Help me with HijackThis
16 min read
My name is JonTom
- Malware Logs can sometimes take a lot of time to research and interpret.
- Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
- Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
- Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
- PLEASE NOTE: If you do not reply after 3 days your thread will be closed.
You are in the right place. There is no need to attach any logs, just copy and paste them directly into your replies.However, I now see in a note below this letter form that I am not allowed to send a file of this kind to you. So am I in the wrong forum?
Please describe the exact problem you are having with your machine (and please do not run any more removal tools unless requested).
HiJackThis is rather outdated now.
Lets take a look at your machine with the following scans:
- Please perform the following scan
- Please download DDS from here and save it to your desktop.
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
- Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
- aswMBR
- Download aswMBR.exe to your desktop.
- Double click the aswMBR.exe to run it.
- When asked if you want to download Avast's virus definitions please select Yes.
- Click the "Scan" button to start scan.
[external image: Posted Image]
- On completion of the scan click save log, save it to your desktop and post in your next reply.
[external image: Posted Image]
Please post both DDS logs and the aswMBR log in your next reply.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 12/19/2011 9:14:03 AM
System Uptime: 7/12/2012 3:55:37 AM (2 hours ago)
.
Motherboard: Hewleet-Packard | | Asterope3
Processor: Intel® Pentium® D CPU 2.80GHz | CPU 1 | 2799/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 225 GiB total, 199.209 GiB free.
D: is FIXED (FAT32) - 8 GiB total, 1.197 GiB free.
E: is CDROM ()
F: is Removable
G: is Removable
H: is Removable
I: is Removable
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP107: 4/13/2012 4:21:27 PM - Software Distribution Service 3.0
RP108: 4/14/2012 5:10:47 PM - System Checkpoint
RP109: 4/15/2012 5:49:59 PM - System Checkpoint
RP110: 4/16/2012 9:11:11 PM - System Checkpoint
RP111: 4/17/2012 10:02:29 PM - System Checkpoint
RP112: 4/17/2012 10:47:03 PM - Software Distribution Service 3.0
RP113: 4/18/2012 4:58:08 PM - Software Distribution Service 3.0
RP114: 4/19/2012 9:27:00 AM - Software Distribution Service 3.0
RP115: 4/20/2012 8:00:03 AM - Software Distribution Service 3.0
RP116: 4/20/2012 6:54:58 PM - Software Distribution Service 3.0
RP117: 4/21/2012 7:23:03 PM - System Checkpoint
RP118: 4/22/2012 4:26:20 PM - Software Distribution Service 3.0
RP119: 4/23/2012 8:27:52 PM - Software Distribution Service 3.0
RP120: 4/24/2012 10:10:52 PM - System Checkpoint
RP121: 4/25/2012 8:49:58 AM - Software Distribution Service 3.0
RP122: 4/25/2012 5:51:52 PM - Software Distribution Service 3.0
RP123: 4/26/2012 5:54:44 PM - System Checkpoint
RP124: 4/27/2012 7:13:13 AM - Software Distribution Service 3.0
RP125: 4/27/2012 11:42:49 PM - Software Distribution Service 3.0
RP126: 4/30/2012 7:09:52 AM - Software Distribution Service 3.0
RP127: 5/1/2012 1:23:30 PM - Software Distribution Service 3.0
RP128: 5/1/2012 4:28:54 PM - Software Distribution Service 3.0
RP129: 5/2/2012 4:47:00 PM - System Checkpoint
RP130: 5/3/2012 3:23:16 PM - Software Distribution Service 3.0
RP131: 5/4/2012 4:08:23 PM - System Checkpoint
RP132: 5/5/2012 7:15:41 AM - Software Distribution Service 3.0
RP133: 5/5/2012 5:35:15 PM - Software Distribution Service 3.0
RP134: 5/6/2012 4:42:00 PM - Software Distribution Service 3.0
RP135: 5/8/2012 4:10:40 AM - System Checkpoint
RP136: 5/8/2012 1:37:55 PM - Software Distribution Service 3.0
RP137: 5/9/2012 7:30:08 AM - Software Distribution Service 3.0
RP138: 5/9/2012 5:33:27 PM - Software Distribution Service 3.0
RP139: 5/10/2012 6:07:40 PM - System Checkpoint
RP140: 5/14/2012 5:56:22 AM - System Checkpoint
RP141: 5/14/2012 7:21:08 AM - Software Distribution Service 3.0
RP142: 5/15/2012 9:54:10 AM - System Checkpoint
RP143: 5/16/2012 8:16:30 AM - Software Distribution Service 3.0
RP144: 5/16/2012 8:22:01 AM - Software Distribution Service 3.0
RP145: 5/17/2012 5:52:37 AM - Software Distribution Service 3.0
RP146: 5/17/2012 7:38:52 AM - Software Distribution Service 3.0
RP147: 5/17/2012 3:23:25 PM - Software Distribution Service 3.0
RP148: 5/17/2012 4:20:55 PM - Software Distribution Service 3.0
RP149: 5/17/2012 6:56:46 PM - Software Distribution Service 3.0
RP150: 5/17/2012 11:16:05 PM - Software Distribution Service 3.0
RP151: 5/19/2012 4:44:30 AM - System Checkpoint
RP152: 5/20/2012 5:03:21 AM - System Checkpoint
RP153: 5/21/2012 5:06:03 AM - System Checkpoint
RP154: 5/21/2012 6:56:46 AM - Software Distribution Service 3.0
RP155: 5/22/2012 12:40:09 PM - System Checkpoint
RP156: 5/23/2012 4:36:08 PM - System Checkpoint
RP157: 5/24/2012 4:46:06 PM - System Checkpoint
RP158: 5/26/2012 5:30:28 AM - System Checkpoint
RP159: 5/26/2012 10:21:05 AM - Software Distribution Service 3.0
RP160: 5/27/2012 6:03:49 PM - System Checkpoint
RP161: 5/28/2012 6:25:31 PM - System Checkpoint
RP162: 5/29/2012 6:42:21 AM - Software Distribution Service 3.0
RP163: 5/30/2012 6:49:30 AM - System Checkpoint
RP164: 5/31/2012 9:13:41 AM - System Checkpoint
RP165: 6/1/2012 9:49:41 AM - System Checkpoint
RP166: 6/2/2012 10:19:02 AM - System Checkpoint
RP167: 6/2/2012 1:24:34 PM - Software Distribution Service 3.0
RP168: 6/4/2012 4:42:32 AM - System Checkpoint
RP169: 6/4/2012 9:14:54 AM - June 3, 2012
RP170: 6/4/2012 9:15:29 AM - Restore Operation
RP171: 6/4/2012 9:32:47 AM - June 4, 2012
RP172: 6/4/2012 9:34:13 AM - Restore Operation
RP173: 6/4/2012 11:11:19 AM - Software Distribution Service 3.0
RP174: 6/5/2012 2:07:00 PM - System Checkpoint
RP175: 6/7/2012 4:41:55 AM - System Checkpoint
RP176: 6/8/2012 5:01:12 AM - System Checkpoint
RP177: 6/9/2012 5:11:55 AM - System Checkpoint
RP178: 6/9/2012 6:31:29 AM - Software Distribution Service 3.0
RP179: 6/10/2012 4:27:01 PM - System Checkpoint
RP180: 6/10/2012 5:05:29 PM - Software Distribution Service 3.0
RP181: 6/11/2012 6:21:59 PM - System Checkpoint
RP182: 6/13/2012 4:48:30 AM - System Checkpoint
RP183: 6/14/2012 9:27:15 AM - Software Distribution Service 3.0
RP184: 6/15/2012 2:33:47 PM - System Checkpoint
RP185: 6/16/2012 4:14:33 PM - System Checkpoint
RP186: 6/16/2012 5:10:40 PM - Software Distribution Service 3.0
RP187: 6/17/2012 6:29:20 PM - System Checkpoint
RP188: 6/19/2012 6:26:55 AM - System Checkpoint
RP189: 6/20/2012 8:46:22 AM - System Checkpoint
RP190: 6/20/2012 4:52:01 PM - Software Distribution Service 3.0
RP191: 6/20/2012 9:27:45 PM - Software Distribution Service 3.0
RP192: 6/21/2012 9:07:27 AM - Software Distribution Service 3.0
RP193: 6/22/2012 9:35:46 AM - System Checkpoint
RP194: 6/23/2012 9:44:12 AM - System Checkpoint
RP195: 6/24/2012 4:50:56 AM - Software Distribution Service 3.0
RP196: 6/25/2012 7:04:07 AM - System Checkpoint
RP197: 6/26/2012 8:21:58 PM - Software Distribution Service 3.0
RP198: 6/28/2012 4:14:36 AM - System Checkpoint
RP199: 6/29/2012 5:40:51 AM - System Checkpoint
RP200: 6/30/2012 6:14:31 AM - System Checkpoint
RP201: 6/30/2012 7:37:10 AM - Software Distribution Service 3.0
RP202: 7/1/2012 8:44:29 AM - System Checkpoint
RP203: 7/1/2012 4:13:01 PM - Software Distribution Service 3.0
RP204: 7/2/2012 7:23:24 PM - System Checkpoint
RP205: 7/3/2012 6:38:47 AM - Software Distribution Service 3.0
RP206: 7/3/2012 1:48:54 PM - Software Distribution Service 3.0
RP207: 7/3/2012 4:53:11 PM - Software Distribution Service 3.0
RP208: 7/5/2012 4:19:42 AM - System Checkpoint
RP209: 7/6/2012 5:05:06 AM - System Checkpoint
RP210: 7/7/2012 5:42:57 AM - System Checkpoint
RP211: 7/8/2012 6:31:09 AM - System Checkpoint
RP212: 7/9/2012 6:33:25 AM - System Checkpoint
RP213: 7/9/2012 8:22:40 AM - Software Distribution Service 3.0
RP214: 7/10/2012 8:33:32 AM - System Checkpoint
RP215: 7/11/2012 8:41:04 AM - System Checkpoint
RP216: 7/11/2012 9:24:36 PM - Software Distribution Service 3.0
RP217: 7/12/2012 5:31:56 AM - Software Distribution Service 3.0
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
Adobe Reader 7.0.5
AIM 7
AliIM Plugins for Browser
AOL Messaging Toolbar
Apple Application Support
Apple Software Update
ATI Control Panel
ATI Display Driver
Bonjour
BufferChm
Canon PhotoRecord
Canon PIXMA iP3000
Canon Utilities Easy-PhotoPrint
Compaq Connections (remove only)
CompuServe
CP_AtenaShokunin1Config
CP_CalendarTemplates1
cp_LightScribeConfig
cp_OnlineProjectsConfig
CP_Package_Basic1
CP_Package_Variety1
CP_Package_Variety2
CP_Package_Variety3
CP_Panorama1Config
cp_PosterPrintConfig
cp_UpdateProjectsConfig
CueTour
Customer Experience Enhancement
Data Fax SoftModem with SmartCP
Destinations
DeviceManagementQFolder
Download Updater (AOL LLC)
Easy-WebPrint
Easy Internet Sign-up
Enhanced Multimedia Keyboard Solution
FullDPAppQFolder
Google Chrome
High Definition Audio Driver Package - KB888111
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB981793)
HP Boot Optimizer
HP DVD Play 2.1
HP Imaging Device Functions 7.0
HP Photosmart Premier Software 6.5
HP Support Overview
HP Update
HP Web Helper
HPPhotoSmartExpress
HpSdpAppCoreApp
InstantShareDevices
J2SE Runtime Environment 5.0 Update 6
Java 2 Runtime Environment Standard Edition v1.3.1_02
LightScribe 1.4.105.1
Microsoft .NET Framework 1.0 Hotfix (KB2572066)
Microsoft .NET Framework 1.0 Hotfix (KB2604042)
Microsoft .NET Framework 1.0 Hotfix (KB2656378)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2656353)
Microsoft .NET Framework 1.1 Security Update (KB2656370)
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Away Mode
Microsoft Security Client
Microsoft Security Essentials
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero Media Player
Nero OEM
OptionalContentQFolder
Otto
PC-Doctor 5 for Windows
PhotoGallery
Python 2.2 pywin32 extensions (build 203)
Python 2.2.3
RandMap
RealPlayer
Realtek High Definition Audio Driver
Rhapsody
Safari
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft Windows (KB2564958)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2491683)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
SkinsHP1
SlideShow
SlideShowMusic
Sonic Express Labeler
Sonic MyDVD Plus
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sonic_PrimoSDK
Switch Sound File Converter
Unload
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB2632503)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2718704)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB961503)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player (Remove Only)
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format Runtime
Windows XP Media Center Edition 2005 KB2502898
Windows XP Media Center Edition 2005 KB2619340
Windows XP Media Center Edition 2005 KB2628259
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar
.
==== Event Viewer Messages From Past Week ========
.
7/8/2012 5:37:34 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/7/2012 5:38:03 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/6/2012 7:11:40 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 60 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
7/6/2012 6:41:40 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 30 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
7/6/2012 6:26:40 AM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751)
7/6/2012 5:46:33 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/6/2012 5:36:04 AM, error: PSched [14103] - QoS [Adapter {BF64AD4B-64B0-4AAD-9001-2F16BC66E1E7}]: The netcard driver failed the query for OID_GEN_LINK_SPEED.
7/6/2012 5:00:12 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/6/2012 4:50:02 AM, error: Service Control Manager [7000] - The ASCTRM service failed to start due to the following error: The system cannot find the file specified.
7/6/2012 10:01:01 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/5/2012 7:59:17 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/5/2012 5:39:39 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/5/2012 5:21:25 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/5/2012 5:10:23 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
7/5/2012 4:35:34 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: Default URL Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8007043c Error description: This service cannot be started in Safe Mode
7/5/2012 4:35:34 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
7/5/2012 4:26:00 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
7/5/2012 4:25:51 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD Fips intelppm IPSec MpFilter MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
7/5/2012 4:25:51 PM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
7/5/2012 4:25:51 PM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/5/2012 4:25:51 PM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/5/2012 4:25:51 PM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
7/5/2012 4:25:51 PM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
7/5/2012 4:14:48 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/5/2012 1:09:11 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.902.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/12/2012 4:06:12 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1269.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/11/2012 4:39:49 AM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1269.0 Update Source: Microsoft Update Server Update Stage: Search Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x8024402c Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
7/10/2012 6:31:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1269.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x80240022 Error description: The program can't check for definition updates.
7/10/2012 6:31:12 PM, error: Microsoft Antimalware [2001] - Microsoft Antimalware has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.129.1269.0 Update Source: Microsoft Update Server Update Stage: Download Source Path: http://www.microsoft.com Signature Type: AntiVirus Update Type: Full User: NT AUTHORITY\SYSTEM Current Engine Version: Previous Engine Version: 1.1.8502.0 Error code: 0x80240022 Error description: The program can't check for definition updates.
.
==== End Of File ===========================
CONTENTS OF DDS FILE: .
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 5:53:09 on 2012-07-12
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.265 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\ARPWRMSG.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Compaq Connections\5577497\Program\Compaq Connections.exe
C:\Program Files\CompuServe 7.0a\cstray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\CompuServe 7.0a\wcs2000.exe
C:\Documents and Settings\Compaq_Administrator.MARIESCOMPUTER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YahooMessenger.exe
C:\Documents and Settings\Compaq_Administrator.MARIESCOMPUTER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Compaq_Administrator.MARIESCOMPUTER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
c:\Program Files\Microsoft Works\WksWP.exe
c:\Program Files\Microsoft Works\WkDStore.exe
c:\Program Files\Microsoft Works\wkgdcach.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\wscntfy.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page =
uSearch Bar =
uStart Page = hxxp://msn.com/
mSearchAssistant =
mURLSearchHooks: AOL Messaging Toolbar Search Class: {03402f96-3dc7-4285-bc50-9e81fefafe43} - c:\program files\aim toolbar\aimtb.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
BHO: AOL Messaging Toolbar Loader: {b0cda128-b425-4eef-a174-61a11ac5dbf8} - c:\program files\aim toolbar\aimtb.dll
TB: Easy-WebPrint: {327c2873-e90d-4c37-aa9d-10ac9baba46c} - c:\program files\canon\easy-webprint\Toolband.dll
TB: AOL Messaging Toolbar: {61539ecd-cc67-4437-a03c-9aaccbd14326} - c:\program files\aim toolbar\aimtb.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messen~1\YahooMessenger.exe" -quiet
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [PCDrProfiler]
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [ISUSScheduler] "c:\progra~1\common~1\instal~1\update~1\issch.exe" -start
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [AlwaysReady Power Message APP] ARPWRMSG.EXE
mRun: [Alcmtr] ALCMTR.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compaq~1.lnk - c:\program files\compaq connections\5577497\program\Compaq Connections.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compus~1.lnk - c:\program files\compuserve 7.0a\cstray.exe
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1341008811078
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab
DPF: {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/1.3.1/jinstall-131_02-win.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
TCP: Interfaces\{80BEC499-54CA-464F-894B-277F1B8FD051} : NameServer = 205.188.146.145
TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = [removed] [removed] [removed] [removed]
Notify: AtiExtEvent - Ati2evxx.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064]
R1 MpKsl0f029fe9;MpKsl0f029fe9;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a62b52c4-5e0a-4df4-a9cb-8a5a467d953a}\MpKsl0f029fe9.sys [2012-7-12 29904]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-07-12 09:40:21 29904 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a62b52c4-5e0a-4df4-a9cb-8a5a467d953a}\MpKsl0f029fe9.sys
2012-07-12 09:32:01 6762896 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a62b52c4-5e0a-4df4-a9cb-8a5a467d953a}\mpengine.dll
2012-07-09 12:22:42 6762896 —-a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-07-04 21:55:20 ——– d—–w- c:\program files\common files\Software Update Utility
2012-06-21 12:23:33 521728 ——w- c:\windows\system32\dllcache\jsdbgui.dll
.
==================== Find3M ====================
.
2012-06-13 13:19:59 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 21:35:26 222448 —-a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32:08 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19:44 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19:38 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19:38 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19:34 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19:30 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:18:58 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18:58 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42:33 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42:33 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38:02 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:16:13 2148352 ——w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32:19 2026496 ——w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46:36 139656 ——w- c:\windows\system32\drivers\rdpwd.sys
.
============= FINISH: 5:58:34.80 ===============
Thank you for the logs.
It appears as though you performed a number of system restores a short while back (which may explain why there is not a great deal showing in your logs).
Please do answer this question <==== Important.Please describe the exact problem you are having with your machine
- Foistware
- I can see from your log that you have Viewpoint Media Player installed.
- Viewpoint Media Player is considered as foistware rather than malware since it is installed without user's approval but doesn't spy or do anything "bad".
- It is recommended that you remove Viewpoint products. However, this choice is up to you.
- To remove these programs, click "Start" and then on "Control Panel" and then on "Add or Remove Programs".
- Select Viewpoint Media Player and click on "Remove".
- Please scan your system with GMER
[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
- Extract the contents of the zipped file to desktop.
- Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
- If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
- In the right panel, you will see several boxes that have been checked. Uncheck the following …
- IAT/EAT
- Drives/Partition other than Systemdrive (typically C:\)
- Show All (don't miss this one)
- Then click the Scan button & wait for it to finish.
- Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
- Save it where you can easily find it, such as your desktop, and post it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries
Please post the GMER log in your next reply along with the answer to my question.
Please describe the exact problem you are having with your machine (and please do not run any more removal tools unless requested).
I have asked you to describe the symptoms that your machine is displaying twice now. Please help me to help you by answering the question.Please do answer this question <==== Important.
I did ask you not to run any more scans unless requested Jokimo. However, since you saved the screen from the avast scan please post it in your next reply.I also managed to get Avast downloaded and I ran a scan.
We are not at the point where we need to perofrm a factory reset but thank you for letting me knowI have a set of restore disks if it becomes necessary to use them
Both of those links work fine on my machine.I tried both links you prodvided for downloading the GMER. But neither download worked
I would like to see if we can get an ARK/MBR scan before we run any removal tools. Lets see if we have any luck with the following:
- Rootkit Unhooker
- Please Download Rootkit Unhooker and Save it to your desktop.
- Now double-click on RKUnhookerLE.exe to run it.
- Click the Report tab, then click Scan.
- Check (Tick) Drivers, Stealth. Uncheck the rest, then Click OK.
- Wait till the scanner has finished and then click File, Save Report.
- Save the report somewhere where you can find it. Click Close.
Copy the entire contents of the report and paste it in your next reply here.
Note: You may get the following warning, just click OK and continue.
"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"
- MBRCheck
- Please download MBRCheck by clicking here and save it to your desktop.
- Be sure to disable your security programs.
- Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt).
- A window will open on your desktop.
- If an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
- If nothing unusual is found just press Enter.
- A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
- Please post the contents of that file in your next reply.
Please describe the problems the machine is presently displaying, and post the avast screenshots, the Rootkit unhooker log and the MBRCheck log in your next reply.
Thank you for the log and extra information.
Just copy and paste the rootkit unhooker log into your reply (there is no need to attach any text logs).You said you'd like me to send the Avast file I have saved. And I know you would like to see the Rootkit Unhooker. BUt I'm unsure how to send files to you.
As for the avast file, try attaching it using the instructions provided here: http://forums.whatthetech.com/index.php?showtopic=107309
Lets see what the following can tell us:
- Combofix
- Download ComboFix from one of the following locations:
Link 1
Link 2
- VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
- IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here .
- Double click on ComboFix.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
- Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
- Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
- Click on Yes, to continue scanning for malware.
- When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
- Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
- Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
- Should there be issues with internet afterward:
In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.
In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
Please post the combofix log in your next reply.
Please run Combofix as requested.
ComboFix 12-07-21.01 - Compaq_Administrator 07/22/2012 7:02.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.959.477 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\docume~1\COMPAQ~1.MAR\LOCALS~1\Temp\IadHide5.dll
c:\documents and settings\Compaq_Administrator.MARIESCOMPUTER\Local Settings\Temp\IadHide5.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-18 21:26 . 2012-07-18 21:26 ——– d—–w- C:\tech help files
2012-07-17 20:08 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{AFAB5BBE-AD67-4DB6-B149-3B0CA39717BB}\mpengine.dll
2012-07-14 19:51 . 2012-05-31 03:41 6762896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-12 22:58 . 2012-07-03 16:21 353688 —-a-w- c:\windows\system32\drivers\aswSP.sys
2012-07-12 22:58 . 2012-07-03 16:21 21256 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2012-07-12 22:58 . 2012-07-03 16:21 54232 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2012-07-12 22:58 . 2012-07-03 16:21 35928 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2012-07-12 22:58 . 2012-07-03 16:21 721000 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2012-07-12 22:58 . 2012-07-03 16:21 97608 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2012-07-12 22:58 . 2012-07-03 16:21 89624 —-a-w- c:\windows\system32\drivers\aswmon.sys
2012-07-12 22:58 . 2012-07-03 16:21 25256 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2012-07-12 22:57 . 2012-07-03 16:21 41224 —-a-w- c:\windows\avastSS.scr
2012-07-12 22:57 . 2012-07-03 16:21 227648 —-a-w- c:\windows\system32\aswBoot.exe
2012-07-12 22:57 . 2012-07-12 22:57 ——– d—–w- c:\program files\AVAST Software
2012-07-12 22:57 . 2012-07-12 22:57 ——– d—–w- c:\documents and settings\All Users\Application Data\AVAST Software
2012-07-05 20:35 . 2012-07-05 20:35 ——– d—–w- c:\documents and settings\Administrator\Application Data\Template
2012-07-04 21:55 . 2012-07-04 21:55 ——– d—–w- c:\program files\Common Files\Software Update Utility
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-06-13 13:19 . 2004-08-10 04:00 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2011-12-21 11:46 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2004-08-10 04:00 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 21:35 . 2011-12-22 10:32 222448 —-a-w- c:\windows\system32\muweb.dll
2012-06-04 04:32 . 2004-08-10 04:00 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 00:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2004-08-10 04:00 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2004-08-10 04:00 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2004-08-10 04:00 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2009-08-07 00:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2004-08-10 04:00 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2004-08-10 04:00 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2004-08-10 04:00 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2009-08-07 00:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2004-08-10 04:00 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2004-08-10 04:00 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2011-12-22 10:32 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2011-12-22 10:32 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2004-08-10 04:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2004-08-10 04:00 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2004-08-10 04:00 43520 ——w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2004-08-10 04:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2004-08-10 04:00 385024 ——w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2004-08-10 11:00 2148352 ——w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-10 11:00 2026496 ——w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2004-08-10 04:00 139656 ——w- c:\windows\system32\drivers\rdpwd.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2012-07-03 16:21 121528 —-a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2012-07-12 39408]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YahooMessenger.exe" [2012-01-04 6497592]
"Aim"="c:\program files\AIM\aim.exe" [2012-05-30 4331392]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2012-07-03 4273976]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2006-08-08 180269]
"RTHDCPL"="RTHDCPL.EXE" [2009-02-03 18085888]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-23 237568]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
"ISUSScheduler"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\issch.exe" [2004-07-28 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]
"ftutil2"="ftutil2.dll" [2004-06-07 106496]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 77312]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\RIGHTEOUSCAFE\Start Menu\Programs\Startup\
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-8-8 27136]
.
c:\documents and settings\Guest\Start Menu\Programs\Startup\
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-8-8 27136]
.
c:\documents and settings\Hashabiah\Start Menu\Programs\Startup\
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-8-8 27136]
.
c:\documents and settings\Hogla\Start Menu\Programs\Startup\
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-8-8 27136]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Compaq Connections.lnk - c:\program files\Compaq Connections\5577497\Program\Compaq Connections.exe [2006-8-8 36903]
CompuServe 7.0 Tray Icon.lnk - c:\program files\CompuServe 7.0a\cstray.exe [2011-12-19 32840]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Compaq Connections\\5577497\\Program\\Compaq Connections.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\CompuServe 7.0a\\wcs2000.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [7/12/2012 6:58 PM 721000]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [7/12/2012 6:58 PM 353688]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [7/12/2012 6:58 PM 21256]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/12/2011 9:39 AM 136176]
S3 89A62723;89A62723;c:\windows\system32\89A62723.exe –> c:\windows\system32\89A62723.exe [?]
S3 F906712B;F906712B;c:\windows\system32\F906712B.exe –> c:\windows\system32\F906712B.exe [?]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/12/2011 9:39 AM 136176]
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-07-22 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-07-12 16:21]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-12 13:39]
.
2012-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-12 13:39]
.
2012-07-22 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
2012-04-22 c:\windows\Tasks\switchShakeIcon.job
- c:\program files\NCH Software\Switch\switch.exe [2012-01-02 11:28]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
TCP: Interfaces\{80BEC499-54CA-464F-894B-277F1B8FD051}: NameServer = 205.188.146.145
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-22 07:16
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(800)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3284)
c:\windows\system32\WININET.dll
c:\docume~1\COMPAQ~1.MAR\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\arservice.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\wanmpsvc.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\RTHDCPL.EXE
c:\windows\ARPWRMSG.EXE
c:\windows\eHome\ehmsas.exe
c:\progra~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
.
**************************************************************************
.
Completion time: 2012-07-22 07:23:46 - machine was rebooted
ComboFix-quarantined-files.txt 2012-07-22 11:23
ComboFix2.txt 2012-07-17 22:02
.
Pre-Run: 218,953,388,032 bytes free
Post-Run: 219,019,399,168 bytes free
.
- - End Of File - - AD68ABDEF73950A14214189D35A2AE3B
Thank you for the log.
There is no need to do that at the moment.So if you like, I could disable Avast through that icon, and run any or all of those programs you had given me - if you like - and give you their results.
Lets proceed as follows:
- Security Programs
- I can see from your log that you have a number of real-time security programs running, namely avast! Antivirus and Microsoft Security Essentials.
- Whilst both of these programs provide good security, they may clash with each other which can leave your system vulnerable to infection.
- You are advised to remove one of these programs.
- Please make sure that you only have ONE Firewall and ONE real-time Antivirus running on your system.
- Please scan the following file
- Please go to VirusTotal
- On the page you'll find a "Choose File" button.
- Click on the Choose File button.
- In the File Upload window which opens, copy and paste this into the File Name box.
c:\documents and settings\Compaq_Administrator.MARIESCOMPUTER\Local Settings\Temp\IadHide5.dll
- Next, click the Open button.
- Then click the "Send File" button just below.
- This will scan the file. Please be patient.
- If you get a message saying File has already been analyzed: click Reanalyze file now.
- Once scanned, copy and paste the link to the results page in your next reply.
You appear to have run Combofix more than once. I did ask you to run the tool once only.
I now need to see the combofix log that was produced when you ran the tool the first time.
Please navigate to the following file and post it in your next reply:
C:\Qoobox\ComboFix2.txt
Also, please uninstall one of the security programs mentioned above and post the link to the Virus Total results page as requested.
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI