This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Think my PC is Infected with malware

75 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,Yesterday Advanced windows Cleaner found something called Trojan Agent.Win32 or something and It seemingly removed it. However,My PC has been performing strangely and my internet has been very slow. After numerous virus scans that found nothing I ran two rootkit scanners,one was TDSS and I copied 4 risk items to my kaspersky quarantine but can't find them in my quarantine folder :unsure: The other rootkit scanner I ran was rootkit repealer which I did'nt use other than saved a copy of the txt as it had two hidden items in it. I scanned with DDS : . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 21:21:29.42 on 17/10/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2814 [GMT 1:00] . AV: Kaspersky Internet Security *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe C:\Program Files\HostsMan\hm.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe C:\WINDOWS\system32\svchost.exe -k imgsvc svchost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\Allyc\Desktop\Downloads\dds.scr . ============== Pseudo HJT Report =============== . mStart Page = about:blank BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll uRun: [HostsMan] "c:\program files\hostsman\hm.exe" -s mRun: [RTHDCPL] RTHDCPL.EXE mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2012\avp.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2012\ie_banner_deny.htm IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {C2A80015-C447-4dc4-82DD-AED83D6ED57E} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1307033399078 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: klogon - c:\windows\system32\klogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\allyc\applic~1\mozilla\firefox\profiles\kesbenv4.default\ FF - prefs.js: browser.startup.homepage - hxxp://uk.yahoo.com/ FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll . —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: browser.chrome.favicons - true FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: browser.xul.error_pages.enabled - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 8191 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 750000 FF - user.js: content.notify.ontimer - true FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 750000 FF - user.js: network.http.max-connections - 32 FF - user.js: network.http.max-connections-per-server - 8 FF - user.js: network.http.max-persistent-connections-per-proxy - 8 FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 0 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . ============= SERVICES / DRIVERS =============== . R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2011-3-4 133208] R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2011-10-3 11448] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2011-3-4 11352] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-8-5 565552] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-5-4 116608] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-6-2 328536] R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2012\avp.exe [2011-4-24 202296] R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-7-16 35088] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2011-3-10 34608] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472] R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2011-6-3 580480] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-10-17 13:19:05 ——– d—–w- C:\TDSSKiller_Quarantine 2011-10-17 04:29:11 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-10-16 19:48:52 ——– d—–w- c:\program files\ESET 2011-10-14 11:50:10 9078960 —-a-w- c:\windows\system32\mkl_p4p.dll 2011-10-14 11:50:09 9410736 —-a-w- c:\windows\system32\mkl_p4m.dll 2011-10-14 11:50:09 9210032 —-a-w- c:\windows\system32\mkl_p4.dll 2011-10-14 11:50:09 9033904 —-a-w- c:\windows\system32\mkl_p4m3.dll 2011-10-14 11:50:09 3868848 —-a-w- c:\windows\system32\mkl_intel_thread.dll 2011-10-14 11:50:08 6944944 —-a-w- c:\windows\system32\mkl_core.dll 2011-10-14 11:50:08 530608 —-a-w- c:\windows\system32\libiomp5md.dll 2011-10-14 11:49:44 499712 —-a-w- c:\windows\msvcp71.dll 2011-10-14 11:49:44 348160 —-a-w- c:\windows\msvcr71.dll 2011-10-14 11:49:44 ——– d—–w- c:\program files\Steinberg 2011-10-14 11:49:29 ——– d—–w- c:\program files\VstPlugIns 2011-10-14 11:49:29 ——– d—–w- c:\program files\IK Multimedia 2011-10-14 10:40:41 ——– d—–w- c:\docume~1\allyc\applic~1\IK Multimedia 2011-10-14 08:30:03 ——– d—–w- c:\program files\WinPcap 2011-10-14 08:24:25 65602 —-a-w- c:\windows\system32\cook3260.dll 2011-10-14 08:24:25 626688 —-a-w- c:\windows\system32\vp7vfw.dll 2011-10-14 08:24:25 217127 —-a-w- c:\windows\system32\drv43260.dll 2011-10-14 08:24:25 208935 —-a-w- c:\windows\system32\drv33260.dll 2011-10-14 08:24:25 176165 —-a-w- c:\windows\system32\drv23260.dll 2011-10-14 08:24:25 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll 2011-10-14 08:24:25 102439 —-a-w- c:\windows\system32\sipr3260.dll 2011-10-06 02:36:34 ——– d—–w- c:\program files\CCleaner 2011-10-04 01:51:24 ——– d—–w- c:\program files\TweakNow RegCleaner 2011 2011-10-04 01:51:24 ——– d—–w- c:\docume~1\allyc\applic~1\TweakNow RegCleaner 2011 2011-10-03 09:12:57 11448 —-a-w- c:\windows\system32\drivers\AsUpIO.sys 2011-10-03 09:12:46 24576 —-a-w- c:\windows\system32\AsIO.dll 2011-10-03 09:12:46 11296 —-a-w- c:\windows\system32\drivers\AsIO.sys 2011-10-03 09:12:41 ——– d—–w- c:\program files\ASUS 2011-09-30 03:37:17 ——– d—–w- c:\program files\VideoLAN 2011-09-30 03:16:11 ——– d–h–w- c:\windows\msdownld.tmp 2011-09-30 03:15:44 ——– d—–w- c:\program files\Essentials Codec Pack 2011-09-30 03:14:59 ——– d—–w- c:\docume~1\allyc\applic~1\Nullsoft 2011-09-24 10:50:25 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-24 10:41:28 ——– d—–w- c:\docume~1\allyc\locals~1\applic~1\Solid State Networks 2011-09-20 06:33:08 ——– d—–w- c:\program files\Free Download Manager 2011-09-20 06:33:08 ——– d—–w- c:\docume~1\alluse~1\applic~1\FreeDownloadManager.ORG 2011-09-18 15:47:06 73728 —-a-w- c:\windows\system32\javacpl.cpl . ==================== Find3M ==================== . 2011-10-16 15:08:13 32 —-a-w- c:\windows\system32\msvcsv60.dll 2011-10-14 08:24:32 87608 —-a-w- c:\docume~1\allyc\applic~1\inst.exe 2011-10-14 08:24:32 47360 —-a-w- c:\docume~1\allyc\applic~1\pcouffin.sys 2011-09-26 10:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 10:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 10:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-18 15:46:53 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys 2011-08-22 23:48:55 916480 —-a-w- c:\windows\system32\wininet.dll 2011-08-22 23:48:54 43520 ——w- c:\windows\system32\licmgr10.dll 2011-08-22 23:48:54 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-08-22 11:56:39 385024 ——w- c:\windows\system32\html.iec 2011-07-28 19:54:24 947472 —-a-w- c:\windows\system32\msjava.dll 2011-07-26 20:57:54 1060864 —-a-w- c:\windows\system32\mfc71.dll 2011-07-26 20:57:53 1700352 —-a-w- c:\windows\system32\gdiplus.dll . ============= FINISH: 21:22:03.85 =============== Any help would be great thanks! PS here is my rootrepeal txt > ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2011/10/17 14:20 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: 74UbaPx6.sys Image Path: C:\DOCUME~1\Allyc\LOCALS~1\Temp\74UbaPx6.sys Address: 0xAA43E000 Size: 206208 File Visible: No Signed: - Status: - Name: ACPI.sys Image Path: ACPI.sys Address: 0xF7358000 Size: 187776 File Visible: - Signed: - Status: - Name: ACPI_HAL Image Path: \Driver\ACPI_HAL Address: 0x804D7000 Size: 2154496 File Visible: - Signed: - Status: - Name: afd.sys Image Path: C:\WINDOWS\System32\drivers\afd.sys Address: 0xAE01B000 Size: 138496 File Visible: - Signed: - Status: - Name: ASACPI.sys Image Path: C:\WINDOWS\system32\DRIVERS\ASACPI.sys Address: 0xF798D000 Size: 5152 File Visible: - Signed: - Status: - Name: AsIO.sys Image Path: C:\WINDOWS\system32\drivers\AsIO.sys Address: 0xF7BBB000 Size: 4000 File Visible: - Signed: - Status: - Name: AsUpIO.sys Image Path: C:\WINDOWS\system32\drivers\AsUpIO.sys Address: 0xF79B9000 Size: 4224 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0xF7310000 Size: 96512 File Visible: - Signed: - Status: - Name: atapi.sys Image Path: atapi.sys Address: 0xF7310000 Size: 96512 File Visible: - Signed: - Status: Hidden from the Windows API! Name: ati2cqag.dll Image Path: C:\WINDOWS\System32\ati2cqag.dll Address: 0xBF060000 Size: 704512 File Visible: - Signed: - Status: - Name: ati2dvag.dll Image Path: C:\WINDOWS\System32\ati2dvag.dll Address: 0xBF012000 Size: 319488 File Visible: - Signed: - Status: - Name: ati2mtag.sys Image Path: C:\WINDOWS\system32\DRIVERS\ati2mtag.sys Address: 0xF66C3000 Size: 5406720 File Visible: - Signed: - Status: - Name: ati3duag.dll Image Path: C:\WINDOWS\System32\ati3duag.dll Address: 0xBF20E000 Size: 3870720 File Visible: - Signed: - Status: - Name: AtiHdmi.sys Image Path: C:\WINDOWS\system32\drivers\AtiHdmi.sys Address: 0xF6417000 Size: 114688 File Visible: - Signed: - Status: - Name: atikvmag.dll Image Path: C:\WINDOWS\System32\atikvmag.dll Address: 0xBF10C000 Size: 643072 File Visible: - Signed: - Status: - Name: atiok3x2.dll Image Path: C:\WINDOWS\System32\atiok3x2.dll Address: 0xBF1A9000 Size: 413696 File Visible: - Signed: - Status: - Name: ativvaxx.dll Image Path: C:\WINDOWS\System32\ativvaxx.dll Address: 0xBF5BF000 Size: 2277376 File Visible: - Signed: - Status: - Name: ATMFD.DLL Image Path: C:\WINDOWS\System32\ATMFD.DLL Address: 0xBF9C6000 Size: 290816 File Visible: - Signed: - Status: - Name: audstub.sys Image Path: C:\WINDOWS\system32\DRIVERS\audstub.sys Address: 0xF7B2C000 Size: 3072 File Visible: - Signed: - Status: - Name: Beep.SYS Image Path: C:\WINDOWS\System32\Drivers\Beep.SYS Address: 0xF79AB000 Size: 4224 File Visible: - Signed: - Status: - Name: BOOTVID.dll Image Path: C:\WINDOWS\system32\BOOTVID.dll Address: 0xF7897000 Size: 12288 File Visible: - Signed: - Status: - Name: Cdfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Cdfs.SYS Address: 0xF653B000 Size: 63744 File Visible: - Signed: - Status: - Name: cdrom.sys Image Path: C:\WINDOWS\system32\DRIVERS\cdrom.sys Address: 0xF7537000 Size: 62976 File Visible: - Signed: - Status: - Name: CLASSPNP.SYS Image Path: C:\WINDOWS\system32\DRIVERS\CLASSPNP.SYS Address: 0xF74C7000 Size: 53248 File Visible: - Signed: - Status: - Name: disk.sys Image Path: disk.sys Address: 0xF74B7000 Size: 36352 File Visible: - Signed: - Status: - Name: drmk.sys Image Path: C:\WINDOWS\system32\drivers\drmk.sys Address: 0xF7617000 Size: 61440 File Visible: - Signed: - Status: - Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xADDB6000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF79C5000 Size: 8192 File Visible: No Signed: - Status: - Name: dwprot.sys Image Path: C:\WINDOWS\system32\drivers\dwprot.sys Address: 0xAA471000 Size: 140800 File Visible: No Signed: - Status: - Name: Dxapi.sys Image Path: C:\WINDOWS\System32\drivers\Dxapi.sys Address: 0xAE294000 Size: 12288 File Visible: - Signed: - Status: - Name: dxg.sys Image Path: C:\WINDOWS\System32\drivers\dxg.sys Address: 0xBF000000 Size: 73728 File Visible: - Signed: - Status: - Name: dxgthk.sys Image Path: C:\WINDOWS\System32\drivers\dxgthk.sys Address: 0xF7B08000 Size: 4096 File Visible: - Signed: - Status: - Name: Fips.SYS Image Path: C:\WINDOWS\System32\Drivers\Fips.SYS Address: 0xF76A7000 Size: 44544 File Visible: - Signed: - Status: - Name: fltmgr.sys Image Path: fltmgr.sys Address: 0xF72F0000 Size: 129792 File Visible: - Signed: - Status: - Name: Fs_Rec.SYS Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS Address: 0xF79A7000 Size: 7936 File Visible: - Signed: - Status: - Name: ftdisk.sys Image Path: ftdisk.sys Address: 0xF7328000 Size: 125056 File Visible: - Signed: - Status: - Name: hal.dll Image Path: C:\WINDOWS\system32\hal.dll Address: 0x806E5000 Size: 134400 File Visible: - Signed: - Status: - Name: HDAudBus.sys Image Path: C:\WINDOWS\system32\DRIVERS\HDAudBus.sys Address: 0xF6BEB000 Size: 163840 File Visible: - Signed: - Status: - Name: HIDCLASS.SYS Image Path: C:\WINDOWS\system32\DRIVERS\HIDCLASS.SYS Address: 0xF76C7000 Size: 36864 File Visible: - Signed: - Status: - Name: HIDPARSE.SYS Image Path: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS Address: 0xF784F000 Size: 28672 File Visible: - Signed: - Status: - Name: hidusb.sys Image Path: C:\WINDOWS\system32\DRIVERS\hidusb.sys Address: 0xF6465000 Size: 10368 File Visible: - Signed: - Status: - Name: HTTP.sys Image Path: C:\WINDOWS\System32\Drivers\HTTP.sys Address: 0xAA87F000 Size: 265728 File Visible: - Signed: - Status: - Name: imapi.sys Image Path: C:\WINDOWS\system32\DRIVERS\imapi.sys Address: 0xF7527000 Size: 42112 File Visible: - Signed: - Status: - Name: intelppm.sys Image Path: C:\WINDOWS\system32\DRIVERS\intelppm.sys Address: 0xF7507000 Size: 36352 File Visible: - Signed: - Status: - Name: ipnat.sys Image Path: C:\WINDOWS\system32\DRIVERS\ipnat.sys Address: 0xAE03D000 Size: 152832 File Visible: - Signed: - Status: - Name: ipsec.sys Image Path: C:\WINDOWS\system32\DRIVERS\ipsec.sys Address: 0xAE0E4000 Size: 75264 File Visible: - Signed: - Status: - Name: isapnp.sys Image Path: isapnp.sys Address: 0xF7487000 Size: 37248 File Visible: - Signed: - Status: - Name: kbdclass.sys Image Path: C:\WINDOWS\system32\DRIVERS\kbdclass.sys Address: 0xF77BF000 Size: 24576 File Visible: - Signed: - Status: - Name: kbdhid.sys Image Path: C:\WINDOWS\system32\DRIVERS\kbdhid.sys Address: 0xAE113000 Size: 14592 File Visible: - Signed: - Status: - Name: KDCOM.DLL Image Path: C:\WINDOWS\system32\KDCOM.DLL Address: 0xF7987000 Size: 8192 File Visible: - Signed: - Status: - Name: kl1.sys Image Path: kl1.sys Address: 0xF6CE3000 Size: 5382144 File Visible: - Signed: - Status: - Name: kl2.sys Image Path: C:\WINDOWS\system32\DRIVERS\kl2.sys Address: 0xF787F000 Size: 24576 File Visible: - Signed: - Status: - Name: klif.sys Image Path: C:\WINDOWS\system32\DRIVERS\klif.sys Address: 0xAE1F5000 Size: 602112 File Visible: - Signed: - Status: - Name: klim5.sys Image Path: C:\WINDOWS\system32\DRIVERS\klim5.sys Address: 0xF7567000 Size: 40960 File Visible: - Signed: - Status: - Name: klmouflt.sys Image Path: C:\WINDOWS\system32\DRIVERS\klmouflt.sys Address: 0xF64FB000 Size: 36864 File Visible: - Signed: - Status: - Name: kmixer.sys Image Path: C:\WINDOWS\system32\drivers\kmixer.sys Address: 0xA9AAE000 Size: 172416 File Visible: - Signed: - Status: - Name: ks.sys Image Path: C:\WINDOWS\system32\DRIVERS\ks.sys Address: 0xF668C000 Size: 143360 File Visible: - Signed: - Status: - Name: KSecDD.sys Image Path: KSecDD.sys Address: 0xF72D9000 Size: 92928 File Visible: - Signed: - Status: - Name: L6TPortGX.sys Image Path: C:\WINDOWS\System32\Drivers\L6TPortGX.sys Address: 0xAE13F000 Size: 580480 File Visible: - Signed: - Status: - Name: mnmdd.SYS Image Path: C:\WINDOWS\System32\Drivers\mnmdd.SYS Address: 0xF79AF000 Size: 4224 File Visible: - Signed: - Status: - Name: mouclass.sys Image Path: C:\WINDOWS\system32\DRIVERS\mouclass.sys Address: 0xF77C7000 Size: 23040 File Visible: - Signed: - Status: - Name: mouhid.sys Image Path: C:\WINDOWS\system32\DRIVERS\mouhid.sys Address: 0xAE103000 Size: 12160 File Visible: - Signed: - Status: - Name: MountMgr.sys Image Path: MountMgr.sys Address: 0xF7497000 Size: 42368 File Visible: - Signed: - Status: - Name: mrxsmb.sys Image Path: C:\WINDOWS\system32\DRIVERS\mrxsmb.sys Address: 0xADEBE000 Size: 456320 File Visible: - Signed: - Status: - Name: Msfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Msfs.SYS Address: 0xF7867000 Size: 19072 File Visible: - Signed: - Status: - Name: msgpc.sys Image Path: C:\WINDOWS\system32\DRIVERS\msgpc.sys Address: 0xF75A7000 Size: 35072 File Visible: - Signed: - Status: - Name: mssmbios.sys Image Path: C:\WINDOWS\system32\DRIVERS\mssmbios.sys Address: 0xF6CAB000 Size: 15488 File Visible: - Signed: - Status: - Name: Mup.sys Image Path: Mup.sys Address: 0xF7205000 Size: 105472 File Visible: - Signed: - Status: - Name: NDIS.sys Image Path: NDIS.sys Address: 0xF721F000 Size: 182656 File Visible: - Signed: - Status: - Name: ndistapi.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndistapi.sys Address: 0xF6CBF000 Size: 10496 File Visible: - Signed: - Status: - Name: ndisuio.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndisuio.sys Address: 0xAB269000 Size: 14592 File Visible: - Signed: - Status: - Name: ndiswan.sys Image Path: C:\WINDOWS\system32\DRIVERS\ndiswan.sys Address: 0xF659C000 Size: 91520 File Visible: - Signed: - Status: - Name: NDProxy.SYS Image Path: C:\WINDOWS\System32\Drivers\NDProxy.SYS Address: 0xF75E7000 Size: 40960 File Visible: - Signed: - Status: - Name: netbios.sys Image Path: C:\WINDOWS\system32\DRIVERS\netbios.sys Address: 0xF7697000 Size: 34688 File Visible: - Signed: - Status: - Name: netbt.sys Image Path: C:\WINDOWS\system32\DRIVERS\netbt.sys Address: 0xAE063000 Size: 162816 File Visible: - Signed: - Status: - Name: npf.sys Image Path: C:\WINDOWS\system32\drivers\npf.sys Address: 0xF77CF000 Size: 28416 File Visible: - Signed: - Status: - Name: Npfs.SYS Image Path: C:\WINDOWS\System32\Drivers\Npfs.SYS Address: 0xF7877000 Size: 30848 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: Ntfs.sys Address: 0xF724C000 Size: 574976 File Visible: - Signed: - Status: - Name: Ntfs.sys Image Path: Ntfs.sys Address: 0xF724C000 Size: 574976 File Visible: - Signed: - Status: Hidden from the Windows API! Name: ntkrnlpa.exe Image Path: C:\WINDOWS\system32\ntkrnlpa.exe Address: 0x804D7000 Size: 2154496 File Visible: - Signed: - Status: - Name: Null.SYS Image Path: C:\WINDOWS\System32\Drivers\Null.SYS Address: 0xF7B94000 Size: 2944 File Visible: - Signed: - Status: - Name: NVENETFD.sys Image Path: C:\WINDOWS\system32\DRIVERS\NVENETFD.sys Address: 0xF75D7000 Size: 53632 File Visible: - Signed: - Status: - Name: nvnetbus.sys Image Path: C:\WINDOWS\system32\DRIVERS\nvnetbus.sys Address: 0xF7557000 Size: 40960 File Visible: - Signed: - Status: - Name: NVNRM.SYS Image Path: C:\WINDOWS\system32\DRIVERS\NVNRM.SYS Address: 0xF65B3000 Size: 888832 File Visible: - Signed: - Status: - Name: parport.sys Image Path: C:\WINDOWS\system32\DRIVERS\parport.sys Address: 0xF6C37000 Size: 80128 File Visible: - Signed: - Status: - Name: PartMgr.sys Image Path: PartMgr.sys Address: 0xF770F000 Size: 19712 File Visible: - Signed: - Status: - Name: ParVdm.SYS Image Path: C:\WINDOWS\System32\Drivers\ParVdm.SYS Address: 0xF79DB000 Size: 6784 File Visible: - Signed: - Status: - Name: pci.sys Image Path: pci.sys Address: 0xF7347000 Size: 68224 File Visible: - Signed: - Status: - Name: pciide.sys Image Path: pciide.sys Address: 0xF7A4F000 Size: 3328 File Visible: - Signed: - Status: - Name: PCIIDEX.SYS Image Path: C:\WINDOWS\system32\DRIVERS\PCIIDEX.SYS Address: 0xF7707000 Size: 28672 File Visible: - Signed: - Status: - Name: pcouffin.sys Image Path: C:\WINDOWS\System32\Drivers\pcouffin.sys Address: 0xF75B7000 Size: 47360 File Visible: - Signed: - Status: - Name: PnpManager Image Path: \Driver\PnpManager Address: 0x804D7000 Size: 2154496 File Visible: - Signed: - Status: - Name: portcls.sys Image Path: C:\WINDOWS\system32\drivers\portcls.sys Address: 0xF63F3000 Size: 147456 File Visible: - Signed: - Status: - Name: psched.sys Image Path: C:\WINDOWS\system32\DRIVERS\psched.sys Address: 0xF658B000 Size: 69120 File Visible: - Signed: - Status: - Name: ptilink.sys Image Path: C:\WINDOWS\system32\DRIVERS\ptilink.sys Address: 0xF77A7000 Size: 17792 File Visible: - Signed: - Status: - Name: PxHelp20.sys Image Path: PxHelp20.sys Address: 0xF74D7000 Size: 38080 File Visible: - Signed: - Status: - Name: rasacd.sys Image Path: C:\WINDOWS\system32\DRIVERS\rasacd.sys Address: 0xF6CA7000 Size: 8832 File Visible: - Signed: - Status: - Name: rasl2tp.sys Image Path: C:\WINDOWS\system32\DRIVERS\rasl2tp.sys Address: 0xF7577000 Size: 51328 File Visible: - Signed: - Status: - Name: raspppoe.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspppoe.sys Address: 0xF7587000 Size: 41472 File Visible: - Signed: - Status: - Name: raspptp.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspptp.sys Address: 0xF7597000 Size: 48384 File Visible: - Signed: - Status: - Name: raspti.sys Image Path: C:\WINDOWS\system32\DRIVERS\raspti.sys Address: 0xF77B7000 Size: 16512 File Visible: - Signed: - Status: - Name: RAW Image Path: \FileSystem\RAW Address: 0x804D7000 Size: 2154496 File Visible: - Signed: - Status: - Name: rdbss.sys Image Path: C:\WINDOWS\system32\DRIVERS\rdbss.sys Address: 0xADF2E000 Size: 175744 File Visible: - Signed: - Status: - Name: RDPCDD.sys Image Path: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys Address: 0xF79B3000 Size: 4224 File Visible: - Signed: - Status: - Name: redbook.sys Image Path: C:\WINDOWS\system32\DRIVERS\redbook.sys Address: 0xF7547000 Size: 57600 File Visible: - Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xAA990000 Size: 49152 File Visible: No Signed: - Status: - Name: RtkHDAud.sys Image Path: C:\WINDOWS\system32\drivers\RtkHDAud.sys Address: 0xAE31D000 Size: 4788224 File Visible: - Signed: - Status: - Name: SASDIFSV.SYS Image Path: C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS Address: 0xF7767000 Size: 24576 File Visible: - Signed: - Status: - Name: SASKUTIL.SYS Image Path: C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS Address: 0xADF59000 Size: 139264 File Visible: - Signed: - Status: - Name: serenum.sys Image Path: C:\WINDOWS\system32\DRIVERS\serenum.sys Address: 0xF796B000 Size: 15744 File Visible: - Signed: - Status: - Name: serial.sys Image Path: C:\WINDOWS\system32\DRIVERS\serial.sys Address: 0xF7517000 Size: 64512 File Visible: - Signed: - Status: - Name: srv.sys Image Path: C:\WINDOWS\system32\DRIVERS\srv.sys Address: 0xAAAF0000 Size: 357888 File Visible: - Signed: - Status: - Name: STREAM.SYS Image Path: C:\WINDOWS\System32\Drivers\STREAM.SYS Address: 0xF7657000 Size: 53248 File Visible: - Signed: - Status: - Name: swenum.sys Image Path: C:\WINDOWS\system32\DRIVERS\swenum.sys Address: 0xF7997000 Size: 4352 File Visible: - Signed: - Status: - Name: sysaudio.sys Image Path: C:\WINDOWS\system32\drivers\sysaudio.sys Address: 0xAB0DD000 Size: 60800 File Visible: - Signed: - Status: - Name: tcpip.sys Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys Address: 0xAE08B000 Size: 361600 File Visible: - Signed: - Status: - Name: TDI.SYS Image Path: C:\WINDOWS\system32\DRIVERS\TDI.SYS Address: 0xF7797000 Size: 20480 File Visible: - Signed: - Status: - Name: termdd.sys Image Path: C:\WINDOWS\system32\DRIVERS\termdd.sys Address: 0xF75C7000 Size: 40704 File Visible: - Signed: - Status: - Name: update.sys Image Path: C:\WINDOWS\system32\DRIVERS\update.sys Address: 0xF648D000 Size: 384768 File Visible: - Signed: - Status: - Name: usbccgp.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbccgp.sys Address: 0xF7837000 Size: 32128 File Visible: - Signed: - Status: - Name: USBD.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBD.SYS Address: 0xF799B000 Size: 8192 File Visible: - Signed: - Status: - Name: usbehci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbehci.sys Address: 0xF775F000 Size: 30208 File Visible: - Signed: - Status: - Name: usbhub.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbhub.sys Address: 0xF75F7000 Size: 59520 File Visible: - Signed: - Status: - Name: usbohci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbohci.sys Address: 0xF7757000 Size: 17152 File Visible: - Signed: - Status: - Name: USBPORT.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBPORT.SYS Address: 0xF6C13000 Size: 147456 File Visible: - Signed: - Status: - Name: usbprint.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbprint.sys Address: 0xF779F000 Size: 25856 File Visible: - Signed: - Status: - Name: usbscan.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbscan.sys Address: 0xAE11B000 Size: 15104 File Visible: - Signed: - Status: - Name: USBSTOR.SYS Image Path: C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS Address: 0xF7787000 Size: 26368 File Visible: - Signed: - Status: - Name: usbuhci.sys Image Path: C:\WINDOWS\system32\DRIVERS\usbuhci.sys Address: 0xF776F000 Size: 20608 File Visible: - Signed: - Status: - Name: vga.sys Image Path: C:\WINDOWS\System32\drivers\vga.sys Address: 0xF7857000 Size: 20992 File Visible: - Signed: - Status: - Name: VIDEOPRT.SYS Image Path: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS Address: 0xF66AF000 Size: 81920 File Visible: - Signed: - Status: - Name: VolSnap.sys Image Path: VolSnap.sys Address: 0xF74A7000 Size: 52352 File Visible: - Signed: - Status: - Name: vulfnth.sys Image Path: C:\WINDOWS\System32\Drivers\vulfnth.sys Address: 0xF7991000 Size: 6912 File Visible: - Signed: - Status: - Name: vulfntr.sys Image Path: C:\WINDOWS\System32\Drivers\vulfntr.sys Address: 0xF6C57000 Size: 11264 File Visible: - Signed: - Status: - Name: wanarp.sys Image Path: C:\WINDOWS\system32\DRIVERS\wanarp.sys Address: 0xF7687000 Size: 34560 File Visible: - Signed: - Status: - Name: watchdog.sys Image Path: C:\WINDOWS\System32\watchdog.sys Address: 0xF77FF000 Size: 20480 File Visible: - Signed: - Status: - Name: wdmaud.sys Image Path: C:\WINDOWS\system32\drivers\wdmaud.sys Address: 0xAAF80000 Size: 83072 File Visible: - Signed: - Status: - Name: Win32k Image Path: \Driver\Win32k Address: 0xBF800000 Size: 1859584 File Visible: - Signed: - Status: - Name: win32k.sys Image Path: C:\WINDOWS\System32\win32k.sys Address: 0xBF800000 Size: 1859584 File Visible: - Signed: - Status: - Name: WMILIB.SYS Image Path: C:\WINDOWS\system32\DRIVERS\WMILIB.SYS Address: 0xF7989000 Size: 8192 File Visible: - Signed: - Status: - Name: WMIxWDM Image Path: \Driver\WMIxWDM Address: 0x804D7000 Size: 2154496 File Visible: - Signed: - Status: -
Hi Ally and welcome to WhatTheTech forums!
I'm Sunyata and I will be helping you with your computer problems.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.

Please read the following guidelines which will help to make cleaning your machine easier:

  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
  • Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
  • Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
  • PLEASE DO NOT install/uninstall any programs unless asked to.
  • PLEASE DO NOT run any malware scans other than those requested.
  • Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
  • I will reply back shortly with instructions

Note to Vista and Windows 7 users:
  • These tools MUST be run from the executable. (.exe) every time you run them
  • These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
Hello Ally

First,

Please post the log from the TDSSKiller run you previously executed. It can usually be found here:
C:\TDSSKiller.[Version]_[Date]_[Time]_log.txt, where "[Version]_[Date]_[Time]" is variable information.


Next,

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.

    Vista and Windows 7 users right click the icon and choose "Run as administrator".

  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]

Hi Sunyata, There is only a folder called TDSS Quarantine on my C drive and it has 4 objects in it but no txt file. Here is my Avast Scan result though :- aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-21 18:44:00 —————————– 18:44:00.046 OS Version: Windows 5.1.2600 Service Pack 3 18:44:00.046 Number of processors: 2 586 0x1706 18:44:00.046 ComputerName: ALLY-6A4E09FF10 UserName: Allyc 18:44:00.796 Initialize success 18:44:03.390 AVAST engine defs: 11102100 18:44:14.171 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-6 18:44:14.171 Disk 0 Vendor: Hitachi_HDT721032SLA360 ST2OA3AA Size: 305245MB BusType: 3 18:44:16.187 Disk 0 MBR read successfully 18:44:16.187 Disk 0 MBR scan 18:44:16.234 Disk 0 Windows XP default MBR code 18:44:16.234 Disk 0 scanning sectors +625121280 18:44:16.328 Disk 0 scanning C:\WINDOWS\system32\drivers 18:44:28.109 Service scanning 18:44:28.593 Service KL1 C:\WINDOWS\system32\DRIVERS\kl1.sys **LOCKED** 5 18:44:28.593 Service kl2 C:\WINDOWS\system32\DRIVERS\kl2.sys **LOCKED** 5 18:44:28.609 Service klim5 C:\WINDOWS\system32\DRIVERS\klim5.sys **LOCKED** 5 18:44:28.609 Service klmouflt C:\WINDOWS\system32\DRIVERS\klmouflt.sys **LOCKED** 5 18:44:29.156 Modules scanning 18:44:41.765 Disk 0 trace - called modules: 18:44:41.796 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS 18:44:41.796 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8ab37ab8] 18:44:41.796 3 CLASSPNP.SYS[f74c7fd7] -> nt!IofCallDriver -> \Device\00000061[0x8ac09f18] 18:44:41.796 5 ACPI.sys[f735e620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-6[0x8ab81940] 18:44:42.187 AVAST engine scan C:\WINDOWS 18:44:56.406 AVAST engine scan C:\WINDOWS\system32 18:46:51.187 AVAST engine scan C:\WINDOWS\system32\drivers 18:47:17.390 AVAST engine scan C:\Documents and Settings\Allyc 18:50:41.343 AVAST engine scan C:\Documents and Settings\All Users 18:54:50.015 Scan finished successfully 18:55:12.359 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Allyc\My Documents\MBR.dat" 18:55:12.359 The log file has been saved successfully to "C:\Documents and Settings\Allyc\My Documents\aswMBR.txt" PS. there is a file that keeps appearing in my documents folder called Mplayerc.dat,this time the file is named MBR.
Hello Ally

Please read through these instructions to familarize yourself with what to expect when this tool runs

Please download ComboFix from one of the following locations:
  • LINK 1
  • LINK 2
**IMPORTANT! Save ComboFix to your Desktop. Read the following thoroughly
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link :How to Disable your Security Programs
  • Double click on 'ComboFix.exe' & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message box:



[external image: Posted Image]


Click on 'Yes', to continue scanning for malware.

When finished, it will produce a log for you.
Please include the contents of C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please let me know.
5. ComboFix disconnects your machine from the internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

In your next reply please post the log created by ComboFix. :)
Hi Sunyata, I can't find thw combofix txt in my c drive,there is a folder called qoobox.
I saved a txt file after it scanned to my desktop though and named it combofix, is this the correct log?

ComboFix 11-10-21.03 - Allyc 21/10/2011 19:52:24.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2776 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
FW: Kaspersky Internet Security *Disabled* {2C4D4BC6-0793-4956-A9F9-E252435469C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Allyc\Application Data\inst.exe
c:\documents and settings\Allyc\Application Data\msregsvv.dll
c:\documents and settings\Allyc\Application Data\vso_ts_preview.xml
c:\documents and settings\Allyc\Cookies\isindex.dat
c:\windows\help\tours\htmltour\unlock_playing.htm
c:\windows\system32\d3d9caps.dat
c:\windows\system32\drivers\etc\hosts.txt
c:\windows\system32\msvcsv60.dll
.
.
((((((((((((((((((((((((( Files Created from 2011-09-21 to 2011-10-21 )))))))))))))))))))))))))))))))
.
.
2011-10-17 13:19 . 2011-10-17 13:19 ——– d—–w- C:\TDSSKiller_Quarantine
2011-10-17 04:29 . 2011-05-24 18:14 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-10-16 19:48 . 2011-10-16 19:48 ——– d—–w- c:\program files\ESET
2011-10-14 11:50 . 2010-12-22 10:33 9078960 —-a-w- c:\windows\system32\mkl_p4p.dll
2011-10-14 11:50 . 2010-12-22 10:33 9033904 —-a-w- c:\windows\system32\mkl_p4m3.dll
2011-10-14 11:50 . 2010-12-22 10:33 9410736 —-a-w- c:\windows\system32\mkl_p4m.dll
2011-10-14 11:50 . 2010-12-22 10:33 9210032 —-a-w- c:\windows\system32\mkl_p4.dll
2011-10-14 11:50 . 2010-12-22 10:33 3868848 —-a-w- c:\windows\system32\mkl_intel_thread.dll
2011-10-14 11:50 . 2010-12-22 10:33 6944944 —-a-w- c:\windows\system32\mkl_core.dll
2011-10-14 11:50 . 2010-12-22 10:33 530608 —-a-w- c:\windows\system32\libiomp5md.dll
2011-10-14 11:49 . 2011-10-14 11:49 ——– d—–w- c:\program files\Steinberg
2011-10-14 11:49 . 2009-10-14 15:15 499712 —-a-w- c:\windows\msvcp71.dll
2011-10-14 11:49 . 2009-10-14 15:15 348160 —-a-w- c:\windows\msvcr71.dll
2011-10-14 11:49 . 2011-10-14 11:51 ——– d—–w- c:\program files\IK Multimedia
2011-10-14 11:49 . 2011-10-14 11:49 ——– d—–w- c:\program files\VstPlugIns
2011-10-14 10:40 . 2011-10-14 11:12 ——– d—–w- c:\documents and settings\Allyc\Application Data\IK Multimedia
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\program files\QuickTime
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\program files\Common Files\Apple
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\program files\Apple Software Update
2011-10-14 10:32 . 2011-10-14 10:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2011-10-14 08:30 . 2011-10-14 08:30 ——– d—–w- c:\program files\WinPcap
2011-10-14 08:24 . 2009-09-02 12:44 65602 —-a-w- c:\windows\system32\cook3260.dll
2011-10-14 08:24 . 2009-09-02 12:44 626688 —-a-w- c:\windows\system32\vp7vfw.dll
2011-10-14 08:24 . 2009-09-02 12:44 217127 —-a-w- c:\windows\system32\drv43260.dll
2011-10-14 08:24 . 2009-09-02 12:44 208935 —-a-w- c:\windows\system32\drv33260.dll
2011-10-14 08:24 . 2009-09-02 12:44 176165 —-a-w- c:\windows\system32\drv23260.dll
2011-10-14 08:24 . 2009-09-02 12:44 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll
2011-10-14 08:24 . 2009-09-02 12:44 102439 —-a-w- c:\windows\system32\sipr3260.dll
2011-10-06 02:36 . 2011-10-06 02:36 ——– d—–w- c:\program files\CCleaner
2011-10-04 01:51 . 2011-10-04 01:53 ——– d—–w- c:\program files\TweakNow RegCleaner 2011
2011-10-04 01:51 . 2011-10-04 01:51 ——– d—–w- c:\documents and settings\Allyc\Application Data\TweakNow RegCleaner 2011
2011-10-03 09:12 . 2009-07-06 09:48 11448 —-a-w- c:\windows\system32\drivers\AsUpIO.sys
2011-10-03 09:12 . 2009-09-30 10:33 24576 —-a-w- c:\windows\system32\AsIO.dll
2011-10-03 09:12 . 2009-08-04 09:28 11296 —-a-w- c:\windows\system32\drivers\AsIO.sys
2011-10-03 09:12 . 2011-10-03 09:12 ——– d—–w- c:\program files\ASUS
2011-09-30 03:37 . 2011-10-17 05:15 ——– d—–w- c:\documents and settings\Allyc\Application Data\vlc
2011-09-30 03:37 . 2011-09-30 03:37 ——– d—–w- c:\program files\VideoLAN
2011-09-30 03:24 . 2011-09-30 03:35 ——– d—–w- c:\documents and settings\Allyc\Application Data\Media Player Classic
2011-09-30 03:16 . 2011-09-30 03:16 ——– d–h–w- c:\windows\msdownld.tmp
2011-09-30 03:15 . 2011-09-30 16:39 ——– d—–w- c:\program files\Essentials Codec Pack
2011-09-30 03:14 . 2011-09-30 03:14 ——– d—–w- c:\documents and settings\Allyc\Application Data\Nullsoft
2011-09-24 10:50 . 2011-09-24 10:50 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-24 10:41 . 2011-09-24 10:50 ——– d—–w- c:\documents and settings\Allyc\Local Settings\Application Data\Solid State Networks
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-14 08:24 . 2011-06-03 07:19 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2011-10-14 08:24 . 2011-06-03 07:19 47360 —-a-w- c:\documents and settings\Allyc\Application Data\pcouffin.sys
2011-09-26 10:41 . 2009-10-08 13:57 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 10:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 10:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-18 15:46 . 2011-09-18 15:47 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-18 15:46 . 2011-06-02 18:59 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-09-09 09:12 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2004-08-04 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-31 16:00 . 2011-06-03 06:55 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48 . 2004-08-04 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2004-08-04 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2004-08-04 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2004-08-04 12:00 385024 ——w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2004-08-04 12:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-07-28 19:54 . 2011-02-28 17:01 947472 —-a-w- c:\windows\system32\msjava.dll
2011-07-26 20:57 . 2011-07-26 20:57 1060864 —-a-w- c:\windows\system32\mfc71.dll
2011-07-26 20:57 . 2011-07-26 20:57 1700352 —-a-w- c:\windows\system32\gdiplus.dll
2011-09-30 18:00 . 2011-06-02 16:48 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HostsMan"="c:\program files\HostsMan\hm.exe" [2010-02-06 3043840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-27 16844800]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe" [2011-04-24 202296]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-07-05 421888]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-05 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\VSO\\VSO Downloader\\1\\VsoDownloader.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [03/10/2011 10:12 11448]
R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [04/03/2011 13:23 11352]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [17/02/2010 19:25 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 19:41 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [04/05/2011 18:54 116608]
R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\IObit\Advanced SystemCare 4\ASCService.exe [02/06/2011 21:42 328536]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [16/07/2010 01:45 35088]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [10/03/2011 18:34 34608]
R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [02/11/2009 20:27 19472]
R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [03/06/2011 10:46 580480]
R3 pcouffin;VSO Software pcouffin;c:\windows\system32\drivers\pcouffin.sys [03/06/2011 08:19 47360]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [18/03/2010 13:16 130384]
S3 SwitchBoard;SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13:37 517096]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [04/08/2004 13:00 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [18/03/2010 13:16 753504]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 16:57]
.
2011-10-21 c:\windows\Tasks\ASC4_AutoCare.job
- c:\program files\IObit\Advanced SystemCare 4\AutoCare.exe [2011-06-02 15:38]
.
2011-10-19 c:\windows\Tasks\ASC4_AutoConverter.job
- c:\program files\IObit\Advanced SystemCare 4\LicenseConverter.exe [2011-10-19 16:45]
.
.
——- Supplementary Scan ——-
.
mStart Page = about:blank
IE: Download all with Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Allyc\Application Data\Mozilla\Firefox\Profiles\kesbenv4.default\
FF - prefs.js: browser.startup.homepage - hxxp://uk.yahoo.com/
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - true
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 8191
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 32
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-proxy - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-21 19:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1156)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
.
Completion time: 2011-10-21 19:55:25
ComboFix-quarantined-files.txt 2011-10-21 18:55
.
Pre-Run: 304,943,263,744 bytes free
Post-Run: 304,967,569,408 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - E0CC6C4663E512FA76860FC5AE3D5C76
Hello Ally

is this the correct log?

That'd be the one :thumbup:

It's time to sweep for leftovers…

Scan For Malware:

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.



Do An Online Scan For Viruses:

Note: It is recommended to disable on-board anti-virus program and anti-spyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your anti-virus along with your anti-spyware programs.

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as MyEsetScan. Include the contents of this report in your next reply.
  • Push the Back button.
  • Push Finish
In your next reply please post the logs created by Malwarebytes and the ESET Online Scan.

How is your system is running now?
Hi Sunyata, Here are the results from my scans : Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7995 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 21/10/2011 21:48:41 mbam-log-2011-10-21 (21-48-41).txt Scan type: Quick scan Objects scanned: 152619 Time elapsed: 2 minute(s), 27 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=aaa7e2259a21e94fb850873a0cb1a433 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2011-10-16 08:15:00 # local_time=2011-10-16 09:15:00 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1280 16777175 100 0 6216124 6216124 0 0 # compatibility_mode=8192 67108863 100 0 177 177 0 0 # scanned=63437 # found=0 # cleaned=0 # scan_time=1392 ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=aaa7e2259a21e94fb850873a0cb1a433 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-10-21 09:10:23 # local_time=2011-10-21 10:10:23 (+0000, GMT Daylight Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1280 16777191 100 0 6651677 6651677 0 0 # compatibility_mode=8192 67108863 100 0 435730 435730 0 0 # scanned=64103 # found=0 # cleaned=0 # scan_time=1163 My Internet is running faster,which I noticed after running combofix but on my desktop the icons refresh every now and then which is quite strange.
Hello Ally

For your icon refresh problem, bring up the following page and download number 121 on the list, "iconcache.vbs".
Once on your machine, simply double click the file, press "OK" on the dialog that comes up, then reboot your machine:

http://www.kellys-korner-xp.com/xp_tweaks.htm

Next,


Please run another DDS scan:

  • Double click DDS.scr to run it and wait for the scan to finish
  • When finished DDS.txt will open
  • A small while later, a prompt will open. Answer Yes
  • DDS will continue scanning
  • When done, Attach.txt will open
  • Post DDS.txt and attach Attach.txt

Hi Sunyata, I ran dds again but received no prompt to continue scanning it just came up with the logs. . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 23:20:42.35 on 21/10/2011 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_27 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.3326.2775 [GMT 1:00] . AV: Kaspersky Internet Security *Enabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: Kaspersky Internet Security *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe C:\Program Files\HostsMan\hm.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\IObit\Advanced SystemCare 4\ASCService.exe C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wuauclt.exe svchost.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Documents and Settings\Allyc\Desktop\Downloads\dds.scr . ============== Pseudo HJT Report =============== . mStart Page = about:blank BHO: IEVkbdBHO Class: {59273ab4-e7d3-40f9-a1a8-6fa9cca1862c} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: FilterBHO Class: {e33cf602-d945-461a-83f0-819f76a199f8} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll uRun: [HostsMan] "c:\program files\hostsman\hm.exe" -s mRun: [RTHDCPL] RTHDCPL.EXE mRun: [AVP] "c:\program files\kaspersky lab\kaspersky internet security 2012\avp.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime IE: Add to Anti-Banner - c:\program files\kaspersky lab\kaspersky internet security 2012\ie_banner_deny.htm IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe IE: {C2A80015-C447-4dc4-82DD-AED83D6ED57E} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {4248FE82-7FCB-46AC-B270-339F08212110} - {4248FE82-7FCB-46AC-B270-339F08212110} - c:\program files\kaspersky lab\kaspersky internet security 2012\ievkbd.dll IE: {CCF151D8-D089-449F-A5A4-D9909053F20F} - {CCF151D8-D089-449F-A5A4-D9909053F20F} - c:\program files\kaspersky lab\kaspersky internet security 2012\klwtbbho.dll DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1307033399078 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: klogon - c:\windows\system32\klogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\allyc\applic~1\mozilla\firefox\profiles\kesbenv4.default\ FF - prefs.js: browser.startup.homepage - hxxp://uk.yahoo.com/ FF - plugin: c:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll . —- FIREFOX POLICIES —- FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: browser.chrome.favicons - true FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: browser.xul.error_pages.enabled - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 8191 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 750000 FF - user.js: content.notify.ontimer - true FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 750000 FF - user.js: network.http.max-connections - 32 FF - user.js: network.http.max-connections-per-server - 8 FF - user.js: network.http.max-persistent-connections-per-proxy - 8 FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 0 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . ============= SERVICES / DRIVERS =============== . R0 KL1;kl1;c:\windows\system32\drivers\kl1.sys [2011-3-4 133208] R1 AsUpIO;AsUpIO;c:\windows\system32\drivers\AsUpIO.sys [2011-10-3 11448] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [2011-3-4 11352] R1 KLIF;Kaspersky Lab Driver;c:\windows\system32\drivers\klif.sys [2011-8-5 565552] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2010-2-17 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-5-4 116608] R2 AdvancedSystemCareService;Advanced SystemCare Service;c:\program files\iobit\advanced systemcare 4\ASCService.exe [2011-6-2 328536] R2 AVP;Kaspersky Anti-Virus Service;c:\program files\kaspersky lab\kaspersky internet security 2012\avp.exe [2011-4-24 202296] R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2010-7-16 35088] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2011-3-10 34608] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [2009-11-2 19472] R3 L6TPortGX;Service - Line 6 TonePort GX;c:\windows\system32\drivers\L6TPortGX.sys [2011-6-3 580480] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 SwitchBoard;SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-10-21 20:45:48 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-10-21 18:51:50 ——– d-sha-r- C:\cmdcons 2011-10-21 18:51:08 98816 —-a-w- c:\windows\sed.exe 2011-10-21 18:51:08 518144 —-a-w- c:\windows\SWREG.exe 2011-10-21 18:51:08 256000 —-a-w- c:\windows\PEV.exe 2011-10-21 18:51:08 208896 —-a-w- c:\windows\MBR.exe 2011-10-17 13:19:05 ——– d—–w- C:\TDSSKiller_Quarantine 2011-10-17 04:29:11 222080 ——w- c:\windows\system32\MpSigStub.exe 2011-10-16 19:48:52 ——– d—–w- c:\program files\ESET 2011-10-14 11:50:10 9078960 —-a-w- c:\windows\system32\mkl_p4p.dll 2011-10-14 11:50:09 9410736 —-a-w- c:\windows\system32\mkl_p4m.dll 2011-10-14 11:50:09 9210032 —-a-w- c:\windows\system32\mkl_p4.dll 2011-10-14 11:50:09 9033904 —-a-w- c:\windows\system32\mkl_p4m3.dll 2011-10-14 11:50:09 3868848 —-a-w- c:\windows\system32\mkl_intel_thread.dll 2011-10-14 11:50:08 6944944 —-a-w- c:\windows\system32\mkl_core.dll 2011-10-14 11:50:08 530608 —-a-w- c:\windows\system32\libiomp5md.dll 2011-10-14 11:49:44 499712 —-a-w- c:\windows\msvcp71.dll 2011-10-14 11:49:44 348160 —-a-w- c:\windows\msvcr71.dll 2011-10-14 11:49:44 ——– d—–w- c:\program files\Steinberg 2011-10-14 11:49:29 ——– d—–w- c:\program files\VstPlugIns 2011-10-14 11:49:29 ——– d—–w- c:\program files\IK Multimedia 2011-10-14 10:40:41 ——– d—–w- c:\docume~1\allyc\applic~1\IK Multimedia 2011-10-14 08:30:03 ——– d—–w- c:\program files\WinPcap 2011-10-14 08:24:25 65602 —-a-w- c:\windows\system32\cook3260.dll 2011-10-14 08:24:25 626688 —-a-w- c:\windows\system32\vp7vfw.dll 2011-10-14 08:24:25 217127 —-a-w- c:\windows\system32\drv43260.dll 2011-10-14 08:24:25 208935 —-a-w- c:\windows\system32\drv33260.dll 2011-10-14 08:24:25 176165 —-a-w- c:\windows\system32\drv23260.dll 2011-10-14 08:24:25 1184984 —-a-w- c:\windows\system32\wvc1dmod.dll 2011-10-14 08:24:25 102439 —-a-w- c:\windows\system32\sipr3260.dll 2011-10-06 02:36:34 ——– d—–w- c:\program files\CCleaner 2011-10-04 01:51:24 ——– d—–w- c:\program files\TweakNow RegCleaner 2011 2011-10-04 01:51:24 ——– d—–w- c:\docume~1\allyc\applic~1\TweakNow RegCleaner 2011 2011-10-03 09:12:57 11448 —-a-w- c:\windows\system32\drivers\AsUpIO.sys 2011-10-03 09:12:46 24576 —-a-w- c:\windows\system32\AsIO.dll 2011-10-03 09:12:46 11296 —-a-w- c:\windows\system32\drivers\AsIO.sys 2011-10-03 09:12:41 ——– d—–w- c:\program files\ASUS 2011-09-30 03:37:17 ——– d—–w- c:\program files\VideoLAN 2011-09-30 03:16:11 ——– d–h–w- c:\windows\msdownld.tmp 2011-09-30 03:15:44 ——– d—–w- c:\program files\Essentials Codec Pack 2011-09-30 03:14:59 ——– d—–w- c:\docume~1\allyc\applic~1\Nullsoft 2011-09-24 10:50:25 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-24 10:41:28 ——– d—–w- c:\docume~1\allyc\locals~1\applic~1\Solid State Networks . ==================== Find3M ==================== . 2011-10-14 08:24:32 47360 —-a-w- c:\docume~1\allyc\applic~1\pcouffin.sys 2011-09-26 10:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 10:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 10:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-18 15:46:53 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-09-18 15:46:53 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys 2011-08-22 23:48:55 916480 —-a-w- c:\windows\system32\wininet.dll 2011-08-22 23:48:54 43520 ——w- c:\windows\system32\licmgr10.dll 2011-08-22 23:48:54 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-08-22 11:56:39 385024 ——w- c:\windows\system32\html.iec 2011-07-28 19:54:24 947472 —-a-w- c:\windows\system32\msjava.dll 2011-07-26 20:57:54 1060864 —-a-w- c:\windows\system32\mfc71.dll 2011-07-26 20:57:53 1700352 —-a-w- c:\windows\system32\gdiplus.dll . ============= FINISH: 23:21:16.23 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hello Ally

P2P - I see you have P2P software ( µTorrent ) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.


Ally, please tell me how your machine is running now. Are there any further issues?

Hello Ally

My PC is running great now thanks.

You are most welcome :)

Now we need to clean up our tools…


From your desktop, please delete

  • logs that we created
  • MBR.dat
  • MBR.zip
  • aswMBR.exe
ESET online scan can be removed via add/remove programs

I recommend you keep Malwarebyte's Anti-Malware, update it regularly and run it often.

Follow these steps to uninstall Combofix
  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
[external image: Posted Image]

The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Next, Please re-enable any security that was disabled.

Here are a few recomendations to help keep you malware-free:


Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
(Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
Without a firewall your computer is succeptible to being hacked and taken over.
I am very serious about this and see it happen almost every day with my clients.
Simply using a Firewall in its default configuration can lower your risk greatly.


WOT , Web of Trust, As 'Googling' is such an integral part of internet life, this free browser add on warns you about risky websites that try to scam visitors, deliver malware or send spam. It is especially helpful when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and IE.

Only run one Anti-Virus and Firewall program.

I would suggest you read:
PC Safety and Security–What Do I Need?
How to Prevent Malware


Please acknowledge with one more post so that we may close this thread.
Take care and safe computing :wavey:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI