Jump to content

System clean...but not.


Recommended Posts

I recently got malware on my computer and was told to come here. I have downloaded your program and installed AVG and updated both. Both found and removed threats but they didnt get them all. i read around in your forums and deleted my restore points, and I ran ATF Cleaner for both IE 8 and Firefox.

my problem is that on occasion 1/4 internet links or searches i perform get "redirected" to adds or what assuming is spyware?

The most common redirects are to:

7newsdaily.net

InfoSmash (which I thought I killed days ago but its back).

I tried to use combo fix (yes I downloaded it as the changed name as instructed in a guide) but even after disabling AVG 2011 for 15 mins it would not run and warned me against using it and closes. Was hoping you guys/gals could hep me out? What do you need from me?

Link to post
Share on other sites

I disabled AVG for 15 minutes and ran DDS.scr. It does not produce any txt files nor does it make any progress after 13 minutes. It just stays open. On a side note I ran Stopzilla and it found 97 threats and they were all named or partly named like the sites I have been redirected to. Problem is to "remove" the threats I would have to pay $30.00. That just feels to much like a coincidence...or im just overly paranoid.

Rootkit Unhooker link times out. I found the software through another avenue but im not sure its what you want me to use I think its an older version and if I try to update it it also times out. Its version 3.7.300.509 . I ran DDS.scr in safe mode not sure if that even makes this useful to you or not:

DDS (Ver_10-11-05.01) - NTFSx86 NETWORK

Run by Brandon at 20:42:37.84 on Sat 11/06/2010

Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.3050 [GMT -7:00]

AV: AVG Anti-Virus Free Edition 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

AV: Smart Engine *On-access scanning enabled* (Updated) {C6856A51-15AC-4A45-9CF4-8BD4DACC4579}

FW: Smart Engine *enabled* {DCA89C9F-3B77-47B5-A946-56435694E95D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Documents and Settings\Brandon\Desktop\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyServer = http=127.0.0.1:25471

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: STOPzilla Browser Helper Object: {e3215f20-3212-11d6-9f8b-00d0b743919d} - c:\program files\stopzilla!\SZIEBHO.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File

uRun: [sansaDispatch] c:\documents and settings\brandon\application data\sandisk\sansa updater\SansaDispatch.exe

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [CTHelper] CTHELPER.EXE

mRun: [CTxfiHlp] CTXFIHLP.EXE

mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

mRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"

mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe

dRunOnce: [setDefaultMIDI] MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'

StartupFolder: c:\docume~1\brandon\startm~1\programs\startup\impuls~1.lnk - c:\program files\stardock\impulse\now\ImpulseNow.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wincin~1.lnk - c:\program files\sandisk\common\bin\WinCinemaMgr.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\belkin~1.lnk - c:\program files\belkin\f6d4050\v1\Belkinwcui.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wusb600n\WUSB600N.exe

uPolicies-explorer: DisallowRun = 1 (0x1)

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL

DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15031/CTSUEng.cab

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200274786326

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15034/CTPID.cab

Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

IFEO: image file execution options - svchost.exe

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\brandon\applic~1\mozilla\firefox\profiles\ce3j9wen.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/

FF - component: c:\program files\avg\avg10\firefox\components\avgssff.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll

FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll

FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----

c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]

R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]

R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2009-12-7 61328]

R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2010-2-24 173328]

R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-9-7 298448]

R3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-12-14 551680]

S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2009-12-7 61328]

S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-9-7 249424]

S1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]

S2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2010-10-11 6104656]

S2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-9-10 265400]

S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]

S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]

S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]

S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-12-15 25832]

S3 FXDrv32;FXDrv32;\??\e:\fxdrv32.sys --> e:\FXDrv32.sys [?]

=============== Created Last 30 ================

2010-11-06 23:57:36 -------- d-----w- c:\docume~1\alluse~1\applic~1\SITEguard

2010-11-06 23:56:56 -------- d-----w- c:\program files\STOPzilla!

2010-11-06 23:56:55 -------- d-----w- c:\program files\common files\iS3

2010-11-06 23:56:55 -------- d-----w- c:\docume~1\alluse~1\applic~1\STOPzilla!

2010-11-04 06:09:54 -------- dc-h--w- c:\windows\ie8

2010-10-31 22:54:49 -------- d-----w- c:\docume~1\brandon\locals~1\applic~1\PMB Files

2010-10-31 22:54:46 -------- d-----w- c:\docume~1\alluse~1\applic~1\PMB Files

2010-10-31 21:50:10 -------- d--h--w- C:\$AVG

2010-10-31 21:35:12 -------- d-----w- c:\docume~1\brandon\applic~1\AVG10

2010-10-31 21:33:00 -------- d--h--w- c:\docume~1\alluse~1\applic~1\Common Files

2010-10-31 21:31:40 -------- d-----w- c:\windows\system32\drivers\AVG

2010-10-31 21:31:40 -------- d-----w- c:\docume~1\alluse~1\applic~1\AVG10

2010-10-31 21:31:05 -------- d-----w- c:\program files\AVG

2010-10-31 21:24:50 -------- d-----w- c:\docume~1\alluse~1\applic~1\MFAData

2010-10-25 17:34:19 -------- d-----w- c:\program files\MSECache

2010-10-24 20:57:30 -------- d-----w- c:\docume~1\brandon\applic~1\Malwarebytes

2010-10-24 20:57:23 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-10-24 20:57:22 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-10-24 20:57:22 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-10-24 20:57:22 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-10-24 20:46:44 -------- d-sh--w- c:\docume~1\brandon\applic~1\Smart Engine

2010-10-24 20:46:44 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\SMETDE

2010-10-24 20:45:58 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\2ea96d

2010-10-22 02:03:32 -------- d-sh--w- c:\docume~1\alluse~1\applic~1\SecuROM

2010-10-22 00:00:53 -------- d-----w- c:\docume~1\brandon\locals~1\applic~1\Nexway

2010-10-14 07:30:04 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll

2010-10-14 07:30:04 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll

2010-10-14 07:29:59 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

==================== Find3M ====================

2010-09-18 19:23:26 974848 ----a-w- c:\windows\system32\mfc42u.dll

2010-09-18 06:53:25 974848 ----a-w- c:\windows\system32\mfc42.dll

2010-09-18 06:53:25 954368 ----a-w- c:\windows\system32\mfc40.dll

2010-09-18 06:53:25 953856 ----a-w- c:\windows\system32\mfc40u.dll

2010-09-10 05:58:08 916480 ----a-w- c:\windows\system32\wininet.dll

2010-09-10 05:58:06 43520 ------w- c:\windows\system32\licmgr10.dll

2010-09-10 05:58:06 1469440 ------w- c:\windows\system32\inetcpl.cpl

2010-09-01 11:51:14 285824 ----a-w- c:\windows\system32\atmfd.dll

2010-08-31 13:42:52 1852800 ----a-w- c:\windows\system32\win32k.sys

2010-08-27 08:02:29 119808 ----a-w- c:\windows\system32\t2embed.dll

2010-08-27 05:57:43 99840 ----a-w- c:\windows\system32\srvsvc.dll

2010-08-26 12:52:45 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2010-08-23 16:12:04 617472 ----a-w- c:\windows\system32\comctl32.dll

2010-08-17 13:17:06 58880 ----a-w- c:\windows\system32\spoolsv.exe

2010-08-16 08:45:00 590848 ----a-w- c:\windows\system32\rpcrt4.dll

============= FINISH: 20:43:41.57 ===============

Attach.txt

Link to post
Share on other sites

This is what i got from Rootunhooker (ope its the newest version im supposed to be using):

RkUnhooker report generator v0.7

==============================================

Rootkit Unhooker kernel version: 3.7.300.509

==============================================

Windows Major Version: 5

Windows Minor Version: 1

Windows Build Number: 2600

==============================================

>Drivers

Driver: C:\WINDOWS\system32\DRIVERS\nv4_mini.sys

Address: 0xB5336000

Size: 10604544 bytes

Driver: C:\WINDOWS\System32\nv4_disp.dll

Address: 0xBD012000

Size: 6344704 bytes

Driver: C:\WINDOWS\system32\ntkrnlpa.exe

Address: 0x804D7000

Size: 2150400 bytes

Driver: PnpManager

Address: 0x804D7000

Size: 2150400 bytes

Driver: RAW

Address: 0x804D7000

Size: 2150400 bytes

Driver: WMIxWDM

Address: 0x804D7000

Size: 2150400 bytes

Driver: Win32k

Address: 0xBF800000

Size: 1855488 bytes

Driver: C:\WINDOWS\System32\win32k.sys

Address: 0xBF800000

Size: 1855488 bytes

Driver: C:\WINDOWS\system32\drivers\ha10kx2k.sys

Address: 0xB2DF3000

Size: 1064960 bytes

Driver: C:\WINDOWS\system32\drivers\ctac32k.sys

Address: 0xB2D03000

Size: 638976 bytes

Driver: Ntfs.sys

Address: 0xB7DE2000

Size: 577536 bytes

Driver: C:\WINDOWS\system32\DRIVERS\rt2870.sys

Address: 0xB2A45000

Size: 552960 bytes

Driver: C:\WINDOWS\system32\drivers\ctaud2k.sys

Address: 0xB521E000

Size: 499712 bytes

Driver: C:\WINDOWS\System32\DRIVERS\mrxsmb.sys

Address: 0xB29D5000

Size: 458752 bytes

Driver: C:\WINDOWS\System32\DRIVERS\update.sys

Address: 0xB5049000

Size: 385024 bytes

Driver: C:\WINDOWS\System32\DRIVERS\tcpip.sys

Address: 0xB2C4F000

Size: 364544 bytes

Driver: C:\WINDOWS\System32\DRIVERS\srv.sys

Address: 0xB1FCB000

Size: 360448 bytes

Driver: C:\WINDOWS\system32\DRIVERS\avgtdix.sys

Address: 0xB2C07000

Size: 294912 bytes

Driver: C:\WINDOWS\System32\ATMFD.DLL

Address: 0xBFFA0000

Size: 286720 bytes

Driver: C:\WINDOWS\System32\Drivers\HTTP.sys

Address: 0xB170F000

Size: 266240 bytes

Driver: C:\WINDOWS\system32\DRIVERS\avgldx86.sys

Address: 0xB2999000

Size: 245760 bytes

Driver: C:\WINDOWS\system32\drivers\ctoss2k.sys

Address: 0xB51C7000

Size: 208896 bytes

Driver: C:\WINDOWS\System32\DRIVERS\rdpdr.sys

Address: 0xB50CF000

Size: 196608 bytes

Driver: ACPI.sys

Address: 0xB7F50000

Size: 188416 bytes

Driver: C:\WINDOWS\system32\drivers\emupia2k.sys

Address: 0xB2DC6000

Size: 184320 bytes

Driver: C:\WINDOWS\System32\DRIVERS\mrxdav.sys

Address: 0xB219E000

Size: 184320 bytes

Driver: NDIS.sys

Address: 0xB7DB5000

Size: 184320 bytes

Driver: C:\WINDOWS\system32\drivers\kmixer.sys

Address: 0xB01F7000

Size: 176128 bytes

Driver: C:\WINDOWS\System32\DRIVERS\rdbss.sys

Address: 0xB2ACC000

Size: 176128 bytes

Driver: C:\WINDOWS\system32\drivers\hap16v2k.sys

Address: 0xB2EF7000

Size: 172032 bytes

Driver: szkgfs.sys

Address: 0xB7F7E000

Size: 167936 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys

Address: 0xB1E8B000

Size: 163840 bytes

Driver: C:\WINDOWS\System32\DRIVERS\netbt.sys

Address: 0xB2BB9000

Size: 163840 bytes

Driver: C:\WINDOWS\system32\drivers\ctsfm2k.sys

Address: 0xB2D9F000

Size: 159744 bytes

Driver: dmio.sys

Address: 0xB7EFA000

Size: 155648 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ipnat.sys

Address: 0xB2BE1000

Size: 155648 bytes

Driver: C:\WINDOWS\System32\Drivers\Fastfat.SYS

Address: 0xB1CA7000

Size: 147456 bytes

Driver: C:\WINDOWS\system32\drivers\portcls.sys

Address: 0xB51FA000

Size: 147456 bytes

Driver: C:\WINDOWS\System32\DRIVERS\USBPORT.SYS

Address: 0xB5298000

Size: 147456 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ks.sys

Address: 0xB52BC000

Size: 143360 bytes

Driver: C:\WINDOWS\System32\drivers\afd.sys

Address: 0xB2B97000

Size: 139264 bytes

Driver: ACPI_HAL

Address: 0x806E4000

Size: 134400 bytes

Driver: C:\WINDOWS\system32\hal.dll

Address: 0x806E4000

Size: 134400 bytes

Driver: fltmgr.sys

Address: 0xB7EAB000

Size: 131072 bytes

Driver: ftdisk.sys

Address: 0xB7F20000

Size: 126976 bytes

Driver: C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys

Address: 0xB5307000

Size: 110592 bytes

Driver: Mup.sys

Address: 0xB7D9B000

Size: 106496 bytes

Driver: atapi.sys

Address: 0xB7EE2000

Size: 98304 bytes

Driver: C:\WINDOWS\System32\Drivers\dump_atapi.sys

Address: 0xB28B9000

Size: 98304 bytes

Driver: KSecDD.sys

Address: 0xB7E82000

Size: 94208 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ndiswan.sys

Address: 0xB51B0000

Size: 94208 bytes

Driver: C:\WINDOWS\System32\DRIVERS\irda.sys

Address: 0xB2333000

Size: 90112 bytes

Driver: C:\WINDOWS\system32\drivers\wdmaud.sys

Address: 0xB20C1000

Size: 86016 bytes

Driver: C:\WINDOWS\system32\DRIVERS\VIDEOPRT.SYS

Address: 0xB5322000

Size: 81920 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ipsec.sys

Address: 0xB2CA8000

Size: 77824 bytes

Driver: WudfPf.sys

Address: 0xB7E6F000

Size: 77824 bytes

Driver: C:\WINDOWS\System32\drivers\dxg.sys

Address: 0xBD000000

Size: 73728 bytes

Driver: sr.sys

Address: 0xB7E99000

Size: 73728 bytes

Driver: pci.sys

Address: 0xB7F3F000

Size: 69632 bytes

Driver: C:\WINDOWS\System32\DRIVERS\psched.sys

Address: 0xB50FF000

Size: 69632 bytes

Driver: C:\WINDOWS\System32\Drivers\Cdfs.SYS

Address: 0xB8308000

Size: 65536 bytes

Driver: C:\WINDOWS\System32\DRIVERS\cdrom.sys

Address: 0xB8198000

Size: 65536 bytes

Driver: C:\WINDOWS\System32\DRIVERS\nic1394.sys

Address: 0xB81D8000

Size: 65536 bytes

Driver: ohci1394.sys

Address: 0xB80D8000

Size: 65536 bytes

Driver: C:\WINDOWS\System32\DRIVERS\serial.sys

Address: 0xB81B8000

Size: 65536 bytes

Driver: C:\WINDOWS\System32\DRIVERS\arp1394.sys

Address: 0xB8298000

Size: 61440 bytes

Driver: C:\WINDOWS\system32\drivers\drmk.sys

Address: 0xB81C8000

Size: 61440 bytes

Driver: C:\WINDOWS\System32\DRIVERS\redbook.sys

Address: 0xB81A8000

Size: 61440 bytes

Driver: C:\WINDOWS\system32\drivers\sysaudio.sys

Address: 0xB2253000

Size: 61440 bytes

Driver: C:\WINDOWS\System32\DRIVERS\usbhub.sys

Address: 0xB8238000

Size: 61440 bytes

Driver: C:\WINDOWS\System32\DRIVERS\1394BUS.SYS

Address: 0xB80E8000

Size: 57344 bytes

Driver: szkg.sys

Address: 0xB80A8000

Size: 57344 bytes

Driver: C:\WINDOWS\System32\DRIVERS\CLASSPNP.SYS

Address: 0xB8128000

Size: 53248 bytes

Driver: C:\WINDOWS\System32\DRIVERS\rasl2tp.sys

Address: 0xB81E8000

Size: 53248 bytes

Driver: VolSnap.sys

Address: 0xB8108000

Size: 53248 bytes

Driver: C:\WINDOWS\system32\DRIVERS\avgmfx86.sys

Address: 0xB8268000

Size: 49152 bytes

Driver: C:\WINDOWS\System32\DRIVERS\raspptp.sys

Address: 0xB8208000

Size: 49152 bytes

Driver: C:\WINDOWS\System32\Drivers\Fips.SYS

Address: 0xB82C8000

Size: 45056 bytes

Driver: C:\WINDOWS\system32\DRIVERS\imapi.sys

Address: 0xB8188000

Size: 45056 bytes

Driver: MountMgr.sys

Address: 0xB80F8000

Size: 45056 bytes

Driver: C:\WINDOWS\System32\DRIVERS\raspppoe.sys

Address: 0xB81F8000

Size: 45056 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys

Address: 0xB2126000

Size: 40960 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys

Address: 0xB2B17000

Size: 40960 bytes

Driver: isapnp.sys

Address: 0xB80C8000

Size: 40960 bytes

Driver: C:\WINDOWS\System32\Drivers\NDProxy.SYS

Address: 0xB8248000

Size: 40960 bytes

Driver: C:\WINDOWS\System32\DRIVERS\termdd.sys

Address: 0xB8228000

Size: 40960 bytes

Driver: AVGIDSEH.Sys

Address: 0xB8148000

Size: 36864 bytes

Driver: disk.sys

Address: 0xB8118000

Size: 36864 bytes

Driver: C:\WINDOWS\System32\DRIVERS\HIDCLASS.SYS

Address: 0xB82E8000

Size: 36864 bytes

Driver: C:\WINDOWS\System32\DRIVERS\msgpc.sys

Address: 0xB8218000

Size: 36864 bytes

Driver: C:\WINDOWS\System32\DRIVERS\netbios.sys

Address: 0xB82A8000

Size: 36864 bytes

Driver: C:\WINDOWS\System32\DRIVERS\processr.sys

Address: 0xB8178000

Size: 36864 bytes

Driver: PxHelp20.sys

Address: 0xB8138000

Size: 36864 bytes

Driver: C:\WINDOWS\System32\DRIVERS\wanarp.sys

Address: 0xB8288000

Size: 36864 bytes

Driver: C:\WINDOWS\system32\drivers\ctprxy2k.sys

Address: 0xB83E8000

Size: 32768 bytes

Driver: C:\WINDOWS\System32\Drivers\Npfs.SYS

Address: 0xB83A0000

Size: 32768 bytes

Driver: C:\WINDOWS\system32\DRIVERS\usbccgp.sys

Address: 0xB83F8000

Size: 32768 bytes

Driver: C:\WINDOWS\system32\DRIVERS\usbehci.sys

Address: 0xB83B8000

Size: 32768 bytes

Driver: C:\WINDOWS\System32\DRIVERS\fdc.sys

Address: 0xB83C8000

Size: 28672 bytes

Driver: C:\WINDOWS\system32\DRIVERS\HIDPARSE.SYS

Address: 0xB84B0000

Size: 28672 bytes

Driver: C:\WINDOWS\System32\DRIVERS\PCIIDEX.SYS

Address: 0xB8328000

Size: 28672 bytes

Driver: C:\WINDOWS\System32\DRIVERS\kbdclass.sys

Address: 0xB8450000

Size: 24576 bytes

Driver: C:\WINDOWS\System32\DRIVERS\mouclass.sys

Address: 0xB8458000

Size: 24576 bytes

Driver: C:\WINDOWS\System32\Drivers\rkhdrv40.SYS

Address: 0xB83C0000

Size: 24576 bytes

Driver: C:\WINDOWS\System32\drivers\vga.sys

Address: 0xB8358000

Size: 24576 bytes

Driver: C:\WINDOWS\system32\DRIVERS\AegisP.sys

Address: 0xB8408000

Size: 20480 bytes

Driver: avgrkx86.sys

Address: 0xB8338000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\flpydisk.sys

Address: 0xB8488000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\irsir.sys

Address: 0xB83D8000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\Drivers\Msfs.SYS

Address: 0xB8390000

Size: 20480 bytes

Driver: PartMgr.sys

Address: 0xB8330000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\Drivers\PCASp50.sys

Address: 0xB8428000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ptilink.sys

Address: 0xB8430000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\rasirda.sys

Address: 0xB8400000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\raspti.sys

Address: 0xB8440000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\TDI.SYS

Address: 0xB8410000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\DRIVERS\usbohci.sys

Address: 0xB83B0000

Size: 20480 bytes

Driver: C:\WINDOWS\System32\watchdog.sys

Address: 0xB8470000

Size: 20480 bytes

Driver: C:\WINDOWS\system32\DRIVERS\kbdhid.sys

Address: 0xB5035000

Size: 16384 bytes

Driver: C:\WINDOWS\System32\DRIVERS\mssmbios.sys

Address: 0xB7D6F000

Size: 16384 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ndisuio.sys

Address: 0xB25E5000

Size: 16384 bytes

Driver: C:\WINDOWS\System32\DRIVERS\serenum.sys

Address: 0xB8570000

Size: 16384 bytes

Driver: C:\WINDOWS\system32\BOOTVID.dll

Address: 0xB84B8000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\drivers\Dxapi.sys

Address: 0xB2941000

Size: 12288 bytes

Driver: C:\WINDOWS\system32\DRIVERS\gameenum.sys

Address: 0xB8588000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\DRIVERS\hidusb.sys

Address: 0xB503D000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\DRIVERS\irenum.sys

Address: 0xB8574000

Size: 12288 bytes

Driver: C:\WINDOWS\system32\drivers\iviaspi.sys

Address: 0xB8564000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\DRIVERS\mouhid.sys

Address: 0xB502D000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\DRIVERS\ndistapi.sys

Address: 0xB8594000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\DRIVERS\rasacd.sys

Address: 0xB859C000

Size: 12288 bytes

Driver: C:\WINDOWS\System32\Drivers\Beep.SYS

Address: 0xB85C6000

Size: 8192 bytes

Driver: dmload.sys

Address: 0xB85AC000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS

Address: 0xB85DE000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS

Address: 0xB85C2000

Size: 8192 bytes

Driver: C:\WINDOWS\system32\KDCOM.DLL

Address: 0xB85A8000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\Drivers\mnmdd.SYS

Address: 0xB85CA000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\DRIVERS\RDPCDD.sys

Address: 0xB85CE000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\DRIVERS\swenum.sys

Address: 0xB85B6000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\DRIVERS\USBD.SYS

Address: 0xB85BA000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\DRIVERS\WMILIB.SYS

Address: 0xB85AA000

Size: 8192 bytes

Driver: C:\WINDOWS\System32\DRIVERS\audstub.sys

Address: 0xB87BB000

Size: 4096 bytes

Driver: C:\WINDOWS\System32\drivers\dxgthk.sys

Address: 0xB8689000

Size: 4096 bytes

Driver: C:\WINDOWS\System32\Drivers\Null.SYS

Address: 0xB86BA000

Size: 4096 bytes

Driver: pciide.sys

Address: 0xB8670000

Size: 4096 bytes

==============================================

>Stealth

==============================================

>Files

==============================================

>Hooks

ntkrnlpa.exe+0x0002D884, Type: Inline - RelativeJump at address 0x80504884 hook handler located in [ntkrnlpa.exe]

ntkrnlpa.exe+0x0006ECBE, Type: Inline - RelativeJump at address 0x80545CBE hook handler located in [ntkrnlpa.exe]

[3020]firefox.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump at address 0x7C9163C3 hook handler located in [firefox.exe]

[768]explorer.exe-->kernel32.dll-->GetProcAddress, Type: IAT modification at address 0x01001268 hook handler located in [shimeng.dll]

Link to post
Share on other sites

Brandon1983:

I'd recommend not paying for anything to clean this up.

I'm not sure what is going on with Rootkit Unhooker, please run this instead:

icon11.gif Download GMER Rootkit Scanner from here to your desktop.

  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
    GMER_thumb.jpg
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)

    [*] Then click the Scan button & wait for it to finish.

    [*] Once done click on the [save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.

    [*]Save it where you can easily find it, such as your desktop, and post it in reply.

**Caution**

Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

If you have trouble running GEMR:

  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode

Please include the following in your next post:

  • GMER log

Link to post
Share on other sites

Ok here it is thank you for your time. Sorry about the delay getting back im a nursing student.

Brandon1983:

I'd recommend not paying for anything to clean this up.

I'm not sure what is going on with Rootkit Unhooker, please run this instead:

icon11.gif Download GMER Rootkit Scanner from here to your desktop.

  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
    GMER_thumb.jpg
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)

    [*] Then click the Scan button & wait for it to finish.

    [*] Once done click on the [save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.

    [*]Save it where you can easily find it, such as your desktop, and post it in reply.

**Caution**

Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

If you have trouble running GEMR:

  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode

Please include the following in your next post:

  • GMER log

Gmer.txt

Link to post
Share on other sites

Brandon1983:

icon11.gif Download ComboFix from one of the following locations:

Link 1

Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - ComboFix will not run until AVG is uninstalled. This is because AVG falsely detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG first. You may do this through Control Panel > Add/Remove Programs or you can use this tool for a more complete removal:

Download AppRemover from here saving it to your desktop.

  • Double click to run AppRemover
  • Follow the prompts to remove AVG
  • Reboot

Once you've removed AVG please continue with these instructions

  • Double click on ComboFix.exe & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RC1.png

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png

  • Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please include the following in your next post:

  • ComboFix log

Link to post
Share on other sites

No worries, we will get there - try this:

Brandon1983:

Delete your current copy of ComboFix, then follow these instructions:

Download Combofix from any of the links below. Rename it to Brandon.com before saving it to your desktop.

Link 1

Link 2

CF_download_FF.gif

Cfix_Brandon.com.jpg

* IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on Brandon.com & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RC1.png

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png

  • Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please include the following in your next post:

  • ComboFix log

Link to post
Share on other sites

Thank you for your help I followed your altered combo fix instructions. I still am getting the same error message though. deletede all other isntanceds of combo fix and saved as Brandon.com to desktop. No go.

No worries, we will get there - try this:

Brandon1983:

Delete your current copy of ComboFix, then follow these instructions:

Download Combofix from any of the links below. Rename it to Brandon.com before saving it to your desktop.

Link 1

Link 2

CF_download_FF.gif

Cfix_Brandon.com.jpg

* IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on Brandon.com & follow the prompts.

As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RC1.png

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

RC2-1.png

  • Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.

2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please include the following in your next post:

  • ComboFix log

Link to post
Share on other sites

Brandon1983:

Great! Now, download a new copy of ComboFix to your desktop and run it using these instructions:

icon11.gif Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above DDS::

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:25471
DirLook::
c:\documents and settings\All Users\Application Data\2ea96d
Driver::
6482C631
FXDrv32
rkhdrv40
File::
c:\windows\system32\6482C631.exe
e:\FXDrv32.sys

Save this as CFScript to your desktop.

Then disable your security programs and drag the CFScript into ComboFix.exe as you see in the screenshot below.

CFScriptB-4.gif

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:

  • ComboFix log

Link to post
Share on other sites

Did as instructed. Combo fix start after i drag the notepad file onto it but after agreeing to the disclaimer it gives me this in the blue window:

'SWREG' is not recognized as an internal or external command, operable program or batch file.

I let it sit for about 8 mintues before I concluded it wasnt going to go any further or give any more info.

Brandon1983:

Great! Now, download a new copy of ComboFix to your desktop and run it using these instructions:

icon11.gif Open Notepad Go to Start> All Programs> Accessories> Notepad ( this will only work with Notepad ) and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above DDS::

DDS::
uInternet Settings,ProxyServer = http=127.0.0.1:25471
DirLook::
c:\documents and settings\All Users\Application Data\2ea96d
Driver::
6482C631
FXDrv32
rkhdrv40
File::
c:\windows\system32\6482C631.exe
e:\FXDrv32.sys

Save this as CFScript to your desktop.

Then disable your security programs and drag the CFScript into ComboFix.exe as you see in the screenshot below.

CFScriptB-4.gif

This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Please include the following in your next post:

  • ComboFix log

Link to post
Share on other sites

O.O! I tried to repeat the steps to make sure I didnt have a user error and my computer shut itself down and rebooted all on its lonesome. I think I failed to delete Combofix and "Re-redownload" combofix before trying to have it run your script a second time.

Upon boot I got this message:

Windows has recovered from a serious error.

This is what the error code info was that i could copy:

BCCode : 1000008e BCP1 : C0000005 BCP2 : B80AB8F2 BCP3 : B0109B68

BCP4 : 00000000 OSVer : 5_1_2600 SP : 3_0 Product : 256_1

Did as instructed. Combo fix start after i drag the notepad file onto it but after agreeing to the disclaimer it gives me this in the blue window:

'SWREG' is not recognized as an internal or external command, operable program or batch file.

I let it sit for about 8 mintues before I concluded it wasnt going to go any further or give any more info.

Link to post
Share on other sites

Brandon1983:

Alright, here is what we need to do:

  • Go back to post #10 and follow those instructions to rename and save (don't run it yet) ComboFix to c:\
  • Follow the instructions in post #14 to create and save CFScript to your desktop.
  • Press Start > Run or the Windows Key + R. Copy and past the command from the Codebox below into the run box and press OK:
    "C:\iexplore.exe" "C:\Documents and Settings\User\Desktop\CFScript.txt"


  • This should launch CombFix

Please include the following in your next post:

  • ComboFix log

Link to post
Share on other sites

Ok deleted the old and saved comboix as Iexplorer to c;\ and ran your script from desktop using th4e command prompt via "run" from the start menu. here is the log. I asked to download recovery console but failed to detect my internet before it just continued on to malware scan.

Brandon1983:

Alright, here is what we need to do:

  • Go back to post #10 and follow those instructions to rename and save (don't run it yet) ComboFix to c:\
  • Follow the instructions in post #14 to create and save CFScript to your desktop.
  • Press Start > Run or the Windows Key + R. Copy and past the command from the Codebox below into the run box and press OK:
    "C:\iexplore.exe" "C:\Documents and Settings\User\Desktop\CFScript.txt"


  • This should launch CombFix

Please include the following in your next post:

  • ComboFix log

log.txt

Link to post
Share on other sites

Brandon1983:

icon11.gif Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:

c:\Qoobox\ComboFix-quarantined-files.txt

That should open a notepad file. Please post the contents of that file for me

Please include the following in your next post:

  • Contents of ComboFix-quarantined-files.txt

Link to post
Share on other sites

As you requested. Thanks for helping me its already running much better now.

Brandon1983:

icon11.gif Click Start > Run or press Windows Key + R copy/paste the following into the run box that opens and press OK:

c:\Qoobox\ComboFix-quarantined-files.txt

That should open a notepad file. Please post the contents of that file for me

Please include the following in your next post:

  • Contents of ComboFix-quarantined-files.txt

ComboFix_quarantined_files.txt

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.