[DoS attack: STORM] attack packets in last 20 sec from ip [10.0.0.3], Sunday, Dec 11,2011 08:18:08
This is one of the many instances of this line from the router log and it's from my computer.
I have a Netgear N600 router I am hardwired into it.
I am almost certain that this came from a website that is used to shorten download URL's called Addfly that i used to download a minecraft mod.
Assistance would be much appreciated.
(I have seen a similar topic, and it instructed me to do a OTL scan, however the scan.txt file was missing)
Hi,
Please do the following:
Please download
DDS from either of these links
LINK 1
LINK 2
and save it to your
desktop.
Disable any script blocking protection Double click dds to run the tool. When done, two DDS.txt's will open. Save both reports to your desktop. —————————————————
Please include the contents of the following in your next reply:
DDS.txt
Attach.txt .
NEXT
Please download
aswMBR to your desktop.
Double click the aswMBR.exe icon to run it When asked if you want to download Avast's virus definitions please select Yes . Click the Scan button to start the scan On completion of the scan, click the save log button, save it to your desktop and post it in your next reply. You will also notice another file created on the desktop named MBR.dat . Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 10.1.0
Run by [removed] at 18:26:21 on 2011-12-21
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1022.468 [GMT -6:00]
.
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
AV: McAfee VirusScan *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Matt\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Documents and Settings\Matt\Local Settings\Application Data\Akamai\netsession_win.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
.
============== Pseudo HJT Report ===============
.
uSearch Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60001
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Avira SearchFree Toolbar plus WebGuard: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Avira SearchFree Toolbar plus WebGuard: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Steam] "c:\program files\steam\steam.exe" -silent
uRun: [Akamai NetSession Interface] "c:\documents and settings\matt\local settings\application data\akamai\netsession_win.exe"
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Google Update] "c:\documents and settings\matt\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [TrueImageMonitor.exe] c:\program files\acronis\trueimagehome\TrueImageMonitor.exe
mRun: [Acronis Scheduler2 Service] "c:\program files\common files\acronis\schedule2\schedhlp.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: []
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" –auto-start
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\matt\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\matt\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\matt\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL
LSP: c:\program files\avira\antivir desktop\avsda.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_01-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 10.0.0.1
TCP: Interfaces\{18AB7159-3039-4600-B663-B76BE5D8DE99} : DhcpNameServer = 10.0.0.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\matt\application data\mozilla\firefox\profiles\ffmwvzb5.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2680363&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/home.php?ref=hp
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=DMDTDF&PC=VEOH&q=
FF - component: c:\documents and settings\matt\application data\mozilla\firefox\profiles\ffmwvzb5.default\extensions\{a8864317-e18b-4292-99d9-e6e65ab905d3}\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\documents and settings\matt\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nos\bin\np_gp.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-2-5 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-2-5 136360]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-2-5 269480]
R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\avira\antivir desktop\avwebgrd.exe [2011-6-28 428200]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-2-5 66616]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2011-8-4 1361288]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-12 22216]
S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-4 14336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-12 366152]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-12-13 03:09:58 ——– d—–w- c:\documents and settings\matt\application data\Malwarebytes
2011-12-13 03:09:50 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes
2011-12-13 03:09:46 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-13 03:09:45 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-12 03:02:57 ——– d—–w- c:\program files\ESET
2011-12-07 22:34:52 ——– d—–w- c:\documents and settings\matt\local settings\application data\Google
2011-12-02 23:30:52 ——– d—–r- c:\program files\Skype
.
==================== Find3M ====================
.
2011-11-22 21:00:00 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-27 20:24:40 128000 —-a-w- c:\windows\system32\javacpl.cpl
2011-10-27 20:24:39 544656 —-a-w- c:\windows\system32\deployJava1.dll
.
============= FINISH: 18:27:31.76 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 1/30/2011 2:59:47 PM
System Uptime: 12/14/2011 5:49:21 PM (169 hours ago)
.
Motherboard: Dell Inc. | | 0KH290
Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz
Processor: Intel® Pentium® D CPU 2.80GHz | Microprocessor | 2793/800mhz
.
==== Disk Partitions =========================
.
A: is Removable
C: is FIXED (NTFS) - 1397 GiB total, 1272.454 GiB free.
D: is CDROM (UDF)
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP269: 9/23/2011 4:55:41 AM - System Checkpoint
RP270: 9/24/2011 5:58:18 AM - System Checkpoint
RP271: 9/25/2011 6:34:17 AM - System Checkpoint
RP272: 9/26/2011 6:53:19 AM - System Checkpoint
RP273: 9/27/2011 6:55:43 AM - System Checkpoint
RP274: 9/28/2011 7:38:34 AM - System Checkpoint
RP275: 9/29/2011 9:38:34 AM - System Checkpoint
RP276: 9/30/2011 1:51:33 PM - System Checkpoint
RP277: 10/1/2011 7:29:41 PM - System Checkpoint
RP278: 10/2/2011 9:30:02 PM - System Checkpoint
RP279: 10/3/2011 9:33:36 PM - System Checkpoint
RP280: 10/4/2011 11:44:35 PM - System Checkpoint
RP281: 10/6/2011 11:50:47 PM - System Checkpoint
RP282: 10/8/2011 1:20:34 AM - System Checkpoint
RP283: 10/9/2011 2:13:25 AM - System Checkpoint
RP284: 10/10/2011 3:47:44 AM - System Checkpoint
RP285: 10/11/2011 4:35:52 AM - System Checkpoint
RP286: 10/12/2011 5:35:55 AM - System Checkpoint
RP287: 10/13/2011 5:54:55 AM - System Checkpoint
RP288: 10/14/2011 6:11:52 AM - System Checkpoint
RP289: 10/15/2011 7:23:52 AM - System Checkpoint
RP290: 10/16/2011 7:35:53 AM - System Checkpoint
RP291: 10/17/2011 7:46:52 AM - System Checkpoint
RP292: 10/18/2011 9:22:50 AM - System Checkpoint
RP293: 10/19/2011 9:34:51 AM - System Checkpoint
RP294: 10/20/2011 10:58:52 AM - System Checkpoint
RP295: 10/21/2011 11:34:51 AM - System Checkpoint
RP296: 10/23/2011 7:20:55 PM - System Checkpoint
RP297: 10/24/2011 11:18:37 PM - System Checkpoint
RP298: 10/26/2011 1:23:52 AM - System Checkpoint
RP299: 10/26/2011 6:34:53 AM - Removed Apple Application Support
RP300: 10/26/2011 6:36:24 AM - Removed Apple Mobile Device Support
RP301: 10/27/2011 7:02:22 AM - System Checkpoint
RP302: 10/27/2011 2:59:04 PM - Installed Java™ 6 Update 29
RP303: 10/27/2011 3:24:32 PM - Installed Java™ 7 Update 1
RP304: 10/28/2011 4:07:39 PM - System Checkpoint
RP305: 10/29/2011 6:16:38 PM - System Checkpoint
RP306: 10/30/2011 5:35:07 PM - System Checkpoint
RP307: 10/31/2011 8:34:24 PM - System Checkpoint
RP308: 11/1/2011 10:57:27 PM - System Checkpoint
RP309: 11/2/2011 5:47:11 PM - Installed Compatibility Pack for the 2007 Office system
RP310: 11/3/2011 11:21:18 PM - System Checkpoint
RP311: 11/5/2011 12:23:44 AM - System Checkpoint
RP312: 11/6/2011 8:28:31 PM - System Checkpoint
RP313: 11/7/2011 8:50:47 PM - System Checkpoint
RP314: 11/8/2011 10:12:35 PM - System Checkpoint
RP315: 11/9/2011 10:39:08 PM - System Checkpoint
RP316: 11/11/2011 12:20:51 AM - System Checkpoint
RP317: 11/12/2011 12:33:07 AM - System Checkpoint
RP318: 11/13/2011 1:34:44 AM - System Checkpoint
RP319: 11/14/2011 2:11:24 AM - System Checkpoint
RP320: 11/15/2011 3:26:37 AM - System Checkpoint
RP321: 11/16/2011 3:49:05 AM - System Checkpoint
RP322: 11/17/2011 4:32:50 AM - System Checkpoint
RP323: 11/18/2011 4:35:57 AM - System Checkpoint
RP324: 11/20/2011 12:06:47 AM - System Checkpoint
RP325: 11/21/2011 1:00:46 AM - System Checkpoint
RP326: 11/22/2011 2:00:26 AM - System Checkpoint
RP327: 11/23/2011 3:03:50 AM - System Checkpoint
RP328: 11/24/2011 4:25:18 AM - System Checkpoint
RP329: 11/25/2011 11:35:47 PM - System Checkpoint
RP330: 11/27/2011 12:07:40 AM - System Checkpoint
RP331: 11/28/2011 1:21:08 AM - System Checkpoint
RP332: 11/29/2011 2:24:30 AM - System Checkpoint
RP333: 11/30/2011 3:47:18 AM - System Checkpoint
RP334: 12/1/2011 4:56:05 AM - System Checkpoint
RP335: 12/2/2011 7:03:41 AM - System Checkpoint
RP336: 12/3/2011 7:28:47 AM - System Checkpoint
RP337: 12/4/2011 9:03:48 AM - System Checkpoint
RP338: 12/5/2011 10:26:46 AM - System Checkpoint
RP339: 12/6/2011 10:34:48 AM - System Checkpoint
RP340: 12/7/2011 12:57:21 PM - System Checkpoint
RP341: 12/8/2011 1:19:19 PM - System Checkpoint
RP342: 12/9/2011 3:05:13 PM - System Checkpoint
RP343: 12/11/2011 12:26:13 AM - System Checkpoint
RP344: 12/12/2011 7:01:07 AM - System Checkpoint
RP345: 12/13/2011 8:46:34 AM - System Checkpoint
RP346: 12/14/2011 10:31:49 AM - System Checkpoint
RP347: 12/15/2011 12:02:14 PM - System Checkpoint
RP348: 12/16/2011 2:24:10 PM - System Checkpoint
RP349: 12/17/2011 2:34:04 PM - System Checkpoint
RP350: 12/18/2011 2:58:03 PM - System Checkpoint
RP351: 12/19/2011 9:17:58 PM - System Checkpoint
RP352: 12/20/2011 9:19:55 PM - System Checkpoint
.
==== Installed Programs ======================
.
2010 DR PEPPER EA GAMES EVERY BOTTLE/CUP WINS PROMOTION
7-Zip 9.20
Acronis True Image WD Edition
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Age of Mythology
Age of Mythology - The Titans Expansion
Akamai NetSession Interface
Akamai NetSession Interface Service
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
Avernum 2
Avernum 4
Avernum Demo
Avira AntiVir Personal - Free Antivirus
Big Fish Games: Game Manager
Blades of Avernum
Bonjour
Broadcom Gigabit Integrated Controller
Compatibility Pack for the 2007 Office system
Dropbox
ESET Online Scanner v3
FrostWire 4.21.6
Geneforge 4
Geneforge 5
Google Chrome
Half-Life 2: Lost Coast
Hotfix for Windows XP (KB921411)
Hotfix for Windows XP (KB952287)
iTunes
Java Auto Updater
Java™ 6 Update 29
Java™ 7 Update 1
LogMeIn Hamachi
Microsoft .NET Framework 2.0
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Mozilla Firefox 8.0 (x86 en-US)
MSXML 4.0 SP2 Parser and SDK
MSXML 6 Service Pack 2 (KB973686)
MSXML4 Parser
NVIDIA Display Control Panel
NVIDIA Drivers
NVIDIA nView Desktop Manager
NVIDIA PhysX
Oblivion
Oblivion mod manager 1.1.12
Origin
Python 2.6 comtypes-0.6.2
Python 2.6 psyco-1.6
Python 2.6 pywin32-214
Python 2.6.5
QuickTime
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player (KB979402)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB981350)
Security Update for Windows XP (KB982381)
Skype Click to Call
Skype™ 5.6
SPORE™
Team Fortress 2
TeamSpeak 3 Client
Unofficial Oblivion Patch v3.2.0
Update for Windows XP (KB898461)
Update for Windows XP (KB932823-v3)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
WinRAR 4.00 beta 7 (32-bit)
World of Warcraft
Wrye Bash
wxPython 2.8.11.0 (ansi) for Python 2.6
.
==== Event Viewer Messages From Past Week ========
.
12/14/2011 5:59:54 PM, error: Service Control Manager [7023] - The Akamai NetSession Interface service terminated with the following error: The specified module could not be found.
12/14/2011 2:10:38 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the Akamai service.
.
==== End Of File ===========================
aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-21 18:28:03
—————————–
18:28:03.218 OS Version: Windows 5.1.2600 Service Pack 2
18:28:03.218 Number of processors: 2 586 0x407
18:28:03.218 ComputerName: MATT-066F2F7B08 UserName: Matt
18:28:05.671 Initialize success
18:32:13.530 AVAST engine defs: 11122102
21:06:12.577 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e
21:06:12.593 Disk 0 Vendor: WDC_WD15EADS-00P8B0 01.00A01 Size: 1430799MB BusType: 3
21:06:14.608 Disk 0 MBR read successfully
21:06:14.608 Disk 0 MBR scan
21:06:14.655 Disk 0 Windows XP default MBR code
21:06:14.655 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1430789 MB offset 63
21:06:14.702 Disk 0 scanning sectors +2930256000
21:06:14.749 Disk 0 scanning C:\WINDOWS\system32\drivers
21:06:27.030 Service scanning
21:06:29.202 Modules scanning
21:06:36.905 Disk 0 trace - called modules:
21:06:36.952 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
21:06:36.952 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86739ab8]
21:06:36.952 3 CLASSPNP.SYS[f78a605b] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-e[0x867e0d98]
21:06:38.733 AVAST engine scan C:\WINDOWS
21:06:52.827 AVAST engine scan C:\WINDOWS\system32
21:12:03.546 AVAST engine scan C:\WINDOWS\system32\drivers
21:13:43.499 AVAST engine scan C:\Documents and Settings\Matt
22:15:56.343 AVAST engine scan C:\Documents and Settings\All Users
22:19:52.968 Scan finished successfully
22:21:28.999 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Matt\Desktop\MBR.dat"
22:21:29.046 The log file has been saved successfully to "C:\Documents and Settings\Matt\Desktop\aswMBR.txt"
Hi,
Please do the following:
Please download
TDSSKiller.zip
Extract it to your desktop Double click TDSSKiller.exe Press Start Scan
Only if Malicious objects are found then ensure Cure is selected Then click Continue > Reboot now Copy and paste the log in your next reply
A copy of the log will be saved automatically to the root of the drive (typically C:\)
NEXT
Download
ComboFix from one of the following locations:
Link 1
Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your
Desktop
*
IMPORTANT -
Disable your AntiVirus and AntiSpyware applications , usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link
here
Double click on ComboFix.exe & follow the prompts.
As part of it's process,
ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's
strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes , to continue scanning for malware.
When finished, it shall produce a log for you.
Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic