Please download
Malwarebytes' Anti-Malware from
Here or
Here
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware , then click Finish. If an update is found, it will download and install the latest version. Once the program has loaded, select "Perform Quick Scan ", then click Scan . The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked , and click Remove Selected . When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download
Random's System Information Tool (RSIT) by
random/random and save it to your
Desktop .
Double click on RSIT.exe to run the program. Click Continue at the disclaimer screen. Once it has finished, two logs will open. Please post the contents of both log.txt (<< will be maximized) and info.txt (<< will be minimized)
Note: A copy of these logs will be saved to your root drive, usually
C:\rsit
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
So in your next reply, please include the following logs:
The contents of the MBAM log The contents of the two RSIT logs
Please make a separate post for each log.
Regards,
RatHat
Malwarebytes' Anti-Malware 1.31
Database version: 1612
Windows 5.1.2600 Service Pack 2
1/6/2009 12:15:35 PM
mbam-log-2009-01-06 (17-42-31).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 131408
Time elapsed: 39 minute(s), 28 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 5
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091963.sys (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091964.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091965.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091966.dll (Trojan.TDSS) -> No action taken.
C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091967.dll (Trojan.TDSS) -> No action taken.
and these are the 2 rsit logs…..
info.txt logfile of random's system information tool 1.05 2009-01-06 00:11:22
======Uninstall list======
avast! Antivirus–>C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
======Hosts File======
127.0.0.1 localhost
127.0.0.1 1.httpdads.com #SpySweeperCASS
127.0.0.1 207-87-18-203.wsmg.digex.net #SpySweeperCASS
127.0.0.1 a.mktw.net #SpySweeperCASS
127.0.0.1 a.tribalfusion.com #SpySweeperCASS
127.0.0.1 a207.p.f.qz3.net #SpySweeperCASS
127.0.0.1 a3.suntimes.com #SpySweeperCASS
127.0.0.1 actionsplash.com #SpySweeperCASS
127.0.0.1 ad.abcnews.com #SpySweeperCASS
127.0.0.1 ad.adsmart.net #SpySweeperCASS
======Security center information======
AV: Norton Internet Security
AV: avast! antivirus 4.8.1296 [VPS 090104-0]
System event log
Computer Name: MAIN
Event Code: 7035
Message: The avast! Web Scanner service was successfully sent a start control.
Record Number: 5
Source Name: Service Control Manager
Time Written: 20081120110635.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: MAIN
Event Code: 7035
Message: The avast! Mail Scanner service was successfully sent a start control.
Record Number: 4
Source Name: Service Control Manager
Time Written: 20081120110635.000000-300
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: MAIN
Event Code: 4201
Message: The system detected that network adapter \DEVICE\TCPIP_{567A8C54-7218-4297-BDD1-E37300B9C4BF} was connected to the network,
and has initiated normal operation over the network adapter.
Record Number: 3
Source Name: Tcpip
Time Written: 20081120110558.000000-300
Event Type: information
User:
Computer Name: MAIN
Event Code: 6005
Message: The Event log service was started.
Record Number: 2
Source Name: EventLog
Time Written: 20081120110536.000000-300
Event Type: information
User:
Computer Name: MAIN
Event Code: 6009
Message: Microsoft ® Windows ® 5.01. 2600 Service Pack 2 Uniprocessor Free.
Record Number: 1
Source Name: EventLog
Time Written: 20081120110536.000000-300
Event Type: information
User:
Application event log
Computer Name: YOUR-F78BF48CE2
Event Code: 5000
Message:
Record Number: 12278
Source Name: McLogEvent
Time Written: 20070710132959.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: YOUR-F78BF48CE2
Event Code: 1
Message: Application started
Record Number: 12277
Source Name: ccEvtMgr
Time Written: 20070710132956.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: YOUR-F78BF48CE2
Event Code: 26
Message: Application starting
Record Number: 12276
Source Name: ccEvtMgr
Time Written: 20070710132955.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: YOUR-F78BF48CE2
Event Code: 1
Message: Application started
Record Number: 12275
Source Name: ccSetMgr
Time Written: 20070710132955.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM
Computer Name: YOUR-F78BF48CE2
Event Code: 26
Message: Application starting
Record Number: 12274
Source Name: ccSetMgr
Time Written: 20070710132955.000000-240
Event Type: information
User: NT AUTHORITY\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;c:\Python22
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 28 Stepping 0, AuthenticAMD
"PROCESSOR_REVISION"=1c00
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"SonicCentral"=c:\Program Files\Common Files\Sonic Shared\Sonic Central\
—————–EOF—————–
Logfile of random's system information tool 1.05 (written by random/random)
Run by [removed] at 2009-01-06 00:11:15
Microsoft Windows XP Home Edition Service Pack 2
System drive C: has 59 GB (40%) free of 146 GB
Total RAM: 383 MB (35% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SiSPower"=C:\WINDOWS\system32\SiSPower.dll [2005-04-12 49152]
"ccApp"=c:\Program Files\Common Files\Symantec Shared\ccApp.exe [2004-08-27 58488]
"HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2005-02-26 245760]
"SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2005-01-24 544768]
"LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2004-10-14 253952]
"AlcxMonitor"=C:\WINDOWS\ALCXMNTR.EXE [2004-09-07 57344]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-28 221184]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-12-16 282624]
"SpySweeper"=C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2006-01-25 3405312]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43]
C:\Program Files\dvd43\dvd43_tray.exe [2007-11-20 731136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-28 221184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-12-16 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk]
C:\PROGRA~1\COMPAQ~1\6750491\Program\COMPAQ~1.EXE [2005-05-16 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk]
C:\PROGRA~1\Palm\Hotsync.exe [2004-06-09 471040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
C:\WINDOWS\system32\WRLogonNTF.dll [2006-01-25 492544]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-04 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\svcWRSSSDK]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe"="C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe:*:Enabled:BackWeb for Presario"
"C:\Program Files\Total War\Medieval - Total War\Medieval_TW.exe"="C:\Program Files\Total War\Medieval - Total War\Medieval_TW.exe:*:Enabled:Medieval_TW"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\GigaTribe\gigatribe.exe"="C:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480
======List of files/folders created in the last 1 months======
2009-01-06 00:11:17 —-D—- C:\Program Files\trend micro
2009-01-06 00:11:15 —-D—- C:\rsit
2009-01-04 14:38:59 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes
2009-01-04 14:38:39 —-D—- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-04 14:38:39 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-04 12:17:31 —-A—- C:\WINDOWS\zip.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\VFIND.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\SWXCACLS.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\SWSC.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\SWREG.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\sed.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\NIRCMD.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\grep.exe
2009-01-04 12:17:31 —-A—- C:\WINDOWS\fdsv.exe
2009-01-04 12:14:25 —-D—- C:\WINDOWS\ERDNT
2009-01-04 12:14:25 —-AD—- C:\Qoobox
2009-01-04 10:34:34 —-A—- C:\WINDOWS\gmer_uninstall.cmd
2009-01-04 10:34:34 —-A—- C:\WINDOWS\gmer.exe
2009-01-04 10:34:34 —-A—- C:\WINDOWS\gmer.dll
2008-12-26 12:33:28 —-HDC—- C:\WINDOWS\$NtUninstallKB960714$
2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\wrlzma.dll
2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\WRLogonNtf.dll
2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\ssiefr.EXE
2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\islzma.dll
2008-12-16 23:06:11 —-D—- C:\Program Files\Webroot
2008-12-16 23:06:11 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\Webroot
2008-12-10 22:29:16 —-HDC—- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-10 22:29:12 —-HDC—- C:\WINDOWS\$NtUninstallKB955839$
2008-12-10 22:28:58 —-HDC—- C:\WINDOWS\$NtUninstallKB958215$
2008-12-10 22:27:28 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$
2008-12-10 22:27:20 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$
======List of files/folders modified in the last 1 months======
2009-01-06 00:11:17 —-D—- C:\Program Files
2009-01-06 00:10:13 —-D—- C:\Program Files\PeerGuardian2
2009-01-05 16:35:38 —-D—- C:\WINDOWS\Prefetch
2009-01-05 13:01:37 —-D—- C:\WINDOWS\system32\FxsTmp
2009-01-05 12:39:53 —-D—- C:\WINDOWS\Temp
2009-01-05 11:41:05 —-D—- C:\WINDOWS
2009-01-04 19:29:22 —-A—- C:\WINDOWS\Apollo DVD Copy.INI
2009-01-04 17:45:59 —-D—- C:\WINDOWS\system32\drivers
2009-01-04 17:45:32 —-A—- C:\WINDOWS\SchedLgU.Txt
2009-01-04 16:22:51 —-D—- C:\Program Files\Mozilla Thunderbird
2009-01-04 16:21:29 —-D—- C:\WINDOWS\Minidump
2009-01-04 14:10:40 —-D—- C:\WINDOWS\system32
2009-01-04 14:09:19 —-A—- C:\WINDOWS\system.ini
2009-01-04 14:08:45 —-D—- C:\WINDOWS\AppPatch
2009-01-04 14:08:45 —-D—- C:\Program Files\Common Files
2009-01-03 23:33:49 —-D—- C:\QUARANTINE
2009-01-03 20:59:32 —-D—- C:\Program Files\Mozilla Firefox
2009-01-02 16:23:03 —-D—- C:\Documents and Settings
2009-01-02 14:57:50 —-RSHD—- C:\WINDOWS\system32\dllcache
2009-01-02 14:57:48 —-D—- C:\WINDOWS\Help
2009-01-02 14:25:13 —-D—- C:\WINDOWS\system32\CatRoot2
2009-01-02 14:09:11 —-HD—- C:\system.sav
2009-01-01 19:55:02 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\OpenOffice.org2
2008-12-26 12:33:36 —-HD—- C:\WINDOWS\inf
2008-12-26 12:33:18 —-HD—- C:\WINDOWS\$hf_mig$
2008-12-16 23:07:31 —-D—- C:\WINDOWS\Debug
2008-12-15 13:15:33 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\U3
2008-12-12 12:27:54 —-A—- C:\WINDOWS\system32\mshtml.dll
2008-12-10 22:29:04 —-D—- C:\Program Files\Internet Explorer
2008-12-09 18:24:37 —-A—- C:\WINDOWS\system32\MRT.exe
2008-12-07 19:20:26 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\Real
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-26 26944]
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2005-12-30 25244]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-26 111184]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-26 50864]
R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2005-04-12 11904]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2004-08-27 266464]
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-26 94032]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-20 2317696]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-26 23152]
R3 dvd43llh;dvd43llh; C:\WINDOWS\System32\DRIVERS\dvd43llh.sys [2007-12-31 18816]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 Pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\Pcouffin.sys [2008-05-15 47360]
R3 pgfilter;pgfilter; \??\C:\Program Files\PeerGuardian2\pgfilter.sys []
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808]
R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2005-04-12 247296]
R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2003-07-11 32768]
R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-01-25 923863]
R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys []
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2009-01-04 85969]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 PalmUSBD;PalmUSBD; C:\WINDOWS\system32\drivers\PalmUSBD.sys []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys []
S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2004-08-27 25824]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-04 5504]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160]
R2 ccEvtMgr;Symantec Event Manager; c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2004-08-27 197752]
R2 ccSetMgr;Symantec Settings Manager; c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2004-08-27 164984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
R2 svcWRSSSDK;Webroot Spy Sweeper Engine; C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe [2006-01-25 2161152]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 ccPwdSvc;Symantec Password Validation; c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2004-08-27 78968]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [2006-04-27 53337]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2006-04-27 49241]
S3 SNDSrvc;Symantec Network Drivers Service; c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2004-08-27 206048]
S3 SPBBCSvc;Symantec SPBBCSvc; c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2004-07-21 173160]
S3 SPTISRV;Sony SPTI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [2006-04-27 69718]
S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [2006-05-08 69632]
—————–EOF—————–
OK, lets go about this a different way.
Download
OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named
OTScanIt on your desktop.
Close ALL OTHER PROGRAMS . Open the OTScanIt folder and double-click on OTScanIt.exe to start the program. Check the box that says Scan All User Accounts Check the Radio buttons for Files/Folders Created Within 90 Days and Files/Folders Modified Within 90 Days Check the Radio button under Drivers for Non Microsoft Check the radio button under Rootkit Search for Yes Under Additional Scans check the following:Reg - App Paths Reg - Approved Shell Extensions Reg - BotCheck Reg - ControlSets Reg - Desktop Components Reg - Disabled MS Config Items Reg - File Associations Reg - NeverShowExt Settings Reg - Software Policy Settings Reg - Uninstall List File - Additional Folder Scans File - Lop Check File - Purity Scan Evnt - EventViewer Errors/Warnings (last 7 days) Now click the Run Scan button on the toolbar. Let it run unhindered until it finishes. When the scan is complete Notepad will open with the report file loaded in it. Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.
Please
zip the log and
attach the zipped file in your next post.
To attach a file, do the following:
Click Add Reply Under the reply panel is the Attachments Panel Browse for the attachment file you want to upload, then click the green Upload button Once it has uploaded, click the Manage Current Attachments drop down box Click on [external image: Posted Image] to insert the attachment into your post
is there another link to OTScanIt.exe? the link brings up a "404-Not Found" error. I did a search for it but couldn't come up with a working link there either.
Yes, please download OTScanIt from
here or
here
📎 OTScanIt.zip
I wasn't given an option for "non microsoft" under drivers. It also didn't have "additional folder scans". Not sure if it was an older version or just me.
Start OTScanIt2.exe Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the
Run Fix button.
[Kill Explorer]
[Processes - Safe List]
YY -> ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe
YY -> ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe
YY -> ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe
[Win32 Services - Safe List]
YY -> (ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe
YY -> (ccPwdSvc) Symantec Password Validation [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\ccPwdSvc.exe
YY -> (ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe
[Registry - Additional Scans - Safe List]
< App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
YY -> ccApp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe [c:\Program Files\Common Files\Symantec Shared\ccApp.exe]
YN -> MsoHtmEd.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.]
YN -> setup.exe -> Reg Error: Value does not exist or could not be read. [Reg Error: Value does not exist or could not be read.]
[Files/Folders - Created Within 90 Days]
NY -> 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> wrlzma.dll -> %SystemRoot%\System32\wrlzma.dll
[Files/Folders - Modified Within 90 Days]
NY -> 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
[Alternate Data Streams]
NY -> @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:7715B65F
[CatchMe Rootkit Scan by GMER]
NY -> C:\Documents and Settings\All Users\Application Data\TEMP:7715B65F 113 bytes ->
[Purity]
[Empty Temp Folders]
[Start Explorer]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the
Ok button and Notepad will open with a log of actions taken during the fix. Save that information to your desktop, then
Reboot your computer. Post that information back here along with a new OTScanIt scan taken after the reboot, and using the same settings as before.
Let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
📎 01082009_114827.zip
i'm still having some problems with my add/delete programs function. it will show me the list of programs but won't give me any options for them.
Can you tell me if the version of Windows you have has ever been reinstalled onto this machine, after installation of other programs.
The OTScanIt log is still showing a trace of the TDSS rootkit in your registry, so I want to see if we can remove that.
Download the attached zip file:
📎 junior2.zip
Unzip it to a new folder on your desktop.
Open the folder and double click
reset.cmd to run the script.
A command window will open very briefly, then close. When it has closed,
Reboot your computer .
Post me a new OTScanIt log using the same settings as you did last time in your next reply.
No windows have never been reinstalled. It still has the factory install.
📎 OTScanIt..zip
Please copy the entire contents of the codebox below into Notepad:
Open Notepad Copy the contents of the codebox below using CTRL C
@echo off
SWREG ACL HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys /GA:F
SWREG DELETE "HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys" > results.txt
start notepad results.txt Now return to Notepad and use CTRL V to paste the script Verify that you have pasted the complete script, starting with @echo off Save the Notepad file into the same folder that you unzipped reset.cmd and swreg.exe, as Script.cmd using Save as Type: All files Open the folder, and locate Script.cmd Double click to run.
When done it will open a text file, please post me the contents of that file.
This was all it said…
Error: Key: system\controlset001\services\tdssserv.sys does not exist!
OK, that is a good sign. How is the machine doing now, can you give me an update.
Please click
here to download AVP Tool by Kaspersky.
Save it to your desktop. Reboot your computer into SafeMode.
You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter .
Double click the setup file to run it. Click Next to continue. It will by default install it to your desktop folder.Click Next. Hit ok at the prompt for scanning in Safe Mode. It will then open a box There will be a tab that says Automatic scan. Under Automatic scan make sure these are checked.
System Memory Startup Objects Disk Boot Sectors. My Computer. Also any other drives (Removable that you may have)
After that click on
Security level then choose
Customize then click on the tab that says
Heuristic Analyzer then choose
Enable Deep rootkit search then choose
ok .
Then choose OK again then you are back to the main screen.
Then click on Scan at the to right hand Corner. It will automatically Neutralize any objects found. If some objects are left un-neutralized then click the button that says Neutralize all If it says it cannot be Neutralized then chooose The delete option when prompted. After that is done click on the reports button at the bottom and save it to file name it Kas . Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.
Note: This tool will self uninstall when you close it so please save the log before closing it.
I did scan and saved the log to the desktop but when I opened it, the log was blank. Is that normal or did I do something wrong? It did find a trojan downloader which was successfully neutralized.