This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"System Check" took over PC [Solved]

55 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

using MSE for main antivirus ware. On my XP PC, "System Check" somehow got installed, PC started showing alerts. Eventually desktop icons, programs, etc disappeared. MSE and MBam cleaned up some trojans, but MBam wont update or connect online, and problem still existed. I tried some online fixes, using Unhide.exc and Rkill.exe with PC in Safe Mode and running SuperAntispyware (which found problems but didnt fix the real issue). TDSSKiller would not run even when renamed.

Cant connect to internet, so I'm using another PC. I downloaded all 3 preliminary reporting tools and transfered to PC with usb drive. I'm still running Rkill.exe to get the PC to respond, otherwise it locks up. I was only able to run Hijackthis:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:25:08 PM, on 2/22/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\program files\real\realplayer\update\realsched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Dave\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 94.63.147.15 www.bing.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startup
O4 - HKLM\..\Run: [DvhhCCFbLujqW.exe] C:\Documents and Settings\All Users\Application Data\DvhhCCFbLujqW.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "c:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1190818361731
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} (Java Plug-in 1.6.0_07) -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

–
End of file - 5402 bytes
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
Run RKill.

Please post the log generated by MBAM. You can locate it in the Logs tab of the program.

  • HijackThis

    • Open HijackThis.
    • Click Scan to produce a log.
    • Place a check mark beside each one of the following items (if still present):

      O4 - HKLM\..\Run: [DvhhCCFbLujqW.exe] C:\Documents and Settings\All Users\Application Data\DvhhCCFbLujqW.exe
    • Now, with all the items selected, and all windows closed except for HJT, delete them by clicking the Fix checked button. Close the HijackThis window.
  • Farbar Service Scanner

    Please download Farbar Service Scanner and run it on the computer with the issue.

    • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please post the log in your next reply.
Thanks for any help. I did do one thing, which I can reverse. I believe Unhide.exe let me see my desktop, and I could see "System Check" installed a desktop shortcut. I followed that into an Application folder. I removed the Exe, also taking some similarly named files, and an Exe which had a red circle with an x icon (icon popped up alot when the PC was running). I dragged them into a desktop folder rather than delete them. They were all created on the same day the trouble started. If I have to use usb flash drives, how can I make sure I'm not spreading the infection back to my good PC? I'll see if I can find the Mbam log. Should I run in safe mode?
Hi dave e,

Please run all tools in normal mode.

To help prevent the spread of infection via your USB:

Download Flash_Disinfector.exe by sUBs from HERE and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.
my clean PC runs W7 64 bit, and when I tried to run Flash Disinfector, had some compatibility windows pop up. Didnt prompt me to do anything, so I dont know if it ever ran. Managed to run Hijackthis and Farbar on the sick PC. I'm posting 3 MBam logs beneath the Farbar log. Btw, here's what I previously moved to a separate folder from Application Data when I followed the System Check shortcut (the last EXE being the only item you requested to check in the Hijackthis scan): "C:\Documents and Settings\All Users\Application Data\5NnIjyWlYOwvbB.exe" system check icon 5NnIjyWlYOwvbB.exe ~5NnIjyWlYOwvbBr ~5NnIjyWlYOwvbB 5NnIjyWlYOwvbB DvhhCCFbLujqW.exe ===================================================================== Farbar Service Scanner Version: 22-02-2012 Ran by [removed] (administrator) on 24-02-2012 at 09:57:11 Running from "C:\Documents and Settings\Dave\Desktop" Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. There is no connection to network. Attempt to access Google IP returned error: Google IP is unreachable Attempt to access Yahoo IP returend error: Yahoo IP is unreachable Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys [2005-08-16 05:18] - [2008-06-20 06:51] - 0361600 ___AH (Microsoft Corporation) CBEEBEB899E31EF52B962CB31FC8CA5C C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit C:\WINDOWS\system32\netman.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\srsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit C:\WINDOWS\system32\wscsvc.dll => MD5 is legit C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINDOWS\system32\wuauserv.dll => MD5 is legit C:\WINDOWS\system32\qmgr.dll => MD5 is legit C:\WINDOWS\system32\es.dll => MD5 is legit C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit C:\WINDOWS\system32\svchost.exe => MD5 is legit C:\WINDOWS\system32\rpcss.dll => MD5 is legit C:\WINDOWS\system32\services.exe => MD5 is legit Extra List: ======= Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3) 0x0A0000000400000001000000020000000300000008000000090000000A00000005000000060000 0007000000 IpSec Tag value is correct. **** End of log **** =============================================================================== Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.13.06 Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking) Internet Explorer 8.0.6001.18702 Dave :: DGL5F091 [administrator] Protection: Disabled 2/22/2012 9:41:35 AM mbam-log-2012-02-22 (09-41-35).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 227604 Time elapsed: 9 minute(s), 27 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 2 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dplaysvr (Trojan.QHost.Gen) -> Data: C:\Documents and Settings\Dave\Application Data\dplaysvr.exe -> Quarantined and deleted successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|dplaysvr (Trojan.QHost.Gen) -> Data: C:\Documents and Settings\Dave\Application Data\dplaysvr.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 9 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowControlPanel (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowRun (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System|DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 1 C:\Recycle.Bin (Trojan.Spyeyes) -> Quarantined and deleted successfully. Files Detected: 2 C:\Documents and Settings\Dave\Application Data\dplaysvr.exe (Trojan.QHost.Gen) -> Quarantined and deleted successfully. C:\Documents and Settings\Dave\Application Data\dplayx.dll (Trojan.QHost.BG) -> Quarantined and deleted successfully. (end) ============================================================================== Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.13.06 Windows XP Service Pack 3 x86 NTFS (Safe Mode/Networking) Internet Explorer 8.0.6001.18702 Dave :: DGL5F091 [administrator] Protection: Disabled 2/22/2012 10:27:44 AM mbam-log-2012-02-22 (10-27-44).txt Scan type: Full scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 355501 Time elapsed: 56 minute(s), 24 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 7 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowControlPanel (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowRun (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer|NoDesktop (PUM.Hidden.Desktop) -> Bad: (1) Good: (0) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1478\A0400557.exe (Trojan.Backdoor) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP1478\A0400604.exe (Affiliate.Downloader) -> Quarantined and deleted successfully. (end) ============================================================================= Malwarebytes Anti-Malware (Trial) 1.60.1.1000 www.malwarebytes.org Database version: v2012.02.13.06 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 Dave :: DGL5F091 [administrator] Protection: Enabled 2/22/2012 6:53:53 PM mbam-log-2012-02-22 (18-53-53).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 228193 Time elapsed: 15 minute(s), 18 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 6 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowControlPanel (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowMyDocs (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowRun (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully. Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ================================================================================
Yes, Flash Disinfector is intended for XP machines. For Vista/7, you can install Autorun Eater, plug in your USB devices, and it will detect suspicious autorun.inf files. You will need it running in your system tray before you plug in your device. Unlike Flash Disinfector, it doesn't put a dummy autorun.inf into your drives, so you'll need Autorun Eater running every time assuming the infected machine keeps placing a bad autorun.inf into your USB device.

Please re-run Farbar Service Scanner
Type the following in the edit box after "Search:".

tcpip.sys

Click "Search Files" button and post the log created (FSS.txt) in your next reply.

—-

NEXT:


Press the WinKey +R to open a run box > type in CMD to open a command prompt.

Type in the following command in the command prompt and press Enter.


netsh int ip reset reset.log

Then also type the following command and hit enter.

netsh winsock reset catalog

Once that completes then restart the system and see then if you are able to get online.
had to do a search for Mozilla as it's being hidden by the malware. Connected for the moment, but the online window winked out like when the malware started before. Here's the Farbar log: Farbar Service Scanner Version: 22-02-2012 Ran by [removed] (administrator) on 24-02-2012 at 19:19:46 Microsoft Windows XP Professional Service Pack 3 (X86) ************************************************ ======== Search: "tcpip.sys" ========= C:\WINDOWS\system32\drivers\tcpip.sys [2005-08-16 05:18] - [2008-06-20 06:51] - 0361600 ___AH (Microsoft Corporation) CBEEBEB899E31EF52B962CB31FC8CA5C C:\WINDOWS\system32\dllcache\tcpip.sys [2008-06-20 06:51] - [2008-06-20 06:51] - 0361600 ____H (Microsoft Corporation) 9AEFA14BD6B182D61E3119FA5F436D3D C:\WINDOWS\ServicePackFiles\i386\tcpip.sys [2008-09-24 08:42] - [2008-04-13 14:20] - 0361344 ____H (Microsoft Corporation) 93EA8D04EC73A85DB02EB8805988F733 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys [2009-04-20 14:18] - [2008-06-20 05:45] - 0360320 ___HC (Microsoft Corporation) 2A5554FC5B1E04E131230E3CE035C3F9 C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys [2008-06-20 06:59] - [2008-06-20 06:59] - 0361600 ___AH (Microsoft Corporation) AD978A1B783B5719720CFF204B666C8E C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys [2008-06-20 06:51] - [2008-06-20 06:51] - 0361600 ___AH (Microsoft Corporation) 9AEFA14BD6B182D61E3119FA5F436D3D C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys [2008-06-20 05:44] - [2008-06-20 05:44] - 0360960 ___AH (Microsoft Corporation) 744E57C99232201AE98C49168B918F48 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys [2007-10-30 11:53] - [2007-10-30 11:53] - 0360832 ___AH (Microsoft Corporation) 64798ECFA43D78C7178375FCDD16D8C8 C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys [2006-04-20 07:18] - [2006-04-20 07:18] - 0360576 ___AH (Microsoft Corporation) B2220C618B42A2212A59D91EBD6FC4B4 C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys [2008-06-20 06:59] - [2008-06-20 06:59] - 0361600 ___AH (Microsoft Corporation) AD978A1B783B5719720CFF204B666C8E C:\i386\tcpip.sys [2007-09-26 20:22] - [2004-08-10 06:00] - 0359040 ___AH (Microsoft Corporation) 9F4B36614A0FC234525BA224957DE55C ====== End Of Search ======
I see you have already run unhide.exe, you should still have this program on your desktop, if not please download it again from here and run it.

NEXT:

Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer.

***************************************************

Download ComboFix from one of these locations:

Link 1
Link 2


**Note: It is important that it is saved directly to your desktop**

——————————————————————–

Note: If your machine already has the recovery console installed, then you can skip the instructions for its manual installation.


With malware infections being as they are today, it's strongly recommended to have the Windows Recovery Console pre-installed on your machine before doing any malware removal.

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.


Go to Microsoft's website => http://support.microsoft.com/kb/310994

Scroll down to Step 1, and select the download that's appropriate for your Operating System. Download the file & save it as it's originally named.

Note: If you have SP3, use the SP2 package.

The appropriate download for your particular machine is HERE if you have trouble finding it.


———————————————————————

Transfer all files you just downloaded, to the desktop of the infected computer.

——————————————————————–


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[external image: Posted Image]


  • Drag the setup package onto ComboFix.exe and drop it.

  • Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console.


    [external image: Posted Image]


  • At the next prompt, click 'Yes' to run the full ComboFix scan.

  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.
my PC is Dell and am using XP Media Center Edition. Dell stored the installation XP files on the HD - there are no separate discs. I believe I have SP3 installed at this point. The direct link (http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=1000) indicates it's for SP2. Anyway, there's references to installation discs - since I dont have installation discs, can I still use Recovery console? I will wait to run Combofix until I hear from you.
XP Media Center Edition is based on XP Professional. If you have SP3, then SP2 (the one you linked) is the appropriate download for your machine.

And yes, you can use the Recovery Console without the installation disks. Microsoft's Recovery Console is not to be confused with OEM manufacturer's recovery disks/partitions. Unlike the OEM options, RC does not perform a destructive reinstall of the machine.

Once it's installed it will list itself in your boot menu. Selecting the "Recovery Console" from the Boot Menu will take you to a logon menu where only an Administrator can login to conduct a REPAIR not Destroy, of the Operating System.

Just follow my instructions by dragging the setup package into the ComboFix icon on the desktop of your infected machine and it will install itself after you go through the prompts.

I would also recommend you read the ComboFix User Guide to know what to expect before running it.
Combofix has been running (I guess) for several hours. Screen is black. I googled to get an idea if this length of time was normal - some say yes, some say no.
If no progress seems to have been made at this point, please restart your computer and run ComboFix in Safe Mode. If on its first run ComboFix reported that the Recovery Console was successfully installed, please just run ComboFix by double-clicking its icon on your desktop.
restarted Combofix in Safe Mode. I dont believe Combofix ever indicated Recovery Console was previously installed, but it was installed last year. After starting in Safe Mode, I get another option: to run Recovery Console or XP Media Center. I chose Recovery, but nothing much happened, so I escaped out and chose XP Media Center.
Combofix seemed to run as described up until the blue window that says "This might take 10 minute or more". Stayed like that for a couple hours. I rebooted and left it running over night. Same thing (fan roaring all night). Should I have started RKill before hand?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI