This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Home Security 2012 Attack [Closed]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

About 10 minutes ago my firewall switched off. When I clicked to turn it back on all these pop-ups for something called "XP Home Security 2012" started popping up. It was pretty clear that I was infected. I have no idea where this virus/Trojan/whatever it is came from but it looks bad. This could not have come at a worse time. I was in the middle of writing my thesis. Can somebody here help me? EDIT: At first SUPERAntiSpyware seemed to remove it, but after 5-10 minutes it was back. (MSE and Malwarebytes will not run) I wrote a batch file that is running: tskill nlc* in an infinite loop to keep it under control for now. EDIT: Managed to run Malwarebytes. Here is the log: ————————- Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8242 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 11/25/2011 6:53:16 PM mbam-log-2011-11-25 (18-53-16).txt Scan type: Quick scan Objects scanned: 180303 Time elapsed: 10 minute(s), 20 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe" -a "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\exefile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe" -a "%1" %*) Good: ("%1" %*) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\documents and settings\John\local settings\Temp\863.6690.exe (Malware.Packer) -> Quarantined and deleted successfully.
:welcome:

Please don't run any more tools or programs except for what we ask you to as it will just complicate cleaning you up

Lets see whats going on.

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Thank you very much for helping me. Here are the logs. aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-11-28 05:53:42 —————————– 05:53:42.109 OS Version: Windows 5.1.2600 Service Pack 3 05:53:42.109 Number of processors: 2 586 0xF06 05:53:42.109 ComputerName: J-8 UserName: 05:53:43.062 Initialize success 05:53:48.234 AVAST engine defs: 11112701 05:53:59.328 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 05:53:59.328 Disk 0 Vendor: TOSHIBA_MK1661GSYF MF000D Size: 152627MB BusType: 3 05:54:01.390 Disk 0 MBR read successfully 05:54:01.390 Disk 0 MBR scan 05:54:01.437 Disk 0 Windows VISTA default MBR code 05:54:01.437 Disk 0 scanning sectors +312576705 05:54:01.546 Disk 0 scanning C:\WINDOWS\system32\drivers 05:54:17.328 Service scanning 05:54:17.609 Service MpKsla4cd8dfb C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\MpKsla4cd8dfb.sys **LOCKED** 32 05:54:18.171 Modules scanning 05:54:32.171 Disk 0 trace - called modules: 05:54:32.187 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS 05:54:32.203 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa80ab8] 05:54:32.546 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000074[0x8aa9cd38] 05:54:32.546 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa83940] 05:54:33.250 AVAST engine scan C:\WINDOWS 05:54:48.843 AVAST engine scan C:\WINDOWS\system32 05:57:43.765 AVAST engine scan C:\WINDOWS\system32\drivers 05:58:17.671 AVAST engine scan C:\Documents and Settings\John 06:11:55.921 File: C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\6.0\30\488331de-3bba9f6b **INFECTED** Win32:ZAccess-CO [Trj] 06:42:52.968 File: C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe **INFECTED** Win32:ZAccess-CO [Trj] 07:03:48.562 AVAST engine scan C:\Documents and Settings\All Users 07:06:32.500 Scan finished successfully 07:17:49.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\John\Desktop\MBR.dat" 07:17:49.093 The log file has been saved successfully to "C:\Documents and Settings\John\Desktop\aswMBR.txt" ——————————- . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.5512 Run by [removed] at 7:27:36 on 2011-11-28 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.878 [GMT -5:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\WiFi\bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Intel\ASF Agent\ASFAgent.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Program Files\WinPcap\rpcapd.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\Program Files\DellTPad\Apoint.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe C:\Program Files\BOINC\boinctray.exe C:\WINDOWS\system32\wbem\unsecapp.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Update\1.3.21.79\GoogleCrashHandler.exe C:\Documents and Settings\John\Application Data\Dropbox\bin\Dropbox.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Program Files\PdaNet for Android\PdaNetPC.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Program Files\Microsoft Office\Office12\EXCEL.EXE C:\Documents and Settings\John\Local Settings\Application Data\Google\Chrome\Application\chrome.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.dell.com mStart Page = hxxp://www.dell.com uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/ uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: TextAloud: {f053c368-5458-45b2-9b4d-d8914bdddbff} - c:\progra~1\textal~1\TAForIE.dll uRun: [Google Update] "c:\documents and settings\john\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [Apoint] c:\program files\delltpad\Apoint.exe mRun: [DellCleanup] c:\dell\WINCLEAN.EXE mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [NVHotkey] rundll32.exe nvHotkey.dll,Start mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe" mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray mRun: [boincmgr] "c:\program files\boinc\boincmgr.exe" /a /s mRun: [boinctray] "c:\program files\boinc\boinctray.exe" mRun: [InstaLAN] "c:\program files\belkin\router setup and monitor\BelkinSetup.exe" startup mRun: [StartNowToolbarHelper] "c:\program files\startnow toolbar\ToolbarHelper.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t StartupFolder: c:\docume~1\john\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\john\application data\dropbox\bin\Dropbox.exe StartupFolder: c:\docume~1\john\startm~1\programs\startup\pdanet~1.lnk - c:\program files\pdanet for android\PdaNetPC.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab TCP: Interfaces\{BEC8201E-ABAE-46E1-BD62-3469B31D601D} : NameServer = 8.8.8.8 8.8.4.4 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\john\application data\mozilla\firefox\profiles\nnirvzdv.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 52202 FF - prefs.js: network.proxy.type - 1 FF - plugin: c:\documents and settings\john\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.67\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] R1 MpKsl6759a949;MpKsl6759a949;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a443e92a-b359-4334-a4f9-316d73c61683}\MpKsl6759a949.sys [2011-11-25 28752] R1 MpKsla4cd8dfb;MpKsla4cd8dfb;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a443e92a-b359-4334-a4f9-316d73c61683}\MpKsla4cd8dfb.sys [2011-11-26 28752] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2007-4-19 133968] R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2011-11-9 32512] R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [2011-10-7 6609920] R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [2011-9-7 9472] R4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-11-26 41272] S1 MpKsl77c167a1;MpKsl77c167a1; [x] S1 MpKsla01b577c;MpKsla01b577c;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dad1b41-f2d0-4ede-b6d8-9dd8c140b9d8}\mpksla01b577c.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3dad1b41-f2d0-4ede-b6d8-9dd8c140b9d8}\MpKsla01b577c.sys [?] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-9-30 136176] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2011-9-9 30192] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-9-30 136176] S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\drivers\nvtsp50.sys –> c:\windows\system32\drivers\NvtSp50.sys [?] . =============== File Associations =============== . .scr=ft000002 . =============== Created Last 30 ================ . 2011-11-27 00:31:31 28752 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a443e92a-b359-4334-a4f9-316d73c61683}\MpKsla4cd8dfb.sys 2011-11-26 22:59:58 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2011-11-26 03:08:38 28752 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a443e92a-b359-4334-a4f9-316d73c61683}\MpKsl6759a949.sys 2011-11-26 03:08:33 56200 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a443e92a-b359-4334-a4f9-316d73c61683}\offreg.dll 2011-11-26 03:05:46 54016 —-a-w- c:\windows\system32\drivers\vtkcjvk.sys 2011-11-25 23:53:26 54016 —-a-w- c:\windows\system32\drivers\evocs.sys 2011-11-25 18:35:53 ——– d—–w- c:\windows\system32\LogFiles 2011-11-25 18:35:02 ——– d—–w- c:\documents and settings\john\application data\384F4 2011-11-25 18:34:50 296960 —-a-w- c:\documents and settings\john\local settings\application data\nlc.exe 2011-11-25 04:39:08 ——– d—–w- C:\Ready to run with view Thesis 2011-11-25 04:29:31 ——– d—–w- C:\Copy (2) of Thesis 2011-11-25 02:24:22 ——– d—–w- C:\Base Results of Thesis 2011-11-25 02:05:57 ——– d—–w- C:\Copy of Thesis 2011-11-25 00:31:39 ——– d—–w- C:\Thesis 2011-11-24 19:49:18 6668624 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a443e92a-b359-4334-a4f9-316d73c61683}\mpengine.dll 2011-11-24 04:40:15 ——– d—–w- c:\program files\AutoCAD 2008 2011-11-24 04:40:15 ——– d—–w- c:\documents and settings\john\application data\Autodesk 2011-11-24 04:39:35 180224 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\iGdiCnv.dll 2011-11-24 04:39:34 32768 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\objpscnv.dll 2011-11-24 04:39:34 262144 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\IScrCnv.dll 2011-11-24 04:39:33 409600 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\ISRT.dll 2011-11-24 04:39:32 172032 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\IUserCnv.dll 2011-11-24 04:39:30 761856 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\IDriver.exe 2011-11-24 04:39:29 540772 —-a-w- c:\program files\common files\installshield\driver\10\intel 32\_ISRES1033.dll 2011-11-24 04:39:07 ——– d—–w- c:\documents and settings\john\local settings\application data\Autodesk 2011-11-24 04:11:50 ——– d—–w- c:\documents and settings\john\application data\SUPERAntiSpyware.com 2011-11-24 04:09:19 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-11-24 04:09:18 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com 2011-11-23 04:45:14 ——– d—–w- C:\Office 2011-11-22 00:46:55 54016 —-a-w- c:\windows\system32\drivers\cechtwji.sys 2011-11-22 00:29:01 ——– d—–w- c:\documents and settings\john\application data\Malwarebytes 2011-11-22 00:28:55 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-11-22 00:28:51 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-22 00:28:51 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-11-21 23:13:35 299520 —-a-w- c:\windows\uninst.exe 2011-11-21 00:07:53 ——– d—–w- C:\Sierra 2011-11-20 22:00:08 ——– d—–w- c:\program files\Sierra On-Line 2011-11-17 10:55:32 ——– d—–w- c:\program files\Free Convert MPEG WMV to MP4 FLV AVI Converter 2011-11-17 10:55:02 164352 —-a-w- c:\windows\system32\unrar.dll 2011-11-17 10:54:57 860160 —-a-w- c:\windows\system32\lameACM.acm 2011-11-17 10:54:56 217088 —-a-w- c:\windows\system32\yv12vfw.dll 2011-11-17 10:54:56 118784 —-a-w- c:\windows\system32\ac3acm.acm 2011-11-17 10:54:55 81920 —-a-w- c:\windows\system32\dpl100.dll 2011-11-17 10:54:55 755027 —-a-w- c:\windows\system32\xvidcore.dll 2011-11-17 10:54:55 3596288 —-a-w- c:\windows\system32\qt-dx331.dll 2011-11-17 10:54:55 159839 —-a-w- c:\windows\system32\xvidvfw.dll 2011-11-17 10:54:54 7680 —-a-w- c:\windows\system32\ff_vfw.dll 2011-11-17 10:54:54 683520 —-a-w- c:\windows\system32\divx.dll 2011-11-17 10:54:52 ——– d—–w- c:\program files\K-Lite Codec Pack 2011-11-13 20:27:43 ——– d—–w- c:\windows\system32\NtmsData 2011-11-12 23:13:10 ——– d—–w- c:\documents and settings\john\application data\Grasshopper 2011-11-11 21:37:43 ——– d—–w- c:\program files\LucasArts 2011-11-11 21:36:08 69714 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll 2011-11-11 21:36:08 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe 2011-11-11 21:36:08 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll 2011-11-11 21:36:08 184320 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll 2011-11-11 21:36:07 753664 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll 2011-11-11 21:36:01 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll 2011-11-11 21:36:01 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll 2011-11-10 03:22:15 27072 —-a-w- c:\windows\system32\drivers\AFGSp50.sys 2011-11-10 03:22:02 81920 —-a-w- c:\windows\system32\packet.dll 2011-11-10 03:22:02 61440 —-a-w- c:\windows\system32\wanpacket.dll 2011-11-10 03:22:02 57395 —-a-w- c:\windows\system32\pthreadVC.dll 2011-11-10 03:22:02 32512 —-a-w- c:\windows\system32\drivers\npf.sys 2011-11-10 03:22:02 233472 —-a-w- c:\windows\system32\wpcap.dll 2011-11-10 03:22:02 ——– d—–w- c:\program files\WinPcap 2011-11-10 03:21:58 ——– d—–w- c:\program files\Belkin 2011-11-10 03:21:58 ——– d—–w- c:\documents and settings\all users\application data\Affinegy 2011-11-09 20:40:26 ——– d—–w- C:\Shading 2011-11-04 20:52:10 ——– d—–w- c:\program files\BOINC 2011-11-04 20:52:10 ——– d—–w- c:\documents and settings\all users\application data\BOINC 2011-11-02 22:15:33 90112 —-a-w- c:\windows\unvise32.exe 2011-11-02 22:07:01 ——– d—–w- C:\DAYSIM 2011-11-02 20:17:09 ——– d—–w- c:\program files\freestar 2011-11-01 19:03:43 244024 —-a-w- c:\windows\system32\Msflxgrd.ocx 2011-11-01 19:03:42 444064 —-a-w- c:\windows\system32\Vsflex7L.ocx 2011-11-01 19:03:41 115920 —-a-w- c:\windows\system32\MSINET.OCX 2011-11-01 19:03:26 72440 —-a-w- c:\windows\system32\Gswdll32.dll 2011-11-01 19:03:26 290816 —-a-w- c:\windows\system32\Gsw32.exe 2011-11-01 19:03:26 216096 —-a-w- c:\windows\system32\Graph32.ocx 2011-11-01 19:03:23 450560 —-a-w- c:\windows\system32\Dforrt.dll 2011-11-01 19:03:22 434252 —-a-w- c:\windows\system32\Msvcrtd.dll 2011-11-01 19:03:15 155984 —-a-w- c:\windows\system32\ComDlg32.OCX 2011-11-01 18:56:30 ——– d—–w- C:\EnergyPlusV6-0-0 . ==================== Find3M ==================== . 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 02:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 02:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 02:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-08 01:06:13 1227295 —-a-w- c:\program files\unins000.exe 2011-09-06 13:25:11 1867904 —-a-w- c:\windows\system32\win32k.sys 2011-09-05 13:56:22 667136 —-a-w- c:\windows\system32\wininet.dll 2011-09-05 13:56:22 61952 —-a-w- c:\windows\system32\tdc.ocx 2011-09-05 13:56:21 81920 —-a-w- c:\windows\system32\ieencode.dll 2011-09-05 12:35:09 369664 —-a-w- c:\windows\system32\html.iec 2011-09-02 18:11:55 77824 —-a-w- c:\windows\setpwr32.exe . ============= FINISH: 7:28:42.07 ===============

Attachments:

Hi,

Looks like you may be infected with the Zero Access Rootkit. Wanted to add that nlc.exe is a password stealer so use a known clean computer and change all your passwords for any banking or sites you may shop at using a credit card

What I would like you to do is run Combofix and post the log, then rerun aswMBR again, just a scan ( DONT FIX ANYTHING ) and post the NEW LOG



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Here are the logs. Sorry it took a little while.


ComboFix 11-11-30.01 - John 11/30/2011 5:47.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1256 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\searchplugins\bing-zugo.xml
c:\documents and settings\John\Local Settings\Application Data\nlc.exe
c:\documents and settings\John\WINDOWS
C:\Documents
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\dasetup.log
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
——-\Legacy_MpKsl35a3f28f
——-\Legacy_MpKsla01b577c
——-\Legacy_Updater_Service_for_StartNow_Toolbar
——-\Service_MpKsl35a3f28f
——-\Service_MpKsla01b577c
——-\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 10:53 . 2011-11-30 10:53 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\offreg.dll
2011-11-26 22:59 . 2011-11-26 23:01 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-26 03:05 . 2011-11-26 03:05 54016 —-a-w- c:\windows\system32\drivers\vtkcjvk.sys
2011-11-25 23:53 . 2011-11-25 23:53 54016 —-a-w- c:\windows\system32\drivers\evocs.sys
2011-11-25 18:35 . 2011-11-25 18:35 ——– d—–w- c:\windows\system32\LogFiles
2011-11-25 18:35 . 2011-11-25 19:36 ——– d—–w- c:\documents and settings\John\Application Data\384F4
2011-11-25 04:39 . 2011-11-25 04:39 ——– d—–w- C:\Ready to run with view Thesis
2011-11-25 04:29 . 2011-11-25 04:29 ——– d—–w- C:\Copy (2) of Thesis
2011-11-25 02:24 . 2011-11-25 02:24 ——– d—–w- C:\Base Results of Thesis
2011-11-25 02:05 . 2011-11-25 02:05 ——– d—–w- C:\Copy of Thesis
2011-11-25 00:31 . 2011-11-26 04:52 ——– d—–w- C:\Thesis
2011-11-24 19:49 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\mpengine.dll
2011-11-24 04:40 . 2011-11-30 00:00 ——– d—–w- c:\documents and settings\John\Application Data\Autodesk
2011-11-24 04:40 . 2011-11-24 04:45 ——– d—–w- c:\program files\AutoCAD 2008
2011-11-24 04:39 . 2011-11-24 04:39 180224 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\iGdiCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 32768 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\objpscnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 262144 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IScrCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 409600 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\ISRT.dll
2011-11-24 04:39 . 2011-11-24 04:39 172032 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IUserCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 761856 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe
2011-11-24 04:39 . 2011-11-24 04:39 540772 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\_ISRES1033.dll
2011-11-24 04:39 . 2011-11-24 04:40 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Autodesk
2011-11-24 04:11 . 2011-11-24 04:11 ——– d—–w- c:\documents and settings\John\Application Data\SUPERAntiSpyware.com
2011-11-24 04:09 . 2011-11-24 04:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-24 04:09 . 2011-11-24 04:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-11-23 04:45 . 2011-11-23 21:24 ——– d—–w- C:\Office
2011-11-22 00:46 . 2011-11-22 00:46 54016 —-a-w- c:\windows\system32\drivers\cechtwji.sys
2011-11-22 00:29 . 2011-11-22 00:29 ——– d—–w- c:\documents and settings\John\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-22 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-25 23:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-22 00:28 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 23:13 . 1997-04-09 01:08 299520 —-a-w- c:\windows\uninst.exe
2011-11-21 00:07 . 2011-11-21 00:07 ——– d—–w- C:\Sierra
2011-11-20 22:00 . 2011-11-21 00:07 ——– d—–w- c:\program files\Sierra On-Line
2011-11-17 10:55 . 2011-11-17 10:55 ——– d—–w- c:\program files\Free Convert MPEG WMV to MP4 FLV AVI Converter
2011-11-17 10:55 . 2007-09-04 16:56 164352 —-a-w- c:\windows\system32\unrar.dll
2011-11-17 10:54 . 2008-07-04 06:34 860160 —-a-w- c:\windows\system32\lameACM.acm
2011-11-17 10:54 . 2007-09-21 00:52 118784 —-a-w- c:\windows\system32\ac3acm.acm
2011-11-17 10:54 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2011-11-17 10:54 . 2008-05-22 22:22 3596288 —-a-w- c:\windows\system32\qt-dx331.dll
2011-11-17 10:54 . 2008-05-22 22:19 81920 —-a-w- c:\windows\system32\dpl100.dll
2011-11-17 10:54 . 2008-01-10 12:16 159839 —-a-w- c:\windows\system32\xvidvfw.dll
2011-11-17 10:54 . 2008-01-10 12:15 755027 —-a-w- c:\windows\system32\xvidcore.dll
2011-11-17 10:54 . 2008-06-12 18:36 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2011-11-17 10:54 . 2008-05-30 23:22 683520 —-a-w- c:\windows\system32\divx.dll
2011-11-17 10:54 . 2011-11-17 10:54 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-11-13 20:27 . 2011-11-22 04:48 ——– d—–w- c:\windows\system32\NtmsData
2011-11-12 23:13 . 2011-11-13 06:38 ——– d—–w- c:\documents and settings\John\Application Data\Grasshopper
2011-11-12 20:20 . 2008-04-14 12:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-11-11 21:37 . 2011-11-11 21:37 ——– d—–w- c:\program files\LucasArts
2011-11-11 21:36 . 2005-04-04 04:02 69714 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-11-11 21:36 . 2005-04-04 04:01 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-11-11 21:36 . 2005-04-04 04:00 184320 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-11-11 21:36 . 2005-04-04 03:59 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-11-11 21:36 . 2005-04-04 04:02 753664 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-11-11 21:36 . 2011-11-11 21:36 331908 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-11-11 21:36 . 2011-11-11 21:36 200836 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-11-10 03:22 . 2009-09-10 17:48 27072 —-a-w- c:\windows\system32\drivers\AFGSp50.sys
2011-11-10 03:21 . 2011-11-10 03:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Affinegy
2011-11-10 03:21 . 2011-11-10 03:21 ——– d—–w- c:\program files\Belkin
2011-11-09 20:40 . 2011-11-10 01:05 ——– d—–w- C:\Shading
2011-11-04 20:52 . 2011-11-30 10:54 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2011-11-04 20:52 . 2011-11-04 22:16 ——– d—–w- c:\program files\BOINC
2011-11-02 22:15 . 2008-01-30 21:36 90112 —-a-w- c:\windows\unvise32.exe
2011-11-02 22:07 . 2011-11-02 22:15 ——– d—–w- C:\DAYSIM
2011-11-02 20:17 . 2011-11-02 20:17 ——– d—–w- c:\program files\freestar
2011-11-01 19:03 . 2002-08-14 14:51 244024 —-a-w- c:\windows\system32\Msflxgrd.ocx
2011-11-01 19:03 . 2002-03-22 19:40 444064 —-a-w- c:\windows\system32\Vsflex7L.ocx
2011-11-01 19:03 . 2000-05-22 04:00 115920 —-a-w- c:\windows\system32\MSINET.OCX
2011-11-01 19:03 . 2002-08-14 14:50 72440 —-a-w- c:\windows\system32\Gswdll32.dll
2011-11-01 19:03 . 2002-08-14 14:50 290816 —-a-w- c:\windows\system32\Gsw32.exe
2011-11-01 19:03 . 2002-08-14 14:50 216096 —-a-w- c:\windows\system32\Graph32.ocx
2011-11-01 19:03 . 2002-08-14 14:49 450560 —-a-w- c:\windows\system32\Dforrt.dll
2011-11-01 19:03 . 2000-03-06 23:00 434252 —-a-w- c:\windows\system32\Msvcrtd.dll
2011-11-01 19:03 . 2009-03-24 16:52 155984 —-a-w- c:\windows\system32\ComDlg32.OCX
2011-11-01 18:56 . 2011-11-23 19:29 ——– d—–w- C:\EnergyPlusV6-0-0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2011-09-11 06:10 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2008-04-25 16:16 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 02:41 . 2008-07-30 07:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 02:41 . 2008-04-25 16:16 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 02:41 . 2008-04-25 16:16 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-08 01:06 . 2011-09-08 01:06 1227295 —-a-w- c:\program files\unins000.exe
2011-09-06 13:25 . 2008-04-25 16:16 1867904 —-a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-25 16:16 667136 —-a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-25 16:16 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2008-04-25 16:16 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2008-04-25 16:16 369664 —-a-w- c:\windows\system32\html.iec
2011-09-02 18:11 . 2011-09-02 18:11 77824 —-a-w- c:\windows\setpwr32.exe
2011-07-23 02:45 . 2011-09-08 01:06 309248 —-a-w- c:\program files\mpcresources.ua.dll
2011-07-23 02:45 . 2011-09-08 01:06 305152 —-a-w- c:\program files\mpcresources.tr.dll
2011-07-23 02:45 . 2011-09-08 01:06 304128 —-a-w- c:\program files\mpcresources.sv.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.es.dll
2011-07-23 02:45 . 2011-09-08 01:06 311296 —-a-w- c:\program files\mpcresources.sk.dll
2011-07-23 02:45 . 2011-09-08 01:06 310784 —-a-w- c:\program files\mpcresources.ru.dll
2011-07-23 02:45 . 2011-09-08 01:06 315904 —-a-w- c:\program files\mpcresources.pl.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.br.dll
2011-07-23 02:45 . 2011-09-08 01:06 273920 —-a-w- c:\program files\mpcresources.kr.dll
2011-07-23 02:45 . 2011-09-08 01:06 278016 —-a-w- c:\program files\mpcresources.ja.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.it.dll
2011-07-23 02:45 . 2011-09-08 01:06 313344 —-a-w- c:\program files\mpcresources.hu.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.de.dll
2011-07-23 02:45 . 2011-09-08 01:06 295936 —-a-w- c:\program files\mpcresources.he.dll
2011-07-23 02:45 . 2011-09-08 01:06 316416 —-a-w- c:\program files\mpcresources.fr.dll
2011-07-23 02:45 . 2011-09-08 01:06 306688 —-a-w- c:\program files\mpcresources.nl.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.cz.dll
2011-07-23 02:45 . 2011-09-08 01:06 267776 —-a-w- c:\program files\mpcresources.tc.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.ca.dll
2011-07-23 02:45 . 2011-09-08 01:06 267264 —-a-w- c:\program files\mpcresources.sc.dll
2011-07-23 02:45 . 2011-09-08 01:06 307200 —-a-w- c:\program files\mpcresources.by.dll
2011-07-23 02:45 . 2011-09-08 01:06 305664 —-a-w- c:\program files\mpcresources.hy.dll
2011-07-23 02:45 . 2011-09-08 01:06 2845184 —-a-w- c:\program files\mpciconlib.dll
2011-07-23 02:45 . 2011-09-08 01:06 9981952 —-a-w- c:\program files\mpc-hc.exe
2011-09-03 06:01 . 2011-09-09 20:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-09 20:38 . 2011-09-09 20:38 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"DellCleanup"="c:\dell\WINCLEAN.EXE" [2011-09-02 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NVHotkey"="nvHotkey.dll" [2008-02-22 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-22 86016]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-09-09 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-22 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-22 1210640]
"boincmgr"="c:\program files\BOINC\boincmgr.exe" [2011-07-28 4514992]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2011-07-28 70832]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe" [2009-09-11 6788944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\John\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\John\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-9-20 447952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-9-30 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\John\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 5:56 AM 133968]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [10/7/2011 12:20 AM 6609920]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [9/7/2011 2:14 PM 9472]
S1 MpKsl77c167a1;MpKsl77c167a1; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/9/2011 3:38 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NvtSp50.sys –> c:\windows\system32\Drivers\NvtSp50.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 11:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005Core.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005UA.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-11-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-11-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-08 02:18]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52202
FF - prefs.js: network.proxy.type - 1
.
.
——- File Associations ——-
.
.scr=ft000002
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
HKLM-Run-StartNowToolbarHelper - c:\program files\StartNow Toolbar\ToolbarHelper.exe
AddRemove-StartNow Toolbar - c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-30 05:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1056)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
.
- - - - - - - > 'explorer.exe'(3796)
c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\BOINC\boinc.exe
.
**************************************************************************
.
Completion time: 2011-11-30 05:58:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-30 10:58
.
Pre-Run: 21,321,789,440 bytes free
Post-Run: 21,741,621,248 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 334E0787FAC060A70CAA5DBD2D137512



———————————



aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-28 05:53:42
—————————–
05:53:42.109 OS Version: Windows 5.1.2600 Service Pack 3
05:53:42.109 Number of processors: 2 586 0xF06
05:53:42.109 ComputerName: J-8 UserName:
05:53:43.062 Initialize success
05:53:48.234 AVAST engine defs: 11112701
05:53:59.328 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
05:53:59.328 Disk 0 Vendor: TOSHIBA_MK1661GSYF MF000D Size: 152627MB BusType: 3
05:54:01.390 Disk 0 MBR read successfully
05:54:01.390 Disk 0 MBR scan
05:54:01.437 Disk 0 Windows VISTA default MBR code
05:54:01.437 Disk 0 scanning sectors +312576705
05:54:01.546 Disk 0 scanning C:\WINDOWS\system32\drivers
05:54:17.328 Service scanning
05:54:17.609 Service MpKsla4cd8dfb C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\MpKsla4cd8dfb.sys **LOCKED** 32
05:54:18.171 Modules scanning
05:54:32.171 Disk 0 trace - called modules:
05:54:32.187 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
05:54:32.203 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa80ab8]
05:54:32.546 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000074[0x8aa9cd38]
05:54:32.546 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa83940]
05:54:33.250 AVAST engine scan C:\WINDOWS
05:54:48.843 AVAST engine scan C:\WINDOWS\system32
05:57:43.765 AVAST engine scan C:\WINDOWS\system32\drivers
05:58:17.671 AVAST engine scan C:\Documents and Settings\John
06:11:55.921 File: C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\6.0\30\488331de-3bba9f6b **INFECTED** Win32:ZAccess-CO [Trj]
06:42:52.968 File: C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe **INFECTED** Win32:ZAccess-CO [Trj]
07:03:48.562 AVAST engine scan C:\Documents and Settings\All Users
07:06:32.500 Scan finished successfully
07:17:49.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\John\Desktop\MBR.dat"
07:17:49.093 The log file has been saved successfully to "C:\Documents and Settings\John\Desktop\aswMBR.txt"


aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-30 06:08:05
—————————–
06:08:05.359 OS Version: Windows 5.1.2600 Service Pack 3
06:08:05.359 Number of processors: 2 586 0xF06
06:08:05.359 ComputerName: J-8 UserName:
06:08:06.375 Initialize success
06:17:45.625 AVAST engine defs: 11113000
06:37:13.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
06:37:13.000 Disk 0 Vendor: TOSHIBA_MK1661GSYF MF000D Size: 152627MB BusType: 3
06:37:15.062 Disk 0 MBR read successfully
06:37:15.062 Disk 0 MBR scan
06:37:15.125 Disk 0 Windows VISTA default MBR code
06:37:15.125 Disk 0 scanning sectors +312576705
06:37:15.203 Disk 0 scanning C:\WINDOWS\system32\drivers
06:37:20.343 Service scanning
06:37:21.281 Modules scanning
06:37:25.531 Disk 0 trace - called modules:
06:37:25.546 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
06:37:25.546 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa70ab8]
06:37:25.546 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000077[0x8aaa18a8]
06:37:25.546 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa87940]
06:37:26.406 AVAST engine scan C:\WINDOWS
06:37:34.953 AVAST engine scan C:\WINDOWS\system32
06:38:36.078 AVAST engine scan C:\WINDOWS\system32\drivers
06:38:43.843 AVAST engine scan C:\Documents and Settings\John
06:45:56.234 File: C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\6.0\30\488331de-3bba9f6b **INFECTED** Win32:FakeAV-COA [Trj]
07:16:41.281 AVAST engine scan C:\Documents and Settings\All Users
07:18:21.359 Scan finished successfully
16:46:38.062 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\John\Desktop\MBR.dat"
16:46:38.078 The log file has been saved successfully to "C:\Documents and Settings\John\Desktop\aswMBR.txt"
Looks like Zero Access is gone but you picked up something else along the way, Combofix logs take some time to analyse so while I am looking it over run this tool please.

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\john\my documents\downloads\(demonoid.me)-adobe_photoshop_cs5_extended_crack_2126635.3788.torrent c:\documents and settings\john\my documents\downloads\++demonoid.me++-autodesk_autocad_2008_full_version_incl_keygen_2126635.3788.torrent c:\documents and settings\john\my documents\downloads\matlab_2011a_for_windows_(32_64_bit)_iso_license_(cracked)_-demonoid.me-__2126635.3788.torrent c:\documents and settings\john\my documents\downloads\matlab_2011b_for_windows_(32_64_bit)_iso_license_(cracked)_+-demonoid.me-+_2126635.3788.torrent c:\documents and settings\john\my documents\downloads\[]demonoid.me[]-star_wars_battlefront_ii_with_crack_2126635.3788.torrent c:\documents and settings\john\my documents\downloads\adobe photoshop cs5 extended\crack\adbe_crack - 32bit.rar c:\documents and settings\john\my documents\downloads\adobe photoshop cs5 extended\crack\adbe_crack - 64bit.rar c:\documents and settings\john\my documents\downloads\adobe photoshop cs5 extended\crack\apcs5 - crack read me.txt c:\documents and settings\john\my documents\downloads\matlab_windows_2011a\crack\install.txt c:\documents and settings\john\my documents\downloads\matlab_windows_2011a\crack\lic_server.dat c:\documents and settings\john\my documents\downloads\matlab_windows_2011a\crack\lic_standalone.dat c:\documents and settings\john\my documents\downloads\matlab_windows_2011a\ml2011aw\crack\install.txt c:\documents and settings\john\my documents\downloads\matlab_windows_2011a\ml2011aw\crack\lic_server.dat c:\documents and settings\john\my documents\downloads\matlab_windows_2011a\ml2011aw\crack\lic_standalone.dat c:\documents and settings\john\my documents\downloads\matlab_windows_2011b\crack\install.txt c:\documents and settings\john\my documents\downloads\matlab_windows_2011b\crack\lic_server.dat c:\documents and settings\john\my documents\downloads\matlab_windows_2011b\crack\lic_standalone.dat c:\dropbox\dropbox\public\june fabrics pdanet v2.42\keygen.exe c:\program files\matlab\r2007b\toolbox\pde\crackb.m c:\program files\matlab\r2007b\toolbox\pde\crackg.m c:\program files\matlab\r2007b\toolbox\pde\ja\crackb.m c:\program files\matlab\r2007b\toolbox\pde\ja\crackg.m c:\program files\matlab\r2011a\resources\pde\en\crackg.xml c:\program files\matlab\r2011a\toolbox\pde\crackb.m c:\program files\matlab\r2011a\toolbox\pde\crackg.m c:\program files\matlab\r2011a\toolbox\pde\ja\crackb.m c:\program files\matlab\r2011a\toolbox\pde\ja\crackg.m c:\sierra\homeworld\homeworld.exe.cracked scanner sequence 3.ZZ.11.OWAPGJ —– EOF —–
Whoa :blush:

Let me tell you where we're at, let me explain how you infected your system and how your system will continue to be infected unless you take action on it



You have illegal software on your system, this is how you infected your computer, besides it being illegal, cracked/keygens are one of the fastest way of infecting your system, 100% of illegal software contains some form of malicious code. This forum as well as all the other malware removal forums do not support the use of illegal software, if I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime. If you you want to continue, what I need you to do is to look through the CKScanner log and uninstall all the illegal software that you have downloaded and installed . After you uninstall them all, run CKScanner again and post a new log. If I dont hear back from you in 24 hours this thread will be closed and no more help will be offered.

My apologies. I of course do not want to cause any trouble for you or this site. I'll cooperate with whatever instructions you find prudent. I have a hectic schedule and often accepted software installed, transfer files or accept links without asking any questions. Many programs are legally provided by my school and installed by helpful colleagues. Note that many of the threats listed are not installed on this machine. (I try not to throw any files away which might be useful in the future.)
I am currently doing so. Thank you for your understanding. Out of curiosity, how does CKScanner identify illegal software? I recognize some of the files on that list that contain the word "crack" or "cracked" and they are both legal and safe. In one case files are part of a toolbox for "cracking" mathematical problems or models.
Sorry, I cant divulge that information. Using any kind of File sharing, or downloading files or programs via the torrents are bad news. If you where sitting in my seat and where aware of all the latest threats, some that steal all your banking info, credit card numbers, log in info from sites you do online purchasing from, it would make your hair stand on end. There are also some threats that are uncleanable, which means that they have caused so much damage that your only option is to reformat your drive and do a clean install of windows, losing all your precious pictures and documents because there infected as well, not a lot of fun. If you want that program that you love to use, buy it legally, if you want to listen to music you love, buy the CD or download it from a legit site. I can go on and on but will stop here
All suspected files and software removed. CKScanner running now. I will be more prudent in the future about what files are stored or installed on this system. I have to reiterate that just because a file on my computer contains a word like "crack" does not make it illegal or dangerous. Many of the files on that list were certainly legit. Presuming that CKScanner looks for problems by scanning for keywords like "crack," it is bound to find many such false positives.
CKScanner - Additional Security Risks - These are not necessarily bad c:\program files\matlab\r2011a\resources\pde\en\crackg.xml scanner sequence 3.AP.11.XCAABT —– EOF —– This is also a part of the (now deleted) toolbox that I forgot to get rid of. Deleting now. Will run CKScanner one more time if needed.
Thats fine, thank you for understanding also.

Drag Combofix to the trash and download and run a fresh updated copy and post the log.



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI