This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Unknown virus

24 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Please download Random's System Information Tool (RSIT) by random/random and save it to your Desktop.
  • Double click on RSIT.exe to run the program.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
Note: A copy of these logs will be saved to your root drive, usually C:\rsit

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


So in your next reply, please include the following logs:
  • The contents of the MBAM log
  • The contents of the two RSIT logs
Please make a separate post for each log.

Regards,
RatHat
Malwarebytes' Anti-Malware 1.31 Database version: 1612 Windows 5.1.2600 Service Pack 2 1/6/2009 12:15:35 PM mbam-log-2009-01-06 (17-42-31).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 131408 Time elapsed: 39 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091963.sys (Trojan.TDSS) -> No action taken. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091964.dll (Trojan.TDSS) -> No action taken. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091965.dll (Trojan.TDSS) -> No action taken. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091966.dll (Trojan.TDSS) -> No action taken. C:\System Volume Information\_restore{2466A83D-1B81-456E-9766-38C2B7E48210}\RP358\A0091967.dll (Trojan.TDSS) -> No action taken.
and these are the 2 rsit logs….. info.txt logfile of random's system information tool 1.05 2009-01-06 00:11:22 ======Uninstall list====== avast! Antivirus–>C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup Malwarebytes' Anti-Malware–>"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe" ======Hosts File====== 127.0.0.1 localhost 127.0.0.1 1.httpdads.com #SpySweeperCASS 127.0.0.1 207-87-18-203.wsmg.digex.net #SpySweeperCASS 127.0.0.1 a.mktw.net #SpySweeperCASS 127.0.0.1 a.tribalfusion.com #SpySweeperCASS 127.0.0.1 a207.p.f.qz3.net #SpySweeperCASS 127.0.0.1 a3.suntimes.com #SpySweeperCASS 127.0.0.1 actionsplash.com #SpySweeperCASS 127.0.0.1 ad.abcnews.com #SpySweeperCASS 127.0.0.1 ad.adsmart.net #SpySweeperCASS ======Security center information====== AV: Norton Internet Security AV: avast! antivirus 4.8.1296 [VPS 090104-0] System event log Computer Name: MAIN Event Code: 7035 Message: The avast! Web Scanner service was successfully sent a start control. Record Number: 5 Source Name: Service Control Manager Time Written: 20081120110635.000000-300 Event Type: information User: NT AUTHORITY\SYSTEM Computer Name: MAIN Event Code: 7035 Message: The avast! Mail Scanner service was successfully sent a start control. Record Number: 4 Source Name: Service Control Manager Time Written: 20081120110635.000000-300 Event Type: information User: NT AUTHORITY\SYSTEM Computer Name: MAIN Event Code: 4201 Message: The system detected that network adapter \DEVICE\TCPIP_{567A8C54-7218-4297-BDD1-E37300B9C4BF} was connected to the network, and has initiated normal operation over the network adapter. Record Number: 3 Source Name: Tcpip Time Written: 20081120110558.000000-300 Event Type: information User: Computer Name: MAIN Event Code: 6005 Message: The Event log service was started. Record Number: 2 Source Name: EventLog Time Written: 20081120110536.000000-300 Event Type: information User: Computer Name: MAIN Event Code: 6009 Message: Microsoft ® Windows ® 5.01. 2600 Service Pack 2 Uniprocessor Free. Record Number: 1 Source Name: EventLog Time Written: 20081120110536.000000-300 Event Type: information User: Application event log Computer Name: YOUR-F78BF48CE2 Event Code: 5000 Message: Record Number: 12278 Source Name: McLogEvent Time Written: 20070710132959.000000-240 Event Type: information User: NT AUTHORITY\SYSTEM Computer Name: YOUR-F78BF48CE2 Event Code: 1 Message: Application started Record Number: 12277 Source Name: ccEvtMgr Time Written: 20070710132956.000000-240 Event Type: information User: NT AUTHORITY\SYSTEM Computer Name: YOUR-F78BF48CE2 Event Code: 26 Message: Application starting Record Number: 12276 Source Name: ccEvtMgr Time Written: 20070710132955.000000-240 Event Type: information User: NT AUTHORITY\SYSTEM Computer Name: YOUR-F78BF48CE2 Event Code: 1 Message: Application started Record Number: 12275 Source Name: ccSetMgr Time Written: 20070710132955.000000-240 Event Type: information User: NT AUTHORITY\SYSTEM Computer Name: YOUR-F78BF48CE2 Event Code: 26 Message: Application starting Record Number: 12274 Source Name: ccSetMgr Time Written: 20070710132955.000000-240 Event Type: information User: NT AUTHORITY\SYSTEM ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;c:\Python22 "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 28 Stepping 0, AuthenticAMD "PROCESSOR_REVISION"=1c00 "NUMBER_OF_PROCESSORS"=1 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "SonicCentral"=c:\Program Files\Common Files\Sonic Shared\Sonic Central\ —————–EOF—————– Logfile of random's system information tool 1.05 (written by random/random) Run by [removed] at 2009-01-06 00:11:15 Microsoft Windows XP Home Edition Service Pack 2 System drive C: has 59 GB (40%) free of 146 GB Total RAM: 383 MB (35% free) HijackThis download failed ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "SiSPower"=C:\WINDOWS\system32\SiSPower.dll [2005-04-12 49152] "ccApp"=c:\Program Files\Common Files\Symantec Shared\ccApp.exe [2004-08-27 58488] "HPBootOp"=C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe [2005-02-26 245760] "SMSERIAL"=C:\WINDOWS\sm56hlpr.exe [2005-01-24 544768] "LSBWatcher"=c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe [2004-10-14 253952] "AlcxMonitor"=C:\WINDOWS\ALCXMNTR.EXE [2004-09-07 57344] "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000] "ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-28 221184] "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-12-16 282624] "SpySweeper"=C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2006-01-25 3405312] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "PeerGuardian"=C:\Program Files\PeerGuardian2\pg2.exe [2005-09-18 1421824] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dvd43] C:\Program Files\dvd43\dvd43_tray.exe [2007-11-20 731136] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-07-28 221184] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Program Files\QuickTime\qttask.exe [2006-12-16 282624] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Compaq Connections.lnk] C:\PROGRA~1\COMPAQ~1\6750491\Program\COMPAQ~1.EXE [2005-05-16 45056] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HOTSYNCSHORTCUTNAME.lnk] C:\PROGRA~1\Palm\Hotsync.exe [2004-06-09 471040] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier] C:\WINDOWS\system32\WRLogonNTF.dll [2006-01-25 492544] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2004-08-04 239616] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\svcWRSSSDK] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\svcWRSSSDK] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=323 "NoDriveAutoRun"=67108863 "NoDrives"=0 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveAutoRun"= "NoDriveTypeAutoRun"= "NoDrives"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe"="C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe:*:Enabled:BackWeb for Presario" "C:\Program Files\Total War\Medieval - Total War\Medieval_TW.exe"="C:\Program Files\Total War\Medieval - Total War\Medieval_TW.exe:*:Enabled:Medieval_TW" "C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader" "C:\Program Files\GigaTribe\gigatribe.exe"="C:\Program Files\GigaTribe\gigatribe.exe:*:Enabled:gigatribe" "C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath " [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%ProgramFiles%\iTunes\iTunes.exe"="%ProgramFiles%\iTunes\iTunes.exe:*:enabled:iTunes" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D] shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 ======List of files/folders created in the last 1 months====== 2009-01-06 00:11:17 —-D—- C:\Program Files\trend micro 2009-01-06 00:11:15 —-D—- C:\rsit 2009-01-04 14:38:59 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\Malwarebytes 2009-01-04 14:38:39 —-D—- C:\Program Files\Malwarebytes' Anti-Malware 2009-01-04 14:38:39 —-D—- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-01-04 12:17:31 —-A—- C:\WINDOWS\zip.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\VFIND.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\SWXCACLS.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\SWSC.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\SWREG.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\sed.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\NIRCMD.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\grep.exe 2009-01-04 12:17:31 —-A—- C:\WINDOWS\fdsv.exe 2009-01-04 12:14:25 —-D—- C:\WINDOWS\ERDNT 2009-01-04 12:14:25 —-AD—- C:\Qoobox 2009-01-04 10:34:34 —-A—- C:\WINDOWS\gmer_uninstall.cmd 2009-01-04 10:34:34 —-A—- C:\WINDOWS\gmer.exe 2009-01-04 10:34:34 —-A—- C:\WINDOWS\gmer.dll 2008-12-26 12:33:28 —-HDC—- C:\WINDOWS\$NtUninstallKB960714$ 2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\wrlzma.dll 2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\WRLogonNtf.dll 2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\ssiefr.EXE 2008-12-16 23:06:14 —-A—- C:\WINDOWS\system32\islzma.dll 2008-12-16 23:06:11 —-D—- C:\Program Files\Webroot 2008-12-16 23:06:11 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\Webroot 2008-12-10 22:29:16 —-HDC—- C:\WINDOWS\$NtUninstallKB952069_WM9$ 2008-12-10 22:29:12 —-HDC—- C:\WINDOWS\$NtUninstallKB955839$ 2008-12-10 22:28:58 —-HDC—- C:\WINDOWS\$NtUninstallKB958215$ 2008-12-10 22:27:28 —-HDC—- C:\WINDOWS\$NtUninstallKB954600$ 2008-12-10 22:27:20 —-HDC—- C:\WINDOWS\$NtUninstallKB956802$ ======List of files/folders modified in the last 1 months====== 2009-01-06 00:11:17 —-D—- C:\Program Files 2009-01-06 00:10:13 —-D—- C:\Program Files\PeerGuardian2 2009-01-05 16:35:38 —-D—- C:\WINDOWS\Prefetch 2009-01-05 13:01:37 —-D—- C:\WINDOWS\system32\FxsTmp 2009-01-05 12:39:53 —-D—- C:\WINDOWS\Temp 2009-01-05 11:41:05 —-D—- C:\WINDOWS 2009-01-04 19:29:22 —-A—- C:\WINDOWS\Apollo DVD Copy.INI 2009-01-04 17:45:59 —-D—- C:\WINDOWS\system32\drivers 2009-01-04 17:45:32 —-A—- C:\WINDOWS\SchedLgU.Txt 2009-01-04 16:22:51 —-D—- C:\Program Files\Mozilla Thunderbird 2009-01-04 16:21:29 —-D—- C:\WINDOWS\Minidump 2009-01-04 14:10:40 —-D—- C:\WINDOWS\system32 2009-01-04 14:09:19 —-A—- C:\WINDOWS\system.ini 2009-01-04 14:08:45 —-D—- C:\WINDOWS\AppPatch 2009-01-04 14:08:45 —-D—- C:\Program Files\Common Files 2009-01-03 23:33:49 —-D—- C:\QUARANTINE 2009-01-03 20:59:32 —-D—- C:\Program Files\Mozilla Firefox 2009-01-02 16:23:03 —-D—- C:\Documents and Settings 2009-01-02 14:57:50 —-RSHD—- C:\WINDOWS\system32\dllcache 2009-01-02 14:57:48 —-D—- C:\WINDOWS\Help 2009-01-02 14:25:13 —-D—- C:\WINDOWS\system32\CatRoot2 2009-01-02 14:09:11 —-HD—- C:\system.sav 2009-01-01 19:55:02 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\OpenOffice.org2 2008-12-26 12:33:36 —-HD—- C:\WINDOWS\inf 2008-12-26 12:33:18 —-HD—- C:\WINDOWS\$hf_mig$ 2008-12-16 23:07:31 —-D—- C:\WINDOWS\Debug 2008-12-15 13:15:33 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\U3 2008-12-12 12:27:54 —-A—- C:\WINDOWS\system32\mshtml.dll 2008-12-10 22:29:04 —-D—- C:\Program Files\Internet Explorer 2008-12-09 18:24:37 —-A—- C:\WINDOWS\system32\MRT.exe 2008-12-07 19:20:26 —-D—- C:\Documents and Settings\Compaq_Owner\Application Data\Real ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-26 26944] R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352] R1 ASPI32;ASPI32; C:\WINDOWS\system32\drivers\ASPI32.sys [2005-12-30 25244] R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-26 111184] R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-26 50864] R1 SiSkp;SiSkp; C:\WINDOWS\system32\DRIVERS\srvkp.sys [2005-04-12 11904] R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2004-08-27 266464] R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560] R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-26 94032] R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2005-04-20 2317696] R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800] R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-26 23152] R3 dvd43llh;dvd43llh; C:\WINDOWS\System32\DRIVERS\dvd43llh.sys [2007-12-31 18816] R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128] R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824] R3 Pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\Pcouffin.sys [2008-05-15 47360] R3 pgfilter;pgfilter; \??\C:\Program Files\PeerGuardian2\pgfilter.sys [] R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2002-07-29 23808] R3 SiS315;SiS315; C:\WINDOWS\system32\DRIVERS\sisgrp.sys [2005-04-12 247296] R3 SISNIC;SiS PCI Fast Ethernet Adapter Driver; C:\WINDOWS\system32\DRIVERS\sisnic.sys [2003-07-11 32768] R3 smserial;smserial; C:\WINDOWS\system32\DRIVERS\smserial.sys [2005-01-25 923863] R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS [] R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624] R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600] R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024] R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496] S1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [] S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2009-01-04 85969] S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600] S3 PalmUSBD;PalmUSBD; C:\WINDOWS\system32\drivers\PalmUSBD.sys [] S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992] S3 SPBBCDrv;SPBBCDrv; \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys [] S3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2004-08-27 25824] S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264] S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616] S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480] S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-04 5504] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752] R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160] R2 ccEvtMgr;Symantec Event Manager; c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2004-08-27 197752] R2 ccSetMgr;Symantec Settings Manager; c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2004-08-27 164984] R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120] R2 svcWRSSSDK;Webroot Spy Sweeper Engine; C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe [2006-01-25 2161152] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912] R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040] R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768] S3 ccPwdSvc;Symantec Password Validation; c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2004-08-27 78968] S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 MSCSPTISRV;MSCSPTISRV; C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe [2006-04-27 53337] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 PACSPTISVR;PACSPTISVR; C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe [2006-04-27 49241] S3 SNDSrvc;Symantec Network Drivers Service; c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2004-08-27 206048] S3 SPBBCSvc;Symantec SPBBCSvc; c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe [2004-07-21 173160] S3 SPTISRV;Sony SPTI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe [2006-04-27 69718] S3 SSScsiSV;SonicStage SCSI Service; C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe [2006-05-08 69632] —————–EOF—————–
OK, lets go about this a different way.

Download OTScanIt.exe to your Desktop and double-click on it to extract the files. It will create a folder named OTScanIt on your desktop.
  • Close ALL OTHER PROGRAMS.
  • Open the OTScanIt folder and double-click on OTScanIt.exe to start the program.
  • Check the box that says Scan All User Accounts
  • Check the Radio buttons for Files/Folders Created Within 90 Days and Files/Folders Modified Within 90 Days
  • Check the Radio button under Drivers for Non Microsoft
  • Check the radio button under Rootkit Search for Yes
  • Under Additional Scans check the following:
    • Reg - App Paths
    • Reg - Approved Shell Extensions
    • Reg - BotCheck
    • Reg - ControlSets
    • Reg - Desktop Components
    • Reg - Disabled MS Config Items
    • Reg - File Associations
    • Reg - NeverShowExt Settings
    • Reg - Software Policy Settings
    • Reg - Uninstall List
    • File - Additional Folder Scans
    • File - Lop Check
    • File - Purity Scan
    • Evnt - EventViewer Errors/Warnings (last 7 days)
  • Now click the Run Scan button on the toolbar.
  • Let it run unhindered until it finishes.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Click the Format menu and make sure that Wordwrap is not checked. If it is then click on it to uncheck it.

Please zip the log and attach the zipped file in your next post.

To attach a file, do the following:
  • Click Add Reply
  • Under the reply panel is the Attachments Panel
  • Browse for the attachment file you want to upload, then click the green Upload button
  • Once it has uploaded, click the Manage Current Attachments drop down box
  • Click on [external image: Posted Image] to insert the attachment into your post
is there another link to OTScanIt.exe? the link brings up a "404-Not Found" error. I did a search for it but couldn't come up with a working link there either.
Start OTScanIt2.exe Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Kill Explorer]
[Processes - Safe List]
YY -> ccapp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe
YY -> ccevtmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe
YY -> ccsetmgr.exe -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe
[Win32 Services - Safe List]
YY -> (ccEvtMgr) Symantec Event Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccEvtMgr.exe
YY -> (ccPwdSvc) Symantec Password Validation [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\Symantec Shared\ccPwdSvc.exe
YY -> (ccSetMgr) Symantec Settings Manager [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Symantec Shared\ccSetMgr.exe
[Registry - Additional Scans - Safe List]
< App Paths [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\
YY -> ccApp.exe -> %CommonProgramFiles%\Symantec Shared\ccApp.exe [c:\Program Files\Common Files\Symantec Shared\ccApp.exe]
YN -> MsoHtmEd.exe -> Reg Error: Value  does not exist or could not be read. [Reg Error: Value  does not exist or could not be read.]
YN -> setup.exe -> Reg Error: Value  does not exist or could not be read. [Reg Error: Value  does not exist or could not be read.]
[Files/Folders - Created Within 90 Days]
NY -> 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> wrlzma.dll -> %SystemRoot%\System32\wrlzma.dll
[Files/Folders - Modified Within 90 Days]
NY -> 1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> 2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
[Alternate Data Streams]
NY -> @Alternate Data Stream - 113 bytes -> %AllUsersProfile%\Application Data\TEMP:7715B65F
[CatchMe Rootkit Scan by GMER]
NY -> C:\Documents and Settings\All Users\Application Data\TEMP:7715B65F 113 bytes -> 
[Purity]
[Empty Temp Folders]
[Start Explorer]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Save that information to your desktop, then Reboot your computer. Post that information back here along with a new OTScanIt scan taken after the reboot, and using the same settings as before.

Let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
Can you tell me if the version of Windows you have has ever been reinstalled onto this machine, after installation of other programs.

The OTScanIt log is still showing a trace of the TDSS rootkit in your registry, so I want to see if we can remove that.

Download the attached zip file: 📎junior2.zip

Unzip it to a new folder on your desktop.

Open the folder and double click reset.cmd to run the script.

A command window will open very briefly, then close. When it has closed, Reboot your computer.

Post me a new OTScanIt log using the same settings as you did last time in your next reply.
Please copy the entire contents of the codebox below into Notepad:
  • Open Notepad
  • Copy the contents of the codebox below using CTRL C

@echo off
SWREG ACL HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys /GA:F
SWREG DELETE "HKLM\SYSTEM\ControlSet001\Services\TDSSserv.sys" > results.txt
start notepad results.txt
  • Now return to Notepad and use CTRL V to paste the script
  • Verify that you have pasted the complete script, starting with @echo off
  • Save the Notepad file into the same folder that you unzipped reset.cmd and swreg.exe, as Script.cmd using Save as Type: All files
  • Open the folder, and locate Script.cmd
  • Double click to run.
When done it will open a text file, please post me the contents of that file.
OK, that is a good sign. How is the machine doing now, can you give me an update.

Please click here to download AVP Tool by Kaspersky.
  • Save it to your desktop.
  • Reboot your computer into SafeMode.

    You can do this by restarting your computer and continually tapping the F8 key until a menu appears.
    Use your up arrow key to highlight SafeMode then hit enter
    .

  • Double click the setup file to run it.
  • Click Next to continue.
  • It will by default install it to your desktop folder.Click Next.
  • Hit ok at the prompt for scanning in Safe Mode.
  • It will then open a box There will be a tab that says Automatic scan.
  • Under Automatic scan make sure these are checked.

  • System Memory
  • Startup Objects
  • Disk Boot Sectors.
  • My Computer.
  • Also any other drives (Removable that you may have)


After that click on Security level then choose Customize then click on the tab that says Heuristic Analyzer then choose Enable Deep rootkit search then choose ok.
Then choose OK again then you are back to the main screen.

  • Then click on Scan at the to right hand Corner.
  • It will automatically Neutralize any objects found.
  • If some objects are left un-neutralized then click the button that says Neutralize all
  • If it says it cannot be Neutralized then chooose The delete option when prompted.
  • After that is done click on the reports button at the bottom and save it to file name it Kas.
  • Save it somewhere convenient like your desktop and just post only the detected Virus\malware in the report it will be at the very top under Detected post those results in your next reply.

    Note: This tool will self uninstall when you close it so please save the log before closing it.

I did scan and saved the log to the desktop but when I opened it, the log was blank. Is that normal or did I do something wrong? It did find a trojan downloader which was successfully neutralized.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI