AlyssaV
Topic Starter
Hi,
OS- Windows XP Media Center Edition SP3
PC- Dell Dimension E520, 160 GB Serial ATA hard drive
Network Interface-integrated 10/100 Ethernet
Modem-56K PCI
My PC was recently infected by the "WIndows XP Repair" virus. I received direction on another site about removal instructions and it appeared to work. However since getting my PC "working" I have not been able to get onto the internet and it is unclear if the virus was completely removed.
I am on a home LAN with the above PC, this laptop via wireless, and my XBOX 360 sharing the DSL connection. After initial virus "removal" the PC was the only thing that couldn't connect with a hardline although it showed a strong connection in it's properties. After several days with no response I did more research and learned that my TCP/IP was uninstalled. When I went into Device Manager "view hidden files" I had the following problems in the non-plug and play drivers:
TCP/IP Protocol Driver - Code 24 "Device not present, or does not have all it's drivers installed"
IPSEC Driver - Code 24
IP Network Address Translator - Code 24
MpKsI02752991 - Code 24
MpKsI6b04cb30 - Code 24
MpKsIc1be6d6a - Code 24
I have made the following attempts to fix the problem:
System Restore - Unable to restore to an earlier date (probably due to the virus)
Installed Superantispyware 5.0.1098 released that day (an upgrade) - Removed a few problems but no change in internet capabilities
In Device Manager: Scanned for hardware changes - No change. Troubleshoot/Add hardware wizard - none appear in categories
In Network Connection: Automatic Install TCP/IP - No change. Assigning static IP - No change
—-recurring problem here seems to be the need for the driver which I cannot find—-
TDSS Killer by Kapersky - Found same problem but failed to remove/cure it. Now finds nothing.
Microsoft "Fixit" TCP/IP reset - No change
Dell TCP/IP fix - No change
WinsockXPfix.exe - No change
Various Registry changes (Winsock, Winsock2) - No change
Windows File Protection (sfc scannow) - Constantly looks for XP Professional CD Rom dispite it being in the drive - No change
System Restore again - Successful restore back to before any registry changes were made but AFTER the initial problem.
RegCure - No change despite fixing over 1100 problems.
Problems remaining after initial malware "removal":
All of the above Non-plug and play driver errors
Cannot update Malwarebytes (with a copy saved to portable drive) or fully install Avast or AVG due to no internet.
Cannot do a System Restore earlier than initial infection
Cannot turn on Windows Firewall - "Windows Firewall settings could not be displayed because the associated service is not running. Do you want to start the Windows Firewall Sharing (ICS) service? Clicked "Yes" then "Windows cannot start the Windows Firewall/ICS service".
New Problems:
Cannot re-install newest version of Superantispyware since System Restored back to before it was installed. When the new version requires uninstall of the older one it won't do it. "Error reading uninstall data".
—–Weird because that's what seemed to fix System Restore in the first place.—-
XBox will now only work via a wireless connection. The hardline no longer works for Xbox or the BluRay player I had it connected to.
I have been thinking that my inability to get onto the internet may be the biggest problem, since updating Malwarebytes et al would most likely completely rid my PC of the XP Repair virus. Do you think the virus originated at the router? And if so what should I do for that? It also seems that all I need are the drivers. I have gone to Dell, Microsoft, and numerous other websites to try and locate the drivers to no avail. Do you know where I can download the drivers? Are they part of a bundle that's named something else/specific?
Here is the ComboFix log following the intial "removal" of the virus:
ComboFix 11-07-10.03 - Van Story n 07/10/11 13:32:28.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1569 [GMT -7:00]
Running from: I:\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\vb.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-06-10 to 2011-07-10 )))))))))))))))))))))))))))))))
.
.
2011-07-03 22:55 . 2011-05-10 12:03 307928 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-03 22:55 . 2011-05-10 11:59 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-03 22:55 . 2011-05-10 12:03 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-03 22:55 . 2011-05-10 12:02 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-03 22:55 . 2011-05-10 11:59 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-03 22:55 . 2011-05-10 12:02 102616 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-07-03 22:55 . 2011-05-10 12:02 96344 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-07-03 22:55 . 2011-05-10 11:59 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-07-03 22:55 . 2011-05-10 12:10 40112 —-a-w- c:\windows\avastSS.scr
2011-07-03 22:55 . 2011-05-10 12:10 199304 —-a-w- c:\windows\system32\aswBoot.exe
2011-07-03 22:55 . 2011-07-03 22:55 ——– d—–w- c:\program files\AVAST Software
2011-07-03 22:55 . 2011-07-03 22:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-07-01 23:40 . 2011-07-02 07:46 ——– d—–w- C:\TDSSKiller_Quarantine
2011-07-01 21:10 . 2011-07-01 21:10 54016 —-a-w- c:\windows\system32\drivers\krks.sys
2011-07-01 19:10 . 2011-07-05 22:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-29 23:54 . 2011-06-29 23:54 248 —-a-w- c:\documents and settings\All Users\Application Data\123.vir
2011-06-29 23:54 . 2011-06-29 23:54 176 —-a-w- c:\documents and settings\All Users\Application Data\122.vir
2011-06-29 23:53 . 2011-06-29 23:53 336 —-a-w- c:\documents and settings\All Users\Application Data\124.vir
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-01 23:45 . 2004-08-04 05:08 59520 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-07-01 23:42 . 2005-08-16 10:18 384768 —-a-w- c:\windows\system32\drivers\update.sys
2011-07-01 23:38 . 2005-08-16 10:35 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2011-07-01 23:34 . 2005-08-16 10:18 574976 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-05-02 15:31 . 2005-08-16 10:40 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2005-08-16 10:18 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2006-11-08 04:04 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2005-08-16 10:18 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2005-08-16 10:18 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2005-08-16 10:18 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-03-22 08:17 . 2011-03-22 08:16 7734208 —-a-w- c:\program files\malwarebyte-setup-1.50.1.1100.exe
2011-03-10 18:51 . 2011-03-10 18:51 7866472 —-a-w- c:\program files\mseinstall.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickCare"="c:\program files\Qwest\Quickcare\bin\sprtcmd.exe" [2010-01-16 206120]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
"QwestTouchPointAgent"="c:\program files\Qwest\Desktop\QwestTouchPointAgent.exe" [2010-08-27 45992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\WildTangent\\Apps\\Dell Game Console\\GameConsole.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Qwest\\QuickConnect\\QuickConnect.exe"=
"c:\\Program Files\\Qwest\\Quickcare\\bin\\sprtcmd.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/3/11 3:55 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/3/11 3:55 PM 307928]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/10 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/10 11:41 AM 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/3/11 3:55 PM 19544]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2/23/05 3:56 PM 53248]
R2 sprtsvc_quickcare;SupportSoft Sprocket Service (quickcare);c:\program files\Qwest\Quickcare\bin\sprtsvc.exe [1/20/11 3:18 PM 206120]
R2 tgsrvc_quickcare;SupportSoft Repair Service (quickcare);c:\program files\Qwest\Quickcare\bin\tgsrvc.exe [1/20/11 3:18 PM 185640]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/06 6:19 PM 13592]
S1 MpKsl02752991;MpKsl02752991;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{717A2C0D-2704-4D4D-8EA5-CD256870EA70}\MpKsl02752991.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{717A2C0D-2704-4D4D-8EA5-CD256870EA70}\MpKsl02752991.sys [?]
S1 MpKsl6b04cb30;MpKsl6b04cb30;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9F0C3EDC-E183-47AE-BE53-E69B6723EBEE}\MpKsl6b04cb30.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9F0C3EDC-E183-47AE-BE53-E69B6723EBEE}\MpKsl6b04cb30.sys [?]
S1 MpKslc1be6d6a;MpKslc1be6d6a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D246A76F-A854-4B97-ACF5-916A92CB3961}\MpKslc1be6d6a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D246A76F-A854-4B97-ACF5-916A92CB3961}\MpKslc1be6d6a.sys [?]
S2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/08 12:02 PM 1213728]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [3/23/05 2:17 PM 126976]
S3 VVBETHERNET;Actiontec Gateway Service;c:\windows\system32\drivers\vvbeth.sys [11/16/06 7:22 PM 33411]
S3 vvbususb;Actiontec Gateway USB Service;c:\windows\system32\drivers\vvbususb.sys [11/16/06 7:18 PM 50911]
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
2011-07-05 c:\windows\Tasks\QuickConnectSupportTask.job
- c:\program files\Qwest\QuickConnect\QuickConnect.exe [2009-02-10 21:36]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 192.168.0.1 [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-10 14:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.cdrom]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.ipsec]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.ndiswan]
"ImagePath"="\*"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Enum\Root\*PNPe348\0000]
@DACL=(02 0000)
"Service"="1162959334"
"ClassGUID"="{4D36E97D-E325-11CE-BFC1-08002BE10318}"
"Class"="System"
"DeviceDesc"="PCI bus"
"Mfg"="Technologies Inc"
"LocationInformation"="on Microsoft ACPI-Compliant System"
"ConfigFlags"=dword:00000000
"Capabilities"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(476)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-07-10 14:09:49
ComboFix-quarantined-files.txt 2011-07-10 21:09
ComboFix2.txt 2011-07-05 23:40
.
Pre-Run: 102,836,932,608 bytes free
Post-Run: 102,811,176,960 bytes free
.
- - End Of File - - 23E92D3FFCADC54644741DCFD7C064E6
I realize this is a TON of information and appreciate the amount of time and energy it would take to help me with this problem. Thank you VERY MUCH in advance!
Have a great day!
Alyssa
OS- Windows XP Media Center Edition SP3
PC- Dell Dimension E520, 160 GB Serial ATA hard drive
Network Interface-integrated 10/100 Ethernet
Modem-56K PCI
My PC was recently infected by the "WIndows XP Repair" virus. I received direction on another site about removal instructions and it appeared to work. However since getting my PC "working" I have not been able to get onto the internet and it is unclear if the virus was completely removed.
I am on a home LAN with the above PC, this laptop via wireless, and my XBOX 360 sharing the DSL connection. After initial virus "removal" the PC was the only thing that couldn't connect with a hardline although it showed a strong connection in it's properties. After several days with no response I did more research and learned that my TCP/IP was uninstalled. When I went into Device Manager "view hidden files" I had the following problems in the non-plug and play drivers:
TCP/IP Protocol Driver - Code 24 "Device not present, or does not have all it's drivers installed"
IPSEC Driver - Code 24
IP Network Address Translator - Code 24
MpKsI02752991 - Code 24
MpKsI6b04cb30 - Code 24
MpKsIc1be6d6a - Code 24
I have made the following attempts to fix the problem:
System Restore - Unable to restore to an earlier date (probably due to the virus)
Installed Superantispyware 5.0.1098 released that day (an upgrade) - Removed a few problems but no change in internet capabilities
In Device Manager: Scanned for hardware changes - No change. Troubleshoot/Add hardware wizard - none appear in categories
In Network Connection: Automatic Install TCP/IP - No change. Assigning static IP - No change
—-recurring problem here seems to be the need for the driver which I cannot find—-
TDSS Killer by Kapersky - Found same problem but failed to remove/cure it. Now finds nothing.
Microsoft "Fixit" TCP/IP reset - No change
Dell TCP/IP fix - No change
WinsockXPfix.exe - No change
Various Registry changes (Winsock, Winsock2) - No change
Windows File Protection (sfc scannow) - Constantly looks for XP Professional CD Rom dispite it being in the drive - No change
System Restore again - Successful restore back to before any registry changes were made but AFTER the initial problem.
RegCure - No change despite fixing over 1100 problems.
Problems remaining after initial malware "removal":
All of the above Non-plug and play driver errors
Cannot update Malwarebytes (with a copy saved to portable drive) or fully install Avast or AVG due to no internet.
Cannot do a System Restore earlier than initial infection
Cannot turn on Windows Firewall - "Windows Firewall settings could not be displayed because the associated service is not running. Do you want to start the Windows Firewall Sharing (ICS) service? Clicked "Yes" then "Windows cannot start the Windows Firewall/ICS service".
New Problems:
Cannot re-install newest version of Superantispyware since System Restored back to before it was installed. When the new version requires uninstall of the older one it won't do it. "Error reading uninstall data".
—–Weird because that's what seemed to fix System Restore in the first place.—-
XBox will now only work via a wireless connection. The hardline no longer works for Xbox or the BluRay player I had it connected to.
I have been thinking that my inability to get onto the internet may be the biggest problem, since updating Malwarebytes et al would most likely completely rid my PC of the XP Repair virus. Do you think the virus originated at the router? And if so what should I do for that? It also seems that all I need are the drivers. I have gone to Dell, Microsoft, and numerous other websites to try and locate the drivers to no avail. Do you know where I can download the drivers? Are they part of a bundle that's named something else/specific?
Here is the ComboFix log following the intial "removal" of the virus:
ComboFix 11-07-10.03 - Van Story n 07/10/11 13:32:28.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1569 [GMT -7:00]
Running from: I:\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\vb.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-06-10 to 2011-07-10 )))))))))))))))))))))))))))))))
.
.
2011-07-03 22:55 . 2011-05-10 12:03 307928 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-03 22:55 . 2011-05-10 11:59 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-03 22:55 . 2011-05-10 12:03 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-03 22:55 . 2011-05-10 12:02 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-03 22:55 . 2011-05-10 11:59 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-03 22:55 . 2011-05-10 12:02 102616 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-07-03 22:55 . 2011-05-10 12:02 96344 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-07-03 22:55 . 2011-05-10 11:59 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-07-03 22:55 . 2011-05-10 12:10 40112 —-a-w- c:\windows\avastSS.scr
2011-07-03 22:55 . 2011-05-10 12:10 199304 —-a-w- c:\windows\system32\aswBoot.exe
2011-07-03 22:55 . 2011-07-03 22:55 ——– d—–w- c:\program files\AVAST Software
2011-07-03 22:55 . 2011-07-03 22:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-07-01 23:40 . 2011-07-02 07:46 ——– d—–w- C:\TDSSKiller_Quarantine
2011-07-01 21:10 . 2011-07-01 21:10 54016 —-a-w- c:\windows\system32\drivers\krks.sys
2011-07-01 19:10 . 2011-07-05 22:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-29 23:54 . 2011-06-29 23:54 248 —-a-w- c:\documents and settings\All Users\Application Data\123.vir
2011-06-29 23:54 . 2011-06-29 23:54 176 —-a-w- c:\documents and settings\All Users\Application Data\122.vir
2011-06-29 23:53 . 2011-06-29 23:53 336 —-a-w- c:\documents and settings\All Users\Application Data\124.vir
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-01 23:45 . 2004-08-04 05:08 59520 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-07-01 23:42 . 2005-08-16 10:18 384768 —-a-w- c:\windows\system32\drivers\update.sys
2011-07-01 23:38 . 2005-08-16 10:35 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2011-07-01 23:34 . 2005-08-16 10:18 574976 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-05-02 15:31 . 2005-08-16 10:40 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2005-08-16 10:18 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2006-11-08 04:04 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2005-08-16 10:18 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2005-08-16 10:18 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2005-08-16 10:18 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-03-22 08:17 . 2011-03-22 08:16 7734208 —-a-w- c:\program files\malwarebyte-setup-1.50.1.1100.exe
2011-03-10 18:51 . 2011-03-10 18:51 7866472 —-a-w- c:\program files\mseinstall.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickCare"="c:\program files\Qwest\Quickcare\bin\sprtcmd.exe" [2010-01-16 206120]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
"QwestTouchPointAgent"="c:\program files\Qwest\Desktop\QwestTouchPointAgent.exe" [2010-08-27 45992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\WildTangent\\Apps\\Dell Game Console\\GameConsole.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Qwest\\QuickConnect\\QuickConnect.exe"=
"c:\\Program Files\\Qwest\\Quickcare\\bin\\sprtcmd.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/3/11 3:55 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/3/11 3:55 PM 307928]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/10 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/10 11:41 AM 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/3/11 3:55 PM 19544]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2/23/05 3:56 PM 53248]
R2 sprtsvc_quickcare;SupportSoft Sprocket Service (quickcare);c:\program files\Qwest\Quickcare\bin\sprtsvc.exe [1/20/11 3:18 PM 206120]
R2 tgsrvc_quickcare;SupportSoft Repair Service (quickcare);c:\program files\Qwest\Quickcare\bin\tgsrvc.exe [1/20/11 3:18 PM 185640]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/06 6:19 PM 13592]
S1 MpKsl02752991;MpKsl02752991;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{717A2C0D-2704-4D4D-8EA5-CD256870EA70}\MpKsl02752991.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{717A2C0D-2704-4D4D-8EA5-CD256870EA70}\MpKsl02752991.sys [?]
S1 MpKsl6b04cb30;MpKsl6b04cb30;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9F0C3EDC-E183-47AE-BE53-E69B6723EBEE}\MpKsl6b04cb30.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9F0C3EDC-E183-47AE-BE53-E69B6723EBEE}\MpKsl6b04cb30.sys [?]
S1 MpKslc1be6d6a;MpKslc1be6d6a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D246A76F-A854-4B97-ACF5-916A92CB3961}\MpKslc1be6d6a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D246A76F-A854-4B97-ACF5-916A92CB3961}\MpKslc1be6d6a.sys [?]
S2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/08 12:02 PM 1213728]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [3/23/05 2:17 PM 126976]
S3 VVBETHERNET;Actiontec Gateway Service;c:\windows\system32\drivers\vvbeth.sys [11/16/06 7:22 PM 33411]
S3 vvbususb;Actiontec Gateway USB Service;c:\windows\system32\drivers\vvbususb.sys [11/16/06 7:18 PM 50911]
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
2011-07-05 c:\windows\Tasks\QuickConnectSupportTask.job
- c:\program files\Qwest\QuickConnect\QuickConnect.exe [2009-02-10 21:36]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 192.168.0.1 [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-10 14:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.cdrom]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.ipsec]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.ndiswan]
"ImagePath"="\*"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Enum\Root\*PNPe348\0000]
@DACL=(02 0000)
"Service"="1162959334"
"ClassGUID"="{4D36E97D-E325-11CE-BFC1-08002BE10318}"
"Class"="System"
"DeviceDesc"="PCI bus"
"Mfg"="Technologies Inc"
"LocationInformation"="on Microsoft ACPI-Compliant System"
"ConfigFlags"=dword:00000000
"Capabilities"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(476)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-07-10 14:09:49
ComboFix-quarantined-files.txt 2011-07-10 21:09
ComboFix2.txt 2011-07-05 23:40
.
Pre-Run: 102,836,932,608 bytes free
Post-Run: 102,811,176,960 bytes free
.
- - End Of File - - 23E92D3FFCADC54644741DCFD7C064E6
I realize this is a TON of information and appreciate the amount of time and energy it would take to help me with this problem. Thank you VERY MUCH in advance!
Have a great day!
Alyssa