XP Home Security 2012 Attack [Closed]
10 min read
Please don't run any more tools or programs except for what we ask you to as it will just complicate cleaning you up
Lets see whats going on.
Download aswMBR.exe ( 511KB ) to your desktop.
Double click the aswMBR.exe to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Download DDS from one of the links below to your desktop
Link 1
Link 2
- Double click the tool to run it.
- A black Screen will open, just read the contents and do nothing.
- When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
- Copy/Paste the contents of 'DDS.txt' into your post.
- 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Looks like you may be infected with the Zero Access Rootkit. Wanted to add that nlc.exe is a password stealer so use a known clean computer and change all your passwords for any banking or sites you may shop at using a credit card
What I would like you to do is run Combofix and post the log, then rerun aswMBR again, just a scan ( DONT FIX ANYTHING ) and post the NEW LOG
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
- See this Link for programs that need to be disabled and instruction on how to disable them.
- Remember to re-enable them when we're done.
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-11-30.01 - John 11/30/2011 5:47.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1256 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\searchplugins\bing-zugo.xml
c:\documents and settings\John\Local Settings\Application Data\nlc.exe
c:\documents and settings\John\WINDOWS
C:\Documents
c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\dasetup.log
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
——-\Legacy_MpKsl35a3f28f
——-\Legacy_MpKsla01b577c
——-\Legacy_Updater_Service_for_StartNow_Toolbar
——-\Service_MpKsl35a3f28f
——-\Service_MpKsla01b577c
——-\Service_Updater Service for StartNow Toolbar
.
.
((((((((((((((((((((((((( Files Created from 2011-10-28 to 2011-11-30 )))))))))))))))))))))))))))))))
.
.
2011-11-30 10:53 . 2011-11-30 10:53 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\offreg.dll
2011-11-26 22:59 . 2011-11-26 23:01 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-26 03:05 . 2011-11-26 03:05 54016 —-a-w- c:\windows\system32\drivers\vtkcjvk.sys
2011-11-25 23:53 . 2011-11-25 23:53 54016 —-a-w- c:\windows\system32\drivers\evocs.sys
2011-11-25 18:35 . 2011-11-25 18:35 ——– d—–w- c:\windows\system32\LogFiles
2011-11-25 18:35 . 2011-11-25 19:36 ——– d—–w- c:\documents and settings\John\Application Data\384F4
2011-11-25 04:39 . 2011-11-25 04:39 ——– d—–w- C:\Ready to run with view Thesis
2011-11-25 04:29 . 2011-11-25 04:29 ——– d—–w- C:\Copy (2) of Thesis
2011-11-25 02:24 . 2011-11-25 02:24 ——– d—–w- C:\Base Results of Thesis
2011-11-25 02:05 . 2011-11-25 02:05 ——– d—–w- C:\Copy of Thesis
2011-11-25 00:31 . 2011-11-26 04:52 ——– d—–w- C:\Thesis
2011-11-24 19:49 . 2011-10-07 03:48 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\mpengine.dll
2011-11-24 04:40 . 2011-11-30 00:00 ——– d—–w- c:\documents and settings\John\Application Data\Autodesk
2011-11-24 04:40 . 2011-11-24 04:45 ——– d—–w- c:\program files\AutoCAD 2008
2011-11-24 04:39 . 2011-11-24 04:39 180224 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\iGdiCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 32768 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\objpscnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 262144 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IScrCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 409600 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\ISRT.dll
2011-11-24 04:39 . 2011-11-24 04:39 172032 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IUserCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 761856 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe
2011-11-24 04:39 . 2011-11-24 04:39 540772 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\_ISRES1033.dll
2011-11-24 04:39 . 2011-11-24 04:40 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Autodesk
2011-11-24 04:11 . 2011-11-24 04:11 ——– d—–w- c:\documents and settings\John\Application Data\SUPERAntiSpyware.com
2011-11-24 04:09 . 2011-11-24 04:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-24 04:09 . 2011-11-24 04:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-11-23 04:45 . 2011-11-23 21:24 ——– d—–w- C:\Office
2011-11-22 00:46 . 2011-11-22 00:46 54016 —-a-w- c:\windows\system32\drivers\cechtwji.sys
2011-11-22 00:29 . 2011-11-22 00:29 ——– d—–w- c:\documents and settings\John\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-22 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-25 23:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-22 00:28 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 23:13 . 1997-04-09 01:08 299520 —-a-w- c:\windows\uninst.exe
2011-11-21 00:07 . 2011-11-21 00:07 ——– d—–w- C:\Sierra
2011-11-20 22:00 . 2011-11-21 00:07 ——– d—–w- c:\program files\Sierra On-Line
2011-11-17 10:55 . 2011-11-17 10:55 ——– d—–w- c:\program files\Free Convert MPEG WMV to MP4 FLV AVI Converter
2011-11-17 10:55 . 2007-09-04 16:56 164352 —-a-w- c:\windows\system32\unrar.dll
2011-11-17 10:54 . 2008-07-04 06:34 860160 —-a-w- c:\windows\system32\lameACM.acm
2011-11-17 10:54 . 2007-09-21 00:52 118784 —-a-w- c:\windows\system32\ac3acm.acm
2011-11-17 10:54 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2011-11-17 10:54 . 2008-05-22 22:22 3596288 —-a-w- c:\windows\system32\qt-dx331.dll
2011-11-17 10:54 . 2008-05-22 22:19 81920 —-a-w- c:\windows\system32\dpl100.dll
2011-11-17 10:54 . 2008-01-10 12:16 159839 —-a-w- c:\windows\system32\xvidvfw.dll
2011-11-17 10:54 . 2008-01-10 12:15 755027 —-a-w- c:\windows\system32\xvidcore.dll
2011-11-17 10:54 . 2008-06-12 18:36 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2011-11-17 10:54 . 2008-05-30 23:22 683520 —-a-w- c:\windows\system32\divx.dll
2011-11-17 10:54 . 2011-11-17 10:54 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-11-13 20:27 . 2011-11-22 04:48 ——– d—–w- c:\windows\system32\NtmsData
2011-11-12 23:13 . 2011-11-13 06:38 ——– d—–w- c:\documents and settings\John\Application Data\Grasshopper
2011-11-12 20:20 . 2008-04-14 12:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-11-11 21:37 . 2011-11-11 21:37 ——– d—–w- c:\program files\LucasArts
2011-11-11 21:36 . 2005-04-04 04:02 69714 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-11-11 21:36 . 2005-04-04 04:01 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-11-11 21:36 . 2005-04-04 04:00 184320 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-11-11 21:36 . 2005-04-04 03:59 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-11-11 21:36 . 2005-04-04 04:02 753664 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-11-11 21:36 . 2011-11-11 21:36 331908 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-11-11 21:36 . 2011-11-11 21:36 200836 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-11-10 03:22 . 2009-09-10 17:48 27072 —-a-w- c:\windows\system32\drivers\AFGSp50.sys
2011-11-10 03:21 . 2011-11-10 03:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Affinegy
2011-11-10 03:21 . 2011-11-10 03:21 ——– d—–w- c:\program files\Belkin
2011-11-09 20:40 . 2011-11-10 01:05 ——– d—–w- C:\Shading
2011-11-04 20:52 . 2011-11-30 10:54 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2011-11-04 20:52 . 2011-11-04 22:16 ——– d—–w- c:\program files\BOINC
2011-11-02 22:15 . 2008-01-30 21:36 90112 —-a-w- c:\windows\unvise32.exe
2011-11-02 22:07 . 2011-11-02 22:15 ——– d—–w- C:\DAYSIM
2011-11-02 20:17 . 2011-11-02 20:17 ——– d—–w- c:\program files\freestar
2011-11-01 19:03 . 2002-08-14 14:51 244024 —-a-w- c:\windows\system32\Msflxgrd.ocx
2011-11-01 19:03 . 2002-03-22 19:40 444064 —-a-w- c:\windows\system32\Vsflex7L.ocx
2011-11-01 19:03 . 2000-05-22 04:00 115920 —-a-w- c:\windows\system32\MSINET.OCX
2011-11-01 19:03 . 2002-08-14 14:50 72440 —-a-w- c:\windows\system32\Gswdll32.dll
2011-11-01 19:03 . 2002-08-14 14:50 290816 —-a-w- c:\windows\system32\Gsw32.exe
2011-11-01 19:03 . 2002-08-14 14:50 216096 —-a-w- c:\windows\system32\Graph32.ocx
2011-11-01 19:03 . 2002-08-14 14:49 450560 —-a-w- c:\windows\system32\Dforrt.dll
2011-11-01 19:03 . 2000-03-06 23:00 434252 —-a-w- c:\windows\system32\Msvcrtd.dll
2011-11-01 19:03 . 2009-03-24 16:52 155984 —-a-w- c:\windows\system32\ComDlg32.OCX
2011-11-01 18:56 . 2011-11-23 19:29 ——– d—–w- C:\EnergyPlusV6-0-0
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-10-10 14:22 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 03:48 . 2011-09-11 06:10 6668624 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-28 07:06 . 2008-04-25 16:16 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 02:41 . 2008-07-30 07:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 02:41 . 2008-04-25 16:16 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 02:41 . 2008-04-25 16:16 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-08 01:06 . 2011-09-08 01:06 1227295 —-a-w- c:\program files\unins000.exe
2011-09-06 13:25 . 2008-04-25 16:16 1867904 —-a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-25 16:16 667136 —-a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-25 16:16 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2008-04-25 16:16 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2008-04-25 16:16 369664 —-a-w- c:\windows\system32\html.iec
2011-09-02 18:11 . 2011-09-02 18:11 77824 —-a-w- c:\windows\setpwr32.exe
2011-07-23 02:45 . 2011-09-08 01:06 309248 —-a-w- c:\program files\mpcresources.ua.dll
2011-07-23 02:45 . 2011-09-08 01:06 305152 —-a-w- c:\program files\mpcresources.tr.dll
2011-07-23 02:45 . 2011-09-08 01:06 304128 —-a-w- c:\program files\mpcresources.sv.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.es.dll
2011-07-23 02:45 . 2011-09-08 01:06 311296 —-a-w- c:\program files\mpcresources.sk.dll
2011-07-23 02:45 . 2011-09-08 01:06 310784 —-a-w- c:\program files\mpcresources.ru.dll
2011-07-23 02:45 . 2011-09-08 01:06 315904 —-a-w- c:\program files\mpcresources.pl.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.br.dll
2011-07-23 02:45 . 2011-09-08 01:06 273920 —-a-w- c:\program files\mpcresources.kr.dll
2011-07-23 02:45 . 2011-09-08 01:06 278016 —-a-w- c:\program files\mpcresources.ja.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.it.dll
2011-07-23 02:45 . 2011-09-08 01:06 313344 —-a-w- c:\program files\mpcresources.hu.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.de.dll
2011-07-23 02:45 . 2011-09-08 01:06 295936 —-a-w- c:\program files\mpcresources.he.dll
2011-07-23 02:45 . 2011-09-08 01:06 316416 —-a-w- c:\program files\mpcresources.fr.dll
2011-07-23 02:45 . 2011-09-08 01:06 306688 —-a-w- c:\program files\mpcresources.nl.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.cz.dll
2011-07-23 02:45 . 2011-09-08 01:06 267776 —-a-w- c:\program files\mpcresources.tc.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.ca.dll
2011-07-23 02:45 . 2011-09-08 01:06 267264 —-a-w- c:\program files\mpcresources.sc.dll
2011-07-23 02:45 . 2011-09-08 01:06 307200 —-a-w- c:\program files\mpcresources.by.dll
2011-07-23 02:45 . 2011-09-08 01:06 305664 —-a-w- c:\program files\mpcresources.hy.dll
2011-07-23 02:45 . 2011-09-08 01:06 2845184 —-a-w- c:\program files\mpciconlib.dll
2011-07-23 02:45 . 2011-09-08 01:06 9981952 —-a-w- c:\program files\mpc-hc.exe
2011-09-03 06:01 . 2011-09-09 20:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-09 20:38 . 2011-09-09 20:38 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"DellCleanup"="c:\dell\WINCLEAN.EXE" [2011-09-02 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NVHotkey"="nvHotkey.dll" [2008-02-22 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-22 86016]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-09-09 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-22 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-22 1210640]
"boincmgr"="c:\program files\BOINC\boincmgr.exe" [2011-07-28 4514992]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2011-07-28 70832]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe" [2009-09-11 6788944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\John\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\John\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-9-20 447952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-9-30 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\John\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 5:56 AM 133968]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [10/7/2011 12:20 AM 6609920]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [9/7/2011 2:14 PM 9472]
S1 MpKsl77c167a1;MpKsl77c167a1; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/9/2011 3:38 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NvtSp50.sys –> c:\windows\system32\Drivers\NvtSp50.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 11:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005Core.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-11-30 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005UA.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-11-30 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-11-30 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-08 02:18]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52202
FF - prefs.js: network.proxy.type - 1
.
.
——- File Associations ——-
.
.scr=ft000002
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
HKLM-Run-StartNowToolbarHelper - c:\program files\StartNow Toolbar\ToolbarHelper.exe
AddRemove-StartNow Toolbar - c:\program files\StartNow Toolbar\StartNowToolbarUninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-11-30 05:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1056)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
.
- - - - - - - > 'explorer.exe'(3796)
c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\program files\SUPERAntiSpyware\SASSEH.DLL
c:\program files\Microsoft Office\Office12\1033\GrooveIntlResource.dll
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
.
———————— Other Running Processes ————————
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Belkin\Router Setup and Monitor\BelkinService.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Dell\QuickSet\NICCONFIGSVC.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Common Files\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\BOINC\boinc.exe
.
**************************************************************************
.
Completion time: 2011-11-30 05:58:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-11-30 10:58
.
Pre-Run: 21,321,789,440 bytes free
Post-Run: 21,741,621,248 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 334E0787FAC060A70CAA5DBD2D137512
———————————
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-28 05:53:42
—————————–
05:53:42.109 OS Version: Windows 5.1.2600 Service Pack 3
05:53:42.109 Number of processors: 2 586 0xF06
05:53:42.109 ComputerName: J-8 UserName:
05:53:43.062 Initialize success
05:53:48.234 AVAST engine defs: 11112701
05:53:59.328 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
05:53:59.328 Disk 0 Vendor: TOSHIBA_MK1661GSYF MF000D Size: 152627MB BusType: 3
05:54:01.390 Disk 0 MBR read successfully
05:54:01.390 Disk 0 MBR scan
05:54:01.437 Disk 0 Windows VISTA default MBR code
05:54:01.437 Disk 0 scanning sectors +312576705
05:54:01.546 Disk 0 scanning C:\WINDOWS\system32\drivers
05:54:17.328 Service scanning
05:54:17.609 Service MpKsla4cd8dfb C:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{A443E92A-B359-4334-A4F9-316D73C61683}\MpKsla4cd8dfb.sys **LOCKED** 32
05:54:18.171 Modules scanning
05:54:32.171 Disk 0 trace - called modules:
05:54:32.187 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
05:54:32.203 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa80ab8]
05:54:32.546 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000074[0x8aa9cd38]
05:54:32.546 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa83940]
05:54:33.250 AVAST engine scan C:\WINDOWS
05:54:48.843 AVAST engine scan C:\WINDOWS\system32
05:57:43.765 AVAST engine scan C:\WINDOWS\system32\drivers
05:58:17.671 AVAST engine scan C:\Documents and Settings\John
06:11:55.921 File: C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\6.0\30\488331de-3bba9f6b **INFECTED** Win32:ZAccess-CO [Trj]
06:42:52.968 File: C:\Documents and Settings\John\Local Settings\Application Data\nlc.exe **INFECTED** Win32:ZAccess-CO [Trj]
07:03:48.562 AVAST engine scan C:\Documents and Settings\All Users
07:06:32.500 Scan finished successfully
07:17:49.093 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\John\Desktop\MBR.dat"
07:17:49.093 The log file has been saved successfully to "C:\Documents and Settings\John\Desktop\aswMBR.txt"
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-11-30 06:08:05
—————————–
06:08:05.359 OS Version: Windows 5.1.2600 Service Pack 3
06:08:05.359 Number of processors: 2 586 0xF06
06:08:05.359 ComputerName: J-8 UserName:
06:08:06.375 Initialize success
06:17:45.625 AVAST engine defs: 11113000
06:37:13.000 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
06:37:13.000 Disk 0 Vendor: TOSHIBA_MK1661GSYF MF000D Size: 152627MB BusType: 3
06:37:15.062 Disk 0 MBR read successfully
06:37:15.062 Disk 0 MBR scan
06:37:15.125 Disk 0 Windows VISTA default MBR code
06:37:15.125 Disk 0 scanning sectors +312576705
06:37:15.203 Disk 0 scanning C:\WINDOWS\system32\drivers
06:37:20.343 Service scanning
06:37:21.281 Modules scanning
06:37:25.531 Disk 0 trace - called modules:
06:37:25.546 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS
06:37:25.546 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa70ab8]
06:37:25.546 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\00000077[0x8aaa18a8]
06:37:25.546 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa87940]
06:37:26.406 AVAST engine scan C:\WINDOWS
06:37:34.953 AVAST engine scan C:\WINDOWS\system32
06:38:36.078 AVAST engine scan C:\WINDOWS\system32\drivers
06:38:43.843 AVAST engine scan C:\Documents and Settings\John
06:45:56.234 File: C:\Documents and Settings\John\Application Data\Sun\Java\Deployment\cache\6.0\30\488331de-3bba9f6b **INFECTED** Win32:FakeAV-COA [Trj]
07:16:41.281 AVAST engine scan C:\Documents and Settings\All Users
07:18:21.359 Scan finished successfully
16:46:38.062 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\John\Desktop\MBR.dat"
16:46:38.078 The log file has been saved successfully to "C:\Documents and Settings\John\Desktop\aswMBR.txt"
Download CKScanner by askey127 from Here & save it to your Desktop.
- Doubleclick CKScanner.exe then click Search For Files
- When the cursor hourglass disappears, click Save List To File
- A message box will verify the file saved
- Please Run this program only once
- Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Let me tell you where we're at, let me explain how you infected your system and how your system will continue to be infected unless you take action on it
You have illegal software on your system, this is how you infected your computer, besides it being illegal, cracked/keygens are one of the fastest way of infecting your system, 100% of illegal software contains some form of malicious code. This forum as well as all the other malware removal forums do not support the use of illegal software, if I was to continue helping you it could be construed in the eyes of the law as aiding and abetting a crime. If you you want to continue, what I need you to do is to look through the CKScanner log and uninstall all the illegal software that you have downloaded and installed . After you uninstall them all, run CKScanner again and post a new log. If I dont hear back from you in 24 hours this thread will be closed and no more help will be offered.
Drag Combofix to the trash and download and run a fresh updated copy and post the log.
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
- See this Link for programs that need to be disabled and instruction on how to disable them.
- Remember to re-enable them when we're done.
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI