This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search redirection

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am redirected from any search engine to strange sites when click on search results. I have tried Malware bytes and found nothing. Please help.

here is my hijack this log.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:56:55 PM, on 7/30/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Alban Towers\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} (VaioInfo.CMClass) - http://esupport.sony.com/VaioInfo.CAB
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe

–
End of file - 5851 bytes
Hello otisx and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Lets take a closer look at your machine with the following scans:


  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
      • IAT/EAT
      • Drives/Partition other than Systemdrive (typically C:\)
      • Show All (don't miss this one)
    • Then click the Scan button & wait for it to finish.
    • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
    • Save it where you can easily find it, such as your desktop, and post it in your reply.

    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


  • aswMBR


    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • Click the "Scan" button to start scan.

    [external image: Posted Image]

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    [external image: Posted Image]

    Please post the DDS logs, the GMER log and the aswMBR log in your next reply (you may need to make multiple posts to fit all of the information in).
Sorry took so long to reply. I do still need help. Here are the scan results.

dds
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 19:03:23 on 2011-08-03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.760.187 [GMT -4:00]
.
AV: Norton 360 *Disabled/Updated* {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Auto-Pilot\AutoPt.exe
C:\Program Files\Auto-Pilot\ObServer.exe
C:\Program Files\Auto-Pilot\AlarmsView.exe
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: NCO 2.0 IE BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\common files\symantec shared\coshared\browser\2.6\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\progra~1\common~1\symant~1\ids\IPSBHO.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Show Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\common files\symantec shared\coshared\browser\2.6\CoIEPlg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [ccApp] c:\program files\common files\symantec shared\ccApp.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {02CF1781-EA91-4FA5-A200-646E8241987C} - hxxp://esupport.sony.com/VaioInfo.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{CD2B10CB-6848-42EA-BAD0-593993E4D29A} : DhcpNameServer = [removed] [removed]
Notify: igfxcui - igfxsrvc.dll
.
============= SERVICES / DRIVERS ===============
.
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\common files\symantec shared\CCSVCHST.EXE [2008-2-18 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-30 105592]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20110803.001\NAVENG.SYS [2011-8-3 86008]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20110803.001\NAVEX15.SYS [2011-8-3 1542392]
R3 Symantec Core LC;Symantec Core LC;c:\progra~1\common~1\symant~1\ccpd-lc\symlcsvc.exe [2011-7-12 1245064]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-4 135664]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-7-30 366640]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2008-1-12 23888]
S3 EraserUtilDrv11113;EraserUtilDrv11113;\??\c:\program files\common files\symantec shared\eengine\eraserutildrv11113.sys –> c:\program files\common files\symantec shared\eengine\EraserUtilDrv11113.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-4 135664]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys –> c:\windows\system32\drivers\mbam.sys [?]
.
=============== Created Last 30 ================
.
2011-08-03 19:59:13 1915904 —-a-w- C:\aswMBR.exe
2011-08-02 21:10:55 607017 ——r- C:\dds.scr
2011-08-02 21:08:11 302592 —-a-w- C:\gmer.exe
2011-08-02 21:02:12 ——– d—–w- C:\gmer
2011-07-30 19:54:43 388608 —-a-w- C:\HiJackThis.exe
2011-07-30 16:38:27 ——– d-sha-r- C:\cmdcons
2011-07-30 16:33:26 208896 —-a-w- c:\windows\MBR.exe
2011-07-30 16:33:25 98816 —-a-w- c:\windows\sed.exe
2011-07-30 16:33:25 518144 —-a-w- c:\windows\SWREG.exe
2011-07-30 16:33:25 256000 —-a-w- c:\windows\PEV.exe
2011-07-30 16:31:48 ——– d—–w- C:\ComboFix
2011-07-30 16:10:39 4157735 ——r- C:\ComboFix.exe
2011-07-30 16:08:43 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-30 13:15:15 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-30 13:15:09 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-07-30 13:13:21 9466208 —-a-w- C:\mbam-setup-1.51.1.1800.exe
2011-07-15 21:18:07 ——– d—–w- c:\windows\pss
2011-07-12 19:07:17 ——– d—–w- c:\documents and settings\all users\application data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2011-07-12 18:04:18 ——– d—–w- c:\documents and settings\alban towers\application data\Symantec
2011-07-12 18:00:01 ——– d—–w- c:\program files\Norton 360
2011-07-12 17:58:28 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-07-12 17:58:28 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-12 17:58:10 ——– d—–w- c:\program files\Symantec
2011-07-12 17:58:10 ——– d—–w- c:\documents and settings\all users\application data\Symantec
2011-07-12 17:57:23 ——– d—–w- c:\program files\common files\Symantec Shared
2011-07-08 17:37:32 ——– d—–w- c:\documents and settings\alban towers\application data\Malwarebytes
2011-07-08 17:37:17 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
.
==================== Find3M ====================
.
2011-06-02 14:02:05 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-07 18:31:01 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-07 18:31:00 472808 —-a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 19:09:43.35 ===============


Attach.txt is added as attachment


Here is the GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-03 19:00:16
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD600BB-22DKA0 rev.77.07W77
Running: gmer.exe; Driver: C:\DOCUME~1\ALBANT~1\LOCALS~1\Temp\fwldrkob.sys


—- System - GMER 1.0.15 —-

SSDT 8245CD28 ZwAlertResumeThread
SSDT 82236AA8 ZwAlertThread
SSDT 82E7D9A0 ZwAllocateVirtualMemory
SSDT 82C903D8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xED6FA020]
SSDT 82BD3A28 ZwCreateMutant
SSDT 8232A750 ZwCreateThread
SSDT 820A4298 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xED6FA2A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xED6FA800]
SSDT 8233A168 ZwFreeVirtualMemory
SSDT 822C6608 ZwImpersonateAnonymousToken
SSDT 822F2B68 ZwImpersonateThread
SSDT 82001630 ZwMapViewOfSection
SSDT 8238DA10 ZwOpenEvent
SSDT 82349388 ZwOpenProcessToken
SSDT 8242AAF0 ZwOpenSection
SSDT 8216A2F8 ZwOpenThreadToken
SSDT 81FA0A28 ZwResumeThread
SSDT 824504F8 ZwSetContextThread
SSDT 82C15778 ZwSetInformationProcess
SSDT 8244CAD0 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xED6FAA50]
SSDT 81F89A48 ZwSuspendProcess
SSDT 823436F0 ZwSuspendThread
SSDT 822FEBA0 ZwTerminateProcess
SSDT 8213D840 ZwTerminateThread
SSDT 82B95F38 ZwUnmapViewOfSection
SSDT 82296168 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text KDCOM.DLL!KdSendPacket F7BD6345 6 Bytes [FA, 8D, 46, 01, 25, FF]
.text KDCOM.DLL!KdSendPacket F7BD634D 5 Bytes [80, 79, 07, 48, 0D]
.text KDCOM.DLL!KdSendPacket F7BD6353 29 Bytes [FF, FF, FF, 40, 0F, B6, F0, …]
.text KDCOM.DLL!KdSendPacket F7BD6371 28 Bytes [FF, FF, FF, 42, 0F, B6, FA, …]
.text KDCOM.DLL!KdD0Transition + 8 F7BD638E 17 Bytes [08, 03, 55, F8, 03, D8, 81, …]
.text KDCOM.DLL!KdD0Transition + 1A F7BD63A0 42 Bytes [FF, FF, FF, 43, 0F, B6, C3, …]
.text KDCOM.DLL!KdDebuggerInitialize0 + 25 F7BD63CB 6 Bytes [00, C9, C2, 08, 00, 55] {ADD CL, CL; RET 0x8; PUSH EBP}
.text KDCOM.DLL!KdDebuggerInitialize0 + 2C F7BD63D2 23 Bytes [EC, 83, C8, FF, 83, 7D, 08, …]
.text KDCOM.DLL!KdDebuggerInitialize0 + 44 F7BD63EA 162 Bytes [42, 5E, F6, C1, 01, 74, 0A, …]
.text KDCOM.DLL!KdRestore + 2D F7BD648D 1 Byte [43]
.text KDCOM.DLL!KdRestore + 2D F7BD648D 77 Bytes [43, 08, 89, 45, FC, 8B, 55, …]
.text KDCOM.DLL!KdRestore + 7C F7BD64DC 25 Bytes [C9, C2, 08, 00, 55, 8B, EC, …]
.text KDCOM.DLL!KdRestore + 97 F7BD64F7 21 Bytes [89, 06, 89, 46, 08, 89, 46, …]
.text KDCOM.DLL!KdRestore + 19F F7BD65FF 118 Bytes [68, 3B, 66, BD, F7, FF, 15, …]
.text …
PAGEKD KDCOM.DLL!KdReceivePacket + 2 F7BD6F4E 205 Bytes [F0, 8D, 45, FC, 50, 53, 56, …]
PAGEKD KDCOM.DLL!KdReceivePacket + D0 F7BD701C 2 Bytes [75, 0E] {JNZ 0x10}
PAGEKD KDCOM.DLL!KdReceivePacket + D3 F7BD701F 1 Byte [C0]
PAGEKD KDCOM.DLL!KdReceivePacket + D3 F7BD701F 103 Bytes [C0, 02, 83, C2, 02, 84, DB, …]
PAGEKD KDCOM.DLL!KdReceivePacket + 13B F7BD7087 131 Bytes [7D, 0C, B8, 4D, 5A, 00, 00, …]
PAGEKD …
? C:\DOCUME~1\ALBANT~1\LOCALS~1\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] WININET.dll!HttpAddRequestHeadersA 3D94CF4E 5 Bytes JMP 00B16840
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[472] WININET.dll!HttpAddRequestHeadersW 3D94FE49 5 Bytes JMP 00B16A4B
.text C:\Program Files\Internet Explorer\iexplore.exe[964] ntdll.dll!RtlValidateUnicodeString + 55E 7C916328 10 Bytes JMP 070A003A
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A91 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD0CD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] ole32.dll!CreateBindCtx + B5F 774FF14F 7 Bytes JMP 070A00F3
.text C:\Program Files\Internet Explorer\iexplore.exe[964] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB60 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] ole32.dll!CoImpersonateClient + 51 775151F0 7 Bytes JMP 070A01A9
.text C:\Program Files\Internet Explorer\iexplore.exe[964] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E5691 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WININET.dll!HttpAddRequestHeadersA 3D94CF4E 5 Bytes JMP 00B16840
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WININET.dll!HttpAddRequestHeadersW 3D94FE49 5 Bytes JMP 00B16A4B
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00C7000A
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C4000A
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 00C3000A
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C5000A
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00C6000A
.text C:\Program Files\Internet Explorer\iexplore.exe[964] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C2000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] ntdll.dll!RtlValidateUnicodeString + 55E 7C916328 10 Bytes JMP 0921003A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A91 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD0CD C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] ole32.dll!CreateBindCtx + B5F 774FF14F 7 Bytes JMP 092100F3
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] ole32.dll!CoCreateInstance 774FF1AC 5 Bytes JMP 3E2EDB60 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] ole32.dll!CoImpersonateClient + 51 775151F0 7 Bytes JMP 092101A9
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] ole32.dll!OleLoadFromStream 7752981B 5 Bytes JMP 3E3E5691 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00C3000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00C0000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 00BF000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00C1000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00C2000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00B5000A
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WININET.dll!HttpAddRequestHeadersA 3D94CF4E 5 Bytes JMP 00B16840
.text C:\Program Files\Internet Explorer\IEXPLORE.EXE[3132] WININET.dll!HttpAddRequestHeadersW 3D94FE49 5 Bytes JMP 00B16A4B
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2154C5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDB04 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E5329 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E525B C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E52C6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E512C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E518E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E538C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E51F0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WS2_32.dll!getaddrinfo 71AB2A6F 5 Bytes JMP 00CD000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WS2_32.dll!closesocket 71AB3E2B 5 Bytes JMP 00CA000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WS2_32.dll!connect 71AB4A07 5 Bytes JMP 00C9000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WS2_32.dll!send 71AB4C27 5 Bytes JMP 00CB000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WS2_32.dll!gethostbyname 71AB5355 5 Bytes JMP 00CC000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WS2_32.dll!recv 71AB676F 5 Bytes JMP 00C8000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WININET.dll!HttpAddRequestHeadersA 3D94CF4E 5 Bytes JMP 00B16840
.text C:\Program Files\Internet Explorer\iexplore.exe[3696] WININET.dll!HttpAddRequestHeadersW 3D94FE49 5 Bytes JMP 00B16A4B

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Threads - GMER 1.0.15 —-

Thread System [4:112] 82F380B3
Thread System [4:124] 82F397FB

—- Disk sectors - GMER 1.0.15 —-

Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <– ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior

—- EOF - GMER 1.0.15 —-



Here is the aswMBR
aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software
Run date: 2011-08-03 19:00:29
—————————–
19:00:29.046 OS Version: Windows 5.1.2600 Service Pack 3
19:00:29.046 Number of processors: 1 586 0x209
19:00:29.046 ComputerName: WEBB-N924XKXWG0 UserName: Alban Towers
19:00:30.656 Initialize success
19:01:17.343 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
19:01:17.343 Disk 0 Vendor: WDC_WD600BB-22DKA0 77.07W77 Size: 57241MB BusType: 3
19:01:17.406 Disk 0 MBR read successfully
19:01:17.406 Disk 0 MBR scan
19:01:17.406 Disk 0 TDL4@MBR code has been found
19:01:17.406 Disk 0 Windows XP default MBR code found via API
19:01:17.406 Disk 0 MBR hidden
19:01:17.406 Disk 0 MBR [TDL4] **ROOTKIT**
19:01:17.406 Disk 0 trace - called modules:
19:01:17.453 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82f35f16]<<
19:01:17.453 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f6fab8]
19:01:17.453 3 CLASSPNP.SYS[f7736fd7] -> nt!IofCallDriver -> \Device\0000006c[0x82f71f18]
19:01:17.453 5 ACPI.sys[f768d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82fcb940]
19:01:17.453 \Driver\atapi[0x82f81b30] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x82f35f16
19:01:17.984 Scan finished successfully
19:01:41.953 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
19:01:41.953 The log file has been saved successfully to "C:\aswMBR.txt"

Attachments:

Hello otisx

Thank you for the logs.

It looks as though you have an infected master boot record. Lets see if we can take care of it as follows:

  • aswMBR


  • Double click the aswMBR.exe to run it.
  • Click the "Scan" button to start scan.
  • Once the scan has completed, click on the FIX button.
  • Save the log as before and post it in your next reply.
I did it. Here is the log. aswMBR version 0.9.8.978 Copyright© 2011 AVAST Software Run date: 2011-08-04 16:34:36 —————————– 16:34:36.937 OS Version: Windows 5.1.2600 Service Pack 3 16:34:36.937 Number of processors: 1 586 0x209 16:34:36.937 ComputerName: WEBB-N924XKXWG0 UserName: Alban Towers 16:34:38.609 Initialize success 16:37:05.031 AVAST engine download error: 0 16:37:42.500 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 16:37:42.500 Disk 0 Vendor: WDC_WD600BB-22DKA0 77.07W77 Size: 57241MB BusType: 3 16:37:42.578 Disk 0 MBR read successfully 16:37:42.578 Disk 0 MBR scan 16:37:42.578 Disk 0 TDL4@MBR code has been found 16:37:42.578 Disk 0 Windows XP default MBR code found via API 16:37:42.578 Disk 0 MBR hidden 16:37:42.578 Disk 0 MBR [TDL4] **ROOTKIT** 16:37:42.578 Disk 0 trace - called modules: 16:37:42.609 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82f35f16]<< 16:37:42.609 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f6fab8] 16:37:42.609 3 CLASSPNP.SYS[f7736fd7] -> nt!IofCallDriver -> \Device\0000006c[0x82f71f18] 16:37:42.609 5 ACPI.sys[f768d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82fcb940] 16:37:43.125 \Driver\atapi[0x82f81b30] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x82f35f16 16:37:43.125 Scan finished successfully 16:38:08.015 Disk 0 MBR read successfully 16:38:08.015 Disk 0 TDL4@MBR code has been found 16:38:08.015 Disk 0 fixing MBR … 16:38:18.078 Disk 0 MBR restored successfully 16:38:18.109 Verifying disinfection 16:38:28.312 Infection fixed successfully - please reboot ASAP 16:38:50.156 Disk 0 MBR has been saved successfully to "C:\MBR.dat" 16:38:50.187 The log file has been saved successfully to "C:\aswMBR log2.txt"
Thank you very much JonTom this seems to have worked. I rebooted now search engines are normal again. Do you have any more recomendations as to preventing this type of infection from re-occuring? And should i get avast instead of norton 360. norton seems to be slowing this computer down.
Hello otisx

I rebooted now search engines are normal again

Thats great news but we still have more work to do.

We will deal with your choice of AV is due course but for now I would like you to do the following.

First, please scan with aswMBR and post the new log for me to review.

Second, I see that ComboFix has been run on this machine. ComboFix should never be used without appropriate supervision.

If you still have ComboFix installed on your machine please make sure that the executable (.exe file) is located on your desktop, disable all of your security applications and run the tool.

If you no longer have ComboFix on your machine download and run it using the following instructions:


  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the aswMBR log and the ComboFix log in your next reply.
Here is combofix log.

ComboFix 11-08-04.02 - Alban Towers 08/04/2011 17:32:57.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.760.363 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {A5F1BC7C-EA33-4247-961C-0217208396C4}
FW: Norton 360 *Enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\messenger\msmsgsin.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-07-04 to 2011-08-04 )))))))))))))))))))))))))))))))
.
.
2011-07-30 16:08 . 2011-07-30 16:08 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-30 13:15 . 2011-07-06 23:52 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-30 13:15 . 2011-07-30 13:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-07-30 13:13 . 2011-07-30 13:13 9466208 —-a-w- C:\mbam-setup-1.51.1.1800.exe
2011-07-12 19:07 . 2011-07-12 19:07 ——– dc—-w- c:\windows\system32\DRVSTORE
2011-07-12 19:07 . 2011-07-12 19:07 ——– d—–w- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2011-07-12 18:04 . 2011-07-22 19:40 ——– d—–w- c:\documents and settings\Alban Towers\Application Data\Symantec
2011-07-12 18:00 . 2011-07-12 18:00 ——– d—–w- c:\program files\Windows Sidebar
2011-07-12 18:00 . 2011-07-13 11:53 ——– d—–w- c:\program files\Norton 360
2011-07-12 17:58 . 2011-07-20 12:29 60808 —-a-w- c:\windows\system32\S32EVNT1.DLL
2011-07-12 17:58 . 2011-07-20 12:29 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-12 17:58 . 2011-07-26 20:46 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2011-07-12 17:58 . 2011-07-20 12:29 ——– d—–w- c:\program files\Symantec
2011-07-12 17:57 . 2011-08-04 20:44 ——– d—–w- c:\program files\Common Files\Symantec Shared
2011-07-08 17:37 . 2011-07-08 17:37 ——– d—–w- c:\documents and settings\Alban Towers\Application Data\Malwarebytes
2011-07-08 17:37 . 2011-07-08 17:37 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-02 21:01 . 2011-08-02 21:01 294216 —-a-w- C:\gmer.zip
2011-06-02 14:02 . 2001-08-23 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-05-07 18:31 . 2011-05-07 18:31 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-05-07 18:31 . 2011-05-07 18:31 472808 —-a-w- c:\windows\system32\deployJava1.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-07-30_17.09.38 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-04 20:44 . 2011-08-04 20:44 16384 c:\windows\Temp\Perflib_Perfdata_674.dat
+ 2011-08-04 20:43 . 2011-08-04 20:43 16384 c:\windows\Temp\Perflib_Perfdata_5cc.dat
+ 2011-08-01 05:39 . 2011-08-01 05:39 22016 c:\windows\Installer\737c2df.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-27 68856]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 21:10 35696 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2008-10-17 19:52 51048 —-a-w- c:\program files\Common Files\Symantec Shared\CCAPP.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2004-02-10 15:51 118784 —-a-w- c:\windows\system32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2002-12-10 00:19 188416 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2004-02-10 15:55 155648 —-a-w- c:\windows\system32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
2008-02-26 14:50 988512 —-a-w- c:\program files\Norton 360\osCheck.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2011-01-07 17:12 253672 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-12-27 16:40 68856 —-a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Auto-Pilot\\ObServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
.
R2 LiveUpdate Notice;LiveUpdate Notice;c:\program files\Common Files\Symantec Shared\CCSVCHST.EXE [2/18/2008 3:37 PM 149352]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/30/2011 7:23 AM 105592]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2010 9:03 AM 135664]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/30/2011 9:15 AM 366640]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 10:32 PM 23888]
S3 EraserUtilDrv11113;EraserUtilDrv11113;\??\c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11113.sys –> c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilDrv11113.sys [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2/4/2010 9:03 AM 135664]
S3 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys –> c:\windows\system32\drivers\mbam.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
.
2011-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 13:03]
.
2011-08-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-04 13:03]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
TCP: DhcpNameServer = [removed] [removed]
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-04 17:39
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-08-04 17:42:44
ComboFix-quarantined-files.txt 2011-08-04 21:42
ComboFix2.txt 2011-07-30 17:24
.
Pre-Run: 48,180,989,952 bytes free
Post-Run: 48,175,140,864 bytes free
.
- - End Of File - - 8020DC317822879C910DEFF74692E992
Hello otisx

Thank you for the log.

Lets take care of anything that may have been left behind with the following:

  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • MalwareBytes AntiMalware:


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please run the following scan


    • Note:Internet Explorer is preferred for this scan, although it will run with other browsers.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the MBAM and ESET logs in your next reply and let me know how the machine is running.
Thanks agaim JonTom I ran MBAM here is the log [No infections found] Malwarebytes' Anti-Malware 1.51.1.1800 www.malwarebytes.org Database version: 7390 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 8/5/2011 7:26:24 PM mbam-log-2011-08-05 (19-26-24).txt Scan type: Quick scan Objects scanned: 145607 Time elapsed: 18 minute(s), 10 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) No infection found on ESET either. I coould not produce a log so i am attaching a screenshot of the result

Attachments:

The Computer back to normal :clap: It is a old machine and a bit slow. So was wandering if i should change antivirus to something that uses less CPU Let me know if you have any recomenations on this. :D
Hello otisx

The Computer back to normal

Thats great news :)

Lets remove the tools we used in the steps below:

  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Removal of Tools

    • You no longer need DDS, GMER or aswMBR. Please delete them from your system.

  • Your Adobe Reader is out of date


    • You can obtain the latest version of Adobe Reader from here, and the latest version of Flash Player from here.
    • For more information and links to Adobe updates and downloads click here.

    Let me know if you have any recomenations on this

    You have Norton installed at the moment. Most security applications will draw heavily on system resources.

    The best thing to do would be to try a few applications and see which one runs well on your system (just install one at a time).

    I usually reccommend the following free AV programs:

  • Security programs


    • I have provided links to three trusted programs.




    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • You can download Firefox from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.
    • Please Note: IE9 is not configured to run on XP machines.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI