This is a read-only archive. No new posts or registrations. Privacy Page
Hardware

"Removed" XP Repair virus, no internet now, several non-plug

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

OS- Windows XP Media Center Edition SP3
PC- Dell Dimension E520, 160 GB Serial ATA hard drive
Network Interface-integrated 10/100 Ethernet
Modem-56K PCI


My PC was recently infected by the "WIndows XP Repair" virus. I received direction on another site about removal instructions and it appeared to work. However since getting my PC "working" I have not been able to get onto the internet and it is unclear if the virus was completely removed.

I am on a home LAN with the above PC, this laptop via wireless, and my XBOX 360 sharing the DSL connection. After initial virus "removal" the PC was the only thing that couldn't connect with a hardline although it showed a strong connection in it's properties. After several days with no response I did more research and learned that my TCP/IP was uninstalled. When I went into Device Manager "view hidden files" I had the following problems in the non-plug and play drivers:

TCP/IP Protocol Driver - Code 24 "Device not present, or does not have all it's drivers installed"
IPSEC Driver - Code 24
IP Network Address Translator - Code 24
MpKsI02752991 - Code 24
MpKsI6b04cb30 - Code 24
MpKsIc1be6d6a - Code 24

I have made the following attempts to fix the problem:

System Restore - Unable to restore to an earlier date (probably due to the virus)
Installed Superantispyware 5.0.1098 released that day (an upgrade) - Removed a few problems but no change in internet capabilities
In Device Manager: Scanned for hardware changes - No change. Troubleshoot/Add hardware wizard - none appear in categories
In Network Connection: Automatic Install TCP/IP - No change. Assigning static IP - No change
—-recurring problem here seems to be the need for the driver which I cannot find—-
TDSS Killer by Kapersky - Found same problem but failed to remove/cure it. Now finds nothing.
Microsoft "Fixit" TCP/IP reset - No change
Dell TCP/IP fix - No change
WinsockXPfix.exe - No change
Various Registry changes (Winsock, Winsock2) - No change
Windows File Protection (sfc scannow) - Constantly looks for XP Professional CD Rom dispite it being in the drive - No change
System Restore again - Successful restore back to before any registry changes were made but AFTER the initial problem.
RegCure - No change despite fixing over 1100 problems.

Problems remaining after initial malware "removal":

All of the above Non-plug and play driver errors
Cannot update Malwarebytes (with a copy saved to portable drive) or fully install Avast or AVG due to no internet.
Cannot do a System Restore earlier than initial infection
Cannot turn on Windows Firewall - "Windows Firewall settings could not be displayed because the associated service is not running. Do you want to start the Windows Firewall Sharing (ICS) service? Clicked "Yes" then "Windows cannot start the Windows Firewall/ICS service".

New Problems:

Cannot re-install newest version of Superantispyware since System Restored back to before it was installed. When the new version requires uninstall of the older one it won't do it. "Error reading uninstall data".
—–Weird because that's what seemed to fix System Restore in the first place.—-

XBox will now only work via a wireless connection. The hardline no longer works for Xbox or the BluRay player I had it connected to.

I have been thinking that my inability to get onto the internet may be the biggest problem, since updating Malwarebytes et al would most likely completely rid my PC of the XP Repair virus. Do you think the virus originated at the router? And if so what should I do for that? It also seems that all I need are the drivers. I have gone to Dell, Microsoft, and numerous other websites to try and locate the drivers to no avail. Do you know where I can download the drivers? Are they part of a bundle that's named something else/specific?

Here is the ComboFix log following the intial "removal" of the virus:

ComboFix 11-07-10.03 - Van Story n 07/10/11 13:32:28.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1569 [GMT -7:00]
Running from: I:\ComboFix.exe
AV: avast! Antivirus *Disabled/Outdated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\vb.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-06-10 to 2011-07-10 )))))))))))))))))))))))))))))))
.
.
2011-07-03 22:55 . 2011-05-10 12:03 307928 —-a-w- c:\windows\system32\drivers\aswSP.sys
2011-07-03 22:55 . 2011-05-10 11:59 19544 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2011-07-03 22:55 . 2011-05-10 12:03 441176 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2011-07-03 22:55 . 2011-05-10 12:02 49240 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2011-07-03 22:55 . 2011-05-10 11:59 25432 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2011-07-03 22:55 . 2011-05-10 12:02 102616 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2011-07-03 22:55 . 2011-05-10 12:02 96344 —-a-w- c:\windows\system32\drivers\aswmon.sys
2011-07-03 22:55 . 2011-05-10 11:59 30808 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2011-07-03 22:55 . 2011-05-10 12:10 40112 —-a-w- c:\windows\avastSS.scr
2011-07-03 22:55 . 2011-05-10 12:10 199304 —-a-w- c:\windows\system32\aswBoot.exe
2011-07-03 22:55 . 2011-07-03 22:55 ——– d—–w- c:\program files\AVAST Software
2011-07-03 22:55 . 2011-07-03 22:55 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2011-07-01 23:40 . 2011-07-02 07:46 ——– d—–w- C:\TDSSKiller_Quarantine
2011-07-01 21:10 . 2011-07-01 21:10 54016 —-a-w- c:\windows\system32\drivers\krks.sys
2011-07-01 19:10 . 2011-07-05 22:13 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-06-29 23:54 . 2011-06-29 23:54 248 —-a-w- c:\documents and settings\All Users\Application Data\123.vir
2011-06-29 23:54 . 2011-06-29 23:54 176 —-a-w- c:\documents and settings\All Users\Application Data\122.vir
2011-06-29 23:53 . 2011-06-29 23:53 336 —-a-w- c:\documents and settings\All Users\Application Data\124.vir
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-01 23:45 . 2004-08-04 05:08 59520 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-07-01 23:42 . 2005-08-16 10:18 384768 —-a-w- c:\windows\system32\drivers\update.sys
2011-07-01 23:38 . 2005-08-16 10:35 57600 —-a-w- c:\windows\system32\drivers\redbook.sys
2011-07-01 23:34 . 2005-08-16 10:18 574976 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-05-02 15:31 . 2005-08-16 10:40 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25 . 2005-08-16 10:18 151552 —-a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19 . 2006-11-08 04:04 456320 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11 . 2005-08-16 10:18 916480 —-a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11 . 2005-08-16 10:18 1469440 —-a-w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2011-04-21 13:37 . 2005-08-16 10:18 105472 —-a-w- c:\windows\system32\drivers\mup.sys
2011-03-22 08:17 . 2011-03-22 08:16 7734208 —-a-w- c:\program files\malwarebyte-setup-1.50.1.1100.exe
2011-03-10 18:51 . 2011-03-10 18:51 7866472 —-a-w- c:\program files\mseinstall.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2011-05-10 12:10 122512 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickCare"="c:\program files\Qwest\Quickcare\bin\sprtcmd.exe" [2010-01-16 206120]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-16 7323648]
"QwestTouchPointAgent"="c:\program files\Qwest\Desktop\QwestTouchPointAgent.exe" [2010-08-27 45992]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-30 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-05-10 3459712]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Yahoo!\\Yahoo! Music Jukebox\\YahooMusicEngine.exe"=
"c:\\Program Files\\BitLord\\BitLord.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\WildTangent\\Apps\\Dell Game Console\\GameConsole.exe"=
"c:\\Program Files\\Java\\jre1.6.0_01\\bin\\javaw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Qwest\\QuickConnect\\QuickConnect.exe"=
"c:\\Program Files\\Qwest\\Quickcare\\bin\\sprtcmd.exe"=
"c:\\Program Files\\Common Files\\Microsoft Shared\\DW\\DW20.EXE"=
"c:\\Program Files\\SUPERAntiSpyware\\SUPERAntiSpyware.exe"=
"c:\\WINDOWS\\system32\\dwwin.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/3/11 3:55 PM 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/3/11 3:55 PM 307928]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/10 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/10 11:41 AM 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/3/11 3:55 PM 19544]
R2 LogWatch;Event Log Watch;c:\program files\CA\SharedComponents\CA_LIC\LogWatNT.exe [2/23/05 3:56 PM 53248]
R2 sprtsvc_quickcare;SupportSoft Sprocket Service (quickcare);c:\program files\Qwest\Quickcare\bin\sprtsvc.exe [1/20/11 3:18 PM 206120]
R2 tgsrvc_quickcare;SupportSoft Repair Service (quickcare);c:\program files\Qwest\Quickcare\bin\tgsrvc.exe [1/20/11 3:18 PM 185640]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/06 6:19 PM 13592]
S1 MpKsl02752991;MpKsl02752991;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{717A2C0D-2704-4D4D-8EA5-CD256870EA70}\MpKsl02752991.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{717A2C0D-2704-4D4D-8EA5-CD256870EA70}\MpKsl02752991.sys [?]
S1 MpKsl6b04cb30;MpKsl6b04cb30;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9F0C3EDC-E183-47AE-BE53-E69B6723EBEE}\MpKsl6b04cb30.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{9F0C3EDC-E183-47AE-BE53-E69B6723EBEE}\MpKsl6b04cb30.sys [?]
S1 MpKslc1be6d6a;MpKslc1be6d6a;\??\c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D246A76F-A854-4B97-ACF5-916A92CB3961}\MpKslc1be6d6a.sys –> c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{D246A76F-A854-4B97-ACF5-916A92CB3961}\MpKslc1be6d6a.sys [?]
S2 sprtlisten;SupportSoft Listener Service;c:\program files\Common Files\supportsoft\bin\sprtlisten.exe [1/8/08 12:02 PM 1213728]
S3 CA_LIC_CLNT;CA License Client;c:\program files\CA\SharedComponents\CA_LIC\lic98rmt.exe [3/23/05 2:17 PM 126976]
S3 VVBETHERNET;Actiontec Gateway Service;c:\windows\system32\drivers\vvbeth.sys [11/16/06 7:22 PM 33411]
S3 vvbususb;Actiontec Gateway USB Service;c:\windows\system32\drivers\vvbususb.sys [11/16/06 7:18 PM 50911]
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-10 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 01:20]
.
2011-07-05 c:\windows\Tasks\QuickConnectSupportTask.job
- c:\program files\Qwest\QuickConnect\QuickConnect.exe [2009-02-10 21:36]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office10\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
IE: Yahoo! &SMS - file:///c:\program files\Yahoo!\Common/ycsms.htm
Trusted Zone: intuit.com\ttlc
TCP: DhcpNameServer = 192.168.0.1 [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-07-10 14:04
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.cdrom]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.ipsec]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\.ndiswan]
"ImagePath"="\*"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Enum\Root\*PNPe348\0000]
@DACL=(02 0000)
"Service"="1162959334"
"ClassGUID"="{4D36E97D-E325-11CE-BFC1-08002BE10318}"
"Class"="System"
"DeviceDesc"="PCI bus"
"Mfg"="Technologies Inc"
"LocationInformation"="on Microsoft ACPI-Compliant System"
"ConfigFlags"=dword:00000000
"Capabilities"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(476)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
Completion time: 2011-07-10 14:09:49
ComboFix-quarantined-files.txt 2011-07-10 21:09
ComboFix2.txt 2011-07-05 23:40
.
Pre-Run: 102,836,932,608 bytes free
Post-Run: 102,811,176,960 bytes free
.
- - End Of File - - 23E92D3FFCADC54644741DCFD7C064E6


I realize this is a TON of information and appreciate the amount of time and energy it would take to help me with this problem. Thank you VERY MUCH in advance!

Have a great day!

Alyssa
You've tried everything I can think of so I suggest doing a Repair Install.

Should leave all your data intact and most programs will still work though Anti-virus will definitely have to be reinstalled and some others maybe. Even though a Repair Install should not affect your data I would make sure I have a good, current backup of it just in case.

You must have a Windows Install disc to do this. If not, do you have a manufacturers recovery disc? If yes then you could use it to restore your computer to it's Factory Installed state. It's quite likely all your data and installed software will be lost doing this so a good backup is absolutely necessary.

One other thing you could try first is to download and run Dial-A-Fix.

Just run Dial-a-fix.exe, no install needed.
Click on the double green check mark at the bottom then click on GO.
Wait for it to complete.

Reboot and see what happens.
Hi Z, Thank you very much for your reply! I tried the Dial a fix and no luck. I am unsure as to what disk I have. It is called the "Reinstallation DVD" "Microsoft Windows XP Media Center Version 2005 with Update Rollup 2" by Dell. I guess it's the recovery disk but that seems crazy since its the only one I ever received. Nonetheless I have backed up the important stuff to an external drive so if I had to start over it wouldn't kill me. I just thought that it was a complex process that I'm not knowledgeable enough to do on my own. I will start the process but I am curious. When I installed combofix on my computer I had to use the Windows Recovery Console. And when I put the disk in it doesn't automatically bring up the blue screen to "boot from cd", it gives two choices to either start xp media edition or the recovery console. Will I need to fix this prior to using the disk? If so how do I do that? Thanks again, Alyssa
Please disregard the last. Out of sheer luck and the third go round looking…I found the resource CD with drivers and diagnostics tool. Unbelievable!!! I will report back if the problems are resolved. Thanks!
No, having XP and the Recovery Console as boot selections is okay.

I think with the CD you have you can do a Repair Install so I would try that. If for some reason that does not work or you are not given that option, follow these directions to do a Clean Install.

Clean Install- WhatTheTech
Clean Install - Michael Stevens Tech

I'm giving you two places to look at so you can get familiar with this before continuing. It's not difficult, you just need to follow directions. They are both very good.

Ask any questions here for Repair or Clean and I'll do my best to help.
Are you trying to do a normal boot or start the Repair Install? For normal boot, select XP. The Recovery Console is there for times when you need to do something that you can't do while XP is booted normally.
Well I attempted to do the repair but throughout the process it kept telling me there were files missing, and asking for the appropriate location to retrieve certain files. And since I didn't know I just clicked "ok" or "cancel". Now after repair has been "completed" it wont boot up the OS. Goes thorugh a loop of "we apologize but windows didn't start successfully…." and it wants to know what mode to startup in. When I indicate "start windows normally" it just eventually goes back into that same page. "safe mode" does the same thing. :( I can attempt another repair but it looks like I may be in over my head. What do you think? lol
When I run into this it's usually one of three things:

1. CD/DVD is dirty or scratched - you can try making a copy of it and see if that will install. SOmetimes a dirty/scratched CD/DVD disc will copy okay but doesn't work when you try to install from it.

I would recommend using ImgBurn to do this.
a. First you create an image file from the CD/DVD.
b. Then you create a new CD/DVD disc from the image file, burning at the lowest speed possible, usually 4X.
Once you start ImgBurn you will see buttons labeled Create Image File From Disc and Write Image File To Disc. It's pretty straight forward.

2. CD/DVD drive is dirty or defective.

3. Hard drive has a problem.

If #1 doesn't work for you I would recommend taking it to a reputable computer repair shop and having them do the Repair Install.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI