This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe Virus [Closed]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

So I seem to have contracted the problem most other are these days. Tried to read through some of the other similar threads but its all foreign to me. Not sure which programs I need or what scans to run. Help would be greatly appreciated. Not at all familiar with any of the programs so I will probably need detailed instructions/lots of questions answered.
:welcome:

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]





Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
Thanks for the reply Ken.

The first scan produced this:

aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software
Run date: 2011-12-16 01:49:12
—————————–
01:49:12.140 OS Version: Windows 5.1.2600 Service Pack 3
01:49:12.140 Number of processors: 2 586 0x604
01:49:12.140 ComputerName: TEST UserName: joe
01:49:15.109 Initialize success
01:49:27.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12
01:49:27.156 Disk 0 Vendor: WDC_WD400JD-22LSA0 06.01D06 Size: 38166MB BusType: 3
01:49:29.171 Disk 0 MBR read successfully
01:49:29.171 Disk 0 MBR scan
01:49:29.187 Disk 0 Windows XP default MBR code
01:49:29.187 Disk 0 scanning sectors +78140160
01:49:29.250 Disk 0 scanning C:\WINDOWS\system32\drivers
01:49:41.984 Service scanning
01:49:43.343 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32
01:49:43.937 Modules scanning
01:49:50.718 Module: C:\WINDOWS\System32\DRIVERS\serial.sys **SUSPICIOUS**
01:50:00.187 Disk 0 trace - called modules:
01:50:00.218 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86a5cf10]<<
01:50:00.218 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86c7fab8]
01:50:00.312 3 CLASSPNP.SYS[f761dfd7] -> nt!IofCallDriver -> [0x86a1c760]
01:50:00.312 \Driver\00000854[0x86ab4b18] -> IRP_MJ_CREATE -> 0x86a5cf10
01:50:00.312 Scan finished successfully
01:50:56.500 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\joe\Desktop\MBR.dat"
01:50:56.500 The log file has been saved successfully to "C:\Documents and Settings\joe\Desktop\scan log.txt"
Had to attach both of the DDS reports because the length of the post was stopping me from being able to put them on the boards. The 'test' post above was an experiment and can be deleted. . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_24 Run by [removed] at 2:18:37 on 2011-12-16 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.344 [GMT -5:00] . FW: AVG Firewall *Enabled* . ============== Running Processes =============== . C:\PROGRA~1\AVG\AVG2012\avgrsx.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\acs.exe svchost.exe C:\Program Files\AVG\AVG2012\avgfws.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVG\AVG2012\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\System32\WLTRAY.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe C:\Program Files\AVG\AVG2012\avgtray.exe C:\WINDOWS\System32\wltrysvc.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\System32\bcmwltry.exe C:\Program Files\AVG\AVG2012\avgnsx.exe C:\Program Files\AVG\AVG2012\avgemcx.exe C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\AVG\AVG2012\avgcsrvx.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\winmine.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\AVG\AVG2012\avgui.exe C:\WINDOWS\System32\ping.exe . ============== Pseudo HJT Report =============== . BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg2012\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [Google Update] "c:\documents and settings\joe\local settings\application data\google\update\GoogleUpdate.exe" /c mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [TWCU] "c:\program files\tp-link\tp-link wireless client utility\TWCU.exe" -nogui mRun: [AVG_TRAY] "c:\program files\avg\avg2012\avgtray.exe" mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x08b2 -f video -m logitech -d 10.5.1.2023 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll LSP: mswsock.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - hxxp://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259556635639 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{180D8A17-BB50-46D4-B0D6-EED456C8C6C2} : DhcpNameServer = [removed] [removed] Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg2012\avgpp.dll Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Notify: igfxcui - igfxdev.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\joe\application data\mozilla\firefox\profiles\5ma6jye9.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.ituroncavalry.com/ FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff4.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff5.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff6.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff7.dll FF - component: c:\program files\avg\avg2012\firefox4\components\avgssff8.dll FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\documents and settings\joe\local settings\application data\google\update\1.3.21.79\npGoogleUpdate3.dll FF - plugin: c:\documents and settings\joe\local settings\application data\unity\webplayer\loader\npUnity3D32.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF - Ext: Java Quick Starter: [removed] - c:\program files\java\jre6\lib\deploy\jqs\ff FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\avg\avg2012\Firefox4 FF - Ext: ChatZilla: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2} - %profile%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} . ============= SERVICES / DRIVERS =============== . R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-7-11 23120] R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-9-13 32592] R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-10-7 230608] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-8-8 40016] R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-7-11 295248] R2 avgfws;AVG Firewall;c:\program files\avg\avg2012\avgfws.exe [2011-11-23 2391832] R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg2012\AVGIDSAgent.exe [2011-10-12 4433248] R2 avgwd;AVG WatchDog;c:\program files\avg\avg2012\avgwdsvc.exe [2011-8-2 192776] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-12-14 366152] R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [2011-8-15 1714176] R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2011-5-23 30944] R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-7-11 134608] R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-7-11 24272] R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-10-4 16720] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-14 22216] S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2011-5-23 30944] S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?] S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service –> c:\windows\system32\GameMon.des -service [?] . =============== Created Last 30 ================ . 2011-12-16 07:10:52 ——– d—–w- c:\documents and settings\joe\local settings\application data\Google 2011-12-15 04:50:15 ——– d—–w- c:\documents and settings\joe\application data\Malwarebytes 2011-12-15 04:49:20 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-12-15 04:48:55 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-15 04:48:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-12-14 20:54:55 ——– d—–w- c:\documents and settings\joe\application data\AVG2012 2011-12-14 20:51:41 ——– d—–w- c:\windows\system32\drivers\AVG 2011-12-14 20:51:40 ——– d—–w- c:\documents and settings\all users\application data\AVG2012 2011-12-14 19:47:59 ——– d—–w- c:\documents and settings\all users\application data\MFAData 2011-12-14 19:26:11 ——– d—–w- c:\windows\system32\LogFiles 2011-12-05 18:07:01 ——– d—–w- c:\program files\The Creative Assembly . ==================== Find3M ==================== . 2011-10-13 07:33:44 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-10-10 14:22:41 692736 —-a-w- c:\windows\system32\inetcomm.dll 2011-10-07 11:23:48 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2011-10-04 11:21:42 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys 2011-09-28 07:06:50 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll . ============= FINISH: 2:19:13.43 ===============

Attachments:

Good Morning,

Looks like your infected with the Zero Access Rootkit This is fairly new and sometimes a bugger to remove. But lets give it a shot

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 11-12-18.01 - joe 12/18/2011 17:04:32.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.578 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
FW: AVG Firewall *Enabled* {8decf618-9569-4340-b34a-d78d28969b66}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfapx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgmfarx.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgntdumpx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avgrunasx.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\avi7.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\compat.ini
c:\documents and settings\All Users\Application Data\TEMP\AVG\htmlayout.dll
c:\documents and settings\All Users\Application Data\TEMP\AVG\incavi.avm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_cz.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_da.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_es.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_fr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ge.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_hu.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_id.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_in.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_it.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_jp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ko.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ms.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_nl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pb.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pl.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_pt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_ru.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sc.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sk.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_sp.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_tr.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_us.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zh.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\license_zt.htm
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaconf.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfada.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaes.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfafr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfage.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfahu.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaid.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfain.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfait.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfajp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfako.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfams.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfanl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapb.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapl.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfapt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaru.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasc.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfask.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfasp.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfatr.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaus.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfavera.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfaverx.txt
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazh.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\mfazt.lns
c:\documents and settings\All Users\Application Data\TEMP\AVG\microavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\miniavi.avg
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.exe
c:\documents and settings\All Users\Application Data\TEMP\AVG\setup.ini
c:\documents and settings\joe\Application Data\Bitcoin
c:\documents and settings\joe\Application Data\Bitcoin\.lock
c:\documents and settings\joe\Application Data\Bitcoin\__db.001
c:\documents and settings\joe\Application Data\Bitcoin\__db.002
c:\documents and settings\joe\Application Data\Bitcoin\__db.003
c:\documents and settings\joe\Application Data\Bitcoin\__db.004
c:\documents and settings\joe\Application Data\Bitcoin\__db.005
c:\documents and settings\joe\Application Data\Bitcoin\__db.006
c:\documents and settings\joe\Application Data\Bitcoin\addr.dat
c:\documents and settings\joe\Application Data\Bitcoin\blk0001.dat
c:\documents and settings\joe\Application Data\Bitcoin\blkindex.dat
c:\documents and settings\joe\Application Data\Bitcoin\database\log.0000000038
c:\documents and settings\joe\Application Data\Bitcoin\db.log
c:\documents and settings\joe\Application Data\Bitcoin\debug.log
c:\documents and settings\joe\Application Data\Bitcoin\New Wordpad Document.doc
c:\documents and settings\joe\Application Data\Bitcoin\wallet.dat
c:\windows\$NtUninstallKB49042$\2322422960
c:\windows\$NtUninstallKB49042$\4175251279\@
c:\windows\$NtUninstallKB49042$\4175251279\bckfg.tmp
c:\windows\$NtUninstallKB49042$\4175251279\cfg.ini
c:\windows\$NtUninstallKB49042$\4175251279\Desktop.ini
c:\windows\$NtUninstallKB49042$\4175251279\keywords
c:\windows\$NtUninstallKB49042$\4175251279\kwrd.dll
c:\windows\$NtUninstallKB49042$\4175251279\L\akygdmgo
c:\windows\$NtUninstallKB49042$\4175251279\lsflt7.ver
c:\windows\$NtUninstallKB49042$\4175251279\U\00000001.@
c:\windows\$NtUninstallKB49042$\4175251279\U\00000002.@
c:\windows\$NtUninstallKB49042$\4175251279\U\00000004.@
c:\windows\$NtUninstallKB49042$\4175251279\U\80000000.@
c:\windows\$NtUninstallKB49042$\4175251279\U\80000004.@
c:\windows\$NtUninstallKB49042$\4175251279\U\80000032.@
c:\windows\system32\Temp
c:\windows\TEMP\MPENGINE.DLL
c:\windows\TEMP\offreg.dll
c:\windows\tsoc.log
c:\windows\$NtUninstallKB49042$ . . . . Failed to delete
.
.
((((((((((((((((((((((((( Files Created from 2011-11-18 to 2011-12-18 )))))))))))))))))))))))))))))))
.
.
2011-12-16 07:10 . 2011-12-16 08:16 ——– d—–w- c:\documents and settings\joe\Local Settings\Application Data\Google
2011-12-15 04:50 . 2011-12-15 04:50 ——– d—–w- c:\documents and settings\joe\Application Data\Malwarebytes
2011-12-15 04:49 . 2011-12-15 04:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-12-15 04:48 . 2011-08-31 22:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-12-15 04:48 . 2011-12-15 04:49 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-12-14 21:02 . 2011-12-14 21:02 ——– d-s—w- c:\documents and settings\NetworkService\UserData
2011-12-14 20:54 . 2011-12-14 20:54 ——– d—–w- c:\documents and settings\joe\Application Data\AVG2012
2011-12-14 20:51 . 2011-12-18 14:20 ——– d—–w- c:\windows\system32\drivers\AVG
2011-12-14 20:51 . 2011-12-15 04:58 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG2012
2011-12-14 19:47 . 2011-12-18 14:20 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData
2011-12-14 19:26 . 2011-12-14 19:26 ——– d—–w- c:\windows\system32\LogFiles
2011-12-05 18:07 . 2011-12-05 18:07 ——– d—–w- c:\program files\The Creative Assembly
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-23 13:25 . 2001-08-18 12:00 1859584 —-a-w- c:\windows\system32\win32k.sys
2011-11-01 20:35 . 2004-08-04 07:56 81920 ——w- c:\windows\system32\ieencode.dll
2011-11-01 20:35 . 2001-08-18 12:00 667136 —-a-w- c:\windows\system32\wininet.dll
2011-11-01 20:35 . 2001-08-18 12:00 61952 —-a-w- c:\windows\system32\tdc.ocx
2011-11-01 16:07 . 2001-08-18 12:00 1288704 —-a-w- c:\windows\system32\ole32.dll
2011-11-01 15:02 . 2004-08-04 05:59 369664 ——w- c:\windows\system32\html.iec
2011-10-28 05:31 . 2001-08-18 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37 . 2001-08-18 12:00 2148864 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52 . 2001-08-17 13:48 2027008 —-a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-18 11:13 . 2004-08-04 07:56 186880 ——w- c:\windows\system32\encdec.dll
2011-10-13 07:33 . 2011-08-15 18:11 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-10 14:22 . 2009-11-17 19:18 692736 —-a-w- c:\windows\system32\inetcomm.dll
2011-10-07 11:23 . 2011-10-07 11:23 230608 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2011-10-04 11:21 . 2011-10-04 11:21 16720 —-a-w- c:\windows\system32\drivers\AVGIDSShim.sys
2011-09-28 07:06 . 2002-09-23 20:10 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-30 00:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2001-08-18 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2001-08-18 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\System32\WLTRAY" [X]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"LogitechQuickCamRibbon"="c:\program files\Logitech\Logitech WebCam Software\LWS.exe" [2009-10-14 2793304]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
"TWCU"="c:\program files\TP-LINK\TP-LINK Wireless Client Utility\TWCU.exe" [2010-05-21 561263]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2011-12-03 2415456]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2009-10-07 460048]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56357:TCP"= 56357:TCP:Pando Media Booster
"56357:UDP"= 56357:UDP:Pando Media Booster
"8378:TCP"= 8378:TCP:League of Legends Launcher
"8378:UDP"= 8378:UDP:League of Legends Launcher
"8379:TCP"= 8379:TCP:League of Legends Launcher
"8379:UDP"= 8379:UDP:League of Legends Launcher
"8380:TCP"= 8380:TCP:League of Legends Launcher
"8380:UDP"= 8380:UDP:League of Legends Launcher
"6981:TCP"= 6981:TCP:League of Legends Launcher
"6981:UDP"= 6981:UDP:League of Legends Launcher
"6890:TCP"= 6890:TCP:League of Legends Launcher
"6890:UDP"= 6890:UDP:League of Legends Launcher
"8381:TCP"= 8381:TCP:League of Legends Launcher
"8381:UDP"= 8381:UDP:League of Legends Launcher
"58405:TCP"= 58405:TCP:Pando Media Booster
"58405:UDP"= 58405:UDP:Pando Media Booster
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 1:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 6:30 AM 32592]
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [12/5/2009 3:35 AM 691696]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 6:23 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 1:14 AM 295248]
R2 avgfws;AVG Firewall;c:\program files\AVG\AVG2012\avgfws.exe [11/23/2011 2:36 AM 2391832]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 6:25 AM 4433248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 6:09 AM 192776]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [12/14/2011 11:49 PM 366152]
R3 AR9271;Wireless Network Adapter Service;c:\windows\system32\drivers\athuw.sys [8/15/2011 11:06 AM 1714176]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [5/23/2011 1:03 AM 30944]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 1:14 AM 134608]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 1:14 AM 24272]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/4/2011 6:21 AM 16720]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [12/14/2011 11:48 PM 22216]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [5/23/2011 1:03 AM 30944]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service –> c:\windows\system32\GameMon.des -service [?]
.
.
——- Supplementary Scan ——-
.
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\joe\Application Data\Mozilla\Firefox\Profiles\5ma6jye9.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.ituroncavalry.com/
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: Java Quick Starter: [removed] - c:\program files\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: AVG Safe Search: {1E73965B-8B48-48be-9C8D-68B920ABC1C4} - c:\program files\AVG\AVG2012\Firefox4
FF - Ext: ChatZilla: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2} - %profile%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-62289540-dc30-11dc-95ff-0800200c9a66_is1 - c:\program files\Turbine\Turbine Download Manager\UninstallTDM.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-18 17:26
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(1380)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(5236)
c:\windows\TEMP\logishrd\LVPrcInj01.dll
.
———————— Other Running Processes ————————
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\acs.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\windows\System32\wltrysvc.exe
c:\windows\System32\bcmwltry.exe
c:\program files\AVG\AVG2012\avgnsx.exe
c:\program files\AVG\AVG2012\avgemcx.exe
c:\windows\System32\WLTRAY.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\Common Files\Logishrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Completion time: 2011-12-18 17:31:02 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-18 22:30
.
Pre-Run: 20,736,262,144 bytes free
Post-Run: 24,235,286,528 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn /usepmtimer
.
- - End Of File - - DDA36DCD665FCFA995E77764F5C6D31A
Hi,

Run aswMBR again and post a new log.



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 8392 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 12/18/2011 6:14:47 PM mbam-log-2011-12-18 (18-14-47).txt Scan type: Quick scan Objects scanned: 169244 Time elapsed: 7 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-12-18 19:17:20 —————————– 19:17:20.500 OS Version: Windows 5.1.2600 Service Pack 3 19:17:20.500 Number of processors: 2 586 0x604 19:17:20.500 ComputerName: TEST UserName: joe 19:17:22.281 Initialize success 19:25:08.156 AVAST engine defs: 11121801 19:36:05.937 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12 19:36:05.937 Disk 0 Vendor: WDC_WD400JD-22LSA0 06.01D06 Size: 38166MB BusType: 3 19:36:07.984 Disk 0 MBR read successfully 19:36:07.984 Disk 0 MBR scan 19:36:08.093 Disk 0 Windows XP default MBR code 19:36:08.093 Disk 0 scanning sectors +78140160 19:36:08.250 Disk 0 scanning C:\WINDOWS\system32\drivers 19:36:27.859 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Alureon-AOW [Rtk] 19:36:38.375 Service scanning 19:36:39.000 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32 19:36:39.593 Modules scanning 19:36:47.296 Disk 0 trace - called modules: 19:36:47.312 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spbw.sys >>UNKNOWN [0x86d88938]<< 19:36:47.375 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86cfdab8] 19:36:47.375 3 CLASSPNP.SYS[f761dfd7] -> nt!IofCallDriver -> \Device\00000070[0x86d2ef18] 19:36:47.375 5 ACPI.sys[f7389620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-12[0x86d33940] 19:36:48.250 AVAST engine scan C:\WINDOWS 19:37:10.671 AVAST engine scan C:\WINDOWS\system32 19:39:43.015 AVAST engine scan C:\WINDOWS\system32\drivers 19:39:56.234 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Alureon-AOW [Rtk] 19:40:06.468 AVAST engine scan C:\Documents and Settings\joe 19:45:21.593 AVAST engine scan C:\Documents and Settings\All Users 19:47:42.265 Scan finished successfully 19:51:18.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\joe\Desktop\MBR.dat" 19:51:18.656 The log file has been saved successfully to "C:\Documents and Settings\joe\Desktop\aswMBR.txt"
Hi,

Lets try this as it looks like the main rootkit has been removed but some of the infections still remains


Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI