exe[3596] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00E2282F
.text C:\Program Files\Java\jre6\bin\jusched.exe[3596] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00E22775
.text C:\Program Files\Java\jre6\bin\jusched.exe[3596] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00E227AD
.text C:\Program Files\iTunes\iTunesHelper.exe[3724] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 034128B1
.text C:\Program Files\iTunes\iTunesHelper.exe[3724] WS2_32.dll!send 71AB4C27 5 Bytes JMP 0341273D
.text C:\Program Files\iTunes\iTunesHelper.exe[3724] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 0341282F
.text C:\Program Files\iTunes\iTunesHelper.exe[3724] WS2_32.dll!recv 71AB676F 5 Bytes JMP 03412775
.text C:\Program Files\iTunes\iTunesHelper.exe[3724] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 034127AD
.text C:\Program Files\iPod\bin\iPodService.exe[3880] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00BA28B1
.text C:\Program Files\iPod\bin\iPodService.exe[3880] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00BA273D
.text C:\Program Files\iPod\bin\iPodService.exe[3880] WS2_32.dll!WSARecv 71AB4CB5 5 Bytes JMP 00BA282F
.text C:\Program Files\iPod\bin\iPodService.exe[3880] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00BA2775
.text C:\Program Files\iPod\bin\iPodService.exe[3880] WS2_32.dll!WSASend 71AB68FA 5 Bytes JMP 00BA27AD

—- Devices - GMER 1.0.15 —-

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 82528518
Device \Driver\atapi \Device\Ide\IdePort0 82528518
Device \Driver\atapi \Device\Ide\IdePort1 82528518
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 82528518

—- Registry - GMER 1.0.15 —-

Reg HKLM\SOFTWARE\Classes\CLSID\{992D8806-2671-D222-4FDB-0CE7B3E8FBE5}\InprocServer32@ C:\WINDOWS\system32\comaddin.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{992D8806-2671-D222-4FDB-0CE7B3E8FBE5}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{992D8806-2671-D222-4FDB-0CE7B3E8FBE5}\ProgID@ MTxAddIn.RegRefresh
Reg HKLM\SOFTWARE\Classes\CLSID\{992D8806-2671-D222-4FDB-0CE7B3E8FBE5}\VersionIndependentProgID@ MTxAddIn.RegRefresh.1
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\Implemented Categories\{00021492-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InProcServer32@ %SystemRoot%\system32\SHELL32.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A40F8BBE-77CD-78A3-DF6D-3C14B7105899}\InProcServer32@ThreadingModel Apartment
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{B371C4C1-4F55-2EAA-427C-673701621939}

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior;

—- EOF - GMER 1.0.15 —-
16:11:01:602 2772 TDSS rootkit removing tool 2.2.8 Mar 10 2010 15:53:20 16:11:01:602 2772 ================================================================================ 16:11:01:602 2772 SystemInfo: 16:11:01:602 2772 OS Version: 5.1.2600 ServicePack: 3.0 16:11:01:602 2772 Product type: Workstation 16:11:01:602 2772 ComputerName: PAUL 16:11:01:602 2772 UserName: Paul 16:11:01:602 2772 Windows directory: C:\WINDOWS 16:11:01:602 2772 Processor architecture: Intel x86 16:11:01:602 2772 Number of processors: 1 16:11:01:602 2772 Page size: 0x1000 16:11:01:612 2772 Boot type: Normal boot 16:11:01:612 2772 ================================================================================ 16:11:02:343 2772 UnloadDriverW: NtUnloadDriver error 2 16:11:02:343 2772 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2 16:11:03:144 2772 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system 16:11:03:144 2772 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 16:11:03:144 2772 wfopen_ex: Trying to KLMD file open 16:11:03:144 2772 wfopen_ex: File opened ok (Flags 2) 16:11:03:144 2772 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software 16:11:03:144 2772 wfopen_ex: MyNtCreateFileW error 32 (C0000043) 16:11:03:144 2772 wfopen_ex: Trying to KLMD file open 16:11:03:144 2772 wfopen_ex: File opened ok (Flags 2) 16:11:03:144 2772 Initialize success 16:11:03:144 2772 16:11:03:144 2772 Scanning Services … 16:11:04:906 2772 GetAdvancedServicesInfo: Raw services enum returned 313 services 16:11:04:906 2772 16:11:04:906 2772 Scanning Kernel memory … 16:11:04:906 2772 Devices to scan: 2 16:11:04:906 2772 16:11:04:906 2772 Driver Name: Disk 16:11:04:906 2772 IRP_MJ_CREATE : F9B78BB0 16:11:04:906 2772 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 16:11:04:906 2772 IRP_MJ_CLOSE : F9B78BB0 16:11:04:906 2772 IRP_MJ_READ : F9B72D1F 16:11:04:906 2772 IRP_MJ_WRITE : F9B72D1F 16:11:04:906 2772 IRP_MJ_QUERY_INFORMATION : 804FA88E 16:11:04:906 2772 IRP_MJ_SET_INFORMATION : 804FA88E 16:11:04:906 2772 IRP_MJ_QUERY_EA : 804FA88E 16:11:04:906 2772 IRP_MJ_SET_EA : 804FA88E 16:11:04:906 2772 IRP_MJ_FLUSH_BUFFERS : F9B732E2 16:11:04:906 2772 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 16:11:04:906 2772 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 16:11:04:906 2772 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 16:11:04:906 2772 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 16:11:04:906 2772 IRP_MJ_DEVICE_CONTROL : F9B733BB 16:11:04:906 2772 IRP_MJ_INTERNAL_DEVICE_CONTROL : F9B76F28 16:11:04:906 2772 IRP_MJ_SHUTDOWN : F9B732E2 16:11:04:906 2772 IRP_MJ_LOCK_CONTROL : 804FA88E 16:11:04:906 2772 IRP_MJ_CLEANUP : 804FA88E 16:11:04:906 2772 IRP_MJ_CREATE_MAILSLOT : 804FA88E 16:11:04:906 2772 IRP_MJ_QUERY_SECURITY : 804FA88E 16:11:04:906 2772 IRP_MJ_SET_SECURITY : 804FA88E 16:11:04:906 2772 IRP_MJ_POWER : F9B74C82 16:11:04:916 2772 IRP_MJ_SYSTEM_CONTROL : F9B7999E 16:11:04:916 2772 IRP_MJ_DEVICE_CHANGE : 804FA88E 16:11:04:916 2772 IRP_MJ_QUERY_QUOTA : 804FA88E 16:11:04:916 2772 IRP_MJ_SET_QUOTA : 804FA88E 16:11:04:956 2772 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1 16:11:04:956 2772 16:11:04:956 2772 Driver Name: atapi 16:11:04:956 2772 IRP_MJ_CREATE : F9A876F2 16:11:04:956 2772 IRP_MJ_CREATE_NAMED_PIPE : 804FA88E 16:11:04:956 2772 IRP_MJ_CLOSE : F9A876F2 16:11:04:956 2772 IRP_MJ_READ : 804FA88E 16:11:04:956 2772 IRP_MJ_WRITE : 804FA88E 16:11:04:956 2772 IRP_MJ_QUERY_INFORMATION : 804FA88E 16:11:04:956 2772 IRP_MJ_SET_INFORMATION : 804FA88E 16:11:04:956 2772 IRP_MJ_QUERY_EA : 804FA88E 16:11:04:956 2772 IRP_MJ_SET_EA : 804FA88E 16:11:04:956 2772 IRP_MJ_FLUSH_BUFFERS : 804FA88E 16:11:04:956 2772 IRP_MJ_QUERY_VOLUME_INFORMATION : 804FA88E 16:11:04:956 2772 IRP_MJ_SET_VOLUME_INFORMATION : 804FA88E 16:11:04:956 2772 IRP_MJ_DIRECTORY_CONTROL : 804FA88E 16:11:04:956 2772 IRP_MJ_FILE_SYSTEM_CONTROL : 804FA88E 16:11:04:956 2772 IRP_MJ_DEVICE_CONTROL : F9A87712 16:11:04:956 2772 IRP_MJ_INTERNAL_DEVICE_CONTROL : 82660308 16:11:04:956 2772 IRP_MJ_SHUTDOWN : 804FA88E 16:11:04:956 2772 IRP_MJ_LOCK_CONTROL : 804FA88E 16:11:04:956 2772 IRP_MJ_CLEANUP : 804FA88E 16:11:04:956 2772 IRP_MJ_CREATE_MAILSLOT : 804FA88E 16:11:04:956 2772 IRP_MJ_QUERY_SECURITY : 804FA88E 16:11:04:956 2772 IRP_MJ_SET_SECURITY : 804FA88E 16:11:04:956 2772 IRP_MJ_POWER : F9A8773C 16:11:04:956 2772 IRP_MJ_SYSTEM_CONTROL : F9A8E336 16:11:04:956 2772 IRP_MJ_DEVICE_CHANGE : 804FA88E 16:11:04:956 2772 IRP_MJ_QUERY_QUOTA : 804FA88E 16:11:04:956 2772 IRP_MJ_SET_QUOTA : 804FA88E 16:11:05:016 2772 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1 16:11:05:016 2772 16:11:05:016 2772 Completed 16:11:05:016 2772 16:11:05:016 2772 Results: 16:11:05:016 2772 Memory objects infected / cured / cured on reboot: 0 / 0 / 0 16:11:05:016 2772 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 16:11:05:016 2772 File objects infected / cured / cured on reboot: 0 / 0 / 0 16:11:05:016 2772 16:11:05:016 2772 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system 16:11:05:016 2772 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software 16:11:05:026 2772 KLMD(ARK) unloaded successfully
I was concerned about a driver being infected but it looks ok.

Download DDS by sUBs from one of the following links. Save it to your desktop.
  • DDS.com
  • DDS.scr
  • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control Here
DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 20:41:33.35 on Fri 03/12/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 ============== Running Processes =============== C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Paul\My Documents\Downloads\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} - hxxp://simcity.ea.com/play/classic/SimCityX.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {0D4CE743-A9FD-4C88-86F7-DC289838F413} = 10.106.128.1 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\5gj188sf.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query= FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: browser.startup.homepage - hxxp://google.com/ FF - prefs.js: network.proxy.type - 4 FF - plugin: c:\documents and settings\paul\application data\mozilla\firefox\profiles\5gj188sf.default\extensions\[removed]\plugins\npTVUAx.dll FF - plugin: c:\documents and settings\paul\application data\mozilla\firefox\profiles\5gj188sf.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07076007.dll FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R? gupdate;Google Update Service (gupdate) R? sasenum;sasenum R? SerialNW;NW Serial port driver R? TDWXP;WavePlus 802.11b Wireless PCI/PCMCIA Card Driver S? antivirschedulerservice;Avira AntiVir Scheduler S? antivirservice;Avira AntiVir Guard S? avgio;avgio S? avgntflt;avgntflt S? Ptserli;PCTEL Serial Device Driver for INTEL S? SASDIFSV;SASDIFSV S? saskutil;saskutil =============== Created Last 30 ================ 2010-03-07 09:23:45 54016 —-a-w- c:\windows\system32\drivers\rnjj.sys ==================== Find3M ==================== 2010-01-05 10:00:29 832512 ——w- c:\windows\system32\wininet.dll 2010-01-05 10:00:21 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-01-05 10:00:20 17408 —-a-w- c:\windows\system32\corpol.dll 2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll ============= FINISH: 20:43:56.47 ===============

Attachments:

You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see.

c:\windows\system32\drivers\rnjj.sys <–This file

If the site is busy you can try this one

http://virusscan.jotti.org/en
Antivirus Version Last Update Result a-squared 4.5.0.50 2010.03.12 - AhnLab-V3 5.0.0.2 2010.03.12 - AntiVir 8.2.1.180 2010.03.12 - Antiy-AVL 2.0.3.7 2010.03.12 - Authentium 5.2.0.5 2010.03.12 - Avast 4.8.1351.0 2010.03.12 - Avast5 5.0.332.0 2010.03.12 - AVG 9.0.0.787 2010.03.12 - BitDefender 7.2 2010.03.12 - CAT-QuickHeal 10.00 2010.03.12 - ClamAV 0.96.0.0-git 2010.03.12 - Comodo 4240 2010.03.12 - DrWeb 5.0.1.12222 2010.03.12 - eSafe 7.0.17.0 2010.03.11 Win32.TrojanHorse eTrust-Vet 35.2.7357 2010.03.12 - F-Prot 4.5.1.85 2010.03.12 - F-Secure 9.0.15370.0 2010.03.12 - Fortinet 4.0.14.0 2010.03.09 - GData 19 2010.03.12 - Ikarus T3.1.1.80.0 2010.03.12 - Jiangmin 13.0.900 2010.03.12 - K7AntiVirus 7.10.996 2010.03.12 - Kaspersky 7.0.0.125 2010.03.12 - McAfee 5918 2010.03.12 - McAfee+Artemis 5918 2010.03.12 - McAfee-GW-Edition 6.8.5 2010.03.12 - Microsoft 1.5502 2010.03.12 - NOD32 4940 2010.03.12 - Norman 6.04.08 2010.03.12 - nProtect 2009.1.8.0 2010.03.12 - Panda 10.0.2.2 2010.03.12 - PCTools 7.0.3.5 2010.03.12 - Prevx 3.0 2010.03.12 - Rising 22.38.04.03 2010.03.12 - Sophos 4.51.0 2010.03.12 - Sunbelt 5844 2010.03.12 - Symantec 20091.2.0.41 2010.03.12 Suspicious.Insight TheHacker 6.5.2.0.232 2010.03.12 - TrendMicro 9.120.0.1004 2010.03.12 - VBA32 3.12.12.2 2010.03.12 - ViRobot 2010.3.12.2224 2010.03.12 - VirusBuster 5.0.27.0 2010.03.12 - Additional information File size: 54016 bytes MD5 : e6d35f3aa51a65eb35c1f2340154a25e SHA1 : aabbd57e20d2e7041f9e7abce6cfd8a53c366537 SHA256: 3da4f51682e7d42c5569f1fb1adc6295182962e36f748219e1d0c8f2389ba516 PEInfo: PE Structure information ( base data ) entrypointaddress.: 0xC505 timedatestamp…..: 0x4A9EE5B5 (Wed Sep 2 23:37:57 2009) machinetype…….: 0x14C (Intel I386) ( 5 sections ) name viradd virsiz rawdsiz ntrpy md5 .text 0x480 0xBD9F 0xBE00 5.83 9474f39576a0e15bdbaa2ea3355f0a4a .rdata 0xC280 0x126 0x180 3.78 375b710d9f213cfced30e9fdb29567e1 .data 0xC400 0xC0 0x100 0.33 786971ca2b109729eda604b44d6c72ad INIT 0xC500 0x3C8 0x400 5.20 eea49a93a73afb6afc178455582133c6 .reloc 0xC900 0x9EC 0xA00 6.62 bddd5a40c508bfc84ec87de5f8e6a5d3 ( 1 imports ) > ntoskrnl.exe: ZwWriteFile, RtlUpcaseUnicodeChar, ZwClose, ZwCreateFile, RtlInitUnicodeString, _wcsicmp, ZwQueryValueKey, ZwOpenKey, ZwDeleteKey, swprintf, ZwEnumerateKey, ExFreePoolWithTag, DbgPrint, ExAllocatePool, RtlPrefixUnicodeString, memcpy, RtlDeleteRegistryValue, ZwSetValueKey, RtlWriteRegistryValue, ZwEnumerateValueKey, ZwSetInformationFile, ZwQueryInformationFile, ZwQueryDirectoryFile, ZwOpenFile, KeTickCount, KeBugCheck, MmGetSystemRoutineAddress, ZwFlushKey, PsTerminateSystemThread, KeSetPriorityThread, KeGetCurrentThread, RtlCheckRegistryKey, KeDelayExecutionThread, ZwReadFile, PsCreateSystemThread, PsGetVersion, KeBugCheckEx ( 0 exports ) TrID : File type identification Clipper DOS Executable (33.3%) Generic Win/DOS Executable (33.0%) DOS Executable Generic (33.0%) VXD Driver (0.5%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) ssdeep: 768:Bosx0q2ph6P2Jpz8ftoSUiJP7hYTCMrhwYKUzY4q:j076P2Jpz8ftBUMPaCMrhwY sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEiD : - RDS : NSRL Reference Data Set -
Good Morning,

Lets remove it, we can restore it if need be but I am sure its bad.



  • Please download OTM by OldTimer and save it to your desktop.
  • Double click the [external image: Posted Image] icon on your desktop.
  • Paste the following code under the [external image: Posted Image] area.
    Do not include the word "Code".

    :Processes
    explorer.exe
    
    :Files
    c:\windows\system32\drivers\rnjj.sys
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Push the large [external image: Posted Image] button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy/Paste the contents under the [external image: Posted Image] line here in your next reply.
  • If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.





Run DDS again and post a new log
All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== c:\windows\system32\drivers\rnjj.sys moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 41044 bytes User: HelpAssistant ->Temp folder emptied: 588896 bytes ->Temporary Internet Files folder emptied: 105443 bytes ->Java cache emptied: 7570295 bytes ->FireFox cache emptied: 179277111 bytes ->Flash cache emptied: 373429 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 534537 bytes User: Paul ->Temp folder emptied: 65648541 bytes ->Temporary Internet Files folder emptied: 4008191 bytes ->Java cache emptied: 37839845 bytes ->FireFox cache emptied: 57821476 bytes ->Flash cache emptied: 2252361 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 114688 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 13334791 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 67 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 352.00 mb OTM by OldTimer - Version 3.1.10.0 log created on 03132010_093717 Files moved on Reboot… File move failed. C:\WINDOWS\temp\$$$dq3e scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\$67we.$ scheduled to be moved on reboot. Registry entries deleted on Reboot… DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 9:52:40.82 on Sat 03/13/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 ============== Running Processes =============== C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe C:\WINDOWS\system32\pctspk.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\iPod\bin\iPodService.exe C:\Documents and Settings\Paul\My Documents\Downloads\dds.scr C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7 mStart Page = hxxp://www.yahoo.com uInternet Settings,ProxyOverride = *.local BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} - hxxp://simcity.ea.com/play/classic/SimCityX.cab DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_11-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {0D4CE743-A9FD-4C88-86F7-DC289838F413} = 10.106.128.1 Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\5gj188sf.default\ FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query= FF - prefs.js: browser.search.selectedEngine - AIM Search FF - prefs.js: browser.startup.homepage - hxxp://google.com/ FF - prefs.js: network.proxy.type - 4 FF - plugin: c:\documents and settings\paul\application data\mozilla\firefox\profiles\5gj188sf.default\extensions\[removed]\plugins\npTVUAx.dll FF - plugin: c:\documents and settings\paul\application data\mozilla\firefox\profiles\5gj188sf.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp07076007.dll FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R? gupdate;Google Update Service (gupdate) R? sasenum;sasenum R? SerialNW;NW Serial port driver R? TDWXP;WavePlus 802.11b Wireless PCI/PCMCIA Card Driver S? antivirschedulerservice;Avira AntiVir Scheduler S? antivirservice;Avira AntiVir Guard S? avgio;avgio S? avgntflt;avgntflt S? Ptserli;PCTEL Serial Device Driver for INTEL S? SASDIFSV;SASDIFSV S? saskutil;saskutil =============== Created Last 30 ================ 2010-03-13 15:37:17 0 d—–w- C:\_OTM ==================== Find3M ==================== 2010-01-05 10:00:29 832512 ——w- c:\windows\system32\wininet.dll 2010-01-05 10:00:21 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-01-05 10:00:20 17408 —-a-w- c:\windows\system32\corpol.dll 2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll ============= FINISH: 9:54:35.06 ===============

Attachments:

Sorry for the late reply, major storm with high winds came through our area yesterday and last night and have been without power, sitting in a coffee shop with wifi in another town, Hopefully they wlll have it restored later today. That bad file is gone, how are things running now , we can dig deeper if need be
The computer itself is running faster than it was. The only problem I seem to have is that when I'm browsing the internet my browser will stop working and I'll have to restart firefox or restart my computer completely to be able to start browsing again. I've noticed in my task manager that multiple firefox.exe will be running when I only have one window open and that one of them will be chewing up my CPU at like 95 or more. I don't know if that's a problem you can fix though.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI