This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ping.exe 100% cpu usage and goggle redirect issue [Solved]

49 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ping.exe process draining resources. when process is ended,using task manager, computer speed returns. 15 minutes later ping.exe process starts again. also noticed that when on internet, i will be redirected to a site saying i have won a prize. here is my hijack log below. thanks for the help.




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:06:08 PM, on 12/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\steve\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink PopUp Blocker V2 - {512ACF1B-64D9-4928-B382-A80556F28DB4} - C:\Program Files\EarthLink TotalAccess\Toolbar\ElnkPub.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Earthlink Protection BHO - {9579D574-D4D8-4335-9560-FE8641A013BD} - C:\Program Files\EarthLink TotalAccess\Toolbar\ProtctIE.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Uninstall Legacy Earthlink Toolbar - {E713904C-DF05-4C79-BBAD-02DB923253BE} - C:\Program Files\EarthLink TotalAccess\Toolbar\uninsttb.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: EarthLink Toolbar - {C7768536-96F8-4001-B1A2-90EE21279187} - C:\Program Files\EarthLink TotalAccess\Toolbar\Toolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe"
O4 - HKLM\..\Run: [IPInSightLAN 01] "C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe" -l
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 \3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: WD Quick View.lnk = C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: EarthLink Google Search - res://C:\Program Files\EarthLink TotalAccess\Toolbar\SearchUI.dll/search.html
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: EarthLink Monitor Service (EarthLinkMonitor) - Boingo Wireless, Inc. - C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MotoConnect Service - Unknown owner - C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\PC Tools Security\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\PC Tools Security\pctsSvc.exe
O23 - Service: WDDMService - WDC - C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
O23 - Service: WDFMEService - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
O23 - Service: WDRulesService - Western Digital - C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe

–
End of file - 10780 bytes

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, rocky41

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello there,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.com
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


===================================================

Download Security Check by screen317 from here or here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===================================================

On your next reply please post :
DDS log
GMER log
Checkup log

Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
thanks for the help conspire. here is the info you requested below. i could not get the security check to work properly. it would give be this error message "netsh.exe-entry point found" "The procedure entry point migratewinsockconf could not be located in the dynamic link library mswsock.dll. it did submit a log , which i will post.

DDS.txt:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_29
Run by [removed] at 0:22:08 on 2011-12-14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.446 [GMT -5:00]
.
AV: Spyware Doctor with AntiVirus *Disabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPMon32.exe
C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe
C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\System32\ping.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://start.earthlink.net
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://start.earthlink.net
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uSearch Bar = hxxp://start.earthlink.net/AL/Search
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://start.earthlink.net/AL/Search
uURLSearchHooks: SrchHook Class: {44f9b173-041c-4825-a9b9-d914bd9dcbb3} - c:\program files\earthlink totalaccess\ElnIE.dll
uURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: ElnkPubBHO Class: {512acf1b-64d9-4928-b382-a80556f28db4} - c:\program files\earthlink totalaccess\toolbar\ElnkPub.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: ElnkProtectionBHO Class: {9579d574-d4d8-4335-9560-fe8641a013bd} - c:\program files\earthlink totalaccess\toolbar\ProtctIE.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7018.1622\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: ElnkLegacyUninstBHO Class: {e713904c-df05-4c79-bbad-02db923253be} - c:\program files\earthlink totalaccess\toolbar\uninsttb.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: EarthLink Toolbar: {c7768536-96f8-4001-b1a2-90ee21279187} - c:\program files\earthlink totalaccess\toolbar\Toolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Sonic RecordNow!]
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\steve\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [E6TaskPanel] "c:\program files\earthlink totalaccess\TaskPanl.exe" -winstart
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [StorageGuard] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe"
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [IPInSightMonitor 01] "c:\program files\earthlink totalaccess\fastlane2\IPMon32.exe"
mRun: [IPInSightLAN 01] "c:\program files\earthlink totalaccess\fastlane2\IPClient.exe" -l
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [DLCCCATS] rundll32 \3\DLCCtime.dll,_RunDLLEntry@16
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wdquic~1.lnk - c:\program files\western digital\wd smartware\WDDMStatus.exe
IE: EarthLink Google Search - c:\program files\earthlink totalaccess\toolbar\SearchUI.dll/search.html
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{18E5B217-295D-4BF8-93D6-A120A2BE5A5F} : DhcpNameServer = 192.168.1.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\steve\application data\mozilla\firefox\profiles\4nwpzili.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 1050
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\steve\application data\move networks\plugins\npqmp071503000010.dll
FF - plugin: c:\documents and settings\steve\application data\move networks\plugins\npqmp071701000002.dll
FF - plugin: c:\documents and settings\steve\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\steve\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\steve\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2011-11-2 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2011-11-2 338880]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-10-29 587096]
R2 EarthLinkMonitor;EarthLink Monitor Service;c:\program files\earthlink totalaccess\wengine\wmonitor.exe [2005-1-26 65604]
R2 MotoConnect Service;MotoConnect Service;c:\program files\motorola\motoconnectservice\MotoConnectService.exe [2011-5-23 91456]
R2 WDDMService;WDDMService;c:\program files\western digital\wd smartware\WDDMService.exe [2011-8-1 263056]
R2 WDFMEService;WDFMEService;c:\program files\western digital\wd smartware\WDFME.exe [2011-8-1 1592208]
R2 WDRulesService;WDRulesService;c:\program files\western digital\wd smartware\WDRulesEngine.exe [2011-8-1 1091984]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-7-5 133104]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\BW2NDIS5.SYS [2004-11-1 17536]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-7-5 133104]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2011-5-23 9472]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\pc tools security\pctsAuxs.exe [2011-11-2 366840]
S3 sdCoreService;PC Tools Security Service;c:\program files\pc tools security\pctsSvc.exe [2011-11-2 1150936]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2011-11-17 11520]
.
=============== Created Last 30 ================
.
2011-12-10 23:02:39 ——– d—–w- C:\TDSSKiller_Quarantine
2011-12-10 02:36:09 ——– d—–w- c:\program files\CCleaner
2011-12-09 04:34:01 ——– d—–w- c:\documents and settings\steve\local settings\application data\MPlayer
2011-12-09 04:33:31 ——– d—–w- c:\documents and settings\all users\PMS
2011-12-04 22:02:49 ——– d—–w- c:\documents and settings\steve\application data\Tuvofa
2011-12-04 22:02:49 ——– d—–w- c:\documents and settings\steve\application data\Cici
2011-11-28 06:47:38 ——– d—–w- c:\windows\system32\wbem\repository\FS
2011-11-28 06:47:38 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-18 23:26:07 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2011-11-18 23:25:03 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2011-11-18 23:24:06 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-11-18 23:21:45 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-11-18 23:21:31 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-11-18 23:16:01 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
2011-11-18 23:15:44 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2011-11-18 03:38:03 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys
2011-11-18 02:24:06 ——– d—–w- c:\windows\system32\scripting
2011-11-18 02:24:05 ——– d—–w- c:\windows\l2schemas
2011-11-18 02:24:04 ——– d—–w- c:\windows\system32\en
2011-11-18 02:24:04 ——– d—–w- c:\windows\system32\bits
2011-11-18 02:05:46 ——– d—–w- c:\windows\EHome
2011-11-17 23:15:21 ——– d—–w- c:\documents and settings\steve\local settings\application data\Western_Digital
2011-11-17 21:40:11 ——– d—–w- c:\documents and settings\all users\application data\Western Digital
2011-11-17 21:39:11 ——– d—–w- c:\program files\Western Digital
2011-11-17 21:37:59 ——– d—–w- c:\windows\system32\XPSViewer
2011-11-17 21:37:28 89088 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-11-17 21:37:07 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-11-17 21:37:07 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-11-17 21:37:07 597504 ——w- c:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-11-17 21:37:07 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-11-17 21:37:07 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-11-17 21:37:07 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2011-11-17 21:37:07 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-11-17 21:37:07 117760 ——w- c:\windows\system32\prntvpt.dll
2011-11-17 21:35:05 ——– d—–w- c:\program files\MSXML 6.0
2011-11-17 21:33:16 ——– d—–w- c:\documents and settings\steve\local settings\application data\Western Digital
.
==================== Find3M ====================
.
2011-10-13 15:57:02 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 09:06:03 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 06:37:52 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 0:22:25.18 ===============


security check:
``````````End of Log````````````
That's ok. The log isn't looking very good at this moment. Please stick with me until you're all clear.

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
===================================================

Please do the following:

I'd like to get a dump of the MBR outside of the Windows environment.

You will need a CD

Download GETxPUD.exe to the desktop of your clean computer
  • Run GETxPUD.exe
  • A new folder will appear on the desktop.
  • Open the GETxPUD folder and click on the get&burn.bat
  • The program will download xpud_0.9.2.iso, and when finished, it will open BurnCDCC which will be ready to burn the image.
  • Click on Start and follow the prompts to burn the image to a CD.


NEXT

  • Boot the infected computer with the CD you just burned
  • The computer must be set to boot from the CD
  • Follow the prompts
  • A Welcome to xPUD screen will appear
  • Click on File
  • Expand mnt
  • sda1 or sda2 will usually correspond to your HDD
  • expand the folder that corresponds to your harddrive.
  • Press Tool on the top menu bar
  • Choose Open Terminal
  • Type dd if=/dev/sda of=mbr.bin bs=512 count=1

This will place a back-up of your MBR on your harddrive it will be called C:/mbr.bin


Now exit > Home > reboot (remove the CD so your computer will boot normally)

Please attach a copy of c:\mbr.bin in your next reply (you may need to zip it up to attach it)
thanks here you go, xpud program ran fine but i cannot find the mbr.bin file on my hard drive. ran search for it also. MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000001c Kernel Drivers (total 145): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x80700000 \WINDOWS\system32\hal.dll 0xF7B21000 \WINDOWS\system32\KDCOM.DLL 0xF7A31000 \WINDOWS\system32\BOOTVID.dll 0xF75D2000 ACPI.sys 0xF7B23000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF75C1000 pci.sys 0xF7621000 isapnp.sys 0xF7BE9000 pciide.sys 0xF78A1000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7B25000 intelide.sys 0xF7631000 MountMgr.sys 0xF75A2000 ftdisk.sys 0xF78A9000 PartMgr.sys 0xF7641000 VolSnap.sys 0xF758A000 atapi.sys 0xF78B1000 cercsr6.sys 0xF7572000 \WINDOWS\System32\Drivers\SCSIPORT.SYS 0xF7651000 disk.sys 0xF7661000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7552000 fltmgr.sys 0xF7540000 sr.sys 0xF7503000 PCTCore.sys 0xF74AC000 pctDS.sys 0xF78B9000 PxHelp20.sys 0xF7497000 drvmcdb.sys 0xF7480000 KSecDD.sys 0xF746D000 WudfPf.sys 0xF73E0000 Ntfs.sys 0xF73B3000 NDIS.sys 0xF7399000 Mup.sys 0xF7671000 agp440.sys 0xF7871000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF69EC000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xF69D8000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF79B9000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF69B4000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF79C1000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF7881000 \SystemRoot\system32\DRIVERS\IntelC53.sys 0xF6991000 \SystemRoot\system32\DRIVERS\ks.sys 0xF686A000 \SystemRoot\system32\DRIVERS\IntelC51.sys 0xF67D5000 \SystemRoot\system32\DRIVERS\IntelC52.sys 0xF79C9000 \SystemRoot\system32\DRIVERS\mohfilt.sys 0xF79D1000 \SystemRoot\System32\Drivers\Modem.SYS 0xF67AD000 \SystemRoot\system32\DRIVERS\e100b325.sys 0xF79D9000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF7891000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF79E1000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF7691000 \SystemRoot\system32\DRIVERS\serial.sys 0xF7B01000 \SystemRoot\system32\DRIVERS\serenum.sys 0xF6799000 \SystemRoot\system32\DRIVERS\parport.sys 0xF76A1000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF6781000 \SystemRoot\System32\Drivers\AnyDVD.sys 0xF7B3D000 \SystemRoot\system32\drivers\sscdbhk5.sys 0xF76B1000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF76C1000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF79E9000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF66F3000 \SystemRoot\system32\drivers\smwdm.sys 0xF66CF000 \SystemRoot\system32\drivers\portcls.sys 0xF76D1000 \SystemRoot\system32\drivers\drmk.sys 0xF7B3F000 \SystemRoot\system32\drivers\aeaudio.sys 0xF7C1F000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF76E1000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7B0D000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF66B8000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF76F1000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF7701000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF79F1000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF66A7000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7711000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF79F9000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7A01000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF7721000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7A09000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7B41000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF661A000 \SystemRoot\system32\DRIVERS\update.sys 0xF7B1D000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7731000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF7741000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7B4F000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF6DC0000 \SystemRoot\system32\drivers\MODEMCSA.sys 0xF7B51000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C24000 \SystemRoot\System32\Drivers\Null.SYS 0xF7B53000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7A21000 \SystemRoot\system32\drivers\ssrtln.sys 0xF7A29000 \SystemRoot\System32\drivers\vga.sys 0xF7B55000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7B57000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF78C9000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78E1000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7AD5000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xF53F7000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xF539E000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF5378000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF7761000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF78E9000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xF533A000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF7AE9000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xF7929000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xF7AED000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xF5318000 \SystemRoot\System32\drivers\afd.sys 0xF7811000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF52ED000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF7AF5000 \SystemRoot\SYSTEM32\DRIVERS\OMCI.SYS 0xF5255000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF7AF9000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF7831000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF7939000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF7841000 \SystemRoot\System32\Drivers\Fips.SYS 0xF7941000 \SystemRoot\System32\Drivers\ElbyCDIO.sys 0xF660A000 \SystemRoot\System32\Drivers\LHidUsbK.Sys 0xF78F9000 \SystemRoot\system32\DRIVERS\LHidKE.Sys 0xF6552000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xF5244000 \SystemRoot\system32\DRIVERS\LMouKE.Sys 0xF65FA000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF5204000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B29000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF6562000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7969000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C0E000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xBF464000 \SystemRoot\System32\ATMFD.DLL 0xF51D4000 \SystemRoot\system32\drivers\drvnddm.sys 0xF7CCB000 \SystemRoot\system32\dla\tfsndres.sys 0xBA4D3000 \SystemRoot\system32\dla\tfsnifs.sys 0xBA514000 \SystemRoot\system32\dla\tfsnopio.sys 0xF7BAD000 \SystemRoot\system32\dla\tfsnpool.sys 0xF7921000 \SystemRoot\system32\dla\tfsnboio.sys 0xF51C4000 \SystemRoot\system32\dla\tfsncofs.sys 0xF7CD2000 \SystemRoot\system32\dla\tfsndrct.sys 0xBA493000 \SystemRoot\system32\dla\tfsnudf.sys 0xBA47A000 \SystemRoot\system32\dla\tfsnudfa.sys 0xBA442000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xB98A5000 \SystemRoot\system32\drivers\wdmaud.sys 0xB9A72000 \SystemRoot\system32\drivers\sysaudio.sys 0xB95CA000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xF7B79000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xF7B6D000 \SystemRoot\system32\DRIVERS\dsunidrv.sys 0xB8901000 \SystemRoot\System32\Drivers\HTTP.sys 0xB87B9000 \SystemRoot\system32\DRIVERS\srv.sys 0xB79F4000 \SystemRoot\system32\drivers\NPF.sys 0xB6A43000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 53): 0 System Idle Process 4 System 608 C:\WINDOWS\system32\smss.exe 684 csrss.exe 712 C:\WINDOWS\system32\winlogon.exe 756 C:\WINDOWS\system32\services.exe 768 C:\WINDOWS\system32\lsass.exe 964 C:\WINDOWS\system32\svchost.exe 1032 svchost.exe 1144 C:\WINDOWS\system32\svchost.exe 1200 C:\WINDOWS\system32\svchost.exe 1320 svchost.exe 1400 svchost.exe 1468 C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe 1760 C:\WINDOWS\explorer.exe 1852 C:\WINDOWS\system32\spoolsv.exe 552 C:\WINDOWS\system32\dla\tfswctrl.exe 600 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe 668 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe 820 C:\Program Files\EarthLink TotalAccess\FastLane2\ipmon32.exe 1132 svchost.exe 1312 C:\Program Files\EarthLink TotalAccess\FastLane2\IPClient.exe 1364 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 2028 C:\WINDOWS\system32\rundll32.exe 196 C:\Program Files\QuickTime\QTTask.exe 212 C:\Program Files\Common Files\Java\Java Update\jusched.exe 1632 C:\Program Files\iTunes\iTunesHelper.exe 272 C:\WINDOWS\Temp\_ex-68.exe 344 C:\Program Files\Messenger\msmsgs.exe 352 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 360 C:\WINDOWS\system32\ctfmon.exe 444 C:\Program Files\Windows Media Player\wmpnscfg.exe 412 C:\Program Files\EarthLink TotalAccess\TaskPanl.exe 428 C:\Program Files\Logitech\SetPoint\SetPoint.exe 1584 C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe 2088 C:\Program Files\Bonjour\mDNSResponder.exe 2160 C:\Program Files\EarthLink TotalAccess\WENGINE\wmonitor.exe 2964 C:\WINDOWS\system32\svchost.exe 3332 C:\Program Files\Java\jre6\bin\jqs.exe 3496 C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE 3628 C:\Program Files\Motorola\MotoConnectService\MotoConnectService.exe 3688 C:\WINDOWS\system32\nvsvc32.exe 3728 C:\WINDOWS\system32\svchost.exe 3888 C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe 464 C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe 2000 C:\Program Files\Motorola\MotoConnectService\MotoConnect.exe 2676 wmpnetwk.exe 2840 C:\Program Files\Western Digital\WD SmartWare\WDFME.exe 3840 C:\WINDOWS\system32\dlcccoms.exe 1588 C:\Program Files\iPod\bin\iPodService.exe 1724 alg.exe 2124 C:\Program Files\Internet Explorer\iexplore.exe 1736 C:\Documents and Settings\steve\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: WDCWD1600JS-00MHB1, Rev: 10.02E02 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644A Done!
That's odd. Let's see if we can find it.

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    MBR.*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
here you go, also every since i ran the last program ,i have been getting corrupt file error messages on start up, telling me to run chk disk ultility. the last one said "tfswctrl.exe-corrupt file." SystemLook 30.07.11 by jpshortstuff Log created at 23:34 on 15/12/2011 by steve Administrator - Elevation successful ========== filefind ========== Searching for "MBR.*" C:\WINDOWS\Prefetch\MBR.DAT-105CC322.pf –a—- 6776 bytes [05:22 14/12/2011] [05:22 14/12/2011] 7CC8943742E056FD0342B5F24222F4FE C:\WINDOWS\Prefetch\MBR.DAT-16F01966.pf –a—- 7758 bytes [05:16 14/12/2011] [05:16 14/12/2011] 81A74FB9105C5AC3B0190D26FC81D0B0 -= EOF =-
Ok thanks. Is it MBRCheck?

Using FireFox, please download and save dumpit to your usb device.

You may want to print out this part as you will not be able to view these instructions.

  • Leave the usb device attached to the computer
  • Boot the infected computer with the CD you just burned
    • with the CD in the computer, restart the computer
  • The computer must be set to boot from the CD,depending on your computer you can either do this by pressing F12 and selecting the CD as the first boot option or it can be set in the BIOS
  • Once you have the computer set to boot from the CD allow it to boot
  • A Welcome to xPUD screen will appear
  • Click on File
  • Expand mnt
  • sda1,2…usually corresponds to your HDD
  • sdb1 is likely your USB
  • Click on the folder that represents your USB drive (sdb1 ?)
    (you will be able to tell if it the right one as the screen will populate with your files)
  • Locate the file you downloaded and saved earlier, dumpit
  • double click it to run it
  • a black window will open, follow the instructions to close the window when it's finished
  • a file called MBR.zip should now be placed in the right hand panel
  • Click the Home icon at top
  • Remove the CD and click Power off
  • Click restart

Once the computer has rebooted open the usb device and attach the MBR.zip file to your next reply.
conspire, question. i have a WD passport essential external hard drive. i downloaded dumpit to it. but, when i boot xpud, it only shows sda1 that cooresponds to my internal hard drive. do i need to get a memory stick? or some other type of usb device?
Great. Thanks. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================

Disable your AntiVirus and AntiSpyware applications as they will interfere with our tools and the removal. If you are unsure how to do this, please refer to our sticky topic How to disable your security applications

====================================================


Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
ComboFix 11-12-16.03 - steve 12/17/2011 13:49:50.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.480 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Spyware Doctor with AntiVirus *Disabled/Updated* {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\steve\Application Data\Xeha
c:\documents and settings\steve\Application Data\Xeha\cata.exe
c:\documents and settings\steve\Start Menu\Programs\System Restore
c:\documents and settings\steve\Start Menu\Programs\System Restore\System Restore.lnk
c:\documents and settings\steve\Start Menu\Programs\System Restore\Uninstall System Restore.lnk
c:\documents and settings\steve\WINDOWS
c:\windows\$NtUninstallKB59474$\3624994403
c:\windows\$NtUninstallKB59474$\4068743894\@
c:\windows\$NtUninstallKB59474$\4068743894\bckfg.tmp
c:\windows\$NtUninstallKB59474$\4068743894\cfg.ini
c:\windows\$NtUninstallKB59474$\4068743894\Desktop.ini
c:\windows\$NtUninstallKB59474$\4068743894\keywords
c:\windows\$NtUninstallKB59474$\4068743894\kwrd.dll
c:\windows\$NtUninstallKB59474$\4068743894\L\xapwuzsr
c:\windows\$NtUninstallKB59474$\4068743894\lsflt7.ver
c:\windows\$NtUninstallKB59474$\4068743894\U\00000001.@
c:\windows\$NtUninstallKB59474$\4068743894\U\00000002.@
c:\windows\$NtUninstallKB59474$\4068743894\U\00000004.@
c:\windows\$NtUninstallKB59474$\4068743894\U\80000000.@
c:\windows\$NtUninstallKB59474$\4068743894\U\80000004.@
c:\windows\$NtUninstallKB59474$\4068743894\U\80000032.@
c:\windows\$NtUninstallKB6061$
c:\windows\$NtUninstallKB6061$\2101877131
c:\windows\$NtUninstallKB6061$\4068743894\{1B372133-BFFA-4dba-9CCF-5474BED6A9F6}
c:\windows\$NtUninstallKB6061$\4068743894\L\xapwuzsr
c:\windows\system32\Packet.dll
c:\windows\system32\wpcap.dll
c:\windows\Temp\_ex-68.exe
c:\windows\$NtUninstallKB59474$ . . . . Failed to delete
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_NPF
——-\Service_NPF
.
.
((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 )))))))))))))))))))))))))))))))
.
.
2011-12-17 16:20 . 2008-04-13 18:36 187776 -c–a-w- c:\windows\system32\dllcache\acpi.sys
2011-12-17 16:20 . 2008-04-13 18:36 187776 —-a-w- c:\windows\system32\drivers\acpi.sys
2011-12-17 15:47 . 2011-12-17 15:47 ——– d—–w- c:\documents and settings\Administrator.STEVEN-D12C98C6\Local Settings\Application Data\Western Digital
2011-12-17 03:29 . 2011-12-17 03:29 ——– d—–w- c:\documents and settings\steve\Local Settings\Application Data\WinZip
2011-12-17 03:29 . 2011-12-17 03:29 ——– d—–w- c:\program files\Conduit
2011-12-17 03:29 . 2011-12-17 03:29 ——– d—–w- c:\documents and settings\steve\Local Settings\Application Data\Conduit
2011-12-17 03:28 . 2011-12-17 03:29 ——– d—–w- c:\documents and settings\All Users\Application Data\WinZip
2011-12-17 03:21 . 2011-12-16 21:53 512 —-a-w- C:\Copy of mbr.bin
2011-12-15 16:36 . 2011-12-16 06:07 ——– d—–w- c:\documents and settings\steve\Application Data\Erdyo
2011-12-15 16:26 . 2011-12-15 16:26 50704 —-a-w- c:\windows\system32\drivers\npf.sys
2011-12-10 23:02 . 2011-12-11 06:53 ——– d—–w- C:\TDSSKiller_Quarantine
2011-12-10 02:36 . 2011-12-10 02:36 ——– d—–w- c:\program files\CCleaner
2011-12-09 04:34 . 2011-12-09 04:34 ——– d—–w- c:\documents and settings\steve\Local Settings\Application Data\MPlayer
2011-12-09 04:33 . 2011-12-09 04:34 ——– d—–w- c:\documents and settings\All Users\PMS
2011-12-04 22:02 . 2011-12-05 04:23 ——– d—–w- c:\documents and settings\steve\Application Data\Tuvofa
2011-12-04 22:02 . 2011-12-05 04:09 ——– d—–w- c:\documents and settings\steve\Application Data\Cici
2011-11-28 06:47 . 2011-11-28 06:47 ——– d—–w- c:\windows\system32\wbem\Repository
2011-11-28 04:58 . 2011-11-28 04:58 ——– d—–w- c:\documents and settings\Administrator.STEVEN-D12C98C6\Application Data\Malwarebytes
2011-11-18 23:26 . 2010-09-18 06:53 953856 -c—-w- c:\windows\system32\dllcache\mfc40u.dll
2011-11-18 23:25 . 2010-08-23 16:12 617472 -c—-w- c:\windows\system32\dllcache\comctl32.dll
2011-11-18 23:24 . 2010-11-02 15:17 40960 -c—-w- c:\windows\system32\dllcache\ndproxy.sys
2011-11-18 23:21 . 2011-06-24 14:10 139656 -c—-w- c:\windows\system32\dllcache\rdpwd.sys
2011-11-18 23:21 . 2011-04-21 13:37 105472 -c—-w- c:\windows\system32\dllcache\mup.sys
2011-11-18 23:16 . 2011-07-08 14:02 10496 -c—-w- c:\windows\system32\dllcache\ndistapi.sys
2011-11-18 23:15 . 2010-10-11 14:59 45568 -c—-w- c:\windows\system32\dllcache\wab.exe
2011-11-18 03:38 . 2011-11-18 03:38 ——– d—–w- c:\documents and settings\Default User\Local Settings\Application Data\Western Digital
2011-11-18 03:38 . 2011-02-16 22:52 11520 —-a-w- c:\windows\system32\drivers\wdcsam.sys
2011-11-18 02:24 . 2011-11-18 02:24 ——– d—–w- c:\windows\system32\scripting
2011-11-18 02:24 . 2011-11-18 02:24 ——– d—–w- c:\windows\l2schemas
2011-11-18 02:24 . 2011-11-18 02:24 ——– d—–w- c:\windows\system32\en
2011-11-18 02:24 . 2011-11-18 02:24 ——– d—–w- c:\windows\system32\bits
2011-11-18 02:05 . 2011-11-18 02:05 ——– d—–w- c:\windows\EHome
2011-11-17 23:15 . 2011-11-18 03:42 ——– d—–w- c:\documents and settings\steve\Local Settings\Application Data\Western_Digital
2011-11-17 21:40 . 2011-11-18 03:38 ——– d—–w- c:\documents and settings\All Users\Application Data\Western Digital
2011-11-17 21:39 . 2011-11-18 03:37 ——– d—–w- c:\program files\Western Digital
2011-11-17 21:37 . 2011-11-17 21:37 ——– d—–w- c:\windows\system32\XPSViewer
2011-11-17 21:37 . 2011-11-17 21:37 ——– d—–w- c:\program files\MSBuild
2011-11-17 21:37 . 2011-11-17 21:37 ——– d—–w- c:\program files\Reference Assemblies
2011-11-17 21:37 . 2008-07-06 12:06 89088 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\filterpipelineprintproc.dll
2011-11-17 21:37 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2011-11-17 21:37 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2011-11-17 21:37 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2011-11-17 21:37 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2011-11-17 21:37 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2011-11-17 21:37 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2011-11-17 21:37 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2011-11-17 21:37 . 2008-07-06 10:50 597504 ——w- c:\windows\system32\Spool\prtprocs\w32x86\printfilterpipelinesvc.exe
2011-11-17 21:35 . 2011-11-17 21:35 ——– d—–w- c:\program files\MSXML 6.0
2011-11-17 21:33 . 2011-11-17 21:33 ——– d—–w- c:\documents and settings\steve\Local Settings\Application Data\Western Digital
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-17 03:32 . 2011-12-17 03:32 499 —-a-w- C:\mbr.zip
2011-11-03 00:23 . 2011-11-03 00:23 22 —-a-w- C:\New Compressed (zipped) Folder.zip
2011-10-13 15:57 . 2011-05-13 22:22 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2007-05-05 04:43 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-03 09:06 . 2010-06-26 22:55 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-10-03 06:37 . 2007-05-10 01:51 73728 —-a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2004-08-04 10:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 16:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 16:41 . 2004-08-04 10:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 16:41 . 2004-08-04 10:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-11-10 05:10 . 2011-08-24 22:19 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files\WinZipBar\prxtbWinZ.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
2011-05-09 08:49 176936 —-a-w- c:\program files\WinZipBar\prxtbWinZ.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}"= "c:\program files\WinZipBar\prxtbWinZ.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{50FAFAF0-70A9-419D-A109-FA4B4FFD4E37}"= "c:\program files\WinZipBar\prxtbWinZ.dll" [2011-05-09 176936]
.
[HKEY_CLASSES_ROOT\clsid\{50fafaf0-70a9-419d-a109-fa4b4ffd4e37}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-16 68856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]
"E6TaskPanel"="c:\program files\EarthLink TotalAccess\TaskPanl.exe" [2005-09-01 942080]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 28160]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"IPInSightMonitor 01"="c:\program files\EarthLink TotalAccess\FastLane2\IPMon32.exe" [2005-08-11 122880]
"IPInSightLAN 01"="c:\program files\EarthLink TotalAccess\FastLane2\IPClient.exe" [2005-08-11 380928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-22 7700480]
"nwiz"="nwiz.exe" [2006-10-22 1622016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-10-22 86016]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-04-14 421160]
.
c:\documents and settings\Administrator.STEVEN-D12C98C6\Start Menu\Programs\Startup\
zyuk.exe [2011-12-15 194560]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
leyciz.exe [2011-12-15 194560]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2007-5-5 450560]
WD Quick View.lnk - c:\program files\Western Digital\WD SmartWare\WDDMStatus.exe [2011-8-1 3983760]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK32.EXE [2011-11-17 611144]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\steve\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
"21950:TCP"= 21950:TCP:*:Disabled:lime2
"29283:UDP"= 29283:UDP:UDP 29283
"17335:TCP"= 17335:TCP:TCP 17335
.
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [11/2/2011 9:38 PM 239168]
R0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [11/2/2011 9:38 PM 338880]
R2 EarthLinkMonitor;EarthLink Monitor Service;c:\program files\EarthLink TotalAccess\WENGINE\wmonitor.exe [1/26/2005 10:47 AM 65604]
R2 MotoConnect Service;MotoConnect Service;c:\program files\Motorola\MotoConnectService\MotoConnectService.exe [5/23/2011 7:51 PM 91456]
R2 WDDMService;WDDMService;c:\program files\Western Digital\WD SmartWare\WDDMService.exe [8/1/2011 10:11 AM 263056]
R2 WDFMEService;WDFMEService;c:\program files\Western Digital\WD SmartWare\WDFME.exe [8/1/2011 10:11 AM 1592208]
R2 WDRulesService;WDRulesService;c:\program files\Western Digital\WD SmartWare\WDRulesEngine.exe [8/1/2011 10:11 AM 1091984]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/5/2009 3:52 PM 133104]
S3 BW2NDIS5;BW2NDIS5;c:\windows\system32\drivers\BW2NDIS5.SYS [11/1/2004 1:16 PM 17536]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/5/2009 3:52 PM 133104]
S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [5/23/2011 7:50 PM 9472]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [11/2/2011 9:38 PM 366840]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [11/17/2011 10:38 PM 11520]
.
Contents of the 'Scheduled Tasks' folder
.
2011-11-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-05 20:52]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-07-05 20:52]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1682526488-682003330-1004Core.job
- c:\documents and settings\steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-27 04:09]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1715567821-1682526488-682003330-1004UA.job
- c:\documents and settings\steve\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-08-27 04:09]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://start.earthlink.net
uDefault_Search_URL = hxxp://www.earthlink.net/partner/more/msie/button/search.html
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid;=ie7&rls;=com.microsoft:en-US&ie;=utf8&oe;=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: EarthLink Google Search - c:\program files\EarthLink TotalAccess\Toolbar\SearchUI.dll/search.html
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\documents and settings\steve\Application Data\Mozilla\Firefox\Profiles\4nwpzili.default\
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 1050
FF - prefs.js: network.proxy.type - 4
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
Toolbar-SITEguard - (no file)
HKCU-Run-Sonic RecordNow! - (no file)
HKCU-Run-{5CE70930-AFF2-AD7B-B5DA-0704A4A62416} - c:\documents and settings\steve\Application Data\Xeha\cata.exe
HKLM-Run-DLCCCATS - \3\DLCCtime.dll
AddRemove-WebCyberCoach_wtrb - c:\program files\WebCyberCoach\b_Dell\WCC_Wipe.exe WebCyberCoach ext\wtrb
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-17 14:11
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCCCATS = rundll32 \3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
.
c:\windows\3592062194:226223401.exe 816 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1715567821-1682526488-682003330-1004\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'lsass.exe'(748)
c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
.
- - - - - - - > 'explorer.exe'(1784)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\Motorola\MotoConnectService\MotoConnect.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\dlcccoms.exe
c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-12-17 14:17:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-17 19:17
.
Pre-Run: 75,497,177,088 bytes free
Post-Run: 79,096,979,456 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 17C133D0F688EAE4190EC6A14D713174
Let's see how this goes.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

File::
c:\documents and settings\Administrator.STEVEN-D12C98C6\Start Menu\Programs\Startup\zyuk.exe
c:\documents and settings\Default User\Start Menu\Programs\Startup\leyciz.exe

Firefox::
FF - ProfilePath - c:\documents and settings\steve\Application Data\Mozilla\Firefox\Profiles\4nwpzili.default\
FF - prefs.js: network.proxy.http -
FF - prefs.js: network.proxy.http_port -
FF - prefs.js: network.proxy.type -

DirLook::
c:\windows\system32\scripting
c:\windows\l2schemas
c:\windows\system32\en
c:\windows\system32\bits

Rootkit::
c:\windows\3592062194:226223401.exe


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI