This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Security scanner auto virus, think removed. hjt att [Solved]

52 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

java is now gone. it is no longer listed. There was 2 intances removed. one was slow cache and i dont recall the other. Whats next ? Thanks.
  • OTL

    Run OTL.exe.

  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL.

    :Files
    C:\Documents and Settings\Tom\My Documents\Downloads\CDRip-_lifehouse falling in_.mp3
    C:\Documents and Settings\Tom\My Documents\Downloads\[CD.RIP] - falling in lifehouse.mp3
    C:\Documents and Settings\Tom\My Documents\My Music\Top of Charts - 2005.wma
    C:\WINDOWS.0\system32\drivers\AFS2K.SYS
    C:\WINDOWS.0\system32\spool\drivers\w32x86\3\HP1006MC.EXE
    
    :OTL
    FF - prefs.js..browser.search.defaultenginename: "SweetIM Search"
    FF - prefs.js..browser.search.selectedEngine: "SweetIM Search"
    FF - prefs.js..browser.startup.homepage: "http://home.sweetim.com"
    [2010/04/08 23:30:03 | 000,009,916 | -HS- | C] () – C:\Documents and Settings\Tom\Local Settings\Application Data\6e6301sD6p
    [2010/04/08 23:30:03 | 000,009,916 | -HS- | C] () – C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6e6301sD6p
    @Alternate Data Stream - 88 bytes -> C:\WINDOWS\system32\svchost.exe:SummaryInformation
    
    :Commands
    [createrestorepoint]
    [purity]
    [emptytemp]

  • Click the Run Fix button.
  • OTL will now process the instructions.
  • When finished a box will open asking you to open the fix log, click OK.
  • The fix log will open.
  • Copy/Paste the log in your next reply please.

Note: If necessary, OTL may reboot your computer, or request that you do so. If it does, please go ahead and reboot your machine. After rebooting, open up Windows Explorer (Windows Key +E) and navigate to C:\_OTL\MovedFiles. Within, you should find a .log file with the format mmddyyyy_hhmmss, which represents the date and time the fix was run. Please copy and paste the contents of that file, making sure Word Wrap is off beforehand, if necessary.
Not unless MBAM or another security program is interfering. Right-click its icon in the system tray, uncheck "Enable Protection," and confirm. Also make sure any other security programs are not running before clicking "Run Fix" in OTL.
Delete ComboFix.exe from your desktop and download a fresh copy from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

1. Close any open browsers.

2. IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.

3. Open notepad and copy/paste the text in the quotebox below into it:

ADS::
C:\WINDOWS\system32\svchost.exe
File::
C:\Documents and Settings\Tom\Local Settings\Application Data\6e6301sD6p
C:\Documents and Settings\All Users.WINDOWS.0\Application Data\6e6301sD6p
C:\WINDOWS.0\system32\drivers\AFS2K.SYS
C:\WINDOWS.0\system32\spool\drivers\w32x86\3\HP1006MC.EXE
C:\Documents and Settings\Tom\My Documents\Downloads\CDRip-_lifehouse falling in_.mp3
C:\Documents and Settings\Tom\My Documents\Downloads\[CD.RIP] - falling in lifehouse.mp3
C:\Documents and Settings\Tom\My Documents\My Music\Top of Charts - 2005.wma
FireFox::
FF - ProfilePath - c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\7tmtob3r.default\
FF - prefs.js: browser.search.selectedEngine - SweetIM Search
FF - prefs.js: browser.startup.homepage - hxxp://home.sweetim.com


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
ComboFix 12-03-18.01 - Tom 03/18/2012 21:13:28.7.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1471.955 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Tom\Desktop\CFScript.txt
.
FILE ::
"c:\documents and settings\All Users.WINDOWS.0\Application Data\6e6301sD6p"
"c:\documents and settings\Tom\Local Settings\Application Data\6e6301sD6p"
"c:\documents and settings\Tom\My Documents\Downloads\[CD.RIP] - falling in lifehouse.mp3"
"c:\documents and settings\Tom\My Documents\Downloads\CDRip-_lifehouse falling in_.mp3"
"c:\documents and settings\Tom\My Documents\My Music\Top of Charts - 2005.wma"
"c:\windows.0\system32\drivers\AFS2K.SYS"
"c:\windows.0\system32\spool\drivers\w32x86\3\HP1006MC.EXE"
.
ADS - svchost.exe: deleted 88 bytes in 2 streams.
.
((((((((((((((((((((((((( Files Created from 2012-02-19 to 2012-03-19 )))))))))))))))))))))))))))))))
.
.
2012-03-18 18:35 . 2012-03-18 18:35 ——– d—–w- C:\_OTL
2012-03-18 13:05 . 2012-03-18 13:05 ——– d—–w- c:\program files\VS Revo Group
2012-03-17 14:38 . 2012-03-17 14:38 ——– d—–w- c:\program files\ESET
2012-03-16 01:49 . 2012-03-16 01:49 ——– d—–w- C:\TDSSKiller_Quarantine
2012-03-15 23:07 . 2008-04-13 19:40 62976 -c–a-w- c:\windows.0\system32\dllcache\cdrom.sys
2012-03-15 23:07 . 2008-04-13 19:40 62976 —-a-w- c:\windows.0\system32\drivers\cdrom.sys
2012-03-09 14:20 . 2012-03-12 15:36 ——– d—–w- c:\windows.0\SxsCaPendDel
2012-03-09 14:00 . 2012-03-09 14:00 388096 —-a-r- c:\documents and settings\Tom\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-31 23:39 . 2011-05-16 02:16 414368 —-a-w- c:\windows.0\system32\FlashPlayerCPLApp.cpl
2012-01-29 20:22 . 2012-01-29 20:22 1461992 —-a-w- c:\windows.0\system32\WdfCoInstaller01009.dll
2012-01-29 20:22 . 2012-01-29 20:22 851176 —-a-w- c:\windows.0\system32\WinUSBCoInstaller2.dll
2012-01-29 20:09 . 2012-01-29 20:09 544656 —-a-w- c:\windows.0\system32\deployJava1.dll
2012-01-29 20:03 . 2012-01-29 20:02 29561554 —-a-w- C:\installer_r16-windows.exe
2012-01-29 20:02 . 2012-01-29 20:02 84132744 —-a-w- C:\jdk-7u1-windows-x64.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-03-15_23.12.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-10-11 21:19 . 2012-03-17 02:21 278152 c:\windows.0\system32\FNTCACHE.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AOL Fast Start"="c:\program files\AOL Desktop 9.6\AOL.EXE" [2011-01-13 42320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malwarell\mbamgui.exe" [2012-01-13 460872]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [N/A]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 557056]
.
c:\documents and settings\Guest\Start Menu\Programs\Startup\
Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [N/A]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 557056]
.
c:\documents and settings\Default User\Start Menu\Programs\Startup\
Organize.lnk - c:\program files\Hewlett-Packard\HP Organize\bin\displayAgent.exe [N/A]
spamsubtract.lnk - c:\program files\interMute\SpamSubtract\SpamSub.exe [2003-10-14 557056]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows.0\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.0^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk]
path=c:\documents and settings\All Users.WINDOWS.0\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
backup=c:\windows.0\pss\McAfee Security Scan Plus.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Tom^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Tom\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows.0\pss\Adobe Gamma.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows.0\system32\dumprep 0 -k [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeAAMUpdater-1.0]
2010-03-06 08:44 500208 ——w- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS5ServiceManager]
2010-02-22 09:57 406992 —-a-w- c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows.0\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
2010-03-08 07:27 41800 —-a-w- c:\program files\Common Files\AOL\1168712829\ee\AOLSoftware.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2009-11-18 20:13 54576 —-a-w- c:\program files\Hewlett-Packard\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpbdfawep]
2007-04-25 18:28 954368 —-a-w- c:\program files\HP\Dfawep\bin\hpbdfawep.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelliPoint]
2005-03-23 21:26 217088 —-a-w- c:\program files\Microsoft IntelliPoint\point32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-06-14 21:18 221184 —-a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-06-14 21:18 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2010-04-17 02:12 3872080 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QveCtl2Tray]
2003-07-08 19:35 704512 —-a-w- c:\program files\Philips\Aurilium Sound Agent 2\805cpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
2006-10-12 03:41 95960 —-a-w- c:\progra~1\SYMNET~1\SNDMon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\type32]
2005-03-15 07:46 196608 —-a-w- c:\program files\Microsoft IntelliType Pro\type32.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
2004-10-22 15:53 53248 —-a-w- c:\windows.0\system32\VTTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"navapsvc"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccPwdSvc"=3 (0x3)
"ccEvtMgr"=2 (0x2)
"wuauserv"=2 (0x2)
"WmdmPmSN"=3 (0x3)
"winmgmt"=2 (0x2)
"WebClient"=2 (0x2)
"TermService"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\1168712829\\ee\\aolsoftware.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"c:\\Program Files\\Common Files\\AOL\\1168712829\\ee\\AOLDesktop.exe"=
"c:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\CreativesFiles\\Shareaza.exe"=
"c:\\WINDOWS.0\\system32\\dpvsetup.exe"=
"c:\\Program Files\\AOL 9.5\\waol.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpfcCopy.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqgplgtupl.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqusgm.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpqusgh.exe"=
"c:\\Program Files\\Hewlett-Packard\\HP Software Update\\hpwucli.exe"=
"c:\\Program Files\\Hewlett-Packard\\Digital Imaging\\smart web printing\\SmartWebPrintExe.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\AOL Desktop 9.6\\waol.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1900:UDP"= 1900:UDP:@xpsp2res.dll,-22007
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
"12555:TCP"= 12555:TCP:shareaza
"12555:UDP"= 12555:UDP:Shareaza2
"6346:TCP"= 6346:TCP:shareaza3
"6346:UDP"= 6346:UDP:shareaza4
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"12777:TCP"= 12777:TCP:sha
"12777:UDP"= 12777:UDP:sah2
.
R0 viasraid;viasraid;c:\windows.0\system32\drivers\viasraid.sys [10/31/2003 4:22 PM 77312]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malwarell\mbamservice.exe [11/15/2011 10:52 AM 652360]
R3 MBAMProtector;MBAMProtector;c:\windows.0\system32\drivers\mbam.sys [4/9/2010 7:01 PM 20464]
R3 psa805;Aurilium Sound Agent 2 (WDM);c:\windows.0\system32\drivers\psa805.sys [10/12/2006 12:51 AM 417536]
R3 QsndEnum;QSound Virtual Audio Devices Bus Enumerator;c:\windows.0\system32\drivers\QsndEnum.sys [10/12/2006 12:51 AM 12800]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys –> c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - ATWPKT2
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-13 c:\windows.0\Tasks\AdobeAAMUpdater-1.0-BASEMENT-Tom.job
- c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2011-02-22 08:44]
.
2009-01-28 c:\windows.0\Tasks\FRU Task 2003-04-06 08:52ewlett-Packard2003-04-06 08:52p psc 1200 series5E771253C1676EBED677BF361FDFC537825E15B8224905129.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 04:52]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://aol.com/
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 5.0\resources\en-US\local\search.html
IE: Download with &Shareaza - c:\creativesfiles\RazaWebHook32.dll/3000
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Tom\Application Data\Mozilla\Firefox\Profiles\7tmtob3r.default\
FF - prefs.js: browser.search.defaulturl -
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows.0\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Common Files\Java\Java Update\jusched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-18 21:23
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\.AFS2K]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\.DVDVRRdr_xp]
"ImagePath"="\*"
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\.UDFReadr]
"ImagePath"="\*"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3816)
c:\windows.0\system32\WININET.dll
c:\windows.0\system32\ieframe.dll
c:\windows.0\system32\webcheck.dll
c:\windows.0\system32\WPDShServiceObj.dll
c:\windows.0\system32\PortableDeviceTypes.dll
c:\windows.0\system32\PortableDeviceApi.dll
c:\program files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\windows.0\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll
.
Completion time: 2012-03-18 21:26:07
ComboFix-quarantined-files.txt 2012-03-19 01:26
ComboFix2.txt 2012-03-17 02:44
ComboFix3.txt 2012-03-15 23:19
.
Pre-Run: 101,790,871,552 bytes free
Post-Run: 101,798,748,160 bytes free
.
- - End Of File - - 457EFB414F7C5D8D526ACB78C5D42D8A
  • Please download the Java installer and save it to your desktop.
  • Double-click the new jxpiinstall icon on your desktop and go through the installation.
  • When the installation finishes, delete jxpiinstall from your desktop.
  • Now let's clear Java's cache.
    • Click Start > Control Panel
    • Double-click the Java icon. (If you don't see it, switch to Classic View on the left of the Control Panel window)
    • Under the General tab, click Settings under Temporary Internet Files.
    • Choose to Delete Files.
    • Check all boxes.
    • Click OK.
  • If you weren't prompted to reboot, please do so.
Also, please open Windows Explorer (Windows Key +E) and navigate to C:\WINDOWS.0\system32\drivers and let me know if AFS2K.SYS exists in that folder.

Finally, please advise how your computer is running and if there are any outstanding issues.
Thanks. Machine seems to be a little better. Its still a little slow but not bad for an older pc. Yes that file exists where you said it would be. Is that bad ? Says created oct 2008
  • VirusTotal

    We need to upload a file to VirusTotal for inspection.

    • Please visit VirusTotal by clicking here.
    • Click the Choose File button and search for the following file:
      • C:\WINDOWS.0\system32\drivers\AFS2K.SYS
    • Click Open.
    • Click Scan it!
    • Please be patient while the file is scanned.
    • If VirusTotal tells you that the file has already been scanned, click "reanalyse now".
    • Once scanned, copy and paste the link to the results page in your next reply.
    If you're having trouble loading VirusTotal, try VirSCAN or Jotti.

  • aswMBR

    • Double click aswMBR.exe to start the tool.
    • If virus definitions need to be downloaded, please do so.
    • Click Scan. Note: Do NOT attempt any Fix yet.
    • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • TDSSKiller

    Please download a fresh copy of TDSSKiller.zip

    • Extract it to your desktop
    • Double click TDSSKiller.exe
    • When the window opens, click on Change parameters
    • Under ”Additional options”, put a check mark in the box next to “Detect TDLFS file system”
    • Click OK
    • Press Start Scan
      • IMPORTANT: As we are only looking for a log of what is on the machine right now, choose to Skip whatever is found
      • Then click Continue > Reboot now
    • Copy and paste the log in your next reply
      • A copy of the log will be saved automatically to the root of the drive (typically C:\)
aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-15 09:34:12 —————————– 09:34:12.906 OS Version: Windows 5.1.2600 Service Pack 3 09:34:12.906 Number of processors: 1 586 0xA00 09:34:12.906 ComputerName: BASEMENT UserName: Tom 09:34:14.062 Initialize success 09:35:04.312 AVAST engine defs: 12031401 09:35:19.437 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 09:35:19.468 Disk 0 Vendor: Maxtor_6Y160P0 YAR41BW0 Size: 156334MB BusType: 3 09:35:19.484 Disk 0 MBR read successfully 09:35:19.484 Disk 0 MBR scan 09:35:19.546 Disk 0 Windows XP default MBR code 09:35:19.546 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 5647 MB offset 63 09:35:19.578 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 150675 MB offset 11566800 09:35:19.609 Disk 0 scanning sectors +320150880 09:35:19.703 Disk 0 scanning C:\WINDOWS.0\system32\drivers 09:35:20.500 File: C:\WINDOWS.0\system32\drivers\AFS2K.SYS **INFECTED** Win32:Alureon-AJI [Rtk] 09:35:25.515 File: C:\WINDOWS.0\system32\drivers\DVDVRRdr_xp.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:35:35.796 File: C:\WINDOWS.0\system32\drivers\Udfreadr.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:35:37.859 Disk 0 trace - called modules: 09:35:37.875 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaidexp.sys PCIIDEX.SYS 09:35:37.875 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a51aab8] 09:35:37.875 3 CLASSPNP.SYS[f7657fd7] -> nt!IofCallDriver -> \Device\00000067[0x8a5306c0] 09:35:37.890 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a4d3940] 09:35:38.640 AVAST engine scan C:\WINDOWS.0 09:35:56.359 File: C:\WINDOWS.0\wanmpsvc.exe **INFECTED** Win32:Patched-WQ [Trj] 09:35:58.000 AVAST engine scan C:\WINDOWS.0\system32 09:40:10.859 AVAST engine scan C:\WINDOWS.0\system32\drivers 09:40:11.546 File: C:\WINDOWS.0\system32\drivers\AFS2K.SYS **INFECTED** Win32:Alureon-AJI [Rtk] 09:40:15.937 File: C:\WINDOWS.0\system32\drivers\DVDVRRdr_xp.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:40:27.843 File: C:\WINDOWS.0\system32\drivers\Udfreadr.sys **INFECTED** Win32:Alureon-AJI [Rtk] 09:40:37.703 AVAST engine scan C:\Documents and Settings\Tom 09:43:36.437 File: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\80000000.@ **INFECTED** Win64:Sirefef-A [Trj] 09:43:36.546 File: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\800000cb.@ **INFECTED** Win32:Sirefef-AO [Rtk] 09:43:36.625 File: C:\Documents and Settings\Tom\Local Settings\Application Data\b9173f48\U\800000cf.@ **INFECTED** Win32:Trojan-gen 09:43:37.093 File: C:\Documents and Settings\Tom\Local Settings\Application Data\ilybnmel.exe **INFECTED** Win32:FakeAlert-CER [Trj] 09:56:41.812 AVAST engine scan C:\Documents and Settings\All Users.WINDOWS.0 10:11:38.484 Scan finished successfully 10:19:51.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Tom\Desktop\MBR.dat" 10:19:51.625 The log file has been saved successfully to "C:\Documents and Settings\Tom\Desktop\aswMBR.txt" aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-03-19 18:55:21 —————————– 18:55:21.875 OS Version: Windows 5.1.2600 Service Pack 3 18:55:21.875 Number of processors: 1 586 0xA00 18:55:21.875 ComputerName: BASEMENT UserName: Tom 18:55:22.468 Initialize success 18:56:25.515 AVAST engine defs: 12031700 18:56:46.203 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 18:56:46.203 Disk 0 Vendor: Maxtor_6Y160P0 YAR41BW0 Size: 156334MB BusType: 3 18:56:46.218 Disk 0 MBR read successfully 18:56:46.218 Disk 0 MBR scan 18:56:46.265 Disk 0 Windows XP default MBR code 18:56:46.265 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 5647 MB offset 63 18:56:46.281 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 150675 MB offset 11566800 18:56:46.296 Disk 0 scanning sectors +320150880 18:56:46.390 Disk 0 scanning C:\WINDOWS.0\system32\drivers 18:56:46.921 File: C:\WINDOWS.0\system32\drivers\AFS2K.SYS **INFECTED** Win32:Alureon-AJI [Rtk] 18:57:00.250 Disk 0 trace - called modules: 18:57:00.312 ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys viaidexp.sys PCIIDEX.SYS 18:57:00.359 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4abab8] 18:57:00.390 3 CLASSPNP.SYS[f7657fd7] -> nt!IofCallDriver -> \Device\00000068[0x8a57ecd8] 18:57:00.390 5 ACPI.sys[f75ae620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8a517940] 18:57:01.078 AVAST engine scan C:\WINDOWS.0 18:57:20.093 AVAST engine scan C:\WINDOWS.0\system32 19:11:28.250 AVAST engine scan C:\WINDOWS.0\system32\drivers 19:11:28.875 File: C:\WINDOWS.0\system32\drivers\AFS2K.SYS **INFECTED** Win32:Alureon-AJI [Rtk] 19:11:51.750 AVAST engine scan C:\Documents and Settings\Tom 19:18:18.453 AVAST engine scan C:\Documents and Settings\All Users.WINDOWS.0 19:27:48.453 Scan finished successfully 19:41:03.203 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Tom\Desktop\MBR.dat" 19:41:03.312 The log file has been saved successfully to "C:\Documents and Settings\Tom\Desktop\aswMBR.txt"

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI