This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

DoS attack: STORM [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

[DoS attack: STORM] attack packets in last 20 sec from ip [10.0.0.3], Sunday, Dec 11,2011 08:18:08 This is one of the many instances of this line from the router log and it's from my computer. I have a Netgear N600 router I am hardwired into it. I am almost certain that this came from a website that is used to shorten download URL's called Addfly that i used to download a minecraft mod. Assistance would be much appreciated. (I have seen a similar topic, and it instructed me to do a OTL scan, however the scan.txt file was missing)
Hi,

Please do the following:



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
. DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 10.1.0 Run by [removed] at 18:26:21 on 2011-12-21 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.468 [GMT -6:00] . AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7} AV: McAfee VirusScan *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Ask.com\Updater\Updater.exe C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Skype\Phone\Skype.exe C:\Documents and Settings\Matt\Application Data\Dropbox\bin\Dropbox.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\Program Files\LogMeIn Hamachi\hamachi-2.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\cidaemon.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Akamai\netsession_win.exe C:\Documents and Settings\Matt\Local Settings\Application Data\Akamai\netsession_win.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe . ============== Pseudo HJT Report =============== . uSearch Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60001 uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Avira SearchFree Toolbar plus WebGuard: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Avira SearchFree Toolbar plus WebGuard: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Steam] "c:\program files\steam\steam.exe" -silent uRun: [Akamai NetSession Interface] "c:\documents and settings\matt\local settings\application data\akamai\netsession_win.exe" uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Google Update] "c:\documents and settings\matt\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [nwiz] nwiz.exe /installquiet mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [] mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" –auto-start mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\matt\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\matt\application data\dropbox\bin\Dropbox.exe StartupFolder: c:\docume~1\matt\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL LSP: c:\program files\avira\antivir desktop\avsda.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: DhcpNameServer = 10.0.0.1 TCP: Interfaces\{18AB7159-3039-4600-B663-B76BE5D8DE99} : DhcpNameServer = 10.0.0.1 Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\matt\application data\mozilla\firefox\profiles\ffmwvzb5.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2680363&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=hp FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=DMDTDF&PC=VEOH&q= FF - component: c:\documents and settings\matt\application data\mozilla\firefox\profiles\ffmwvzb5.default\extensions\{a8864317-e18b-4292-99d9-e6e65ab905d3}\components\RadioWMPCoreGecko19.dll FF - plugin: c:\documents and settings\matt\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\nos\bin\np_gp.dll FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll . —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== . R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-2-5 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-2-5 136360] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-2-5 269480] R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\avira\antivir desktop\avwebgrd.exe [2011-6-28 428200] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-2-5 66616] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2011-8-4 1361288] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-12 22216] S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-4 14336] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-12 366152] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] . =============== Created Last 30 ================ . 2011-12-13 03:09:58 ——– d—–w- c:\documents and settings\matt\application data\Malwarebytes 2011-12-13 03:09:50 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-12-13 03:09:46 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-13 03:09:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-12-12 03:02:57 ——– d—–w- c:\program files\ESET 2011-12-07 22:34:52 ——– d—–w- c:\documents and settings\matt\local settings\application data\Google 2011-12-02 23:30:52 ——– d—–r- c:\program files\Skype . ==================== Find3M ==================== . 2011-11-22 21:00:00 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-27 20:24:40 128000 —-a-w- c:\windows\system32\javacpl.cpl 2011-10-27 20:24:39 544656 —-a-w- c:\windows\system32\deployJava1.dll . ============= FINISH: 18:27:31.76 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 1/30/2011 2:59:47 PM System Uptime: 12/14/2011 5:49:21 PM (169 hours ago) . Motherboard: Dell Inc. | | 0KH290 Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 1397 GiB total, 1272.454 GiB free. D: is CDROM (UDF) . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP269: 9/23/2011 4:55:41 AM - System Checkpoint RP270: 9/24/2011 5:58:18 AM - System Checkpoint RP271: 9/25/2011 6:34:17 AM - System Checkpoint RP272: 9/26/2011 6:53:19 AM - System Checkpoint RP273: 9/27/2011 6:55:43 AM - System Checkpoint RP274: 9/28/2011 7:38:34 AM - System Checkpoint RP275: 9/29/2011 9:38:34 AM - System Checkpoint RP276: 9/30/2011 1:51:33 PM - System Checkpoint RP277: 10/1/2011 7:29:41 PM - System Checkpoint RP278: 10/2/2011 9:30:02 PM - System Checkpoint RP279: 10/3/2011 9:33:36 PM - System Checkpoint RP280: 10/4/2011 11:44:35 PM - System Checkpoint RP281: 10/6/2011 11:50:47 PM - System Checkpoint RP282: 10/8/2011 1:20:34 AM - System Checkpoint RP283: 10/9/2011 2:13:25 AM - System Checkpoint RP284: 10/10/2011 3:47:44 AM - System Checkpoint RP285: 10/11/2011 4:35:52 AM - System Checkpoint RP286: 10/12/2011 5:35:55 AM - System Checkpoint RP287: 10/13/2011 5:54:55 AM - System Checkpoint RP288: 10/14/2011 6:11:52 AM - System Checkpoint RP289: 10/15/2011 7:23:52 AM - System Checkpoint RP290: 10/16/2011 7:35:53 AM - System Checkpoint RP291: 10/17/2011 7:46:52 AM - System Checkpoint RP292: 10/18/2011 9:22:50 AM - System Checkpoint RP293: 10/19/2011 9:34:51 AM - System Checkpoint RP294: 10/20/2011 10:58:52 AM - System Checkpoint RP295: 10/21/2011 11:34:51 AM - System Checkpoint RP296: 10/23/2011 7:20:55 PM - System Checkpoint RP297: 10/24/2011 11:18:37 PM - System Checkpoint RP298: 10/26/2011 1:23:52 AM - System Checkpoint RP299: 10/26/2011 6:34:53 AM - Removed Apple Application Support RP300: 10/26/2011 6:36:24 AM - Removed Apple Mobile Device Support RP301: 10/27/2011 7:02:22 AM - System Checkpoint RP302: 10/27/2011 2:59:04 PM - Installed Java™ 6 Update 29 RP303: 10/27/2011 3:24:32 PM - Installed Java™ 7 Update 1 RP304: 10/28/2011 4:07:39 PM - System Checkpoint RP305: 10/29/2011 6:16:38 PM - System Checkpoint RP306: 10/30/2011 5:35:07 PM - System Checkpoint RP307: 10/31/2011 8:34:24 PM - System Checkpoint RP308: 11/1/2011 10:57:27 PM - System Checkpoint RP309: 11/2/2011 5:47:11 PM - Installed Compatibility Pack for the 2007 Office system RP310: 11/3/2011 11:21:18 PM - System Checkpoint RP311: 11/5/2011 12:23:44 AM - System Checkpoint RP312: 11/6/2011 8:28:31 PM - System Checkpoint RP313: 11/7/2011 8:50:47 PM - System Checkpoint RP314: 11/8/2011 10:12:35 PM - System Checkpoint RP315: 11/9/2011 10:39:08 PM - System Checkpoint RP316: 11/11/2011 12:20:51 AM - System Checkpoint RP317: 11/12/2011 12:33:07 AM - System Checkpoint RP318: 11/13/2011 1:34:44 AM - System Checkpoint RP319: 11/14/2011 2:11:24 AM - System Checkpoint RP320: 11/15/2011 3:26:37 AM - System Checkpoint RP321: 11/16/2011 3:49:05 AM - System Checkpoint RP322: 11/17/2011 4:32:50 AM - System Checkpoint RP323: 11/18/2011 4:35:57 AM - System Checkpoint RP324: 11/20/2011 12:06:47 AM - System Checkpoint RP325: 11/21/2011 1:00:46 AM - System Checkpoint RP326: 11/22/2011 2:00:26 AM - System Checkpoint RP327: 11/23/2011 3:03:50 AM - System Checkpoint RP328: 11/24/2011 4:25:18 AM - System Checkpoint RP329: 11/25/2011 11:35:47 PM - System Checkpoint RP330: 11/27/2011 12:07:40 AM - System Checkpoint RP331: 11/28/2011 1:21:08 AM - System Checkpoint RP332: 11/29/2011 2:24:30 AM - System Checkpoint RP333: 11/30/2011 3:47:18 AM - System Checkpoint RP334: 12/1/2011 4:56:05 AM - System Checkpoint RP335: 12/2/2011 7:03:41 AM - System Checkpoint RP336: 12/3/2011 7:28:47 AM - System Checkpoint RP337: 12/4/2011 9:03:48 AM - System Checkpoint RP338: 12/5/2011 10:26:46 AM - System Checkpoint RP339: 12/6/2011 10:34:48 AM - System Checkpoint RP340: 12/7/2011 12:57:21 PM - System Checkpoint RP341: 12/8/2011 1:19:19 PM - System Checkpoint RP342: 12/9/2011 3:05:13 PM - System Checkpoint RP343: 12/11/2011 12:26:13 AM - System Checkpoint RP344: 12/12/2011 7:01:07 AM - System Checkpoint RP345: 12/13/2011 8:46:34 AM - System Checkpoint RP346: 12/14/2011 10:31:49 AM - System Checkpoint RP347: 12/15/2011 12:02:14 PM - System Checkpoint RP348: 12/16/2011 2:24:10 PM - System Checkpoint RP349: 12/17/2011 2:34:04 PM - System Checkpoint RP350: 12/18/2011 2:58:03 PM - System Checkpoint RP351: 12/19/2011 9:17:58 PM - System Checkpoint RP352: 12/20/2011 9:19:55 PM - System Checkpoint . ==== Installed Programs ====================== . 2010 DR PEPPER EA GAMES EVERY BOTTLE/CUP WINS PROMOTION 7-Zip 9.20 Acronis True Image WD Edition Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 11 Plugin Age of Mythology Age of Mythology - The Titans Expansion Akamai NetSession Interface Akamai NetSession Interface Service Apple Application Support Apple Mobile Device Support Apple Software Update Ask Toolbar Avernum 2 Avernum 4 Avernum Demo Avira AntiVir Personal - Free Antivirus Big Fish Games: Game Manager Blades of Avernum Bonjour Broadcom Gigabit Integrated Controller Compatibility Pack for the 2007 Office system Dropbox ESET Online Scanner v3 FrostWire 4.21.6 Geneforge 4 Geneforge 5 Google Chrome Half-Life 2: Lost Coast Hotfix for Windows XP (KB921411) Hotfix for Windows XP (KB952287) iTunes Java Auto Updater Java™ 6 Update 29 Java™ 7 Update 1 LogMeIn Hamachi Microsoft .NET Framework 2.0 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Office Professional Edition 2003 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Mozilla Firefox 8.0 (x86 en-US) MSXML 4.0 SP2 Parser and SDK MSXML 6 Service Pack 2 (KB973686) MSXML4 Parser NVIDIA Display Control Panel NVIDIA Drivers NVIDIA nView Desktop Manager NVIDIA PhysX Oblivion Oblivion mod manager 1.1.12 Origin Python 2.6 comtypes-0.6.2 Python 2.6 psyco-1.6 Python 2.6 pywin32-214 Python 2.6.5 QuickTime Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981350) Security Update for Windows XP (KB982381) Skype Click to Call Skype™ 5.6 SPORE™ Team Fortress 2 TeamSpeak 3 Client Unofficial Oblivion Patch v3.2.0 Update for Windows XP (KB898461) Update for Windows XP (KB932823-v3) Update for Windows XP (KB955759) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Installer 3.1 (KB893803) WinRAR 4.00 beta 7 (32-bit) World of Warcraft Wrye Bash wxPython 2.8.11.0 (ansi) for Python 2.6 . ==== Event Viewer Messages From Past Week ======== . 12/14/2011 5:59:54 PM, error: Service Control Manager [7023] - The Akamai NetSession Interface service terminated with the following error: The specified module could not be found. 12/14/2011 2:10:38 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Akamai service. . ==== End Of File =========================== aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software Run date: 2011-12-21 18:28:03 —————————– 18:28:03.218 OS Version: Windows 5.1.2600 Service Pack 2 18:28:03.218 Number of processors: 2 586 0x407 18:28:03.218 ComputerName: MATT-066F2F7B08 UserName: Matt 18:28:05.671 Initialize success 18:32:13.530 AVAST engine defs: 11122102 21:06:12.577 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e 21:06:12.593 Disk 0 Vendor: WDC_WD15EADS-00P8B0 01.00A01 Size: 1430799MB BusType: 3 21:06:14.608 Disk 0 MBR read successfully 21:06:14.608 Disk 0 MBR scan 21:06:14.655 Disk 0 Windows XP default MBR code 21:06:14.655 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1430789 MB offset 63 21:06:14.702 Disk 0 scanning sectors +2930256000 21:06:14.749 Disk 0 scanning C:\WINDOWS\system32\drivers 21:06:27.030 Service scanning 21:06:29.202 Modules scanning 21:06:36.905 Disk 0 trace - called modules: 21:06:36.952 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS 21:06:36.952 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86739ab8] 21:06:36.952 3 CLASSPNP.SYS[f78a605b] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x867e0d98] 21:06:38.733 AVAST engine scan C:\WINDOWS 21:06:52.827 AVAST engine scan C:\WINDOWS\system32 21:12:03.546 AVAST engine scan C:\WINDOWS\system32\drivers 21:13:43.499 AVAST engine scan C:\Documents and Settings\Matt 22:15:56.343 AVAST engine scan C:\Documents and Settings\All Users 22:19:52.968 Scan finished successfully 22:21:28.999 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Matt\Desktop\MBR.dat" 22:21:29.046 The log file has been saved successfully to "C:\Documents and Settings\Matt\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT



Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI