This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

browser redirect, ping.exe using all resouces [Solved]

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

And thanks in advance for this forum and any help you might provide.

I developed a slow operating system with stalls and freezes a few days ago. While it was annoying, I didn't bother to react right away as it could have been anything. But now I have browser redirects and several programs that refuse to open. I use PC tools, but it is mostly turned off because it interferes with gaming. I turned it on and scanned and it cleaned a lot of problems but didn't solve anything. Then I used TDSSKiller and it found 3 or 4 more issues. But the problem persists. So I have followed the instructions for "Are you infected?" The logs follow as requested. I downloaded HiJack This and DDS also. Do you want those files too?

OTL logfile created on: 12/1/2011 7:29:58 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1023.48 Mb Total Physical Memory | 341.15 Mb Available Physical Memory | 33.33% Memory free
2.40 Gb Paging File | 1.84 Gb Available in Paging File | 76.52% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 79.77 Gb Free Space | 71.36% Space Free | Partition Type: NTFS

Computer Name: M-A192F4C1027D4 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\PC Tools Security\BDT\BSPatch.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\NETGEAR\WG311v3\WlanDll.dll ()
MOD - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)


========== Driver Services (SafeList) ==========

DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (PCTBD) – C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (Htsysm) – C:\WINDOWS\system32\HtsysmNT.sys ()
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (W8335XP) NETGEAR WG311v3 802.11g Wireless PCI Adapter for Windows XP (8335) – C:\WINDOWS\system32\drivers\WG311v3XP.sys (Marvell Semiconductor, Inc)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.lotro.com;*.turbine.com;12.130.63.*;206.17.109.*
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:54808

========== FireFox ==========

FF - prefs.js..network.proxy.type: 4

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011/11/11 06:20:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/28 17:47:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/01 23:54:16 | 000,000,000 | —D | M]

[2010/09/10 04:05:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/09/06 11:28:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions
[2011/09/06 11:28:13 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/03/12 08:16:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/03 13:25:15 | 000,000,000 | —D | M] (vShare Plugin) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\vshare@toolbar
[2010/10/09 19:55:42 | 000,001,820 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\searchplugins\bing.xml
[2011/11/28 17:47:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/28 17:47:23 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/04 11:07:11 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/28 17:47:23 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

Hosts file not found
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [408809432] C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.EXE /r "C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.rpd" File not found
O4 - HKLM..\Run: [MozillaAgent] C:\WINDOWS\Temp\_ex-68.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [2230012402] C:\Documents and Settings\Owner\Local Settings\Application Data\xsb.exe File not found
O4 - HKCU..\Run: [Spyware Doctor with AntiVirus] C:\Documents and Settings\Owner\Desktop\sdasetup.exe -min File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA0992D5-09CD-4887-8AA3-0DE0C21E8169}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (MrvGINA.dll) -C:\WINDOWS\System32\MrvGINA.dll (Marvell®)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/03 12:38:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/12/01 19:26:49 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/01 19:26:14 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/01 19:06:33 | 004,731,432 | —- | C] (SpeedyPC Software Inc.) – C:\Documents and Settings\Owner\Desktop\RepairTool.exe
[2011/12/01 18:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/11/30 13:29:11 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/30 13:29:11 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/30 13:05:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\40107822.sys
[2011/11/24 12:33:42 | 001,566,512 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2011/11/11 06:38:02 | 000,574,424 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/11/11 06:38:02 | 000,054,328 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/11/11 06:38:02 | 000,035,264 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/11/11 06:20:40 | 002,291,664 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/11/11 06:20:40 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/11/11 06:20:40 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/11/11 06:20:40 | 000,056,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTBD.sys
[2011/11/11 06:20:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/11/11 06:20:27 | 000,017,848 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctBTFix.sys
[2011/11/11 06:18:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\TestApp
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/01 19:28:56 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/01 19:27:39 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/12/01 19:26:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/01 19:26:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/01 19:06:45 | 004,731,432 | —- | M] (SpeedyPC Software Inc.) – C:\Documents and Settings\Owner\Desktop\RepairTool.exe
[2011/12/01 17:59:27 | 000,868,017 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/12/01 17:59:20 | 000,029,204 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/01 17:57:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/01 06:52:44 | 226,189,610 | —- | M] () – C:\Documents and Settings\Owner\Desktop\populationsc17900006unit.pdf
[2011/11/30 13:29:11 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/30 13:29:11 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/30 13:05:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\40107822.sys
[2011/11/30 13:04:03 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/28 17:46:48 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/27 21:19:42 | 000,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/27 21:19:42 | 000,071,250 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/27 21:10:39 | 1073,299,456 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/11/15 11:33:00 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/11 06:34:48 | 000,341,656 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/11/09 23:08:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/08 17:25:28 | 000,002,935 | —- | M] () – C:\Documents and Settings\Owner\My Documents\S-61.odb
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/01 06:28:46 | 226,189,610 | —- | C] () – C:\Documents and Settings\Owner\Desktop\populationsc17900006unit.pdf
[2011/11/29 17:47:35 | 000,012,254 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/29 17:47:35 | 000,012,254 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/11 06:20:40 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/11/11 06:20:40 | 000,003,488 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/11/11 06:20:40 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/11/11 06:20:40 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/11/11 06:20:40 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/11/08 17:17:30 | 000,002,935 | —- | C] () – C:\Documents and Settings\Owner\My Documents\S-61.odb
[2011/09/09 18:44:20 | 000,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
[2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
[2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\734ic5kl480kc2nvg31
[2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\734ic5kl480kc2nvg31
[2011/06/05 21:01:23 | 000,004,109 | —- | C] () – C:\Documents and Settings\Owner\Application Data\267E.B5F
[2011/05/30 06:37:30 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/04/30 07:55:27 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2011/01/07 19:36:56 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\HtsysmNT.sys
[2010/12/10 21:14:27 | 000,000,070 | —- | C] () – C:\WINDOWS\Esv44JBS5X2.dll
[2010/12/10 21:14:27 | 000,000,004 | —- | C] () – C:\WINDOWS\Esv44JBS5X.dll
[2010/09/10 04:05:00 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/09/09 21:32:20 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/03 17:33:38 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2010/09/03 12:58:58 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/09/03 12:58:55 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/09/03 12:58:55 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/09/03 12:40:34 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/09/03 12:36:37 | 000,023,348 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/09/03 08:28:15 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/09/03 08:27:13 | 000,118,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/07/20 23:07:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,441,124 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,071,250 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat

========== LOP Check ==========

[2011/12/01 18:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/19 19:22:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2010/12/30 11:35:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2010/12/04 19:01:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Magic Match
[2010/09/06 15:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/09/05 06:25:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/04/30 08:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony Online Entertainment
[2011/09/09 19:09:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/11/11 06:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TestApp
[2011/06/30 19:36:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Turbine

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010/09/03 12:38:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/12/01 19:27:39 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/09/05 07:26:55 | 000,000,211 | -HS- | M] () – C:\boot.ini.old
[2010/09/03 12:38:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/09/03 12:38:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/03 12:38:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/26 05:00:23 | 003,607,552 | —- | M] () – C:\NETGEAR WG311v3 802.11g Wireless PCI Adapter.msi
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/04 08:28:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/01 17:57:28 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2011/06/06 04:07:06 | 000,034,998 | —- | M] () – C:\TDSSKiller.2.5.3.0_06.06.2011_05.06.49_log.txt
[2011/11/30 13:02:24 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.3.0_30.11.2011_13.02.13_log.txt
[2011/05/31 18:19:51 | 000,035,958 | —- | M] () – C:\TDSSKiller.2.5.3.0_31.05.2011_19.19.13_log.txt
[2011/12/01 05:24:21 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_05.23.47_log.txt
[2011/12/01 07:03:10 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_06.44.55_log.txt
[2011/12/01 17:59:45 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_17.59.32_log.txt
[2011/11/30 13:05:27 | 000,045,304 | —- | M] () – C:\TDSSKiller.2.6.21.0_30.11.2011_13.04.25_log.txt

< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/09/08 11:30:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/09/08 17:02:12 | 000,001,546 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/09/08 07:16:10 | 000,524,288 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011/09/08 10:46:34 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2011/09/08 07:16:10 | 020,709,376 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011/09/08 07:16:10 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/09/08 22:12:01 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All LS\x00\x00\x00\x00
I was wondering if I should continue to add the other logs I made. This whole ping virus has me about ready to reformat and and start over. Thanks,
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:54808
    O4 - HKLM..\Run: [408809432] C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.EXE /r "C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.rpd" File not found
    O4 - HKLM..\Run: [MozillaAgent] C:\WINDOWS\Temp\_ex-68.exe File not found
    O4 - HKCU..\Run: [2230012402] C:\Documents and Settings\Owner\Local Settings\Application Data\xsb.exe File not found
    [2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
    [2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
    [2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
    [2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
    [2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\734ic5kl480kc2nvg31
    [2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\734ic5kl480kc2nvg31
    [2011/06/05 21:01:23 | 000,004,109 | —- | C] () – C:\Documents and Settings\Owner\Application Data\267E.B5F
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log



NEXT


  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Catbyte,

Thanks so much for replying. Some notes this morning… I had PCTools running when I read your reply, pasted in the data into OTL, and attempted to run the program. PCTools popped up a warning box, and OTL was deleted. It all happened too quick to react. I downloaded OTL again, turned off PCTools and ran the program as requested. OTL then caused a Windows pop up box to appear with the error "The file or directory C:\$Mft is corrupt and unreadable. Please run Chkdsk utility."

OTL worked anyway. I'm not sure if that error is relevant. Here is the OTL file. I'll run aswMBR.exe next and post it in a minute or two.

Thanks again,

Zdac


All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\408809432 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MozillaAgent not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\2230012402 not found.
C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5 moved successfully.
C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5 moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512 moved successfully.
C:\Documents and Settings\All Users\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512 moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\734ic5kl480kc2nvg31 moved successfully.
C:\Documents and Settings\All Users\Application Data\734ic5kl480kc2nvg31 moved successfully.
C:\Documents and Settings\Owner\Application Data\267E.B5F moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Owner\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Owner\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
HOSTS file reset successfully

[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 56504 bytes

User: All Users

User: Default User
->Flash cache emptied: 56504 bytes

User: LocalService
->Flash cache emptied: 11062 bytes

User: NetworkService
->Flash cache emptied: 48840 bytes

User: Owner
->Flash cache emptied: 793 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 69612 bytes
->Temporary Internet Files folder emptied: 3531963 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 278328806 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 311791779 bytes
->Temporary Internet Files folder emptied: 102580882 bytes
->Java cache emptied: 1733019 bytes
->FireFox cache emptied: 50838535 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 4324566 bytes
%systemroot%\System32 .tmp files removed: 3770897 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 128537960 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 78092172 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 124760 bytes

Total Files Cleaned = 919.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12042011_071953

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
Catbyte, No issues with the aswMBR.exe tool. Here is the log file and the zipped file. Thanks, Zdac aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-04 07:42:58 —————————– 07:42:58.468 OS Version: Windows 5.1.2600 Service Pack 3 07:42:58.500 Number of processors: 1 586 0x2F02 07:42:58.500 ComputerName: M-A192F4C1027D4 UserName: Owner 07:43:18.156 Initialize success 07:46:54.187 AVAST engine defs: 11120400 07:52:54.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts2Port3Path0Target0Lun0 07:52:54.406 Disk 0 Vendor: WDC_WD12 02.0 Size: 114473MB BusType: 3 07:52:54.406 Device \Driver\nvgts -> DriverStartIo SCSIPORT.SYS f72b640e 07:52:54.421 Disk 0 MBR read successfully 07:52:54.421 Disk 0 MBR scan 07:52:54.468 Disk 0 Windows XP default MBR code 07:52:54.468 Disk 0 malicious Win32:MBRoot code @ sector 61 ! 07:52:54.484 Disk 0 PE file @ sector 234436545 ! 07:52:54.531 Disk 0 scanning C:\WINDOWS\system32\drivers 07:53:03.031 File: C:\WINDOWS\system32\drivers\redbook.sys **INFECTED** Win32:Aluroot [Rtk] 07:53:05.015 Service scanning 07:53:06.234 Modules scanning 07:53:08.984 Module: C:\WINDOWS\system32\DRIVERS\redbook.sys **SUSPICIOUS** 07:53:12.468 Disk 0 trace - called modules: 07:53:12.500 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8672df10]<< 07:53:12.515 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d5f840] 07:53:12.515 3 CLASSPNP.SYS[f74e7fd7] -> nt!IofCallDriver -> [0x86710278] 07:53:12.515 \Driver\00000882[0x866d0268] -> IRP_MJ_CREATE -> 0x8672df10 07:53:13.046 AVAST engine scan C:\WINDOWS 07:53:14.890 File: C:\WINDOWS\1626822744:2812741791.exe **INFECTED** Win32:Tiny-AMB [Rtk] 07:53:22.796 AVAST engine scan C:\WINDOWS\system32 07:55:03.765 AVAST engine scan C:\WINDOWS\system32\drivers 07:55:12.984 File: C:\WINDOWS\system32\drivers\redbook.sys **INFECTED** Win32:Aluroot [Rtk] 07:55:16.703 AVAST engine scan C:\Documents and Settings\Owner 07:56:23.921 AVAST engine scan C:\Documents and Settings\All Users 07:56:39.781 Scan finished successfully 07:58:59.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 07:58:59.234 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"

Attachments:

Hi

Please do the following:

I'd like to get a dump of the MBR outside of the Windows environment.

You will need a CD

Download GETxPUD.exe to the desktop of your clean computer
  • Run GETxPUD.exe
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and when finished, it will open BurnCDCC which will be ready to burn the image.
  • Click on Start and follow the prompts to burn the image to a CD.


NEXT

  • Boot the infected computer with the CD you just burned
  • The computer must be set to boot from the CD
  • Follow the prompts
  • A Welcome to xPUD screen will appear
  • Click on File
  • Expand mnt
  • sda1 or sda2 will usually correspond to your HDD
  • expand the folder that corresponds to your harddrive.
  • Press Tool on the top menu bar
  • Choose Open Terminal
  • Type dd if=/dev/sda of=mbr.bin bs=512 count=1

This will place a back-up of your MBR on your harddrive it will be called C:/mbr.bin


Now exit > Home > reboot (remove the CD so your computer will boot normally)

Please attach a copy of c:\mbr.bin in your next reply (you may need to zip it up to attach it)


NEXT


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Catbyte,

Attached is the mbr.bin file. I zipped it as suggested.

TDSSKiller log is pasted next. It found no infections.

17:14:37.0859 3824 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44
17:14:38.0281 3824 ============================================================
17:14:38.0281 3824 Current date / time: 2011/12/04 17:14:38.0281
17:14:38.0281 3824 SystemInfo:
17:14:38.0281 3824
17:14:38.0281 3824 OS Version: 5.1.2600 ServicePack: 3.0
17:14:38.0281 3824 Product type: Workstation
17:14:38.0281 3824 ComputerName: M-A192F4C1027D4
17:14:38.0281 3824 UserName: Owner
17:14:38.0281 3824 Windows directory: C:\WINDOWS
17:14:38.0281 3824 System windows directory: C:\WINDOWS
17:14:38.0281 3824 Processor architecture: Intel x86
17:14:38.0281 3824 Number of processors: 1
17:14:38.0281 3824 Page size: 0x1000
17:14:38.0281 3824 Boot type: Normal boot
17:14:38.0281 3824 ============================================================
17:14:39.0125 3824 Initialize success
17:14:42.0453 2064 ============================================================
17:14:42.0453 2064 Scan started
17:14:42.0453 2064 Mode: Manual;
17:14:42.0453 2064 ============================================================
17:14:44.0421 2064 Abiosdsk - ok
17:14:44.0468 2064 abp480n5 - ok
17:14:44.0625 2064 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
17:14:44.0656 2064 ACPI - ok
17:14:44.0703 2064 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
17:14:44.0718 2064 ACPIEC - ok
17:14:44.0765 2064 adpu160m - ok
17:14:45.0109 2064 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
17:14:45.0140 2064 aec - ok
17:14:45.0281 2064 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
17:14:45.0312 2064 AFD - ok
17:14:45.0328 2064 Aha154x - ok
17:14:45.0390 2064 aic78u2 - ok
17:14:45.0406 2064 aic78xx - ok
17:14:46.0062 2064 ALCXWDM (35045a23957a71ba649740741e69408c) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
17:14:46.0609 2064 ALCXWDM - ok
17:14:46.0718 2064 AliIde - ok
17:14:46.0796 2064 amsint - ok
17:14:46.0984 2064 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
17:14:46.0984 2064 Arp1394 - ok
17:14:47.0187 2064 asc - ok
17:14:47.0343 2064 asc3350p - ok
17:14:47.0609 2064 asc3550 - ok
17:14:48.0031 2064 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
17:14:48.0062 2064 AsyncMac - ok
17:14:48.0468 2064 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
17:14:48.0515 2064 atapi - ok
17:14:48.0890 2064 Atdisk - ok
17:14:49.0281 2064 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
17:14:49.0343 2064 Atmarpc - ok
17:14:49.0781 2064 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
17:14:49.0828 2064 audstub - ok
17:14:50.0218 2064 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
17:14:50.0234 2064 Beep - ok
17:14:50.0593 2064 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
17:14:50.0640 2064 cbidf2k - ok
17:14:50.0937 2064 cd20xrnt - ok
17:14:51.0375 2064 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
17:14:51.0390 2064 Cdaudio - ok
17:14:51.0750 2064 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
17:14:51.0781 2064 Cdfs - ok
17:14:52.0156 2064 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
17:14:52.0187 2064 Cdrom - ok
17:14:52.0437 2064 Changer - ok
17:14:52.0734 2064 CmdIde - ok
17:14:53.0046 2064 Cpqarray - ok
17:14:53.0312 2064 dac2w2k - ok
17:14:53.0671 2064 dac960nt - ok
17:14:54.0015 2064 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
17:14:54.0046 2064 Disk - ok
17:14:54.0687 2064 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
17:14:55.0281 2064 dmboot - ok
17:14:55.0718 2064 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
17:14:55.0843 2064 dmio - ok
17:14:56.0203 2064 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
17:14:56.0218 2064 dmload - ok
17:14:56.0515 2064 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
17:14:56.0625 2064 DMusic - ok
17:14:56.0921 2064 dpti2o - ok
17:14:57.0218 2064 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
17:14:57.0218 2064 drmkaud - ok
17:14:57.0640 2064 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
17:14:57.0734 2064 Fastfat - ok
17:14:58.0140 2064 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
17:14:58.0171 2064 Fdc - ok
17:14:58.0546 2064 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
17:14:58.0578 2064 Fips - ok
17:14:58.0953 2064 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
17:14:59.0031 2064 Flpydisk - ok
17:14:59.0437 2064 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
17:14:59.0453 2064 FltMgr - ok
17:14:59.0781 2064 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
17:14:59.0796 2064 Fs_Rec - ok
17:15:00.0093 2064 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
17:15:00.0125 2064 Ftdisk - ok
17:15:00.0500 2064 gameenum (065639773d8b03f33577f6cdaea21063) C:\WINDOWS\system32\DRIVERS\gameenum.sys
17:15:00.0531 2064 gameenum - ok
17:15:00.0921 2064 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
17:15:00.0937 2064 Gpc - ok
17:15:01.0281 2064 hpn - ok
17:15:01.0562 2064 Htsysm (57bd2878b475f530a9cf965c785c74a3) C:\WINDOWS\system32\HtsysmNT.sys
17:15:01.0593 2064 Htsysm - ok
17:15:02.0015 2064 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
17:15:02.0218 2064 HTTP - ok
17:15:02.0562 2064 i2omgmt - ok
17:15:02.0937 2064 i2omp - ok
17:15:03.0328 2064 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
17:15:03.0343 2064 i8042prt - ok
17:15:03.0718 2064 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
17:15:03.0734 2064 Imapi - ok
17:15:04.0046 2064 ini910u - ok
17:15:04.0437 2064 IntelIde - ok
17:15:04.0812 2064 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
17:15:04.0843 2064 Ip6Fw - ok
17:15:05.0140 2064 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
17:15:05.0156 2064 IpFilterDriver - ok
17:15:05.0468 2064 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
17:15:05.0500 2064 IpInIp - ok
17:15:05.0812 2064 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
17:15:05.0843 2064 IpNat - ok
17:15:06.0218 2064 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
17:15:06.0234 2064 IPSec - ok
17:15:06.0671 2064 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
17:15:06.0734 2064 IRENUM - ok
17:15:07.0125 2064 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
17:15:07.0140 2064 isapnp - ok
17:15:07.0515 2064 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
17:15:07.0531 2064 Kbdclass - ok
17:15:07.0906 2064 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
17:15:07.0953 2064 kmixer - ok
17:15:08.0343 2064 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
17:15:08.0453 2064 KSecDD - ok
17:15:08.0656 2064 lbrtfdc - ok
17:15:09.0015 2064 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
17:15:09.0031 2064 mnmdd - ok
17:15:09.0390 2064 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
17:15:09.0406 2064 Modem - ok
17:15:09.0765 2064 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
17:15:09.0781 2064 Mouclass - ok
17:15:10.0265 2064 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
17:15:10.0265 2064 MountMgr - ok
17:15:10.0515 2064 mraid35x - ok
17:15:10.0953 2064 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
17:15:11.0093 2064 MRxDAV - ok
17:15:11.0515 2064 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
17:15:11.0828 2064 MRxSmb - ok
17:15:12.0187 2064 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
17:15:12.0203 2064 Msfs - ok
17:15:12.0593 2064 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
17:15:12.0609 2064 MSKSSRV - ok
17:15:12.0890 2064 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
17:15:12.0906 2064 MSPCLOCK - ok
17:15:13.0234 2064 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
17:15:13.0250 2064 MSPQM - ok
17:15:13.0546 2064 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
17:15:13.0562 2064 mssmbios - ok
17:15:13.0875 2064 ms_mpu401 (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
17:15:13.0890 2064 ms_mpu401 - ok
17:15:14.0265 2064 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
17:15:14.0296 2064 Mup - ok
17:15:14.0718 2064 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
17:15:14.0812 2064 NDIS - ok
17:15:15.0156 2064 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
17:15:15.0171 2064 NdisTapi - ok
17:15:15.0515 2064 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
17:15:15.0546 2064 Ndisuio - ok
17:15:15.0843 2064 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
17:15:15.0875 2064 NdisWan - ok
17:15:16.0218 2064 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
17:15:16.0234 2064 NDProxy - ok
17:15:16.0578 2064 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
17:15:16.0593 2064 NetBIOS - ok
17:15:16.0906 2064 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
17:15:17.0000 2064 NetBT - ok
17:15:17.0390 2064 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys
17:15:17.0406 2064 NIC1394 - ok
17:15:17.0703 2064 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
17:15:17.0750 2064 Npfs - ok
17:15:18.0343 2064 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
17:15:18.0703 2064 Ntfs - ok
17:15:19.0078 2064 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
17:15:19.0093 2064 Null - ok
17:15:20.0218 2064 nv (7fe3f1721856365c882dae13f3600223) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
17:15:22.0140 2064 nv - ok
17:15:22.0343 2064 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
17:15:22.0406 2064 NVENETFD - ok
17:15:22.0984 2064 nvgts (ea98bfe4931bd13d747d647c1859796e) C:\WINDOWS\system32\DRIVERS\nvgts.sys
17:15:22.0984 2064 nvgts - ok
17:15:23.0406 2064 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
17:15:23.0437 2064 nvnetbus - ok
17:15:23.0781 2064 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
17:15:23.0796 2064 NwlnkFlt - ok
17:15:24.0125 2064 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
17:15:24.0140 2064 NwlnkFwd - ok
17:15:24.0531 2064 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
17:15:24.0546 2064 ohci1394 - ok
17:15:24.0937 2064 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
17:15:24.0984 2064 Parport - ok
17:15:25.0281 2064 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
17:15:25.0312 2064 PartMgr - ok
17:15:25.0671 2064 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
17:15:25.0718 2064 ParVdm - ok
17:15:26.0109 2064 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
17:15:26.0156 2064 PCI - ok
17:15:26.0406 2064 PCIDump - ok
17:15:26.0828 2064 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
17:15:26.0843 2064 PCIIde - ok
17:15:27.0203 2064 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
17:15:27.0218 2064 Pcmcia - ok
17:15:27.0578 2064 PCTBD (3a0262b85b5bb4d4cfc096ea00ed610b) C:\WINDOWS\system32\Drivers\PCTBD.sys
17:15:27.0578 2064 PCTBD - ok
17:15:28.0093 2064 PCTCore (3a1efee38dcc8db0b0ee8bb98edd950d) C:\WINDOWS\system32\drivers\PCTCore.sys
17:15:28.0359 2064 PCTCore - ok
17:15:28.0687 2064 pctDS (af08ec0f2093867ab955e24121ee7002) C:\WINDOWS\system32\drivers\pctDS.sys
17:15:28.0828 2064 pctDS - ok
17:15:29.0296 2064 pctEFA (4b1b0cd45a047c0941f6b6151f6fb3c1) C:\WINDOWS\system32\drivers\pctEFA.sys
17:15:29.0500 2064 pctEFA - ok
17:15:30.0031 2064 pctgntdi (92f69754ad3f18ccc7e7232ca5262029) C:\WINDOWS\system32\drivers\pctgntdi.sys
17:15:30.0234 2064 pctgntdi - ok
17:15:30.0640 2064 pctplsg (91aa056e365e1e093cf6e43540e60b28) C:\WINDOWS\system32\drivers\pctplsg.sys
17:15:30.0671 2064 pctplsg - ok
17:15:31.0078 2064 PCTSD (6f8c66b756eccff3e75d362a8c66b21e) C:\WINDOWS\system32\Drivers\PCTSD.sys
17:15:31.0109 2064 PCTSD - ok
17:15:31.0390 2064 PDCOMP - ok
17:15:31.0593 2064 PDFRAME - ok
17:15:31.0953 2064 PDRELI - ok
17:15:32.0234 2064 PDRFRAME - ok
17:15:32.0578 2064 perc2 - ok
17:15:32.0843 2064 perc2hib - ok
17:15:33.0281 2064 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
17:15:33.0312 2064 PptpMiniport - ok
17:15:33.0781 2064 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
17:15:33.0812 2064 Processor - ok
17:15:34.0234 2064 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
17:15:34.0250 2064 PSched - ok
17:15:34.0687 2064 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
17:15:34.0687 2064 Ptilink - ok
17:15:35.0031 2064 ql1080 - ok
17:15:35.0359 2064 Ql10wnt - ok
17:15:35.0671 2064 ql12160 - ok
17:15:36.0000 2064 ql1240 - ok
17:15:36.0234 2064 ql1280 - ok
17:15:36.0609 2064 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
17:15:36.0625 2064 RasAcd - ok
17:15:37.0015 2064 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
17:15:37.0031 2064 Rasl2tp - ok
17:15:37.0390 2064 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
17:15:37.0406 2064 RasPppoe - ok
17:15:37.0781 2064 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
17:15:37.0796 2064 Raspti - ok
17:15:38.0140 2064 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
17:15:38.0203 2064 Rdbss - ok
17:15:38.0578 2064 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
17:15:38.0593 2064 RDPCDD - ok
17:15:39.0000 2064 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys
17:15:39.0140 2064 RDPWD - ok
17:15:39.0468 2064 redbook (a80a417168cfb6080b26d5b66b3163dd) C:\WINDOWS\system32\DRIVERS\redbook.sys
17:15:39.0500 2064 redbook - ok
17:15:39.0750 2064 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
17:15:39.0765 2064 Secdrv - ok
17:15:40.0171 2064 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
17:15:40.0187 2064 serenum - ok
17:15:40.0562 2064 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
17:15:40.0578 2064 Serial - ok
17:15:40.0937 2064 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
17:15:40.0968 2064 Sfloppy - ok
17:15:41.0234 2064 Simbad - ok
17:15:41.0578 2064 Sparrow - ok
17:15:41.0843 2064 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
17:15:41.0937 2064 splitter - ok
17:15:42.0281 2064 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
17:15:42.0312 2064 sr - ok
17:15:42.0796 2064 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
17:15:43.0031 2064 Srv - ok
17:15:43.0375 2064 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
17:15:43.0390 2064 swenum - ok
17:15:43.0859 2064 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
17:15:43.0921 2064 swmidi - ok
17:15:44.0328 2064 symc810 - ok
17:15:44.0703 2064 symc8xx - ok
17:15:45.0250 2064 sym_hi - ok
17:15:45.0671 2064 sym_u3 - ok
17:15:46.0187 2064 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
17:15:47.0031 2064 sysaudio - ok
17:15:47.0328 2064 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
17:15:47.0343 2064 Tcpip - ok
17:15:47.0421 2064 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
17:15:47.0421 2064 TDPIPE - ok
17:15:47.0437 2064 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
17:15:47.0437 2064 TDTCP - ok
17:15:47.0453 2064 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
17:15:47.0453 2064 TermDD - ok
17:15:47.0515 2064 TfFsMon (eb8f8b25bb64452d86d2bd577607694a) C:\WINDOWS\system32\drivers\TfFsMon.sys
17:15:47.0531 2064 TfFsMon - ok
17:15:47.0625 2064 TfNetMon (8d157e44ba7f87c8744ac977ca428c1d) C:\WINDOWS\system32\drivers\TfNetMon.sys
17:15:47.0625 2064 TfNetMon - ok
17:15:47.0687 2064 TfSysMon (c866eb15c3cb83dac8f348abe6a42ea7) C:\WINDOWS\system32\drivers\TfSysMon.sys
17:15:47.0687 2064 TfSysMon - ok
17:15:47.0750 2064 TosIde - ok
17:15:47.0812 2064 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
17:15:47.0812 2064 Udfs - ok
17:15:47.0828 2064 ultra - ok
17:15:47.0890 2064 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
17:15:47.0906 2064 Update - ok
17:15:47.0968 2064 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
17:15:47.0968 2064 usbehci - ok
17:15:48.0031 2064 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
17:15:48.0031 2064 usbhub - ok
17:15:48.0062 2064 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
17:15:48.0062 2064 usbohci - ok
17:15:48.0078 2064 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
17:15:48.0078 2064 USBSTOR - ok
17:15:48.0125 2064 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
17:15:48.0125 2064 VgaSave - ok
17:15:48.0140 2064 ViaIde - ok
17:15:48.0140 2064 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
17:15:48.0156 2064 VolSnap - ok
17:15:48.0218 2064 W8335XP (7455b3c11a1d6a844b53febdb58646e9) C:\WINDOWS\system32\DRIVERS\WG311v3XP.sys
17:15:48.0218 2064 W8335XP - ok
17:15:48.0250 2064 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
17:15:48.0265 2064 Wanarp - ok
17:15:48.0265 2064 WDICA - ok
17:15:48.0312 2064 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
17:15:48.0312 2064 wdmaud - ok
17:15:48.0375 2064 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
17:15:48.0375 2064 WS2IFSL - ok
17:15:48.0437 2064 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
17:15:48.0437 2064 WudfPf - ok
17:15:48.0453 2064 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
17:15:48.0453 2064 WudfRd - ok
17:15:48.0500 2064 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
17:15:48.0609 2064 \Device\Harddisk0\DR0 - ok
17:15:48.0609 2064 Boot (0x1200) (1c35434a34625f0fa09c33d18c71b9af) \Device\Harddisk0\DR0\Partition0
17:15:48.0609 2064 \Device\Harddisk0\DR0\Partition0 - ok
17:15:48.0625 2064 ============================================================
17:15:48.0625 2064 Scan finished
17:15:48.0625 2064 ============================================================
17:15:48.0625 2056 Detected object count: 0
17:15:48.0625 2056 Actual detected object count: 0
17:17:36.0156 3380 Deinitialize success

Last is the Combofix log. It warned me I had a nasty rootkit infection and that it might take some time. Combofix also told me I had PCTools running, however I had disabled it prior to using Combo and I verified by checking task manager. I didn't see anything, but I'm not that savvy, so who knows? It follows…

ComboFix 11-12-04.04 - Owner 12/04/2011 17:59:38.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.784 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: PC Tools Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Owner\Recent\Redir-NVIDIA.url
c:\windows\$NtUninstallKB20679$
c:\windows\$NtUninstallKB20679$\1482225504\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB20679$\1482225504\click.tlb
c:\windows\$NtUninstallKB20679$\1482225504\L\vewbymva
c:\windows\$NtUninstallKB20679$\1482225504\loader.tlb
c:\windows\$NtUninstallKB20679$\1482225504\U\@00000001
c:\windows\$NtUninstallKB20679$\1482225504\U\@000000c0
c:\windows\$NtUninstallKB20679$\1482225504\U\@000000cb
c:\windows\$NtUninstallKB20679$\1482225504\U\@000000cf
c:\windows\$NtUninstallKB20679$\1482225504\U\@80000000
c:\windows\$NtUninstallKB20679$\1482225504\U\@800000c0
c:\windows\$NtUninstallKB20679$\1482225504\U\@800000cb
c:\windows\$NtUninstallKB20679$\1482225504\U\@800000cf
c:\windows\$NtUninstallKB20679$\779263299
c:\windows\$NtUninstallKB44856$\1482225504\@
c:\windows\$NtUninstallKB44856$\1482225504\bckfg.tmp
c:\windows\$NtUninstallKB44856$\1482225504\cfg.ini
c:\windows\$NtUninstallKB44856$\1482225504\Desktop.ini
c:\windows\$NtUninstallKB44856$\1482225504\keywords
c:\windows\$NtUninstallKB44856$\1482225504\kwrd.dll
c:\windows\$NtUninstallKB44856$\1482225504\L\vewbymva
c:\windows\$NtUninstallKB44856$\1482225504\lsflt7.ver
c:\windows\$NtUninstallKB44856$\1482225504\U\00000001.@
c:\windows\$NtUninstallKB44856$\1482225504\U\00000002.@
c:\windows\$NtUninstallKB44856$\1482225504\U\00000004.@
c:\windows\$NtUninstallKB44856$\1482225504\U\80000000.@
c:\windows\$NtUninstallKB44856$\1482225504\U\80000004.@
c:\windows\$NtUninstallKB44856$\1482225504\U\80000032.@
c:\windows\$NtUninstallKB44856$\4188973248
c:\windows\{2521BB91-29B1-4d7e-9137-AC9875D77735}
c:\windows\system32\drivers\npf.sys
c:\windows\system32\MrvGINA.dll
c:\windows\system32\wpcap.dll
c:\windows\$NtUninstallKB44856$ . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-04 23:10 . 2011-12-04 23:10 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2011-12-04 11:54 . 2011-12-04 11:54 ——– d—–w- C:\_OTL
2011-12-04 02:56 . 2011-12-04 03:19 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-03 13:57 . 2011-12-03 13:57 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2011-12-03 11:20 . 2011-12-03 11:20 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2011-12-03 11:19 . 2011-12-03 11:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-03 11:19 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-03 11:19 . 2011-12-03 11:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-01 23:12 . 2011-12-01 23:12 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-11-30 18:05 . 2011-11-30 18:05 94896 —-a-w- c:\windows\system32\drivers\40107822.sys
2011-11-11 11:38 . 2011-10-28 02:49 574424 –s—w- c:\windows\system32\drivers\TfSysMon.sys
2011-11-11 11:38 . 2011-10-28 02:49 54328 –s—w- c:\windows\system32\drivers\TfFsMon.sys
2011-11-11 11:38 . 2011-10-28 02:49 35264 –s—w- c:\windows\system32\drivers\TfNetMon.sys
2011-11-11 11:20 . 2011-10-25 18:38 149456 —-a-w- c:\windows\SGDetectionTool.dll
2011-11-11 11:20 . 2011-10-25 18:38 2291664 —-a-w- c:\windows\PCTBDCore.dll
2011-11-11 11:20 . 2011-10-25 18:38 1681360 —-a-w- c:\windows\PCTBDRes.dll
2011-11-11 11:20 . 2011-10-25 18:38 767952 —-a-w- c:\windows\BDTSupport.dll
2011-11-11 11:20 . 2011-09-28 18:14 56840 —-a-w- c:\windows\system32\drivers\PCTBD.sys
2011-11-11 11:20 . 2011-10-28 16:01 17848 —-a-w- c:\windows\system32\drivers\pctBTFix.sys
2011-11-11 11:18 . 2011-11-11 11:18 ——– d—–w- c:\documents and settings\Owner\Application Data\TestApp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 16:33 . 2011-06-08 10:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-11 11:34 . 2010-09-04 14:06 341656 —-a-w- c:\windows\system32\drivers\pctDS.sys
2011-10-28 16:03 . 2010-09-04 14:06 70536 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2011-10-28 16:02 . 2011-06-16 11:35 185560 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2011-10-28 15:40 . 2010-09-04 14:06 252840 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-10-22 20:11 . 2010-09-04 14:06 331880 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2011-10-22 20:11 . 2010-09-04 14:06 162584 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-10-10 14:22 . 2010-09-03 17:36 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 22:52 . 2010-09-04 14:06 660992 —-a-w- c:\windows\system32\drivers\pctEFA.sys
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2004-08-04 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-11-28 22:47 . 2011-05-06 11:04 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 77824]
"nwiz"="nwiz.exe" [2005-07-21 1519616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-21 7110656]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-21 86016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-04-13 10:07 69632 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineInvoker.exe"=
"c:\\Program Files\\AvRack\\rtlrack.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineLauncher.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1032:TCP"= 1032:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"58051:TCP"= 58051:TCP:*:Disabled:Pando Media Booster
"58051:UDP"= 58051:UDP:*:Disabled:Pando Media Booster
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/4/2010 9:06 AM 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [9/4/2010 9:06 AM 341656]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [9/4/2010 9:06 AM 660992]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [11/11/2011 6:38 AM 54328]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [11/11/2011 6:38 AM 574424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [9/4/2010 9:06 AM 252840]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [6/16/2011 6:35 AM 185560]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [11/11/2011 6:20 AM 542672]
R2 Htsysm;Htsysm;c:\windows\system32\HtsysmNT.sys [1/7/2011 7:36 PM 2304]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [11/11/2011 6:20 AM 56840]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [9/4/2010 9:06 AM 70536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/16/2011 6:35 AM 402336]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [11/11/2011 6:38 AM 35264]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service –> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.lotro.com;*.turbine.com;12.130.63.*;206.17.109.*
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\
FF - prefs.js: network.proxy.type - 4
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Spyware Doctor with AntiVirus - c:\documents and settings\Owner\Desktop\sdasetup.exe
SafeBoot-51712675.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 18:11
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
.
c:\windows\1626822744:2812741791.exe 812 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-436374069-789336058-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(756)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
- - - - - - - > 'explorer.exe'(2492)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\nvsvc32.exe
c:\windows\SOUNDMAN.EXE
.
**************************************************************************
.
Completion time: 2011-12-04 18:16:28 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-04 23:16
.
Pre-Run: 90,890,301,440 bytes free
Post-Run: 91,042,467,840 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - A500FD417DFE2B30CB4787C7BC9D4C06


Please let me know what you see. I have not taken the time to see if the computer is working any better or if ping.exe is still in the task manager.

Attachments:

Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Folder::
c:\windows\$NtUninstallKB44856$

ADS::
c:\windows\1626822744

ClearJavaCache::

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Ok, here they are. ComboFix log is first. Malwarebytes is second. Eset is last.



ComboFix 11-12-05.04 - Owner 12/05/2011 18:14:58.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.770 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: PC Tools Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
ADS - 1626822744: deleted 812 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
((((((((((((((((((((((((( Files Created from 2011-11-05 to 2011-12-05 )))))))))))))))))))))))))))))))
.
.
2011-12-04 11:54 . 2011-12-04 11:54 ——– d—–w- C:\_OTL
2011-12-04 02:56 . 2011-12-04 03:19 41272 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-12-03 13:57 . 2011-12-03 13:57 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2011-12-03 11:20 . 2011-12-03 11:20 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2011-12-03 11:19 . 2011-12-03 11:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-03 11:19 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-03 11:19 . 2011-12-03 11:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-01 23:12 . 2011-12-01 23:12 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-11-30 18:05 . 2011-11-30 18:05 94896 —-a-w- c:\windows\system32\drivers\40107822.sys
2011-11-11 11:38 . 2011-10-28 02:49 574424 –s—w- c:\windows\system32\drivers\TfSysMon.sys
2011-11-11 11:38 . 2011-10-28 02:49 54328 –s—w- c:\windows\system32\drivers\TfFsMon.sys
2011-11-11 11:38 . 2011-10-28 02:49 35264 –s—w- c:\windows\system32\drivers\TfNetMon.sys
2011-11-11 11:20 . 2011-10-25 18:38 149456 —-a-w- c:\windows\SGDetectionTool.dll
2011-11-11 11:20 . 2011-10-25 18:38 2291664 —-a-w- c:\windows\PCTBDCore.dll
2011-11-11 11:20 . 2011-10-25 18:38 1681360 —-a-w- c:\windows\PCTBDRes.dll
2011-11-11 11:20 . 2011-10-25 18:38 767952 —-a-w- c:\windows\BDTSupport.dll
2011-11-11 11:20 . 2011-09-28 18:14 56840 —-a-w- c:\windows\system32\drivers\PCTBD.sys
2011-11-11 11:20 . 2011-10-28 16:01 17848 —-a-w- c:\windows\system32\drivers\pctBTFix.sys
2011-11-11 11:18 . 2011-11-11 11:18 ——– d—–w- c:\documents and settings\Owner\Application Data\TestApp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 16:33 . 2011-06-08 10:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-11 11:34 . 2010-09-04 14:06 341656 —-a-w- c:\windows\system32\drivers\pctDS.sys
2011-10-28 16:03 . 2010-09-04 14:06 70536 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2011-10-28 16:02 . 2011-06-16 11:35 185560 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2011-10-28 15:40 . 2010-09-04 14:06 252840 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-10-22 20:11 . 2010-09-04 14:06 331880 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2011-10-22 20:11 . 2010-09-04 14:06 162584 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-10-10 14:22 . 2010-09-03 17:36 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 22:52 . 2010-09-04 14:06 660992 —-a-w- c:\windows\system32\drivers\pctEFA.sys
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-11-28 22:47 . 2011-05-06 11:04 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 77824]
"nwiz"="nwiz.exe" [2005-07-21 1519616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-21 7110656]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-21 86016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-04-13 10:07 69632 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineInvoker.exe"=
"c:\\Program Files\\AvRack\\rtlrack.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineLauncher.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1032:TCP"= 1032:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"58051:TCP"= 58051:TCP:*:Disabled:Pando Media Booster
"58051:UDP"= 58051:UDP:*:Disabled:Pando Media Booster
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/4/2010 9:06 AM 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [9/4/2010 9:06 AM 341656]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [9/4/2010 9:06 AM 660992]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [11/11/2011 6:38 AM 54328]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [11/11/2011 6:38 AM 574424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [9/4/2010 9:06 AM 252840]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [6/16/2011 6:35 AM 185560]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [11/11/2011 6:20 AM 542672]
R2 Htsysm;Htsysm;c:\windows\system32\HtsysmNT.sys [1/7/2011 7:36 PM 2304]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [11/11/2011 6:20 AM 56840]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [9/4/2010 9:06 AM 70536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/16/2011 6:35 AM 402336]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [11/11/2011 6:38 AM 35264]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service –> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.lotro.com;*.turbine.com;12.130.63.*;206.17.109.*
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\
FF - prefs.js: network.proxy.type - 4
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-05 18:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-436374069-789336058-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(756)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
- - - - - - - > 'explorer.exe'(1540)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-05 18:25:28
ComboFix-quarantined-files.txt 2011-12-05 23:25
ComboFix2.txt 2011-12-04 23:16
.
Pre-Run: 90,998,153,216 bytes free
Post-Run: 90,990,166,016 bytes free
.
- - End Of File - - 482D466E51426E0855BDAC0F68C089C9




Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8319

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

12/5/2011 6:35:41 PM
mbam-log-2011-12-05 (18-35-41).txt

Scan type: Quick scan
Objects scanned: 168406
Time elapsed: 2 minute(s), 33 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019174.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019196.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019207.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019220.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019233.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019247.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\System Volume Information\_restore{06C14598-9057-4D62-B653-39C3A9B45EAF}\RP58\A0019257.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
C:\WINDOWS\system32\drivers\redbook.sys a variant of Win32/Rootkit.Kryptik.FJ trojan
Hi,

Please do the following,


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:

    :filefind
    *redbook*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Here it is…

SystemLook 30.07.11 by jpshortstuff
Log created at 21:08 on 05/12/2011 by Owner
Administrator - Elevation successful

========== filefind ==========

Searching for "*redbook*"
C:\WINDOWS\$NtServicePackUninstall$\redbook.sys —–c- 57472 bytes [02:59 09/09/2011] [02:59 04/08/2004] B31B4588E4086D8D84ADBF9845C2402B
C:\WINDOWS\ServicePackFiles\i386\redbook.sys ——- 57600 bytes [18:40 13/04/2008] [18:40 13/04/2008] F828DD7E1419B6653894A8F97A0094C5
C:\WINDOWS\system32\drivers\redbook.sys –a—- 57600 bytes [13:29 03/09/2010] [18:40 13/04/2008] A80A417168CFB6080B26D5B66B3163DD

-= EOF =-


By the way, I also got a tray icon with a balloon that said, "The file or Directory C:\$Mft is corrupt and unreadable. Please run Chkdsk Utility." That same warning has popped up a couple of times while running the various software I've downloaded. Don't know if that is relevant, just passing it along.
OK,

we may have to run chkdsk if that doesn't resolve itself


please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

FCopy::
C:\WINDOWS\ServicePackFiles\i386\redbook.sys | C:\WINDOWS\system32\drivers\redbook.sys

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix may request an update; please allow it.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please advise if there are any other outstanding issues besides the C:\$Mft corrupt?
Catbyte,

Below is the latest ComboFix log. With regard to your question "other outstanding issues besides the C:\$Mft corrupt" the only thing I could pass along is that Combo Fix seems to insist I have PCTools running. It warns me to shut it down every time I run Combo Fix. I DO have PCTools disabled and it is not monitoring my system. I can only guess it sees a PC Tools dll somewhere that is "standing by" ready to assist in turning PC Tools Back on. Other than that minor thing, everything seems to be going very well. Thanks again for all your help.

Zdac




ComboFix 11-12-05.04 - Owner 12/06/2011 5:40.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.751 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: PC Tools Spyware Doctor with AntiVirus *Enabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
————— FCopy —————
.
c:\windows\ServicePackFiles\i386\redbook.sys –> c:\windows\system32\drivers\redbook.sys
.
((((((((((((((((((((((((( Files Created from 2011-11-06 to 2011-12-06 )))))))))))))))))))))))))))))))
.
.
2011-12-05 23:42 . 2011-12-05 23:42 ——– d—–w- c:\program files\ESET
2011-12-04 11:54 . 2011-12-04 11:54 ——– d—–w- C:\_OTL
2011-12-03 13:57 . 2011-12-03 13:57 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2011-12-03 11:20 . 2011-12-03 11:20 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2011-12-03 11:19 . 2011-12-03 11:19 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-03 11:19 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-03 11:19 . 2011-12-03 11:20 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-01 23:12 . 2011-12-01 23:12 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2011-11-30 18:05 . 2011-11-30 18:05 94896 —-a-w- c:\windows\system32\drivers\40107822.sys
2011-11-11 11:38 . 2011-10-28 02:49 574424 –s—w- c:\windows\system32\drivers\TfSysMon.sys
2011-11-11 11:38 . 2011-10-28 02:49 54328 –s—w- c:\windows\system32\drivers\TfFsMon.sys
2011-11-11 11:38 . 2011-10-28 02:49 35264 –s—w- c:\windows\system32\drivers\TfNetMon.sys
2011-11-11 11:20 . 2011-10-25 18:38 149456 —-a-w- c:\windows\SGDetectionTool.dll
2011-11-11 11:20 . 2011-10-25 18:38 2291664 —-a-w- c:\windows\PCTBDCore.dll
2011-11-11 11:20 . 2011-10-25 18:38 1681360 —-a-w- c:\windows\PCTBDRes.dll
2011-11-11 11:20 . 2011-10-25 18:38 767952 —-a-w- c:\windows\BDTSupport.dll
2011-11-11 11:20 . 2011-09-28 18:14 56840 —-a-w- c:\windows\system32\drivers\PCTBD.sys
2011-11-11 11:20 . 2011-10-28 16:01 17848 —-a-w- c:\windows\system32\drivers\pctBTFix.sys
2011-11-11 11:18 . 2011-11-11 11:18 ——– d—–w- c:\documents and settings\Owner\Application Data\TestApp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-15 16:33 . 2011-06-08 10:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-11 11:34 . 2010-09-04 14:06 341656 —-a-w- c:\windows\system32\drivers\pctDS.sys
2011-10-28 16:03 . 2010-09-04 14:06 70536 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2011-10-28 16:02 . 2011-06-16 11:35 185560 —-a-w- c:\windows\system32\drivers\PCTSD.sys
2011-10-28 15:40 . 2010-09-04 14:06 252840 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2011-10-22 20:11 . 2010-09-04 14:06 331880 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2011-10-22 20:11 . 2010-09-04 14:06 162584 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2011-10-10 14:22 . 2010-09-03 17:36 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 22:52 . 2010-09-04 14:06 660992 —-a-w- c:\windows\system32\drivers\pctEFA.sys
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-11-28 22:47 . 2011-05-06 11:04 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2011-12-04_23.11.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-03 13:29 . 2008-04-13 18:40 57600 c:\windows\system32\dllcache\redbook.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"SoundMan"="SOUNDMAN.EXE" [2005-06-21 77824]
"nwiz"="nwiz.exe" [2005-07-21 1519616]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-21 7110656]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-07-21 86016]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
NETGEAR WG311v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG311v3\wlancfg5.exe [2006-1-26 1486848]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C:\0autocheck autochk *
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-04-13 10:07 69632 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\lotroclient.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineInvoker.exe"=
"c:\\Program Files\\AvRack\\rtlrack.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\WINDOWS\\system32\\msiexec.exe"=
"c:\\Program Files\\Turbine\\The Lord of the Rings Online\\TurbineLauncher.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1032:TCP"= 1032:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
"58051:TCP"= 58051:TCP:*:Disabled:Pando Media Booster
"58051:UDP"= 58051:UDP:*:Disabled:Pando Media Booster
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [9/4/2010 9:06 AM 331880]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [9/4/2010 9:06 AM 341656]
R0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [9/4/2010 9:06 AM 660992]
R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [11/11/2011 6:38 AM 54328]
R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [11/11/2011 6:38 AM 574424]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [9/4/2010 9:06 AM 252840]
R1 PCTSD;PC Tools Spyware Doctor Driver;c:\windows\system32\drivers\PCTSD.sys [6/16/2011 6:35 AM 185560]
R2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [11/11/2011 6:20 AM 542672]
R2 Htsysm;Htsysm;c:\windows\system32\HtsysmNT.sys [1/7/2011 7:36 PM 2304]
R3 PCTBD;PC Tools Browser Defender Driver;c:\windows\system32\drivers\PCTBD.sys [11/11/2011 6:20 AM 56840]
S3 pctplsg;pctplsg;c:\windows\system32\drivers\pctplsg.sys [9/4/2010 9:06 AM 70536]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [6/16/2011 6:35 AM 402336]
S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [11/11/2011 6:38 AM 35264]
S3 ThreatFire;ThreatFire;c:\program files\PC Tools Security\TFEngine\TFService.exe service –> c:\program files\PC Tools Security\TFEngine\TFService.exe service [?]
.
.
——- Supplementary Scan ——-
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.lotro.com;*.turbine.com;12.130.63.*;206.17.109.*
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\
FF - prefs.js: network.proxy.type - 4
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-06 05:48
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-436374069-789336058-839522115-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(760)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
- - - - - - - > 'explorer.exe'(464)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2011-12-06 05:51:29
ComboFix-quarantined-files.txt 2011-12-06 10:51
ComboFix2.txt 2011-12-05 23:25
ComboFix3.txt 2011-12-04 23:16
.
Pre-Run: 90,858,254,336 bytes free
Post-Run: 90,844,299,264 bytes free
.
- - End Of File - - FD514BF3F7733A1E56251A45362009BD
are you still getting this error C:\$Mft is corrupt and unreadable

if so, please run the following:

  • Click Start > Run… then type in CMD and click on OK.
  • At the Command Prompt C:\ > type the following: chkdsk c: /r and hit the Enter/Return key.
    Note: chkdsk c: /r presumes that the disk upon which you wish to run Error Checking is your C: Drive (most often)
  • When prompted with:

CHKDSK cannot run because the volume is in use by another process
Would you like to schedule this volume to be checked next time the system
restarts (Y/N)

  • Hit the Y key then at the Command Prompt C:\ >
  • Type in EXIT and and hit the Enter/Return key.
  • Now Reboot(Restart) your computer.
Note: Upon Reboot(Restart), CHKDSK will start and carry out the repairs required.


let me know if that resolves it
Actually, I just turned on the computer and check disk ran on its own. I may have confirmed I wanted chkdsk to run a day or two ago during a warning, but it never did until now. It's too early to say it is resolved because I didn't get the error all the time. I think this is the log file entry for the chkdsk event that happened on start-up. If it isn't… I tried, lol. So, ya think the nasty little culprit is gone?

Checking file system on C:
The type of the file system is NTFS.


One of your disks needs to be checked for consistency. You
may cancel the disk check, but it is strongly recommended
that you continue.
Windows will now check the disk.
Index entry LOG_5_~1.GIF of index $I30 in file 0x16def points to unused file 0xa0e4.
Deleting index entry LOG_5_~1.GIF in index $I30 of file 93679.
Index entry ADEAF3~1.HTM of index $I30 in file 0x16df1 points to unused file 0xa1d6.
Deleting index entry ADEAF3~1.HTM in index $I30 of file 93681.
Index entry DisplayIntersticial[2] of index $I30 in file 0x16df1 points to unused file 0xa1d5.
Deleting index entry DisplayIntersticial[2] in index $I30 of file 93681.
Index entry DISPLA~2 of index $I30 in file 0x16df1 points to unused file 0xa1d5.
Deleting index entry DISPLA~2 in index $I30 of file 93681.
Index entry dot[4].gif of index $I30 in file 0x16df1 points to unused file 0xa0ee.
Deleting index entry dot[4].gif in index $I30 of file 93681.
Index entry DOT_4_~1.GIF of index $I30 in file 0x16df1 points to unused file 0xa0ee.
Deleting index entry DOT_4_~1.GIF in index $I30 of file 93681.
Unable to locate the file name attribute of index entry header_box_bg[1].png
of index $I30 with parent 0x16df1 in file 0xa17f.
Deleting index entry header_box_bg[1].png in index $I30 of file 93681.
Index entry sugarsD[1].jpg of index $I30 in file 0x16df1 points to unused file 0xa1fe.
Deleting index entry sugarsD[1].jpg in index $I30 of file 93681.
Index entry SUGARS~1.JPG of index $I30 in file 0x16df1 points to unused file 0xa1fe.
Deleting index entry SUGARS~1.JPG in index $I30 of file 93681.
Cleaning up minor inconsistencies on the drive.
CHKDSK is recovering lost files.
Recovering orphaned file DISPLA~1 (40632) into directory file 93681.
Recovering orphaned file DisplayIntersticial[1] (40632) into directory file 93681.
Cleaning up 2642 unused index entries from index $SII of file 0x9.
Cleaning up 2642 unused index entries from index $SDH of file 0x9.
Cleaning up 2642 unused security descriptors.
CHKDSK is verifying Usn Journal…
Usn Journal verification completed.
CHKDSK discovered free space marked as allocated in the
master file table (MFT) bitmap.
Windows has made corrections to the file system.

117218240 KB total disk space.
28248728 KB in 40875 files.
14868 KB in 4940 indexes.
0 KB in bad sectors.
208400 KB in use by the system.
65536 KB occupied by the log file.
88746244 KB available on disk.

4096 bytes in each allocation unit.
29304560 total allocation units on disk.
22186561 allocation units available on disk.

Internal Info:
90 0e 02 00 02 b3 00 00 cc f3 00 00 00 00 00 00 …………….
ce 00 00 00 02 00 00 00 d1 10 00 00 00 00 00 00 …………….
cc fe c4 01 00 00 00 00 66 5d 1c 1b 00 00 00 00 ……..f]……
fc 8e 93 13 00 00 00 00 00 00 00 00 00 00 00 00 …………….
00 00 00 00 00 00 00 00 e2 bd a0 37 00 00 00 00 ………..7….
99 9e 36 00 00 00 00 00 00 39 07 00 ab 9f 00 00 ..6……9……
00 00 00 00 00 60 2a bc 06 00 00 00 4c 13 00 00 …..`*…..L…

Windows has finished checking your disk.
Please wait while your computer restarts.


For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI