This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HiJack This Log

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This morning when I turned on one of the student computers I was greated with a porn website and a bunch of pop up windows.
My virus protection was taken over by some other virus protection program, I downloaded virus cleaner and booted in safe mode and cleaned the computer. Then I went on Trend Micro and downloaded some other tools including HiJack This and this is what it produced.

Please help this computer is a vital tool at our school, it is used for many different things by many different students, thank you very much for your help.


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:21:08 PM, on 8/31/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Trend Micro\Browser Guard 2010\BGUI.exe
C:\Program Files\Trend Micro\Browser Guard 2010\tmiegsrv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\My Documents\Downloads\en-US_TISDell_Download\Setup\Setup.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\MsiExec.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

O2 - BHO: IEGBH0 - {9F3209E2-334B-41E9-B09C-703F398742E7} - (no file)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: TMIEGBHO - {F1AD4A42-BA52-47BC-89DF-3F68F24C017F} - C:\Program Files\Trend Micro\Browser Guard 2010\TMAMS.dll
O3 - Toolbar: TMBGBAR TOOLBAR - {C8137A8D-415D-450C-A1B1-D0C519D45296} - C:\Program Files\Trend Micro\Browser Guard 2010\tmeig.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TMRUBottedTray] "C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe"
O4 - HKLM\..\Run: [Trend Micro Browser Guard v2.0 Beta] "C:\Program Files\Trend Micro\Browser Guard 2010\BGUI.EXE"
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1282855552375
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Trend Micro RUBotted Service (RUBotted) - Trend Micro Inc. - C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe

–
End of file - 3646 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thank you very much for your response, it is greatly appreciated. Here is what you requested and I attached the other two logs. Thank you again!!! :D MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 121): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EC000 \WINDOWS\system32\hal.dll 0xF7A64000 \WINDOWS\system32\KDCOM.DLL 0xF7974000 \WINDOWS\system32\BOOTVID.dll 0xF7515000 ACPI.sys 0xF7A66000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7504000 pci.sys 0xF7564000 isapnp.sys 0xF7B2C000 pciide.sys 0xF77E4000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7A68000 intelide.sys 0xF7574000 MountMgr.sys 0xF74E5000 ftdisk.sys 0xF77EC000 PartMgr.sys 0xF7584000 VolSnap.sys 0xF74CD000 atapi.sys 0xF77F4000 cercsr6.sys 0xF74B5000 \WINDOWS\System32\Drivers\SCSIPORT.SYS 0xF7594000 disk.sys 0xF75A4000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7495000 fltMgr.sys 0xF7483000 sr.sys 0xF75B4000 PxHelp20.sys 0xF746C000 KSecDD.sys 0xF73DF000 Ntfs.sys 0xF73B2000 NDIS.sys 0xF7397000 Mup.sys 0xF7684000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF6DD6000 \SystemRoot\system32\DRIVERS\ialmnt5.sys 0xF6DC2000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF783C000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF6D9F000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7844000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF784C000 \SystemRoot\system32\DRIVERS\RTL8139.SYS 0xF6C31000 \SystemRoot\system32\drivers\P17.sys 0xF6C0D000 \SystemRoot\system32\drivers\portcls.sys 0xF7694000 \SystemRoot\system32\drivers\drmk.sys 0xF6BEA000 \SystemRoot\system32\drivers\ks.sys 0xF6BBA000 \SystemRoot\system32\DRIVERS\ctoss2k.sys 0xF5ED4000 \SystemRoot\system32\DRIVERS\ctsfm2k.sys 0xF76B4000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys 0xF7854000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF76C4000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF785C000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF76D4000 \SystemRoot\system32\DRIVERS\serial.sys 0xF79FC000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF5EC0000 \SystemRoot\system32\DRIVERS\parport.sys 0xF76E4000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF76F4000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF7704000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF7BE1000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF7744000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7A00000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF5EA9000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF7754000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7764000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF786C000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF5E98000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7774000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7874000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF787C000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF7784000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7884000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7A80000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF5E64000 \SystemRoot\system32\DRIVERS\update.sys 0xF7A08000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF5CAD000 \SystemRoot\system32\DRIVERS\TM_CFW.sys 0xF5BDC000 \SystemRoot\system32\DRIVERS\TMPassthru.sys 0xF7624000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF7634000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7AD6000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xEDB11000 \SystemRoot\system32\DRIVERS\MpFilter.sys 0xF7ADC000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7B7A000 \SystemRoot\System32\Drivers\Null.SYS 0xF7ADE000 \SystemRoot\System32\Drivers\Beep.SYS 0xF78D4000 \SystemRoot\System32\drivers\vga.sys 0xF7AE0000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7AE2000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF78DC000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78E4000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF6E8B000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xEDADE000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xEDA86000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xEDA5E000 \SystemRoot\system32\DRIVERS\netbt.sys 0xEDA3C000 \SystemRoot\System32\drivers\afd.sys 0xF7654000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF7664000 \SystemRoot\system32\DRIVERS\tmtdi.sys 0xEDA1B000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xED9EF000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xED958000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF7674000 \SystemRoot\System32\Drivers\Fips.SYS 0xF7A44000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF7714000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF795C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF7A48000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF7724000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF796C000 \SystemRoot\System32\watchdog.sys 0xEDB50000 \SystemRoot\System32\drivers\Dxapi.sys 0xF5C7D000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xBF9C1000 \SystemRoot\System32\drivers\dxg.sys 0xF7BC8000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF9E1000 \SystemRoot\System32\ialmdnt5.dll 0xBF9D3000 \SystemRoot\System32\ialmrnt5.dll 0xBF9FF000 \SystemRoot\System32\ialmdev5.DLL 0xBFA25000 \SystemRoot\System32\ialmdd5.DLL 0xED900000 \SystemRoot\system32\DRIVERS\tmpreflt.sys 0xED6D6000 \SystemRoot\system32\DRIVERS\vsapint.sys 0xED665000 \SystemRoot\system32\DRIVERS\tmxpflt.sys 0xED575000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xED240000 \SystemRoot\system32\drivers\wdmaud.sys 0xF5C0D000 \SystemRoot\system32\drivers\sysaudio.sys 0xED006000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7AFA000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xECEC3000 \SystemRoot\system32\DRIVERS\srv.sys 0xECE46000 \??\C:\WINDOWS\system32\drivers\tmcomm.sys 0xED485000 \??\C:\WINDOWS\system32\drivers\tmevtmgr.sys 0xECDE0000 \??\C:\WINDOWS\system32\drivers\tmactmon.sys 0xECB1F000 \SystemRoot\System32\Drivers\HTTP.sys 0xEC09A000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 37): 0 System Idle Process 4 System 824 C:\WINDOWS\system32\smss.exe 1436 csrss.exe 1528 C:\WINDOWS\system32\winlogon.exe 1572 C:\WINDOWS\system32\services.exe 1584 C:\WINDOWS\system32\lsass.exe 1784 C:\WINDOWS\system32\svchost.exe 1872 svchost.exe 224 C:\Program Files\Microsoft Security Essentials\MsMpEng.exe 280 C:\WINDOWS\system32\svchost.exe 552 svchost.exe 852 svchost.exe 948 C:\WINDOWS\explorer.exe 1152 C:\WINDOWS\system32\spoolsv.exe 1308 C:\WINDOWS\system32\hkcmd.exe 1316 C:\WINDOWS\system32\rundll32.exe 1324 C:\Program Files\Microsoft Security Essentials\msseces.exe 1332 C:\Program Files\Common Files\Java\Java Update\jusched.exe 1372 C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe 1380 C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe 1420 C:\Program Files\LimeWire\LimeWire.exe 1980 C:\Program Files\Java\jre6\bin\jqs.exe 2032 C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe 568 C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe 684 wdfmgr.exe 1044 C:\Program Files\Trend Micro\BM\TMBMSRV.exe 2884 alg.exe 3668 C:\WINDOWS\system32\svchost.exe 480 C:\WINDOWS\system32\wuauclt.exe 2652 C:\Program Files\Common Files\Java\Java Update\jucheck.exe 4044 C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe 2700 C:\Program Files\Trend Micro\Internet Security\TmProxy.exe 2488 C:\WINDOWS\system32\wuauclt.exe 3360 MpCmdRun.exe 3012 C:\Documents and Settings\Owner\Desktop\MBRCheck.exe 2504 C:\Program Files\Mozilla Firefox\firefox.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: SAMSUNGSP0802N, Rev: TK100-28 Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done! DDS (Ver_10-03-17.01) - NTFSx86 NETWORK Run by [removed] at 16:03:02.82 on Wed 09/01/2010 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.595 [GMT -7:00] AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} AV: Trend Micro Internet Security *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} FW: Trend Micro Personal Firewall *enabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Owner\My Documents\ie27gnnj.exe C:\Documents and Settings\Owner\My Documents\dds.scr ============== Pseudo HJT Report =============== BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [P17Helper] Rundll32 P17.dll,P17Helper mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe" mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1282855552375 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: igfxcui - igfxsrvc.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admini~1.cou\applic~1\mozilla\firefox\profiles\igbmp4w3.default\ —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [2010-8-31 335376] R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2010-8-31 206608] S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216] S2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2010-8-31 582992] S2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2010-8-31 51792] S2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2010-8-31 36368] S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2010-8-31 206608] S3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\trendm~1\intern~1\TmPfw.exe [2010-8-31 488768] S3 tmproxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2010-8-31 648456] =============== Created Last 30 ================ 2010-09-01 22:19:49 0 d—–w- c:\windows\system32\LogFiles 2010-08-31 22:33:02 59472 —-a-w- c:\windows\system32\drivers\tmactmon.sys 2010-08-31 22:33:02 51792 —-a-w- c:\windows\system32\drivers\tmevtmgr.sys 2010-08-31 22:33:02 0 d—–w- c:\windows\system32\log 2010-08-31 22:29:02 0 d—–w- c:\docume~1\alluse~1\applic~1\Trend Micro 2010-08-31 22:17:14 656648 —-a-w- c:\windows\system32\UfWSC.cpl 2010-08-31 22:17:05 335376 —-a-w- c:\windows\system32\drivers\TM_CFW.sys 2010-08-31 22:17:05 1322808 —-a-w- c:\windows\system32\drivers\vsapint.sys 2010-08-31 22:17:04 66320 —-a-w- c:\windows\system32\drivers\tmtdi.sys 2010-08-31 22:17:04 36368 —-a-w- c:\windows\system32\drivers\tmpreflt.sys 2010-08-31 22:17:04 230928 —-a-w- c:\windows\system32\drivers\tmxpflt.sys 2010-08-31 21:36:59 206608 —-a-w- c:\windows\system32\drivers\TMPassthru.sys 2010-08-31 21:36:55 0 d—–w- c:\program files\Trend Micro 2010-08-31 21:33:17 163408 —-a-w- c:\windows\system32\drivers\tmcomm.sys 2010-08-31 16:57:21 0 d—–w- c:\windows\system32\wbem\Repository 2010-08-27 17:40:33 0 d—–w- c:\program files\IObit 2010-08-27 16:17:51 0 d—–w- c:\windows\ServicePackFiles 2010-08-27 00:56:14 0 d—–w- c:\program files\Mozilla Firefox(3) 2010-08-26 21:56:40 0 d—–w- c:\program files\Mozilla Firefox(2) 2010-08-26 21:12:38 0 d—–w- c:\windows\Logs 2010-08-26 21:12:26 0 d—–w- c:\program files\Winamp Detect 2010-08-26 21:11:29 0 d—–w- c:\windows\RegisteredPackages 2010-08-26 21:07:01 0 d—–w- c:\windows\pss 2010-08-26 21:05:25 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-08-26 21:05:25 411368 —-a-w- c:\windows\system32\deploytk.dll 2010-08-26 21:03:12 0 d—–w- c:\program files\LimeWire 2010-08-26 20:56:18 221568 ——w- c:\windows\system32\MpSigStub.exe 2010-08-26 20:50:47 0 d—–w- c:\program files\Microsoft Security Essentials 2010-08-26 20:50:39 274288 —-a-w- c:\windows\system32\mucltui.dll 2010-08-26 20:50:39 215920 —-a-w- c:\windows\system32\muweb.dll 2010-08-26 20:50:39 16736 —-a-w- c:\windows\system32\mucltui.dll.mui 2010-08-26 20:48:46 22752 —-a-w- c:\windows\system32\spupdsvc.exe 2010-08-26 20:48:46 0 d—–w- c:\windows\system32\PreInstall 2010-08-26 20:46:15 21728 —-a-w- c:\windows\system32\wucltui.dll.mui 2010-08-26 20:46:15 17632 —-a-w- c:\windows\system32\wuaueng.dll.mui 2010-08-26 20:46:15 15072 —-a-w- c:\windows\system32\wuaucpl.cpl.mui 2010-08-26 20:46:15 0 d—–w- c:\windows\system32\SoftwareDistribution 2010-08-26 20:46:14 15064 —-a-w- c:\windows\system32\wuapi.dll.mui 2010-08-26 20:43:06 584 —-a-w- c:\windows\system32\settingsbkup.sfm 2010-08-26 20:43:06 584 —-a-w- c:\windows\system32\settings.sfm 2010-08-26 20:39:56 75 —-a-w- c:\windows\system32\ctzapxx.ini 2010-08-26 20:39:56 5663 —-a-w- c:\windows\system32\ludap17.ini 2010-08-26 20:39:56 11264 —-a-w- c:\windows\INRES.DLL 2010-08-26 20:39:56 0 d—–w- c:\windows\system32\Data 2010-08-26 20:13:42 159744 —-a-w- c:\windows\system32\igfxres.dll 2010-08-26 19:47:14 0 d—–w- c:\program files\Broadcom 2010-08-26 19:44:26 0 d—–w- c:\program files\Creative 2010-08-26 19:29:14 0 d-sh–w- c:\documents and settings\all users\DRM 2010-08-26 19:28:50 0 d–h–w- c:\program files\WindowsUpdate 2010-08-26 19:27:51 0 d—–w- c:\program files\common files\MSSoap 2010-08-26 19:26:03 0 d—–w- c:\program files\Online Services 2010-08-26 19:25:57 0 d—–w- c:\program files\Messenger 2010-08-26 19:25:52 0 d—–w- c:\program files\MSN Gaming Zone 2010-08-26 19:25:04 0 d—–w- c:\program files\Windows NT 2010-08-26 12:19:54 0 d—–w- c:\program files\common files\ODBC 2010-08-26 12:19:50 0 d—–w- c:\program files\common files\SpeechEngines 2010-08-26 12:19:19 0 d—–r- c:\documents and settings\all users\Documents ==================== Find3M ==================== 2010-08-26 20:40:30 409600 —-a-w- c:\windows\system32\wrap_oal.dll 2010-08-26 20:40:30 114688 —-a-w- c:\windows\system32\OpenAL32.dll 2010-08-26 19:26:59 21640 —-a-w- c:\windows\system32\emptyregdb.dat ============= FINISH: 16:04:02.31 ===============
Hi,

please do the following:

Download ComboFix from either of these locations:
Link 1
Link 2


VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.



Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Hello,

I followed your instructions and here are the results:


ComboFix 10-09-01.04 - Owner 09/02/2010 16:06:51.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.429 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Trend Micro Internet Security *On-access scanning enabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}
FW: Trend Micro Personal Firewall *disabled* {3E790E9E-6A5D-4303-A7F9-185EC20F3EB6}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\.wtav
c:\windows\settings.reg
c:\windows\system32\certstore.dat
c:\windows\system32\Data
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

Infected copy of c:\windows\system32\DRIVERS\redbook.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-08-02 to 2010-09-02 )))))))))))))))))))))))))))))))
.

2010-09-01 23:03 . 2010-09-01 23:03 ——– d—–w- c:\documents and settings\Administrator.COUNSELORS\Local Settings\Application Data\Mozilla
2010-09-01 22:19 . 2010-09-01 22:19 ——– d—–w- c:\windows\system32\LogFiles
2010-08-31 22:40 . 2007-10-23 16:27 110592 —-a-w- c:\documents and settings\Owner\Application Data\U3\temp\cleanup.exe
2010-08-31 22:39 . 2008-05-02 17:41 3493888 —ha-w- c:\documents and settings\Owner\Application Data\U3\temp\Launchpad Removal.exe
2010-08-31 22:39 . 2010-09-01 23:26 ——– d—–w- c:\documents and settings\Owner\Application Data\U3
2010-08-31 21:36 . 2010-08-31 21:36 ——– d—–w- c:\documents and settings\Owner\Application Data\InstallShield
2010-08-31 21:33 . 2010-08-31 21:33 ——– d—–w- c:\documents and settings\Owner\log
2010-08-31 21:33 . 2010-07-20 01:02 163408 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2010-08-31 18:43 . 2010-08-31 18:43 12328 —-a-w- c:\documents and settings\Administrator.COUNSELORS\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-31 17:59 . 2010-08-31 17:59 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7d58f44b-n\msvcp71.dll
2010-08-31 17:59 . 2010-08-31 17:59 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7d58f44b-n\msvcr71.dll
2010-08-31 17:59 . 2010-08-31 17:59 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-7d58f44b-n\jmc.dll
2010-08-31 17:59 . 2010-08-31 17:59 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-20ff6327-n\decora-sse.dll
2010-08-31 17:59 . 2010-08-31 17:59 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-20ff6327-n\decora-d3d.dll
2010-08-31 16:57 . 2010-08-31 16:57 ——– d—–w- c:\windows\system32\wbem\Repository
2010-08-31 16:53 . 2010-08-31 16:54 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Microsoft
2010-08-31 16:53 . 2010-08-31 16:54 ——– d-s—w- c:\documents and settings\Administrator
2010-08-27 17:40 . 2010-08-27 17:40 ——– d—–w- c:\program files\IObit
2010-08-27 16:17 . 2010-08-27 16:17 ——– d—–w- c:\windows\ServicePackFiles
2010-08-27 00:56 . 2010-08-31 16:56 ——– d—–w- c:\program files\Mozilla Firefox(3)
2010-08-26 22:25 . 2010-09-02 21:17 ——– d—–w- c:\documents and settings\Owner\Application Data\LimeWire
2010-08-26 21:57 . 2010-08-26 21:57 0 —-a-w- c:\windows\nsreg.dat
2010-08-26 21:57 . 2010-08-26 21:57 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
2010-08-26 21:56 . 2010-08-31 16:57 ——– d—–w- c:\program files\Mozilla Firefox(2)
2010-08-26 21:12 . 2010-08-26 21:12 ——– d—–w- c:\windows\Logs
2010-08-26 21:12 . 2010-08-26 21:12 ——– d—–w- c:\program files\Winamp Detect
2010-08-26 21:09 . 2010-08-31 16:57 ——– d—–w- c:\program files\Winamp
2010-08-26 21:09 . 2010-08-26 21:10 ——– d—–w- c:\documents and settings\Owner\Application Data\Winamp
2010-08-26 21:05 . 2010-08-26 21:05 ——– d—–w- c:\program files\Common Files\Java
2010-08-26 21:05 . 2010-08-26 21:04 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-08-26 21:04 . 2010-08-26 21:04 ——– d—–w- c:\program files\Java
2010-08-26 21:03 . 2010-08-26 21:06 ——– d—–w- c:\program files\LimeWire
2010-08-26 20:56 . 2010-06-01 17:37 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-08-26 20:52 . 2010-08-26 20:52 12328 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-26 20:50 . 2010-08-26 20:50 ——– d—–w- c:\program files\Microsoft Security Essentials
2010-08-26 20:50 . 2009-08-07 02:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2010-08-26 20:50 . 2009-08-07 02:23 215920 —-a-w- c:\windows\system32\muweb.dll
2010-08-26 20:48 . 2005-02-25 03:35 22752 —-a-w- c:\windows\system32\spupdsvc.exe
2010-08-26 20:46 . 2009-08-07 02:24 44768 —-a-w- c:\windows\system32\wups2.dll
2010-08-26 20:45 . 2010-08-26 20:45 ——– d-s—w- c:\documents and settings\Owner\UserData
2010-08-26 20:39 . 2005-06-15 18:07 11264 —-a-w- c:\windows\INRES.DLL
2010-08-26 20:13 . 2004-08-20 22:50 159744 —-a-w- c:\windows\system32\igfxres.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-31 22:33 . 2010-08-31 21:36 ——– d—–w- c:\program files\Trend Micro
2010-08-31 22:29 . 2010-08-31 22:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Trend Micro
2010-08-31 22:17 . 2010-08-31 22:17 335376 —-a-w- c:\windows\system32\drivers\TM_CFW.sys
2010-08-31 22:17 . 2010-08-31 22:17 66320 —-a-w- c:\windows\system32\drivers\tmtdi.sys
2010-08-31 22:01 . 2010-08-31 22:01 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-08-31 21:36 . 2010-08-26 19:44 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-08-27 19:43 . 2010-08-26 19:29 77423 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-08-26 20:41 . 2010-08-26 19:44 ——– d—–w- c:\program files\Creative
2010-08-26 20:40 . 2010-08-26 20:40 409600 —-a-w- c:\windows\system32\wrap_oal.dll
2010-08-26 20:40 . 2010-08-26 20:40 114688 —-a-w- c:\windows\system32\OpenAL32.dll
2010-08-26 20:28 . 2010-08-26 19:44 ——– d—–w- c:\program files\Common Files\InstallShield
2010-08-26 19:47 . 2010-08-26 19:47 ——– d—–w- c:\program files\Broadcom
2010-08-26 19:45 . 2010-08-26 19:45 ——– d—–w- c:\program files\Intel
2010-08-26 19:31 . 2010-08-26 19:31 ——– d—–w- c:\program files\microsoft frontpage
2010-08-26 19:26 . 2010-08-26 19:26 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2010-07-20 01:03 . 2010-08-31 22:33 59472 —-a-w- c:\windows\system32\drivers\tmactmon.sys
2010-07-20 01:03 . 2010-08-31 22:33 51792 —-a-w- c:\windows\system32\drivers\tmevtmgr.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-20 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-20 118784]
"P17Helper"="P17.dll" [2005-05-04 64512]
"MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-06-01 1093208]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
"TMRUBottedTray"="c:\program files\Trend Micro\RUBotted\TMRUBottedTray.exe" [2008-11-06 288088]
"UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-08-31 1398024]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2010-8-19 503808]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=

R2 RUBotted;Trend Micro RUBotted Service;c:\program files\Trend Micro\RUBotted\TMRUBotted.exe [8/31/2010 2:36 PM 582992]
R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [8/31/2010 3:33 PM 51792]
R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [8/31/2010 3:17 PM 36368]
R3 tmcfw;Trend Micro Common Firewall Service;c:\windows\system32\drivers\TM_CFW.sys [8/31/2010 3:17 PM 335376]
R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [8/31/2010 2:36 PM 206608]
R3 TmPfw;Trend Micro Personal Firewall;c:\progra~1\TRENDM~1\INTERN~1\TmPfw.exe [8/31/2010 3:36 PM 488768]
R3 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [8/31/2010 3:36 PM 648456]
S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [8/31/2010 2:36 PM 206608]
.
Contents of the 'Scheduled Tasks' folder

2010-09-02 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2010-03-26 04:40]
.
.
——- Supplementary Scan ——-
.
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\mwc6uk45.default\
FF - prefs.js: network.proxy.type - 0

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-02 16:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x82C52EC5]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75a8fc3
\Driver\ACPI -> ACPI.sys @ 0xf751bcb8
\Driver\atapi -> atapi.sys @ 0xf74d37b4
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0130
ParseProcedure -> ntoskrnl.exe @ 0x8056f10e
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805a0130
ParseProcedure -> ntoskrnl.exe @ 0x8056f10e
NDIS: Broadcom 440x 10/100 Integrated Controller -> SendCompleteHandler -> NDIS.sys @ 0xf73c7ba0
PacketIndicateHandler -> NDIS.sys @ 0xf73d4b21
SendHandler -> NDIS.sys @ 0xf73b287b
user & kernel MBR OK

**************************************************************************
.
Completion time: 2010-09-02 16:48:05
ComboFix-quarantined-files.txt 2010-09-02 23:47

Pre-Run: 72,726,974,464 bytes free
Post-Run: 72,750,071,808 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - C08092EDC2D91BC770C3D6B816044311
Ok, so i tried to go online and firefox and internet explorer 8 continue to crash. The last time i went on a second tab popped up and it was for the same virus protection program that took over the computer before. Thanks again for all of your help hopefully it isnt too much of a pain in the neck for you.
Hi

Please run the following:



Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
Hi, I downloaded and installed that program, and a malicious object came up, so i hit cure and here is the log: Thanks. 2010/09/07 09:46:58.0891 TDSS rootkit removing tool 2.4.2.1 Sep 7 2010 14:43:44 2010/09/07 09:46:58.0891 ================================================================================ 2010/09/07 09:46:58.0891 SystemInfo: 2010/09/07 09:46:58.0891 2010/09/07 09:46:58.0891 OS Version: 5.1.2600 ServicePack: 2.0 2010/09/07 09:46:58.0891 Product type: Workstation 2010/09/07 09:46:58.0891 ComputerName: COUNSELORS 2010/09/07 09:46:58.0906 UserName: Owner 2010/09/07 09:46:58.0906 Windows directory: C:\WINDOWS 2010/09/07 09:46:58.0906 System windows directory: C:\WINDOWS 2010/09/07 09:46:58.0906 Processor architecture: Intel x86 2010/09/07 09:46:58.0906 Number of processors: 1 2010/09/07 09:46:58.0906 Page size: 0x1000 2010/09/07 09:46:58.0906 Boot type: Normal boot 2010/09/07 09:46:58.0906 ================================================================================ 2010/09/07 09:47:00.0375 Initialize success 2010/09/07 09:47:03.0484 ================================================================================ 2010/09/07 09:47:03.0484 Scan started 2010/09/07 09:47:03.0484 Mode: Manual; 2010/09/07 09:47:03.0484 ================================================================================ 2010/09/07 09:47:07.0219 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 2010/09/07 09:47:07.0640 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 2010/09/07 09:47:08.0500 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 2010/09/07 09:47:08.0734 AFD (5ac495f4cb807b2b98ad2ad591e6d92e) C:\WINDOWS\System32\drivers\afd.sys 2010/09/07 09:47:10.0828 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 2010/09/07 09:47:11.0640 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 2010/09/07 09:47:12.0515 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 2010/09/07 09:47:13.0578 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 2010/09/07 09:47:14.0031 bcm4sbxp (b60f57b4d9cdbc663cc03eb8af7ec34e) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys 2010/09/07 09:47:14.0421 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 2010/09/07 09:47:14.0906 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 2010/09/07 09:47:15.0234 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 2010/09/07 09:47:15.0578 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 2010/09/07 09:47:15.0953 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys 2010/09/07 09:47:16.0218 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 2010/09/07 09:47:16.0781 ctsfm2k (8db84de3aab34a8b4c2f644eff41cd76) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys 2010/09/07 09:47:17.0124 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 2010/09/07 09:47:17.0328 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 2010/09/07 09:47:17.0593 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 2010/09/07 09:47:17.0812 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 2010/09/07 09:47:17.0984 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 2010/09/07 09:47:18.0234 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 2010/09/07 09:47:18.0437 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 2010/09/07 09:47:18.0609 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys 2010/09/07 09:47:18.0781 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 2010/09/07 09:47:18.0953 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 2010/09/07 09:47:19.0109 FltMgr (358db977c3247038eb58a81fddd2b58f) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 2010/09/07 09:47:19.0281 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 2010/09/07 09:47:19.0468 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 2010/09/07 09:47:19.0952 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 2010/09/07 09:47:20.0109 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 2010/09/07 09:47:20.0327 HTTP (c19b522a9ae0bbc3293397f3055e80a1) C:\WINDOWS\system32\Drivers\HTTP.sys 2010/09/07 09:47:20.0562 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 2010/09/07 09:47:20.0749 ialm (0acebb31989cbf9a5663fe4a33d28d21) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys 2010/09/07 09:47:21.0031 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 2010/09/07 09:47:21.0281 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 2010/09/07 09:47:21.0421 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 2010/09/07 09:47:21.0546 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 2010/09/07 09:47:21.0656 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 2010/09/07 09:47:21.0781 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 2010/09/07 09:47:21.0906 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 2010/09/07 09:47:22.0046 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 2010/09/07 09:47:22.0171 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 2010/09/07 09:47:22.0312 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 2010/09/07 09:47:22.0452 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 2010/09/07 09:47:22.0593 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 2010/09/07 09:47:22.0765 KSecDD (eb7ffe87fd367ea8fca0506f74a87fbb) C:\WINDOWS\system32\drivers\KSecDD.sys 2010/09/07 09:47:23.0046 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 2010/09/07 09:47:23.0171 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 2010/09/07 09:47:23.0296 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 2010/09/07 09:47:23.0484 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 2010/09/07 09:47:23.0624 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 2010/09/07 09:47:23.0765 MpFilter (c98301ad8173a2235a9ab828955c32bb) C:\WINDOWS\system32\DRIVERS\MpFilter.sys 2010/09/07 09:47:24.0015 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 2010/09/07 09:47:24.0202 MRxSmb (1fd607fc67f7f7c633c3da65bfc53d18) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 2010/09/07 09:47:24.0484 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 2010/09/07 09:47:24.0624 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 2010/09/07 09:47:24.0734 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 2010/09/07 09:47:24.0843 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 2010/09/07 09:47:24.0968 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 2010/09/07 09:47:25.0109 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 2010/09/07 09:47:25.0234 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 2010/09/07 09:47:25.0390 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 2010/09/07 09:47:25.0546 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 2010/09/07 09:47:25.0671 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 2010/09/07 09:47:25.0843 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 2010/09/07 09:47:25.0999 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 2010/09/07 09:47:26.0140 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 2010/09/07 09:47:26.0374 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 2010/09/07 09:47:26.0530 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 2010/09/07 09:47:26.0780 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 2010/09/07 09:47:26.0905 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 2010/09/07 09:47:26.0999 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 2010/09/07 09:47:27.0124 ossrv (103a9b117a7d9903111955cdafe65ac6) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys 2010/09/07 09:47:27.0327 P17 (df886ffed69aead0cf608b89b18c3f6f) C:\WINDOWS\system32\drivers\P17.sys 2010/09/07 09:47:27.0624 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 2010/09/07 09:47:27.0765 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 2010/09/07 09:47:27.0874 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 2010/09/07 09:47:28.0015 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 2010/09/07 09:47:28.0218 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 2010/09/07 09:47:28.0343 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys 2010/09/07 09:47:28.0812 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 2010/09/07 09:47:28.0905 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 2010/09/07 09:47:28.0999 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 2010/09/07 09:47:29.0108 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys 2010/09/07 09:47:29.0437 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 2010/09/07 09:47:29.0562 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 2010/09/07 09:47:29.0671 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 2010/09/07 09:47:29.0780 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 2010/09/07 09:47:29.0905 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 2010/09/07 09:47:30.0046 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 2010/09/07 09:47:30.0187 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 2010/09/07 09:47:30.0343 redbook (48d8301532e8cb0105d679feaf44a8f1) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/09/07 09:47:30.0343 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\redbook.sys. Real md5: 48d8301532e8cb0105d679feaf44a8f1, Fake md5: b15c974bcd20e607336e7d778c78819b 2010/09/07 09:47:30.0358 redbook - detected Rootkit.Win32.TDSS.tdl3 (0) 2010/09/07 09:47:30.0499 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS 2010/09/07 09:47:30.0671 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 2010/09/07 09:47:30.0827 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 2010/09/07 09:47:30.0921 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 2010/09/07 09:47:31.0030 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 2010/09/07 09:47:31.0296 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 2010/09/07 09:47:31.0421 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 2010/09/07 09:47:31.0593 Srv (20b7e396720353e4117d64d9dcb926ca) C:\WINDOWS\system32\DRIVERS\srv.sys 2010/09/07 09:47:31.0921 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 2010/09/07 09:47:32.0140 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 2010/09/07 09:47:32.0640 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 2010/09/07 09:47:32.0827 Tcpip (9f4b36614a0fc234525ba224957de55c) C:\WINDOWS\system32\DRIVERS\tcpip.sys 2010/09/07 09:47:32.0999 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 2010/09/07 09:47:33.0108 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 2010/09/07 09:47:33.0218 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 2010/09/07 09:47:33.0390 tmactmon (ca9e9c2c04a198ed345c1752222a5f3e) C:\WINDOWS\system32\drivers\tmactmon.sys 2010/09/07 09:47:33.0608 tmcfw (e5aa5bcb134d3ab03a8b56ddd728c37f) C:\WINDOWS\system32\DRIVERS\TM_CFW.sys 2010/09/07 09:47:34.0030 tmcomm (a3d20789b3ff0576a29462bef25bcfcc) C:\WINDOWS\system32\drivers\tmcomm.sys 2010/09/07 09:47:34.0374 tmevtmgr (21f215e54770c4bf93efaf63f58fe57e) C:\WINDOWS\system32\drivers\tmevtmgr.sys 2010/09/07 09:47:34.0499 TMPassthru (690acb48dac04e44a3d5e7654ca3260d) C:\WINDOWS\system32\DRIVERS\TMPassthru.sys 2010/09/07 09:47:34.0561 TMPassthruMP (690acb48dac04e44a3d5e7654ca3260d) C:\WINDOWS\system32\DRIVERS\TMPassthru.sys 2010/09/07 09:47:34.0686 tmpreflt (7aab3fef8b19ae023ee05386f1b0a5dd) C:\WINDOWS\system32\DRIVERS\tmpreflt.sys 2010/09/07 09:47:34.0874 tmtdi (1cf2f398e08592985a5bd1bbef59d043) C:\WINDOWS\system32\DRIVERS\tmtdi.sys 2010/09/07 09:47:35.0030 tmxpflt (1d84c335eb869bbe64543c6945a1f3c9) C:\WINDOWS\system32\DRIVERS\tmxpflt.sys 2010/09/07 09:47:35.0577 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 2010/09/07 09:47:35.0811 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 2010/09/07 09:47:36.0014 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 2010/09/07 09:47:36.0155 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 2010/09/07 09:47:36.0296 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 2010/09/07 09:47:36.0421 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 2010/09/07 09:47:36.0546 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 2010/09/07 09:47:36.0764 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 2010/09/07 09:47:36.0968 vsapint (8b9325c1d1167a703042986df758d799) C:\WINDOWS\system32\DRIVERS\vsapint.sys 2010/09/07 09:47:37.0374 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 2010/09/07 09:47:37.0593 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 2010/09/07 09:47:37.0843 ================================================================================ 2010/09/07 09:47:37.0843 Scan finished 2010/09/07 09:47:37.0843 ================================================================================ 2010/09/07 09:47:37.0874 Detected object count: 1 2010/09/07 09:50:43.0008 redbook (48d8301532e8cb0105d679feaf44a8f1) C:\WINDOWS\system32\DRIVERS\redbook.sys 2010/09/07 09:50:43.0024 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\redbook.sys. Real md5: 48d8301532e8cb0105d679feaf44a8f1, Fake md5: b15c974bcd20e607336e7d778c78819b 2010/09/07 09:50:44.0118 Backup copy found, using it.. 2010/09/07 09:50:44.0243 C:\WINDOWS\system32\DRIVERS\redbook.sys - will be cured after reboot 2010/09/07 09:50:44.0243 Rootkit.Win32.TDSS.tdl3(redbook) - User select action: Cure 2010/09/07 09:50:47.0508 Deinitialize success
Hi,

Please do the following:

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so.

NEXT

Using Internet Explorer or Firefox, visit Kaspersky Online Scanner:
1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Hello, I was able to do the first one but the second one provided me with this message: Launch of the Java application is interrupted! Please establish an uninterrupted Internet connection for work with this program. All of my virus protection is turned off. Here is the log from the first program: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4564 Windows 5.1.2600 Service Pack 2 Internet Explorer 6.0.2900.2180 9/7/2010 2:09:38 PM mbam-log-2010-09-07 (14-09-38).txt Scan type: Quick scan Objects scanned: 136575 Time elapsed: 9 minute(s), 52 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi

Try this scanner instead:


Go here to run an online scanner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.
Hi, Thanks again for all of your help. The computer seems to be running much better at this point, I followed your instructions and ESET produced the following log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=97309f603e75104aa47e6e1358307585 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-09-07 11:11:24 # local_time=2010-09-07 04:11:24 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5891 16776869 100 100 0 13400463 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=27032 # found=8 # cleaned=0 # scan_time=1202 C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP10\A0001297.dll a variant of Win32/Olmarik.ADC trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP11\A0002311.exe Win32/Sirefef.BJ trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP11\A0002313.exe a variant of Win32/Kryptik.GJE trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP11\A0002314.exe a variant of Win32/Kryptik.GJE trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP11\A0002569.dll a variant of Win32/Wimpixo.AA trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP17\A0009638.exe Win32/Spy.Zbot.YW trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP17\A0009651.exe Win32/Adware.SpywareProtect2009 application 00000000000000000000000000000000 I C:\System Volume Information\_restore{06DE7A17-E17A-4EF0-8BB0-CC39BF78F11B}\RP17\A0011923.dll a variant of Win32/Wimpixo.AA trojan 00000000000000000000000000000000 I
Hi

Please do the following:

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 18 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Sun Jave cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT

Please post a fresh DDS log and advise how the computer is running now and if there are any outstanding issues.
Hello, The computer seems to be running great. I really appreciate all of your help!! I followed your instructions and updated Java and then ran DDS. It produced the following and I attached the one that is labeled as such. Thanks again!! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 15:16:31.71 on Wed 09/08/2010 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.766.417 [GMT -7:00] AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\Rundll32.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\Program Files\Trend Micro\RUBotted\TMRUBottedTray.exe svchost.exe C:\Program Files\Trend Micro\RUBotted\TMRUBotted.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Documents and Settings\Owner\My Documents\Tech Help\dds.scr ============== Pseudo HJT Report =============== BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [P17Helper] Rundll32 P17.dll,P17Helper mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [TMRUBottedTray] "c:\program files\trend micro\rubotted\TMRUBottedTray.exe" StartupFolder: c:\docume~1\owner\startm~1\programs\startup\limewi~1.lnk - c:\program files\limewire\LimeWire.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1282855552375 DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Notify: igfxcui - igfxsrvc.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\mwc6uk45.default\ FF - prefs.js: network.proxy.type - 0 FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-3-25 151216] R2 RUBotted;Trend Micro RUBotted Service;c:\program files\trend micro\rubotted\TMRUBotted.exe [2010-8-31 582992] R3 TMPassthruMP;TMPassthruMP;c:\windows\system32\drivers\TMPassthru.sys [2010-8-31 206608] S3 TMPassthru;Trend Micro Passthru Ndis Service;c:\windows\system32\drivers\TMPassthru.sys [2010-8-31 206608] =============== Created Last 30 ================ 2010-09-08 22:13:06 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-09-07 23:29:12 0 d—–w- C:\17b5153ccd94472babde84f24e6481eb 2010-09-07 23:18:38 221184 —-a-w- c:\windows\system32\wmpns.dll 2010-09-07 22:48:19 0 d—–w- c:\program files\ESET 2010-09-07 20:58:28 0 d—–w- c:\docume~1\owner\applic~1\Malwarebytes 2010-09-07 20:58:04 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-07 20:57:56 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-09-07 20:57:54 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-09-07 20:57:51 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-09-07 17:28:38 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys 2010-09-07 17:28:38 272128 ——w- c:\windows\system32\drivers\bthport.sys 2010-09-07 17:27:43 454016 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys 2010-09-07 17:26:41 2143744 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe 2010-09-07 17:26:40 2186880 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe 2010-09-07 17:26:38 2021888 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe 2010-09-07 17:26:37 2063744 -c—-w- c:\windows\system32\dllcache\ntkrnlpa.exe 2010-09-03 00:50:53 0 dc-h–w- c:\windows\ie8 2010-09-03 00:48:56 0 d—–w- C:\1d20adaa294a784b656d0dff8797 2010-09-02 21:37:43 0 d-sha-r- C:\cmdcons 2010-09-02 21:35:52 98816 —-a-w- c:\windows\sed.exe 2010-09-02 21:35:52 77312 —-a-w- c:\windows\MBR.exe 2010-09-02 21:35:52 256512 —-a-w- c:\windows\PEV.exe 2010-09-02 21:35:52 161792 —-a-w- c:\windows\SWREG.exe 2010-09-01 22:19:49 0 d—–w- c:\windows\system32\LogFiles 2010-08-31 22:33:02 0 d—–w- c:\windows\system32\log 2010-08-31 22:29:02 0 d—–w- c:\docume~1\alluse~1\applic~1\Trend Micro 2010-08-31 21:36:59 206608 —-a-w- c:\windows\system32\drivers\TMPassthru.sys 2010-08-31 21:36:55 0 d—–w- c:\program files\Trend Micro 2010-08-31 21:33:17 0 d—–w- c:\documents and settings\owner\log 2010-08-31 16:57:21 0 d—–w- c:\windows\system32\wbem\Repository 2010-08-27 17:40:33 0 d—–w- c:\program files\IObit 2010-08-27 16:17:51 0 d—–w- c:\windows\ServicePackFiles 2010-08-27 00:56:14 0 d—–w- c:\program files\Mozilla Firefox(3) 2010-08-26 22:25:52 0 d—–w- c:\docume~1\owner\applic~1\LimeWire 2010-08-26 21:56:40 0 d—–w- c:\program files\Mozilla Firefox(2) 2010-08-26 21:12:38 0 d—–w- c:\windows\Logs 2010-08-26 21:12:26 0 d—–w- c:\program files\Winamp Detect 2010-08-26 21:11:29 0 d—–w- c:\windows\RegisteredPackages 2010-08-26 21:07:01 0 d—–w- c:\windows\pss 2010-08-26 21:05:25 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-08-26 21:03:12 0 d—–w- c:\program files\LimeWire 2010-08-26 20:56:18 221568 ——w- c:\windows\system32\MpSigStub.exe 2010-08-26 20:50:47 0 d—–w- c:\program files\Microsoft Security Essentials 2010-08-26 20:50:39 274288 —-a-w- c:\windows\system32\mucltui.dll 2010-08-26 20:50:39 215920 —-a-w- c:\windows\system32\muweb.dll 2010-08-26 20:50:39 16736 —-a-w- c:\windows\system32\mucltui.dll.mui 2010-08-26 20:48:46 26488 —-a-w- c:\windows\system32\spupdsvc.exe 2010-08-26 20:48:46 0 d—–w- c:\windows\system32\PreInstall 2010-08-26 20:46:15 21728 —-a-w- c:\windows\system32\wucltui.dll.mui 2010-08-26 20:46:15 17632 —-a-w- c:\windows\system32\wuaueng.dll.mui 2010-08-26 20:46:15 15072 —-a-w- c:\windows\system32\wuaucpl.cpl.mui 2010-08-26 20:46:15 0 d—–w- c:\windows\system32\SoftwareDistribution 2010-08-26 20:46:14 15064 —-a-w- c:\windows\system32\wuapi.dll.mui 2010-08-26 20:45:42 0 d-s—w- c:\documents and settings\owner\UserData 2010-08-26 20:43:06 584 —-a-w- c:\windows\system32\settingsbkup.sfm 2010-08-26 20:43:06 584 —-a-w- c:\windows\system32\settings.sfm 2010-08-26 20:39:56 75 —-a-w- c:\windows\system32\ctzapxx.ini 2010-08-26 20:39:56 5663 —-a-w- c:\windows\system32\ludap17.ini 2010-08-26 20:39:56 11264 —-a-w- c:\windows\INRES.DLL 2010-08-26 20:13:42 159744 —-a-w- c:\windows\system32\igfxres.dll 2010-08-26 19:47:14 0 d—–w- c:\program files\Broadcom 2010-08-26 19:44:26 0 d—–w- c:\program files\Creative 2010-08-26 19:29:14 0 d-sh–w- c:\documents and settings\all users\DRM 2010-08-26 19:28:50 0 d–h–w- c:\program files\WindowsUpdate 2010-08-26 19:27:51 0 d—–w- c:\program files\common files\MSSoap 2010-08-26 19:26:03 0 d—–w- c:\program files\Online Services 2010-08-26 19:25:57 0 d—–w- c:\program files\Messenger 2010-08-26 19:25:52 0 d—–w- c:\program files\MSN Gaming Zone 2010-08-26 19:25:04 0 d—–w- c:\program files\Windows NT 2010-08-26 12:19:54 0 d—–w- c:\program files\common files\ODBC 2010-08-26 12:19:50 0 d—–w- c:\program files\common files\SpeechEngines 2010-08-26 12:19:19 0 d—–r- c:\documents and settings\all users\Documents ==================== Find3M ==================== 2010-09-07 16:51:18 57472 —-a-w- c:\windows\system32\drivers\redbook.sys 2010-08-26 20:40:30 409600 —-a-w- c:\windows\system32\wrap_oal.dll 2010-08-26 20:40:30 114688 —-a-w- c:\windows\system32\OpenAL32.dll 2010-08-26 19:26:59 21640 —-a-w- c:\windows\system32\emptyregdb.dat ============= FINISH: 15:17:08.81 ===============

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI