This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Home Security 2012 Attack [Closed]

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 11-12-04.02 - John 12/04/2011 7:17.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1379 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
H:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 12:09 . 2011-12-04 12:09 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\MpKsld69ad287.sys
2011-12-04 12:09 . 2011-12-04 12:09 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\offreg.dll
2011-12-04 12:09 . 2011-11-21 10:47 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\mpengine.dll
2011-12-02 05:41 . 2011-12-02 05:41 ——– d—–w- c:\program files\CamStudio 2.6b
2011-12-02 05:41 . 2010-10-24 05:56 49664 —-a-w- c:\windows\system32\CamCodec.dll
2011-11-26 22:59 . 2011-11-26 23:01 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-26 03:05 . 2011-11-26 03:05 54016 —-a-w- c:\windows\system32\drivers\vtkcjvk.sys
2011-11-25 23:53 . 2011-11-25 23:53 54016 —-a-w- c:\windows\system32\drivers\evocs.sys
2011-11-25 18:35 . 2011-11-25 18:35 ——– d—–w- c:\windows\system32\LogFiles
2011-11-25 18:35 . 2011-11-25 19:36 ——– d—–w- c:\documents and settings\John\Application Data\384F4
2011-11-25 04:39 . 2011-11-25 04:39 ——– d—–w- C:\Ready to run with view Thesis
2011-11-25 04:29 . 2011-11-25 04:29 ——– d—–w- C:\Copy (2) of Thesis
2011-11-25 02:24 . 2011-11-25 02:24 ——– d—–w- C:\Base Results of Thesis
2011-11-25 02:05 . 2011-11-25 02:05 ——– d—–w- C:\Copy of Thesis
2011-11-25 00:31 . 2011-11-26 04:52 ——– d—–w- C:\Thesis
2011-11-24 04:40 . 2011-11-30 00:00 ——– d—–w- c:\documents and settings\John\Application Data\Autodesk
2011-11-24 04:40 . 2011-11-24 04:45 ——– d—–w- c:\program files\AutoCAD 2008
2011-11-24 04:39 . 2011-11-24 04:39 180224 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\iGdiCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 32768 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\objpscnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 262144 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IScrCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 409600 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\ISRT.dll
2011-11-24 04:39 . 2011-11-24 04:39 172032 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IUserCnv.dll
2011-11-24 04:39 . 2011-11-24 04:39 761856 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\IDriver.exe
2011-11-24 04:39 . 2011-11-24 04:39 540772 —-a-w- c:\program files\Common Files\InstallShield\Driver\10\Intel 32\_ISRES1033.dll
2011-11-24 04:39 . 2011-11-24 04:40 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\Autodesk
2011-11-24 04:11 . 2011-11-24 04:11 ——– d—–w- c:\documents and settings\John\Application Data\SUPERAntiSpyware.com
2011-11-24 04:09 . 2011-11-24 04:11 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-24 04:09 . 2011-11-24 04:09 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-11-23 04:45 . 2011-11-23 21:24 ——– d—–w- C:\Office
2011-11-22 00:46 . 2011-11-22 00:46 54016 —-a-w- c:\windows\system32\drivers\cechtwji.sys
2011-11-22 00:29 . 2011-11-22 00:29 ——– d—–w- c:\documents and settings\John\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-22 00:28 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-22 00:28 . 2011-11-25 23:40 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-22 00:28 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 23:13 . 1997-04-09 01:08 299520 —-a-w- c:\windows\uninst.exe
2011-11-21 00:07 . 2011-11-21 00:07 ——– d—–w- C:\Sierra
2011-11-20 22:00 . 2011-11-21 00:07 ——– d—–w- c:\program files\Sierra On-Line
2011-11-17 10:55 . 2011-11-17 10:55 ——– d—–w- c:\program files\Free Convert MPEG WMV to MP4 FLV AVI Converter
2011-11-17 10:55 . 2007-09-04 16:56 164352 —-a-w- c:\windows\system32\unrar.dll
2011-11-17 10:54 . 2008-07-04 06:34 860160 —-a-w- c:\windows\system32\lameACM.acm
2011-11-17 10:54 . 2007-09-21 00:52 118784 —-a-w- c:\windows\system32\ac3acm.acm
2011-11-17 10:54 . 2004-01-25 16:18 217088 —-a-w- c:\windows\system32\yv12vfw.dll
2011-11-17 10:54 . 2008-05-22 22:22 3596288 —-a-w- c:\windows\system32\qt-dx331.dll
2011-11-17 10:54 . 2008-05-22 22:19 81920 —-a-w- c:\windows\system32\dpl100.dll
2011-11-17 10:54 . 2008-01-10 12:16 159839 —-a-w- c:\windows\system32\xvidvfw.dll
2011-11-17 10:54 . 2008-01-10 12:15 755027 —-a-w- c:\windows\system32\xvidcore.dll
2011-11-17 10:54 . 2008-06-12 18:36 7680 —-a-w- c:\windows\system32\ff_vfw.dll
2011-11-17 10:54 . 2008-05-30 23:22 683520 —-a-w- c:\windows\system32\divx.dll
2011-11-17 10:54 . 2011-11-17 10:54 ——– d—–w- c:\program files\K-Lite Codec Pack
2011-11-13 20:27 . 2011-11-22 04:48 ——– d—–w- c:\windows\system32\NtmsData
2011-11-12 23:13 . 2011-11-13 06:38 ——– d—–w- c:\documents and settings\John\Application Data\Grasshopper
2011-11-12 20:20 . 2008-04-14 12:00 26624 —-a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2011-11-11 21:37 . 2011-11-11 21:37 ——– d—–w- c:\program files\LucasArts
2011-11-11 21:36 . 2005-04-04 04:02 69714 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\ctor.dll
2011-11-11 21:36 . 2005-04-04 04:01 274432 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iscript.dll
2011-11-11 21:36 . 2005-04-04 04:00 184320 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iuser.dll
2011-11-11 21:36 . 2005-04-04 03:59 5632 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\DotNetInstaller.exe
2011-11-11 21:36 . 2005-04-04 04:02 753664 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iKernel.dll
2011-11-11 21:36 . 2011-11-11 21:36 331908 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\setup.dll
2011-11-11 21:36 . 2011-11-11 21:36 200836 —-a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\11\00\Intel32\iGdi.dll
2011-11-10 03:22 . 2009-09-10 17:48 27072 —-a-w- c:\windows\system32\drivers\AFGSp50.sys
2011-11-10 03:21 . 2011-11-10 03:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Affinegy
2011-11-10 03:21 . 2011-11-10 03:21 ——– d—–w- c:\program files\Belkin
2011-11-09 20:40 . 2011-11-10 01:05 ——– d—–w- C:\Shading
2011-11-04 20:52 . 2011-12-04 11:59 ——– d—–w- c:\documents and settings\All Users\Application Data\BOINC
2011-11-04 20:52 . 2011-11-04 22:16 ——– d—–w- c:\program files\BOINC
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-09-11 06:10 6823496 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-10-10 14:22 . 2008-04-25 21:27 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2008-04-25 16:16 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 02:41 . 2008-07-30 07:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 02:41 . 2008-04-25 16:16 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 02:41 . 2008-04-25 16:16 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-08 01:06 . 2011-09-08 01:06 1227295 —-a-w- c:\program files\unins000.exe
2011-09-06 13:25 . 2008-04-25 16:16 1867904 —-a-w- c:\windows\system32\win32k.sys
2011-09-05 13:56 . 2008-04-25 16:16 667136 —-a-w- c:\windows\system32\wininet.dll
2011-09-05 13:56 . 2008-04-25 16:16 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-09-05 13:56 . 2008-04-25 16:16 81920 —-a-w- c:\windows\system32\ieencode.dll
2011-09-05 12:35 . 2008-04-25 16:16 369664 —-a-w- c:\windows\system32\html.iec
2011-07-23 02:45 . 2011-09-08 01:06 309248 —-a-w- c:\program files\mpcresources.ua.dll
2011-07-23 02:45 . 2011-09-08 01:06 305152 —-a-w- c:\program files\mpcresources.tr.dll
2011-07-23 02:45 . 2011-09-08 01:06 304128 —-a-w- c:\program files\mpcresources.sv.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.es.dll
2011-07-23 02:45 . 2011-09-08 01:06 311296 —-a-w- c:\program files\mpcresources.sk.dll
2011-07-23 02:45 . 2011-09-08 01:06 310784 —-a-w- c:\program files\mpcresources.ru.dll
2011-07-23 02:45 . 2011-09-08 01:06 315904 —-a-w- c:\program files\mpcresources.pl.dll
2011-07-23 02:45 . 2011-09-08 01:06 312320 —-a-w- c:\program files\mpcresources.br.dll
2011-07-23 02:45 . 2011-09-08 01:06 273920 —-a-w- c:\program files\mpcresources.kr.dll
2011-07-23 02:45 . 2011-09-08 01:06 278016 —-a-w- c:\program files\mpcresources.ja.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.it.dll
2011-07-23 02:45 . 2011-09-08 01:06 313344 —-a-w- c:\program files\mpcresources.hu.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.de.dll
2011-07-23 02:45 . 2011-09-08 01:06 295936 —-a-w- c:\program files\mpcresources.he.dll
2011-07-23 02:45 . 2011-09-08 01:06 316416 —-a-w- c:\program files\mpcresources.fr.dll
2011-07-23 02:45 . 2011-09-08 01:06 306688 —-a-w- c:\program files\mpcresources.nl.dll
2011-07-23 02:45 . 2011-09-08 01:06 308736 —-a-w- c:\program files\mpcresources.cz.dll
2011-07-23 02:45 . 2011-09-08 01:06 267776 —-a-w- c:\program files\mpcresources.tc.dll
2011-07-23 02:45 . 2011-09-08 01:06 310272 —-a-w- c:\program files\mpcresources.ca.dll
2011-07-23 02:45 . 2011-09-08 01:06 267264 —-a-w- c:\program files\mpcresources.sc.dll
2011-07-23 02:45 . 2011-09-08 01:06 307200 —-a-w- c:\program files\mpcresources.by.dll
2011-07-23 02:45 . 2011-09-08 01:06 305664 —-a-w- c:\program files\mpcresources.hy.dll
2011-07-23 02:45 . 2011-09-08 01:06 2845184 —-a-w- c:\program files\mpciconlib.dll
2011-07-23 02:45 . 2011-09-08 01:06 9981952 —-a-w- c:\program files\mpc-hc.exe
2011-09-03 06:01 . 2011-09-09 20:32 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-09-09 20:38 . 2011-09-09 20:38 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-11-30_10.54.20 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-12-04 11:57 . 2011-12-04 11:57 16384 c:\windows\Temp\Perflib_Perfdata_630.dat
+ 2011-09-08 00:40 . 2011-12-04 02:39 27744 c:\windows\system32\nvModes.dat
- 2011-09-08 00:40 . 2011-11-29 09:25 27744 c:\windows\system32\nvModes.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\John\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-07 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2010-02-17 278528]
"DellCleanup"="c:\dell\WINCLEAN.EXE" [2011-09-02 212992]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-02-22 13508608]
"nwiz"="nwiz.exe" [2008-02-22 1626112]
"NVHotkey"="nvHotkey.dll" [2008-02-22 86016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-02-22 86016]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2011-09-09 30192]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2007-05-14 1191936]
"IntelZeroConfig"="c:\program files\Intel\WiFi\bin\ZCfgSvc.exe" [2011-06-22 1407248]
"IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-06-22 1210640]
"boincmgr"="c:\program files\BOINC\boincmgr.exe" [2011-07-28 4514992]
"boinctray"="c:\program files\BOINC\boinctray.exe" [2011-07-28 70832]
"InstaLAN"="c:\program files\Belkin\Router Setup and Monitor\BelkinSetup.exe" [2009-09-11 6788944]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\John\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\John\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
PdaNet Desktop.lnk - c:\program files\PdaNet for Android\PdaNetPC.exe [2011-9-20 447952]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2011-9-30 113664]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\John\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Opera\\opera.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R1 MpKsld69ad287;MpKsld69ad287;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5C8EDF44-D1EB-4EA2-B351-4839BADF2C80}\MpKsld69ad287.sys [12/4/2011 7:09 AM 29904]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 6:38 PM 116608]
R2 ASFAgent;ASF Agent;c:\program files\Intel\ASF Agent\ASFAgent.exe [4/19/2007 5:56 AM 133968]
R3 NETwLx32; Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows XP 32 Bit;c:\windows\system32\drivers\NETwLx32.sys [10/7/2011 12:20 AM 6609920]
R3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [9/7/2011 2:14 PM 9472]
S1 MpKsl77c167a1;MpKsl77c167a1; [x]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [9/9/2011 3:38 PM 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [9/30/2011 11:44 PM 136176]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\Drivers\NvtSp50.sys –> c:\windows\system32\Drivers\NvtSp50.sys [?]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [4/25/2008 11:16 AM 14336]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLD69AD287
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-01 04:44]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005Core.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2236261959-3548182743-1203336554-1005UA.job
- c:\documents and settings\John\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-07 19:25]
.
2011-12-04 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2011-12-04 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2011-09-08 02:18]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\documents and settings\John\Application Data\Mozilla\Firefox\Profiles\nnirvzdv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.gmail.com
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 52202
FF - prefs.js: network.proxy.type - 1
.
.
——- File Associations ——-
.
.scr=ft000002
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 07:29
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1064)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\program files\Common Files\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
c:\windows\system32\netprovcredman.dll
.
Completion time: 2011-12-04 07:31:07
ComboFix-quarantined-files.txt 2011-12-04 12:31
ComboFix2.txt 2011-11-30 10:58
.
Pre-Run: 27,081,134,080 bytes free
Post-Run: 37,447,417,856 bytes free
.
- - End Of File - - 1DDA729C4A4BD8D07BA00ACF93DC5FC9
Hi,

Lets see what's going on with this file



You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again

c:\windows\system32\drivers\cechtwji.sys <—-This file

If the site is busy you can try this one
http://virusscan.jotti.org/en






ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI