This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE8 Redirects to Adverts and Popup Ads during browsing [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I am having a problem with one of the PCs I have. When you do a search or click on links in IE8, most of the time it redirects to some sort of advertisement. It is pretty annoying.

Also I get Popup Ads in the bottom corners of the screen, not in IE Windows but just with little crosses in the corner. They go away when you close them, but soon come back.

Here are my logs:

OTL logfile created on: 13/09/2012 11:10:58 - Run 1
OTL by OldTimer - Version 3.2.61.3 Folder = C:\Documents and Settings\SR Parkin\Desktop\Scanners
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.75 Gb Total Physical Memory | 2.35 Gb Available Physical Memory | 85.49% Memory free
4.59 Gb Paging File | 4.37 Gb Available in Paging File | 95.21% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINXP | %ProgramFiles% = C:\Program Files
Drive C: | 100.00 Gb Total Space | 82.61 Gb Free Space | 82.61% Space Free | Partition Type: NTFS
Drive D: | 132.88 Gb Total Space | 132.79 Gb Free Space | 99.94% Space Free | Partition Type: NTFS
Drive H: | 7.39 Gb Total Space | 5.75 Gb Free Space | 77.80% Space Free | Partition Type: FAT32
Drive S: | 232.72 Gb Total Space | 213.04 Gb Free Space | 91.55% Space Free | Partition Type: NTFS

Computer Name: RS-01 | User Name: SR Parkin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\SR Parkin\Desktop\Scanners\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
PRC - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
PRC - C:\WINXP\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll ()
MOD - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll ()
MOD - C:\WINXP\system32\cpwmon2k.dll ()
MOD - C:\WINXP\system32\ssp2ml3.dll ()


========== Services (SafeList) ==========

SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (nSvcIp) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe ()
SRV - (ForceWare Intelligent Application Manager (IAM) – C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe ()


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (HTCAND32) – System32\Drivers\ANDROIDUSB.sys File not found
DRV - (Changer) – File not found
DRV - (5789) – C:\DOCUME~1\SRPARK~1\LOCALS~1\Temp\5789.sys File not found
DRV - (VIAHdAudAddService) – C:\WINXP\system32\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV - (nvgts) – C:\WINXP\system32\drivers\nvgts.sys (NVIDIA Corporation)
DRV - (FTDIBUS) – C:\WINXP\system32\drivers\ftdibus.sys (FTDI Ltd.)
DRV - (nvnetbus) – C:\WINXP\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINXP\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (DgiVecp) – C:\WINXP\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (NSHE) – C:\WINXP\system32\drivers\NSHE.SYS (T0r0 2008)
DRV - (AmdPPM) – C:\WINXP\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (Hardlock) – C:\WINXP\system32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (MTsensor) – C:\WINXP\system32\drivers\ASACPI.sys ()
DRV - (EZUSB) – C:\WINXP\system32\drivers\ezusb.sys (cypress semiconductor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINXP\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://mail.google.com/mail/u/0/?hl=en&shva=1#inbox
IE - HKCU\..\SearchScopes,DefaultScope = {DFC37C1C-BC1E-4D81-A049-6F8A72543F64}
IE - HKCU\..\SearchScopes\{DFC37C1C-BC1E-4D81-A049-6F8A72543F64}: "URL" = http://www.google.co.uk/search?hl=en&q…erms}&meta=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINXP\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)



O1 HOSTS File: ([2011/08/03 08:50:20 | 000,000,764 | —- | M]) - C:\WINXP\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe" File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINXP\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINXP\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /installquiet File not found
O4 - HKLM..\Run: [Seagull Drivers] C:\WINXP\ssdal_nc.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: mamsoft.co.uk ([online] https in Local intranet)
O15 - HKCU\..Trusted Domains: rmdmo.co.uk ([www] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{68C03A3E-EB26-4600-9834-A0EA41CB0A56}: NameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINXP\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINXP\system32\userinit.exe) - C:\WINXP\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\SR Parkin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/05 13:07:48 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2012/01/05 08:45:16 | 000,000,122 | RHS- | M] () - H:\Autorun.inf – [ FAT32 ]
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{17f9bcc2-a706-11e0-904d-806d6172696f}\Shell\AutoRun\command - "" = E:\Bin\ASSETUP.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.iac2 - C:\WINXP\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINXP\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINXP\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINXP\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINXP\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINXP\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINXP\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINXP\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/10 08:57:33 | 000,000,000 | —D | C] – S:\Downloads
[2012/09/03 13:48:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/03 13:48:03 | 000,022,344 | —- | C] (Malwarebytes Corporation) – C:\WINXP\System32\drivers\mbam.sys
[2012/09/03 13:48:03 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Pictures
[2012/09/03 09:19:29 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Music
[2012/09/03 09:17:21 | 000,000,000 | —D | C] – C:\Documents and Settings\SR Parkin\Desktop\Scanners
[2012/08/31 19:13:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Zeitronix Data Logger
[2012/08/31 19:13:17 | 000,000,000 | —D | C] – C:\Program Files\Zeitronix
[2012/08/24 19:08:53 | 000,000,000 | -HSD | C] – C:\Documents and Settings\SR Parkin\IECompatCache
[2012/08/17 18:45:19 | 000,014,640 | —- | C] (Microsoft Corporation) – C:\WINXP\System32\spmsgXP_2k3.dll
[3 S:\*.tmp files -> S:\*.tmp -> ]
[3 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/13 11:12:00 | 000,000,242 | —- | M] () – C:\WINXP\tasks\Scheduled Update for Ask Toolbar.job
[2012/09/13 08:06:38 | 000,276,202 | —- | M] () – C:\WINXP\System32\NvApps.xml
[2012/09/13 08:06:37 | 000,002,206 | —- | M] () – C:\WINXP\System32\wpa.dbl
[2012/09/13 08:06:26 | 000,002,048 | –S- | M] () – C:\WINXP\bootstat.dat
[2012/09/07 14:22:16 | 000,022,562 | —- | M] () – S:\INVOICE-INV2200 FinTurbo.pdf
[2012/09/05 12:46:54 | 000,002,493 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Microsoft Word.lnk
[2012/08/31 19:13:17 | 000,000,804 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Zeitronix Data Logger v3.1.6.lnk
[2012/08/17 18:45:23 | 000,000,000 | -H– | M] () – C:\WINXP\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/08/17 18:45:22 | 000,001,374 | —- | M] () – C:\WINXP\imsins.BAK
[2012/08/17 18:45:22 | 000,000,000 | -H– | M] () – C:\WINXP\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/08/16 15:00:11 | 000,002,491 | —- | M] () – C:\Documents and Settings\SR Parkin\Desktop\Microsoft Excel.lnk
[2012/08/16 07:43:48 | 002,043,088 | —- | M] () – C:\WINXP\System32\FNTCACHE.DAT
[3 S:\*.tmp files -> S:\*.tmp -> ]
[3 C:\WINXP\System32\*.tmp files -> C:\WINXP\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/09/07 14:21:41 | 000,022,562 | —- | C] () – S:\INVOICE-INV2200 FinTurbo.pdf
[2012/08/31 19:13:17 | 000,000,804 | —- | C] () – C:\Documents and Settings\SR Parkin\Desktop\Zeitronix Data Logger v3.1.6.lnk
[2012/08/17 18:45:23 | 000,000,000 | -H– | C] () – C:\WINXP\System32\drivers\Msft_Kernel_ANDROIDUSB_01007.Wdf
[2012/08/17 18:45:22 | 000,000,000 | -H– | C] () – C:\WINXP\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/02/15 08:48:56 | 000,003,072 | —- | C] () – C:\WINXP\System32\iacenc.dll
[2011/11/05 14:05:21 | 000,000,169 | —- | C] () – C:\WINXP\ETKINST.INI
[2011/08/19 11:06:11 | 000,000,727 | —- | C] () – C:\WINXP\pagebreeze.ini
[2011/08/19 11:06:11 | 000,000,044 | —- | C] () – C:\WINXP\formbreeze.ini
[2011/07/30 10:31:19 | 000,003,584 | —- | C] () – C:\Documents and Settings\SR Parkin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/19 09:25:20 | 000,000,000 | —- | C] () – C:\WINXP\eDrawingOfficeAutomator.INI
[2011/07/19 09:18:43 | 000,022,723 | —- | C] () – C:\WINXP\System32\ssp2ml3.dll
[2011/07/18 20:10:31 | 000,153,088 | —- | C] () – C:\WINXP\System32\UNWISE.EXE
[2011/07/18 20:10:31 | 000,028,672 | —- | C] () – C:\WINXP\System32\hlduinst.exe
[2011/07/18 19:40:39 | 000,087,552 | —- | C] () – C:\WINXP\System32\cpwmon2k.dll
[2011/07/18 19:37:53 | 000,000,370 | —- | C] () – C:\WINXP\ODBC.INI
[2011/07/05 13:56:50 | 000,004,073 | —- | C] () – C:\WINXP\ODBCINST.INI
[2011/07/05 13:55:53 | 002,043,088 | —- | C] () – C:\WINXP\System32\FNTCACHE.DAT
[2011/07/05 13:17:56 | 000,010,084 | R— | C] () – C:\WINXP\System32\drivers\nvphy.bin
[2011/07/05 13:16:30 | 000,254,000 | R— | C] ( ) – C:\WINXP\System32\Audio3D.dll
[2011/07/05 13:16:30 | 000,254,000 | R— | C] ( ) – C:\WINXP\System32\A3D.dll
[2011/07/05 13:13:54 | 000,005,810 | R— | C] () – C:\WINXP\System32\drivers\ASACPI.sys
[2011/07/05 13:13:48 | 000,001,769 | —- | C] () – C:\WINXP\Language_trs.ini
[2011/07/05 13:13:43 | 000,026,638 | —- | C] () – C:\WINXP\Ascd_tmp.ini
[2011/07/05 13:13:43 | 000,010,296 | —- | C] () – C:\WINXP\System32\drivers\ASUSHWIO.SYS
[2011/07/05 13:09:41 | 000,002,048 | –S- | C] () – C:\WINXP\bootstat.dat
[2011/07/05 13:05:32 | 000,021,640 | —- | C] () – C:\WINXP\System32\emptyregdb.dat
[2011/06/30 18:53:20 | 000,061,952 | —- | C] () – C:\WINXP\ssdal_nc.exe

========== LOP Check ==========

[2011/10/25 16:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2011/11/02 22:32:42 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\CoreFTP
[2011/10/25 16:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\DassaultSystemes
[2011/10/25 16:48:58 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\EDrawings
[2011/07/26 13:55:39 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\Foxit Software
[2011/07/05 15:35:39 | 000,000,000 | —D | M] – C:\Documents and Settings\SR Parkin\Application Data\OpenOffice.org
[2012/09/13 11:12:00 | 000,000,242 | —- | M] () – C:\WINXP\Tasks\Scheduled Update for Ask Toolbar.job

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2008/04/14 10:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\explorer.exe
[2008/04/14 10:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINXP\system32\dllcache\explorer.exe

< MD5 for: EXPLORER.EXE-0D300D8F.PF >
[2012/08/29 07:55:20 | 000,081,356 | —- | M] () MD5=28A69FB3DCA7E7388BE15E1C934A8580 – C:\WINXP\Prefetch\EXPLORER.EXE-0D300D8F.pf

< MD5 for: EXPLORER.SCF >
[2008/04/14 10:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINXP\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2010/09/16 11:27:16 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINXP\Help\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2010/09/16 11:27:16 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2010/09/16 11:27:16 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINXP\system32\dllcache\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2010/09/16 11:27:34 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2010/09/16 11:27:34 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/09/13 11:03:38 | 000,108,296 | —- | M] () MD5=F81DE174A3E4FA5F8FEAADF4B00161F5 – C:\WINXP\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2008/04/14 10:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINXP\Help\iexplore.hlp

< MD5 for: SERVICES >
[2008/04/14 10:00:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINXP\system32\drivers\etc\services

< MD5 for: SERVICES.EXE >
[2010/09/16 14:11:07 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\system32\dllcache\services.exe
[2010/09/16 14:11:07 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINXP\system32\services.exe

< MD5 for: SERVICES.LNK >
[2011/07/05 13:07:54 | 000,001,590 | —- | M] () MD5=2C6B5A5D07DE7EB0663A9590CE904AC9 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk

< MD5 for: SERVICES.MSC >
[2008/04/14 10:00:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINXP\system32\services.msc

< MD5 for: WINLOGON.EXE >
[2012/07/03 13:46:42 | 000,217,672 | —- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 10:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\dllcache\winlogon.exe
[2008/04/14 10:00:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINXP\system32\winlogon.exe

< %SYSTEMDRIVE%\*.* >
[2011/07/05 13:07:48 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/07/05 13:03:36 | 000,000,207 | -HS- | M] () – C:\boot.ini
[2011/07/05 13:07:48 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012/05/23 16:14:47 | 000,454,078 | —- | M] () – C:\Etka7.txt
[2011/10/19 09:11:30 | 000,001,466 | —- | M] () – C:\FONTLOG.TXT
[2011/07/05 13:07:48 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/07/05 13:07:48 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 10:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 10:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2012/09/13 08:06:23 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINXP\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINXP\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINXP\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINXP\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2011/07/05 13:07:27 | 000,000,067 | -HS- | M] () – C:\WINXP\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2003/06/18 17:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINXP\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008/01/11 06:16:58 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINXP\system32\spool\prtprocs\w32x86\ssp2mpc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >
[2012/02/06 09:24:46 | 000,108,789 | —- | M] () – C:\WINXP\system32\Cover mount.JPG
[3 C:\WINXP\system32\*.tmp files -> C:\WINXP\system32\*.tmp -> ]

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2011/07/05 13:55:20 | 000,094,208 | —- | M] () – C:\WINXP\System32\config\default.sav
[2011/07/05 13:55:20 | 001,089,536 | —- | M] () – C:\WINXP\System32\config\software.sav
[2011/07/05 13:55:20 | 000,917,504 | —- | M] () – C:\WINXP\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/07/05 13:07:54 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/07/05 13:11:50 | 000,000,060 | -HS- | M] () – C:\Documents and Settings\SR Parkin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/07/05 13:11:50 | 000,000,079 | —- | M] () – C:\Documents and Settings\SR Parkin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-09-12 18:01:48

< End of report >
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:16:38, on 13/09/2012
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINXP\System32\smss.exe
C:\WINXP\system32\winlogon.exe
C:\WINXP\system32\services.exe
C:\WINXP\system32\lsass.exe
C:\WINXP\system32\nvsvc32.exe
C:\WINXP\system32\svchost.exe
C:\WINXP\System32\svchost.exe
C:\WINXP\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINXP\system32\svchost.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINXP\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINXP\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINXP\system32\ctfmon.exe
C:\WINXP\System32\svchost.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINXP\system32\notepad.exe
C:\Documents and Settings\SR Parkin\Desktop\Scanners\OTL.exe
C:\WINXP\notepad.exe
C:\WINXP\notepad.exe
C:\Documents and Settings\SR Parkin\Desktop\Scanners\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://mail.google.com/mail/u/0/?hl=en&shva=1#inbox
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINXP\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINXP\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Seagull Drivers] ssdal_nc.exe startup
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINXP\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINXP\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{68C03A3E-EB26-4600-9834-A0EA41CB0A56}: NameServer = 192.168.1.1
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINXP\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINXP\system32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINXP\system32\nvsvc32.exe

–
End of file - 4860 bytes
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 11:17:24 on 2012-09-13
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2815.2350 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\WINXP\system32\nvsvc32.exe
C:\WINXP\system32\svchost -k DcomLaunch
svchost.exe
C:\WINXP\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINXP\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINXP\system32\svchost.exe -k imgsvc
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINXP\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINXP\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINXP\system32\ctfmon.exe
C:\WINXP\System32\svchost.exe -k HTTPFilter
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\WINXP\system32\notepad.exe
C:\WINXP\notepad.exe
C:\WINXP\notepad.exe
C:\WINXP\system32\NOTEPAD.EXE
.
============== Pseudo HJT Report ===============
.
uStart Page = https://mail.google.com/mail/u/0/?hl=en&shva=1#inbox
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\winxp\system32\ctfmon.exe
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Seagull Drivers] ssdal_nc.exe startup
mRun: []
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: rmdmo.co.uk\www
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{68C03A3E-EB26-4600-9834-A0EA41CB0A56} : NameServer = 192.168.1.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winxp\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R2 NSHE;Guardant Emulator Driver;c:\winxp\system32\drivers\NSHE.SYS [2011-7-18 97792]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\winxp\system32\drivers\viahduaa.sys [2011-7-5 2136224]
S2 5789;5789;\??\c:\docume~1\srpark~1\locals~1\temp\5789.sys –> c:\docume~1\srpark~1\locals~1\temp\5789.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\winxp\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 EZUSB;GQ USB EPROM Programmer Driver;c:\winxp\system32\drivers\ezusb.sys [2002-9-16 27507]
S3 HTCAND32;HTC Device Driver;c:\winxp\system32\drivers\androidusb.sys –> c:\winxp\system32\drivers\ANDROIDUSB.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\winxp\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-09-03 12:48:03 22344 —-a-w- c:\winxp\system32\drivers\mbam.sys
2012-09-03 12:48:03 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-08-31 18:13:17 ——– d—–w- c:\program files\Zeitronix
2012-08-24 18:08:53 ——– d-sh–w- c:\documents and settings\sr parkin\IECompatCache
2012-08-17 17:45:19 14640 ——w- c:\winxp\system32\spmsgXP_2k3.dll
.
==================== Find3M ====================
.
2012-07-06 13:58:10 78336 —-a-w- c:\winxp\system32\browser.dll
2012-07-04 14:05:18 139784 —-a-w- c:\winxp\system32\drivers\rdpwd.sys
2012-07-03 13:40:18 1875072 —-a-w- c:\winxp\system32\win32k.sys
2012-07-02 17:48:20 920064 —-a-w- c:\winxp\system32\wininet.dll
2012-07-02 17:48:20 43520 —-a-w- c:\winxp\system32\licmgr10.dll
2012-07-02 17:48:20 1469440 —-a-w- c:\winxp\system32\inetcpl.cpl
2012-07-02 11:57:07 385024 —-a-w- c:\winxp\system32\html.iec
2012-06-25 15:04:24 1394248 —-a-w- c:\winxp\system32\msxml4.dll
.
============= FINISH: 11:17:32.51 ===============
Hi,

Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • If Malicious objects are found then ensure Cure is selected
    • If TDLFS File System is found then ensure Cure is selected (if Cure is not available, select Skip)
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



NEXT



Download ComboFix from the following location:

Link 1

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi,

Thanks a lot for your reply. I have completed the actions as directed, here are the logs for you. I have MalwareBytes installed, but it was not active during this process


TDSSKiller.exe
________________________________________________________________________________
___________

08:09:38.0875 1364 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
08:09:41.0109 1364 ============================================================
08:09:41.0109 1364 Current date / time: 2012/09/17 08:09:41.0109
08:09:41.0109 1364 SystemInfo:
08:09:41.0109 1364
08:09:41.0109 1364 OS Version: 5.1.2600 ServicePack: 3.0
08:09:41.0109 1364 Product type: Workstation
08:09:41.0109 1364 ComputerName: RS-01
08:09:41.0109 1364 UserName: SR Parkin
08:09:41.0109 1364 Windows directory: C:\WINXP
08:09:41.0109 1364 System windows directory: C:\WINXP
08:09:41.0109 1364 Processor architecture: Intel x86
08:09:41.0109 1364 Number of processors: 2
08:09:41.0109 1364 Page size: 0x1000
08:09:41.0109 1364 Boot type: Normal boot
08:09:41.0109 1364 ============================================================
08:09:42.0046 1364 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000058
08:09:42.0062 1364 ============================================================
08:09:42.0062 1364 \Device\Harddisk0\DR0:
08:09:42.0062 1364 MBR partitions:
08:09:42.0062 1364 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0xC7FF53F
08:09:42.0078 1364 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xC7FF5BD, BlocksNum 0x109C1103
08:09:42.0078 1364 ============================================================
08:09:42.0125 1364 C: <-> \Device\Harddisk0\DR0\Partition1
08:09:42.0140 1364 D: <-> \Device\Harddisk0\DR0\Partition2
08:09:42.0140 1364 ============================================================
08:09:42.0140 1364 Initialize success
08:09:42.0140 1364 ============================================================
08:10:00.0125 2580 ============================================================
08:10:00.0125 2580 Scan started
08:10:00.0125 2580 Mode: Manual; TDLFS;
08:10:00.0125 2580 ============================================================
08:10:00.0453 2580 ================ Scan system memory ========================
08:10:00.0453 2580 System memory - ok
08:10:00.0453 2580 ================ Scan services =============================
08:10:00.0531 2580 5789 - ok
08:10:00.0578 2580 Abiosdsk - ok
08:10:00.0578 2580 abp480n5 - ok
08:10:00.0593 2580 [ EA38C961260F29295C6D03070FA9D0B5 ] ACPI C:\WINXP\system32\DRIVERS\ACPI.sys
08:10:00.0593 2580 Suspicious file (Forged): C:\WINXP\system32\DRIVERS\ACPI.sys. Real md5: EA38C961260F29295C6D03070FA9D0B5, Fake md5: 8FD99680A539792A30E97944FDAECF17
08:10:00.0593 2580 ACPI ( Virus.Win32.Rloader.a ) - infected
08:10:00.0593 2580 ACPI - detected Virus.Win32.Rloader.a (0)
08:10:00.0625 2580 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINXP\system32\drivers\ACPIEC.sys
08:10:00.0625 2580 ACPIEC - ok
08:10:00.0625 2580 adpu160m - ok
08:10:00.0656 2580 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINXP\system32\drivers\aec.sys
08:10:00.0671 2580 aec - ok
08:10:00.0687 2580 [ F6B7B1ECD7B41736BDB6FF4B092BCB79 ] AFD C:\WINXP\System32\drivers\afd.sys
08:10:00.0687 2580 AFD - ok
08:10:00.0703 2580 Aha154x - ok
08:10:00.0703 2580 aic78u2 - ok
08:10:00.0703 2580 aic78xx - ok
08:10:00.0718 2580 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINXP\system32\alrsvc.dll
08:10:00.0718 2580 Alerter - ok
08:10:00.0734 2580 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINXP\System32\alg.exe
08:10:00.0734 2580 ALG - ok
08:10:00.0734 2580 AliIde - ok
08:10:00.0765 2580 [ 033448D435E65C4BD72E70521FD05C76 ] AmdPPM C:\WINXP\system32\DRIVERS\AmdPPM.sys
08:10:00.0765 2580 AmdPPM - ok
08:10:00.0781 2580 amsint - ok
08:10:00.0796 2580 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINXP\System32\appmgmts.dll
08:10:00.0796 2580 AppMgmt - ok
08:10:00.0796 2580 asc - ok
08:10:00.0796 2580 asc3350p - ok
08:10:00.0796 2580 asc3550 - ok
08:10:00.0859 2580 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINXP\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
08:10:00.0859 2580 aspnet_state - ok
08:10:00.0890 2580 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINXP\system32\DRIVERS\asyncmac.sys
08:10:00.0890 2580 AsyncMac - ok
08:10:00.0906 2580 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINXP\system32\DRIVERS\atapi.sys
08:10:00.0906 2580 atapi - ok
08:10:00.0906 2580 Atdisk - ok
08:10:00.0921 2580 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINXP\system32\DRIVERS\atmarpc.sys
08:10:00.0921 2580 Atmarpc - ok
08:10:00.0937 2580 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINXP\System32\audiosrv.dll
08:10:00.0937 2580 AudioSrv - ok
08:10:00.0968 2580 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINXP\system32\DRIVERS\audstub.sys
08:10:00.0968 2580 audstub - ok
08:10:01.0015 2580 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINXP\system32\drivers\Beep.sys
08:10:01.0015 2580 Beep - ok
08:10:01.0031 2580 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINXP\system32\qmgr.dll
08:10:01.0031 2580 BITS - ok
08:10:01.0062 2580 [ FC6D1D80588D371F0321E15A75B2F8F2 ] Browser C:\WINXP\System32\browser.dll
08:10:01.0062 2580 Browser - ok
08:10:01.0078 2580 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINXP\system32\drivers\cbidf2k.sys
08:10:01.0093 2580 cbidf2k - ok
08:10:01.0093 2580 cd20xrnt - ok
08:10:01.0109 2580 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINXP\system32\drivers\Cdaudio.sys
08:10:01.0109 2580 Cdaudio - ok
08:10:01.0140 2580 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINXP\system32\drivers\Cdfs.sys
08:10:01.0140 2580 Cdfs - ok
08:10:01.0140 2580 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINXP\system32\DRIVERS\cdrom.sys
08:10:01.0156 2580 Cdrom - ok
08:10:01.0156 2580 Changer - ok
08:10:01.0171 2580 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINXP\system32\cisvc.exe
08:10:01.0171 2580 CiSvc - ok
08:10:01.0171 2580 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINXP\system32\clipsrv.exe
08:10:01.0171 2580 ClipSrv - ok
08:10:01.0234 2580 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINXP\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
08:10:01.0234 2580 clr_optimization_v2.0.50727_32 - ok
08:10:01.0265 2580 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINXP\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
08:10:01.0312 2580 clr_optimization_v4.0.30319_32 - ok
08:10:01.0312 2580 CmdIde - ok
08:10:01.0312 2580 COMSysApp - ok
08:10:01.0328 2580 Cpqarray - ok
08:10:01.0343 2580 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINXP\System32\cryptsvc.dll
08:10:01.0343 2580 CryptSvc - ok
08:10:01.0343 2580 dac2w2k - ok
08:10:01.0343 2580 dac960nt - ok
08:10:01.0375 2580 [ 9222562D44021B988B9F9F62207FB6F2 ] DcomLaunch C:\WINXP\system32\rpcss.dll
08:10:01.0375 2580 DcomLaunch - ok
08:10:01.0406 2580 [ 7F19DBA1A467B838CCB23124A2C55568 ] DgiVecp C:\WINXP\system32\Drivers\DgiVecp.sys
08:10:01.0406 2580 DgiVecp - ok
08:10:01.0406 2580 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINXP\System32\dhcpcsvc.dll
08:10:01.0421 2580 Dhcp - ok
08:10:01.0421 2580 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINXP\system32\DRIVERS\disk.sys
08:10:01.0421 2580 Disk - ok
08:10:01.0421 2580 dmadmin - ok
08:10:01.0453 2580 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINXP\system32\drivers\dmboot.sys
08:10:01.0468 2580 dmboot - ok
08:10:01.0484 2580 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINXP\system32\drivers\dmio.sys
08:10:01.0484 2580 dmio - ok
08:10:01.0500 2580 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINXP\system32\drivers\dmload.sys
08:10:01.0500 2580 dmload - ok
08:10:01.0515 2580 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINXP\System32\dmserver.dll
08:10:01.0515 2580 dmserver - ok
08:10:01.0546 2580 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINXP\system32\drivers\DMusic.sys
08:10:01.0546 2580 DMusic - ok
08:10:01.0562 2580 [ D977659AE4D8ECE5286D99D1ED34614D ] Dnscache C:\WINXP\System32\dnsrslvr.dll
08:10:01.0562 2580 Dnscache - ok
08:10:01.0578 2580 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINXP\System32\dot3svc.dll
08:10:01.0578 2580 Dot3svc - ok
08:10:01.0578 2580 dpti2o - ok
08:10:01.0593 2580 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINXP\system32\drivers\drmkaud.sys
08:10:01.0593 2580 drmkaud - ok
08:10:01.0609 2580 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINXP\System32\eapsvc.dll
08:10:01.0609 2580 EapHost - ok
08:10:01.0625 2580 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINXP\System32\ersvc.dll
08:10:01.0625 2580 ERSvc - ok
08:10:01.0640 2580 [ 020CEAAEDC8EB655B6506B8C70D53BB6 ] Eventlog C:\WINXP\system32\services.exe
08:10:01.0656 2580 Eventlog - ok
08:10:01.0656 2580 [ F17F6226BDC0CD5F0BEF0DAF84D29BEC ] EventSystem C:\WINXP\system32\es.dll
08:10:01.0656 2580 EventSystem - ok
08:10:01.0687 2580 [ 3501A9554B5C584A102B2C66F95916DC ] EZUSB C:\WINXP\system32\Drivers\ezusb.sys
08:10:01.0687 2580 EZUSB - ok
08:10:01.0703 2580 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINXP\system32\drivers\Fastfat.sys
08:10:01.0703 2580 Fastfat - ok
08:10:01.0718 2580 [ 888CD7B39C37E13A2419BECFAAF0A28C ] FastUserSwitchingCompatibility C:\WINXP\System32\shsvcs.dll
08:10:01.0718 2580 FastUserSwitchingCompatibility - ok
08:10:01.0734 2580 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINXP\system32\drivers\Fdc.sys
08:10:01.0734 2580 Fdc - ok
08:10:01.0734 2580 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINXP\system32\drivers\Fips.sys
08:10:01.0734 2580 Fips - ok
08:10:01.0812 2580 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
08:10:01.0828 2580 FLEXnet Licensing Service - ok
08:10:01.0843 2580 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINXP\system32\drivers\Flpydisk.sys
08:10:01.0843 2580 Flpydisk - ok
08:10:01.0890 2580 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINXP\system32\DRIVERS\fltMgr.sys
08:10:01.0890 2580 FltMgr - ok
08:10:01.0937 2580 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINXP\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
08:10:01.0937 2580 FontCache3.0.0.0 - ok
08:10:01.0984 2580 [ 7DFF82ACDAB23414ABC2A95FEF8982F8 ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
08:10:02.0000 2580 ForceWare Intelligent Application Manager (IAM) - ok
08:10:02.0031 2580 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINXP\system32\drivers\Fs_Rec.sys
08:10:02.0031 2580 Fs_Rec - ok
08:10:02.0046 2580 [ F8C2888B12253D8390C94887FFB699F2 ] FTDIBUS C:\WINXP\system32\drivers\ftdibus.sys
08:10:02.0046 2580 FTDIBUS - ok
08:10:02.0062 2580 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINXP\system32\DRIVERS\ftdisk.sys
08:10:02.0062 2580 Ftdisk - ok
08:10:02.0093 2580 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINXP\system32\DRIVERS\msgpc.sys
08:10:02.0093 2580 Gpc - ok
08:10:02.0140 2580 [ D95554949082FD29A04D351B58396718 ] Hardlock C:\WINXP\system32\drivers\hardlock.sys
08:10:02.0156 2580 Hardlock - ok
08:10:02.0171 2580 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINXP\system32\DRIVERS\HDAudBus.sys
08:10:02.0171 2580 HDAudBus - ok
08:10:02.0234 2580 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINXP\PCHealth\HelpCtr\Binaries\pchsvc.dll
08:10:02.0234 2580 helpsvc - ok
08:10:02.0265 2580 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINXP\System32\hidserv.dll
08:10:02.0265 2580 HidServ - ok
08:10:02.0281 2580 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINXP\system32\DRIVERS\hidusb.sys
08:10:02.0281 2580 hidusb - ok
08:10:02.0312 2580 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINXP\System32\kmsvc.dll
08:10:02.0312 2580 hkmsvc - ok
08:10:02.0312 2580 hpn - ok
08:10:02.0328 2580 [ 5FABA4775D4C61E55EC669D643FFC71F ] HPZid412 C:\WINXP\system32\DRIVERS\HPZid412.sys
08:10:02.0328 2580 HPZid412 - ok
08:10:02.0343 2580 [ A3C43980EE1F1BEAC778B44EA65DBDD4 ] HPZipr12 C:\WINXP\system32\DRIVERS\HPZipr12.sys
08:10:02.0343 2580 HPZipr12 - ok
08:10:02.0343 2580 [ 2906949BD4E206F2BB0DD1896CE9F66F ] HPZius12 C:\WINXP\system32\DRIVERS\HPZius12.sys
08:10:02.0343 2580 HPZius12 - ok
08:10:02.0343 2580 HTCAND32 - ok
08:10:02.0359 2580 [ 937031C085718C1C04A9C0864625EC6B ] HTTP C:\WINXP\system32\Drivers\HTTP.sys
08:10:02.0375 2580 HTTP - ok
08:10:02.0406 2580 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINXP\System32\w3ssl.dll
08:10:02.0406 2580 HTTPFilter - ok
08:10:02.0406 2580 i2omgmt - ok
08:10:02.0406 2580 i2omp - ok
08:10:02.0421 2580 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINXP\system32\DRIVERS\i8042prt.sys
08:10:02.0421 2580 i8042prt - ok
08:10:02.0484 2580 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINXP\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
08:10:02.0500 2580 idsvc - ok
08:10:02.0515 2580 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINXP\system32\DRIVERS\imapi.sys
08:10:02.0515 2580 Imapi - ok
08:10:02.0531 2580 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINXP\system32\imapi.exe
08:10:02.0531 2580 ImapiService - ok
08:10:02.0531 2580 ini910u - ok
08:10:02.0546 2580 IntelIde - ok
08:10:02.0562 2580 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINXP\system32\DRIVERS\Ip6Fw.sys
08:10:02.0562 2580 Ip6Fw - ok
08:10:02.0578 2580 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINXP\system32\DRIVERS\ipfltdrv.sys
08:10:02.0578 2580 IpFilterDriver - ok
08:10:02.0593 2580 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINXP\system32\DRIVERS\ipinip.sys
08:10:02.0593 2580 IpInIp - ok
08:10:02.0609 2580 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINXP\system32\DRIVERS\ipnat.sys
08:10:02.0609 2580 IpNat - ok
08:10:02.0609 2580 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINXP\system32\DRIVERS\ipsec.sys
08:10:02.0625 2580 IPSec - ok
08:10:02.0640 2580 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINXP\system32\DRIVERS\irenum.sys
08:10:02.0640 2580 IRENUM - ok
08:10:02.0656 2580 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINXP\system32\DRIVERS\isapnp.sys
08:10:02.0656 2580 isapnp - ok
08:10:02.0718 2580 [ 381B25DC8E958D905B33130D500BBF29 ] JavaQuickStarterService C:\Program Files\Java\jre6\bin\jqs.exe
08:10:02.0718 2580 JavaQuickStarterService - ok
08:10:02.0765 2580 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINXP\system32\DRIVERS\kbdclass.sys
08:10:02.0765 2580 Kbdclass - ok
08:10:02.0765 2580 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINXP\system32\DRIVERS\kbdhid.sys
08:10:02.0781 2580 kbdhid - ok
08:10:02.0781 2580 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINXP\system32\drivers\kmixer.sys
08:10:02.0781 2580 kmixer - ok
08:10:02.0812 2580 [ C6EBF1D6AD71DF30DB49B8D3287E1368 ] KSecDD C:\WINXP\system32\drivers\KSecDD.sys
08:10:02.0812 2580 KSecDD - ok
08:10:02.0843 2580 [ 3695B8D03745B2F8022B161238347A9D ] LanmanServer C:\WINXP\System32\srvsvc.dll
08:10:02.0843 2580 LanmanServer - ok
08:10:02.0859 2580 [ 3B9324D60DD321BAB7BF6F77931D3FD1 ] lanmanworkstation C:\WINXP\System32\wkssvc.dll
08:10:02.0859 2580 lanmanworkstation - ok
08:10:02.0859 2580 lbrtfdc - ok
08:10:02.0875 2580 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINXP\System32\lmhsvc.dll
08:10:02.0875 2580 LmHosts - ok
08:10:02.0890 2580 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINXP\System32\msgsvc.dll
08:10:02.0890 2580 Messenger - ok
08:10:02.0906 2580 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINXP\system32\drivers\mnmdd.sys
08:10:02.0906 2580 mnmdd - ok
08:10:02.0937 2580 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINXP\system32\mnmsrvc.exe
08:10:02.0937 2580 mnmsrvc - ok
08:10:02.0953 2580 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINXP\system32\drivers\Modem.sys
08:10:02.0953 2580 Modem - ok
08:10:02.0984 2580 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINXP\system32\DRIVERS\mouclass.sys
08:10:02.0984 2580 Mouclass - ok
08:10:02.0984 2580 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINXP\system32\DRIVERS\mouhid.sys
08:10:02.0984 2580 mouhid - ok
08:10:03.0000 2580 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINXP\system32\drivers\MountMgr.sys
08:10:03.0000 2580 MountMgr - ok
08:10:03.0000 2580 mraid35x - ok
08:10:03.0000 2580 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINXP\system32\DRIVERS\mrxdav.sys
08:10:03.0000 2580 MRxDAV - ok
08:10:03.0031 2580 [ FB2FCCC70F7174C7BF64F48E96D3ADF4 ] MRxSmb C:\WINXP\system32\DRIVERS\mrxsmb.sys
08:10:03.0046 2580 MRxSmb - ok
08:10:03.0062 2580 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINXP\system32\msdtc.exe
08:10:03.0062 2580 MSDTC - ok
08:10:03.0078 2580 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINXP\system32\drivers\Msfs.sys
08:10:03.0078 2580 Msfs - ok
08:10:03.0078 2580 MSIServer - ok
08:10:03.0093 2580 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINXP\system32\drivers\MSKSSRV.sys
08:10:03.0093 2580 MSKSSRV - ok
08:10:03.0109 2580 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINXP\system32\drivers\MSPCLOCK.sys
08:10:03.0109 2580 MSPCLOCK - ok
08:10:03.0109 2580 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINXP\system32\drivers\MSPQM.sys
08:10:03.0109 2580 MSPQM - ok
08:10:03.0125 2580 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINXP\system32\DRIVERS\mssmbios.sys
08:10:03.0125 2580 mssmbios - ok
08:10:03.0156 2580 [ D48659BB24C48345D926ECB45C1EBDF5 ] MTsensor C:\WINXP\system32\DRIVERS\ASACPI.sys
08:10:03.0156 2580 MTsensor - ok
08:10:03.0171 2580 [ F7B1AD991491F02AF6DA70B00B8BF114 ] Mup C:\WINXP\system32\drivers\Mup.sys
08:10:03.0171 2580 Mup - ok
08:10:03.0187 2580 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINXP\System32\qagentrt.dll
08:10:03.0203 2580 napagent - ok
08:10:03.0218 2580 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINXP\system32\drivers\NDIS.sys
08:10:03.0218 2580 NDIS - ok
08:10:03.0250 2580 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINXP\system32\DRIVERS\ndistapi.sys
08:10:03.0250 2580 NdisTapi - ok
08:10:03.0265 2580 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINXP\system32\DRIVERS\ndisuio.sys
08:10:03.0265 2580 Ndisuio - ok
08:10:03.0265 2580 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINXP\system32\DRIVERS\ndiswan.sys
08:10:03.0265 2580 NdisWan - ok
08:10:03.0281 2580 [ 816460BD4B4ACD27937D1D0813E2E9E9 ] NDProxy C:\WINXP\system32\drivers\NDProxy.sys
08:10:03.0281 2580 NDProxy - ok
08:10:03.0281 2580 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINXP\system32\DRIVERS\netbios.sys
08:10:03.0281 2580 NetBIOS - ok
08:10:03.0296 2580 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINXP\system32\DRIVERS\netbt.sys
08:10:03.0296 2580 NetBT - ok
08:10:03.0312 2580 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINXP\system32\netdde.exe
08:10:03.0312 2580 NetDDE - ok
08:10:03.0328 2580 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINXP\system32\netdde.exe
08:10:03.0328 2580 NetDDEdsdm - ok
08:10:03.0343 2580 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINXP\system32\lsass.exe
08:10:03.0343 2580 Netlogon - ok
08:10:03.0343 2580 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINXP\System32\netman.dll
08:10:03.0343 2580 Netman - ok
08:10:03.0421 2580 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINXP\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
08:10:03.0421 2580 NetTcpPortSharing - ok
08:10:03.0437 2580 [ FCEE5FCB99F7C724593365C706D28388 ] Nla C:\WINXP\System32\mswsock.dll
08:10:03.0437 2580 Nla - ok
08:10:03.0453 2580 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINXP\system32\drivers\Npfs.sys
08:10:03.0453 2580 Npfs - ok
08:10:03.0484 2580 [ F8E396F5E703D7A8F37D90F59C776268 ] NSHE C:\WINXP\system32\Drivers\NSHE.SYS
08:10:03.0484 2580 NSHE - ok
08:10:03.0515 2580 [ 198FF60A42802C319FBA58FDB13EEE49 ] nSvcIp C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
08:10:03.0515 2580 nSvcIp - ok
08:10:03.0531 2580 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINXP\system32\drivers\Ntfs.sys
08:10:03.0546 2580 Ntfs - ok
08:10:03.0562 2580 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINXP\system32\lsass.exe
08:10:03.0562 2580 NtLmSsp - ok
08:10:03.0578 2580 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINXP\system32\ntmssvc.dll
08:10:03.0593 2580 NtmsSvc - ok
08:10:03.0609 2580 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINXP\system32\drivers\Null.sys
08:10:03.0609 2580 Null - ok
08:10:03.0765 2580 [ CD9ED87B4FC6EC41D3B5BE0B923843FC ] nv C:\WINXP\system32\DRIVERS\nv4_mini.sys
08:10:03.0906 2580 nv - ok
08:10:03.0937 2580 [ C61927D27B75ED56723F2508F1A6B1BE ] NVENETFD C:\WINXP\system32\DRIVERS\NVENETFD.sys
08:10:03.0937 2580 NVENETFD - ok
08:10:03.0937 2580 [ 52DCE3B30C9D61C8E20FE3C6DA4BDFB7 ] nvgts C:\WINXP\system32\DRIVERS\nvgts.sys
08:10:03.0937 2580 nvgts - ok
08:10:03.0953 2580 [ C529B614EF88BE0F62B886C67B516550 ] nvnetbus C:\WINXP\system32\DRIVERS\nvnetbus.sys
08:10:03.0953 2580 nvnetbus - ok
08:10:03.0968 2580 [ E48C1AA03B6519B51756E3232C093300 ] nvsvc C:\WINXP\system32\nvsvc32.exe
08:10:03.0968 2580 nvsvc - ok
08:10:04.0000 2580 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINXP\system32\DRIVERS\nwlnkflt.sys
08:10:04.0000 2580 NwlnkFlt - ok
08:10:04.0000 2580 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINXP\system32\DRIVERS\nwlnkfwd.sys
08:10:04.0000 2580 NwlnkFwd - ok
08:10:04.0062 2580 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
08:10:04.0062 2580 ose - ok
08:10:04.0093 2580 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINXP\system32\DRIVERS\parport.sys
08:10:04.0093 2580 Parport - ok
08:10:04.0093 2580 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINXP\system32\drivers\PartMgr.sys
08:10:04.0093 2580 PartMgr - ok
08:10:04.0125 2580 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINXP\system32\drivers\ParVdm.sys
08:10:04.0140 2580 ParVdm - ok
08:10:04.0140 2580 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINXP\system32\DRIVERS\pci.sys
08:10:04.0140 2580 PCI - ok
08:10:04.0140 2580 PCIDump - ok
08:10:04.0156 2580 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINXP\system32\DRIVERS\pciide.sys
08:10:04.0156 2580 PCIIde - ok
08:10:04.0171 2580 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINXP\system32\drivers\Pcmcia.sys
08:10:04.0171 2580 Pcmcia - ok
08:10:04.0171 2580 PDCOMP - ok
08:10:04.0171 2580 PDFRAME - ok
08:10:04.0171 2580 PDRELI - ok
08:10:04.0171 2580 PDRFRAME - ok
08:10:04.0187 2580 perc2 - ok
08:10:04.0187 2580 perc2hib - ok
08:10:04.0203 2580 [ 020CEAAEDC8EB655B6506B8C70D53BB6 ] PlugPlay C:\WINXP\system32\services.exe
08:10:04.0218 2580 PlugPlay - ok
08:10:04.0218 2580 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINXP\system32\lsass.exe
08:10:04.0218 2580 PolicyAgent - ok
08:10:04.0218 2580 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINXP\system32\DRIVERS\raspptp.sys
08:10:04.0218 2580 PptpMiniport - ok
08:10:04.0234 2580 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor C:\WINXP\system32\DRIVERS\processr.sys
08:10:04.0234 2580 Processor - ok
08:10:04.0234 2580 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINXP\system32\lsass.exe
08:10:04.0234 2580 ProtectedStorage - ok
08:10:04.0234 2580 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINXP\system32\DRIVERS\psched.sys
08:10:04.0250 2580 PSched - ok
08:10:04.0265 2580 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINXP\system32\DRIVERS\ptilink.sys
08:10:04.0281 2580 Ptilink - ok
08:10:04.0281 2580 ql1080 - ok
08:10:04.0281 2580 Ql10wnt - ok
08:10:04.0281 2580 ql12160 - ok
08:10:04.0281 2580 ql1240 - ok
08:10:04.0281 2580 ql1280 - ok
08:10:04.0312 2580 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINXP\system32\DRIVERS\rasacd.sys
08:10:04.0312 2580 RasAcd - ok
08:10:04.0328 2580 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINXP\System32\rasauto.dll
08:10:04.0328 2580 RasAuto - ok
08:10:04.0343 2580 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINXP\system32\DRIVERS\rasl2tp.sys
08:10:04.0343 2580 Rasl2tp - ok
08:10:04.0359 2580 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINXP\System32\rasmans.dll
08:10:04.0359 2580 RasMan - ok
08:10:04.0359 2580 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINXP\system32\DRIVERS\raspppoe.sys
08:10:04.0359 2580 RasPppoe - ok
08:10:04.0375 2580 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINXP\system32\DRIVERS\raspti.sys
08:10:04.0375 2580 Raspti - ok
08:10:04.0375 2580 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINXP\system32\DRIVERS\rdbss.sys
08:10:04.0375 2580 Rdbss - ok
08:10:04.0375 2580 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINXP\system32\DRIVERS\RDPCDD.sys
08:10:04.0375 2580 RDPCDD - ok
08:10:04.0406 2580 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINXP\system32\DRIVERS\rdpdr.sys
08:10:04.0406 2580 rdpdr - ok
08:10:04.0437 2580 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINXP\system32\drivers\RDPWD.sys
08:10:04.0453 2580 RDPWD - ok
08:10:04.0468 2580 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINXP\system32\sessmgr.exe
08:10:04.0468 2580 RDSessMgr - ok
08:10:04.0484 2580 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINXP\system32\DRIVERS\redbook.sys
08:10:04.0484 2580 redbook - ok
08:10:04.0500 2580 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINXP\System32\mprdim.dll
08:10:04.0500 2580 RemoteAccess - ok
08:10:04.0531 2580 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINXP\system32\regsvc.dll
08:10:04.0531 2580 RemoteRegistry - ok
08:10:04.0546 2580 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINXP\system32\locator.exe
08:10:04.0546 2580 RpcLocator - ok
08:10:04.0578 2580 [ 9222562D44021B988B9F9F62207FB6F2 ] RpcSs C:\WINXP\system32\rpcss.dll
08:10:04.0578 2580 RpcSs - ok
08:10:04.0593 2580 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINXP\system32\rsvp.exe
08:10:04.0609 2580 RSVP - ok
08:10:04.0625 2580 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINXP\system32\lsass.exe
08:10:04.0625 2580 SamSs - ok
08:10:04.0640 2580 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINXP\System32\SCardSvr.exe
08:10:04.0640 2580 SCardSvr - ok
08:10:04.0671 2580 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINXP\system32\schedsvc.dll
08:10:04.0671 2580 Schedule - ok
08:10:04.0687 2580 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINXP\system32\DRIVERS\secdrv.sys
08:10:04.0687 2580 Secdrv - ok
08:10:04.0703 2580 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINXP\System32\seclogon.dll
08:10:04.0703 2580 seclogon - ok
08:10:04.0718 2580 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINXP\system32\sens.dll
08:10:04.0718 2580 SENS - ok
08:10:04.0734 2580 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINXP\system32\DRIVERS\serenum.sys
08:10:04.0734 2580 serenum - ok
08:10:04.0734 2580 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINXP\system32\DRIVERS\serial.sys
08:10:04.0734 2580 Serial - ok
08:10:04.0750 2580 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINXP\system32\drivers\Sfloppy.sys
08:10:04.0750 2580 Sfloppy - ok
08:10:04.0765 2580 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINXP\System32\ipnathlp.dll
08:10:04.0765 2580 SharedAccess - ok
08:10:04.0781 2580 [ 888CD7B39C37E13A2419BECFAAF0A28C ] ShellHWDetection C:\WINXP\System32\shsvcs.dll
08:10:04.0781 2580 ShellHWDetection - ok
08:10:04.0781 2580 Simbad - ok
08:10:04.0781 2580 Sparrow - ok
08:10:04.0812 2580 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINXP\system32\drivers\splitter.sys
08:10:04.0812 2580 splitter - ok
08:10:04.0843 2580 [ 258DD5D4283FD9F9A7166BE9AE45CE73 ] Spooler C:\WINXP\system32\spoolsv.exe
08:10:04.0843 2580 Spooler - ok
08:10:04.0875 2580 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINXP\system32\DRIVERS\sr.sys
08:10:04.0875 2580 sr - ok
08:10:04.0875 2580 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINXP\system32\srsvc.dll
08:10:04.0875 2580 srservice - ok
08:10:04.0890 2580 [ 9B390283569EA58D43D2586032B892F5 ] Srv C:\WINXP\system32\DRIVERS\srv.sys
08:10:04.0906 2580 Srv - ok
08:10:04.0937 2580 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINXP\System32\ssdpsrv.dll
08:10:04.0937 2580 SSDPSRV - ok
08:10:04.0953 2580 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINXP\system32\wiaservc.dll
08:10:04.0968 2580 stisvc - ok
08:10:04.0984 2580 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINXP\system32\DRIVERS\swenum.sys
08:10:04.0984 2580 swenum - ok
08:10:05.0015 2580 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINXP\system32\drivers\swmidi.sys
08:10:05.0015 2580 swmidi - ok
08:10:05.0015 2580 SwPrv - ok
08:10:05.0015 2580 symc810 - ok
08:10:05.0031 2580 symc8xx - ok
08:10:05.0031 2580 sym_hi - ok
08:10:05.0031 2580 sym_u3 - ok
08:10:05.0046 2580 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINXP\system32\drivers\sysaudio.sys
08:10:05.0046 2580 sysaudio - ok
08:10:05.0078 2580 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINXP\system32\smlogsvc.exe
08:10:05.0078 2580 SysmonLog - ok
08:10:05.0109 2580 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINXP\System32\tapisrv.dll
08:10:05.0109 2580 TapiSrv - ok
08:10:05.0125 2580 [ AD978A1B783B5719720CFF204B666C8E ] Tcpip C:\WINXP\system32\DRIVERS\tcpip.sys
08:10:05.0125 2580 Tcpip - ok
08:10:05.0156 2580 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINXP\system32\drivers\TDPIPE.sys
08:10:05.0156 2580 TDPIPE - ok
08:10:05.0171 2580 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINXP\system32\drivers\TDTCP.sys
08:10:05.0171 2580 TDTCP - ok
08:10:05.0187 2580 [ 88155247177638048422893737429D9E ] TermDD C:\WINXP\system32\DRIVERS\termdd.sys
08:10:05.0187 2580 TermDD - ok
08:10:05.0187 2580 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINXP\System32\termsrv.dll
08:10:05.0203 2580 TermService - ok
08:10:05.0203 2580 [ 888CD7B39C37E13A2419BECFAAF0A28C ] Themes C:\WINXP\System32\shsvcs.dll
08:10:05.0203 2580 Themes - ok
08:10:05.0234 2580 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINXP\system32\tlntsvr.exe
08:10:05.0234 2580 TlntSvr - ok
08:10:05.0234 2580 TosIde - ok
08:10:05.0250 2580 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINXP\system32\trkwks.dll
08:10:05.0250 2580 TrkWks - ok
08:10:05.0265 2580 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINXP\system32\drivers\Udfs.sys
08:10:05.0265 2580 Udfs - ok
08:10:05.0265 2580 ultra - ok
08:10:05.0296 2580 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINXP\system32\DRIVERS\update.sys
08:10:05.0296 2580 Update - ok
08:10:05.0312 2580 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINXP\System32\upnphost.dll
08:10:05.0328 2580 upnphost - ok
08:10:05.0343 2580 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINXP\System32\ups.exe
08:10:05.0343 2580 UPS - ok
08:10:05.0359 2580 [ E919708DB44ED8543A7C017953148330 ] usbaudio C:\WINXP\system32\drivers\usbaudio.sys
08:10:05.0359 2580 usbaudio - ok
08:10:05.0375 2580 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINXP\system32\DRIVERS\usbccgp.sys
08:10:05.0375 2580 usbccgp - ok
08:10:05.0375 2580 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINXP\system32\DRIVERS\usbehci.sys
08:10:05.0375 2580 usbehci - ok
08:10:05.0406 2580 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINXP\system32\DRIVERS\usbhub.sys
08:10:05.0406 2580 usbhub - ok
08:10:05.0421 2580 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci C:\WINXP\system32\DRIVERS\usbohci.sys
08:10:05.0421 2580 usbohci - ok
08:10:05.0437 2580 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINXP\system32\DRIVERS\usbprint.sys
08:10:05.0437 2580 usbprint - ok
08:10:05.0453 2580 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINXP\system32\DRIVERS\usbscan.sys
08:10:05.0453 2580 usbscan - ok
08:10:05.0468 2580 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINXP\system32\DRIVERS\USBSTOR.SYS
08:10:05.0468 2580 USBSTOR - ok
08:10:05.0500 2580 [ B6CC50279D6CD28E090A5D33244ADC9A ] usb_rndisx C:\WINXP\system32\DRIVERS\usb8023x.sys
08:10:05.0500 2580 usb_rndisx - ok
08:10:05.0531 2580 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINXP\System32\drivers\vga.sys
08:10:05.0531 2580 VgaSave - ok
08:10:05.0593 2580 [ CBC1CE0A1FCE0DEED4F6F093BE91D132 ] VIAHdAudAddService C:\WINXP\system32\drivers\viahduaa.sys
08:10:05.0593 2580 VIAHdAudAddService - ok
08:10:05.0609 2580 ViaIde - ok
08:10:05.0609 2580 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINXP\system32\drivers\VolSnap.sys
08:10:05.0609 2580 VolSnap - ok
08:10:05.0625 2580 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINXP\System32\vssvc.exe
08:10:05.0625 2580 VSS - ok
08:10:05.0656 2580 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINXP\system32\w32time.dll
08:10:05.0656 2580 W32Time - ok
08:10:05.0656 2580 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINXP\system32\DRIVERS\wanarp.sys
08:10:05.0656 2580 Wanarp - ok
08:10:05.0687 2580 [ 4769596D7CC0F5FA447D2BABC239672A ] Wdf01000 C:\WINXP\system32\Drivers\wdf01000.sys
08:10:05.0703 2580 Wdf01000 - ok
08:10:05.0703 2580 WDICA - ok
08:10:05.0718 2580 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINXP\system32\drivers\wdmaud.sys
08:10:05.0718 2580 wdmaud - ok
08:10:05.0750 2580 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINXP\System32\webclnt.dll
08:10:05.0750 2580 WebClient - ok
08:10:05.0812 2580 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINXP\system32\wbem\WMIsvc.dll
08:10:05.0812 2580 winmgmt - ok
08:10:05.0828 2580 [ 051B1BDECD6DEE18C771B5D5EC7F044D ] WmdmPmSN C:\WINXP\system32\MsPMSNSv.dll
08:10:05.0828 2580 WmdmPmSN - ok
08:10:05.0859 2580 [ C8A6C82F90B055149925DC7526B2D78C ] Wmi C:\WINXP\System32\advapi32.dll
08:10:05.0875 2580 Wmi - ok
08:10:05.0906 2580 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINXP\system32\wbem\wmiapsrv.exe
08:10:05.0906 2580 WmiApSrv - ok
08:10:05.0953 2580 [ 6BAB4DC65515A098505F8B3D01FB6FE5 ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
08:10:05.0968 2580 WMPNetworkSvc - ok
08:10:06.0031 2580 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINXP\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
08:10:06.0046 2580 WPFFontCache_v0400 - ok
08:10:06.0078 2580 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINXP\System32\drivers\ws2ifsl.sys
08:10:06.0078 2580 WS2IFSL - ok
08:10:06.0109 2580 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINXP\system32\wscsvc.dll
08:10:06.0109 2580 wscsvc - ok
08:10:06.0140 2580 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINXP\system32\wuauserv.dll
08:10:06.0140 2580 wuauserv - ok
08:10:06.0156 2580 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINXP\system32\DRIVERS\WudfPf.sys
08:10:06.0156 2580 WudfPf - ok
08:10:06.0171 2580 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINXP\system32\DRIVERS\wudfrd.sys
08:10:06.0171 2580 WudfRd - ok
08:10:06.0187 2580 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINXP\System32\WUDFSvc.dll
08:10:06.0187 2580 WudfSvc - ok
08:10:06.0203 2580 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINXP\System32\wzcsvc.dll
08:10:06.0203 2580 WZCSVC - ok
08:10:06.0218 2580 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINXP\System32\xmlprov.dll
08:10:06.0234 2580 xmlprov - ok
08:10:06.0234 2580 ================ Scan global ===============================
08:10:06.0250 2580 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINXP\system32\basesrv.dll
08:10:06.0281 2580 [ B23423313519C522E0E73BA170D3CE71 ] C:\WINXP\system32\winsrv.dll
08:10:06.0281 2580 [ B23423313519C522E0E73BA170D3CE71 ] C:\WINXP\system32\winsrv.dll
08:10:06.0296 2580 [ 020CEAAEDC8EB655B6506B8C70D53BB6 ] C:\WINXP\system32\services.exe
08:10:06.0296 2580 [Global] - ok
08:10:06.0296 2580 ================ Scan MBR ==================================
08:10:06.0312 2580 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
08:10:06.0578 2580 \Device\Harddisk0\DR0 - ok
08:10:06.0578 2580 ================ Scan VBR ==================================
08:10:06.0578 2580 [ BF9745B394B0705E99A283AE90CBCB1D ] \Device\Harddisk0\DR0\Partition1
08:10:06.0578 2580 \Device\Harddisk0\DR0\Partition1 - ok
08:10:06.0578 2580 [ 0DAD9429FB5BC515236286B07036371F ] \Device\Harddisk0\DR0\Partition2
08:10:06.0578 2580 \Device\Harddisk0\DR0\Partition2 - ok
08:10:06.0578 2580 ============================================================
08:10:06.0578 2580 Scan finished
08:10:06.0578 2580 ============================================================
08:10:06.0593 1744 Detected object count: 1
08:10:06.0593 1744 Actual detected object count: 1
08:10:16.0250 1744 C:\WINXP\system32\DRIVERS\ACPI.sys - copied to quarantine
08:10:17.0234 1744 Backup copy found, using it..
08:10:17.0234 1744 C:\WINXP\system32\DRIVERS\ACPI.sys - will be cured on reboot
08:10:17.0234 1744 ACPI ( Virus.Win32.Rloader.a ) - User select action: Cure
08:10:24.0390 2204 Deinitialize success
________________________________________________________________________________
_______________________________________________________________

ComboFix 12-09-16.01 - SR Parkin 17/09/2012 8:19.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2815.2408 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\winxp\system32\NEWBB.tmp
c:\winxp\system32\NEWC1.tmp
c:\winxp\system32\UNWISE.EXE
.
.
((((((((((((((((((((((((( Files Created from 2012-08-17 to 2012-09-17 )))))))))))))))))))))))))))))))
.
.
2012-09-17 07:10 . 2012-09-17 07:10 ——– d—–w- C:\TDSSKiller_Quarantine
2012-09-03 12:48 . 2012-09-03 12:48 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2012-09-03 12:48 . 2012-07-03 12:46 22344 —-a-w- c:\winxp\system32\drivers\mbam.sys
2012-08-31 18:13 . 2012-08-31 18:13 ——– d—–w- c:\program files\Zeitronix
2012-08-24 18:08 . 2012-08-24 18:08 ——– d-sh–w- c:\documents and settings\SR Parkin\IECompatCache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-17 07:10 . 2008-04-14 09:00 187776 —-a-w- c:\winxp\system32\drivers\acpi.sys
2012-07-06 13:58 . 2008-04-14 09:00 78336 —-a-w- c:\winxp\system32\browser.dll
2012-07-04 14:05 . 2011-07-05 12:04 139784 —-a-w- c:\winxp\system32\drivers\rdpwd.sys
2012-07-03 13:40 . 2011-04-12 18:46 1875072 —-a-w- c:\winxp\system32\win32k.sys
2012-07-02 17:48 . 2011-06-14 18:15 920064 —-a-w- c:\winxp\system32\wininet.dll
2012-07-02 17:48 . 2011-06-14 18:15 43520 —-a-w- c:\winxp\system32\licmgr10.dll
2012-07-02 17:48 . 2011-06-14 18:15 1469440 —-a-w- c:\winxp\system32\inetcpl.cpl
2012-07-02 11:57 . 2011-06-14 18:15 385024 —-a-w- c:\winxp\system32\html.iec
2012-06-25 15:04 . 2012-06-25 15:04 1394248 —-a-w- c:\winxp\system32\msxml4.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Seagull Drivers"="ssdal_nc.exe startup" [X]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2010-05-24 33747360]
"NvMediaCenter"="c:\winxp\system32\NvMcTray.dll" [2010-03-16 110696]
"NvCplDaemon"="c:\winxp\system32\NvCpl.dll" [2010-03-16 13670504]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
.
R2 NSHE;Guardant Emulator Driver;c:\winxp\system32\drivers\NSHE.SYS [18/07/2011 20:10 97792]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\winxp\system32\drivers\viahduaa.sys [05/07/2011 13:16 2136224]
S2 5789;5789;\??\c:\docume~1\SRPARK~1\LOCALS~1\Temp\5789.sys –> c:\docume~1\SRPARK~1\LOCALS~1\Temp\5789.sys [?]
S2 EZUSB;GQ USB EPROM Programmer Driver;c:\winxp\system32\drivers\ezusb.sys [16/09/2002 12:43 27507]
S3 HTCAND32;HTC Device Driver;c:\winxp\system32\Drivers\ANDROIDUSB.sys –> c:\winxp\system32\Drivers\ANDROIDUSB.sys [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - 13155748
*NewlyCreated* - 40260911
*NewlyCreated* - WS2IFSL
*Deregistered* - 13155748
*Deregistered* - 40260911
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
uStart Page = https://mail.google.com/mail/u/0/?hl=en&shva=1#inbox
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: rmdmo.co.uk\www
TCP: Interfaces\{68C03A3E-EB26-4600-9834-A0EA41CB0A56}: NameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
HKLM-Run-nwiz - nwiz.exe
HKLM-Run-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
SafeBoot-40260911.sys
AddRemove-Hardlock Device Drivers - c:\winxp\system32\UNWISE.EXE
AddRemove-{79A765E1-C399-405B-85AF-466F52E918B0} - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-09-17 08:21
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-09-17 08:22:06
ComboFix-quarantined-files.txt 2012-09-17 07:22
.
Pre-Run: 88,517,615,616 bytes free
Post-Run: 88,762,720,256 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINXP
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINXP="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 697CC4E38E44B947867ED8FEB529B6B4
MalwareBytes is an excellent program and I am very glad to see that you are using it, however, it is very different from an AntiVirus program, which you need to use as well.

Microsoft Security Essentials, is an excellent free antivirus, which runs very well alongside Malwarebytes Antimalware, so please download and install it, give it a run and let me know if it finds anything:

http://www.microsoft.com/security_essentials/


NEXT


  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Hi, Yes it seems a very good program, but it never found any issues initially with the PC, so I figured it had some gaps. Here are the Logs Malwarebytes Anti-Malware 1.65.0.1400 www.malwarebytes.org Database version: v2012.09.17.08 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 SR Parkin :: RS-01 [administrator] 17/09/2012 19:01:04 mbam-log-2012-09-17 (19-01-04).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 181437 Time elapsed: 2 minute(s), Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) ___________________________________ ESTESCAN C:\TDSSKiller_Quarantine\17.09.2012_08.09.41\rtkt0000\svc0000\tsk0000.dta Win32/Simda.M.Gen trojan Looks like the Trojan showing on ESET Scan is already in the Quarrantine, from the TDSS Tool. If there is anything else you can recommend, please let me know. Please also tell me where I can donact, as I would not have been able to do this without the help of this forum. I posted on another and didn't get a reply so was pretty peeved. Thanks! Scott
yes, that item is in quarantine already, so it can't harm your computer, did you install Microsoft Security Essentials? Did it find anything? (you can delete the TDSSKiller quarantine at the end if you wish)

there are just a couple more scans I'd like you to run just in case there are any leftovers

I posted on another and didn't get a reply

that happens sometimes, all the helpers are volunteers and quite often there are more people looking for help than there are volunteers, it can get overwhelming sometimes (there is a donate button in my signature :))


Please run the following:

Download AdwCleaner from here and save it to your desktop.
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply


NEXT


  • Please download MiniToolBox and save it to your desktop and run it.

    Checkmark following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Report FF Proxy Settings
  • List content of Hosts
  • List installed programs.

Click Go and post the result (Result.txt) that pops up. A copy of result.txt will be saved in the same directory the tool is run.


NEXT


Please download Farbar Service Scanner to your desktop and run it.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


NEXT


Please advise how the computer is running now and if there are any outstanding issues
I haven't done Microsoft Security Essentials yet, I will try that once you have had a look at these. I have used it before on this PC and it didnt find anything if I remember! Here are the Logs: # AdwCleaner v2.002 - Logfile created 09/18/2012 at 11:23:45 # Updated 16/09/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 3 (32 bits) # User : SR Parkin - RS-01 # Boot Mode : Normal # Running from : C:\Documents and Settings\SR Parkin\Desktop\Scanners\adwcleaner.exe # Option [Delete] ***** [Services] ***** Farbar Service Scanner Version: 06-08-2012 Ran by [removed] (administrator) on 18-09-2012 at 11:26:57 Running from "C:\Documents and Settings\SR Parkin\Desktop\Scanners" Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\WINXP\system32\dhcpcsvc.dll => MD5 is legit C:\WINXP\system32\Drivers\afd.sys => MD5 is legit C:\WINXP\system32\Drivers\netbt.sys => MD5 is legit C:\WINXP\system32\Drivers\tcpip.sys => MD5 is legit C:\WINXP\system32\Drivers\ipsec.sys => MD5 is legit C:\WINXP\system32\dnsrslvr.dll => MD5 is legit C:\WINXP\system32\ipnathlp.dll => MD5 is legit C:\WINXP\system32\netman.dll => MD5 is legit C:\WINXP\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINXP\system32\srsvc.dll => MD5 is legit C:\WINXP\system32\Drivers\sr.sys => MD5 is legit C:\WINXP\system32\wscsvc.dll => MD5 is legit C:\WINXP\system32\wbem\WMIsvc.dll => MD5 is legit C:\WINXP\system32\wuauserv.dll => MD5 is legit C:\WINXP\system32\qmgr.dll => MD5 is legit C:\WINXP\system32\es.dll [2010-09-16 14:10] - [2010-09-16 14:10] - 0253952 ____A (Microsoft Corporation) F17F6226BDC0CD5F0BEF0DAF84D29BEC C:\WINXP\system32\cryptsvc.dll => MD5 is legit C:\WINXP\system32\svchost.exe => MD5 is legit C:\WINXP\system32\rpcss.dll [2010-09-16 14:11] - [2010-09-16 14:11] - 0401408 ____A (Microsoft Corporation) 9222562D44021B988B9F9F62207FB6F2 C:\WINXP\system32\services.exe [2010-09-16 14:11] - [2010-09-16 14:11] - 0110592 ____A (Microsoft Corporation) 020CEAAEDC8EB655B6506B8C70D53BB6 Extra List: ======= Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4) 0x0700000005000000010000000200000003000000040000000600000007000000 IpSec Tag value is correct. **** End of log **** ***** [Files / Folders] ***** Folder Deleted : C:\Documents and Settings\SR Parkin\Local Settings\Application Data\AskToolbar Folder Deleted : C:\WINXP\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registry] ***** Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\Software\APN Key Deleted : HKLM\Software\AskToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Restored : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Restored : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxps://mail.google.com/mail/u/0/?hl=en&shva=1#inbox –> hxxp://www.google.com ************************* AdwCleaner[S1].txt - [3123 octets] - [18/09/2012 11:23:45] ########## EOF - C:\AdwCleaner[S1].txt - [3183 octets] ########## MiniToolBox by Farbar Version: 23-07-2012 Ran by [removed] (administrator) on 18-09-2012 at 11:26:34 Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= Hosts content: ================================= 127.0.0.1 localhost =========================== Installed Programs ============================ Adobe AIR (Version: 2.6.0.19120) Adobe Anchor Service CS4 (Version: 2.0) Adobe Bridge CS4 (Version: 3) Adobe CMaps CS4 (Version: 2.0) Adobe Color - Photoshop Specific CS4 (Version: 2.0) Adobe Color EU Extra Settings CS4 (Version: 2.0) Adobe Color JA Extra Settings CS4 (Version: 2.0) Adobe Color NA Recommended Settings CS4 (Version: 2.0) Adobe Color Video Profiles CS CS4 (Version: 2.0) Adobe CSI CS4 (Version: 1) Adobe Default Language CS4 (Version: 2.0) Adobe ExtendScript Toolkit CS4 (Version: 3.0.0) Adobe Flash Player 11 ActiveX (Version: 11.1.102.55) Adobe Fonts All (Version: 2.0) Adobe Linguistics CS4 (Version: 4.0.0) Adobe Output Module (Version: 2.0) Adobe PDF Library Files CS4 (Version: 9.0) Adobe Photoshop CS4 (Version: 11.0) Adobe Photoshop CS4 Support (Version: 11.0) Adobe Search for Help (Version: 1.0) Adobe Service Manager Extension (Version: 1.0) Adobe Setup (Version: 2.0) Adobe Type Support CS4 (Version: 9.0) Adobe Update Manager CS4 (Version: 6.0.0) Adobe WinSoft Linguistics Plugin (Version: 1.1) Adobe XMP Panels CS4 (Version: 2.0) AdobeColorCommonSetCMYK (Version: 2.0) AdobeColorCommonSetRGB (Version: 2.0) Compatibility Pack for the 2007 Office system (Version: 12.0.6514.5001) Connect (Version: 1.0.0.1) Core FTP LE CutePDF Writer 2.8 Driver FTDI (1.00.020) ESET Online Scanner v3 ETKA 7.3 Germany 2011 Foxit Reader (Version: 5.3.0.423) GQ USB Programmer (Version: 4.00.4) Java Auto Updater (Version: 2.0.6.1) Java™ 6 Update 29 (Version: 6.0.290) kuler (Version: 2.0) Malwarebytes Anti-Malware version 1.65.0.1400 (Version: 1.65.0.1400) Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729) Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Kernel-Mode Driver Framework Feature Pack 1.7 Microsoft Office Professional Edition 2003 (Version: 11.0.5614.0) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148) MSXML 4.0 SP3 Parser (KB2721691) (Version: 4.30.2114.0) MSXML 4.0 SP3 Parser (Version: 4.30.2100.0) NVIDIA Display Control Panel (Version: 6.14.11.9713) NVIDIA Drivers (Version: 1.10.57.35) NVIDIA ForceWare Network Access Manager (Version: 1.00.7325.0) NVIDIA nView Desktop Manager (Version: 6.14.10.00) NVIDIA PhysX (Version: 9.10.0129) PageBreeze Free HTML Editor PDF Settings CS4 (Version: 9.0) Photoshop Camera Raw (Version: 5.0) Platform (Version: 1.34) QFolder (Version: 1.00.0000) Samsung ML-1640 Series SolidWorks eDrawings 2011 (Version: 11.4.113) Suite Shared Configuration CS4 (Version: 1.0) Universal Extractor 1.6.1 (Version: 1.6.1) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1) Update for Microsoft Windows (KB971513) Update for Windows XP (KB2467659) (Version: 1) Update for Windows XP (KB2541763) (Version: 1) Update for Windows XP (KB2607712) (Version: 1) Update for Windows XP (KB2616676) (Version: 1) Update for Windows XP (KB2641690) (Version: 1) Update for Windows XP (KB2718704) (Version: 1) Update for Windows XP (KB2736233) (Version: 1) Update for Windows XP (KB898461) (Version: 1) VIA Platform Device Manager (Version: 1.34) WebFldrs XP (Version: 9.50.7523) Windows Driver Package - FTDI USB Device Driver Package (03/30/2010 2.06.02) (Version: 03/30/2010 2.06.02) Windows Genuine Advantage Notifications (KB905474) (Version: 1.9.0040.0) Windows Media Format 11 runtime Zeitronix Data Logger v3.1.6 (Version: 3.1.6) **** End of log **** Thanks!!!!!!!!
good, the logs are looking better,

[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click on "Do I have Java"
  • It will check your current version and then offer to update to the latest version
  • Watch for and make sure you untick the box next to whatever free program they prompt you to install during the installation, unless you want it.

Note: Check in Programs and Features (or Add/Remove Programs if you are an XP user) to make certain there are no old versions of Java still installed, if there are - remove them.



Please advise how the computer is running now and if there are any outstanding issues
Hi, I have updated Java and all seems good. I will report back if I have any further issues. Going to do some full scans on the other 6 PCs I have now to see if anything is going on with those! I will donate £50 now! Thanks
Thank-you, that was very kind.

If I might suggest, for the machines that aren't showing any sign of infection, run the Malwarebytes Antimalware scan and the ESET on-line scan. As long as they are both clear, then the machines should be fine.

If any of the machines are showing signs of infection, please post a DDS log and asw MBR and I can look at them for you
(one at a time or else I get confused :wacko:

I'll post instructions for all the scans here to save you scrolling back through the topic

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


NEXT

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well



NEXT


Please download Malwarebytes Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish
Well the first computer I tried, not good. After starting the scan, my brother who uses it said 'yeah it crashes all the time', thanks for telling me!

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by [removed] at 17:15:28 on 2012-09-21
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2815.1941 [GMT 1:00]
.
.
============== Running Processes ===============
.
C:\WINXP\system32\nvsvc32.exe
C:\WINXP\system32\svchost -k DcomLaunch
svchost.exe
C:\WINXP\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINXP\system32\spoolsv.exe
svchost.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINXP\system32\svchost.exe -k imgsvc
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINXP\Explorer.EXE
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINXP\system32\RUNDLL32.EXE
C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe
C:\WINXP\system32\ctfmon.exe
C:\WINXP\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\RS Parkin Ltd\Desktop\Scanners\aswMBR.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://mail.google.com/mail/?hl=en&shva;=1#inbox
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [ctfmon.exe] c:\winxp\system32\ctfmon.exe
uRun: [ISUSPM] "c:\documents and settings\all users\application data\flexnet\connect\11\ISUSPM.exe" -scheduler
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\winxp\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\winxp\system32\NvCpl.dll,NvStartup
mRun: [AdobeCS4ServiceManager] "c:\program files\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [Seagull Drivers] ssdal_nc.exe startup
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [HTC Sync Loader] "c:\program files\htc\htc sync 3.0\htcUPCTLoader.exe" -startup
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
dRun: [CTFMON.EXE] c:\winxp\system32\CTFMON.EXE
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Trusted Zone: parcelforce.net\www
Trusted Zone: rmdmo.co.uk\www
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: Interfaces\{7DF36725-0848-4B01-A80C-D5A30E228A18} : NameServer = 192.168.1.1
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winxp\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-9-21 399432]
R2 MSSQL$FINAWARE;SQL Server (FINAWARE);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
R2 NSHE;Guardant Emulator Driver;c:\winxp\system32\drivers\NSHE.SYS [2011-7-20 97792]
R2 PassThru Service;Internet Pass-Through Service;c:\program files\htc\internet pass-through\PassThruSvr.exe [2011-3-31 80896]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\winxp\system32\drivers\viahduaa.sys [2011-7-6 2136224]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-3 676936]
S2 SSPORT;SSPORT;\??\c:\winxp\system32\drivers\ssport.sys –> c:\winxp\system32\drivers\SSPORT.sys [?]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\winxp\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-3-30 250288]
S3 HTCAND32;HTC Device Driver;c:\winxp\system32\drivers\ANDROIDUSB.sys [2012-8-7 24576]
S3 htcnprot;HTC NDIS Protocol Driver;c:\winxp\system32\drivers\htcnprot.sys [2010-6-22 21248]
S3 MBAMProtector;MBAMProtector;c:\winxp\system32\drivers\mbam.sys [2012-8-3 22856]
.
=============== Created Last 30 ================
.
2012-09-21 15:52:52 73728 —-a-w- c:\winxp\system32\javacpl.cpl
2012-09-21 15:52:52 477168 —-a-w- c:\winxp\system32\npdeployJava1.dll
2012-09-21 15:14:41 ——– d—–w- c:\program files\ESET
.
==================== Find3M ====================
.
2012-09-21 15:52:46 473072 —-a-w- c:\winxp\system32\deployJava1.dll
2012-09-21 10:15:16 73136 —-a-w- c:\winxp\system32\FlashPlayerCPLApp.cpl
2012-09-21 10:15:16 696240 —-a-w- c:\winxp\system32\FlashPlayerApp.exe
2012-09-21 10:15:15 9573296 —-a-w- c:\winxp\system32\FlashPlayerInstaller.exe
2012-09-07 16:04:46 22856 —-a-w- c:\winxp\system32\drivers\mbam.sys
2012-08-03 12:37:49 35144 —-a-w- c:\winxp\system32\drivers\mbamchameleon.sys
2012-08-03 11:44:00 162816 –sha-w- c:\documents and settings\rs parkin ltd\application data\vcape.dll
2012-07-06 13:58:10 78336 —-a-w- c:\winxp\system32\browser.dll
2012-07-04 14:05:18 139784 —-a-w- c:\winxp\system32\drivers\rdpwd.sys
2012-07-03 13:40:18 1875072 —-a-w- c:\winxp\system32\win32k.sys
2012-07-02 17:48:20 920064 —-a-w- c:\winxp\system32\wininet.dll
2012-07-02 17:48:20 43520 —-a-w- c:\winxp\system32\licmgr10.dll
2012-07-02 17:48:20 1469440 —-a-w- c:\winxp\system32\inetcpl.cpl
2012-07-02 11:57:07 385024 —-a-w- c:\winxp\system32\html.iec
2012-06-25 15:04:24 1394248 —-a-w- c:\winxp\system32\msxml4.dll
.
============= FINISH: 17:15:34.71 ===============




ESETSCAN

C:\Documents and Settings\RS Parkin Ltd\Application Data\vcape.dll a variant of Win32/Medfos.BR trojan
C:\Documents and Settings\RS Parkin Ltd\Application Data\Sun\Java\Deployment\cache\6.0\39\4f581d67-38f5fb3e a variant of Win32/Injector.USA trojan
C:\Documents and Settings\RS Parkin Ltd\Local Settings\Application Data\{0f181d9d-f14f-950d-5715-e95a70b79248}\n a variant of Win32/Kryptik.AKUA trojan
C:\Documents and Settings\RS Parkin Ltd\Local Settings\Temp\jar_cache6259055816955697368.tmp multiple threats
C:\WINXP\Installer\{0f181d9d-f14f-950d-5715-e95a70b79248}\U\00000001.@ Win32/Conedex.I trojan

_________________________________

ASWMBR

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-09-21 16:53:36
—————————–
16:53:36.343 OS Version: Windows 5.1.2600 Service Pack 3
16:53:36.343 Number of processors: 2 586 0x603
16:53:36.343 ComputerName: RS-02 UserName:
16:53:41.125 Initialize success
16:56:28.656 AVAST engine defs: 12092100
17:06:23.796 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Scsi\nvgts1Port2Path0Target0Lun0
17:06:23.796 Disk 0 Vendor: ST325031 CC38 Size: 238475MB BusType: 3
17:06:23.828 Disk 0 MBR read successfully
17:06:23.828 Disk 0 MBR scan
17:06:23.859 Disk 0 Windows XP default MBR code
17:06:23.875 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 102398 MB offset 63
17:06:23.875 Disk 0 Partition - 00 0F Extended LBA 136066 MB offset 209712510
17:06:23.890 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 136066 MB offset 209712573
17:06:23.890 Disk 0 scanning sectors +488376000
17:06:23.968 Disk 0 scanning C:\WINXP\system32\drivers
17:06:30.796 Service scanning
17:06:44.453 Modules scanning
17:06:49.562 Disk 0 trace - called modules:
17:06:49.578 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll SCSIPORT.SYS nvgts.sys
17:06:49.578 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a2f8ab8]
17:06:49.578 3 CLASSPNP.SYS[b80f8fd7] -> nt!IofCallDriver -> \Device\00000061[0x8a2f5920]
17:06:49.578 5 ACPI.sys[b7f7f620] -> nt!IofCallDriver -> \Device\Scsi\nvgts1Port2Path0Target0Lun0[0x8a2f5030]
17:06:53.578 AVAST engine scan C:\WINXP
17:06:57.968 AVAST engine scan C:\WINXP\system32
17:08:32.750 AVAST engine scan C:\WINXP\system32\drivers
17:08:45.953 AVAST engine scan C:\Documents and Settings\RS Parkin Ltd
17:08:57.859 File: C:\Documents and Settings\RS Parkin Ltd\Application Data\Sun\Java\Deployment\cache\6.0\39\4f581d67-38f5fb3e **INFECTED** Win32:Kryptik-JNK [Trj]
17:08:59.000 File: C:\Documents and Settings\RS Parkin Ltd\Application Data\vcape.dll **INFECTED** Win32:Delf-STA [Trj]
17:09:10.437 File: C:\Documents and Settings\RS Parkin Ltd\Local Settings\Application Data\{0f181d9d-f14f-950d-5715-e95a70b79248}\n **INFECTED** Win32:Malware-gen
17:09:42.953 AVAST engine scan C:\Documents and Settings\All Users
17:09:47.718 Scan finished successfully
17:14:38.265 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\RS Parkin Ltd\Desktop\MBR.dat"
17:14:38.281 The log file has been saved successfully to "C:\Documents and Settings\RS Parkin Ltd\Desktop\aswMBR.txt"


_________________________

Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.21.07

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
RS Parkin Ltd :: RS-02 [administrator]

21/09/2012 15:58:30
mbam-log-2012-09-21 (16-07-06).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 206055
Time elapsed: 2 minute(s), 47 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 3
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowHelp (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowRun (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken.

Folders Detected: 1
C:\Documents and Settings\RS Parkin Ltd\Start Menu\Programs\Live Security Platinum (Rogue.LiveSecurityPlatinum) -> No action taken.

Files Detected: 8
C:\Documents and Settings\RS Parkin Ltd\Application Data\Bafo\qyaca.exe (Exploit.Drop.COD) -> No action taken.
C:\WINXP\system32\asr_hare.dll (Trojan.Agent) -> No action taken.
C:\Documents and Settings\RS Parkin Ltd\Local Settings\Temp\sgwe3t.exe (Trojan.Inject) -> No action taken.
C:\Documents and Settings\RS Parkin Ltd\Local Settings\Temp\~!#3A.tmp (Exploit.Drop.COD) -> No action taken.
C:\WINXP\Installer\{0f181d9d-f14f-950d-5715-e95a70b79248}\n (Trojan.Sirefef) -> No action taken.
C:\WINXP\Installer\{0f181d9d-f14f-950d-5715-e95a70b79248}\U\80000000.@ (Trojan.Small) -> No action taken.
C:\WINXP\Installer\{0f181d9d-f14f-950d-5715-e95a70b79248}\U\800000cb.@ (Rootkit.0Access) -> No action taken.
C:\Documents and Settings\RS Parkin Ltd\Start Menu\Programs\Live Security Platinum\Live Security Platinum.lnk (Rogue.LiveSecurityPlatinum) -> No action taken.

(end)


NOT GOOD!!

Thanks
Please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • If Malicious objects are found then ensure Cure is selected
    • If TDLFS File System is found then ensure Cure is selected (if Cure is not available, select Skip)
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



NEXT



Download ComboFix from the following location:

Link 1

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI