This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

multiple trojan infectection [Closed]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

i recently started updating my pc. i downloaded avast it did an initial scan found some infections it removed or moved them to teh vault. when it was done it gave me the option to run a boot up scan i clicked yes. during the boot up scan it found multiple trojans and adware in the c:\windows folder I entered the option to remove all. when it was done and windows loaded normally my mouse was clicking on stuff without me pushing the button, pc was slower so i did a system restore to before avast was installed and everything started looking normal. I ran another scan with avast it found about 100 trojans and adware it moved them to vault or removed them, now internet sometimes works it does the mouse thing ocasionally i turn it off and start it up again seems to work, right now im in safe mode. if someone could take a look at the log and tell me,if this machine still salvageable? thanks. . DDS (Ver_11-03-05.01) - NTFSx86 NETWORK Run by [removed] at 11:55:49.59 on Tue 05/22/2012 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.266 [GMT -7:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Sonny13\My Documents\Downloads\dds.scr . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uSearch Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http://www.yahoo.com uWindow Title = Microsoft Internet Explorer provided by Compaq uSearch Bar = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=searchfavweb&c=3c01&lc=0409 mDefault_Page_URL = hxxp://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=3c01&lc=0409 mDefault_Search_URL = hxxp://www.i–search.com/ie/ mStart Page = hxxp://yahoo.sbc.com/dsl BHO: Band Class: {00f1d395-4744-40f0-a611-980f61ae2c59} - c:\windows\dsr.dll BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll BHO: BestOffers Shopping BHO: {f5de8adb-4a69-4e56-96ab-823171c8e9d8} - c:\program files\tbonas\TBONlchr.dll TB: BestOffers Shopping v1.20: {7fd44536-9df0-4034-939f-5bd4d98e3187} - c:\program files\tbonas\TBONlchr.dll EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Microsoft Works Update Detection] c:\program files\microsoft works\WkDetect.exe uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\GetFlash.exe mRun: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize mRun: [WorksFUD] mRun: [Microsoft Works Portfolio] c:\program files\microsoft works\WksSb.exe /AllUsers mRun: [srmclean] c:\cpqs\scom\srmclean.exe mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe mRun: [zXDHX9] c:\documents and settings\michael corleone\local settings\temp\zXDHX9.exe mRun: [IPInSightLAN 02] "c:\program files\visual networks\visual ip insight\sbc\IPClient.exe" -l mRun: [IPInSightMonitor 02] "c:\program files\visual networks\visual ip insight\sbc\IPMon32.exe" mRun: [PKBdhT.exe] c:\windows\system32\PKBdhT.exe mRun: [zXDHX9.exe] c:\documents and settings\michael corleone\local settings\temp\zXDHX9.exe mRun: [Dinst] c:\windows\dinst.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot mRun: [PaperPort PTD] c:\program files\scansoft\paperport\pptd40nt.exe mRun: [IndexSearch] c:\program files\scansoft\paperport\IndexSearch.exe mRun: [ftimels] c:\windows\system32\cwybbic.exe mRun: [CPQEASYACC] c:\compaq\eakdrv\STARTDRV.exe mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSConfig.exe /auto StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\common files\microsoft shared\works shared\wkcalrem.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\status~1.lnk - c:\program files\brother\brmfcmon\BrMfcWnd.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {00000075-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxacm.CAB DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://activation.rr.com/install/download/tgctlcm.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {205FF73B-CA67-11D5-99DD-444553540013} - hxxp://adserver.sharewareonline.com/adserver/Install.cab DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv9dmo.cab DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} - hxxp://aolcc.aol.com/computercheckup/qdiagcc.cab DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.pw.aol.com/molbin/shared/mcinsctl/en-us/4,0,0,77/mcinsctl.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123900699093 DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.pw.aol.com/molbin/shared/mcgdmgr/en-us/1,0,0,18/mcgdmgr.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Hosts: 64.12.152.18 search.netscape.com . ================= FIREFOX =================== . FF - ProfilePath - c:\docume~1\sonny13\applic~1\mozilla\firefox\profiles\rihcn18h.default\ FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll . ============= SERVICES / DRIVERS =============== . S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-5-21 337880] S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-5-21 44768] S3 Gcr432;Gcr432;c:\windows\system32\drivers\Gcr432.sys [2001-9-6 89371] S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [1980-5-21 129976] S4 SvcProc;System Startup Service ;c:\windows\svcproc.exe [2003-1-26 8704] . =============== Created Last 30 ================ . 2012-05-22 08:52:00 ——– d—–w- c:\windows\pss 2012-05-22 08:14:19 ——– d—–w- c:\windows\system32\wbem\AutoRecover 2012-05-22 07:54:49 ——– d—–w- c:\windows\peernet 2012-05-22 07:54:47 ——– d—–w- c:\windows\provisioning 2012-05-22 07:49:31 ——– d—–w- c:\windows\ServicePackFiles 2012-05-22 07:40:46 ——– d—–w- c:\windows\system32\ReinstallBackups 2012-05-22 07:40:15 15872 —-a-w- c:\windows\system32\spupdsvc.exe 2012-05-22 07:33:30 ——– d—–w- c:\windows\EHome 2012-05-22 02:56:51 ——– d—–w- c:\docume~1\sonny13\locals~1\applic~1\Adobe 2012-05-21 22:06:59 41184 —-a-w- c:\windows\avastSS.scr 2012-05-21 22:05:53 ——– d—–w- c:\program files\AVAST Software 2012-05-21 22:05:53 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVAST Software . ==================== Find3M ==================== . . ============= FINISH: 11:56:10.10 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———-

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
CKScanner - Additional Security Risks - These are not necessarily bad c:\documents and settings\michael corleone\application data\macromedia\flash player\macromedia.com\support\flashplayer\sys\#crackle.com\settings.sol scanner sequence 3.NA.11.SWLBHO —– EOF —– aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-05-22 23:24:09 —————————– 23:24:09.359 OS Version: Windows 5.1.2600 Service Pack 2 23:24:09.359 Number of processors: 1 586 0x102 23:24:09.359 ComputerName: PANCHO1 UserName: Sonny13 23:24:12.015 Initialize success 23:24:13.109 AVAST engine defs: 12060201 23:24:22.359 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 23:24:22.375 Disk 0 Vendor: Maxtor_4D060H3 DAH017K0 Size: 57241MB BusType: 3 23:24:22.390 Disk 0 MBR read successfully 23:24:22.390 Disk 0 MBR scan 23:24:22.406 Disk 0 unknown MBR code 23:24:22.421 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 53237 MB offset 63 23:24:22.421 Disk 0 Partition - 00 0F Extended LBA 4001 MB offset 109030320 23:24:22.453 Disk 0 Partition 2 00 0B FAT32 MSWIN4.1 4001 MB offset 109030383 23:24:22.468 Disk 0 scanning sectors +117225360 23:24:22.562 Disk 0 scanning C:\WINDOWS\system32\drivers 23:24:42.593 Service scanning 23:25:03.578 Modules scanning 23:25:21.515 Disk 0 trace - called modules: 23:25:21.890 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys intelide.sys PCIIDEX.SYS 23:25:21.906 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82e7bab8] 23:25:21.906 3 CLASSPNP.SYS[f869705b] -> nt!IofCallDriver -> \Device\0000005b[0x82ebff18] 23:25:21.921 5 ACPI.sys[f85ed620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x82fac940] 23:25:22.390 AVAST engine scan C:\WINDOWS 23:25:37.234 AVAST engine scan C:\WINDOWS\system32 23:29:15.734 AVAST engine scan C:\WINDOWS\system32\drivers 23:29:38.687 AVAST engine scan C:\Documents and Settings\Sonny13 23:30:08.234 AVAST engine scan C:\Documents and Settings\All Users 23:30:42.531 Scan finished successfully 23:31:09.312 Disk 0 MBR has been saved successfully to "C:\Program Files\Mozilla Firefox\MBR.dat" 23:31:09.343 The log file has been saved successfully to "C:\Program Files\Mozilla Firefox\aswMBR.txt"
Hi,

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000003d Kernel Drivers (total 124): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EC000 \WINDOWS\system32\hal.dll 0xF8AB6000 \WINDOWS\system32\KDCOM.DLL 0xF89C6000 \WINDOWS\system32\BOOTVID.dll 0xF8567000 ACPI.sys 0xF8AB8000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF8556000 pci.sys 0xF85B6000 isapnp.sys 0xF85C6000 ohci1394.sys 0xF85D6000 \WINDOWS\System32\DRIVERS\1394BUS.SYS 0xF8ABA000 intelide.sys 0xF8836000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF85E6000 MountMgr.sys 0xF8537000 ftdisk.sys 0xF883E000 PartMgr.sys 0xF85F6000 VolSnap.sys 0xF851F000 atapi.sys 0xF8606000 disk.sys 0xF8616000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF8500000 fltmgr.sys 0xF84EE000 sr.sys 0xF84D7000 KSecDD.sys 0xF844A000 Ntfs.sys 0xF841D000 NDIS.sys 0xF8626000 vvoice.sys 0xF83BB000 vpctcom.sys 0xF8327000 vmodem.sys 0xF830C000 Mup.sys 0xF82F3000 IPVNMon.sys 0xF8636000 agp440.sys 0xF8666000 \SystemRoot\System32\DRIVERS\nic1394.sys 0xF7B92000 \SystemRoot\System32\DRIVERS\nv4_mini.sys 0xF7B7E000 \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS 0xF7B61000 \SystemRoot\System32\DRIVERS\e100b325.sys 0xF7B45000 \SystemRoot\System32\DRIVERS\ptserlp.sys 0xF88AE000 \SystemRoot\System32\Drivers\Modem.SYS 0xF88B6000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF88BE000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF7B31000 \SystemRoot\System32\DRIVERS\parport.sys 0xF8756000 \SystemRoot\System32\DRIVERS\serial.sys 0xF8A62000 \SystemRoot\System32\DRIVERS\serenum.sys 0xF88C6000 \SystemRoot\System32\DRIVERS\fdc.sys 0xF8766000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xF8776000 \SystemRoot\System32\DRIVERS\redbook.sys 0xF7B0E000 \SystemRoot\System32\DRIVERS\ks.sys 0xF8786000 \SystemRoot\System32\Drivers\Imapi.SYS 0xF88CE000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xF7AEB000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF7A85000 \SystemRoot\system32\drivers\smwdm.sys 0xF8C16000 \SystemRoot\system32\drivers\SENSUPGD.SYS 0xF7A61000 \SystemRoot\system32\drivers\portcls.sys 0xF8796000 \SystemRoot\system32\drivers\drmk.sys 0xF87A6000 \SystemRoot\System32\DRIVERS\processr.sys 0xF8ADA000 \SystemRoot\System32\DRIVERS\serscan.sys 0xF8C25000 \SystemRoot\System32\DRIVERS\audstub.sys 0xF87B6000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xF8A6E000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xF79EA000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xF87C6000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xF87D6000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xF88D6000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xF79D9000 \SystemRoot\System32\DRIVERS\psched.sys 0xF87E6000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xF88DE000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xF88E6000 \SystemRoot\System32\DRIVERS\raspti.sys 0xF87F6000 \SystemRoot\System32\DRIVERS\termdd.sys 0xF8ADC000 \SystemRoot\System32\DRIVERS\swenum.sys 0xF79A5000 \SystemRoot\System32\DRIVERS\update.sys 0xF8A7E000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xF8816000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF88EE000 \SystemRoot\System32\DRIVERS\flpydisk.sys 0xF8676000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF8AE4000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xF8AE6000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF8D05000 \SystemRoot\System32\Drivers\Null.SYS 0xF8AE8000 \SystemRoot\System32\Drivers\Beep.SYS 0xF88FE000 \SystemRoot\System32\DRIVERS\HIDPARSE.SYS 0xF8906000 \SystemRoot\System32\drivers\vga.sys 0xF8AEA000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF8AEC000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF890E000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF8916000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF8AAA000 \SystemRoot\System32\DRIVERS\rasacd.sys 0xF5919000 \SystemRoot\System32\DRIVERS\ipsec.sys 0xF58C1000 \SystemRoot\System32\DRIVERS\tcpip.sys 0xF8686000 \SystemRoot\System32\Drivers\aswTdi.SYS 0xF5899000 \SystemRoot\System32\DRIVERS\netbt.sys 0xF891E000 \SystemRoot\System32\Drivers\AswRdr.SYS 0xF5877000 \SystemRoot\System32\drivers\afd.sys 0xF8696000 \SystemRoot\System32\DRIVERS\netbios.sys 0xF584B000 \SystemRoot\System32\DRIVERS\rdbss.sys 0xF57B4000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xF7CE7000 \SystemRoot\System32\Drivers\Fips.SYS 0xF5793000 \SystemRoot\System32\DRIVERS\ipnat.sys 0xF7CD7000 \SystemRoot\System32\DRIVERS\wanarp.sys 0xF7CC7000 \SystemRoot\System32\DRIVERS\arp1394.sys 0xF8926000 \SystemRoot\System32\DRIVERS\usbccgp.sys 0xF8202000 \SystemRoot\System32\DRIVERS\hidusb.sys 0xF7CB7000 \SystemRoot\System32\DRIVERS\HIDCLASS.SYS 0xF81FE000 \SystemRoot\System32\DRIVERS\mouhid.sys 0xF81FA000 \SystemRoot\System32\DRIVERS\kbdhid.sys 0xF56A2000 \SystemRoot\System32\Drivers\aswSP.SYS 0xF7CA7000 \SystemRoot\System32\Drivers\Aavmker4.SYS 0xF5657000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF563F000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF8AFC000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF5950000 \SystemRoot\System32\drivers\Dxapi.sys 0xF8946000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF8CA7000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xF52C9000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xF51C7000 \SystemRoot\System32\Drivers\aswMon2.SYS 0xF4F0A000 \SystemRoot\system32\drivers\wdmaud.sys 0xF5157000 \SystemRoot\system32\drivers\sysaudio.sys 0xF4CF8000 \SystemRoot\System32\DRIVERS\mrxdav.sys 0xF8B56000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xF8B5C000 \SystemRoot\System32\Drivers\ASCTRM.SYS 0xF4E6D000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF4BD9000 \SystemRoot\System32\DRIVERS\srv.sys 0xF46F4000 \SystemRoot\System32\Drivers\HTTP.sys 0xF3D2D000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 33): 0 System Idle Process 4 System 572 C:\WINDOWS\system32\smss.exe 636 csrss.exe 660 C:\WINDOWS\system32\winlogon.exe 708 C:\WINDOWS\system32\services.exe 720 C:\WINDOWS\system32\lsass.exe 880 C:\WINDOWS\system32\svchost.exe 956 svchost.exe 1048 C:\WINDOWS\system32\svchost.exe 1100 svchost.exe 1240 svchost.exe 1404 C:\Program Files\AVAST Software\Avast\AvastSvc.exe 1456 C:\WINDOWS\system32\spoolsv.exe 1568 scardsvr.exe 200 svchost.exe 328 C:\WINDOWS\system32\nvsvc32.exe 608 C:\WINDOWS\system32\pctspk.exe 788 C:\WINDOWS\system32\svchost.exe 1728 alg.exe 2236 C:\WINDOWS\explorer.exe 2344 C:\Program Files\BroadJump\Client Foundation\CFD.exe 2380 C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe 2388 C:\Program Files\Visual Networks\Visual IP InSight\SBC\ipmon32.exe 2460 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe 2576 C:\Compaq\EAKDRV\STARTDRV.exe 2596 C:\Program Files\AVAST Software\Avast\AvastUI.exe 2792 C:\Compaq\EAKDRV\EAKDRV.exe 2832 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe 2980 C:\Compaq\EAKDRV\EAUSBKBD.exe 4028 C:\WINDOWS\system32\wuauclt.exe 2284 C:\WINDOWS\system32\wscntfy.exe 2556 C:\Documents and Settings\Sonny13\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x0000000c`ff57de00 (FAT32) PhysicalDrive0 Model Number: Maxtor4D060H3, Rev: DAH017K0 Size Device Name MBR Status ——————————————– 55 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: 2B97AC1E4CC0001F5E628D06B3A72CB8C9A67E75 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Hi,

Thank you. :)

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-
ComboFix 12-06-04.02 - Sonny13 05/24/2012 16:33:16.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.189 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Administrator\WINDOWS
c:\documents and settings\Default User\WINDOWS
c:\documents and settings\michael corleone\WINDOWS
c:\documents and settings\Owner\WINDOWS
c:\documents and settings\shera\WINDOWS
c:\documents and settings\Sonny13\WINDOWS
C:\Install.exe
c:\program files\SoftwareOnline
c:\windows\_detmp.2
c:\windows\desktop
c:\windows\desktop\Compaq Knowledge Center.lnk
c:\windows\didduid.ini
c:\windows\Downloaded Program Files\Install.inf
c:\windows\Downloaded Program Files\UWFX5LP_0001_0802NetInstaller.exe
c:\windows\patch.exe
c:\windows\SET4DB.tmp
c:\windows\system32\_005646_.tmp.dll
c:\windows\system32\_005647_.tmp.dll
c:\windows\system32\_005648_.tmp.dll
c:\windows\system32\_005649_.tmp.dll
c:\windows\system32\_005656_.tmp.dll
c:\windows\system32\_005657_.tmp.dll
c:\windows\system32\_005658_.tmp.dll
c:\windows\system32\_005659_.tmp.dll
c:\windows\system32\_005661_.tmp.dll
c:\windows\system32\_005662_.tmp.dll
c:\windows\system32\_005663_.tmp.dll
c:\windows\system32\_005665_.tmp.dll
c:\windows\system32\_005666_.tmp.dll
c:\windows\system32\_005668_.tmp.dll
c:\windows\system32\_005669_.tmp.dll
c:\windows\system32\_005670_.tmp.dll
c:\windows\system32\_005671_.tmp.dll
c:\windows\system32\_005672_.tmp.dll
c:\windows\system32\_005675_.tmp.dll
c:\windows\system32\_005676_.tmp.dll
c:\windows\system32\_005680_.tmp.dll
c:\windows\system32\_005681_.tmp.dll
c:\windows\system32\_005683_.tmp.dll
c:\windows\system32\_005685_.tmp.dll
c:\windows\system32\_005686_.tmp.dll
c:\windows\system32\_005688_.tmp.dll
c:\windows\system32\_005689_.tmp.dll
c:\windows\system32\_005690_.tmp.dll
c:\windows\system32\_005691_.tmp.dll
c:\windows\system32\_005692_.tmp.dll
c:\windows\system32\_005695_.tmp.dll
c:\windows\system32\_005696_.tmp.dll
c:\windows\system32\_005697_.tmp.dll
c:\windows\system32\_005698_.tmp.dll
c:\windows\system32\_005699_.tmp.dll
c:\windows\system32\_005704_.tmp.dll
c:\windows\system32\_005706_.tmp.dll
c:\windows\system32\_005707_.tmp.dll
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\dllcache\wmpvis.dll
c:\windows\system32\drivers\etc\hosts.bho
c:\windows\system32\SET179.tmp
c:\windows\system32\SET17A.tmp
c:\windows\system32\SET17C.tmp
c:\windows\system32\SET17E.tmp
c:\windows\system32\SET17F.tmp
c:\windows\system32\SET180.tmp
c:\windows\system32\SET187.tmp
c:\windows\system32\SET188.tmp
c:\windows\system32\SET18B.tmp
c:\windows\system32\SET19A.tmp
c:\windows\system32\SET1A0.tmp
c:\windows\system32\SET1A1.tmp
c:\windows\system32\SET1A4.tmp
c:\windows\system32\SET1A5.tmp
c:\windows\system32\SET1A6.tmp
c:\windows\system32\SET1A8.tmp
c:\windows\system32\SET1A9.tmp
c:\windows\system32\SET1AC.tmp
c:\windows\system32\SET1AD.tmp
c:\windows\system32\SET1AE.tmp
c:\windows\system32\SET1AF.tmp
c:\windows\system32\SET1B5.tmp
c:\windows\system32\SET1BC.tmp
c:\windows\system32\SET1BD.tmp
c:\windows\system32\SET1BE.tmp
c:\windows\system32\SET1BF.tmp
c:\windows\system32\SET1C2.tmp
c:\windows\system32\SET1C4.tmp
c:\windows\system32\SET1C5.tmp
c:\windows\system32\SET1CC.tmp
c:\windows\system32\SET1CE.tmp
c:\windows\system32\SET1CF.tmp
c:\windows\system32\SET1D0.tmp
c:\windows\system32\SET1D2.tmp
c:\windows\system32\SET1D3.tmp
c:\windows\system32\SET1D4.tmp
c:\windows\system32\SET1D9.tmp
c:\windows\system32\SET1DA.tmp
c:\windows\system32\SET1DB.tmp
c:\windows\system32\SET1DC.tmp
c:\windows\system32\SET1DF.tmp
c:\windows\system32\SET1E5.tmp
c:\windows\system32\SET1EB.tmp
c:\windows\system32\SET1EC.tmp
c:\windows\system32\SET1EF.tmp
c:\windows\system32\SET1F0.tmp
c:\windows\system32\SET1F2.tmp
c:\windows\system32\SET1F3.tmp
c:\windows\system32\SET1F5.tmp
c:\windows\system32\SET1FA.tmp
c:\windows\system32\SET1FB.tmp
c:\windows\system32\SET1FD.tmp
c:\windows\system32\SET20A.tmp
c:\windows\system32\SET20B.tmp
c:\windows\system32\SET20E.tmp
c:\windows\system32\SET210.tmp
c:\windows\system32\SET211.tmp
c:\windows\system32\SET212.tmp
c:\windows\system32\SET213.tmp
c:\windows\system32\SET214.tmp
c:\windows\system32\SET215.tmp
c:\windows\system32\SET219.tmp
c:\windows\system32\SET225.tmp
c:\windows\system32\SET22A.tmp
c:\windows\system32\SET22C.tmp
c:\windows\system32\SET22E.tmp
c:\windows\system32\SET22F.tmp
c:\windows\system32\SET230.tmp
c:\windows\system32\SET233.tmp
c:\windows\system32\SET234.tmp
c:\windows\system32\SET239.tmp
c:\windows\system32\SET23C.tmp
c:\windows\system32\SET23D.tmp
c:\windows\system32\SET23E.tmp
c:\windows\system32\SET244.tmp
c:\windows\system32\SET245.tmp
c:\windows\system32\SET246.tmp
c:\windows\system32\SET24E.tmp
c:\windows\system32\SET254.tmp
c:\windows\system32\SET255.tmp
c:\windows\system32\SET256.tmp
c:\windows\system32\SET258.tmp
c:\windows\system32\SET25A.tmp
c:\windows\system32\SET260.tmp
c:\windows\system32\SET26C.tmp
c:\windows\system32\SET26E.tmp
c:\windows\system32\SET270.tmp
c:\windows\system32\SET271.tmp
c:\windows\system32\SET272.tmp
c:\windows\system32\SET27F.tmp
c:\windows\system32\SET281.tmp
c:\windows\system32\SET282.tmp
c:\windows\system32\SET285.tmp
c:\windows\system32\SET287.tmp
c:\windows\system32\SET28B.tmp
c:\windows\system32\SET29F.tmp
c:\windows\system32\SET2A0.tmp
c:\windows\system32\SET2A7.tmp
c:\windows\system32\SET2A8.tmp
c:\windows\system32\SET2AB.tmp
c:\windows\system32\SET2AC.tmp
c:\windows\system32\SET2AD.tmp
c:\windows\system32\SET2AE.tmp
c:\windows\system32\SET2AF.tmp
c:\windows\system32\SET2B1.tmp
c:\windows\system32\SET2B2.tmp
c:\windows\system32\SET2B3.tmp
c:\windows\system32\SET2B5.tmp
c:\windows\system32\SET2B6.tmp
c:\windows\system32\SET2B7.tmp
c:\windows\system32\SET2BA.tmp
c:\windows\system32\SET2BD.tmp
c:\windows\system32\SET2C2.tmp
c:\windows\system32\SET2C3.tmp
c:\windows\system32\SET2C4.tmp
c:\windows\system32\SET2C8.tmp
c:\windows\system32\SET2C9.tmp
c:\windows\system32\SET2CA.tmp
c:\windows\system32\SET2CC.tmp
c:\windows\system32\SET2CF.tmp
c:\windows\system32\SET2D1.tmp
c:\windows\system32\SET2D2.tmp
c:\windows\system32\SET2D5.tmp
c:\windows\system32\SET2D6.tmp
c:\windows\system32\SET2D9.tmp
c:\windows\system32\SET2DC.tmp
c:\windows\system32\SET2DD.tmp
c:\windows\system32\SET2E4.tmp
c:\windows\system32\SET2EA.tmp
c:\windows\system32\SET2F0.tmp
c:\windows\system32\SET2F2.tmp
c:\windows\system32\SET2F3.tmp
c:\windows\system32\SET2F7.tmp
c:\windows\system32\SET304.tmp
c:\windows\system32\SET307.tmp
c:\windows\system32\SET309.tmp
c:\windows\system32\SET30A.tmp
c:\windows\system32\SET316.tmp
c:\windows\system32\SET318.tmp
c:\windows\system32\SET319.tmp
c:\windows\system32\SET31A.tmp
c:\windows\system32\SET31B.tmp
c:\windows\system32\SET31D.tmp
c:\windows\system32\SET31F.tmp
c:\windows\system32\SET323.tmp
c:\windows\system32\SET327.tmp
c:\windows\system32\SET333.tmp
c:\windows\system32\SET336.tmp
c:\windows\system32\SET337.tmp
c:\windows\system32\SET339.tmp
c:\windows\system32\SET33A.tmp
c:\windows\system32\SET33F.tmp
c:\windows\system32\SET341.tmp
c:\windows\system32\SET342.tmp
c:\windows\system32\SET349.tmp
c:\windows\system32\SET358.tmp
c:\windows\system32\SET359.tmp
c:\windows\system32\SET35A.tmp
c:\windows\system32\SET35B.tmp
c:\windows\system32\SET35E.tmp
c:\windows\system32\SET366.tmp
c:\windows\system32\SET368.tmp
c:\windows\system32\SET36E.tmp
c:\windows\system32\SET370.tmp
c:\windows\system32\SET377.tmp
c:\windows\system32\SET379.tmp
c:\windows\system32\SET393.tmp
c:\windows\system32\SET397.tmp
c:\windows\system32\SET399.tmp
c:\windows\system32\SET39B.tmp
c:\windows\system32\SET3A2.tmp
c:\windows\system32\SET3A7.tmp
c:\windows\system32\SET3BD.tmp
c:\windows\system32\SET3C0.tmp
c:\windows\system32\SET3C6.tmp
c:\windows\system32\SET3C8.tmp
c:\windows\system32\SET3C9.tmp
c:\windows\system32\SET3CA.tmp
c:\windows\system32\SET3D0.tmp
c:\windows\system32\SET3D4.tmp
c:\windows\system32\SET3DD.tmp
c:\windows\system32\SET3E3.tmp
c:\windows\system32\SET3E5.tmp
c:\windows\system32\SET3E6.tmp
c:\windows\system32\SET3E7.tmp
c:\windows\system32\SET3F1.tmp
c:\windows\system32\SET3F5.tmp
c:\windows\system32\SET400.tmp
c:\windows\system32\SET413.tmp
c:\windows\system32\SET414.tmp
c:\windows\system32\SET43E.tmp
c:\windows\system32\SET441.tmp
c:\windows\system32\SET449.tmp
c:\windows\system32\SET44A.tmp
c:\windows\system32\SET44C.tmp
c:\windows\system32\SET44D.tmp
c:\windows\system32\SET44E.tmp
c:\windows\system32\SET451.tmp
c:\windows\system32\SET453.tmp
c:\windows\system32\SET454.tmp
c:\windows\system32\SET456.tmp
c:\windows\system32\SET459.tmp
c:\windows\system32\SET45B.tmp
c:\windows\system32\SET460.tmp
c:\windows\system32\SET461.tmp
c:\windows\system32\SET469.tmp
c:\windows\system32\SET470.tmp
c:\windows\system32\SET477.tmp
c:\windows\system32\SET47B.tmp
c:\windows\system32\SET47E.tmp
c:\windows\system32\SET480.tmp
c:\windows\system32\SET484.tmp
c:\windows\system32\SET487.tmp
c:\windows\system32\SET488.tmp
c:\windows\system32\SET489.tmp
c:\windows\system32\SET48D.tmp
c:\windows\system32\SET48E.tmp
c:\windows\system32\SET48F.tmp
c:\windows\system32\SET492.tmp
c:\windows\system32\SET493.tmp
c:\windows\system32\SET49C.tmp
c:\windows\system32\SET49F.tmp
c:\windows\system32\SET4A1.tmp
c:\windows\system32\SET4A4.tmp
c:\windows\system32\SET4A7.tmp
c:\windows\system32\SET4A9.tmp
c:\windows\system32\SETF5D.tmp
c:\windows\system32\SETF61.tmp
c:\windows\system32\SETF64.tmp
c:\windows\system32\SETF69.tmp
c:\windows\system32\SETF9A.tmp
c:\windows\system32\SETFC3.tmp
c:\windows\system32\stlbdist.XML
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_SVCPROC
——-\Service_SvcProc
.
.
((((((((((((((((((((((((( Files Created from 2012-04-24 to 2012-05-24 )))))))))))))))))))))))))))))))
.
.
2012-05-24 22:07 . 2012-05-24 22:07 ——– d—–w- c:\documents and settings\Sonny13\Local Settings\Application Data\Thunderbird
2012-05-24 22:07 . 2012-05-24 22:07 ——– d—–w- c:\documents and settings\Sonny13\Application Data\Thunderbird
2012-05-24 02:37 . 2012-05-24 02:37 ——– d—–w- c:\program files\OpenOffice.org 3
2012-05-24 02:17 . 2012-05-24 02:17 ——– d—–w- c:\program files\Mozilla Thunderbird
2012-05-23 22:45 . 2012-05-23 22:45 1010720 –s—r- c:\windows\system32\MSCHRT20.OCX
2012-05-23 22:45 . 2012-05-23 22:45 ——– d—–w- c:\program files\Technitium
2012-05-23 22:38 . 2012-05-23 22:38 ——– d—–w- c:\program files\CCleaner
2012-05-23 03:00 . 2012-05-23 03:06 ——– d—–w- c:\windows\system32\scripting
2012-05-23 03:00 . 2012-05-23 03:06 ——– d—–w- c:\windows\l2schemas
2012-05-23 03:00 . 2012-05-23 03:06 ——– d—–w- c:\windows\system32\en
2012-05-23 02:41 . 2004-08-04 07:56 2897920 ——w- c:\windows\system32\xpsp2res.dll
2012-05-23 02:40 . 2001-08-18 12:00 5120 —-a-w- c:\windows\system32\dllcache\dcomcnfg.exe
2012-05-23 02:39 . 2010-02-05 18:40 1291264 —-a-w- c:\windows\system32\dllcache\quartz.dll
2012-05-23 02:38 . 2009-12-31 16:14 352640 —-a-w- c:\windows\system32\drivers\srv.sys
2012-05-22 21:41 . 2008-04-14 00:12 178176 —-a-w- c:\windows\system32\wbem\SET52C.tmp
2012-05-22 21:41 . 2008-04-14 00:12 65536 —-a-w- c:\program files\Common Files\System\Ole DB\SET4F0.tmp
2012-05-22 21:41 . 2008-04-14 00:12 487424 —-a-w- c:\program files\Common Files\System\Ole DB\SET4F1.tmp
2012-05-22 21:41 . 2008-04-14 00:12 47104 —-a-w- c:\windows\system32\wbem\SET52F.tmp
2012-05-22 21:39 . 2008-04-14 00:11 185344 —-a-w- c:\windows\system32\wbem\SET533.tmp
2012-05-22 21:39 . 2006-12-28 19:01 19569 —-a-w- c:\windows\005250_.tmp
2012-05-22 21:39 . 2008-04-14 00:11 472064 —-a-w- c:\windows\system32\wbem\SET534.tmp
2012-05-22 21:39 . 2008-04-14 00:11 247808 —-a-w- c:\windows\system32\wbem\SET536.tmp
2012-05-22 20:55 . 2012-05-22 20:55 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-22 20:55 . 2012-05-22 20:55 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-22 20:50 . 2012-05-23 21:15 ——– d—–w- c:\windows\system32\CatRoot_bak
2012-05-22 20:39 . 2009-06-21 22:04 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2012-05-22 20:39 . 2009-10-23 14:27 3555328 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2012-05-22 20:37 . 2009-06-05 07:42 655872 -c—-w- c:\windows\system32\dllcache\mstscax.dll
2012-05-22 20:36 . 2009-07-31 04:57 1172480 -c—-w- c:\windows\system32\dllcache\msxml3.dll
2012-05-22 20:28 . 2008-05-01 14:30 331776 -c—-w- c:\windows\system32\dllcache\msadce.dll
2012-05-22 20:13 . 2012-05-23 21:17 ——– d–h–w- c:\windows\$hf_mig$
2012-05-22 08:14 . 2012-05-23 03:18 ——– d—–w- c:\windows\system32\wbem\AutoRecover
2012-05-22 07:54 . 2012-05-23 03:08 ——– d—–w- c:\windows\peernet
2012-05-22 07:54 . 2012-05-22 07:54 ——– d—–w- c:\windows\provisioning
2012-05-22 07:49 . 2012-05-22 22:46 ——– d—–w- c:\windows\ServicePackFiles
2012-05-22 07:40 . 2007-08-11 03:46 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2012-05-22 07:33 . 2012-05-23 02:37 ——– d—–w- c:\windows\EHome
2012-05-22 02:56 . 2012-05-22 02:56 ——– d—–w- c:\documents and settings\Sonny13\Local Settings\Application Data\Adobe
2012-05-22 00:04 . 2012-05-22 00:05 ——– d—–w- c:\documents and settings\Sonny13\Application Data\MSN6
2012-05-21 22:08 . 2012-03-06 23:03 337880 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-05-21 22:08 . 2012-03-06 23:02 35672 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-05-21 22:08 . 2012-03-06 23:01 53848 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-05-21 22:08 . 2012-03-06 23:01 95704 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2012-05-21 22:08 . 2012-03-06 23:01 89048 —-a-w- c:\windows\system32\drivers\aswmon.sys
2012-05-21 22:08 . 2012-03-06 22:58 24920 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2012-05-21 22:06 . 2012-03-06 23:15 41184 —-a-w- c:\windows\avastSS.scr
2012-05-21 22:06 . 2012-03-06 23:15 201352 —-a-w- c:\windows\system32\aswBoot.exe
2012-05-21 22:05 . 2012-05-21 22:05 ——– d—–w- c:\program files\AVAST Software
2012-05-21 22:05 . 2012-05-21 22:05 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-21 01:19 . 1980-05-22 01:03 97208 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="NvQTwk" [X]
"Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2000-07-13 311350]
"srmclean"="c:\cpqs\Scom\srmclean.exe" [2001-07-24 36864]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2002-09-11 368706]
"IPInSightLAN 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" [2003-06-11 380928]
"IPInSightMonitor 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" [2003-06-11 122880]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-13 98304]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2004-04-14 40960]
"CPQEASYACC"="c:\compaq\eakdrv\STARTDRV.exe" [2001-07-11 40960]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-03-06 4241512]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2000-7-13 24633]
Status Monitor.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2006-4-22 819200]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
2004-07-20 16:34 851968 —-a-w- c:\program files\Brother\ControlCenter2\brctrcen.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2001-11-17 15:55 26112 —-a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Brother XP spl Service"=2 (0x2)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [5/21/2012 3:08 PM 337880]
S3 Gcr432;Gcr432;c:\windows\system32\drivers\Gcr432.sys [9/6/2001 11:05 AM 89371]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [5/21/1980 6:03 PM 129976]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WS2IFSL
*Deregistered* - IPVNMon
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://yahoo.sbc.com/dsl
TCP: DhcpNameServer = [removed] [removed]
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Sonny13\Application Data\Mozilla\Firefox\Profiles\rihcn18h.default\
FF - prefs.js: network.proxy.ftp - 107.10.85.131
FF - prefs.js: network.proxy.http - 107.10.85.131
FF - prefs.js: network.proxy.socks - [removed]
FF - prefs.js: network.proxy.ssl - [removed]
FF - prefs.js: network.proxy.type - 1
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
HKLM-Run-WorksFUD - (no file)
HKLM-Run-zXDHX9 - c:\documents and settings\michael corleone\local settings\temp\zXDHX9.exe
HKLM-Run-PKBdhT.exe - c:\windows\system32\PKBdhT.exe
HKLM-Run-zXDHX9.exe - c:\documents and settings\michael corleone\local settings\temp\zXDHX9.exe
HKLM-Run-Dinst - c:\windows\dinst.exe
HKLM-Run-ftimels - c:\windows\system32\cwybbic.exe
Notify-dimsntfy - (no file)
MSConfigStartUp-Rundll32_8 - c:\windows\System32\inetp60.dll
AddRemove-BroadJump Client Foundation - c:\program files\BroadJump\Client Foundation\Uninst.isu
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-24 16:55
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
———————— Other Running Processes ————————
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\System32\SCardSvr.exe
c:\windows\System32\nvsvc32.exe
c:\windows\system32\pctspk.exe
c:\compaq\eakdrv\EAKDRV.exe
c:\compaq\eakdrv\EAUSBKBD.EXE
.
**************************************************************************
.
Completion time: 2012-05-24 17:01:48 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-25 00:01
.
Pre-Run: 20,858,564,608 bytes free
Post-Run: 20,839,682,048 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
- - End Of File - - 69D12CECF12330622523AC32C30DDB54
Hi,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\Sonny13\Application Data\Mozilla\Firefox\Profiles\rihcn18h.default\
    FF - prefs.js: network.proxy.ftp - 107.10.85.131
    FF - prefs.js: network.proxy.http - 107.10.85.131
    FF - prefs.js: network.proxy.socks - 107.10.85.131
    FF - prefs.js: network.proxy.ssl - 107.10.85.131
    FF - prefs.js: network.proxy.type - 1
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-

When you ran DDS there should have been a log created named Attach.txt. In your next reply please post the new ComboFix log and the Attach.txt :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI