PING.EXE
5 min read
I'm Sunyata and I will be helping you with your computer problems.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts before I post them. This is to ensure that I am giving you the best possible advice. This may cause a delay, but I will do my very best to keep it as short as possible.
Please read the following guidelines which will help to make cleaning your machine easier:
- Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
- The fixes I will give you are specific to your problem and should only be used for this issue on this machine.
- Please make sure to carefully read any instructions posted. If you're not sure, please stop and ask!
- Please stay with this thread until I tell you your machine appears to be clean. Absence of symptoms does not necessarily mean that all malware is gone.
- PLEASE DO NOT install/uninstall any programs unless asked to.
- PLEASE DO NOT run any malware scans other than those requested.
- Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
- I will reply back shortly with instructions
Note to Vista and Windows 7 users:
- These tools MUST be run from the executable. (.exe) every time you run them
- These tools MUST be run With Admin Rights (Right click, choose "Run as Administrator")
First,
Please download DDS by sUBs to your desktop.
Your antivirus software might question the file. If it does, turn it off please ![]()
- Double click DDS.scr to run it and wait for the scan to finish
- When finished DDS.txt will open
- A small while later, a prompt will open. Answer Yes
- DDS will continue scanning
- When done, Attach.txt will open
- Post DDS.txt and attach Attach.txt
Next,
Please download aswMBR to your desktop.
- Double click the aswMBR icon to run it.
Vista and Windows 7 users right click the icon and choose "Run as administrator".
- When asked if you want to download Avast's virus definitions please select Yes.
- Click the Scan button to start scan.
- When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
[external image: Posted Image]
In your next reply please include:
- DDS.txt
- Attach.txt
- aswMBR.log
Internet Explorer: 8.0.6001.18702
Run by [removed] at 13:24:09 on 2011-11-16
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.421 [GMT -8:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\IDT\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\PROGRA~1\RADIOP~2\bar\1.bin\4ebrmon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Documents and Settings\Manny\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Manny\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Manny\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Documents and Settings\Manny\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Documents and Settings\Manny\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\System32\ping.exe
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uSearch Bar = hxxp://toolbar.inbox.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=%tb_id&%language
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
uURLSearchHooks: N/A: {8bc67b0f-a721-45e0-a0b6-db0121b0aade} - c:\program files\radiopi_4e\bar\1.bin\4eSrcAs.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Toolbar BHO: {35fd2bab-ab2b-494f-b5bf-8755ec043784} - c:\progra~1\radiop~2\bar\1.bin\4ebar.dll
BHO: Search Assistant BHO: {4adc9c1b-9c50-4c2d-a471-5c06d8de7e80} - c:\program files\radiopi_4e\bar\1.bin\4eSrcAs.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Javaβ’ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: RadioPI: {92926b63-5116-4c6f-a33e-378767b8d15f} - c:\program files\radiopi_4e\bar\1.bin\4ebar.dll
TB: RadioRage: {78ba36c9-6036-482b-b48d-ecca6f964b84} - c:\program files\radiorage_4j\bar\1.bin\4jbar.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\manny\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [RadioPI_4e Browser Plugin Loader] c:\progra~1\radiop~2\bar\1.bin\4ebrmon.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
StartupFolder: c:\docume~1\manny\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
IE: &Search - http://tbedits.radiorage.com/one-toolbaredβ¦mp;n=2011092212
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki⦠- c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
LSP: mswsock.dll
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {14E35D5F-DEBA-4DB3-B2ED-17542BA12D1F} - hxxp://208.13.129.198/AVC_AX_DVR.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {389956FE-3A45-469C-B944-70308E06BAAC} - hxxp://65.40.145.90/videocom.cab
"x"
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {9B479D7B-916A-45B0-B042-D42865A60E21} - hxxp://208.13.129.198/DvrOcx.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
TCP: Interfaces\{E0AFD16E-42E1-4D5D-AC91-AA568542E4C4} : DhcpNameServer = 192.168.1.1 [removed] [removed]
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-9-10 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-9-10 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-9-10 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-9-10 56816]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2009-9-10 366152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2009-9-10 22216]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-7-21 136176]
S2 RadioPI_4eService;RadioPI Service;c:\progra~1\radiop~2\bar\1.bin\4ebarsvc.exe [2011-9-20 34864]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-7-21 136176]
.
=============== Created Last 30 ================
.
2011-11-11 20:15:36 388096 β-a-r- c:\documents and settings\manny\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-11-11 20:15:35 βββ dββw- c:\program files\Trend Micro
2011-11-08 18:24:14 βββ dββw- c:\documents and settings\manny\application data\wFFF4pmmG5QJ7
2011-11-08 18:24:14 βββ dββw- c:\documents and settings\manny\application data\puuvvS2ob
2011-11-08 18:24:03 βββ dββw- c:\documents and settings\manny\application data\THH66sWKR
2011-11-08 18:24:02 βββ dββw- c:\documents and settings\manny\application data\DAA00uvS2obFpm5
.
==================== Find3M ====================
.
2011-10-10 14:22:41 692736 β-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06:50 599040 β-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41:20 611328 β-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41:20 220160 β-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41:14 20480 β-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20:51 1858944 β-a-w- c:\windows\system32\win32k.sys
2011-09-01 01:00:50 22216 β-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48:55 916480 β-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48:54 43520 β-a-w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48:54 1469440 ββw- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56:39 385024 β-a-w- c:\windows\system32\html.iec
.
============= FINISH: 13:24:46.40 ===============
Please read through these instructions to familarize yourself with what to expect when this tool runs
Please download ComboFix from one of the following locations:
- LINK 1
- LINK 2
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link :How to Disable your Security Programs
- Double click on 'ComboFix.exe' & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message box:
[external image: Posted Image]
Click on 'Yes', to continue scanning for malware.
When finished, it will produce a log for you.
Please include the contents of C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making Internet Explorer the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you β please let me know.
5. ComboFix disconnects your machine from the internet. The connection is automatically restored before ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
In your next reply please post the log created by ComboFix.
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.658 [GMT -8:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\RadioRage_4jEI
c:\windows\$NtUninstallKB28138$
c:\windows\$NtUninstallKB28138$\1785772381
c:\windows\$NtUninstallKB28138$\634996787\@
c:\windows\$NtUninstallKB28138$\634996787\bckfg.tmp
c:\windows\$NtUninstallKB28138$\634996787\cfg.ini
c:\windows\$NtUninstallKB28138$\634996787\Desktop.ini
c:\windows\$NtUninstallKB28138$\634996787\keywords
c:\windows\$NtUninstallKB28138$\634996787\kwrd.dll
c:\windows\$NtUninstallKB28138$\634996787\L\wiyydlfm
c:\windows\$NtUninstallKB28138$\634996787\lsflt7.ver
c:\windows\$NtUninstallKB28138$\634996787\U\00000001.@
c:\windows\$NtUninstallKB28138$\634996787\U\00000002.@
c:\windows\$NtUninstallKB28138$\634996787\U\00000004.@
c:\windows\$NtUninstallKB28138$\634996787\U\80000000.@
c:\windows\$NtUninstallKB28138$\634996787\U\80000004.@
c:\windows\$NtUninstallKB28138$\634996787\U\80000032.@
c:\windows\CSC\d6
c:\windows\system32\AutoRun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-10-18 to 2011-11-18 )))))))))))))))))))))))))))))))
.
.
2011-11-11 20:15 . 2011-11-11 20:15 388096 β-a-r- c:\documents and settings\Manny\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-11-11 20:15 . 2011-11-11 20:15 βββ dββw- c:\program files\Trend Micro
2011-11-11 19:42 . 2011-11-11 19:42 βββ dββw- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-11-08 18:24 . 2011-11-08 18:24 βββ dββw- c:\documents and settings\Manny\Application Data\wFFF4pmmG5QJ7
2011-11-08 18:24 . 2011-11-08 18:24 βββ dββw- c:\documents and settings\Manny\Application Data\puuvvS2ob
2011-11-08 18:24 . 2011-11-08 18:24 βββ dββw- c:\documents and settings\Manny\Application Data\THH66sWKR
2011-11-08 18:24 . 2011-11-08 18:24 βββ dββw- c:\documents and settings\Manny\Application Data\DAA00uvS2obFpm5
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2009-01-27 19:30 692736 β-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-04-14 12:41 599040 β-a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41 . 2008-07-30 02:59 611328 β-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41 . 2001-08-23 13:00 220160 β-a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41 . 2001-08-23 13:00 20480 β-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2008-04-14 08:00 1858944 β-a-w- c:\windows\system32\win32k.sys
2011-09-01 01:00 . 2009-09-10 22:36 22216 β-a-w- c:\windows\system32\drivers\mbam.sys
2011-08-22 23:48 . 2008-04-14 12:42 916480 β-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2008-04-14 12:42 1469440 ββw- c:\windows\system32\inetcpl.cpl
2011-08-22 23:48 . 2008-04-14 12:41 43520 β-a-w- c:\windows\system32\licmgr10.dll
2011-08-22 11:56 . 2008-04-14 07:07 385024 β-a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{8bc67b0f-a721-45e0-a0b6-db0121b0aade}"= "c:\program files\RadioPI_4e\bar\1.bin\4eSrcAs.dll" [2011-09-20 59344]
.
[HKEY_CLASSES_ROOT\clsid\{8bc67b0f-a721-45e0-a0b6-db0121b0aade}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{35fd2bab-ab2b-494f-b5bf-8755ec043784}]
2011-09-20 19:32 706512 β-a-w- c:\progra~1\RADIOP~2\bar\1.bin\4ebar.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4adc9c1b-9c50-4c2d-a471-5c06d8de7e80}]
2011-09-20 19:32 59344 β-a-w- c:\program files\RadioPI_4e\bar\1.bin\4eSrcAs.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{92926b63-5116-4c6f-a33e-378767b8d15f}"= "c:\program files\RadioPI_4e\bar\1.bin\4ebar.dll" [2011-09-20 706512]
.
[HKEY_CLASSES_ROOT\clsid\{92926b63-5116-4c6f-a33e-378767b8d15f}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{92926B63-5116-4C6F-A33E-378767B8D15F}"= "c:\program files\RadioPI_4e\bar\1.bin\4ebar.dll" [2011-09-20 706512]
.
[HKEY_CLASSES_ROOT\clsid\{92926b63-5116-4c6f-a33e-378767b8d15f}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-07-21 39408]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-04-11 413696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-01-07 253672]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"RadioPI_4e Browser Plugin Loader"="c:\progra~1\RADIOP~2\bar\1.bin\4ebrmon.exe" [2011-09-20 26576]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-09-01 449608]
.
c:\documents and settings\Manny\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Avira\\AntiVir Desktop\\avcenter.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
.
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/10/2009 2:32 PM 108289]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/10/2009 2:36 PM 366152]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/10/2009 2:36 PM 22216]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/21/2011 12:31 PM 136176]
S2 RadioPI_4eService;RadioPI Service;c:\progra~1\RADIOP~2\bar\1.bin\4ebarsvc.exe [9/20/2011 11:32 AM 34864]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/21/2011 12:31 PM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys β> c:\windows\system32\drivers\mbamswissarmy.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
.
2011-11-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-21 20:31]
.
2011-11-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-21 20:31]
.
2011-11-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-1580818891-1177238915-1003Core.job
- c:\documents and settings\Manny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-07 19:06]
.
2011-11-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1343024091-1580818891-1177238915-1003UA.job
- c:\documents and settings\Manny\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-12-07 19:06]
.
.
ββ- Supplementary Scan ββ-
.
uStart Page = hxxp://www.yahoo.com/?ilc=1
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki⦠- c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.1 [removed] [removed]
DPF: {14E35D5F-DEBA-4DB3-B2ED-17542BA12D1F} - hxxp://208.13.129.198/AVC_AX_DVR.cab
DPF: {389956FE-3A45-469C-B944-70308E06BAAC} - hxxp://65.40.145.90/videocom.cab
DPF: {9B479D7B-916A-45B0-B042-D42865A60E21} - hxxp://208.13.129.198/DvrOcx.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-{78ba36c9-6036-482b-b48d-ecca6f964b84} - c:\program files\RadioRage_4j\bar\1.bin\4jbar.dll
WebBrowser-{78BA36C9-6036-482B-B48D-ECCA6F964B84} - c:\program files\RadioRage_4j\bar\1.bin\4jbar.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-18 10:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes β¦
.
scanning hidden autostart entries β¦
.
scanning hidden files β¦
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
βββββββ DLLs Loaded Under Running Processes βββββββ
.
- - - - - - - > 'explorer.exe'(1948)
c:\windows\system32\WININET.dll
c:\progra~1\RADIOP~2\bar\1.bin\4ebrstub.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
ββββββββ Other Running Processes ββββββββ
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2011-11-18 10:53:17 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-18 18:53
.
Pre-Run: 233,175,031,808 bytes free
Post-Run: 235,676,139,520 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - E6150E0CE1DBCE98C5D968C76EE3CB98
Please Create and Run a CFScript:
- Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
ClearJavaCache::
Driver::
RadioPI_4eService
DDS::
uURLSearchHooks: N/A: {8bc67b0f-a721-45e0-a0b6-db0121b0aade} - c:\program files\radiopi_4e\bar\1.bin\4eSrcAs.dll
BHO: Toolbar BHO: {35fd2bab-ab2b-494f-b5bf-8755ec043784} - c:\progra~1\radiop~2\bar\1.bin\4ebar.dll
BHO: Search Assistant BHO: {4adc9c1b-9c50-4c2d-a471-5c06d8de7e80} - c:\program files\radiopi_4e\bar\1.bin\4eSrcAs.dll
TB: RadioPI: {92926b63-5116-4c6f-a33e-378767b8d15f} - c:\program files\radiopi_4e\bar\1.bin\4ebar.dll
TB: RadioRage: {78ba36c9-6036-482b-b48d-ecca6f964b84} - c:\program files\radiorage_4j\bar\1.bin\4jbar.dll
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
mRun: [RadioPI_4e Browser Plugin Loader] c:\progra~1\radiop~2\bar\1.bin\4ebrmon.exe
IE: &Search - http://tbedits.radiorage.com/one-toolbaredβ¦mp;n=2011092212
File::
c:\progra~1\radiop~2\bar\1.bin\4ebarsvc.exe
Folder::
c:\documents and settings\manny\application data\wFFF4pmmG5QJ7
c:\documents and settings\manny\application data\puuvvS2ob
c:\documents and settings\manny\application data\THH66sWKR
c:\documents and settings\manny\application data\DAA00uvS2obFpm5
- Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.
[external image: Posted Image]
- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
- If you need help to disable your protection programs see here.
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
Run TDSSKiller:
Please read carefully and follow these steps.
- Download TDSSKiller and save it to your Desktop.
- Extract its contents to your desktop.
- Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
Click to load external image (Posted Image)
- If an infected file is detected, the default action will be Cure, click on Continue.
Click to load external image (Posted Image)
- If a suspicious file is detected, the default action will be Skip, click on Continue.
Click to load external image (Posted Image)
- It may ask you to reboot the computer to complete the process. Click on Reboot Now.
Click to load external image (Posted Image)
- If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
- If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt".
- Please copy and paste the contents of that file here.
How is your machine running now? Are there any issues?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI