This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

combofix scan to analyze [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 12-10-03.03 - Owner 04/10/2012 6:13.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.2.1033.18.3327.2773 [GMT 2:00]
Running from: d:\abatman\ComboFix.exe
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users.WINDOWS4\Application Data\TEMP
C:\install.exe
c:\windows4\system\VB40032.DLL
c:\windows4\system32\default_user_class.dat.LOG
c:\windows4\system32\msssc.dll
c:\windows4\system32\PowerToyReadme.htm
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-04 to 2012-10-04 )))))))))))))))))))))))))))))))
.
.
2012-10-04 03:06 . 2011-03-10 16:04 46280 —-a-w- c:\windows4\system32\drivers\PSKMAD.sys
2012-10-03 01:55 . 2012-10-03 01:55 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Application Data\mkvtoolnix
2012-10-03 01:54 . 2012-10-03 01:55 ——– d—–w- c:\program files\MKVToolNix
2012-10-03 01:42 . 2012-10-03 01:42 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Local Settings\Application Data\MPlayer
2012-10-03 01:40 . 2012-10-03 01:48 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Application Data\VC
2012-10-03 01:40 . 2012-10-03 01:40 ——– d—–w- c:\program files\TEncoder Video Converter
2012-09-28 08:24 . 2012-09-28 08:24 ——– d—–w- c:\documents and settings\All Users.WINDOWS4\Application Data\ProcessLasso
2012-09-28 08:23 . 2012-09-28 08:27 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Application Data\ProcessLasso
2012-09-28 03:50 . 2012-09-28 03:51 ——– d—–w- c:\windows4\system32\NtmsData
2012-09-24 07:22 . 2012-09-24 07:22 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Local Settings\Application Data\Wondershare
2012-09-24 07:21 . 2012-09-24 07:21 ——– d—–w- c:\program files\Common Files\Wondershare
2012-09-24 07:20 . 2012-09-24 07:20 ——– d—–w- c:\program files\Wondershare
2012-09-22 19:21 . 2012-05-22 10:21 29056 —-a-w- c:\windows4\system32\drivers\jddrv.sys
2012-09-22 19:21 . 2012-05-22 10:21 15360 —-a-w- c:\windows4\system32\jdnat.dll
2012-09-22 19:21 . 2012-05-22 10:21 6656 —-a-w- c:\windows4\system32\jdboot.exe
2012-09-22 19:21 . 2012-05-22 10:21 16384 —-a-w- c:\windows4\system32\jddac.dll
2012-09-22 19:20 . 2012-05-29 14:54 9728 —-a-w- c:\windows4\system32\WindowsClosingService.exe
2012-09-22 19:20 . 2012-09-22 20:50 ——– d—–w- c:\program files\JetDrive
2012-09-21 21:42 . 2012-09-21 21:42 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Local Settings\Application Data\ESET
2012-09-21 21:42 . 2012-09-21 21:42 ——– d—–w- c:\documents and settings\LocalService.NT AUTHORITY.001\Local Settings\Application Data\ESET
2012-09-19 22:59 . 2012-09-19 22:59 ——– d—–w- c:\documents and settings\All Users.WINDOWS4\Application Data\ESET
2012-09-19 22:31 . 2012-09-19 22:31 ——– d—–w- c:\documents and settings\All Users.WINDOWS4\Application Data\Malwarebytes
2012-09-19 22:31 . 2012-09-19 22:31 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Application Data\Malwarebytes
2012-09-19 22:31 . 2012-09-07 14:04 22856 —-a-w- c:\windows4\system32\drivers\mbam,2.sys
2012-09-18 20:36 . 2012-09-18 20:37 102400 —-a-w- c:\windows4\RegBootClean.exe
2012-09-18 12:10 . 2012-09-18 12:10 ——– d—–w- c:\program files\Kaspersky Lab
2012-09-18 12:10 . 2012-09-18 12:10 ——– d—–w- c:\documents and settings\All Users.WINDOWS4\Application Data\Kaspersky Lab
2012-09-18 09:37 . 2012-09-19 22:59 ——– d—–w- c:\program files\ESET
2012-09-18 09:35 . 2012-06-05 07:37 256904 —-a-w- c:\windows4\system32\drivers\tmcomm.sys
2012-09-17 23:17 . 2009-06-30 08:37 28552 —-a-w- c:\windows4\system32\drivers\pavboot.sys
2012-09-17 21:41 . 2012-09-17 21:41 ——– d—–w- c:\documents and settings\All Users.WINDOWS4\Application Data\CA
2012-09-17 21:16 . 2012-09-18 09:35 ——– d—–w- c:\documents and settings\Owner.ANONYMOUS\Application Data\QuickScan
2012-09-17 20:52 . 2012-09-17 21:09 ——– d—–w- c:\documents and settings\All Users.WINDOWS4\Application Data\6C82EAA600547533B24F289B7B07D287
2012-09-10 03:37 . 2012-04-08 22:39 48128 —-a-w- c:\windows4\system32\ff_acm.acm
2012-09-10 03:37 . 2012-04-08 22:40 79360 —-a-w- c:\windows4\system32\ff_vfw.dll
2012-09-10 03:37 . 2012-09-10 03:37 ——– d—–w- c:\program files\ffdshow
2012-09-10 03:33 . 2012-09-10 03:33 ——– d—–w- c:\program files\TVersity Codec Pack
2012-09-10 03:33 . 2012-09-10 03:33 ——– d—–w- c:\program files\TVersity
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-09-17 21:14 . 2012-03-27 23:40 70344 —-a-w- c:\windows4\system32\FlashPlayerCPLApp.cpl
2012-09-17 21:14 . 2012-03-27 23:40 426184 —-a-w- c:\windows4\system32\FlashPlayerApp.exe
2012-09-07 15:04 . 2012-08-31 18:13 22856 —-a-w- c:\windows4\system32\drivers\mbam.sys
2012-08-27 01:29 . 2012-08-27 01:29 48192 —-a-w- c:\windows4\system32\drivers\KSafeDISK.sys
2012-08-27 01:29 . 2012-08-27 01:29 43584 —-a-w- c:\windows4\system32\drivers\BTOWSVF.sys
2012-08-27 01:29 . 2012-08-27 01:29 27200 —-a-w- c:\windows4\system32\drivers\BTOWSFF.sys
2012-08-03 04:02 . 2012-08-03 04:02 159608 —-a-w- c:\windows4\system32\mfevtps.exe.a8a3.deleteme
2012-07-13 05:02 . 2012-07-13 05:02 120616 —-a-w- c:\windows4\system32\drivers\PSINProt.sys
2012-07-13 05:02 . 2012-07-13 05:02 179112 —-a-w- c:\windows4\system32\drivers\PSINKNC.sys
2012-07-13 05:02 . 2012-07-13 05:02 114728 —-a-w- c:\windows4\system32\drivers\PSINProc.sys
2012-07-13 05:02 . 2012-07-13 05:02 101544 —-a-w- c:\windows4\system32\drivers\PSINFile.sys
2012-07-13 05:02 . 2012-07-13 05:02 149032 —-a-w- c:\windows4\system32\drivers\PSINAflt.sys
2012-07-12 09:18 . 2012-07-12 09:18 206632 —-a-w- c:\windows4\system32\drivers\NNSStrm.sys
.
.
——- Sigcheck ——-
Note: Unsigned files aren't necessarily malware.
.
[-] 2012-04-11 . F738697D2AA60AC4BA9B9DED1412D4B2 . 361600 . . [5.1.2600.6009] . . c:\windows4\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows4\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"PHIME2002ASync"="c:\windows4\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows4\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"CoolSwitch"="c:\windows4\system32\taskswitch.exe" [2002-03-19 45632]
"NvCplDaemon"="c:\windows4\system32\NvCpl.dll" [2006-07-12 7626752]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2012-03-07 3117344]
"ProcessLassoManagementConsole"="c:\program files\Process Lasso\processlasso.exe" [2012-09-25 938352]
"ProcessGovernor"="c:\program files\Process Lasso\processgovernor.exe" [2012-09-25 633200]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows4\system32\CTFMON.EXE" [2008-04-14 15360]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
.
c:\documents and settings\All Users.WINDOWS4\Start Menu\Programs\Startup\
Microsoft .NET Framework v4 - Slow Windows XP Boot Fix.vbs [2012-2-20 870]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"MaxRecentDocs"= 18 (0x12)
"NoSMConfigurePrograms"= 1 (0x1)
"NoRecentDocsNetHood"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS4^Start Menu^Programs^Startup^CineForm Status.lnk]
path=c:\documents and settings\All Users.WINDOWS4\Start Menu\Programs\Startup\CineForm Status.lnk
backup=c:\windows4\pss\CineForm Status.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Owner.ANONYMOUS^Start Menu^Programs^Startup^Epson printer Registration.lnk]
path=c:\documents and settings\Owner.ANONYMOUS\Start Menu\Programs\Startup\Epson printer Registration.lnk
backup=c:\windows4\pss\Epson printer Registration.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2012-07-27 20:51 919008 —-a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon]
2012-02-21 04:28 59240 —-a-w- c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2011-07-28 23:08 1259376 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DrvLsnr]
2003-05-08 10:34 69632 ——w- c:\program files\Analog Devices\SoundMAX\DrvLsnr.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\emsisoft anti-malware]
2012-09-19 03:33 3363240 —-a-w- c:\program files\Emsisoft Anti-Malware\a2guard.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Artisan 50 Series]
2008-10-09 07:00 199680 —-a-w- c:\windows4\system32\spool\drivers\w32x86\3\E_FATIFFA.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2007-05-08 14:24 54840 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KSS]
2012-04-25 17:53 202296 —-a-w- c:\program files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2012-09-07 15:04 766536 —-a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-07-12 21:19 7626752 —-a-w- c:\windows4\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-07-12 21:19 86016 —-a-w- c:\windows4\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-07-12 21:19 1519616 —-a-w- c:\windows4\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSUAMain]
2012-07-13 05:15 37152 —-a-w- c:\program files\Panda Security\Panda Cloud Antivirus\PSUAMain.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2012-04-19 03:56 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 14:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2012-01-17 16:07 252296 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ToolwizCareFree]
2012-08-27 01:29 5216848 —-a-w- c:\program files\ToolwizCareFree\ToolwizCares.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnThreat]
2012-06-11 13:28 12088920 —-a-w- c:\program files\UnThreat AntiVirus\UnThreat.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
2011-03-07 13:33 89456 —-a-w- c:\program files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Wondershare Helper Compact.exe]
2012-03-27 10:20 1686528 —-a-w- c:\program files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 BTOWSVF;BTOWSVF;c:\windows4\system32\drivers\BTOWSVF.sys [27/08/2012 3:29 AM 43584]
R0 KSafeDISK;KSafeDISK;c:\windows4\system32\drivers\KSafeDISK.sys [27/08/2012 3:29 AM 48192]
R0 mv61xxmm;mv61xxmm;c:\windows4\system32\drivers\mv61xxmm.sys [11/04/2012 5:44 PM 13616]
R0 mv64xxmm;mv64xxmm;c:\windows4\system32\drivers\mv64xxmm.sys [11/04/2012 5:44 PM 5632]
R0 mvxxmm;mvxxmm;c:\windows4\system32\drivers\mvxxmm.sys [11/04/2012 5:44 PM 13616]
R0 pavboot;pavboot;c:\windows4\system32\drivers\pavboot.sys [18/09/2012 1:17 AM 28552]
R1 A2DDA;A2 Direct Disk Access Support Driver;c:\program files\Emsisoft Anti-Malware\a2ddax86.sys [20/09/2012 10:36 AM 17904]
R1 BTOWSFF;BTOWSFF;c:\windows4\system32\drivers\BTOWSFF.sys [27/08/2012 3:29 AM 27200]
R1 ehdrv;ehdrv;c:\windows4\system32\drivers\ehdrv.sys [14/03/2012 8:40 AM 120152]
R1 epfwtdir;epfwtdir;c:\windows4\system32\drivers\epfwtdir.sys [14/03/2012 8:40 AM 104160]
R1 NNSALPC;NNSAlpc;c:\windows4\system32\drivers\NNSAlpc.sys [27/06/2012 3:51 PM 82472]
R1 NNSHTTP;NNSHttp;c:\windows4\system32\drivers\NNSHttp.sys [27/06/2012 3:51 PM 120744]
R1 NNSIDS;NNSids;c:\windows4\system32\drivers\NNSIds.sys [27/06/2012 3:51 PM 122664]
R1 NNSPICC;NNSPicc;c:\windows4\system32\drivers\NNSpicc.sys [27/06/2012 3:51 PM 93992]
R1 NNSPOP3;NNSPop3;c:\windows4\system32\drivers\NNSPop3.sys [27/06/2012 3:51 PM 104104]
R1 NNSPROT;NNSProt;c:\windows4\system32\drivers\NNSProt.sys [27/06/2012 3:51 PM 286376]
R1 NNSPRV;NNSPrv;c:\windows4\system32\drivers\NNSPrv.sys [27/06/2012 3:51 PM 153000]
R1 NNSSMTP;NNSSmtp;c:\windows4\system32\drivers\NNSSmtp.sys [27/06/2012 3:51 PM 106536]
R1 NNSSTRM;NNSStrm;c:\windows4\system32\drivers\NNSStrm.sys [12/07/2012 11:18 AM 206632]
R1 NNSTLSC;NNSTlsc;c:\windows4\system32\drivers\NNStlsc.sys [27/06/2012 3:51 PM 92840]
R1 PSINKNC;PSINKnc;c:\windows4\system32\drivers\PSINKNC.sys [13/07/2012 7:02 AM 179112]
R1 sbaphd;sbaphd;c:\windows4\system32\drivers\sbaphd.sys [01/09/2012 12:23 AM 21240]
R1 SBRE;SBRE;c:\windows4\system32\drivers\SBREDrv.sys [01/09/2012 12:23 AM 101112]
R2 a2AntiMalware;Emsisoft Anti-Malware 6.6 - Service;c:\program files\Emsisoft Anti-Malware\a2service.exe [20/09/2012 10:36 AM 3082640]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [07/03/2012 3:40 PM 913144]
R2 KSS;Kaspersky Security Scan Service;c:\program files\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [25/04/2012 7:53 PM 202296]
R2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [18/09/2012 12:26 AM 399432]
R2 NanoServiceMain;Panda Cloud Antivirus Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSANHost.exe [13/07/2012 6:57 AM 140064]
R2 PSINAflt;PSINAflt;c:\windows4\system32\drivers\PSINAflt.sys [13/07/2012 7:02 AM 149032]
R2 PSINFile;PSINFile;c:\windows4\system32\drivers\PSINFile.sys [13/07/2012 7:02 AM 101544]
R2 PSINProc;PSINProc;c:\windows4\system32\drivers\PSINProc.sys [13/07/2012 7:02 AM 114728]
R2 PSINProt;PSINProt;c:\windows4\system32\drivers\PSINProt.sys [13/07/2012 7:02 AM 120616]
R2 PSUAService;Panda Product Service;c:\program files\Panda Security\Panda Cloud Antivirus\PSUAService.exe [13/07/2012 7:15 AM 36640]
R2 rsdsys;rsd protect;c:\windows4\system32\drivers\protreg.sys [18/07/2012 12:33 AM 19712]
R2 sbapifs;sbapifs;c:\windows4\system32\drivers\sbapifs.sys [01/09/2012 12:23 AM 77816]
R2 UTSvcManager3;UnThreat Service Manager;c:\program files\UnThreat AntiVirus\utsvc.exe [01/09/2012 12:23 AM 2856024]
R3 MBAMProtector;MBAMProtector;c:\windows4\system32\drivers\mbam.sys [31/08/2012 8:13 PM 22856]
R3 PSKMAD;PSKMAD;c:\windows4\system32\drivers\PSKMAD.sys [04/10/2012 5:06 AM 46280]
S0 symmpiv;symmpiv;c:\windows4\system32\drivers\symmpiv.sys [11/04/2012 5:44 PM 86528]
S2 JetDrive WindowsClosingService;JetDrive WindowsClosingService;c:\windows4\System32\WindowsClosingService –> c:\windows4\System32\WindowsClosingService [?]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [01/03/2012 6:00 PM 676936]
S2 RsMgrSvc;Rsd Service;"c:\program files\Rising\RSD\RsMgrSvc.exe" –> c:\program files\Rising\RSD\RsMgrSvc.exe [?]
S3 a2acc;a2acc;c:\program files\Emsisoft Anti-Malware\a2accx86.sys [20/09/2012 10:36 AM 54072]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows4\system32\Macromed\Flash\FlashPlayerUpdateService.exe [28/03/2012 1:40 AM 250056]
S3 jetdrive;jddrv;c:\windows4\system32\drivers\jddrv.sys [22/09/2012 9:21 PM 29056]
S3 NNSNAHS;Network Activity Hook Server Service;c:\windows4\system32\drivers\NNSNAHS.sys [09/09/2011 1:54 PM 38536]
S3 NPF;NetGroup Packet Filter Driver;c:\windows4\system32\drivers\npf.sys [20/10/2009 8:19 PM 50704]
S3 rspSanity;rspSanity;c:\windows4\system32\drivers\rspSanity32.sys [20/07/2012 7:01 PM 27192]
S3 sbhips;sbhips;c:\windows4\system32\drivers\sbhips.sys [01/09/2012 12:23 AM 93816]
S4 NNSPIHS;NNSPihs;c:\windows4\system32\drivers\NNSpihs.sys [27/06/2012 3:51 PM 51496]
.
— Other Services/Drivers In Memory —
.
*Deregistered* - uphcleanhlp
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-09-17 c:\windows4\Tasks\Adobe Flash Player Updater.job
- c:\windows4\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-03-27 21:14]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
TCP: DhcpNameServer = 192.168.1.1
DPF: {E6BB2089-163F-466B-812A-748096614DFD} - hxxp://cainternetsecurity.net/scanner/cascanner.cab
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-33173378.sys
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-ugeci - c:\documents and settings\Owner.ANONYMOUS\Application Data\ugeci.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-04 06:32
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\JetDrive WindowsClosingService]
"ImagePath"="c:\windows4\System32\WindowsClosingService"
.
Completion time: 2012-10-04 06:36:54
ComboFix-quarantined-files.txt 2012-10-04 04:36
.
Pre-Run: 2,287,288,320 bytes free
Post-Run: 2,566,000,640 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS4
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS4="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.1="Microsoft Windows XP Professional" /3gb /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS.0="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - 6549BE6D9BF2966E16BB49494513CA38
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
———

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI