This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rookits: Win32/Sirefef.AB, Win64/Sirefef.P - Google Redirect [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings, For the last couple of days, I've had a nasty Rootkit as mentioned on Title, I do believe it also goes under the name ZeroAccess. It redirect my google searches, slows down my PC and crashes my internet browsers alot (I actually about to make this topic, but Firefox crashed). Under Process for Task Manager, it is named PING.EXE I heard Combofix works wonders, but reading the Topic FAQ on your website says not to use it without permission, this rookit prevents the installiation of it anyway. I've used the following virus programs with little/no luck: Malwarebytes Anti-Malware Spybot Search and Destroy (Actually disabled some of the code that the rootkit uses on my browser, I still get redirects but not as common as I did before) TDSSKiller (It found NO threats) Microsoft Security Essentials (It detects the virus, it says it has removed but 5 minutes later, it finds it again) SUPERAntiSpyware Avast Microsoft Security Scanner. Now I've had this problem before, but I managed to disable it, now I got another one. I will change my passwords to Forums, bank accounts etc once I get this removed. I have Windows 7- 64bit. DDS report on next post in thread
DDS Report:

mRun-x64: [SeePassword] C:\Program Files (x86)\SeePassword\SeePassword.exe
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce-x64: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.894
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\p3o862tz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\GameSpy\Comrade\npcomrade.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\Andrew\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Andrew\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Users\Andrew\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R0 dc_fsf;dc_fsf;C:\Windows\system32\drivers\dc_fsf.sys –> C:\Windows\system32\drivers\dc_fsf.sys [?]
R0 dcrypt;dcrypt;C:\Windows\system32\drivers\dcrypt.sys –> C:\Windows\system32\drivers\dcrypt.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\system32\DRIVERS\scmndisp.sys –> C:\Windows\system32\DRIVERS\scmndisp.sys [?]
R0 Soluto;Soluto;C:\Windows\system32\DRIVERS\Soluto.sys –> C:\Windows\system32\DRIVERS\Soluto.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys –> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R1 EIO64;EIO Driver;C:\Windows\system32\DRIVERS\EIO64.sys –> C:\Windows\system32\DRIVERS\EIO64.sys [?]
R1 ndistgb;TheGreenBow NDIS filter driver;C:\Windows\system32\DRIVERS\ndistgb.sys –> C:\Windows\system32\DRIVERS\ndistgb.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-12 140672]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys –> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-5-16 44768]
R2 BCUService;Browser Configuration Utility Service;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-4-12 212232]
R2 GS In-Game Service;GS In-Game Service;C:\Program Files (x86)\GameTracker\GSInGameService.exe [2011-11-10 1677072]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-28 2343816]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;H:\Games\Program Files\Tribes Ascend Beta\HiPatchService.exe [2012-2-11 8704]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-16 654408]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-5-16 1153368]
R2 TgbIke Starter;TgbIke Starter;C:\Windows\System32\tgbstarter.exe –> C:\Windows\System32\tgbstarter.exe [?]
R2 WSWNA3100;WSWNA3100;C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2011-9-18 285152]
R3 Lycosa;Lycosa Keyboard;C:\Windows\system32\drivers\Lycosa.sys –> C:\Windows\system32\drivers\Lycosa.sys [?]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2010-8-12 15504]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R4 IOMap;IOMap;\??\C:\Windows\system32\drivers\IOMap64.sys –> C:\Windows\system32\drivers\IOMap64.sys [?]
S1 vaoxqunb;vaoxqunb;\??\C:\Windows\system32\drivers\vaoxqunb.sys –> C:\Windows\system32\drivers\vaoxqunb.sys [?]
S2 BackupService;BackupService;C:\Users\Andrew\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe [2011-4-24 83512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SolutoService;Soluto PCGenome Core Service;C:\Program Files\Soluto\SolutoService.exe [2012-4-24 584224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-6 257696]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe –> system32\AppleChargerSrv.exe [?]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;H:\Games\Program Files\Dragon Age Origins\Dragon Age\bin_ship\daupdatersvc.service.exe [2011-8-15 25832]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys –> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
S3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\system32\drivers\massfilter.sys –> C:\Windows\system32\drivers\massfilter.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-16 129976]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-24 370688]
S3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);C:\Windows\system32\drivers\t3.sys –> C:\Windows\system32\drivers\t3.sys [?]
S3 tapoas;TAP-Win32 Adapter OAS;C:\Windows\system32\DRIVERS\tapoas.sys –> C:\Windows\system32\DRIVERS\tapoas.sys [?]
S3 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-1-18 2250616]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vcd10bus;Virtual CD v10 Bus Enumerator;C:\Windows\system32\DRIVERS\vcd10bus.sys –> C:\Windows\system32\DRIVERS\vcd10bus.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 ZTEusbnet;ZTE USB-NDIS miniport;C:\Windows\system32\DRIVERS\ZTEusbnet.sys –> C:\Windows\system32\DRIVERS\ZTEusbnet.sys [?]
SUnknown jkbhmbji;jkbhmbji; [x]
SUnknown jqmpmaub;jqmpmaub; [x]
.
=============== Created Last 30 ================
.
2012-05-18 17:31:32 50000 —-a-w- C:\Windows\System32\drivers\vaoxqunb.sys
2012-05-18 17:30:43 69000 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73E37F07-F850-4958-8F01-C03DD6BDF523}\offreg.dll
2012-05-18 06:34:04 8955792 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73E37F07-F850-4958-8F01-C03DD6BDF523}\mpengine.dll
2012-05-17 06:36:41 8955792 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-16 20:34:49 8955792 ——w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Updates\mpengine.dll
2012-05-16 12:20:12 69976 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-05-16 12:19:20 41184 —-a-w- C:\Windows\avastSS.scr
2012-05-16 12:19:05 ——– d—–w- C:\ProgramData\AVAST Software
2012-05-16 12:15:15 ——– d—–w- C:\Program Files\AVAST Software
2012-05-16 11:36:16 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com
2012-05-16 11:36:16 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2012-05-16 11:23:23 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-05-16 11:18:27 ——– d—–w- C:\ProgramData\RegRun
2012-05-16 11:18:16 2 –shatr- C:\Windows\winstart.bat
2012-05-16 11:18:01 ——– d—–w- C:\Program Files (x86)\UnHackMe
2012-05-16 09:38:25 53248 —-a-w- C:\Windows\SysWow64\unrar.dll
2012-05-16 09:38:24 4358144 —-a-w- C:\Windows\uncsetup.exe
2012-05-16 01:00:42 84992 —-a-w- C:\Windows\System32\asycfilt.dll
2012-05-16 01:00:42 67584 —-a-w- C:\Windows\SysWow64\asycfilt.dll
2012-05-15 18:31:49 ——– d—–w- C:\Windows\SysWow64\Wat
2012-05-15 18:31:49 ——– d—–w- C:\Windows\System32\Wat
2012-05-15 17:41:02 ——– d—–w- C:\Program Files (x86)\MSXML 4.0
2012-05-15 17:07:47 80896 —-a-w- C:\Windows\System32\imagehlp.dll
2012-05-15 17:07:47 22896 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-05-15 17:07:47 220672 —-a-w- C:\Windows\System32\wintrust.dll
2012-05-15 17:07:47 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-05-15 17:07:47 158720 —-a-w- C:\Windows\SysWow64\imagehlp.dll
2012-05-15 17:07:46 5120 —-a-w- C:\Windows\SysWow64\wmi.dll
2012-05-15 17:07:46 5120 —-a-w- C:\Windows\System32\wmi.dll
2012-05-15 07:32:49 142336 —-a-w- C:\Windows\System32\poqexec.exe
2012-05-15 07:32:48 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2012-05-15 07:32:46 961024 —-a-w- C:\Windows\System32\CPFilters.dll
2012-05-15 07:32:46 642048 —-a-w- C:\Windows\SysWow64\CPFilters.dll
2012-05-15 07:32:45 850432 —-a-w- C:\Windows\SysWow64\sbe.dll
2012-05-15 07:32:45 259072 —-a-w- C:\Windows\System32\mpg2splt.ax
2012-05-15 07:32:45 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax
2012-05-15 07:32:45 1118720 —-a-w- C:\Windows\System32\sbe.dll
2012-05-15 07:30:55 759296 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2012-05-15 07:28:58 499200 —-a-w- C:\Windows\System32\drivers\afd.sys
2012-05-15 07:27:45 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll 2012-05-15 07:26:13 1895280 —-a-w- C:\Windows\System32\drivers\tcpip.sys 2012-05-15 07:26:03 4582912 —-a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe 2012-05-15 07:26:03 4247040 —-a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe 2012-05-15 07:26:03 2085376 —-a-w- C:\Windows\System32\ole32.dll 2012-05-15 07:26:03 1413632 —-a-w- C:\Windows\SysWow64\ole32.dll 2012-05-15 07:24:56 1732096 —-a-w- C:\Program Files\Windows Journal\NBDoc.DLL 2012-05-15 07:19:43 144384 —-a-w- C:\Windows\System32\cdd.dll 2012-05-15 07:17:35 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll 2012-05-15 07:17:35 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll 2012-05-15 07:12:01 77312 —-a-w- C:\Windows\System32\packager.dll 2012-05-15 07:12:01 67072 —-a-w- C:\Windows\SysWow64\packager.dll 2012-05-15 07:00:37 927800 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0B2251BA-5A07-4C7E-A396-F2FEE141A060}\gapaengine.dll 2012-05-15 06:59:27 167424 —-a-w- C:\Program Files\Windows Media Player\wmplayer.exe 2012-05-15 06:59:27 164864 —-a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe 2012-05-15 06:59:25 12625408 —-a-w- C:\Windows\SysWow64\wmploc.DLL 2012-05-15 06:59:24 12625920 —-a-w- C:\Windows\System32\wmploc.DLL 2012-05-15 06:57:58 826368 —-a-w- C:\Windows\SysWow64\rdpcore.dll 2012-05-15 06:57:58 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys 2012-05-15 06:57:58 204800 —-a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-05-15 06:57:58 1031680 —-a-w- C:\Windows\System32\rdpcore.dll 2012-05-15 06:57:55 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe 2012-05-15 06:57:55 76288 —-a-w- C:\Windows\System32\rdpwsx.dll 2012-05-15 06:57:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll 2012-05-15 06:56:57 9728 —-a-w- C:\Windows\SysWow64\sscore.dll 2012-05-15 06:56:57 236032 —-a-w- C:\Windows\System32\srvsvc.dll 2012-05-15 06:55:57 148992 —-a-w- C:\Windows\System32\t2embed.dll 2012-05-15 06:55:56 109056 —-a-w- C:\Windows\SysWow64\t2embed.dll 2012-05-15 06:47:02 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client 2012-05-15 06:46:56 ——– d—–w- C:\Program Files\Microsoft Security Client 2012-05-15 06:46:17 374664 —-a-w- C:\Windows\System32\drivers\netio.sys 2012-05-14 21:32:41 868848 —-a-w- C:\Windows\System32\drivers\sptd.sys 2012-05-07 11:11:48 ——– d—–w- C:\Users\Andrew\AppData\Local\id Software 2012-05-07 06:57:59 ——– d—–w- C:\Users\Andrew\AppData\Local\SniperV2 2012-05-07 06:00:21 102400 ——w- C:\Users\Andrew\AppData\Roaming\googleoez.exe 2012-05-06 10:08:19 ——– d—–w- C:\Users\Andrew\AppData\Roaming\.spoutcraft 2012-05-06 06:58:26 ——– d—–w- C:\Users\Andrew\AppData\Local\SniperV2 Demo 2012-04-29 11:16:23 ——– d—–w- C:\Users\Andrew\AppData\Roaming\puush 2012-04-29 02:03:23 ——– d—–w- C:\Program Files\TeamSpeak 3 Client 2012-04-28 23:12:36 ——– d—–w- C:\Program Files\Soluto 2012-04-25 02:37:08 ——– d—–w- C:\Users\Andrew\AppData\Local\The Witcher 2 2012-04-24 22:54:47 ——– d—–w- C:\Program Files\iPod 2012-04-24 22:54:45 ——– d—–w- C:\Program Files\iTunes 2012-04-21 12:15:14 ——– d—–w- C:\Program Files (x86)\Common Files\SourceTec 2012-04-20 22:21:04 23680 —-a-w- C:\Windows\System32\drivers\IOMap64.sys 2012-04-19 08:03:37 ——– d—–w- C:\Users\Andrew\AppData\Roaming\NVIDIA 2012-04-19 08:01:46 ——– d—–w- C:\Program Files (x86)\My Company Name 2012-04-19 08:00:08 16384 —-a-w- C:\Windows\System32\drivers\EIO64.sys 2012-04-19 07:49:43 ——– d—–w- C:\ProgramData\NVIDIA Corporation 2012-04-19 07:49:38 ——– d—–w- C:\Program Files\NVIDIA Corporation 2012-04-19 07:46:34 ——– d—–w- C:\Program Files (x86)\ASUS . ==================== Find3M ==================== . 2012-05-17 08:01:58 214520 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr 2012-05-17 08:01:58 214520 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0 2012-05-17 08:01:56 214520 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe 2012-05-14 21:21:31 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-05-14 21:21:31 419488 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-05-05 15:00:17 8744608 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2012-04-24 07:13:24 54728 —-a-w- C:\Windows\System32\drivers\Soluto.sys 2012-04-13 06:39:23 794408 —-a-w- C:\Windows\SysWow64\pbsvc.exe 2012-04-04 05:56:40 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys 2012-04-02 05:34:04 5504880 —-a-w- C:\Windows\System32\ntoskrnl.exe 2012-04-02 04:46:44 3958128 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-04-02 04:46:44 3902320 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-04-02 03:01:19 3143680 —-a-w- C:\Windows\System32\win32k.sys 2012-03-20 10:44:12 98688 —-a-w- C:\Windows\System32\drivers\NisDrvWFP.sys 2012-03-20 10:44:12 203888 —-a-w- C:\Windows\System32\drivers\MpFilter.sys 2012-03-17 08:34:25 11561984 —-a-w- C:\Windows\SysWow64\aticaldd.dll 2012-03-17 08:34:06 120320 —-a-w- C:\Windows\System32\atitmm64.dll 2012-03-17 08:33:57 54784 —-a-w- C:\Windows\System32\atimpc64.dll 2012-03-17 08:33:57 54784 —-a-w- C:\Windows\System32\amdpcom64.dll 2012-03-17 08:33:43 13859840 —-a-w- C:\Windows\System32\aticaldd64.dll 2012-03-17 08:32:19 10856960 —-a-w- C:\Windows\System32\drivers\atikmdag.sys 2012-03-17 08:31:45 19392000 —-a-w- C:\Windows\SysWow64\atioglxx.dll 2012-03-17 08:31:16 6200320 —-a-w- C:\Windows\SysWow64\atidxx32.dll 2012-03-17 08:30:40 5954048 —-a-w- C:\Windows\SysWow64\atiumdag.dll 2012-03-17 08:30:15 59392 —-a-w- C:\Windows\System32\atiedu64.dll 2012-03-17 08:30:11 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll 2012-03-17 08:29:54 7646208 —-a-w- C:\Windows\System32\atidxx64.dll 2012-03-17 08:29:51 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll 2012-03-17 08:29:12 33280 —-a-w- C:\Windows\SysWow64\atigktxx.dll 2012-03-17 08:29:06 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll 2012-03-17 08:29:01 496128 —-a-w- C:\Windows\System32\atieclxx.exe 2012-03-17 08:28:40 512000 —-a-w- C:\Windows\System32\atiadlxx.dll 2012-03-17 08:28:31 17408 —-a-w- C:\Windows\System32\atig6pxx.dll 2012-03-17 08:28:25 7551488 —-a-w- C:\Windows\System32\atiumd64.dll 2012-03-17 08:28:20 58880 —-a-w- C:\Windows\System32\coinst.dll 2012-03-17 08:28:20 159744 —-a-w- C:\Windows\System32\atiapfxx.exe 2012-03-17 08:28:01 51200 —-a-w- C:\Windows\System32\aticalrt64.dll 2012-03-17 08:28:00 25839104 —-a-w- C:\Windows\System32\atio6axx.dll 2012-03-17 08:26:57 53760 —-a-w- C:\Windows\SysWow64\atimpc32.dll 2012-03-17 08:26:57 53760 —-a-w- C:\Windows\SysWow64\amdpcom32.dll 2012-03-17 08:26:39 39936 —-a-w- C:\Windows\System32\atig6txx.dll 2012-03-17 08:26:21 235520 —-a-w- C:\Windows\System32\atiesrxx.exe 2012-03-17 08:26:19 791040 —-a-w- C:\Windows\SysWow64\aticfx32.dll 2012-03-17 08:26:11 33280 —-a-w- C:\Windows\SysWow64\atiuxpag.dll 2012-03-17 08:26:05 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll 2012-03-17 08:26:04 4958208 —-a-w- C:\Windows\System32\atiumd6a.dll 2012-03-17 08:25:54 356352 —-a-w- C:\Windows\SysWow64\atiadlxy.dll 2012-03-17 07:55:58 75632 —-a-w- C:\Windows\System32\drivers\partmgr.sys 2012-03-03 06:29:57 1541120 —-a-w- C:\Windows\System32\DWrite.dll 2012-03-03 06:29:42 320512 —-a-w- C:\Windows\System32\d3d10_1core.dll 2012-03-03 06:29:42 197120 —-a-w- C:\Windows\System32\d3d10_1.dll 2012-03-03 06:29:42 1837568 —-a-w- C:\Windows\System32\d3d10warp.dll 2012-03-03 06:29:41 902656 —-a-w- C:\Windows\System32\d2d1.dll 2012-03-03 05:40:21 1074176 —-a-w- C:\Windows\SysWow64\DWrite.dll 2012-03-03 05:40:10 1170944 —-a-w- C:\Windows\SysWow64\d3d10warp.dll 2012-03-03 05:40:09 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll 2012-03-03 05:40:09 218624 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll 2012-03-03 05:40:09 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2012-02-25 07:16:52 76888 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe 2012-02-23 00:18:36 279656 ——w- C:\Windows\System32\MpSigStub.exe 2008-03-08 21:25:10 236 —-a-w- C:\Program Files (x86)\Common Files\dx.reg . ============= FINISH: 11:45:32.48 ===============
Hi AWarGuy,

It looks like your DDS log was not posted in its entirety. I would like for you to run DDS again, then paste the entire contents of the log in your next post. If the log is too long, please upload the text file. Please also upload attach.txt.

Please download aswMBR.exe and save it to your desktop. 

Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)

Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review.
  • Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat.
  • Right click that file and select Send To>Compressed (zipped) file.
  • Attach that zipped file in your next reply as well.
Please do the following

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ———————————————————————————————

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Well aswMBR found 4 infected files, can't I press the FixMBR now? Besides, the virus is preventing me from INSTALLING ComboFix, it stops installing when it's about to finish.
No. aswMBR fixes MBR infections and as far as we know, you don't have an MBR infection. We are only using it for diagnostic information and to back up the MBR in case something goes wrong. Let's try booting into safe mode, then running ComboFix.

To boot into safe mode follow these steps:
  • Turn on or restart your computer
  • As the computer is booting, press and hold your F8 Key
  • This should bring up the Windows Advanced Options Menu
  • Use your arrow keys to move to Safe Mode and press your Enter Key
Try running ComboFix and let me know if it works.
No luck on Safe mode, as it is about to finish installing, it closes straight away. I tested it on my laptop and it installed fine.
Can you explain what you mean by installing? Do you see the command prompt window? Do you see "Stage 1, Stage 2, Stage 3…" etc? Please check your C:\ drive for a log (combofix.txt).
What I mean is that, when I run the link you gave, as it extracts, when it reaches the final files to extact, it just closes. I didn't close it or anything:

Image shown:

[external image: Posted Image]
Hi AWarGuy,

I need you to enable viewing of file extensions. If you need help doing this, follow this guide. After doing so, please rename ComboFix to iexplore.exe. Make sure there is only one .exe at the end. Move ComboFix (now iexplore.exe) to your C:\ drive. Restart your computer and boot into safe mode. Run ComboFix from the C:\ drive and let me know if you have any luck.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI