This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows XP malware infection [Solved]

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A few days ago, I picked up some malware on my computer while browsing imgur. I don't know what link gave it to me, but I've been too afraid to even touch the computer since. My husband directed me to here and told me to post here. The problem I'm having is being unable to open certain programs as well as pop-ups of fake antivirus ads opening instead and at random times. Here is my HijackThis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:56:03 AM, on 1/14/2012
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:5555
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /install
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O16 - DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} (AxProdInfoCtl Class) - http://www.symantec.com/techsupp/activedata/nprdtinf.cab
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} (Disney Online Games ActiveX Control) - http://disney.go.com/pirates/online/testAc…OnlineGames.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://www-secure.symantec.com/techsupp/as…abs/tgctlsr.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - Unknown owner - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Pure Networks Platform Service (nmservice) - Unknown owner - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 5844 bytes
Hello Geheimnis and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

Support for XP SP2 was discontinued some time ago now. Is there any particular reason why you have not yet updated to XP SP3?

Lets take a closer look at the machine with the following:

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you encounter any problems with the scans come back and let me know.
Here are the DDS logs: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 7/19/2006 3:08:25 PM System Uptime: 1/14/2012 4:38:02 PM (0 hours ago) . Motherboard: ASUSTeK Computer INC. | | P5V800-MX Processor: Intel® Pentium® 4 CPU 2.66GHz | LGA 775 | 2660/133mhz . ==== Disk Partitions ========================= . A: is Removable C: is FIXED (NTFS) - 75 GiB total, 13.398 GiB free. D: is CDROM () E: is Removable . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E96D-E325-11CE-BFC1-08002BE10318} Description: PCI Simple Communications Controller Device ID: PCI\VEN_12B9&DEV_1006&SUBSYS_008112B9&REV_00\4&176304AC&0&4899 Manufacturer: U.S. Robotics Corporation Name: U.S. Robotics 56K Voice Win 1806 PNP Device ID: PCI\VEN_12B9&DEV_1006&SUBSYS_008112B9&REV_00\4&176304AC&0&4899 Service: Modem . Class GUID: {5458011F-08D4-4605-93A2-F03E61BEDBA3} Description: Enhanced Display Driver Helper Service Device ID: ROOT\ASUSOTHERDEVICES\0000 Manufacturer: ASUSTeK Name: Enhanced Display Driver Helper Service PNP Device ID: ROOT\ASUSOTHERDEVICES\0000 Service: asuskbnt . ==== System Restore Points =================== . RP911: 11/1/2011 6:39:54 PM - System Checkpoint RP912: 11/2/2011 11:45:48 AM - Removed World of Warcraft Model Viewer RP913: 11/3/2011 5:33:14 PM - System Checkpoint RP914: 11/4/2011 9:53:19 PM - System Checkpoint RP915: 11/5/2011 9:00:54 PM - System Checkpoint RP916: 11/7/2011 9:04:17 PM - System Checkpoint RP917: 11/9/2011 11:02:43 PM - System Checkpoint RP918: 11/11/2011 8:11:44 PM - System Checkpoint RP919: 11/12/2011 9:06:25 PM - System Checkpoint RP920: 11/15/2011 5:18:22 PM - System Checkpoint RP921: 11/16/2011 7:12:49 PM - System Checkpoint RP922: 11/18/2011 10:15:35 PM - System Checkpoint RP923: 11/19/2011 11:02:34 PM - System Checkpoint RP924: 11/21/2011 10:01:21 PM - System Checkpoint RP925: 11/22/2011 10:03:33 PM - System Checkpoint RP926: 11/24/2011 12:32:46 AM - System Checkpoint RP927: 11/25/2011 10:57:17 AM - System Checkpoint RP928: 11/26/2011 1:20:04 PM - System Checkpoint RP929: 11/27/2011 2:06:49 PM - System Checkpoint RP930: 11/28/2011 5:51:27 PM - System Checkpoint RP931: 11/29/2011 9:13:51 PM - System Checkpoint RP932: 12/1/2011 3:05:45 AM - System Checkpoint RP933: 12/4/2011 9:21:18 PM - System Checkpoint RP934: 12/5/2011 10:53:26 PM - System Checkpoint RP935: 12/7/2011 1:43:06 PM - System Checkpoint RP936: 12/9/2011 9:36:34 PM - System Checkpoint RP937: 12/11/2011 10:48:40 AM - System Checkpoint RP938: 12/13/2011 10:16:55 PM - System Checkpoint RP939: 12/14/2011 10:36:14 PM - System Checkpoint RP940: 12/17/2011 12:23:32 PM - System Checkpoint RP941: 12/18/2011 8:26:40 PM - System Checkpoint RP942: 12/20/2011 10:41:34 PM - System Checkpoint RP943: 12/23/2011 10:34:30 AM - System Checkpoint RP944: 12/24/2011 11:50:57 PM - System Checkpoint RP945: 12/26/2011 1:55:55 PM - System Checkpoint RP946: 12/28/2011 7:07:00 PM - System Checkpoint RP947: 12/29/2011 11:48:36 PM - System Checkpoint RP948: 12/31/2011 2:04:01 PM - System Checkpoint RP949: 1/1/2012 2:07:53 PM - System Checkpoint RP950: 1/4/2012 4:52:12 PM - System Checkpoint RP951: 1/9/2012 9:21:33 PM - System Checkpoint RP952: 1/11/2012 9:31:18 AM - System Checkpoint RP953: 1/12/2012 11:23:33 AM - System Checkpoint RP954: 1/14/2012 10:51:03 AM - Installed HiJackThis . ==== Installed Programs ====================== . Acrobat.com Adobe AIR Adobe Flash Player 11 Plugin Adobe Flash Player 9 ActiveX Adobe Flash Player ActiveX Adobe Reader 9.1 Adobe Shockwave Player 11.5 Age of Mythology Age of Mythology - The Titans Expansion Apple Software Update ASUS GameFace Library ASUS GamerOSD AP ASUS nVidia Driver ASUS Smart Doctor ASUS Utilities ASUS VideoSecurity Online Auslogics Disk Defrag avast! Free Antivirus CCleaner (remove only) Compatibility Pack for the 2007 Office system CutePDF Writer 2.7 Dofus High Definition Audio Driver Package - KB888111 HiJackThis HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB954708) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) HP Deskjet 5700 HP Software Update J2SE Runtime Environment 5.0 Update 8 Java™ 6 Update 13 Java™ 6 Update 3 Java™ 6 Update 5 Junk Mail filter update Malwarebytes Anti-Malware version 1.60.0.1800 Microsoft .NET Compact Framework 1.0 SP3 Developer Microsoft .NET Compact Framework 2.0 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Age of Empires II Microsoft Age of Empires II: The Conquerors Expansion Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Device Emulator version 1.0 - ENU Microsoft Document Explorer 2005 Microsoft National Language Support Downlevel APIs Microsoft Office Small Business Edition 2003 Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft SQL Server 2005 Mobile [ENU] Developer Tools Microsoft Visual C Runtime Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox 9.0.1 (x86 en-US) MSDN Library for Visual Studio 2005 MSVCRT MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) MSXML4 Parser NVIDIA Drivers NVIDIA nView Desktop Manager PCI SoftV92 Modem Platform PowerDVD Project64 1.6 Reg (DOFUS Audio Subsystem) RollerCoaster Tycoon 2 Triple Thrill Pack Security Update for CAPICOM (KB931906) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB917734) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB942615) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944533) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953838) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958215) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960714) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB963027) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB976325) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981350) Security Update for Windows XP (KB982381) Segoe UI Skype™ 3.6 SoundMAX Symantec Technical Support Web Controls System Requirements Lab The Weather Channel Desktop 6 Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925720) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB942840) Update for Windows XP (KB946627) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB976749) Update for Windows XP (KB978207) Update for Windows XP (KB980182) Ventrilo Client Ventrilo Server VIA Platform Device Manager VIA Rhine-Family Fast Ethernet Adapter VIA/S3G Display Driver Warcraft III: All Products WebEx Support Manager for Internet Explorer WebFldrs XP Windows Defender Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Live Writer Windows Media Player Firefox Plugin Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 WinRAR archiver Works Upgrade World of Warcraft WoW Model Exporter XviD MPEG-4 Video Codec . ==== Event Viewer Messages From Past Week ======== . 1/14/2012 10:50:20 AM, error: Service Control Manager [7034] - The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 1 time(s). 1/14/2012 10:40:46 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811} 1/12/2012 9:18:17 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP aswTdi EIO Fips intelppm TfFsMon TfSysMon 1/12/2012 9:05:23 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi EIO Fips intelppm IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip TfFsMon TfSysMon 1/12/2012 9:05:23 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning. 1/12/2012 9:05:23 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/12/2012 9:05:23 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning. 1/12/2012 9:05:23 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning. 1/12/2012 9:04:48 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E} 1/12/2012 9:04:38 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 1/12/2012 6:49:07 AM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the NVSvc service. 1/12/2012 6:48:06 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: TfFsMon TfSysMon 1/12/2012 6:48:06 AM, error: Service Control Manager [7000] - The Pure Networks Platform Service service failed to start due to the following error: The system cannot find the path specified. . ==== End Of File =========================== . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13 Run by [removed] at 16:47:17 on 2012-01-14 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.182 [GMT -6:00] . AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall Pro *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\VTTimer.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Java\jre6\bin\jucheck.exe . ============== Pseudo HJT Report =============== . uInternet Settings,ProxyServer = http=127.0.0.1:5555 uInternet Settings,ProxyOverride = uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {B9D1647F-A66A-4695-B249-07901A45FF59} - No File TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [VTTrayp] VTtrayp.exe mRun: [VTTimer] VTTimer.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} - hxxp://www.symantec.com/techsupp/activedata/nprdtinf.cab DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{3826337C-E293-4786-A1C1-D5C35F7E50F3} : DhcpNameServer = [removed] [removed] Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\0c4bchap.default\ FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q= FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll . ============= SERVICES / DRIVERS =============== . R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-17 165584] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-17 17744] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384] S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?] S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?] S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384] S3 LycoFltr;Lycosa Keyboard;c:\windows\system32\drivers\lycosa.sys –> c:\windows\system32\drivers\Lycosa.sys [?] S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?] S3 XDva276;XDva276;\??\c:\windows\system32\xdva276.sys –> c:\windows\system32\XDva276.sys [?] . =============== File Associations =============== . .exe=mdaw . =============== Created Last 30 ================ . 2012-01-14 16:51:10 388096 —-a-r- c:\documents and settings\owner\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-12-23 15:16:09 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2011-12-23 15:15:57 626688 —-a-w- c:\program files\mozilla firefox\msvcr80.dll 2011-12-23 15:15:57 548864 —-a-w- c:\program files\mozilla firefox\msvcp80.dll 2011-12-23 15:15:57 479232 —-a-w- c:\program files\mozilla firefox\msvcm80.dll 2011-12-23 15:15:57 43992 —-a-w- c:\program files\mozilla firefox\mozutils.dll 2011-12-23 15:15:56 97240 —-a-w- c:\program files\mozilla firefox\libEGL.dll 2011-12-23 15:15:56 814040 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll 2011-12-23 15:15:56 486360 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll 2011-12-23 15:15:56 2124760 —-a-w- c:\program files\mozilla firefox\mozjs.dll 2011-12-23 15:15:56 2106216 —-a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2011-12-23 15:15:56 1998168 —-a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2011-12-23 15:15:56 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll . ==================== Find3M ==================== . 2011-12-10 21:24:06 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-23 16:17:58 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . ============= FINISH: 16:49:25.81 =============== I would give you the GMER report, but every time I try to run it, my computer freezes up. Also, I've noticed that after I posted my topic here the ads suddenly disappeared, not showing up at all anymore or creating any interference.
Hello Geheimnis

every time I try to run it, my computer freezes up

No problem, we can try this one instead:

  • aswMBR


    • Download aswMBR.exe to your desktop.
    • Double click the aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions please select Yes.
    • Click the "Scan" button to start scan.

    [external image: Posted Image]

    • On completion of the scan click save log, save it to your desktop and post in your next reply.

    [external image: Posted Image]


    I would also like to see the reports generated from the following scans:

  • MGADiag


    • Please download MGADiag by clicking here and save it to your desktop.
    • Double click the [external image: Posted Image] icon on your desktop.
    • Push [external image: Posted Image]
    • Push [external image: Posted Image]
    • Go to Start -> Run and type in "Notepad"
    • Go to Edit -> Paste in notepad.
    • "x" out all of the numbers and letters in the line beginning with "Windows Product Key:"
    • Copy and paste that log here.

  • CKScanner


    • Download CKScanner by askey127 from here and save it to your Desktop.
    • Double click CKScanner.exe then click on Search For Files.
    • When the cursor hourglass disappears, click Save List To File.
    • A message box will verify the file saved.
    • Double click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply

    Post the logs in your next reply. If you encounter any problems with the scans just let me know.
Here is the MBR data for my computer: aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-17 14:20:34 —————————– 14:20:34.609 OS Version: Windows 5.1.2600 Service Pack 2 14:20:34.625 Number of processors: 1 586 0x409 14:20:34.625 ComputerName: AARON UserName: Owner 14:20:38.500 Initialize success 14:20:47.343 AVAST engine defs: 12011700 14:20:59.281 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12 14:20:59.281 Disk 0 Vendor: ST3802110A 3.AAH Size: 76319MB BusType: 3 14:20:59.453 Disk 0 MBR read successfully 14:20:59.453 Disk 0 MBR scan 14:20:59.828 Disk 0 Windows XP default MBR code 14:20:59.843 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76308 MB offset 63 14:20:59.890 Disk 0 scanning sectors +156280320 14:21:00.375 Disk 0 scanning C:\WINDOWS\system32\drivers 14:21:33.671 Service scanning 14:21:37.250 Modules scanning 14:22:33.000 Disk 0 trace - called modules: 14:22:33.046 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys 14:22:33.046 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f90ab8] 14:22:33.625 3 CLASSPNP.SYS[f86f705b] -> nt!IofCallDriver -> \Device\00000073[0x82fcb810] 14:22:33.625 5 ACPI.sys[f866d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-12[0x82f91d98] 14:22:34.765 AVAST engine scan C:\WINDOWS 14:22:50.843 AVAST engine scan C:\WINDOWS\system32 14:27:35.875 AVAST engine scan C:\WINDOWS\system32\drivers 14:27:56.593 AVAST engine scan C:\Documents and Settings\Owner 14:34:59.750 File: C:\Documents and Settings\Owner\Local Settings\temp\oiu0.9415787316010847.exe **INFECTED** Win32:Kryptik-GLG [Trj] 14:35:00.734 File: C:\Documents and Settings\Owner\Local Settings\temp\tue0.6597768169728868.exe **INFECTED** Win32:Kryptik-GLG [Trj] 14:41:47.031 AVAST engine scan C:\Documents and Settings\All Users 14:45:45.046 Scan finished successfully 14:52:11.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 14:52:11.781 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt" Next is the MGA data: Diagnostic Report (1.9.0027.0): —————————————– Windows Validation Data–> Validation Status: Genuine Validation Code: 0 Cached Validation Code: N/A Windows Product Key: *****-*****-9TRG9-2WKGX-37PGB Windows Product Key Hash: p01/iPqgobwGspyy8dgsBQ04vy4= Windows Product ID: 76477-OEM-2171037-49136 Windows Product ID Type: 3 Windows License Type: OEM System Builder Windows OS version: 5.1.2600.2.00010300.2.0.hom ID: {B97C55FE-B2F8-4976-AFF6-86DB7BC5862A}(3) Is Admin: Yes TestCab: 0x0 LegitcheckControl ActiveX: Registered, 1.7.69.2 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005 Resolution Status: N/A Vista WgaER Data–> ThreatID(s): N/A Version: N/A Windows XP Notifications Data–> Cached Result: 0 File Exists: Yes Version: 1.5.540.0 WgaTray.exe Signed By: Microsoft WgaLogon.dll Signed By: Microsoft OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 OGAExec.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 100 Genuine Microsoft Office Small Business Edition 2003 - 100 Genuine OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_70AFE6BE-656-80070057_E2AD56EA-815-80070057 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32) Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {B97C55FE-B2F8-4976-AFF6-86DB7BC5862A}1.9.0027.05.1.2600.2.00010300.2.0.homx32*****-*****-*****-*****-37PGB76477-OEM-2171037-491363S-1-5-21-1123561945-1897051121-839522115System manufacturerSystem Product NameAmerican Megatrends Inc.0503 20051226000000.000000+000236B30AF0184205D04090409Central Standard Time(GMT-06:00)03100 Licensing Data–> N/A Windows Activation Technologies–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: yes Marker string from BIOS: 13AC0:ASUSTeK Computer Inc|15ACA:GENUINE C&C INC Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005 OEM Activation 2.0 Data–> N/A Finally, here is the CKScanner information: CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\owner\desktop\bethany's goodies\phreaking\firecrackers.rtf scanner sequence 3.NA.11.GPLBJQ —– EOF —–
Hello Geheimnis

Thank you for the logs.

  • Combofix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the Combofix log in your next reply.
Here's the Combofix log. Sorry it's taking so long to reply.


ComboFix 12-01-19.02 - Owner 01/20/2012 14:43:43.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.163 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: COMODO Firewall Pro *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\g2ax_customer_downloadhelper_win32_x86.exe
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\Owner\Application Data\app
c:\documents and settings\Owner\Application Data\app\Jerakine_lang.dat
c:\documents and settings\Owner\Application Data\app\Jerakine_lang_vesrion.dat
c:\documents and settings\Owner\g2ax_customer_downloadhelper_win32_x86.exe
c:\documents and settings\Owner\Local Settings\Application Data\assembly\tmp
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\2TkkM.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\68e82mA.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\bEckhE4lP.jpg
c:\documents and settings\Owner\Local Settings\Temporary Internet Files\d728lR6H.jpg
c:\documents and settings\Owner\WINDOWS
c:\windows\system32\drivers\etc\hosts.ics
.
.
((((((((((((((((((((((((( Files Created from 2011-12-20 to 2012-01-20 )))))))))))))))))))))))))))))))
.
.
2012-01-17 20:52 . 2012-01-17 20:52 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2012-01-14 16:51 . 2012-01-14 16:51 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-12-23 15:16 . 2011-12-21 07:24 121816 —-a-w- c:\program files\Mozilla Firefox\components\browsercomps.dll
2011-12-23 15:15 . 2011-12-21 07:24 43992 —-a-w- c:\program files\Mozilla Firefox\mozutils.dll
2011-12-23 15:15 . 2011-12-21 04:30 626688 —-a-w- c:\program files\Mozilla Firefox\msvcr80.dll
2011-12-23 15:15 . 2011-12-21 04:30 548864 —-a-w- c:\program files\Mozilla Firefox\msvcp80.dll
2011-12-23 15:15 . 2011-12-21 04:30 479232 —-a-w- c:\program files\Mozilla Firefox\msvcm80.dll
2011-12-23 15:15 . 2011-12-21 07:24 97240 —-a-w- c:\program files\Mozilla Firefox\libEGL.dll
2011-12-23 15:15 . 2011-12-21 07:24 814040 —-a-w- c:\program files\Mozilla Firefox\mozsqlite3.dll
2011-12-23 15:15 . 2011-12-21 07:24 486360 —-a-w- c:\program files\Mozilla Firefox\libGLESv2.dll
2011-12-23 15:15 . 2011-12-21 07:24 2124760 —-a-w- c:\program files\Mozilla Firefox\mozjs.dll
2011-12-23 15:15 . 2011-12-21 07:24 15832 —-a-w- c:\program files\Mozilla Firefox\mozalloc.dll
2011-12-23 15:15 . 2011-12-21 04:30 2106216 —-a-w- c:\program files\Mozilla Firefox\D3DCompiler_43.dll
2011-12-23 15:15 . 2011-12-21 04:30 1998168 —-a-w- c:\program files\Mozilla Firefox\d3dx9_43.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-12-10 21:24 . 2008-11-14 01:12 20464 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-11-23 16:17 . 2011-09-08 22:23 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-21 07:24 . 2011-12-23 15:16 121816 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-09-07 2838912]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-08-17 13877248]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"VTTrayp"="VTtrayp.exe" [2005-03-11 147456]
"VTTimer"="VTTimer.exe" [2005-03-07 53248]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768]
"nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2009-08-13 1657376]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 61952]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^LimeWire On Startup.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\LimeWire On Startup.lnk
backup=c:\windows\pss\LimeWire On Startup.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ArcSoft Connection Service]
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [BU]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUS SmartDoctor]
2007-04-24 03:20 1114112 -c–a-w- c:\program files\ASUS\SmartDoctor\SmartDoctor.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GamerOSD]
2007-02-14 15:42 380928 -c–a-w- c:\program files\ASUS\GamerOSD\GamerOSD.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
2003-12-22 13:38 241664 -c–a-w- c:\program files\HP\hpcoretech\hpcmpmgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2004-02-18 17:55 49152 -c–a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
2004-03-04 14:46 172032 -c–a-w- c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.icd"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/17/2010 11:12 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/17/2010 11:12 PM 17744]
S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?]
S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S3 LycoFltr;Lycosa Keyboard;c:\windows\system32\Drivers\Lycosa.sys –> c:\windows\system32\Drivers\Lycosa.sys [?]
S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\TfNetMon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?]
S3 XDva276;XDva276;\??\c:\windows\system32\XDva276.sys –> c:\windows\system32\XDva276.sys [?]
.
Contents of the 'Scheduled Tasks' folder
.
2010-12-03 c:\windows\Tasks\dfrg.job
- c:\windows\system32\dfrg.msc [2004-08-04 12:00]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\0c4bchap.default\
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?ie=UTF-8&oe;=UTF-8&sourceid;=navclient&gfns;=1&q;=
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-iTunesHelper - c:\program files\iTunes\iTunesHelper.exe
MSConfigStartUp-NeroFilterCheck - c:\windows\system32\NeroCheck.exe
MSConfigStartUp-nmapp - c:\program files\Pure Networks\Network Magic\nmapp.exe
MSConfigStartUp-nmctxth - c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
MSConfigStartUp-PhotoShow Deluxe Media Manager - c:\progra~1\Nero\data\Xtras\mssysmgr.exe
AddRemove-CutePDF Writer Installation - c:\program files\Acro Software\CutePDF Writer\uninscpw.exe
AddRemove-XP Display - c:\progra~1\S3\UChromeP\s3minset.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-01-20 15:01
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-01-20 15:09:28
ComboFix-quarantined-files.txt 2012-01-20 21:09
ComboFix2.txt 2010-03-18 02:46
ComboFix3.txt 2010-02-25 03:07
.
Pre-Run: 13,326,696,448 bytes free
Post-Run: 13,341,749,248 bytes free
.
- - End Of File - - FE369424FE9C400143575F7741852B58
Hello Geheimnis

Thank you for the log.

Since you do not have XP SP3 installed at this time, please keep your web activity to an absolute minimum (you'll be a sitting duck for malware without SP3). Once we confirm that the machine is clean we will get you updated.

  • Please work your way through the following steps


    • Open Notepad (Click on "Start" and then on "Run" and type notepad
    • Copy the text provided in the code box below and paste it into Notepad (make sure you include REGEDIT4).

      REGEDIT4
      
      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
      "ProxyServer"=-
      "ProxyOverride"=-
    • Save the text in Notepad as fix.reg, change the "Save as Type" to "All Files" and select your desktop as the save location.
    • An icon will appear on your desktop called "fix.reg".
    • Double click on the "fix.reg" icon.
    • You will be asked if you wish to merge the contents of the file to the registry. Click "Yes" or "OK".
    • You should then receive a message informing you that the merge was successful.
    • Next, please reboot your machine.
    • Once you have rebooted, you may delete the fix.reg file.

  • Temporary File Cleaner


    • Download TFC to your desktop.
    • Close any open windows.
    • Double click the TFC icon to run the program.
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish.
    • Once complete it should automatically reboot your machine.
    • If your machine does not reboot automatically, manually reboot to ensure a complete clean.
    • Note: After running TFC your machine may take slightly longer to boot the first time. This is normal.

  • MalwareBytes AntiMalware


    • I can see that you have MBAM installed.
    • Double click on your MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • aswMBR


    • Scan your machine with aswMBR as you did before and post the log in your next reply.

    Please post the MBAM log and the aswMBR log in your next reply.
Here are the reports of MBAM(it found something and removed it thankfully) and the aswMBR, respectively: Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Database version: v2012.01.23.01 Windows XP Service Pack 2 x86 NTFS Internet Explorer 6.0.2900.2180 Owner :: AARON [administrator] 1/22/2012 7:55:11 PM mbam-log-2012-01-22 (19-55-11).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 179024 Time elapsed: 22 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\Software\SolutionAV (Rogue.AntivirSolutionPro) -> Quarantined and deleted successfully. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) aswMBR version 0.9.9.1297 Copyright© 2011 AVAST Software Run date: 2012-01-22 20:24:33 —————————– 20:24:33.812 OS Version: Windows 5.1.2600 Service Pack 2 20:24:33.812 Number of processors: 1 586 0x409 20:24:33.812 ComputerName: AARON UserName: Owner 20:24:41.609 Initialize success 20:24:48.140 AVAST engine defs: 12012201 20:25:10.093 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-12 20:25:10.093 Disk 0 Vendor: ST3802110A 3.AAH Size: 76319MB BusType: 3 20:25:10.187 Disk 0 MBR read successfully 20:25:10.187 Disk 0 MBR scan 20:25:10.187 Disk 0 Windows XP default MBR code 20:25:10.203 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 76308 MB offset 63 20:25:10.296 Disk 0 scanning sectors +156280320 20:25:10.875 Disk 0 scanning C:\WINDOWS\system32\drivers 20:26:24.281 Service scanning 20:26:28.593 Modules scanning 20:28:30.953 Disk 0 trace - called modules: 20:28:30.968 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaide.sys 20:28:30.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f90ab8] 20:28:31.484 3 CLASSPNP.SYS[f86f705b] -> nt!IofCallDriver -> \Device\00000073[0x82fcb810] 20:28:31.484 5 ACPI.sys[f866d620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-12[0x82f91d98] 20:28:36.265 AVAST engine scan C:\WINDOWS 20:29:31.390 AVAST engine scan C:\WINDOWS\system32 20:40:40.718 AVAST engine scan C:\WINDOWS\system32\drivers 20:41:38.421 AVAST engine scan C:\Documents and Settings\Owner 20:57:39.625 AVAST engine scan C:\Documents and Settings\All Users 21:00:40.796 Scan finished successfully 21:51:29.500 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat" 21:51:29.500 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt" Also, what is XP SP3?
Hello Geheimnis

Thank you for the logs.

Also, what is XP SP3?

Service Pack 3 is the most up-to-date Service Pack for Windows XP. At present, you appear to have SP2 installed. Microsoft ended support for SP2 several months ago now.

Lets continue:


  • Please un-install your outdated Java


    • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • Click on "remove a program". A list of currently installed programs will be displayed.
    • Find the "J2SE Runtime Environment 5.0 Update 8" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.
    • Repeat for Java™ 6 Update 3 and Java™ 6 Update 5.
    • NOTE: DO NOT uninstall Java™ 6 Update 13.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.

  • Please run the following scan


    • Note:Internet Explorer is preferred for this scan, although it will run with other browsers.
    • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
    • Please disable your real time security programs before performing the scan.


    • Scan your system with Eset Online Scanner
    • Place a check mark in the box YES, I accept the Terms Of Use.
    • Click the [external image: Posted Image] button.
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.


    • Check [external image: Posted Image]
    • Click the [external image: Posted Image] button.
    • Accept any security warnings from your browser.
    • Check [external image: Posted Image]
    • Make sure that the option to "Remove Found Threats" is UN checked.
    • Push the "Start" button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push [external image: Posted Image]
    • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • Push the [external image: Posted Image] button.
    • Push [external image: Posted Image]

    Please post the ESET log and a new set of DDS logs in your next reply.
Here are the DDS logs and ESET report, respectively: . DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_30 Run by [removed] at 22:26:30 on 2012-01-26 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.299 [GMT -6:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: COMODO Firewall Pro *Enabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\system32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [VTTrayp] VTtrayp.exe mRun: [VTTimer] VTTimer.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [nwiz] c:\program files\nvidia corporation\nview\nwiz.exe /install mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab DPF: {34F12AFD-E9B5-492A-85D2-40FA4535BE83} - hxxp://www.symantec.com/techsupp/activedata/nprdtinf.cab DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} - hxxps://www-secure.symantec.com/techsupp/asa/ss/sa/sa_cabs/tgctlsr.cab DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} - hxxp://www.acclaim.com/cabs/acclaim_v4.cab DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/optimize2/pcpitstop2.dll TCP: DhcpNameServer = [removed] [removed] TCP: Interfaces\{3826337C-E293-4786-A1C1-D5C35F7E50F3} : DhcpNameServer = [removed] [removed] Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\administrator\application data\mozilla\firefox\profiles\ura4ijfv.default\ FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll . ============= SERVICES / DRIVERS =============== . S0 TfFsMon;TfFsMon;c:\windows\system32\drivers\tffsmon.sys –> c:\windows\system32\drivers\TfFsMon.sys [?] S0 TfSysMon;TfSysMon;c:\windows\system32\drivers\tfsysmon.sys –> c:\windows\system32\drivers\TfSysMon.sys [?] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-17 165584] S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-17 17744] S2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384] S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-17 40384] S3 LycoFltr;Lycosa Keyboard;c:\windows\system32\drivers\lycosa.sys –> c:\windows\system32\drivers\Lycosa.sys [?] S3 TfNetMon;TfNetMon;\??\c:\windows\system32\drivers\tfnetmon.sys –> c:\windows\system32\drivers\TfNetMon.sys [?] S3 XDva276;XDva276;\??\c:\windows\system32\xdva276.sys –> c:\windows\system32\XDva276.sys [?] . =============== Created Last 30 ================ . 2012-01-23 16:21:17 ——– d—–w- c:\program files\ESET 2012-01-23 16:14:50 476904 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2012-01-23 16:14:50 472808 —-a-w- c:\windows\system32\deployJava1.dll . ==================== Find3M ==================== . 2011-12-10 21:24:06 20464 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-23 16:17:58 414368 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-11-10 09:27:10 73728 —-a-w- c:\windows\system32\javacpl.cpl . ============= FINISH: 22:28:15.89 =============== C:\System Volume Information\_restore{7B85E15E-B024-4AF2-BC3E-ED738362DB0D}\RP954\A0207349.exe a variant of Win32/Kryptik.YWO trojan
Hello Geheimnis

ESET has detected an infected system restore point. This restore point will be removed when we remove our tools and cannot cause harm to your machine (unless you perform a system restore).

How is the machine running now?
It's running fine JonTom. In fact it might be running better than it was before the infection. However, my husband pointed out that the computer has avast! and comodo on it, saying the two interfere with each other. Is this true?
Hello Geheimnis

Your latest DDS log appears to be clean!

It's running fine JonTom. In fact it might be running better than it was before the infection.

Thats what we like to hear :)

my husband pointed out that the computer has avast! and comodo on it, saying the two interfere with each other.
Is this true?

Avast! real time antivirus and the Comodo Firewall are both good products (and you need do need an antivirus AND firewall on your machine for adequate protection). I would'nt think that there would be any problem running them together (if there were conflicts between the two programs you would soon know about it as you would most likely be receiving messages from both).

Should you wish to consider an alternative security program or combination of programs, I will link you to some recommendations in my closing notes.

Lets remove our tools and get the machine updated with XP SP3:

  • Please Uninstall Combofix


    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • Removal of Tools

    • You no longer need DDS, GMER, aswMBR, MGADiag or CKScanner. Please delete them from your machine.

  • Please install XP Service Pack 3


    • XP Service Pack 3 contains many more security features that are not present in Service Pack 2.
    • Instructions for downloading XP Service Pack 3 can be found here

    If you have any problems getting SP3 installed let me know. If everything goes okay with the installation continue with the updates below:

  • Your Adobe Reader is out of date


    • You can obtain the latest version of Adobe Reader from here, and the latest version of Flash Player from here.
    • For more information and links to Adobe updates and downloads click here.


    Once you have completed the above steps you should be good to go! If you have any further questions, please feel free to ask.

  • Finally, please take the time to read through the information provided below:

    Enhance your System Security

    • For an excellent list of free anti virus software, free online virus scanners, free spyware detection/removal and free firewalls, click here.

    • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system. When using "on demand" scanners, first update the detection signature files, then disconnect from the internet and disable your resident security program before running the scan.
    • Once complete, remember to re-engage your resident security before going online.

    Web Browsers and Browser Security

    Firefox
    • You can download Firefox from here.

    No-Script
    • If you use Firefox as your default browser, No-Script can provide additional security by preventing malicious scripts from being executed on your system.
    • You can download No-Script by clicking here.

    Internet Explorer
    • The newest version of Internet Explorer is available from here.
    • Please Note: IE9 is not configured to run on XP machines.

    SpywareBlaster
    • If you use Internet Explorer as your default browser, SpywareBlaster would be a valuable addition to your online security.
    • SpywareBlaster prevents malicious ActiveX objects from being downloaded onto your system.
    • You can download SpywareBlaster by clicking here.

    Web of Trust
    • When using search engines, Web of Trust provides you with an easy way of telling the good sites from the bad and is compatible with both Firefox and Internet Explorer.
    • Coloured symbols are displayed next to search results, giving you more confidence in the links you choose to click on: Green (To go), Yellow (Caution) and Red (Stop).
    • You can download Web of Trust by clicking here.

    Keep your Software Updated
    • Outdated software can sometimes have vulnerabilities that are exploitable by malware.
    • Check if there are available updates for your installed software with Secunia's Online Software Inspector by clicking here.

    Passwords
    • Learn how to create strong passwords by clicking here and test the strength of the passwords you already use by clicking here.

    General Reading

    Learn How To Combat Malware
    • Would you like to learn how to fight back against malware and help others? Enroll at the What The Tech (Formerly Tom Coyotes) Malware Classroom by clicking here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI