This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe uses all my resources [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm one of the many people that is suffering under ping.exe. I had originally gotten the XP Security 2012 and this is what I did before I found these forums. , installed malware bytes (downloaded from another machine) and that appeared to get rid of it but then ping.exe started consuming all the CPU. I then tried fruitlessly rolling back but then website redirects started happening so I rolled "back" to the most recent.. Now I only have 2 problems, ping.exe still slowly takes all the CPU, and IE crashes when going to a website. I normally use Chrome or Firefox but you have to have IE to do updates. Obviously this is frustrating but what makes it doubly so is that this is my media pc, it really only goes to 3 sites, hulu, netflix and occasionally imdb to look up actors and some very light googling. My only thoughts on how it got in are java or some malicious ad. Anyway, I appreciate any help and will put each log in a reply.
First half of DDS . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 19:20:53.43 on Fri 01/06/2012 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_24 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1917.1398 [GMT -8:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\taskmgr.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Bonerchamp\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.ask.com/?o=13920&l=dis BHO: {1FD79A59-37B1-459B-9097-09F9FAB8A523} - No File BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Google Update] "c:\documents and settings\bonerchamp\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [BMUpdate] c:\windows\system32\BMUpdate.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SoundMan] SOUNDMAN.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [OneTouch Monitor] c:\program files\visioneer onetouch\OneTouchMon.exe mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
I don't know what the deal is! I can't post more than a few lines. The instructions say to paste the logs into replies but even when I cut a log down to 15 lines, I'm getting this bizarre "connection interrupted" error so I've attached the logs instead. I'm sorry for all the trouble!

Attachments:

  • [attachment removed: DDS.zip]
Hi

It's fine to attach your logs

Please run the following:

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Thanks CatByte, here you go: aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-07 14:35:59 —————————– 14:35:59.046 OS Version: Windows 5.1.2600 Service Pack 3 14:35:59.046 Number of processors: 2 586 0x1706 14:35:59.046 ComputerName: UNKNOWN UserName: 14:35:59.375 Initialize success 14:37:09.031 AVAST engine defs: 12010701 14:37:17.031 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T1L0-e 14:37:17.031 Disk 0 Vendor: WDC_WD1600AAJS-00L7A0 01.03E01 Size: 152626MB BusType: 3 14:37:17.031 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP3T0L0-19 14:37:17.031 Disk 1 Vendor: WDC_WD6400AAKS-75A7B2 01.03B01 Size: 610480MB BusType: 3 14:37:17.046 Disk 0 MBR read successfully 14:37:17.046 Disk 0 MBR scan 14:37:17.078 Disk 0 Windows XP default MBR code 14:37:17.078 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 29996 MB offset 63 14:37:17.078 Disk 0 Partition - 00 0F Extended LBA 101065 MB offset 61432560 14:37:17.093 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 101065 MB offset 61432623 14:37:17.093 Disk 0 scanning sectors +268414020 14:37:17.171 Disk 0 scanning C:\WINDOWS\system32\drivers 14:37:29.265 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot-B [Rtk] 14:37:31.296 Disk 0 trace - called modules: 14:37:31.312 ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a264f10]<< 14:37:31.312 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4e7ab8] 14:37:31.312 3 CLASSPNP.SYS[ba908fd7] -> nt!IofCallDriver -> [0x8a2e8c78] 14:37:31.312 \Driver\00001463[0x8a252248] -> IRP_MJ_CREATE -> 0x8a264f10 14:37:31.656 AVAST engine scan C:\WINDOWS 14:37:40.906 AVAST engine scan C:\WINDOWS\system32 14:39:46.531 AVAST engine scan C:\WINDOWS\system32\drivers 14:39:57.703 File: C:\WINDOWS\system32\drivers\serial.sys **INFECTED** Win32:Aluroot-B [Rtk] 14:40:00.312 AVAST engine scan C:\Documents and Settings\Bonerchamp 14:42:11.093 AVAST engine scan C:\Documents and Settings\All Users 14:42:23.546 Scan finished successfully 14:45:34.390 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Bonerchamp\Desktop\MBR.dat" 14:45:34.390 The log file has been saved successfully to "C:\Documents and Settings\Bonerchamp\Desktop\aswMBR.txt"

Attachments:

Hi,

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)


NEXT


Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Here's the TDSSKiller Log: 15:50:32.0296 3024 TDSS rootkit removing tool 2.6.25.0 Dec 23 2011 14:51:16 15:50:32.0703 3024 ============================================================ 15:50:32.0703 3024 Current date / time: 2012/01/07 15:50:32.0703 15:50:32.0703 3024 SystemInfo: 15:50:32.0703 3024 15:50:32.0703 3024 OS Version: 5.1.2600 ServicePack: 3.0 15:50:32.0703 3024 Product type: Workstation 15:50:32.0703 3024 ComputerName: UNKNOWN 15:50:32.0703 3024 UserName: Bonerchamp 15:50:32.0703 3024 Windows directory: C:\WINDOWS 15:50:32.0703 3024 System windows directory: C:\WINDOWS 15:50:32.0703 3024 Processor architecture: Intel x86 15:50:32.0703 3024 Number of processors: 2 15:50:32.0703 3024 Page size: 0x1000 15:50:32.0703 3024 Boot type: Normal boot 15:50:32.0703 3024 ============================================================ 15:50:33.0812 3024 Initialize success 15:51:31.0921 3612 ============================================================ 15:51:31.0921 3612 Scan started 15:51:31.0921 3612 Mode: Manual; 15:51:31.0921 3612 ============================================================ 15:51:32.0906 3612 Abiosdsk - ok 15:51:32.0968 3612 abp480n5 - ok 15:51:33.0062 3612 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:51:33.0078 3612 ACPI - ok 15:51:33.0156 3612 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 15:51:33.0156 3612 ACPIEC - ok 15:51:33.0218 3612 adpu160m - ok 15:51:33.0312 3612 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 15:51:33.0328 3612 aec - ok 15:51:33.0421 3612 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 15:51:33.0437 3612 AFD - ok 15:51:33.0484 3612 Aha154x - ok 15:51:33.0546 3612 aic78u2 - ok 15:51:33.0609 3612 aic78xx - ok 15:51:33.0671 3612 AliIde - ok 15:51:33.0781 3612 amsint - ok 15:51:33.0843 3612 Arp1394 (b5b8a80875c1dededa8b02765642c32f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 15:51:33.0859 3612 Arp1394 - ok 15:51:33.0921 3612 asc - ok 15:51:33.0968 3612 asc3350p - ok 15:51:34.0031 3612 asc3550 - ok 15:51:34.0125 3612 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:51:34.0125 3612 AsyncMac - ok 15:51:34.0187 3612 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 15:51:34.0187 3612 atapi - ok 15:51:34.0265 3612 Atdisk - ok 15:51:34.0343 3612 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:51:34.0343 3612 Atmarpc - ok 15:51:34.0421 3612 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 15:51:34.0437 3612 audstub - ok 15:51:34.0515 3612 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 15:51:34.0515 3612 Beep - ok 15:51:34.0609 3612 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 15:51:34.0609 3612 cbidf2k - ok 15:51:34.0656 3612 cd20xrnt - ok 15:51:34.0796 3612 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 15:51:34.0796 3612 Cdaudio - ok 15:51:34.0875 3612 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 15:51:34.0875 3612 Cdfs - ok 15:51:34.0968 3612 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 15:51:34.0984 3612 Cdrom - ok 15:51:35.0093 3612 Changer - ok 15:51:35.0187 3612 CmdIde - ok 15:51:35.0281 3612 Cpqarray - ok 15:51:35.0343 3612 dac2w2k - ok 15:51:35.0406 3612 dac960nt - ok 15:51:35.0484 3612 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 15:51:35.0484 3612 Disk - ok 15:51:35.0640 3612 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 15:51:35.0734 3612 dmboot - ok 15:51:35.0843 3612 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 15:51:35.0859 3612 dmio - ok 15:51:35.0906 3612 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 15:51:35.0921 3612 dmload - ok 15:51:36.0000 3612 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 15:51:36.0000 3612 DMusic - ok 15:51:36.0062 3612 dpti2o - ok 15:51:36.0140 3612 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 15:51:36.0140 3612 drmkaud - ok 15:51:36.0218 3612 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 15:51:36.0234 3612 Fastfat - ok 15:51:36.0312 3612 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 15:51:36.0312 3612 Fdc - ok 15:51:36.0390 3612 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 15:51:36.0390 3612 Fips - ok 15:51:36.0453 3612 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 15:51:36.0453 3612 Flpydisk - ok 15:51:36.0531 3612 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 15:51:36.0546 3612 FltMgr - ok 15:51:36.0625 3612 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:51:36.0625 3612 Fs_Rec - ok 15:51:36.0687 3612 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:51:36.0703 3612 Ftdisk - ok 15:51:36.0781 3612 gdrv (47a244f0dcff72a7ec6dcec111438d28) C:\WINDOWS\gdrv.sys 15:51:36.0890 3612 gdrv - ok 15:51:37.0015 3612 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:51:37.0015 3612 Gpc - ok 15:51:37.0109 3612 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:51:37.0109 3612 HDAudBus - ok 15:51:37.0171 3612 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:51:37.0171 3612 hidusb - ok 15:51:37.0250 3612 hpn - ok 15:51:37.0296 3612 hpt3xx - ok 15:51:37.0406 3612 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys 15:51:37.0437 3612 HTTP - ok 15:51:37.0500 3612 i2omgmt - ok 15:51:37.0562 3612 i2omp - ok 15:51:37.0640 3612 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 15:51:37.0640 3612 i8042prt - ok 15:51:37.0703 3612 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 15:51:37.0718 3612 Imapi - ok 15:51:37.0812 3612 ini910u - ok 15:51:38.0375 3612 IntcAzAudAddService (4aaa8312732655f93a254d1fa695eb79) C:\WINDOWS\system32\drivers\RtkHDAud.sys 15:51:38.0390 3612 IntcAzAudAddService - ok 15:51:38.0484 3612 IntelIde - ok 15:51:38.0562 3612 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 15:51:38.0578 3612 intelppm - ok 15:51:38.0656 3612 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 15:51:38.0671 3612 ip6fw - ok 15:51:38.0796 3612 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:51:38.0796 3612 IpFilterDriver - ok 15:51:38.0875 3612 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:51:38.0875 3612 IpInIp - ok 15:51:38.0968 3612 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:51:38.0984 3612 IpNat - ok 15:51:39.0062 3612 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:51:39.0078 3612 IPSec - ok 15:51:39.0140 3612 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 15:51:39.0140 3612 IRENUM - ok 15:51:39.0218 3612 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:51:39.0218 3612 isapnp - ok 15:51:39.0281 3612 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:51:39.0296 3612 Kbdclass - ok 15:51:39.0359 3612 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 15:51:39.0359 3612 kbdhid - ok 15:51:39.0453 3612 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 15:51:39.0468 3612 kmixer - ok 15:51:39.0546 3612 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 15:51:39.0562 3612 KSecDD - ok 15:51:39.0625 3612 lbrtfdc - ok 15:51:39.0703 3612 MBAMProtector (b7ca8cc3f978201856b6ab82f40953c3) C:\WINDOWS\system32\drivers\mbam.sys 15:51:39.0703 3612 MBAMProtector - ok 15:51:39.0828 3612 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 15:51:39.0828 3612 mnmdd - ok 15:51:39.0921 3612 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 15:51:39.0921 3612 Modem - ok 15:51:40.0000 3612 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:51:40.0000 3612 Mouclass - ok 15:51:40.0078 3612 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:51:40.0078 3612 mouhid - ok 15:51:40.0156 3612 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 15:51:40.0156 3612 MountMgr - ok 15:51:40.0218 3612 mraid35x - ok 15:51:40.0312 3612 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:51:40.0328 3612 MRxDAV - ok 15:51:40.0437 3612 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:51:40.0484 3612 MRxSmb - ok 15:51:40.0593 3612 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 15:51:40.0609 3612 Msfs - ok 15:51:40.0671 3612 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:51:40.0671 3612 MSKSSRV - ok 15:51:40.0796 3612 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:51:40.0796 3612 MSPCLOCK - ok 15:51:40.0859 3612 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 15:51:40.0859 3612 MSPQM - ok 15:51:40.0921 3612 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:51:40.0921 3612 mssmbios - ok 15:51:41.0000 3612 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 15:51:41.0000 3612 Mup - ok 15:51:41.0093 3612 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 15:51:41.0109 3612 NDIS - ok 15:51:41.0171 3612 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:51:41.0171 3612 NdisTapi - ok 15:51:41.0234 3612 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:51:41.0234 3612 Ndisuio - ok 15:51:41.0312 3612 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:51:41.0312 3612 NdisWan - ok 15:51:41.0390 3612 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 15:51:41.0390 3612 NDProxy - ok 15:51:41.0468 3612 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 15:51:41.0468 3612 NetBIOS - ok 15:51:41.0546 3612 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 15:51:41.0562 3612 NetBT - ok 15:51:41.0656 3612 NIC1394 (e9e47cfb2d461fa0fc75b7a74c6383ea) C:\WINDOWS\system32\DRIVERS\nic1394.sys 15:51:41.0656 3612 NIC1394 - ok 15:51:41.0718 3612 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 15:51:41.0765 3612 Npfs - ok 15:51:41.0890 3612 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 15:51:41.0937 3612 Ntfs - ok 15:51:42.0015 3612 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 15:51:42.0015 3612 Null - ok 15:51:42.0828 3612 nv (c190757a29a9bc0199032f353dd2557a) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 15:51:43.0500 3612 nv - ok 15:51:43.0625 3612 NVENETFD (0258d664f93b4b01ddd621b8c084f322) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 15:51:43.0640 3612 NVENETFD - ok 15:51:43.0718 3612 NVHDA (7466677b20d0aba7baf1b43e09f4e881) C:\WINDOWS\system32\drivers\nvhda32.sys 15:51:43.0718 3612 NVHDA - ok 15:51:43.0843 3612 nvnetbus (56ec9207906435ef1bf02f5c68e3ffec) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 15:51:43.0843 3612 nvnetbus - ok 15:51:43.0937 3612 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:51:43.0937 3612 NwlnkFlt - ok 15:51:44.0000 3612 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:51:44.0000 3612 NwlnkFwd - ok 15:51:44.0078 3612 ohci1394 (ca33832df41afb202ee7aeb05145922f) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 15:51:44.0093 3612 ohci1394 - ok 15:51:44.0156 3612 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 15:51:44.0156 3612 Parport - ok 15:51:44.0218 3612 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 15:51:44.0234 3612 PartMgr - ok 15:51:44.0296 3612 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 15:51:44.0312 3612 ParVdm - ok 15:51:44.0390 3612 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 15:51:44.0390 3612 PCI - ok 15:51:44.0453 3612 PCIDump - ok 15:51:44.0515 3612 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 15:51:44.0531 3612 PCIIde - ok 15:51:44.0593 3612 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 15:51:44.0609 3612 Pcmcia - ok 15:51:44.0671 3612 PDCOMP - ok 15:51:44.0781 3612 PDFRAME - ok 15:51:44.0843 3612 PDRELI - ok 15:51:44.0890 3612 PDRFRAME - ok 15:51:44.0968 3612 perc2 - ok 15:51:45.0015 3612 perc2hib - ok 15:51:45.0109 3612 ppsio2 (de4dfb09bf96fd5f810750140e2aa236) C:\WINDOWS\system32\drivers\ppsio2.sys 15:51:45.0109 3612 ppsio2 - ok 15:51:45.0187 3612 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:51:45.0203 3612 PptpMiniport - ok 15:51:45.0265 3612 Processor (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys 15:51:45.0265 3612 Processor - ok 15:51:45.0343 3612 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 15:51:45.0343 3612 PSched - ok 15:51:45.0421 3612 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:51:45.0421 3612 Ptilink - ok 15:51:45.0484 3612 ql1080 - ok 15:51:45.0546 3612 Ql10wnt - ok 15:51:45.0609 3612 ql12160 - ok 15:51:45.0671 3612 ql1240 - ok 15:51:45.0765 3612 ql1280 - ok 15:51:45.0843 3612 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:51:45.0843 3612 RasAcd - ok 15:51:45.0921 3612 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:51:45.0937 3612 Rasl2tp - ok 15:51:46.0000 3612 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:51:46.0000 3612 RasPppoe - ok 15:51:46.0062 3612 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 15:51:46.0062 3612 Raspti - ok 15:51:46.0156 3612 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:51:46.0171 3612 Rdbss - ok 15:51:46.0234 3612 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:51:46.0234 3612 RDPCDD - ok 15:51:46.0328 3612 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 15:51:46.0343 3612 rdpdr - ok 15:51:46.0421 3612 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 15:51:46.0437 3612 RDPWD - ok 15:51:46.0515 3612 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 15:51:46.0531 3612 redbook - ok 15:51:46.0656 3612 RTLWUSB (5a850259b849a899990379a75460a4eb) C:\WINDOWS\system32\DRIVERS\RTL8187.sys 15:51:46.0687 3612 RTLWUSB - ok 15:51:46.0828 3612 sbp2port (b244960e5a1db8e9d5d17086de37c1e4) C:\WINDOWS\system32\DRIVERS\sbp2port.sys 15:51:46.0828 3612 sbp2port - ok 15:51:46.0921 3612 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:51:46.0921 3612 Secdrv - ok 15:51:46.0984 3612 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 15:51:46.0984 3612 serenum - ok 15:51:47.0046 3612 Serial (29ab6266e303b9b092e17243fe6ab69d) C:\WINDOWS\system32\DRIVERS\serial.sys 15:51:47.0062 3612 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\serial.sys. Real md5: 29ab6266e303b9b092e17243fe6ab69d, Fake md5: cca207a8896d4c6a0c9ce29a4ae411a7 15:51:47.0062 3612 Serial ( Rootkit.Win32.ZAccess.aml ) - infected 15:51:47.0062 3612 Serial - detected Rootkit.Win32.ZAccess.aml (0) 15:51:47.0140 3612 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 15:51:47.0156 3612 Sfloppy - ok 15:51:47.0203 3612 Simbad - ok 15:51:47.0265 3612 Sparrow - ok 15:51:47.0343 3612 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 15:51:47.0343 3612 splitter - ok 15:51:47.0421 3612 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 15:51:47.0421 3612 sr - ok 15:51:47.0531 3612 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys 15:51:47.0562 3612 Srv - ok 15:51:47.0640 3612 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 15:51:47.0640 3612 swenum - ok 15:51:47.0718 3612 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 15:51:47.0765 3612 swmidi - ok 15:51:47.0828 3612 symc810 - ok 15:51:47.0890 3612 symc8xx - ok 15:51:47.0953 3612 sym_hi - ok 15:51:48.0015 3612 sym_u3 - ok 15:51:48.0093 3612 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 15:51:48.0093 3612 sysaudio - ok 15:51:48.0203 3612 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:51:48.0234 3612 Tcpip - ok 15:51:48.0312 3612 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 15:51:48.0312 3612 TDPIPE - ok 15:51:48.0375 3612 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 15:51:48.0390 3612 TDTCP - ok 15:51:48.0453 3612 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 15:51:48.0468 3612 TermDD - ok 15:51:48.0531 3612 TosIde - ok 15:51:48.0609 3612 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 15:51:48.0609 3612 Udfs - ok 15:51:48.0671 3612 ultra - ok 15:51:48.0828 3612 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 15:51:48.0875 3612 Update - ok 15:51:48.0953 3612 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:51:48.0953 3612 usbccgp - ok 15:51:49.0015 3612 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:51:49.0015 3612 usbehci - ok 15:51:49.0078 3612 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:51:49.0093 3612 usbhub - ok 15:51:49.0156 3612 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 15:51:49.0156 3612 usbohci - ok 15:51:49.0234 3612 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 15:51:49.0234 3612 usbscan - ok 15:51:49.0312 3612 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:51:49.0312 3612 USBSTOR - ok 15:51:49.0359 3612 vcdrom (bfa4ae30b3ac10e9223830bf103f5a3f) C:\Programs\VirtualCD\VCdRom.sys 15:51:49.0359 3612 vcdrom - ok 15:51:49.0437 3612 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 15:51:49.0437 3612 VgaSave - ok 15:51:49.0500 3612 ViaIde - ok 15:51:49.0578 3612 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 15:51:49.0578 3612 VolSnap - ok 15:51:49.0671 3612 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:51:49.0671 3612 Wanarp - ok 15:51:49.0765 3612 WDICA - ok 15:51:49.0859 3612 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 15:51:49.0859 3612 wdmaud - ok 15:51:49.0953 3612 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 15:51:49.0953 3612 WmiAcpi - ok 15:51:49.0984 3612 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0 15:51:50.0140 3612 \Device\Harddisk0\DR0 - ok 15:51:50.0156 3612 MBR (0x1B8) (8f558eb6672622401da993e1e865c861) \Device\Harddisk1\DR1 15:51:50.0156 3612 \Device\Harddisk1\DR1 - ok 15:51:50.0171 3612 Boot (0x1200) (30b25fec71d1b50119004159409d1780) \Device\Harddisk0\DR0\Partition0 15:51:50.0171 3612 \Device\Harddisk0\DR0\Partition0 - ok 15:51:50.0171 3612 Boot (0x1200) (c15680f788ae21e357ab33c55330c92f) \Device\Harddisk0\DR0\Partition1 15:51:50.0171 3612 \Device\Harddisk0\DR0\Partition1 - ok 15:51:50.0187 3612 Boot (0x1200) (04212c17c7044a19567087e2e8a673b7) \Device\Harddisk1\DR1\Partition0 15:51:50.0187 3612 \Device\Harddisk1\DR1\Partition0 - ok 15:51:50.0187 3612 ============================================================ 15:51:50.0187 3612 Scan finished 15:51:50.0187 3612 ============================================================ 15:51:50.0187 3604 Detected object count: 1 15:51:50.0187 3604 Actual detected object count: 1 15:58:45.0609 3604 Backup copy found, using it.. 15:58:45.0625 3604 C:\WINDOWS\system32\DRIVERS\serial.sys - will be cured on reboot 15:58:50.0593 3604 Serial ( Rootkit.Win32.ZAccess.aml ) - User select action: Cure 15:59:46.0671 2824 Deinitialize success
And ComboFix:


ComboFix 12-01-07.02 - Bonerchamp 01/07/2012 16:12:09.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1917.1620 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Bonerchamp\Application Data\EurekaLog
c:\documents and settings\Bonerchamp\Application Data\EurekaLog\RiffTrax\RiffTrax_UNKNOWN.elf
c:\windows\$NtUninstallKB37428$
c:\windows\$NtUninstallKB37428$\2388663380\@
c:\windows\$NtUninstallKB37428$\2388663380\bckfg.tmp
c:\windows\$NtUninstallKB37428$\2388663380\cfg.ini
c:\windows\$NtUninstallKB37428$\2388663380\Desktop.ini
c:\windows\$NtUninstallKB37428$\2388663380\keywords
c:\windows\$NtUninstallKB37428$\2388663380\kwrd.dll
c:\windows\$NtUninstallKB37428$\2388663380\L\akygdmgo
c:\windows\$NtUninstallKB37428$\2388663380\lsflt7.ver
c:\windows\$NtUninstallKB37428$\2388663380\U\00000001.@
c:\windows\$NtUninstallKB37428$\2388663380\U\00000002.@
c:\windows\$NtUninstallKB37428$\2388663380\U\00000004.@
c:\windows\$NtUninstallKB37428$\2388663380\U\80000000.@
c:\windows\$NtUninstallKB37428$\2388663380\U\80000004.@
c:\windows\$NtUninstallKB37428$\2388663380\U\80000032.@
c:\windows\$NtUninstallKB37428$\3528303311
c:\windows\system32\PowerToyReadme.htm
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_6TO4
——-\Service_6to4
.
.
((((((((((((((((((((((((( Files Created from 2011-12-08 to 2012-01-08 )))))))))))))))))))))))))))))))
.
.
2012-01-03 11:00 . 2011-12-10 23:24 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2012-01-03 10:55 . 2012-01-03 10:55 ——– d—–w- c:\windows\system32\wbem\Repository
2012-01-03 10:55 . 2012-01-03 10:55 ——– d—–w- c:\program files\Java
2012-01-03 10:38 . 2012-01-03 10:38 ——– d—–w- c:\program files\Common Files\Java
2012-01-03 10:38 . 2012-01-03 10:38 ——– d—–w- c:\program files\AskBarDis
2012-01-03 10:38 . 2012-01-03 10:38 ——– d–h–w- c:\documents and settings\All Users\Application Data\~0
2012-01-03 10:37 . 2012-01-03 10:37 ——– d—–w- c:\windows\LastGood(3)
2012-01-03 10:04 . 2012-01-03 10:04 ——– d—–w- c:\documents and settings\Bonerchamp\IECompatCache
2012-01-03 10:02 . 2012-01-03 10:37 ——– d—–w- c:\windows\LastGood(2)
2012-01-03 10:02 . 2009-08-07 03:23 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-01-03 10:01 . 2012-01-08 00:11 ——– d—–w- c:\windows\system32\CatRoot2
2012-01-03 08:59 . 2012-01-03 08:59 ——– d—–w- c:\documents and settings\NetworkService\IETldCache
2012-01-03 08:58 . 2012-01-03 08:58 ——– d—–w- c:\documents and settings\Bonerchamp\PrivacIE
2012-01-03 08:56 . 2012-01-03 08:56 ——– d—–w- c:\documents and settings\Bonerchamp\IETldCache
2012-01-03 08:52 . 2012-01-03 08:53 ——– dc-h–w- c:\windows\ie8
2012-01-03 08:51 . 2012-01-03 10:37 ——– d–h–w- c:\windows\msdownld.tmp
2012-01-03 08:47 . 2012-01-03 08:47 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE17EA8C-EBCD-409B-9973-75191A1BF54F}\MpKsl59f7d60d.sys
2012-01-03 08:46 . 2012-01-03 08:46 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE17EA8C-EBCD-409B-9973-75191A1BF54F}\offreg(2).dll
2012-01-03 07:33 . 2012-01-03 11:00 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-01-03 07:33 . 2011-12-10 23:24 20464 —-a-w- c:\windows\system32\drivers\mbam(2).sys
2012-01-03 07:12 . 2012-01-03 07:12 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{FE17EA8C-EBCD-409B-9973-75191A1BF54F}\MpKsl7c9fa130.sys
2012-01-03 06:46 . 2012-01-03 06:46 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth
2012-01-02 04:45 . 2012-01-03 10:39 ——– d—–w- c:\program files\Microsoft Security Client
2012-01-01 20:25 . 2012-01-01 20:25 ——– d—–w- c:\windows\Logs
2012-01-01 20:25 . 2012-01-01 20:25 ——– d—–w- c:\program files\Microsoft XNA
2011-12-29 06:24 . 2012-01-03 10:39 ——– d—–w- c:\program files\Steam
2011-12-27 03:56 . 2012-01-01 03:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-12-27 03:55 . 2012-01-03 10:39 ——– d—–w- c:\program files\Spybot - Search & Destroy 2
2011-12-27 03:54 . 2011-12-27 03:54 ——– d—–w- c:\documents and settings\Bonerchamp\Application Data\Malwarebytes
2011-12-27 03:54 . 2011-12-27 03:54 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-08 00:00 . 2001-08-23 12:00 64512 —-a-w- c:\windows\system32\drivers\serial.sys
2011-11-09 02:58 . 2011-08-05 08:32 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-13 06:47 . 2011-06-10 03:33 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2009-04-02 19:47 333192 —-a-w- c:\program files\AskBarDis\bar\bin\askBar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
.
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2009-04-02 333192]
.
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\Bonerchamp\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\Bonerchamp\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\Bonerchamp\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 —-a-w- c:\documents and settings\Bonerchamp\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BMUpdate"="c:\windows\system32\BMUpdate.exe" [2001-07-03 176128]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-10-04 8491008]
"nwiz"="nwiz.exe" [2007-10-04 1626112]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-10-04 81920]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-24 16804864]
"SoundMan"="SOUNDMAN.EXE" [2008-06-19 77824]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-20 2808832]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-12-25 460872]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Documents and Settings\\Bonerchamp\\Desktop\\utorrent.exe"=
"c:\\Documents and Settings\\Bonerchamp\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8888:UDP"= 8888:UDP:ds
.
R1 vcdrom;Virtual CD-ROM Device Driver;c:\programs\VirtualCD\VCdRom.sys [12/19/2001 10:45 AM 8576]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [1/3/2012 3:00 AM 652872]
R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [6/7/2010 8:05 AM 23200]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [1/3/2012 3:00 AM 20464]
R3 NVHDA;Service for NVIDIA HDMI Audio Driver;c:\windows\system32\drivers\nvhda32.sys [11/10/2007 3:20 AM 29728]
S2 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [8/8/2009 10:33 PM 234888]
S2 NecUsb;USB Service;c:\windows\System32\svchost.exe -k NecUsbSevice [8/23/2001 4:00 AM 14336]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [12/5/2008 6:15 PM 332928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
NecUsbSevice REG_MULTI_SZ NecUsb
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-03 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-507921405-688789844-839522115-1003Core.job
- c:\documents and settings\Bonerchamp\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-06 21:38]
.
2012-01-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-507921405-688789844-839522115-1003UA.job
- c:\documents and settings\Bonerchamp\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-06 21:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.ask.com/?o=13920&l=dis
TCP: DhcpNameServer = 192.168.0.1
FF - ProfilePath - c:\documents and settings\Bonerchamp\Application Data\Mozilla\Firefox\Profiles\g0le0ks1.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q=
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-OneTouch Monitor - c:\program files\Visioneer OneTouch\OneTouchMon.exe
Notify-USB3Nw32 - USB3Nw32.dll
SafeBoot-39132590.sys
AddRemove-OneTouch Version 3.0 - c:\progra~1\VISION~1\UNWISE.EXE
AddRemove-RiffTrax DVD Player - c:\documents and settings\All Users\Application Data\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF}\RiffTrax Setup.exe
AddRemove-{C4B3A7F9-5CD8-4608-B623-689CA3604A08} - c:\documents and settings\All Users\Application Data\{F71301CF-0E9E-468F-B1CE-FEC9F977CAAF}\RiffTrax Setup.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-07 16:19
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3308)
c:\windows\system32\WININET.dll
c:\documents and settings\Bonerchamp\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\windows\SOUNDMAN.EXE
c:\windows\System32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-01-07 16:21:45 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-08 00:21
.
Pre-Run: 5,846,294,528 bytes free
Post-Run: 6,274,662,400 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
.
- - End Of File - - B868DF305FDEDA8359686923F0B8B303
Hi

Please run the following:

Please press Start->Run, copy/paste the following command from inside the quote box (it's one long command) into the runbox and press OK:

cmd /c dir "c:\documents and settings\All Users\Application Data\~0" /a /s >> "%userprofile%\desktop\look.txt" 2>>&1



A black box will open and a file will appear on your Desktop called look.txt.

Please wait until the black box closes before opening it, and post the contents of look.txt in your next response.


NEXT


Hi,

Please do the following:

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Eset took a looooooong time to run, well over 2 James Bond movies. Here are all the logs: look.txt ================================================= Volume in drive C has no label. Volume Serial Number is AC89-C827 Directory of c:\documents and settings\All Users\Application Data\~0 01/03/2012 02:38 AM . 01/03/2012 02:38 AM .. 01/12/2009 04:27 PM 2,331,715 RiffTrax Setup.exe 1 File(s) 2,331,715 bytes Total Files Listed: 1 File(s) 2,331,715 bytes 2 Dir(s) 6,302,507,008 bytes free mbam log========================================================= Malwarebytes Anti-Malware (Trial) 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.07.04 Windows XP Service Pack 3 x86 NTFS Internet Explorer 7.0.5730.13 Bonerchamp :: UNKNOWN [administrator] Protection: Enabled 1/7/2012 4:46:20 PM mbam-log-2012-01-07 (16-46-20).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 157246 Time elapsed: 3 minute(s), 21 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) eset log============================================= C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\19\7264e953-2ddad455 a variant of Java/Agent.DZ trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\22\30f23856-1e7f32ac a variant of Java/Exploit.CVE-2011-3544.Q trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\29\1b0b81d-407246b5 a variant of Java/Agent.DZ trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\52\58007f34-6e053482 a variant of Java/Agent.DZ trojan C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\6\3a0450c6-1027e6dd a variant of Java/Exploit.CVE-2011-3544.Q trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP274\A0079479.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP274\A0079491.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP275\A0079507.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP277\A0079567.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP279\A0079600.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP280\A0079683.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP280\A0079714.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP283\A0082854.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP285\A0082995.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP286\A0083486.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP286\A0084453.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP287\A0085807.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP289\A0086110.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP289\A0086139.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP290\A0086228.sys a variant of Win32/Rootkit.Kryptik.HB trojan C:\System Volume Information\_restore{1D2DCB84-4EED-4B1C-A67E-02D6871B709C}\RP290\A0086239.sys a variant of Win32/Rootkit.Kryptik.HB trojan
Hi

Please do the following:

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.

NEXT

[external image: Posted Image] Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and Save it to your Desktop.
  • Scroll down to where it says Java SE 6 Update 30
  • Click the Download button under JRE to the right.
  • Read the License Agreement then select Accept License Agreement
  • Click on the link to download Windows x86 Offline and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel, double-click on Add or Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u30-windows-i586.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.


NEXT


Please post a fresh DDS Log and advise how the computer is running now and if there are any outstanding issues
The computer seems to be running fine now. When I was running eset last night, I periodically checked and ping.exe was not running. The only thing left, which may or may not be related is getting Internet Explorer to run again so I can use Windows Update. I suspect it got put into a bad state with my various roll backs and I have another year before XP hits end of life so it would be good for Windows Update to work. Previous to posting here, I had tried running it but it said it couldn't connect and I don't know if that was due to the infection or something else. I have an IE 8 installer downloaded from another computer, is it time to use it and see if Windows Update works again? Here is the DDS log: . DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 15:29:01.98 on Sun 01/08/2012 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_30 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1917.1392 [GMT -8:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\ctfmon.exe svchost.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Bonerchamp\Desktop\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.ask.com/?o=13920&l=dis BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - c:\program files\askbardis\bar\bin\askBar.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [BMUpdate] c:\windows\system32\BMUpdate.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SoundMan] SOUNDMAN.EXE mRun: [AlcWzrd] ALCWZRD.EXE mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1228534513390 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228595078781 DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\bonerc~1\applic~1\mozilla\firefox\profiles\g0le0ks1.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=13917&gct=&gc=1&q= . ============= SERVICES / DRIVERS =============== . R1 vcdrom;Virtual CD-ROM Device Driver;c:\programs\virtualcd\VCdRom.sys [2001-12-19 8576] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-1-3 652872] R2 ppsio2;PPDevice;c:\windows\system32\drivers\ppsio2.sys [2010-6-7 23200] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-1-3 20464] R3 NVHDA;Service for NVIDIA HDMI Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2007-11-10 29728] S2 ASKUpgrade;ASKUpgrade;c:\program files\askbardis\bar\bin\ASKUpgrade.exe [2009-8-8 234888] S2 NecUsb;USB Service;c:\windows\system32\svchost.exe -k NecUsbSevice [2001-8-23 14336] S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8187.sys [2008-12-5 332928] . =============== Created Last 30 ================ . 2012-01-08 23:25:29 73728 —-a-w- c:\windows\system32\javacpl.cpl 2012-01-08 23:22:00 ——– d—–w- c:\windows\system32\appmgmt 2012-01-08 23:20:41 ——– d—–w- c:\docume~1\bonerc~1\locals~1\applic~1\Adobe 2012-01-08 00:55:58 ——– d—–w- c:\program files\ESET 2012-01-08 00:05:00 ——– d-sha-r- C:\cmdcons 2012-01-08 00:03:33 98816 —-a-w- c:\windows\sed.exe 2012-01-08 00:03:33 518144 —-a-w- c:\windows\SWREG.exe 2012-01-08 00:03:33 256000 —-a-w- c:\windows\PEV.exe 2012-01-08 00:03:33 208896 —-a-w- c:\windows\MBR.exe 2012-01-03 11:00:49 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2012-01-03 10:55:43 ——– d—–w- c:\windows\system32\wbem\repository\FS 2012-01-03 10:55:43 ——– d—–w- c:\windows\system32\wbem\Repository 2012-01-03 10:38:11 ——– d—–w- c:\program files\AskBarDis 2012-01-03 10:38:00 ——– d–h–w- c:\docume~1\alluse~1\applic~1\~0 2012-01-03 10:37:39 ——– d—–w- c:\windows\LastGood(3) 2012-01-03 10:23:20 ——– d—–w- c:\program files\AskBarDis(2) 2012-01-03 10:04:22 ——– d—–w- c:\documents and settings\bonerchamp\IECompatCache 2012-01-03 10:02:45 16736 —-a-w- c:\windows\system32\mucltui.dll.mui 2012-01-03 10:02:45 ——– d—–w- c:\windows\LastGood(2) 2012-01-03 10:01:32 ——– d—–w- c:\windows\system32\CatRoot2 2012-01-03 08:58:25 ——– d—–w- c:\documents and settings\bonerchamp\PrivacIE 2012-01-03 08:56:26 ——– d—–w- c:\documents and settings\bonerchamp\IETldCache 2012-01-03 08:52:37 ——– dc-h–w- c:\windows\ie8 2012-01-03 08:51:49 ——– d–h–w- c:\windows\msdownld.tmp 2012-01-03 08:47:11 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{fe17ea8c-ebcd-409b-9973-75191a1bf54f}\MpKsl59f7d60d.sys 2012-01-03 08:46:57 56200 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{fe17ea8c-ebcd-409b-9973-75191a1bf54f}\offreg(2).dll 2012-01-03 08:00:01 ——– d—–w- c:\program files\common files\Java(2) 2012-01-03 07:58:36 ——– d—–w- c:\program files\Java(2) 2012-01-03 07:33:55 20464 —-a-w- c:\windows\system32\drivers\mbam(2).sys 2012-01-03 07:33:55 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2012-01-03 07:12:02 29904 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{fe17ea8c-ebcd-409b-9973-75191a1bf54f}\MpKsl7c9fa130.sys 2012-01-02 04:45:12 ——– d—–w- c:\program files\Microsoft Security Client 2012-01-01 20:25:58 ——– d—–w- c:\windows\Logs 2012-01-01 20:25:56 ——– d—–w- c:\program files\Microsoft XNA 2011-12-29 06:24:25 ——– d—–w- c:\program files\Steam 2011-12-27 03:56:06 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2011-12-27 03:55:40 ——– d—–w- c:\program files\Spybot - Search & Destroy 2 2011-12-27 03:54:54 ——– d—–w- c:\docume~1\bonerc~1\applic~1\Malwarebytes 2011-12-27 03:54:45 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes . ==================== Find3M ==================== . 2012-01-08 23:25:13 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-11-09 02:58:05 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . ============= FINISH: 15:29:27.90 ===============
yes,

the log looks clean, so install IE8 and let me know if your windows update now works

If not, please run the following:

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI