This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently a process called ping.exe has show up in the task manager and is running at 50-100% cpu. When this happens everything starts to get really slow. When I try and end the process it just reappears a few minutes later.


Any help would be appreciated:

Logs:

OTL logfile created on: 12/2/2011 3:34:38 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Localadmin\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.50 Gb Total Physical Memory | 2.41 Gb Available Physical Memory | 68.82% Memory free
5.34 Gb Paging File | 4.02 Gb Available in Paging File | 75.35% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 298.04 Gb Total Space | 278.65 Gb Free Space | 93.49% Space Free | Partition Type: NTFS

Computer Name: M-BEARDSLEY-D83 | User Name: Localadmin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Localadmin\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
PRC - C:\Program Files\Emsisoft Anti-Malware\a2guard.exe (Emsi Software GmbH)
PRC - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\shstat.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\naPrdMgr.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)
PRC - C:\Program Files\McAfee\Common Framework\Mctray.exe (McAfee, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10007.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL ()
MOD - C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll ()
MOD - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
MOD - C:\Program Files\McAfee\Common Framework\naXML71.dll ()
MOD - C:\Program Files\McAfee\Common Framework\naisign.dll ()


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – File not found
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (a2AntiMalware) – C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Emsi Software GmbH)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (McShield) – C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe (McAfee, Inc.)
SRV - (McTaskManager) – C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe (McAfee, Inc.)
SRV - (IJPLMSVC) – C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (STacSV) – C:\WINDOWS\system32\stacsv.exe (SigmaTel, Inc.)
SRV - (McAfeeFramework) – C:\Program Files\McAfee\Common Framework\FrameworkService.exe (McAfee, Inc.)


========== Driver Services (SafeList) ==========

DRV - (NPF) WinPcap Packet Driver (NPF) – C:\WINDOWS\system32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (a2injectiondriver) – C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys (Emsi Software GmbH)
DRV - (a2acc) – C:\Program Files\Emsisoft Anti-Malware\a2accx86.sys (Emsi Software GmbH)
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (A2DDA) – C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys (Emsi Software GmbH)
DRV - (a2util) – C:\Program Files\Emsisoft Anti-Malware\a2util32.sys (Emsi Software GmbH)
DRV - (mferkdk) – C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys (McAfee, Inc.)
DRV - (mfehidk) – C:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) – C:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfeapfk) – C:\WINDOWS\system32\drivers\mfeapfk.sys (McAfee, Inc.)
DRV - (mfetdik) – C:\WINDOWS\system32\drivers\mfetdik.sys (McAfee, Inc.)
DRV - (mfebopk) – C:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (NETw4x32) Intel® – C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (guardian2) – C:\WINDOWS\system32\drivers\oz776.sys (O2Micro)
DRV - (STHDA) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (b57w2k) – C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (HSF_DPV) – C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.)
DRV - (HSFHWAZL) – C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.unh.edu/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/11 13:24:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/04 16:27:24 | 000,000,000 | —D | M]

[2011/11/02 15:43:53 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Localadmin\Application Data\Mozilla\Extensions
[2011/11/02 15:43:54 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Localadmin\Application Data\Mozilla\Firefox\Profiles\j3mctnv8.default\extensions
[2011/11/02 15:43:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/11 13:24:32 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/04 16:27:11 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 19:26:50 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/11 13:24:32 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll (McAfee, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [emsisoft anti-malware] c:\program files\emsisoft anti-malware\a2guard.exe (Emsi Software GmbH)
O4 - HKLM..\Run: [ISUSPM Startup] c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\UdaterUI.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [ShStatEXE] C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE (McAfee, Inc.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0C4D4585-8C45-462A-B6EE-C2228C23BBD3}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4ABB1887-333A-4B3D-AF31-28AECBEA3CB9}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/02 09:44:56 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/20 20:29:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\Malwarebytes
[2011/11/20 20:29:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/20 20:29:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/11/20 20:29:07 | 000,022,216 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/11/20 20:29:06 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/11/20 20:23:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\SUPERAntiSpyware.com
[2011/11/20 20:23:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2011/11/20 20:23:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\SUPERAntiSpyware
[2011/11/20 20:22:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2011/11/20 20:22:59 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2011/11/20 15:09:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Start Menu\Programs\Google Chrome
[2011/11/20 15:08:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Local Settings\Application Data\Google
[2011/11/20 15:08:18 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Local Settings\Application Data\Deployment
[2011/11/20 14:02:06 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/20 14:02:03 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/20 14:02:01 | 000,100,880 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\Packet.dll
[2011/11/20 00:02:05 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Emsisoft Anti-Malware
[2011/11/20 00:01:46 | 000,000,000 | —D | C] – C:\Program Files\Emsisoft Anti-Malware
[2011/11/20 00:01:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\My Documents\Anti-Malware
[2011/11/19 23:11:53 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/11/19 23:11:04 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2011/11/08 22:37:01 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2011/11/08 18:50:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Local Settings\Application Data\Scansoft
[2011/11/08 17:30:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\My Documents\Strategic Management
[2011/11/08 17:18:22 | 000,000,000 | —D | C] – C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2011/11/08 17:18:17 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2011/11/08 14:24:38 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJPLM
[2011/11/08 14:24:18 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP210 series User Registration
[2011/11/08 14:22:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\ScanSoft
[2011/11/08 14:22:22 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ScanSoft OmniPage SE 4
[2011/11/08 14:22:21 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ScanSoft Shared
[2011/11/08 14:22:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/11/08 14:21:52 | 000,000,000 | —D | C] – C:\Program Files\ScanSoft
[2011/11/08 14:19:22 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2011/11/08 14:16:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon Utilities
[2011/11/08 14:15:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP210 series Manual
[2011/11/08 14:15:21 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2011/11/08 14:15:21 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Canon MP210 series
[2011/11/08 14:15:09 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2011/11/08 14:14:35 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2011/11/08 14:12:37 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/11/08 14:12:33 | 000,215,040 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM8S.DLL
[2011/11/08 14:12:10 | 000,025,856 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbprint.sys
[2011/11/08 14:11:33 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2011/11/08 14:10:21 | 000,032,128 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbccgp.sys
[2011/11/04 16:27:38 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2011/11/04 16:27:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2011/11/04 16:27:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2011/11/04 16:27:24 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2011/11/04 16:27:23 | 000,472,808 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2011/11/04 16:27:23 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/11/04 16:27:23 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/11/04 16:27:23 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011/11/04 16:27:08 | 000,000,000 | —D | C] – C:\Program Files\Java
[2011/11/04 16:26:50 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\Sun
[2011/11/04 10:16:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\My Documents\Updater5
[2011/11/03 18:00:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Local Settings\Application Data\Apple Computer
[2011/11/03 18:00:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\Apple Computer
[2011/11/03 18:00:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\iTunes
[2011/11/03 18:00:12 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2011/11/03 17:58:37 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/11/03 17:58:35 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/11/03 17:58:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2011/11/03 17:58:35 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/11/03 17:58:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Local Settings\Application Data\Apple
[2011/11/03 17:58:16 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2011/11/03 17:58:12 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Apple Computer
[2011/11/03 17:58:07 | 004,517,664 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2011/11/03 17:57:38 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/11/03 17:57:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/11/03 17:57:15 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2011/11/03 17:53:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\My Documents\Downloads
[2011/11/03 16:23:01 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\Windows Search
[2011/11/03 13:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Application Data\Macromedia
[2011/11/03 13:36:46 | 000,414,368 | —- | C] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/03 13:34:39 | 000,012,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\mouhid.sys
[2011/11/03 13:34:33 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2011/11/03 10:44:19 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2011/11/03 10:43:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2011/11/03 10:43:26 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio
[2011/11/03 10:43:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2011/11/03 10:40:01 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 8
[2011/11/03 10:39:28 | 000,000,000 | —D | C] – C:\WINDOWS\SHELLNEW
[2011/11/03 10:39:10 | 000,000,000 | —D | C] – C:\Documents and Settings\Localadmin\Local Settings\Application Data\Microsoft Help
[2011/11/03 10:39:05 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/11/03 10:39:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2011/11/03 10:38:29 | 000,000,000 | RH-D | C] – C:\MSOCache
[2011/11/03 08:45:45 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2011/11/03 08:35:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Silverlight
[2011/11/03 08:35:03 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2011/11/03 08:23:49 | 000,000,000 | —D | C] – C:\WINDOWS\System32\WindowsPowerShell
[2011/11/03 08:23:48 | 000,000,000 | —D | C] – C:\WINDOWS\System32\winrm
[2011/11/03 08:23:43 | 000,000,000 | -H-D | C] – C:\WINDOWS\$968930Uinstall_KB968930$
[2011/11/03 08:14:24 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2011/11/03 08:14:03 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\msfeedsbs.dll
[2011/11/03 08:14:02 | 006,076,416 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll
[2011/11/03 08:14:02 | 002,452,872 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieapfltr.dat
[2011/11/03 08:14:02 | 000,991,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ieframe.dll.mui
[2011/11/03 08:14:02 | 000,468,480 | —- | C] (Microsoft Corporation) – C:\WINDOLS\x00\x00\x00\x00
:welcome:

Please reply to this post only by using the ADD REPLY and do not start any new topics.

You did not post the entire OTL log, but lets bypass that for now, lets do this


Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]






Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-04 14:14:32 —————————– 14:14:32.515 OS Version: Windows 5.1.2600 Service Pack 3 14:14:32.515 Number of processors: 2 586 0xF0D 14:14:32.531 ComputerName: M-BEARDSLEY-D83 UserName: Localadmin 14:14:41.328 Initialize success 14:15:02.968 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 14:15:02.968 Disk 0 Vendor: WDC_WD3200BEKT-00PVMT0 01.01A01 Size: 305245MB BusType: 3 14:15:04.984 Disk 0 MBR read successfully 14:15:04.984 Disk 0 MBR scan 14:15:04.984 Disk 0 Windows VISTA default MBR code 14:15:04.984 Disk 0 scanning sectors +625137345 14:15:05.062 Disk 0 scanning C:\WINDOWS\system32\drivers 14:15:22.968 File: C:\WINDOWS\system32\drivers\ipsec.sys **SUSPICIOUS** 14:15:27.062 Service scanning 14:15:27.984 Modules scanning 14:15:36.484 Module: C:\WINDOWS\system32\DRIVERS\ipsec.sys **SUSPICIOUS** 14:15:38.546 Disk 0 trace - called modules: 14:15:38.562 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x88f24f10]<< 14:15:38.562 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a867ab8] 14:15:38.562 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> [0x8a4bf030] 14:15:38.562 \Driver\00000720[0x8a614550] -> IRP_MJ_CREATE -> 0x88f24f10 14:15:38.562 Scan finished successfully 14:16:27.640 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Localadmin\Desktop\MBR.dat" 14:16:27.671 The log file has been saved successfully to "C:\Documents and Settings\Localadmin\Desktop\aswMBR.txt" . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_29 Run by [removed] at 14:17:10 on 2011-12-04 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2670 [GMT -5:00] . AV: VirusScan Enterprise + AntiSpyware Enterprise *Enabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0} AV: Emsisoft Anti-Malware *Enabled/Updated* {0F8591BB-342B-4493-91C3-4E948ED21255} . ============== Running Processes =============== . C:\Program Files\Emsisoft Anti-Malware\a2service.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\McAfee\Common Framework\FrameworkService.exe C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\StacSV.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\McAfee\Common Framework\UdaterUI.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\McAfee\Common Framework\McTray.exe C:\Program Files\Canon\MyPrinter\BJMyPrt.exe C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe C:\program files\emsisoft anti-malware\a2guard.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Localadmin\Desktop\aswMBR.exe C:\WINDOWS\system32\SearchProtocolHost.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.unh.edu/ uInternet Connection Wizard,ShellNext = hxxp://www.unh.edu/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan enterprise\scriptcl.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\localadmin\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [McAfeeUpdaterUI] "c:\program files\mcafee\common framework\UdaterUI.exe" /StartedFromRunKey mRun: [ShStatEXE] "c:\program files\mcafee\virusscan enterprise\SHSTAT.EXE" /STANDALONE mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe" mRun: [emsisoft anti-malware] "c:\program files\emsisoft anti-malware\a2guard.exe" /d=60 mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL LSP: mswsock.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{0C4D4585-8C45-462A-B6EE-C2228C23BBD3} : DhcpNameServer = [removed] [removed] TCP: Interfaces\{4ABB1887-333A-4B3D-AF31-28AECBEA3CB9} : DhcpNameServer = [removed] [removed] Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\localadmin\application data\mozilla\firefox\profiles\j3mctnv8.default\ FF - plugin: c:\documents and settings\localadmin\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll . ============= SERVICES / DRIVERS =============== . R1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files\emsisoft anti-malware\a2ddax86.sys [2011-11-20 17904] R1 a2injectiondriver;a2injectiondriver;c:\program files\emsisoft anti-malware\a2dix86.sys [2011-11-20 34768] R1 a2util;a-squared Malware-IDS utility driver;c:\program files\emsisoft anti-malware\a2util32.sys [2011-11-20 11776] R1 mferkdk;VSCore mferkdk;c:\program files\mcafee\virusscan enterprise\mferkdk.sys [2008-1-24 31816] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCORE.EXE [2011-7-18 116608] R2 a2AntiMalware;Emsisoft Anti-Malware 6.0 - Service;c:\program files\emsisoft anti-malware\a2service.exe [2011-11-20 2996784] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-11-20 366152] R2 McAfeeFramework;McAfee Framework Service;c:\program files\mcafee\common framework\FrameworkService.exe [2008-12-11 104000] R2 McShield;McAfee McShield;c:\program files\mcafee\virusscan enterprise\mcshield.exe [2008-1-24 144704] R2 McTaskManager;McAfee Task Manager;c:\program files\mcafee\virusscan enterprise\vstskmgr.exe [2008-1-24 54608] R3 a2acc;a2acc;c:\program files\emsisoft anti-malware\a2accx86.sys [2011-11-20 51632] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-11-20 22216] R3 mfeavfk;McAfee Inc.;c:\windows\system32\drivers\mfeavfk.sys [2008-12-11 72936] R3 mfebopk;McAfee Inc.;c:\windows\system32\drivers\mfebopk.sys [2008-12-11 33960] R3 mfehidk;McAfee Inc.;c:\windows\system32\drivers\mfehidk.sys [2008-12-11 171400] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\npf.sys [2011-11-20 50704] S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2004-8-4 14336] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-12-02 22:09:47 ——– d—–w- C:\Quarantine 2011-11-21 01:29:19 ——– d—–w- c:\documents and settings\localadmin\application data\Malwarebytes 2011-11-21 01:29:11 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-11-21 01:29:07 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-21 01:29:06 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-11-21 01:23:46 ——– d—–w- c:\documents and settings\localadmin\application data\SUPERAntiSpyware.com 2011-11-21 01:23:05 ——– d—–w- c:\documents and settings\all users\application data\!SASCORE 2011-11-21 01:22:59 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-11-21 01:22:59 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com 2011-11-20 20:08:39 ——– d—–w- c:\documents and settings\localadmin\local settings\application data\Google 2011-11-20 20:08:18 ——– d—–w- c:\documents and settings\localadmin\local settings\application data\Deployment 2011-11-20 19:02:06 50704 —-a-w- c:\windows\system32\drivers\npf.sys 2011-11-20 19:02:03 281104 —-a-w- c:\windows\system32\wpcap.dll 2011-11-20 19:02:01 100880 —-a-w- c:\windows\system32\Packet.dll 2011-11-20 05:01:46 ——– d—–w- c:\program files\Emsisoft Anti-Malware 2011-11-08 23:50:32 ——– d—–w- c:\documents and settings\localadmin\local settings\application data\Scansoft 2011-11-08 22:18:22 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2 2011-11-08 22:18:17 ——– d—–w- c:\program files\MSXML 4.0 2011-11-08 19:24:38 ——– d—–w- c:\documents and settings\all users\application data\CanonIJPLM 2011-11-08 19:22:21 ——– d—–w- c:\program files\common files\ScanSoft Shared 2011-11-08 19:21:52 ——– d—–w- c:\program files\ScanSoft 2011-11-08 19:19:22 ——– d—–w- c:\program files\common files\CANON 2011-11-08 19:14:35 ——– d—–w- c:\program files\Canon 2011-11-08 19:12:34 69632 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPP8S.DLL 2011-11-08 19:12:34 27136 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\CNMPD8S.DLL 2011-11-08 19:12:33 215040 —-a-w- c:\windows\system32\CNMLM8S.DLL 2011-11-08 19:12:10 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys 2011-11-08 19:12:10 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys 2011-11-08 19:11:33 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys 2011-11-08 19:11:33 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys 2011-11-08 19:10:21 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys 2011-11-08 19:10:21 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys 2011-11-04 21:27:24 73728 —-a-w- c:\windows\system32\javacpl.cpl 2011-11-04 21:27:24 476904 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2011-11-04 21:27:23 472808 —-a-w- c:\windows\system32\deployJava1.dll . ==================== Find3M ==================== . 2011-11-18 19:39:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys . ============= FINISH: 14:19:10.57 ===============

Attachments:

Hi,

Glad where on the same page, you do have some nasty stuff going on.

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
15:02:29.0046 0440 TDSS rootkit removing tool 2.6.21.0 Nov 24 2011 12:32:44 15:02:29.0390 0440 ============================================================ 15:02:29.0390 0440 Current date / time: 2011/12/04 15:02:29.0390 15:02:29.0390 0440 SystemInfo: 15:02:29.0390 0440 15:02:29.0390 0440 OS Version: 5.1.2600 ServicePack: 3.0 15:02:29.0390 0440 Product type: Workstation 15:02:29.0390 0440 ComputerName: M-BEARDSLEY-D83 15:02:29.0390 0440 UserName: Localadmin 15:02:29.0390 0440 Windows directory: C:\WINDOWS 15:02:29.0390 0440 System windows directory: C:\WINDOWS 15:02:29.0390 0440 Processor architecture: Intel x86 15:02:29.0390 0440 Number of processors: 2 15:02:29.0390 0440 Page size: 0x1000 15:02:29.0390 0440 Boot type: Normal boot 15:02:29.0390 0440 ============================================================ 15:02:30.0968 0440 Initialize success 15:02:33.0750 3264 ============================================================ 15:02:33.0750 3264 Scan started 15:02:33.0750 3264 Mode: Manual; 15:02:33.0750 3264 ============================================================ 15:02:34.0750 3264 a2acc (05dac43a484272de87eac038814a7840) C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys 15:02:34.0843 3264 a2acc - ok 15:02:34.0859 3264 A2DDA (f7eabca8375ea2dc6f35c4bca4757515) C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys 15:02:34.0859 3264 A2DDA - ok 15:02:34.0859 3264 a2injectiondriver (23aac49133765eeaa86a65452d21ef1c) C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys 15:02:34.0859 3264 a2injectiondriver - ok 15:02:34.0875 3264 a2util (2da26eb05b5495d3b2ee36456c239fb7) C:\Program Files\Emsisoft Anti-Malware\a2util32.sys 15:02:34.0875 3264 a2util - ok 15:02:34.0937 3264 Abiosdsk - ok 15:02:34.0953 3264 abp480n5 - ok 15:02:34.0984 3264 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:02:34.0984 3264 ACPI - ok 15:02:35.0015 3264 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 15:02:35.0015 3264 ACPIEC - ok 15:02:35.0015 3264 adpu160m - ok 15:02:35.0046 3264 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 15:02:35.0046 3264 aec - ok 15:02:35.0078 3264 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 15:02:35.0093 3264 AFD - ok 15:02:35.0093 3264 Aha154x - ok 15:02:35.0109 3264 aic78u2 - ok 15:02:35.0109 3264 aic78xx - ok 15:02:35.0125 3264 AliIde - ok 15:02:35.0140 3264 amsint - ok 15:02:35.0156 3264 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 15:02:35.0156 3264 Arp1394 - ok 15:02:35.0156 3264 asc - ok 15:02:35.0171 3264 asc3350p - ok 15:02:35.0171 3264 asc3550 - ok 15:02:35.0218 3264 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:02:35.0218 3264 AsyncMac - ok 15:02:35.0218 3264 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 15:02:35.0234 3264 atapi - ok 15:02:35.0234 3264 Atdisk - ok 15:02:35.0250 3264 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:02:35.0265 3264 Atmarpc - ok 15:02:35.0281 3264 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 15:02:35.0296 3264 audstub - ok 15:02:35.0312 3264 b57w2k (133ad3794572bce689763a8356c7ed06) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 15:02:35.0328 3264 b57w2k - ok 15:02:35.0359 3264 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 15:02:35.0359 3264 Beep - ok 15:02:35.0390 3264 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 15:02:35.0390 3264 cbidf2k - ok 15:02:35.0406 3264 cd20xrnt - ok 15:02:35.0421 3264 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 15:02:35.0421 3264 Cdaudio - ok 15:02:35.0437 3264 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 15:02:35.0453 3264 Cdfs - ok 15:02:35.0453 3264 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 15:02:35.0453 3264 Cdrom - ok 15:02:35.0484 3264 cercsr6 (84853b3fd012251690570e9e7e43343f) C:\WINDOWS\system32\drivers\cercsr6.sys 15:02:35.0578 3264 cercsr6 - ok 15:02:35.0578 3264 Changer - ok 15:02:35.0609 3264 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 15:02:35.0609 3264 CmBatt - ok 15:02:35.0609 3264 CmdIde - ok 15:02:35.0625 3264 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 15:02:35.0625 3264 Compbatt - ok 15:02:35.0640 3264 Cpqarray - ok 15:02:35.0656 3264 dac2w2k - ok 15:02:35.0656 3264 dac960nt - ok 15:02:35.0671 3264 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 15:02:35.0671 3264 Disk - ok 15:02:35.0718 3264 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 15:02:35.0718 3264 dmboot - ok 15:02:35.0734 3264 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 15:02:35.0734 3264 dmio - ok 15:02:35.0765 3264 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 15:02:35.0765 3264 dmload - ok 15:02:35.0843 3264 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 15:02:35.0843 3264 DMusic - ok 15:02:36.0031 3264 dpti2o - ok 15:02:36.0046 3264 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 15:02:36.0046 3264 drmkaud - ok 15:02:36.0265 3264 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 15:02:36.0265 3264 Fastfat - ok 15:02:36.0343 3264 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 15:02:36.0343 3264 Fdc - ok 15:02:36.0359 3264 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 15:02:36.0375 3264 Fips - ok 15:02:36.0390 3264 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 15:02:36.0390 3264 Flpydisk - ok 15:02:36.0406 3264 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 15:02:36.0421 3264 FltMgr - ok 15:02:36.0437 3264 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:02:36.0453 3264 Fs_Rec - ok 15:02:36.0453 3264 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:02:36.0468 3264 Ftdisk - ok 15:02:36.0500 3264 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 15:02:36.0500 3264 GEARAspiWDM - ok 15:02:36.0515 3264 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:02:36.0515 3264 Gpc - ok 15:02:36.0546 3264 guardian2 (0e1fd1ea2837d6b7a1d7b6c928014d05) C:\WINDOWS\system32\Drivers\oz776.sys 15:02:36.0546 3264 guardian2 - ok 15:02:36.0578 3264 HDAudBus (e31363d186b3e1d7c4e9117884a6aee5) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:02:36.0578 3264 HDAudBus - ok 15:02:36.0625 3264 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:02:36.0625 3264 HidUsb - ok 15:02:36.0656 3264 hpn - ok 15:02:36.0687 3264 HSFHWAZL (b1526810210980bed9d22315946c919d) C:\WINDOWS\system32\DRIVERS\HSFHWAZL.sys 15:02:36.0687 3264 HSFHWAZL - ok 15:02:36.0718 3264 HSF_DPV (ddbd528e60f5961c142a490dc4ea7780) C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys 15:02:36.0734 3264 HSF_DPV - ok 15:02:36.0765 3264 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 15:02:36.0765 3264 HTTP - ok 15:02:36.0781 3264 i2omgmt - ok 15:02:36.0781 3264 i2omp - ok 15:02:36.0812 3264 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 15:02:36.0812 3264 i8042prt - ok 15:02:36.0828 3264 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 15:02:36.0828 3264 Imapi - ok 15:02:36.0843 3264 ini910u - ok 15:02:36.0859 3264 IntelIde - ok 15:02:36.0875 3264 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 15:02:36.0875 3264 intelppm - ok 15:02:36.0906 3264 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 15:02:36.0906 3264 Ip6Fw - ok 15:02:36.0953 3264 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:02:36.0953 3264 IpFilterDriver - ok 15:02:36.0968 3264 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:02:36.0968 3264 IpInIp - ok 15:02:36.0984 3264 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:02:37.0000 3264 IpNat - ok 15:02:37.0015 3264 IPSec (be02384fb861de8d22a8956683e5288a) C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:02:37.0015 3264 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\ipsec.sys. Real md5: be02384fb861de8d22a8956683e5288a, Fake md5: 23c74d75e36e7158768dd63d92789a91 15:02:37.0015 3264 IPSec ( Rootkit.Win32.ZAccess.k ) - infected 15:02:37.0015 3264 IPSec - detected Rootkit.Win32.ZAccess.k (0) 15:02:37.0015 3264 IPSECSHM - ok 15:02:37.0046 3264 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 15:02:37.0046 3264 IRENUM - ok 15:02:37.0062 3264 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:02:37.0062 3264 isapnp - ok 15:02:37.0078 3264 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:02:37.0078 3264 Kbdclass - ok 15:02:37.0093 3264 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 15:02:37.0093 3264 kmixer - ok 15:02:37.0125 3264 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 15:02:37.0125 3264 KSecDD - ok 15:02:37.0125 3264 lbrtfdc - ok 15:02:37.0156 3264 MBAMProtector (69a6268d7f81e53d568ab4e7e991caf3) C:\WINDOWS\system32\drivers\mbam.sys 15:02:37.0156 3264 MBAMProtector - ok 15:02:37.0203 3264 mdmxsdk (0cea2d0d3fa284b85ed5b68365114f76) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 15:02:37.0203 3264 mdmxsdk - ok 15:02:37.0234 3264 mfeapfk (4f557e7140124f7dd347e6e6ba11a696) C:\WINDOWS\system32\drivers\mfeapfk.sys 15:02:37.0234 3264 mfeapfk - ok 15:02:37.0250 3264 mfeavfk (5a88fc236667c8c245f19c62a5e18e70) C:\WINDOWS\system32\drivers\mfeavfk.sys 15:02:37.0250 3264 mfeavfk - ok 15:02:37.0250 3264 mfebopk (e0bf92925c2a68662d32439bef5e9c1f) C:\WINDOWS\system32\drivers\mfebopk.sys 15:02:37.0265 3264 mfebopk - ok 15:02:37.0296 3264 mfehidk (9ac9ea61e33af81b60a65cdb71474ea6) C:\WINDOWS\system32\drivers\mfehidk.sys 15:02:37.0296 3264 mfehidk - ok 15:02:37.0359 3264 mferkdk (fda7f14ad5dda9fca8ee2bae222cd5fb) C:\Program Files\McAfee\VirusScan Enterprise\mferkdk.sys 15:02:37.0359 3264 mferkdk - ok 15:02:37.0375 3264 mfetdik (0371251b81b9898a79a80970be7fadab) C:\WINDOWS\system32\drivers\mfetdik.sys 15:02:37.0375 3264 mfetdik - ok 15:02:37.0421 3264 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 15:02:37.0421 3264 mnmdd - ok 15:02:37.0453 3264 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 15:02:37.0453 3264 Modem - ok 15:02:37.0484 3264 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:02:37.0484 3264 Mouclass - ok 15:02:37.0515 3264 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:02:37.0515 3264 mouhid - ok 15:02:37.0531 3264 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 15:02:37.0531 3264 MountMgr - ok 15:02:37.0546 3264 mraid35x - ok 15:02:37.0562 3264 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:02:37.0562 3264 MRxDAV - ok 15:02:37.0593 3264 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:02:37.0593 3264 MRxSmb - ok 15:02:37.0609 3264 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 15:02:37.0609 3264 Msfs - ok 15:02:37.0625 3264 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:02:37.0625 3264 MSKSSRV - ok 15:02:37.0656 3264 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:02:37.0656 3264 MSPCLOCK - ok 15:02:37.0687 3264 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 15:02:37.0687 3264 MSPQM - ok 15:02:37.0703 3264 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:02:37.0703 3264 mssmbios - ok 15:02:37.0734 3264 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 15:02:37.0734 3264 Mup - ok 15:02:37.0750 3264 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 15:02:37.0750 3264 NDIS - ok 15:02:37.0781 3264 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:02:37.0781 3264 NdisTapi - ok 15:02:37.0812 3264 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:02:37.0812 3264 Ndisuio - ok 15:02:37.0812 3264 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:02:37.0812 3264 NdisWan - ok 15:02:37.0828 3264 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 15:02:37.0828 3264 NDProxy - ok 15:02:37.0843 3264 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 15:02:37.0843 3264 NetBIOS - ok 15:02:37.0875 3264 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 15:02:37.0875 3264 NetBT - ok 15:02:37.0984 3264 NETw4x32 (18b2d3e11ed7a3c898ade6a6692b6929) C:\WINDOWS\system32\DRIVERS\NETw4x32.sys 15:02:38.0015 3264 NETw4x32 - ok 15:02:38.0031 3264 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 15:02:38.0031 3264 NIC1394 - ok 15:02:38.0078 3264 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 15:02:38.0078 3264 NPF - ok 15:02:38.0093 3264 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 15:02:38.0093 3264 Npfs - ok 15:02:38.0140 3264 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 15:02:38.0140 3264 Ntfs - ok 15:02:38.0203 3264 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 15:02:38.0203 3264 Null - ok 15:02:38.0453 3264 nv (8129d762cc3e3c5ab9cf2eabc377fb73) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 15:02:38.0609 3264 nv - ok 15:02:38.0671 3264 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:02:38.0671 3264 NwlnkFlt - ok 15:02:38.0687 3264 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:02:38.0687 3264 NwlnkFwd - ok 15:02:38.0734 3264 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 15:02:38.0734 3264 ohci1394 - ok 15:02:38.0765 3264 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 15:02:38.0765 3264 Parport - ok 15:02:38.0781 3264 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 15:02:38.0781 3264 PartMgr - ok 15:02:38.0812 3264 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 15:02:38.0828 3264 ParVdm - ok 15:02:38.0828 3264 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 15:02:38.0843 3264 PCI - ok 15:02:38.0843 3264 PCIDump - ok 15:02:38.0859 3264 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 15:02:38.0875 3264 PCIIde - ok 15:02:38.0890 3264 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 15:02:38.0890 3264 Pcmcia - ok 15:02:38.0906 3264 PDCOMP - ok 15:02:38.0921 3264 PDFRAME - ok 15:02:38.0937 3264 PDRELI - ok 15:02:38.0937 3264 PDRFRAME - ok 15:02:38.0953 3264 perc2 - ok 15:02:38.0968 3264 perc2hib - ok 15:02:39.0015 3264 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:02:39.0015 3264 PptpMiniport - ok 15:02:39.0031 3264 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 15:02:39.0031 3264 PSched - ok 15:02:39.0062 3264 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:02:39.0062 3264 Ptilink - ok 15:02:39.0093 3264 PxHelp20 (7c81ae3c9b82ba2da437ed4d31bc56cf) C:\WINDOWS\system32\Drivers\PxHelp20.sys 15:02:39.0093 3264 PxHelp20 - ok 15:02:39.0093 3264 ql1080 - ok 15:02:39.0109 3264 Ql10wnt - ok 15:02:39.0109 3264 ql12160 - ok 15:02:39.0125 3264 ql1240 - ok 15:02:39.0140 3264 ql1280 - ok 15:02:39.0156 3264 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:02:39.0156 3264 RasAcd - ok 15:02:39.0171 3264 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:02:39.0171 3264 Rasl2tp - ok 15:02:39.0187 3264 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:02:39.0187 3264 RasPppoe - ok 15:02:39.0187 3264 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 15:02:39.0203 3264 Raspti - ok 15:02:39.0218 3264 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:02:39.0218 3264 Rdbss - ok 15:02:39.0234 3264 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:02:39.0234 3264 RDPCDD - ok 15:02:39.0265 3264 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 15:02:39.0265 3264 rdpdr - ok 15:02:39.0296 3264 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 15:02:39.0296 3264 RDPWD - ok 15:02:39.0328 3264 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 15:02:39.0328 3264 redbook - ok 15:02:39.0406 3264 SASDIFSV (39763504067962108505bff25f024345) C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 15:02:39.0406 3264 SASDIFSV - ok 15:02:39.0421 3264 SASKUTIL (77b9fc20084b48408ad3e87570eb4a85) C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 15:02:39.0421 3264 SASKUTIL - ok 15:02:39.0468 3264 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:02:39.0468 3264 Secdrv - ok 15:02:39.0500 3264 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 15:02:39.0500 3264 serenum - ok 15:02:39.0531 3264 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 15:02:39.0531 3264 Serial - ok 15:02:39.0562 3264 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 15:02:39.0562 3264 Sfloppy - ok 15:02:39.0562 3264 Simbad - ok 15:02:39.0578 3264 Sparrow - ok 15:02:39.0609 3264 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 15:02:39.0609 3264 splitter - ok 15:02:39.0640 3264 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 15:02:39.0640 3264 sr - ok 15:02:39.0656 3264 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 15:02:39.0671 3264 Srv - ok 15:02:39.0718 3264 STHDA (31ba85e1cff39a57f702a2a0877bb8e1) C:\WINDOWS\system32\drivers\sthda.sys 15:02:39.0750 3264 STHDA - ok 15:02:39.0781 3264 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 15:02:39.0781 3264 swenum - ok 15:02:39.0796 3264 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 15:02:39.0796 3264 swmidi - ok 15:02:39.0812 3264 symc810 - ok 15:02:39.0828 3264 symc8xx - ok 15:02:39.0843 3264 sym_hi - ok 15:02:39.0859 3264 sym_u3 - ok 15:02:39.0890 3264 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 15:02:39.0890 3264 sysaudio - ok 15:02:39.0937 3264 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:02:39.0937 3264 Tcpip - ok 15:02:39.0968 3264 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 15:02:39.0968 3264 TDPIPE - ok 15:02:40.0000 3264 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 15:02:40.0000 3264 TDTCP - ok 15:02:40.0031 3264 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 15:02:40.0031 3264 TermDD - ok 15:02:40.0062 3264 TosIde - ok 15:02:40.0093 3264 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 15:02:40.0109 3264 Udfs - ok 15:02:40.0125 3264 ultra - ok 15:02:40.0171 3264 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 15:02:40.0187 3264 Update - ok 15:02:40.0234 3264 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 15:02:40.0453 3264 USBAAPL - ok 15:02:40.0484 3264 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:02:40.0484 3264 usbccgp - ok 15:02:40.0515 3264 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:02:40.0515 3264 usbehci - ok 15:02:40.0531 3264 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:02:40.0531 3264 usbhub - ok 15:02:40.0562 3264 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 15:02:40.0562 3264 usbprint - ok 15:02:40.0578 3264 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 15:02:40.0578 3264 usbscan - ok 15:02:40.0609 3264 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:02:40.0609 3264 USBSTOR - ok 15:02:40.0640 3264 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 15:02:40.0640 3264 usbuhci - ok 15:02:40.0656 3264 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 15:02:40.0656 3264 VgaSave - ok 15:02:40.0656 3264 ViaIde - ok 15:02:40.0671 3264 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 15:02:40.0687 3264 VolSnap - ok 15:02:40.0703 3264 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:02:40.0703 3264 Wanarp - ok 15:02:40.0703 3264 WDICA - ok 15:02:40.0734 3264 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 15:02:40.0734 3264 wdmaud - ok 15:02:40.0781 3264 winachsf (96aff1738271755a39b52eef7e35f98f) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 15:02:40.0781 3264 winachsf - ok 15:02:40.0812 3264 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 15:02:40.0812 3264 WmiAcpi - ok 15:02:40.0859 3264 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 15:02:40.0859 3264 WudfPf - ok 15:02:40.0875 3264 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 15:02:40.0875 3264 WudfRd - ok 15:02:40.0906 3264 MBR (0x1B8) (5c616939100b85e558da92b899a0fc36) \Device\Harddisk0\DR0 15:02:40.0921 3264 \Device\Harddisk0\DR0 - ok 15:02:40.0921 3264 Boot (0x1200) (4cf67bbc1d763c5738721e608e0e0ec9) \Device\Harddisk0\DR0\Partition0 15:02:40.0921 3264 \Device\Harddisk0\DR0\Partition0 - ok 15:02:40.0921 3264 ============================================================ 15:02:40.0921 3264 Scan finished 15:02:40.0921 3264 ============================================================ 15:02:40.0937 3084 Detected object count: 1 15:02:40.0937 3084 Actual detected object count: 1 15:04:37.0500 3084 Backup copy found, using it.. 15:04:37.0656 3084 C:\WINDOWS\system32\DRIVERS\ipsec.sys - will be cured on reboot 15:04:38.0671 3084 IPSec ( Rootkit.Win32.ZAccess.k ) - User select action: Cure 15:04:47.0500 0656 Deinitialize success
Great, make sure you reboot so that it can be removed, then run this program



Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-12-04.04 - Localadmin 12/04/2011 15:49:20.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2942 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Emsisoft Anti-Malware *Disabled/Updated* {0F8591BB-342B-4493-91C3-4E948ED21255}
AV: VirusScan Enterprise + AntiSpyware Enterprise *Disabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
* Resident AV is active
.
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\$NtUninstallKB25645$
c:\windows\$NtUninstallKB25645$\2649291205\@
c:\windows\$NtUninstallKB25645$\2649291205\bckfg.tmp
c:\windows\$NtUninstallKB25645$\2649291205\cfg.ini
c:\windows\$NtUninstallKB25645$\2649291205\Desktop.ini
c:\windows\$NtUninstallKB25645$\2649291205\keywords
c:\windows\$NtUninstallKB25645$\2649291205\kwrd.dll
c:\windows\$NtUninstallKB25645$\2649291205\L\gpzaoped
c:\windows\$NtUninstallKB25645$\2649291205\lsflt7.ver
c:\windows\$NtUninstallKB25645$\2649291205\U\00000001.@
c:\windows\$NtUninstallKB25645$\2649291205\U\00000002.@
c:\windows\$NtUninstallKB25645$\2649291205\U\00000004.@
c:\windows\$NtUninstallKB25645$\2649291205\U\80000000.@
c:\windows\$NtUninstallKB25645$\2649291205\U\80000004.@
c:\windows\$NtUninstallKB25645$\2649291205\U\80000032.@
c:\windows\$NtUninstallKB25645$\5919236
c:\windows\CSC\d6
c:\windows\system\oeminfo.ini
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-11-04 to 2011-12-04 )))))))))))))))))))))))))))))))
.
.
2011-12-02 22:09 . 2011-12-04 20:49 ——– d—–w- C:\Quarantine
2011-11-21 01:29 . 2011-11-21 01:29 ——– d—–w- c:\documents and settings\Localadmin\Application Data\Malwarebytes
2011-11-21 01:29 . 2011-11-21 01:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-11-21 01:29 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-21 01:29 . 2011-11-21 01:29 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-11-21 01:23 . 2011-11-21 01:23 ——– d—–w- c:\documents and settings\Localadmin\Application Data\SUPERAntiSpyware.com
2011-11-21 01:23 . 2011-11-21 01:23 ——– d—–w- c:\documents and settings\All Users\Application Data\!SASCORE
2011-11-21 01:22 . 2011-11-21 01:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-11-21 01:22 . 2011-11-21 01:22 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-11-20 20:08 . 2011-11-20 20:09 ——– d—–w- c:\documents and settings\Localadmin\Local Settings\Application Data\Google
2011-11-20 20:08 . 2011-11-20 20:08 ——– d—–w- c:\documents and settings\Localadmin\Local Settings\Application Data\Deployment
2011-11-20 05:01 . 2011-12-04 20:58 ——– d—–w- c:\program files\Emsisoft Anti-Malware
2011-11-09 03:37 . 2011-11-09 03:37 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2011-11-08 23:50 . 2011-11-08 23:50 ——– d—–w- c:\documents and settings\Localadmin\Local Settings\Application Data\Scansoft
2011-11-08 22:18 . 2011-11-08 22:18 ——– d—–w- c:\program files\Microsoft CAPICOM 2.1.0.2
2011-11-08 22:18 . 2011-11-08 22:18 ——– d—–w- c:\program files\MSXML 4.0
2011-11-08 19:24 . 2011-11-08 19:24 ——– d—–w- c:\documents and settings\All Users\Application Data\CanonIJPLM
2011-11-08 19:22 . 2011-11-08 19:22 ——– d—–w- c:\documents and settings\Localadmin\Application Data\ScanSoft
2011-11-08 19:22 . 2011-11-08 19:22 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2011-11-08 19:22 . 2011-11-08 19:22 ——– d—–w- c:\program files\Common Files\ScanSoft Shared
2011-11-08 19:21 . 2011-11-08 19:21 ——– d—–w- c:\program files\ScanSoft
2011-11-08 19:19 . 2011-11-08 19:19 ——– d—–w- c:\program files\Common Files\CANON
2011-11-08 19:15 . 2011-11-08 19:15 ——– d–h–w- c:\windows\system32\CanonIJ Uninstaller Information
2011-11-08 19:14 . 2011-11-08 19:24 ——– d—–w- c:\program files\Canon
2011-11-08 19:12 . 2011-11-08 19:12 ——– d–h–w- c:\documents and settings\All Users\Application Data\CanonBJ
2011-11-08 19:12 . 2007-03-19 05:00 69632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPP8S.DLL
2011-11-08 19:12 . 2007-03-19 05:00 27136 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\CNMPD8S.DLL
2011-11-08 19:12 . 2007-03-19 05:00 215040 —-a-w- c:\windows\system32\CNMLM8S.DLL
2011-11-08 19:12 . 2008-04-13 19:47 25856 -c–a-w- c:\windows\system32\dllcache\usbprint.sys
2011-11-08 19:12 . 2008-04-13 19:47 25856 —-a-w- c:\windows\system32\drivers\usbprint.sys
2011-11-08 19:11 . 2008-04-13 19:45 15104 -c–a-w- c:\windows\system32\dllcache\usbscan.sys
2011-11-08 19:11 . 2008-04-13 19:45 15104 —-a-w- c:\windows\system32\drivers\usbscan.sys
2011-11-08 19:10 . 2008-04-13 19:45 32128 -c–a-w- c:\windows\system32\dllcache\usbccgp.sys
2011-11-08 19:10 . 2008-04-13 19:45 32128 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-11-04 21:27 . 2011-11-04 21:27 ——– d—–w- c:\windows\Sun
2011-11-04 21:27 . 2011-11-04 21:27 ——– d—–w- c:\program files\Common Files\Java
2011-11-04 21:27 . 2011-11-04 21:27 476904 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-11-04 21:27 . 2011-11-04 21:27 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-11-04 21:27 . 2011-11-04 21:27 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-11-04 21:27 . 2011-11-04 21:27 ——– d—–w- c:\program files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-04 20:05 . 2004-08-04 10:00 75264 —-a-w- c:\windows\system32\drivers\ipsec.sys
2011-11-18 19:39 . 2011-11-03 18:36 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2007-08-02 14:42 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 10:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 10:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 10:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-06 13:20 . 2004-08-04 10:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-11-11 18:24 . 2011-11-02 20:43 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-11-21 4617600]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-04-28 8429568]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-12-10 49152]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-01-25 111952]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-10-09 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400]
"emsisoft anti-malware"="c:\program files\emsisoft anti-malware\a2guard.exe" [2011-11-16 3443600]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"53:UDP"= 53:UDP:Promo
.
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files\Emsisoft Anti-Malware\a2ddax86.sys [11/20/2011 12:01 AM 17904]
R1 a2injectiondriver;a2injectiondriver;c:\program files\Emsisoft Anti-Malware\a2dix86.sys [11/20/2011 12:01 AM 34768]
R1 a2util;a-squared Malware-IDS utility driver;c:\program files\Emsisoft Anti-Malware\a2util32.sys [11/20/2011 12:01 AM 11776]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 11:27 AM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 4:55 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [7/18/2011 7:02 PM 116608]
R2 a2AntiMalware;Emsisoft Anti-Malware 6.0 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [11/20/2011 12:01 AM 2996784]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [11/20/2011 8:29 PM 366152]
R3 a2acc;a2acc;c:\program files\Emsisoft Anti-Malware\a2accx86.sys [11/20/2011 12:01 AM 51632]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [11/20/2011 8:29 PM 22216]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 5:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2237382956-1305487552-4146120090-500Core.job
- c:\documents and settings\Localadmin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-11-20 20:08]
.
2011-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2237382956-1305487552-4146120090-500UA.job
- c:\documents and settings\Localadmin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-11-20 20:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.unh.edu/
uInternet Connection Wizard,ShellNext = hxxp://www.unh.edu/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Localadmin\Application Data\Mozilla\Firefox\Profiles\j3mctnv8.default\
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-ISUSPM Startup - c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
SafeBoot-63387904.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-04 15:58
Windows 5.1.2600 Service Pack 3 NTFS
.
detected NTDLL code modification:
ZwOpenFile
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files:
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(868)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(2080)
c:\windows\system32\WININET.dll
c:\program files\Emsisoft Anti-Malware\a2hooks32.dll
c:\program files\ScanSoft\OmniPageSE4\OpHookSE4.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\WS2HELP.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\System32\SCardSvr.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\StacSV.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2011-12-04 16:02:20 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-04 21:02
.
Pre-Run: 298,771,972,096 bytes free
Post-Run: 298,908,499,968 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /nodebug /noserialmice
.
- - End Of File - - 0E346DE4E1488D9B7D7541DADB388148
Hi,

Just so you know you where infected with the ZeroAccess rootkit, it looks like it gone, things should be running better now. Combofix logs take time to go over so in the meantime do this

You have Malwarebytes installed :thumbup: Open it, check for updates and run the Quick Scan and post the log.

Then run aswMBR again, just to scan and post the NEW LOG




Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <–Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8311 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 12/4/2011 4:57:00 PM mbam-log-2011-12-04 (16-57-00).txt Scan type: Quick scan Objects scanned: 152897 Time elapsed: 1 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8311 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 12/4/2011 4:58:47 PM mbam-log-2011-12-04 (16-58-47).txt Scan type: Quick scan Objects scanned: 152912 Time elapsed: 1 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Localadmin\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Localadmin\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default User
->Temporary Internet Files folder emptied: 33170 bytes

User: Localadmin
->Temp folder emptied: 632 bytes
->Temporary Internet Files folder emptied: 111826 bytes
->Java cache emptied: 10056281 bytes
->FireFox cache emptied: 80942194 bytes
->Google Chrome cache emptied: 365780791 bytes
->Flash cache emptied: 14704 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Java cache emptied: 24550 bytes
->Flash cache emptied: 1911 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 122568704 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 553.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12042011_170025

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-04 17:46:06 —————————– 17:46:06.484 OS Version: Windows 5.1.2600 Service Pack 3 17:46:06.484 Number of processors: 2 586 0xF0D 17:46:06.484 ComputerName: M-BEARDSLEY-D83 UserName: Localadmin 17:46:07.187 Initialize success 17:46:13.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 17:46:13.156 Disk 0 Vendor: WDC_WD3200BEKT-00PVMT0 01.01A01 Size: 305245MB BusType: 3 17:46:15.171 Disk 0 MBR read successfully 17:46:15.171 Disk 0 MBR scan 17:46:15.171 Disk 0 Windows VISTA default MBR code 17:46:15.171 Disk 0 scanning sectors +625137345 17:46:15.250 Disk 0 scanning C:\WINDOWS\system32\drivers 17:46:22.171 Service scanning 17:46:23.296 Modules scanning 17:46:26.281 Disk 0 trace - called modules: 17:46:26.296 ntkrnlpa.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 17:46:26.296 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a838ab8] 17:46:26.296 3 CLASSPNP.SYS[ba108fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x8a78fd98] 17:46:26.296 Scan finished successfully 17:46:42.359 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Localadmin\Desktop\MBR.dat" 17:46:42.375 The log file has been saved successfully to "C:\Documents and Settings\Localadmin\Desktop\aswMBR.txt" Everything seems to be running well at the moment. No sign of ping.exe.
:thumbup:

aswMBR shows its gone .

We always like to follow up with a free online virus scanner to make sure nothing was missed, depending on your system it could take an hour or more so do this when you have the time and post the results back for me to see

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as
    ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
Please make sure you include the following items in your next post:
The log that was produced after running ESET Online Scanner.
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=b51c378de90b9645a98a3ad4e0099b8e # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-12-05 02:01:16 # local_time=2011-12-04 09:01:16 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=50665 # found=0 # cleaned=0 # scan_time=3646 There was nothing found, so there was no option to make a list of found threats.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI