This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP Security 2012 Infection [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi: So here's what's happened. 1. I tried everything with Symantec unsuccessfully so I finally just uninstalled it. 2. I then ran Combo Fix. It did need to download the recovery console. After it did so, it began to run. 3. On my screen in the command box I saw it report that it had completed 5 steps. At that point I walked away from the computer for less than 10 minutes and returned to find a BSOD. I hard shut down and rebooted. 4. Upon boot up I received a MS Windows message that the system has recovered from a serious error. The error signature and technical info on the error are in the attached error.zip 5. I looked for Combofix.txt in c:\ and the file was not present. The 3 new files in that location this morning are hyberfil.sys pagefile.sys boot.ini 6. Below is the most recent copy of the TDSSKiller log. 7. I think that is about it for now. Thanks again for your help. Harold 17:26:16.0599 2124 TDSS rootkit removing tool [removed] Feb 29 2012 14:02:24 17:26:22.0998 2124 ============================================================ 17:26:22.0998 2124 Current date / time: 2012/03/02 17:26:22.0998 17:26:22.0998 2124 SystemInfo: 17:26:22.0998 2124 17:26:22.0998 2124 OS Version: 5.1.2600 ServicePack: 2.0 17:26:22.0998 2124 Product type: Workstation 17:26:22.0998 2124 ComputerName: HG-LATITUDE 17:26:22.0998 2124 UserName: Harold 17:26:22.0998 2124 Windows directory: C:\WINDOWS 17:26:22.0998 2124 System windows directory: C:\WINDOWS 17:26:22.0998 2124 Processor architecture: Intel x86 17:26:22.0998 2124 Number of processors: 1 17:26:22.0998 2124 Page size: 0x1000 17:26:22.0998 2124 Boot type: Normal boot 17:26:22.0998 2124 ============================================================ 17:26:26.0393 2124 Drive \Device\Harddisk0\DR0 - Size: 0x174A446000 (93.16 Gb), SectorSize: 0x200, Cylinders: 0x2F81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 17:26:26.0433 2124 \Device\Harddisk0\DR0: 17:26:26.0453 2124 MBR used 17:26:26.0453 2124 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xBA50E02 17:26:26.0713 2124 Initialize success 17:26:26.0713 2124 ============================================================ 17:26:29.0127 3436 ============================================================ 17:26:29.0127 3436 Scan started 17:26:29.0127 3436 Mode: Manual; 17:26:29.0127 3436 ============================================================ 17:26:29.0768 3436 Abiosdsk - ok 17:26:29.0788 3436 abp480n5 - ok 17:26:29.0848 3436 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys 17:26:29.0848 3436 ACPI - ok 17:26:29.0888 3436 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 17:26:29.0898 3436 ACPIEC - ok 17:26:29.0908 3436 adpu160m - ok 17:26:29.0968 3436 aec (841f385c6cfaf66b58fbd898722bb4f0) C:\WINDOWS\system32\drivers\aec.sys 17:26:29.0968 3436 aec - ok 17:26:30.0028 3436 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys 17:26:30.0028 3436 AFD - ok 17:26:30.0038 3436 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys 17:26:30.0048 3436 agp440 - ok 17:26:30.0068 3436 Aha154x - ok 17:26:30.0088 3436 aic78u2 - ok 17:26:30.0098 3436 aic78xx - ok 17:26:30.0128 3436 AliIde - ok 17:26:30.0148 3436 amsint - ok 17:26:30.0218 3436 ApfiltrService (2aa99fd81693729da66e38dbc108a704) C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 17:26:30.0228 3436 ApfiltrService - ok 17:26:30.0339 3436 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys 17:26:30.0369 3436 Arp1394 - ok 17:26:30.0389 3436 asc - ok 17:26:30.0399 3436 asc3350p - ok 17:26:30.0419 3436 asc3550 - ok 17:26:30.0469 3436 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 17:26:30.0479 3436 AsyncMac - ok 17:26:30.0529 3436 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys 17:26:30.0529 3436 atapi - ok 17:26:30.0549 3436 Atdisk - ok 17:26:30.0589 3436 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 17:26:30.0609 3436 Atmarpc - ok 17:26:30.0669 3436 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 17:26:30.0669 3436 audstub - ok 17:26:30.0789 3436 b57w2k (b9543b0c771feab7ca095303007a159c) C:\WINDOWS\system32\DRIVERS\b57xp32.sys 17:26:30.0799 3436 b57w2k - ok 17:26:30.0859 3436 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 17:26:30.0859 3436 Beep - ok 17:26:30.0899 3436 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 17:26:30.0909 3436 cbidf2k - ok 17:26:30.0939 3436 cd20xrnt - ok 17:26:30.0969 3436 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 17:26:30.0980 3436 Cdaudio - ok 17:26:31.0040 3436 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys 17:26:31.0040 3436 Cdfs - ok 17:26:31.0100 3436 Cdr4_xp (837eef65af62d4e8a37c41d3879f7274) C:\WINDOWS\system32\drivers\Cdr4_xp.sys 17:26:31.0110 3436 Cdr4_xp - ok 17:26:31.0180 3436 Cdralw2k (579da2f9f5401f55dae2cf8779d61dfc) C:\WINDOWS\system32\drivers\Cdralw2k.sys 17:26:31.0180 3436 Cdralw2k - ok 17:26:31.0220 3436 Cdrom (066caf1fc1dfbf468a7610d77b7e0f01) C:\WINDOWS\system32\DRIVERS\cdrom.sys 17:26:31.0230 3436 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\cdrom.sys. Real md5: 066caf1fc1dfbf468a7610d77b7e0f01, Fake md5: e9c58e930283d5b8f1b1772698e8c99b 17:26:31.0230 3436 Cdrom ( Virus.Win32.ZAccess.k ) - infected 17:26:31.0230 3436 Cdrom - detected Virus.Win32.ZAccess.k (0) 17:26:31.0310 3436 cdudf_xp (cfd81f2140193fc7f1812e6d6eaf6795) C:\WINDOWS\system32\drivers\cdudf_xp.sys 17:26:31.0320 3436 cdudf_xp - ok 17:26:31.0340 3436 Changer - ok 17:26:31.0410 3436 CmBatt (4266be808f85826aedf3c64c1e240203) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 17:26:31.0420 3436 CmBatt - ok 17:26:31.0430 3436 CmdIde - ok 17:26:31.0450 3436 Compbatt (df1b1a24bf52d0ebc01ed4ece8979f50) C:\WINDOWS\system32\DRIVERS\compbatt.sys 17:26:31.0460 3436 Compbatt - ok 17:26:31.0490 3436 Cpqarray - ok 17:26:31.0510 3436 dac2w2k - ok 17:26:31.0520 3436 dac960nt - ok 17:26:31.0630 3436 DevUpper (913938a5382bfb2487aacaea408a14d2) C:\WINDOWS\system32\DRIVERS\tiumflt.sys 17:26:31.0640 3436 DevUpper - ok 17:26:31.0751 3436 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys 17:26:31.0771 3436 Disk - ok 17:26:31.0831 3436 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys 17:26:31.0861 3436 dmboot - ok 17:26:31.0881 3436 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys 17:26:31.0901 3436 dmio - ok 17:26:31.0941 3436 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 17:26:31.0951 3436 dmload - ok 17:26:32.0061 3436 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys 17:26:32.0061 3436 DMusic - ok 17:26:32.0081 3436 dpti2o - ok 17:26:32.0101 3436 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys 17:26:32.0101 3436 drmkaud - ok 17:26:32.0161 3436 dvd_2K (677829f7010768eeeed8d0083e510dab) C:\WINDOWS\system32\drivers\dvd_2K.sys 17:26:32.0161 3436 dvd_2K - ok 17:26:32.0321 3436 eeCtrl (75e8b69f28c813675b16db357f20720f) C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys 17:26:32.0321 3436 eeCtrl - ok 17:26:32.0361 3436 EraserUtilRebootDrv (720b18d76de9e603b626dfcd6f1fca7c) C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 17:26:32.0361 3436 EraserUtilRebootDrv - ok 17:26:32.0482 3436 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys 17:26:32.0492 3436 Fastfat - ok 17:26:32.0532 3436 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\drivers\Fdc.sys 17:26:32.0542 3436 Fdc - ok 17:26:32.0622 3436 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys 17:26:32.0622 3436 Fips - ok 17:26:32.0642 3436 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\drivers\Flpydisk.sys 17:26:32.0652 3436 Flpydisk - ok 17:26:32.0712 3436 FltMgr (157754f0df355a9e0a6f54721914f9c6) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 17:26:32.0732 3436 FltMgr - ok 17:26:32.0792 3436 FsUsbExDisk (790a4ca68f44be35967b3df61f3e4675) C:\WINDOWS\system32\FsUsbExDisk.SYS 17:26:32.0802 3436 FsUsbExDisk - ok 17:26:32.0882 3436 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 17:26:32.0882 3436 Fs_Rec - ok 17:26:32.0902 3436 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 17:26:32.0912 3436 Ftdisk - ok 17:26:32.0982 3436 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys 17:26:32.0982 3436 Gpc - ok 17:26:33.0022 3436 GTICARD (b14d8f5dedf7c495c7d3104d58e1d31c) C:\WINDOWS\system32\DRIVERS\gticard.sys 17:26:33.0032 3436 GTICARD - ok 17:26:33.0083 3436 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys 17:26:33.0083 3436 HidUsb - ok 17:26:33.0093 3436 hpn - ok 17:26:33.0123 3436 HSFHWICH (140ba850417896b6b3322048de280368) C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys 17:26:33.0143 3436 HSFHWICH - ok 17:26:33.0203 3436 HSF_DP (b2dfc168d6f7512faea085253c5a37ad) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys 17:26:33.0233 3436 HSF_DP - ok 17:26:33.0353 3436 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys 17:26:33.0393 3436 HTTP - ok 17:26:33.0413 3436 i2omgmt - ok 17:26:33.0433 3436 i2omp - ok 17:26:33.0473 3436 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 17:26:33.0483 3436 i8042prt - ok 17:26:33.0543 3436 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys 17:26:33.0553 3436 Imapi - ok 17:26:33.0573 3436 ini910u - ok 17:26:33.0633 3436 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys 17:26:33.0643 3436 IntelIde - ok 17:26:33.0703 3436 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys 17:26:33.0703 3436 intelppm - ok 17:26:33.0784 3436 Ip6Fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 17:26:33.0794 3436 Ip6Fw - ok 17:26:33.0844 3436 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 17:26:33.0854 3436 IpFilterDriver - ok 17:26:33.0894 3436 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys 17:26:33.0894 3436 IpInIp - ok 17:26:33.0944 3436 IpNat (b5a8e215ac29d24d60b4d1250ef05ace) C:\WINDOWS\system32\DRIVERS\ipnat.sys 17:26:33.0944 3436 IpNat - ok 17:26:34.0004 3436 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys 17:26:34.0014 3436 IPSec - ok 17:26:34.0054 3436 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys 17:26:34.0064 3436 IRENUM - ok 17:26:34.0174 3436 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys 17:26:34.0194 3436 isapnp - ok 17:26:34.0254 3436 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 17:26:34.0274 3436 Kbdclass - ok 17:26:34.0314 3436 kbdhid (e182fa8e49e8ee41b4adc53093f3c7e6) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 17:26:34.0314 3436 kbdhid - ok 17:26:34.0354 3436 kmixer (d93cad07c5683db066b0b2d2d3790ead) C:\WINDOWS\system32\drivers\kmixer.sys 17:26:34.0364 3436 kmixer - ok 17:26:34.0394 3436 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys 17:26:34.0414 3436 KSecDD - ok 17:26:34.0454 3436 lbrtfdc - ok 17:26:34.0535 3436 MDC8021X (0f528e44cdc78365be693ae723e3801c) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys 17:26:34.0545 3436 MDC8021X - ok 17:26:34.0615 3436 mdmxsdk (3c318b9cd391371bed62126581ee9961) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys 17:26:34.0615 3436 mdmxsdk - ok 17:26:34.0695 3436 mmc_2K (9b90303a9c9405a6ce1466ff4aa20fdd) C:\WINDOWS\system32\drivers\mmc_2K.sys 17:26:34.0705 3436 mmc_2K - ok 17:26:34.0765 3436 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 17:26:34.0765 3436 mnmdd - ok 17:26:34.0825 3436 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys 17:26:34.0825 3436 Modem - ok 17:26:34.0845 3436 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys 17:26:34.0855 3436 Mouclass - ok 17:26:34.0915 3436 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 17:26:34.0915 3436 mouhid - ok 17:26:35.0035 3436 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys 17:26:35.0045 3436 MountMgr - ok 17:26:35.0055 3436 mraid35x - ok 17:26:35.0075 3436 MRxDAV (46edcc8f2db2f322c24f48785cb46366) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 17:26:35.0085 3436 MRxDAV - ok 17:26:35.0156 3436 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 17:26:35.0166 3436 MRxSmb - ok 17:26:35.0186 3436 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys 17:26:35.0196 3436 Msfs - ok 17:26:35.0256 3436 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys 17:26:35.0256 3436 MSKSSRV - ok 17:26:35.0346 3436 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 17:26:35.0356 3436 MSPCLOCK - ok 17:26:35.0386 3436 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys 17:26:35.0396 3436 MSPQM - ok 17:26:35.0436 3436 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 17:26:35.0436 3436 mssmbios - ok 17:26:35.0496 3436 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys 17:26:35.0706 3436 Mup - ok 17:26:35.0897 3436 NAVENG (862f55824ac81295837b0ab63f91071f) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111214.001\naveng.sys 17:26:35.0907 3436 NAVENG - ok 17:26:35.0997 3436 NAVEX15 (529d571b551cb9da44237389b936f1ae) C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20111214.001\navex15.sys 17:26:36.0027 3436 NAVEX15 - ok 17:26:36.0157 3436 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys 17:26:36.0167 3436 NDIS - ok 17:26:36.0227 3436 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 17:26:36.0237 3436 NdisTapi - ok 17:26:36.0267 3436 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 17:26:36.0267 3436 Ndisuio - ok 17:26:36.0277 3436 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 17:26:36.0397 3436 NdisWan - ok 17:26:36.0497 3436 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys 17:26:36.0507 3436 NDProxy - ok 17:26:36.0588 3436 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys 17:26:36.0588 3436 NetBIOS - ok 17:26:36.0628 3436 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys 17:26:36.0638 3436 NetBT - ok 17:26:36.0698 3436 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys 17:26:36.0718 3436 NIC1394 - ok 17:26:36.0788 3436 NPF (b9730495e0cf674680121e34bd95a73b) C:\WINDOWS\system32\drivers\NPF.sys 17:26:36.0788 3436 NPF - ok 17:26:36.0848 3436 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys 17:26:36.0848 3436 Npfs - ok 17:26:36.0898 3436 Ntfs (b78be402c3f63dd55521f73876951cdd) C:\WINDOWS\system32\drivers\Ntfs.sys 17:26:36.0938 3436 Ntfs - ok 17:26:37.0048 3436 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 17:26:37.0058 3436 Null - ok 17:26:37.0249 3436 nv (9e4b052c76949de445ad6439cd473548) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 17:26:37.0319 3436 nv - ok 17:26:37.0449 3436 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 17:26:37.0459 3436 NwlnkFlt - ok 17:26:37.0489 3436 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 17:26:37.0499 3436 NwlnkFwd - ok 17:26:37.0559 3436 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys 17:26:37.0559 3436 ohci1394 - ok 17:26:37.0649 3436 OMCI (b17228142cec9b3c222239fd935a37ca) C:\WINDOWS\system32\DRIVERS\omci.sys 17:26:37.0659 3436 OMCI - ok 17:26:37.0719 3436 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys 17:26:37.0739 3436 Parport - ok 17:26:37.0829 3436 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys 17:26:37.0829 3436 PartMgr - ok 17:26:37.0869 3436 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 17:26:37.0869 3436 ParVdm - ok 17:26:37.0919 3436 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 17:26:37.0919 3436 pccsmcfd - ok 17:26:37.0980 3436 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys 17:26:37.0990 3436 PCI - ok 17:26:38.0010 3436 PCIDump - ok 17:26:38.0030 3436 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 17:26:38.0040 3436 PCIIde - ok 17:26:38.0080 3436 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\DRIVERS\pcmcia.sys 17:26:38.0090 3436 Pcmcia - ok 17:26:38.0110 3436 PDCOMP - ok 17:26:38.0120 3436 PDFRAME - ok 17:26:38.0140 3436 PDRELI - ok 17:26:38.0160 3436 PDRFRAME - ok 17:26:38.0170 3436 perc2 - ok 17:26:38.0190 3436 perc2hib - ok 17:26:38.0250 3436 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys 17:26:38.0260 3436 PptpMiniport - ok 17:26:38.0300 3436 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys 17:26:38.0310 3436 PSched - ok 17:26:38.0390 3436 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 17:26:38.0400 3436 Ptilink - ok 17:26:38.0450 3436 pwd_2k (d8b90616a8bd53de281dbdb664c0984a) C:\WINDOWS\system32\drivers\pwd_2k.sys 17:26:38.0460 3436 pwd_2k - ok 17:26:38.0500 3436 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys 17:26:38.0701 3436 PxHelp20 - ok 17:26:38.0791 3436 ql1080 - ok 17:26:38.0811 3436 Ql10wnt - ok 17:26:38.0831 3436 ql12160 - ok 17:26:38.0841 3436 ql1240 - ok 17:26:38.0861 3436 ql1280 - ok 17:26:38.0921 3436 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 17:26:38.0921 3436 RasAcd - ok 17:26:38.0981 3436 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 17:26:38.0991 3436 Rasl2tp - ok 17:26:39.0011 3436 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 17:26:39.0021 3436 RasPppoe - ok 17:26:39.0041 3436 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 17:26:39.0041 3436 Raspti - ok 17:26:39.0081 3436 Rdbss (29d66245adba878fff574cd66abd2884) C:\WINDOWS\system32\DRIVERS\rdbss.sys 17:26:39.0081 3436 Rdbss - ok 17:26:39.0101 3436 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 17:26:39.0101 3436 RDPCDD - ok 17:26:39.0161 3436 rdpdr (a2cae2c60bc37e0751ef9dda7ceaf4ad) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 17:26:39.0181 3436 rdpdr - ok 17:26:39.0221 3436 RDPWD (d4f5643d7714ef499ae9527fdcd50894) C:\WINDOWS\system32\drivers\RDPWD.sys 17:26:39.0231 3436 RDPWD - ok 17:26:39.0311 3436 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys 17:26:39.0321 3436 redbook - ok 17:26:39.0392 3436 RimUsb (0f6756ef8bda6dfa7be50465c83132bb) C:\WINDOWS\system32\Drivers\RimUsb.sys 17:26:39.0402 3436 RimUsb - ok 17:26:39.0442 3436 RimVSerPort (d9b34325ee5df78b8f28a3de9f577c7d) C:\WINDOWS\system32\DRIVERS\RimSerial.sys 17:26:39.0442 3436 RimVSerPort - ok 17:26:39.0492 3436 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys 17:26:39.0502 3436 ROOTMODEM - ok 17:26:39.0592 3436 s24trans (41cf7128424f3bdc35b05be3cc8ce7ec) C:\WINDOWS\system32\DRIVERS\s24trans.sys 17:26:39.0602 3436 s24trans - ok 17:26:39.0752 3436 SAVRT (cdb565c093b0105086cc630b32f9e6e6) C:\Program Files\Symantec AntiVirus\savrt.sys 17:26:39.0772 3436 SAVRT - ok 17:26:39.0782 3436 SAVRTPEL (1042cb5a003f9aed8d6cec56a0fc6c49) C:\Program Files\Symantec AntiVirus\Savrtpel.sys 17:26:39.0792 3436 SAVRTPEL - ok 17:26:39.0912 3436 Secdrv (d26e26ea516450af9d072635c60387f4) C:\WINDOWS\system32\DRIVERS\secdrv.sys 17:26:39.0922 3436 Secdrv - ok 17:26:39.0982 3436 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys 17:26:39.0982 3436 serenum - ok 17:26:40.0002 3436 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys 17:26:40.0012 3436 Serial - ok 17:26:40.0063 3436 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys 17:26:40.0063 3436 Sfloppy - ok 17:26:40.0093 3436 Simbad - ok 17:26:40.0113 3436 Sparrow - ok 17:26:40.0153 3436 SPBBCDrv (cc22bf5631c4837abcd81d75de8fb1aa) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys 17:26:40.0163 3436 SPBBCDrv - ok 17:26:40.0283 3436 splitter (8e186b8f23295d1e42c573b82b80d548) C:\WINDOWS\system32\drivers\splitter.sys 17:26:40.0293 3436 splitter - ok 17:26:40.0363 3436 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys 17:26:40.0373 3436 sr - ok 17:26:40.0413 3436 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys 17:26:40.0423 3436 Srv - ok 17:26:40.0473 3436 STAC97 (ae4797a1fc117c1d28a4ed80be42f734) C:\WINDOWS\system32\drivers\stac97.sys 17:26:40.0493 3436 STAC97 - ok 17:26:40.0553 3436 StillCam (a9573045baa16eab9b1085205b82f1ed) C:\WINDOWS\system32\DRIVERS\serscan.sys 17:26:40.0563 3436 StillCam - ok 17:26:40.0683 3436 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys 17:26:40.0693 3436 swenum - ok 17:26:40.0774 3436 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys 17:26:40.0774 3436 swmidi - ok 17:26:40.0794 3436 symc810 - ok 17:26:40.0814 3436 symc8xx - ok 17:26:40.0914 3436 SymEvent (5156f63e684e8c864ff40e40d5309f41) C:\Program Files\Symantec\SYMEVENT.SYS 17:26:40.0924 3436 SymEvent - ok 17:26:40.0984 3436 SYMREDRV (5314e345dfc068504cfb2676d3b2ca39) C:\WINDOWS\System32\Drivers\SYMREDRV.SYS 17:26:40.0994 3436 SYMREDRV - ok 17:26:41.0034 3436 SYMTDI (8cd0a1478256240249b8ee88e6f25e94) C:\WINDOWS\System32\Drivers\SYMTDI.SYS 17:26:41.0044 3436 SYMTDI - ok 17:26:41.0114 3436 sym_hi - ok 17:26:41.0134 3436 sym_u3 - ok 17:26:41.0164 3436 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys 17:26:41.0164 3436 sysaudio - ok 17:26:41.0244 3436 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys 17:26:41.0254 3436 Tcpip - ok 17:26:41.0334 3436 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys 17:26:41.0344 3436 TDPIPE - ok 17:26:41.0374 3436 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys 17:26:41.0384 3436 TDTCP - ok 17:26:41.0445 3436 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys 17:26:41.0455 3436 TermDD - ok 17:26:41.0525 3436 tiumfwl (a4c6f3e34358c94e5c3acfc3392f8907) C:\WINDOWS\system32\drivers\tiumfwl.sys 17:26:41.0535 3436 tiumfwl - ok 17:26:41.0555 3436 TosIde - ok 17:26:41.0625 3436 UdfReadr_xp (4e75005b74be901c30f2636df40b0c15) C:\WINDOWS\system32\drivers\UdfReadr_xp.sys 17:26:41.0635 3436 UdfReadr_xp - ok 17:26:41.0715 3436 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys 17:26:41.0725 3436 Udfs - ok 17:26:41.0745 3436 UIUSys - ok 17:26:41.0765 3436 ultra - ok 17:26:41.0785 3436 Update (aff2e5045961bbc0a602bb6f95eb1345) C:\WINDOWS\system32\DRIVERS\update.sys 17:26:41.0865 3436 Update - ok 17:26:41.0935 3436 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 17:26:41.0945 3436 usbccgp - ok 17:26:42.0005 3436 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys 17:26:42.0015 3436 usbehci - ok 17:26:42.0085 3436 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys 17:26:42.0106 3436 usbhub - ok 17:26:42.0156 3436 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys 17:26:42.0166 3436 usbprint - ok 17:26:42.0226 3436 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys 17:26:42.0236 3436 usbscan - ok 17:26:42.0346 3436 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 17:26:42.0356 3436 USBSTOR - ok 17:26:42.0396 3436 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 17:26:42.0406 3436 usbuhci - ok 17:26:42.0496 3436 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys 17:26:42.0496 3436 VgaSave - ok 17:26:42.0506 3436 ViaIde - ok 17:26:42.0536 3436 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys 17:26:42.0586 3436 VolSnap - ok 17:26:42.0736 3436 w22n51 (4fed83668f087ecbe810ea90beceb765) C:\WINDOWS\system32\DRIVERS\w22n51.sys 17:26:42.0786 3436 w22n51 - ok 17:26:42.0907 3436 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys 17:26:42.0917 3436 Wanarp - ok 17:26:42.0927 3436 WDICA - ok 17:26:42.0987 3436 wdmaud (2797f33ebf50466020c430ee4f037933) C:\WINDOWS\system32\drivers\wdmaud.sys 17:26:42.0997 3436 wdmaud - ok 17:26:43.0077 3436 winachsf (2dc7c0b6175a0a8ed84a4f70199c93b5) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys 17:26:43.0107 3436 winachsf - ok 17:26:43.0207 3436 MBR (0x1B8) (6f9a1d528242bc09104b85e0becf5554) \Device\Harddisk0\DR0 17:26:43.0227 3436 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - infected 17:26:43.0227 3436 \Device\Harddisk0\DR0 - detected Rootkit.Boot.SST.a (0) 17:26:43.0237 3436 Boot (0x1200) (b57b10d35f0c0a4ce2fa4f6298e87b7e) \Device\Harddisk0\DR0\Partition0 17:26:43.0237 3436 \Device\Harddisk0\DR0\Partition0 - ok 17:26:43.0237 3436 ============================================================ 17:26:43.0237 3436 Scan finished 17:26:43.0237 3436 ============================================================ 17:26:43.0247 0616 Detected object count: 2 17:26:43.0247 0616 Actual detected object count: 2 17:26:49.0416 0616 C:\WINDOWS\system32\DRIVERS\cdrom.sys - copied to quarantine 17:26:49.0456 0616 VerifyFileNameVersionInfo: GetFileVersionInfoSizeW(C:\WINDOWS\system32\drivers\cdrom.sys) error 1813 17:26:52.0891 0616 Backup copy found, using it.. 17:26:53.0001 0616 C:\WINDOWS\system32\DRIVERS\cdrom.sys - will be cured on reboot 17:26:55.0274 0616 Cdrom ( Virus.Win32.ZAccess.k ) - User select action: Cure 17:26:55.0675 0616 \Device\Harddisk0\DR0\# - copied to quarantine 17:26:55.0715 0616 \Device\Harddisk0\DR0 - copied to quarantine 17:26:55.0755 0616 \Device\Harddisk0\DR0\TDLFS\mbr - copied to quarantine 17:26:55.0815 0616 \Device\Harddisk0\DR0\TDLFS\bid - copied to quarantine 17:26:55.0825 0616 \Device\Harddisk0\DR0\TDLFS\affid - copied to quarantine 17:26:55.0855 0616 \Device\Harddisk0\DR0\TDLFS\boot - copied to quarantine 17:26:55.0855 0616 \Device\Harddisk0\DR0\TDLFS\cmd32 - copied to quarantine 17:26:56.0476 0616 \Device\Harddisk0\DR0\TDLFS\cmd64 - copied to quarantine 17:26:56.0827 0616 \Device\Harddisk0\DR0\TDLFS\dbg32 - copied to quarantine 17:26:56.0897 0616 \Device\Harddisk0\DR0\TDLFS\dbg64 - copied to quarantine 17:26:56.0977 0616 \Device\Harddisk0\DR0\TDLFS\drv32 - copied to quarantine 17:26:57.0047 0616 \Device\Harddisk0\DR0\TDLFS\drv64 - copied to quarantine 17:26:57.0237 0616 \Device\Harddisk0\DR0\TDLFS\ldr32 - copied to quarantine 17:26:57.0478 0616 \Device\Harddisk0\DR0\TDLFS\ldr64 - copied to quarantine 17:26:57.0508 0616 \Device\Harddisk0\DR0\TDLFS\subid - copied to quarantine 17:26:57.0518 0616 \Device\Harddisk0\DR0\TDLFS\info - copied to quarantine 17:26:57.0518 0616 \Device\Harddisk0\DR0\TDLFS\mainfb.script - copied to quarantine 17:26:57.0568 0616 \Device\Harddisk0\DR0\TDLFS\com32 - copied to quarantine 17:26:57.0588 0616 \Device\Harddisk0\DR0\TDLFS\main - copied to quarantine 17:26:57.0628 0616 \Device\Harddisk0\DR0\TDLFS\serf_conf - copied to quarantine 17:26:57.0648 0616 \Device\Harddisk0\DR0\TDLFS\bbr232 - copied to quarantine 17:26:57.0718 0616 \Device\Harddisk0\DR0\TDLFS\serf332 - copied to quarantine 17:26:57.0778 0616 \Device\Harddisk0\DR0\TDLFS\bbr_conf - copied to quarantine 17:26:57.0918 0616 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - will be cured on reboot 17:26:57.0928 0616 \Device\Harddisk0\DR0 - ok 17:26:57.0998 0616 \Device\Harddisk0\DR0 ( Rootkit.Boot.SST.a ) - User select action: Cure 17:27:10.0777 3280 Deinitialize success

Attachments:

Hello Clairedog

Frequent BSOD does not sound good at all.

This is why I asked you to back up all of your important data before beggining running any tools; when trying to clean a machine as heavily infected as this unexpected things can sometimes happen.

Please scan the machine with DDS and aswMBR again and post the logs in your next reply.
I agree. I'm not concerned about losing any of the data at this point. I've got what I need, so we're ok on that front. Bottom line is that if it is better to format the drive and start from scratch, that is a possibility. I have discs from Dell that came with it. I've never done that and started back from a blank drive. I'll run the two and post the logs. Have a good evening.
Here is the DDS: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14 Run by [removed] at 17:58:56 on 2012-03-03 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.442 [GMT -8:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\ZCfgSvc.exe svchost.exe C:\Program Files\Application Updater\ApplicationUpdater.exe C:\WINDOWS\system32\FsUsbExService.Exe C:\Program Files\Java\jre6\bin\jqs.exe C:\server\mysql\bin\mysqld.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\RegSrvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\1XConfig.exe C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe C:\Program Files\Brother\ControlCenter3\brccMCtl.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AIM\aim.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe . ============== Pseudo HJT Report =============== . BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [PRONoMgr.exe] c:\program files\intel\prosetwireless\ncs\proset\PRONoMgr.exe mRun: [Dell QuickSet] c:\program files\dell\quickset\quickset.exe mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [BrMfcWnd] c:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [MozillaAgent] c:\windows\temp\_ex-68.exe mRun: [] mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe" mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k dRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil9f.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-000000000003}\_SC_Acrobat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~2.lnk - c:\program files\adobe\acrobat 8.0\acrobat\AdobeCollabSync.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll LSP: mswsock.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1228361578657 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab TCP: DhcpNameServer = 192.168.1.254 TCP: Interfaces\{40607D75-274A-4EEC-BACD-1D9C89442FE7} : DhcpNameServer = 192.168.1.254 Notify: Sebring - c:\windows\system32\LgNotify.dll . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\ FF - prefs.js: browser.search.defaulturl - hxxp://aim.search.aol.com/aol/search?query={searchTerms}&invocationType=tb50-ff-aim-chromesbox-en-us&tb_uuid=20101206013308788&tb_oid=06-12-2010&tb_mrud=06-12-2010 FF - prefs.js: browser.startup.homepage - hxxp://kids.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=971163&p= FF - component: c:\documents and settings\harold\application data\mozilla\firefox\profiles\2myetprq.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}\components\MailUtil.dll FF - component: c:\program files\common files\spigot\wtxpcom\components\WidgiToolbarFF.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll . —- FIREFOX POLICIES —- FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false FF - user.js: browser.sessionstore.resume_from_crash - false FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false ============= SERVICES / DRIVERS =============== . R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2012-2-6 748440] R2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2011-5-29 233472] R3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [2011-5-29 36608] R3 GTICARD;GTICARD;c:\windows\system32\drivers\gticard.sys [2003-2-6 59328] S2 Apache2.2;Apache2.2;c:\server\apache\bin\apache.exe [2008-12-9 24636] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] . =============== Created Last 30 ================ . 2012-03-03 17:48:33 ——– d-sha-r- C:\cmdcons 2012-03-03 17:46:47 98816 —-a-w- c:\windows\sed.exe 2012-03-03 17:46:47 518144 —-a-w- c:\windows\SWREG.exe 2012-03-03 17:46:47 256000 —-a-w- c:\windows\PEV.exe 2012-03-03 17:46:47 208896 —-a-w- c:\windows\MBR.exe 2012-03-03 17:46:40 ——– d-s—w- C:\ComboFix 2012-03-03 17:44:14 ——– d—–w- c:\windows\system32\appmgmt 2012-03-03 03:44:52 83456 —-a-w- c:\windows\system32\TnMaA74.exe_ 2012-03-03 01:26:49 ——– d—–w- C:\TDSSKiller_Quarantine 2012-03-01 04:29:00 83968 —-a-w- c:\documents and settings\all users\application data\J2G0r32Q.exe 2012-02-26 19:07:00 0 –sha-w- c:\windows\system32\dds_trash_log.cmd 2012-02-26 18:58:24 51712 —-a-w- c:\windows\system32\TnMaA74.com 2012-02-26 18:55:14 ——– d—–w- c:\documents and settings\harold\application data\Search Settings 2012-02-26 18:55:05 ——– d—–w- c:\program files\pdfforge Toolbar 2012-02-26 18:55:05 ——– d—–w- c:\program files\common files\Spigot 2012-02-26 18:55:05 ——– d—–w- c:\program files\Application Updater 2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\tkn.exe 2012-02-26 18:49:59 316416 —-a-w- c:\documents and settings\harold\local settings\application data\jpi.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\xfd.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\orj.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\htk.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\edc.exe 2012-02-26 18:49:58 316416 —-a-w- c:\documents and settings\harold\local settings\application data\deb.exe . ==================== Find3M ==================== . 2012-03-03 01:28:40 49536 —-a-w- c:\windows\system32\drivers\cdrom.sys 2011-12-16 12:47:59 50704 —-a-w- c:\windows\system32\drivers\npf.sys 2011-12-16 12:47:57 281104 —-a-w- c:\windows\system32\wpcap.dll 2011-12-16 12:47:55 100880 —-a-w- c:\windows\system32\Packet.dll . ============= FINISH: 17:59:52.65 =============== Here is the Attach.txt . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12/2/2008 10:11:37 PM System Uptime: 3/3/2012 3:26:34 PM (2 hours ago) . Motherboard: Dell Computer Corporation | | 0T1957 Processor: Intel® Pentium® M processor 2.00GHz | Microprocessor | 1993/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 93 GiB total, 62.929 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318} Description: 1394 Net Adapter Device ID: V1394\NIC1394\237718C1374FC000 Manufacturer: Microsoft Name: 1394 Net Adapter PNP Device ID: V1394\NIC1394\237718C1374FC000 Service: NIC1394 . Class GUID: Description: Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX Manufacturer: Name: PNP Device ID: ROOT\LEGACY_BEEP\XX_NPF_XX Service: NPF . ==== System Restore Points =================== . RP237: 12/13/2011 7:46:38 PM - System Checkpoint RP238: 12/14/2011 11:26:34 PM - System Checkpoint RP239: 12/15/2011 3:00:45 AM - Software Distribution Service 3.0 RP240: 12/15/2011 6:57:13 AM - Restore Operation RP241: 12/15/2011 7:06:27 AM - Software Distribution Service 3.0 RP242: 12/15/2011 6:40:55 PM - Software Distribution Service 3.0 RP243: 12/15/2011 7:12:14 PM - Software Distribution Service 3.0 RP244: 2/26/2012 10:54:37 AM - Removed pdfforge Toolbar v4.8. RP245: 2/26/2012 11:20:10 AM - Software Distribution Service 3.0 RP246: 2/29/2012 7:28:40 PM - Software Distribution Service 3.0 RP247: 3/2/2012 6:53:25 AM - System Checkpoint RP248: 3/3/2012 9:43:07 AM - Removed Symantec AntiVirus . ==== Installed Programs ====================== . Acrobat.com Adobe Acrobat 8 Professional Adobe AIR Adobe Flash Player 10 Plugin Adobe Flash Player ActiveX Adobe Reader X AIM 7 ALPS Touch Pad Driver AOL Messaging Toolbar Apple Application Support Apple Software Update BlackBerry Desktop Software 4.3 Broadcom Gigabit Integrated Controller Brother MFL-Pro Suite C-Major Audio CampBrain 5.1 CardBus Compatibility Pack for the 2007 Office system Conexant D480 MDC V.9x Modem Dell ResourceCD Download Updater (AOL LLC) DYMO Label v.8 DYMO LabelWriter Drivers Easy CD Creator 5 Basic Google Talk (remove only) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) Hotfix for Windows XP (KB981793) Intel® mDriver Intel® PROSet for Wireless InterActual Player InterVideo WinDVD Java 2 Runtime Environment, SE v1.4.2_03 Java™ 6 Update 14 LiveUpdate 3.0 (Symantec Corporation) McAfee Security Scan Plus Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB979906) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office File Validation Add-In Microsoft Office Professional Edition 2003 Microsoft VC9 runtime libraries MOM Workstation 6.0 Mozilla Firefox 8.0.1 (x86 en-US) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6 Service Pack 2 (KB973686) Nancy Drew Dossier: Resorting to Danger Nancy Drew: Ghost Dogs of Moon Lake Nancy Drew: Shadow at the Water's Edge Nancy Drew: The Captive Curse Nancy Drew: Warnings at Waverly Academy NVIDIA Drivers PC Connectivity Solution PCI 7510 CardBus Controller with SmartCard and Software PDFCreator pdfforge Toolbar v5.0 Peachtree Complete Accounting 2005 QuickSet QuickTime Roxio Media Manager SAMSUNG Mobile Composite Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung New PC Studio SamsungConnectivityCableDriver Security Update for CAPICOM (KB931906) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB982381) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player (KB979402) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB944338-v2) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979559) Security Update for Windows XP (KB979683) Security Update for Windows XP (KB980195) Security Update for Windows XP (KB980218) Security Update for Windows XP (KB980232) Security Update for Windows XP (KB981349) SimCoaster SimTheme Park Spybot - Search & Destroy Stamps.com The Hardy Boys - The Hidden Theft Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows XP (KB898461) Update for Windows XP (KB904942) Update for Windows XP (KB925720) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Windows Driver Package - MobileTop (sshpmdm) Modem (02/23/2007 2.5.0.0) Windows Driver Package - MobileTop (sshpusb) USB (02/23/2007 2.5.0.0) Windows Driver Package - Nokia pccsmcfd (10/12/2007 6.85.4.0) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime XAMPP 1.7.0 . ==== Event Viewer Messages From Past Week ======== . 3/2/2012 7:01:00 AM, error: Schedule [7901] - The At64.job command failed to start due to the following error: %%2147942402 3/2/2012 7:01:00 AM, error: Schedule [7901] - The At16.job command failed to start due to the following error: %%2147942402 3/2/2012 6:59:32 AM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805660cf, parameter3 eb055a40, parameter4 00000000. 3/1/2012 9:19:29 PM, error: Service Control Manager [7023] - The Network Location Awareness (NLA) service terminated with the following error: The specified procedure could not be found. 3/1/2012 9:01:00 PM, error: Schedule [7901] - The At92.job command failed to start due to the following error: %%2147942402 3/1/2012 8:54:17 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Symantec AntiVirus service to connect. 3/1/2012 11:01:03 PM, error: Schedule [7901] - The At96.job command failed to start due to the following error: %%2147942402 3/1/2012 11:01:01 PM, error: Schedule [7901] - The At47.job command failed to start due to the following error: %%2147942402 3/1/2012 10:01:14 PM, error: Schedule [7901] - The At94.job command failed to start due to the following error: %%2147942402 3/1/2012 10:01:07 PM, error: Schedule [7901] - The At46.job command failed to start due to the following error: %%2147942402 2/29/2012 8:01:00 PM, error: Schedule [7901] - The At90.job command failed to start due to the following error: %%2147942402 2/26/2012 12:01:02 PM, error: Schedule [7901] - The At74.job command failed to start due to the following error: %%2147942402 2/26/2012 11:36:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Windows Malicious Software Removal Tool - December 2011 (KB890830). 2/26/2012 11:36:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft Office PowerPoint 2007 (KB2596843). 2/26/2012 11:36:51 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80246007: Security Update for Microsoft Office 2007 suites (KB2596785). 2/26/2012 11:16:56 AM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the Roxio Hard Drive Watcher 9 service to connect. 2/26/2012 11:01:00 AM, error: Schedule [7901] - The At72.job command failed to start due to the following error: %%2147942402 2/26/2012 11:01:00 AM, error: Schedule [7901] - The At23.job command failed to start due to the following error: %%2147942402 2/26/2012 10:49:56 AM, error: System Error [1003] - Error code 1000008e, parameter1 c0000005, parameter2 805660cf, parameter3 eed49a40, parameter4 00000000. . ==== End Of File =========================== Posting this now and will post the other in a minute.
Here is the aswMBR.txt aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software Run date: 2012-02-29 20:00:55 —————————– 20:00:55.112 OS Version: Windows 5.1.2600 Service Pack 2 20:00:55.122 Number of processors: 1 586 0xD06 20:00:55.122 ComputerName: HG-LATITUDE UserName: Harold 20:00:56.364 Initialize success 20:01:01.091 AVAST engine download error: 0 20:09:44.514 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 20:09:44.514 Disk 0 Vendor: Hitachi_HTS721010G9AT00 MCZOA53A Size: 95396MB BusType: 3 20:09:44.524 Disk 0 MBR read successfully 20:09:44.524 Disk 0 MBR scan 20:09:44.524 Disk 0 TDL4@MBR code has been found 20:09:44.524 Disk 0 Windows XP default MBR code found via API 20:09:44.524 Disk 0 MBR hidden 20:09:44.524 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95393 MB offset 63 20:09:44.524 Disk 0 MBR [TDL4] **ROOTKIT** 20:09:44.524 Disk 0 trace - called modules: 20:09:44.534 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8682cf10]<< 20:09:44.534 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8739fab8] 20:09:44.534 3 CLASSPNP.SYS[f761005b] -> nt!IofCallDriver -> [0x86993248] 20:09:44.874 \Driver\00001111[0x8640af10] -> IRP_MJ_CREATE -> 0x8682cf10 20:09:44.874 Scan finished successfully 20:10:26.864 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Harold\Desktop\MBR.dat" 20:10:26.864 The log file has been saved successfully to "C:\Documents and Settings\Harold\Desktop\aswMBR.txt" aswMBR version 0.9.9.1649 Copyright© 2011 AVAST Software Run date: 2012-03-03 18:07:28 —————————– 18:07:28.637 OS Version: Windows 5.1.2600 Service Pack 2 18:07:28.637 Number of processors: 1 586 0xD06 18:07:28.637 ComputerName: HG-LATITUDE UserName: Harold 18:07:29.688 Initialize success 18:08:19.300 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 18:08:19.300 Disk 0 Vendor: Hitachi_HTS721010G9AT00 MCZOA53A Size: 95396MB BusType: 3 18:08:19.320 Disk 0 MBR read successfully 18:08:19.320 Disk 0 MBR scan 18:08:19.320 Disk 0 Windows XP default MBR code 18:08:19.330 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 95393 MB offset 63 18:08:19.330 Disk 0 scanning sectors +195366465 18:08:19.420 Disk 0 scanning C:\WINDOWS\system32\drivers 18:08:27.021 Service scanning 18:08:47.791 Modules scanning 18:08:51.306 Module: C:\WINDOWS\system32\DRIVERS\i8042prt.sys **SUSPICIOUS** 18:09:02.312 Disk 0 trace - called modules: 18:09:02.322 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xf7712fc0]<< 18:09:02.332 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x87394ab8] 18:09:02.672 3 CLASSPNP.SYS[f761005b] -> nt!IofCallDriver -> [0x8727f2d8] 18:09:02.672 \Driver\00001253[0x87160f10] -> IRP_MJ_CREATE -> 0xf7712fc0 18:09:02.672 Scan finished successfully 18:09:13.898 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Harold\Desktop\MBR.dat" 18:09:13.898 The log file has been saved successfully to "C:\Documents and Settings\Harold\Desktop\aswMBR.txt"

Attachments:

Hello Clairedog

Thank you for the logs.

Bottom line is that if it is better to format the drive and start from scratch, that is a possibility. I have discs from Dell that came with it.

Thats good to know, since a reformat and reinstallation would certainly ensure that all malware was remove from the machine.

I can still see evidence of both ZA and TDL4 in your logs so an R+R may not be out of the question (let me know of you do want to take that route).

At the moment though there are still many things we can try.


Lets see a report from the following tool:


  • Farbar Service Scanner


  • Please download Farbar Service Scanner from here and run it on your machine (The file is called FSS.exe).
  • Make sure the following options are checked:


Internet Services
Windows Firewallsfc
System Restore
Security Center
Windows Update



  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
Hi: Below I've copied the FSS.txt. From your comments, this is sounding rather challenging. I really am fine with reformatting and starting over fresh if I have what I need. If you can help me do that, then your time will be free to help someone who doesn't have that option. I have the following original discs available: Drivers & Utilities - Already Installed on your computer - For reinstalling Dell Latitude System Software Operating System - Already installed on your computer - Re-installation CD MS Windows XP including service pack 2 Application - Already installed…. - For reinstalling Roxio Easy CD Creator 5.3.4. SP8 Basic System Software WinDVD I've never reformatted or installed from scratch before. Below is the FSS.txt Thanks. Harold Farbar Service Scanner Version: 01-03-2012 Ran by [removed] (administrator) on 04-03-2012 at 12:05:37 Running from "C:\Documents and Settings\Harold\Desktop" Microsoft Windows XP Professional Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit C:\WINDOWS\system32\Drivers\afd.sys [2004-08-12 05:17] - [2008-08-14 01:51] - 0138368 ____A (Microsoft Corporation) 55E6E1C51B6D30E54335750955453702 C:\WINDOWS\system32\Drivers\netbt.sys [2004-08-12 05:24] - [2004-08-12 05:24] - 0162816 ____A (Microsoft Corporation) 0C80E410CD2F47134407EE7DD19CC86B C:\WINDOWS\system32\Drivers\tcpip.sys [2004-08-12 05:30] - [2008-06-20 02:45] - 0360320 ____A (Microsoft Corporation) 2A5554FC5B1E04E131230E3CE035C3F9 C:\WINDOWS\system32\Drivers\ipsec.sys [2004-08-12 05:20] - [2004-08-12 05:20] - 0074752 ____A (Microsoft Corporation) 64537AA5C003A6AFEEE1DF819062D0D1 C:\WINDOWS\system32\dnsrslvr.dll [2004-08-12 05:18] - [2004-08-12 05:18] - 0045568 ____A (Microsoft Corporation) 7379DE06FD196E396A00AA97B990C00D C:\WINDOWS\system32\ipnathlp.dll [2004-08-12 05:20] - [2004-08-12 05:20] - 0331264 ____A (Microsoft Corporation) 36CC8C01B5E50163037BEF56CB96DEFF C:\WINDOWS\system32\netman.dll [2004-08-12 05:24] - [2004-08-12 05:24] - 0198144 ____A (Microsoft Corporation) DAB9E6C7105D2EF49876FE92C524F565 C:\WINDOWS\system32\wbem\WMIsvc.dll [2008-12-02 22:05] - [2004-08-12 05:34] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E C:\WINDOWS\system32\srsvc.dll [2008-12-02 22:06] - [2004-08-12 05:29] - 0170496 ____A (Microsoft Corporation) 92BDF74F12D6CBEC43C94D4B7F804838 C:\WINDOWS\system32\Drivers\sr.sys [2008-12-02 22:06] - [2004-08-12 05:29] - 0073472 ____A (Microsoft Corporation) E41B6D037D6CD08461470AF04500DC24 C:\WINDOWS\system32\wscsvc.dll [2004-08-12 05:34] - [2004-08-12 05:34] - 0081408 ____A (Microsoft Corporation) 4D59DAA66C60858CDF4F67A900F42D4A C:\WINDOWS\system32\wbem\WMIsvc.dll [2008-12-02 22:05] - [2004-08-12 05:34] - 0144896 ____A (Microsoft Corporation) F399242A80C4066FD155EFA4CF96658E C:\WINDOWS\system32\wuauserv.dll [2008-12-02 22:07] - [2004-08-12 05:34] - 0006656 ____A (Microsoft Corporation) 13D72740963CBA12D9FF76A7F218BCD8 C:\WINDOWS\system32\qmgr.dll [2008-12-02 22:07] - [2004-08-12 05:26] - 0382464 ____A (Microsoft Corporation) 2C69EC7E5A311334D10DD95F338FCCEA C:\WINDOWS\system32\es.dll [2004-08-12 05:19] - [2008-07-07 12:32] - 0253952 ____A (Microsoft Corporation) 60D1A6342238378BFB7545C81EE3606C C:\WINDOWS\system32\cryptsvc.dll [2004-08-12 05:18] - [2004-08-12 05:18] - 0060416 ____A (Microsoft Corporation) 10654F9DDCEA9C46CFB77554231BE73B C:\WINDOWS\system32\svchost.exe [2004-08-12 05:30] - [2004-08-12 05:30] - 0014336 ____A (Microsoft Corporation) 8F078AE4ED187AAABC0A305146DE6716 C:\WINDOWS\system32\rpcss.dll [2004-08-12 05:27] - [2009-02-09 02:20] - 0399360 ____A (Microsoft Corporation) 01095FEBF33BEEA00C2A0730B9B3EC28 C:\WINDOWS\system32\services.exe [2004-08-12 05:28] - [2009-02-06 09:14] - 0110592 ____A (Microsoft Corporation) 37561F8D4160D62DA86D24AE41FAE8DE Extra List: ======= Gpc(3) IPSec(5) MDC8021X(9) NetBT(6) PSched(7) s24trans(8) Tcpip(4) 0x090000000500000001000000020000000300000004000000060000000700000008000000090000 00 IpSec Tag value is correct. **** End of log ****
Hello Clairedog

If you have no problem with a reset to factory settings or a complete reformat and reinstalation then this would be the thing to do since it will most likely offer the quickest route to removing the infections on the machine.

I have discs from Dell that came with it

The disks you have will probably allow you to perform a factory reset of the machine.

The latest DELL backup and reset guide can be found here

An excellent general guide to reformatting and reinstalling an operating system can be found here

Should you need additional assistance with the procedure, please begin a new thread in our Windows forum located here
Thanks for all of your help. I am reinstalling now. You'd mentioned that you could recommend a good free anti virus/spyware program. That would still be great if you wouldn't mind. Thanks for doing what you do. You are all lifesavers. Harold
Hello Harold

You'd mentioned that you could recommend a good free anti virus/spyware program. That would still be great if you wouldn't mind.

No problem at all :)


  • Security programs

  • I have provided links to three trusted programs (just choose one).


  • For a free Firewall try one of the following:
  • Comodo Personal Firewall
  • NOTE: If you use a Third Party AnitiVirus, make sure you uncheck the option to install Comodo AntiVirus when you install Comodo Firewall.


  • IMPORTANT! Please make sure you only have ONE firewall and ONE real-time antivirus installed on your system.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI