Jump to content

IP BLOCK keeps popping up after standard cleanup


FRMEE

Recommended Posts

Hi Experts,

First of all thank you for your time checking out my loggings.

I have an issue with a notebook that was infected with about 600+ virusses that my antivirus (Avast) found and cleared. Malwarebytes found another 200 malware/registry items that were cleared. Finally the situation arose that no virus / malware was detected by either programs.

I still have an issue with an IP BLOCK that Malwarebytes keeps on popping up with. The message is as followed:

Administrator IP-BLOCK 219.153.41.175 (Type: outgoing)

As it does get blocked this shouldn't be a problem, however I would like to know what is causing this and if how I can clean my computer completely.

Other possibly relevant details:

- A program (c:\program files\usb_anti_autorun) was executing the wscript.exe (C:\WINDOWS\system32\wscript.exe) file upon startup. My virusscanner was giving me warnings about this script. I've deactived the program to start upon startup using CCLEANER (this program deactivated the program in msconfig and neatly deleted the entry from the list in msconfig)

- When I try to safeboot my notebook I get the BSOD (Blue Screen Of Death). I've checked on the internet and this could have two causes: necessary drivers aren't booted in safe mode or the C drive is infected with a virus that prevents a safe boot. Not 100% sure which one it is, norrmal boot works fine though.

Loggings.

1. Malwarebytes' Anti-Malware log file (this is the most recent. I can also provide the one that did find infections)

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 7795

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

9/25/2011 9:36:18 PM

mbam-log-2011-09-25 (21-36-17).txt

Scan type: Quick scan

Objects scanned: 150964

Time elapsed: 6 minute(s), 11 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

2. DDS.txt

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702

Run by Administrator at 20:17:59 on 2011-09-25

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.116 [GMT 8:00]

.

AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

E:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

E:\Program Files\AVAST Software\Avast\avastUI.exe

E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\WINDOWS\system32\igfxsrvc.exe

C:\WINDOWS\system32\ctfmon.exe

E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\NOTEPAD.EXE

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\WINDOWS\system32\wuauclt.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

mWinlogon: SFCDisable=-99 (0xffffff9d)

BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - e:\program files\avast software\avast\aswWebRepIE.dll

TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - e:\program files\avast software\avast\aswWebRepIE.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [avast] "e:\program files\avast software\avast\avastUI.exe" /nogui

mRun: [Malwarebytes' Anti-Malware] "e:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1316611068421

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{9C068E30-59F1-4B34-B036-AE99AD90C3E3} : DhcpNameServer = 192.168.1.1

Notify: igfxcui - igfxdev.dll

.

============= SERVICES / DRIVERS ===============

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-21 442200]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-21 320856]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-21 20568]

R2 avast! Antivirus;avast! Antivirus;e:\program files\avast software\avast\AvastSvc.exe [2011-9-21 44768]

R2 MBAMService;MBAMService;e:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-9-22 366152]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-9-22 22216]

S0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [2004-9-28 242130]

S0 AAC;AAC;c:\windows\system32\drivers\aac.sys [2005-5-11 47496]

S0 aar1210;aar1210;c:\windows\system32\drivers\aar1210.sys [2006-9-16 220104]

S0 aec6210;ACARD AEC6210UF UltraDMA33 Controller;c:\windows\system32\drivers\AEC6210.sys [2004-4-12 27648]

S0 aec6260;ACARD AEC6260 UltraDMA-66 Controller;c:\windows\system32\drivers\AEC6260.sys [2004-4-12 23726]

S0 aec6280;aec6280;c:\windows\system32\drivers\AEC6280.SYS [2004-4-12 22528]

S0 AEC6290;AEC6290;c:\windows\system32\drivers\AEC6290.SYS [2005-5-11 22528]

S0 AEC67160;AEC67160;c:\windows\system32\drivers\AEC67160.SYS [2005-5-11 18432]

S0 AEC671X;AEC671X;c:\windows\system32\drivers\AEC671X.SYS [2006-9-16 15086]

S0 AEC6880;AEC6880;c:\windows\system32\drivers\AEC6880.SYS [2005-5-11 31566]

S0 AEC6890;AEC6890;c:\windows\system32\drivers\AEC6890.SYS [2004-4-12 31566]

S0 aec68x5;aec68x5;c:\windows\system32\drivers\aec68X5.sys [2006-9-16 33982]

S0 elxstor;elxstor;c:\windows\system32\drivers\elxstor.sys [2005-8-19 282112]

S0 FASTSX;FASTSX;c:\windows\system32\drivers\fastsx.sys [2004-4-12 313472]

S0 fasttrak;fasttrak;c:\windows\system32\drivers\fasttrak.sys [2004-4-12 75520]

S0 fasttx2k2;fasttx2k2;c:\windows\system32\drivers\fasttx2k2.sys [2006-9-16 135680]

S0 HpCISSs;HpCISSs;c:\windows\system32\drivers\hpcisss.sys [2005-8-19 23552]

S0 Hpt366;Hpt366;c:\windows\system32\drivers\hpt366.sys [2004-4-12 22880]

S0 HPT371;HPT371;c:\windows\system32\drivers\hpt371.sys [2004-4-12 21877]

S0 hpt374;hpt374;c:\windows\system32\drivers\hpt374.sys [2004-4-12 117607]

S0 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys [2006-9-16 121865]

S0 hptpro;hptpro;c:\windows\system32\drivers\hptpro.sys [2004-4-15 9809]

S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [2004-4-12 24827]

S0 LSI_FC;LSI_FC;c:\windows\system32\drivers\lsi_fc.sys [2005-8-19 54784]

S0 LSI_SAS;LSI_SAS;c:\windows\system32\drivers\lsi_sas.sys [2006-9-16 54784]

S0 LSI_SCSI;LSI_SCSI;c:\windows\system32\drivers\lsi_scsi.sys [2006-9-16 54784]

S0 m5228;m5228;c:\windows\system32\drivers\m5228.sys [2004-4-12 38829]

S0 m5281;m5281;c:\windows\system32\drivers\m5281.sys [2006-9-16 41149]

S0 MegaIDE;MegaIDE;c:\windows\system32\drivers\MegaIDE.sys [2005-5-11 163277]

S0 megasas;megasas;c:\windows\system32\drivers\megasas.sys [2006-9-16 17408]

S0 mraid2k;mraid2k;c:\windows\system32\drivers\MRAID2K.SYS [2004-4-12 17110]

S0 nfrd960;nfrd960;c:\windows\system32\drivers\nfrd960.sys [2005-8-19 35840]

S0 PNP649R;PNP649R;c:\windows\system32\drivers\PnP649r.sys [2005-5-11 66889]

S0 Pnp680;SiI 680 ATA Controller;c:\windows\system32\drivers\Pnp680.sys [2006-9-16 37031]

S0 ql2300;QLogic Fibre Channel SCSI Miniport Driver;c:\windows\system32\drivers\ql2300.sys [2005-8-19 702464]

S0 RAIDSRC;RAIDSRC;c:\windows\system32\drivers\raidsrc.sys [2005-5-11 47164]

S0 S150SX8;S150SX8;c:\windows\system32\drivers\S150sx8.sys [2005-5-11 36864]

S0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [2004-4-15 97530]

S0 SI3114;SiI-3114 SATALink Controller;c:\windows\system32\drivers\Si3114.sys [2006-9-16 54872]

S0 SI3124;SiI-3124 SATALink Controller;c:\windows\system32\drivers\Si3124.sys [2006-9-16 57856]

S0 SI3124r;SiI-3124 SATARaid Controller;c:\windows\system32\drivers\Si3124r.sys [2006-9-16 100881]

S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [2006-9-16 45568]

S0 SISRAIDS;SISRAIDS;c:\windows\system32\drivers\SISRAIDS.SYS [2005-5-11 29568]

S0 sptrak;sptrak;c:\windows\system32\drivers\Sptrak.sys [2006-9-16 41216]

S0 ULSATAS;ULSATAS;c:\windows\system32\drivers\ulsatas.sys [2005-5-11 129024]

S0 viapdsk;VIA ATA/ATAPI Host Controller;c:\windows\system32\drivers\viapdsk.sys [2004-4-12 29184]

S0 viaraid;viaraid;c:\windows\system32\drivers\viaraid.sys [2006-9-16 72192]

S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2006-9-16 77312]

S0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [2004-4-12 11029]

S2 Xzeounuzs;Xzeounuzs;c:\program files\xzeounuzs\srvany.exe [2002-1-12 8192]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2002-1-2 1684736]

S3 AmdK6;AMD K6 Processor Driver;c:\windows\system32\drivers\amdk6.sys [2004-8-4 37376]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\e:\program files\lavasoft\ad-aware\kernexplorer.sys --> e:\program files\lavasoft\ad-aware\KernExplorer.sys [?]

S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2002-1-2 966912]

S3 RTL8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2002-1-2 561280]

.

=============== Created Last 30 ================

.

2011-09-24 14:07:47 -------- d-----w- C:\bt_bckup

2011-09-24 04:06:40 -------- d-sh--w- c:\documents and settings\administrator\PrivacIE

2011-09-24 03:58:30 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll

2011-09-24 03:57:49 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

2011-09-24 03:56:36 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys

2011-09-24 03:54:19 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys

2011-09-24 03:54:17 105472 -c----w- c:\windows\system32\dllcache\mup.sys

2011-09-24 01:46:48 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys

2011-09-23 13:37:22 -------- d--h--w- c:\windows\PIF

2011-09-22 03:24:08 -------- d-----w- c:\windows\system32\appmgmt

2011-09-22 01:21:42 -------- d-----w- c:\windows\system32\scripting

2011-09-22 01:21:40 -------- d-----w- c:\windows\l2schemas

2011-09-22 01:21:39 -------- d-----w- c:\windows\system32\en

2011-09-22 01:21:38 -------- d-----w- c:\windows\system32\bits

2011-09-22 01:15:46 -------- d-----w- c:\windows\network diagnostic

2011-09-22 00:58:56 -------- d-sh--w- c:\documents and settings\administrator\IETldCache

2011-09-21 23:32:44 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes

2011-09-21 23:32:20 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes

2011-09-21 23:32:10 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-09-21 22:42:17 -------- d-----w- c:\windows\ie8updates

2011-09-21 22:41:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2011-09-21 22:41:38 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2011-09-21 22:41:37 599040 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2011-09-21 22:41:36 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2011-09-21 22:41:36 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll

2011-09-21 22:41:35 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2011-09-21 22:41:35 11076096 -c----w- c:\windows\system32\dllcache\ieframe.dll

2011-09-21 22:39:14 -------- dc-h--w- c:\windows\ie8

2011-09-21 15:06:44 73216 ------w- c:\windows\system32\drivers\atintuxx.sys

2011-09-21 14:20:16 272128 -c----w- c:\windows\system32\dllcache\bthport.sys

2011-09-21 14:20:15 272128 ------w- c:\windows\system32\drivers\bthport.sys

2011-09-21 14:17:32 357888 -c----w- c:\windows\system32\dllcache\srv.sys

2011-09-21 14:13:18 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys

2011-09-21 14:12:28 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll

2011-09-21 14:10:42 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe

2011-09-21 14:07:25 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll

2011-09-21 14:07:24 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll

2011-09-21 14:02:49 -------- d-----w- c:\windows\ServicePackFiles

2011-09-21 13:49:12 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys

2011-09-21 13:31:57 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll

2011-09-21 13:30:47 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2011-09-21 13:30:46 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe

2011-09-21 13:27:19 -------- d--h--w- c:\windows\$hf_mig$

2011-09-21 13:17:42 21728 ----a-w- c:\windows\system32\wucltui.dll.mui

2011-09-21 13:17:42 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui

2011-09-21 13:17:42 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

2011-09-21 13:17:41 15064 ----a-w- c:\windows\system32\wuapi.dll.mui

2011-09-21 12:54:51 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2011-09-21 07:53:39 -------- d-----w- c:\documents and settings\all users\application data\SecTaskMan

2011-09-20 23:40:07 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-09-20 23:39:37 41184 ----a-w- c:\windows\avastSS.scr

2011-09-20 23:39:18 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software

2011-09-19 06:58:07 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Google

2011-09-19 06:57:51 -------- d-----w- c:\program files\usb_anti_autorun

2011-09-09 09:12:13 599040 -c----w- c:\windows\system32\dllcache\crypt32.dll

.

==================== Find3M ====================

.

2011-09-09 09:12:13 599040 ----a-w- c:\windows\system32\crypt32.dll

2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys

.

============= FINISH: 20:25:10.93 ===============

3. Attach.zip

(see attachment)

Best regards,

F.M.

attach.zip

Link to post
Share on other sites

  • Staff

Hi and welcome to Malwarebytes.

Please update MBAM, run a Quick Scan, and post its log.

Next, please visit this webpage for instructions for running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

  • When the tool is finished, it will produce a report for you.
  • Please post the contents of C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.

Link to post
Share on other sites

Hi,

Thanks for your reply.

I ran Malwarebytes after running an update. Combofix and DDS runs were completed after.

Loggings:

1. MBAM

Malwarebytes' Anti-Malware 1.51.2.1300

www.malwarebytes.org

Database version: 7813

Windows 5.1.2600 Service Pack 3

Internet Explorer 8.0.6001.18702

9/28/2011 3:47:16 PM

mbam-log-2011-09-28 (15-47-15).txt

Scan type: Quick scan

Objects scanned: 151623

Time elapsed: 10 minute(s), 27 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

2. Combofix

ComboFix 11-09-28.01 - Administrator 09/28/2011 15:55:55.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.87 [GMT 8:00]

Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

* Created a new restore point

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\documents and settings\All Users\Application Data\SecTaskMan\_entreelist.dll

c:\windows\Temp\82fb.tmp2

c:\windows\Temp\8c13.tmp2

.

.

((((((((((((((((((((((((( Files Created from 2011-08-28 to 2011-09-28 )))))))))))))))))))))))))))))))

.

.

2011-09-26 09:03 . 2011-09-26 12:19 -------- d-----w- c:\documents and settings\Administrator\Application Data\FileZilla

2011-09-26 02:02 . 2011-09-26 02:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\OpenOffice.org

2011-09-25 23:58 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe

2011-09-24 14:07 . 2011-09-24 14:08 -------- d-----w- C:\bt_bckup

2011-09-24 04:06 . 2011-09-24 04:06 -------- d-sh--w- c:\documents and settings\Administrator\PrivacIE

2011-09-24 03:58 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll

2011-09-24 03:57 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

2011-09-24 03:56 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys

2011-09-24 03:54 . 2011-06-24 14:10 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys

2011-09-24 03:54 . 2011-04-21 13:37 105472 -c----w- c:\windows\system32\dllcache\mup.sys

2011-09-24 01:46 . 2011-07-08 14:02 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys

2011-09-23 13:37 . 2011-09-23 13:37 -------- d--h--w- c:\windows\PIF

2011-09-23 12:46 . 2011-09-23 12:46 -------- d-----w- c:\documents and settings\Administrator\Application Data\Notepad++

2011-09-22 01:21 . 2011-09-22 01:21 -------- d-----w- c:\windows\system32\scripting

2011-09-22 01:21 . 2011-09-22 01:21 -------- d-----w- c:\windows\l2schemas

2011-09-22 01:21 . 2011-09-22 01:21 -------- d-----w- c:\windows\system32\en

2011-09-22 01:21 . 2011-09-22 01:21 -------- d-----w- c:\windows\system32\bits

2011-09-22 00:58 . 2011-09-22 00:58 -------- d-sh--w- c:\documents and settings\Administrator\IETldCache

2011-09-22 00:20 . 2011-09-22 00:20 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache

2011-09-21 23:32 . 2011-09-21 23:32 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes

2011-09-21 23:32 . 2011-09-21 23:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes

2011-09-21 23:32 . 2011-08-31 09:00 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-09-21 22:41 . 2011-06-23 18:36 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2011-09-21 22:41 . 2011-06-23 18:36 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2011-09-21 22:41 . 2011-06-23 18:36 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2011-09-21 22:41 . 2011-06-23 18:36 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2011-09-21 22:41 . 2011-06-23 18:36 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll

2011-09-21 22:41 . 2011-06-23 18:36 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2011-09-21 22:41 . 2011-06-23 18:36 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll

2011-09-21 22:39 . 2011-09-21 22:41 -------- dc-h--w- c:\windows\ie8

2011-09-21 15:06 . 2004-08-03 14:29 73216 ------w- c:\windows\system32\drivers\atintuxx.sys

2011-09-21 14:20 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys

2011-09-21 14:20 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\drivers\bthport.sys

2011-09-21 14:17 . 2011-02-17 13:18 357888 -c----w- c:\windows\system32\dllcache\srv.sys

2011-09-21 14:13 . 2011-07-15 13:29 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys

2011-09-21 14:12 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll

2011-09-21 14:10 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe

2011-09-21 14:07 . 2009-10-15 16:28 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll

2011-09-21 14:07 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll

2011-09-21 14:02 . 2011-09-22 01:18 -------- d-----w- c:\windows\ServicePackFiles

2011-09-21 13:49 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys

2011-09-21 13:31 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll

2011-09-21 13:30 . 2011-02-17 12:32 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2011-09-21 13:30 . 2010-07-12 12:55 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe

2011-09-21 13:27 . 2011-09-26 01:54 -------- d--h--w- c:\windows\$hf_mig$

2011-09-21 13:17 . 2009-08-06 11:24 21728 ----a-w- c:\windows\system32\wucltui.dll.mui

2011-09-21 13:17 . 2009-08-06 11:24 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

2011-09-21 13:17 . 2009-08-06 11:24 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui

2011-09-21 13:17 . 2009-08-06 11:24 15064 ----a-w- c:\windows\system32\wuapi.dll.mui

2011-09-21 12:54 . 2011-09-21 12:52 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2011-09-21 12:49 . 2011-09-22 03:23 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft

2011-09-21 07:53 . 2011-09-28 08:06 -------- d-----w- c:\documents and settings\All Users\Application Data\SecTaskMan

2011-09-20 23:40 . 2011-09-06 20:37 320856 ----a-w- c:\windows\system32\drivers\aswSP.sys

2011-09-20 23:40 . 2011-09-06 20:36 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys

2011-09-20 23:40 . 2011-09-06 20:36 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys

2011-09-20 23:40 . 2011-09-06 20:38 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-09-20 23:40 . 2011-09-06 20:36 52568 ----a-w- c:\windows\system32\drivers\aswTdi.sys

2011-09-20 23:40 . 2011-09-06 20:36 110552 ----a-w- c:\windows\system32\drivers\aswmon2.sys

2011-09-20 23:40 . 2011-09-06 20:36 104536 ----a-w- c:\windows\system32\drivers\aswmon.sys

2011-09-20 23:40 . 2011-09-06 20:33 30808 ----a-w- c:\windows\system32\drivers\aavmker4.sys

2011-09-20 23:39 . 2011-09-06 20:45 41184 ----a-w- c:\windows\avastSS.scr

2011-09-20 23:39 . 2011-09-06 20:45 199304 ----a-w- c:\windows\system32\aswBoot.exe

2011-09-20 23:39 . 2011-09-20 23:39 -------- d-----w- c:\documents and settings\All Users\Application Data\AVAST Software

2011-09-19 06:58 . 2011-09-20 11:55 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Google

2011-09-09 09:12 . 2011-09-09 09:12 599040 -c----w- c:\windows\system32\dllcache\crypt32.dll

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2011-09-09 09:12 . 2004-08-04 12:00 599040 ----a-w- c:\windows\system32\crypt32.dll

2011-07-15 13:29 . 2004-08-04 12:00 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-07-08 14:02 . 2004-08-04 12:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]

@="{472083B0-C522-11CF-8763-00608CC02F24}"

[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]

2011-09-06 20:45 122512 ----a-w- e:\program files\AVAST Software\Avast\ashShell.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"RTHDCPL"="RTHDCPL.EXE" [2009-08-14 18702336]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]

"avast"="e:\program files\AVAST Software\Avast\avastUI.exe" [2011-09-06 3722416]

"Malwarebytes' Anti-Malware"="e:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]

.

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]

2011-09-20 11:52 136176 ----atw- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

.

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [9/21/2011 7:40 AM 442200]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9/21/2011 7:40 AM 320856]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/21/2011 7:40 AM 20568]

R2 MBAMService;MBAMService;e:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/22/2011 7:32 AM 366152]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/22/2011 7:32 AM 22216]

S0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [9/28/2004 7:42 PM 242130]

S0 AAC;AAC;c:\windows\system32\drivers\aac.sys [5/11/2005 7:50 PM 47496]

S0 aar1210;aar1210;c:\windows\system32\drivers\aar1210.sys [9/16/2006 8:33 AM 220104]

S0 aec6210;ACARD AEC6210UF UltraDMA33 Controller;c:\windows\system32\drivers\AEC6210.sys [4/12/2004 8:37 PM 27648]

S0 aec6260;ACARD AEC6260 UltraDMA-66 Controller;c:\windows\system32\drivers\AEC6260.sys [4/12/2004 8:37 PM 23726]

S0 aec6280;aec6280;c:\windows\system32\drivers\AEC6280.SYS [4/12/2004 8:37 PM 22528]

S0 AEC6290;AEC6290;c:\windows\system32\drivers\AEC6290.SYS [5/11/2005 7:50 PM 22528]

S0 AEC67160;AEC67160;c:\windows\system32\drivers\AEC67160.SYS [5/11/2005 7:50 PM 18432]

S0 AEC671X;AEC671X;c:\windows\system32\drivers\AEC671X.SYS [9/16/2006 8:33 AM 15086]

S0 AEC6880;AEC6880;c:\windows\system32\drivers\AEC6880.SYS [5/11/2005 7:50 PM 31566]

S0 AEC6890;AEC6890;c:\windows\system32\drivers\AEC6890.SYS [4/12/2004 8:37 PM 31566]

S0 aec68x5;aec68x5;c:\windows\system32\drivers\aec68X5.sys [9/16/2006 8:33 AM 33982]

S0 elxstor;elxstor;c:\windows\system32\drivers\elxstor.sys [8/19/2005 7:34 PM 282112]

S0 FASTSX;FASTSX;c:\windows\system32\drivers\fastsx.sys [4/12/2004 8:37 PM 313472]

S0 fasttrak;fasttrak;c:\windows\system32\drivers\fasttrak.sys [4/12/2004 8:37 PM 75520]

S0 fasttx2k2;fasttx2k2;c:\windows\system32\drivers\fasttx2k2.sys [9/16/2006 8:33 AM 135680]

S0 HpCISSs;HpCISSs;c:\windows\system32\drivers\hpcisss.sys [8/19/2005 7:36 PM 23552]

S0 Hpt366;Hpt366;c:\windows\system32\drivers\hpt366.sys [4/12/2004 8:37 PM 22880]

S0 HPT371;HPT371;c:\windows\system32\drivers\hpt371.sys [4/12/2004 8:37 PM 21877]

S0 hpt374;hpt374;c:\windows\system32\drivers\hpt374.sys [4/12/2004 8:37 PM 117607]

S0 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys [9/16/2006 8:33 AM 121865]

S0 hptpro;hptpro;c:\windows\system32\drivers\hptpro.sys [4/15/2004 7:54 PM 9809]

S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [4/12/2004 8:37 PM 24827]

S0 LSI_FC;LSI_FC;c:\windows\system32\drivers\lsi_fc.sys [8/19/2005 7:36 PM 54784]

S0 LSI_SAS;LSI_SAS;c:\windows\system32\drivers\lsi_sas.sys [9/16/2006 8:33 AM 54784]

S0 LSI_SCSI;LSI_SCSI;c:\windows\system32\drivers\lsi_scsi.sys [9/16/2006 8:33 AM 54784]

S0 m5228;m5228;c:\windows\system32\drivers\m5228.sys [4/12/2004 8:37 PM 38829]

S0 m5281;m5281;c:\windows\system32\drivers\m5281.sys [9/16/2006 8:33 AM 41149]

S0 MegaIDE;MegaIDE;c:\windows\system32\drivers\MegaIDE.sys [5/11/2005 7:50 PM 163277]

S0 megasas;megasas;c:\windows\system32\drivers\megasas.sys [9/16/2006 8:33 AM 17408]

S0 mraid2k;mraid2k;c:\windows\system32\drivers\MRAID2K.SYS [4/12/2004 8:37 PM 17110]

S0 nfrd960;nfrd960;c:\windows\system32\drivers\nfrd960.sys [8/19/2005 7:37 PM 35840]

S0 PNP649R;PNP649R;c:\windows\system32\drivers\PnP649r.sys [5/11/2005 7:50 PM 66889]

S0 Pnp680;SiI 680 ATA Controller;c:\windows\system32\drivers\Pnp680.sys [9/16/2006 8:33 AM 37031]

S0 ql2300;QLogic Fibre Channel SCSI Miniport Driver;c:\windows\system32\drivers\ql2300.sys [8/19/2005 7:37 PM 702464]

S0 RAIDSRC;RAIDSRC;c:\windows\system32\drivers\raidsrc.sys [5/11/2005 7:50 PM 47164]

S0 S150SX8;S150SX8;c:\windows\system32\drivers\S150sx8.sys [5/11/2005 7:50 PM 36864]

S0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [4/15/2004 7:54 PM 97530]

S0 SI3114;SiI-3114 SATALink Controller;c:\windows\system32\drivers\Si3114.sys [9/16/2006 8:33 AM 54872]

S0 SI3124;SiI-3124 SATALink Controller;c:\windows\system32\drivers\Si3124.sys [9/16/2006 8:33 AM 57856]

S0 SI3124r;SiI-3124 SATARaid Controller;c:\windows\system32\drivers\Si3124r.sys [9/16/2006 8:33 AM 100881]

S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [9/16/2006 8:33 AM 45568]

S0 SISRAIDS;SISRAIDS;c:\windows\system32\drivers\SISRAIDS.SYS [5/11/2005 7:50 PM 29568]

S0 sptrak;sptrak;c:\windows\system32\drivers\Sptrak.sys [9/16/2006 8:33 AM 41216]

S0 ULSATAS;ULSATAS;c:\windows\system32\drivers\ulsatas.sys [5/11/2005 7:50 PM 129024]

S0 viapdsk;VIA ATA/ATAPI Host Controller;c:\windows\system32\drivers\viapdsk.sys [4/12/2004 8:37 PM 29184]

S0 viaraid;viaraid;c:\windows\system32\drivers\viaraid.sys [9/16/2006 8:33 AM 72192]

S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [9/16/2006 8:33 AM 77312]

S0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [4/12/2004 8:37 PM 11029]

S2 Xzeounuzs;Xzeounuzs;c:\program files\Xzeounuzs\srvany.exe [1/12/2002 3:56 PM 8192]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [1/2/2002 5:55 PM 1684736]

S3 AmdK6;AMD K6 Processor Driver;c:\windows\system32\drivers\amdk6.sys [8/4/2004 6:59 AM 37376]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\e:\program files\Lavasoft\Ad-Aware\KernExplorer.sys --> e:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [?]

S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [1/2/2002 5:55 PM 966912]

S3 RTL8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [1/2/2002 5:55 PM 561280]

.

--- Other Services/Drivers In Memory ---

.

*NewlyCreated* - HTTPFILTER

.

Contents of the 'Scheduled Tasks' folder

.

2011-09-20 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1008497745-3718520985-3937497779-500Core.job

- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-09-20 11:52]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

TCP: DhcpNameServer = 192.168.1.1

.

- - - - ORPHANS REMOVED - - - -

.

SafeBoot-Lavasoft Ad-Aware Service

.

.

.

**************************************************************************

.

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2011-09-28 16:07

Windows 5.1.2600 Service Pack 3 NTFS

.

scanning hidden processes ...

.

scanning hidden autostart entries ...

.

scanning hidden files ...

.

scan completed successfully

hidden files: 0

.

**************************************************************************

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-1008497745-3718520985-3937497779-500\Software\Microsoft\Internet Explorer\User Preferences]

@Denied: (2) (Administrator)

"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ca,77,c7,1e,f4,cf,dc,4a,b8,a9,9e,\

"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,

d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ca,77,c7,1e,f4,cf,dc,4a,b8,a9,9e,\

.

Completion time: 2011-09-28 16:13:20

ComboFix-quarantined-files.txt 2011-09-28 08:13

.

Pre-Run: 12,374,532,096 bytes free

Post-Run: 12,249,567,232 bytes free

.

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe

[boot loader]

timeout=2

default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS

[operating systems]

c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

UnsupportedDebug="do not select this" /debug

multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

.

- - End Of File - - 6C7C963CEA8BD07DE21249591D3F1846

3. DDS.txt

.

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702

Run by Administrator at 16:15:34 on 2011-09-28

Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.159 [GMT 8:00]

.

AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

E:\Program Files\AVAST Software\Avast\AvastSvc.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\RTHDCPL.EXE

C:\WINDOWS\system32\igfxtray.exe

C:\WINDOWS\system32\hkcmd.exe

C:\WINDOWS\system32\igfxpers.exe

C:\WINDOWS\system32\igfxsrvc.exe

E:\Program Files\AVAST Software\Avast\avastUI.exe

E:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe

C:\WINDOWS\system32\ctfmon.exe

C:\WINDOWS\system32\WgaTray.exe

C:\WINDOWS\System32\svchost.exe -k HTTPFilter

C:\WINDOWS\explorer.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.google.com/

uInternet Connection Wizard,ShellNext = wmplayer.exe //ICWLaunch

BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - e:\program files\avast software\avast\aswWebRepIE.dll

TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - e:\program files\avast software\avast\aswWebRepIE.dll

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [igfxTray] c:\windows\system32\igfxtray.exe

mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe

mRun: [Persistence] c:\windows\system32\igfxpers.exe

mRun: [avast] "e:\program files\avast software\avast\avastUI.exe" /nogui

mRun: [Malwarebytes' Anti-Malware] "e:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1316611068421

DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab

TCP: DhcpNameServer = 192.168.1.1

TCP: Interfaces\{9C068E30-59F1-4B34-B036-AE99AD90C3E3} : DhcpNameServer = 192.168.1.1

Notify: igfxcui - igfxdev.dll

.

============= SERVICES / DRIVERS ===============

.

R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-21 442200]

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-21 320856]

R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-21 20568]

R2 avast! Antivirus;avast! Antivirus;e:\program files\avast software\avast\AvastSvc.exe [2011-9-21 44768]

R2 MBAMService;MBAMService;e:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-9-22 366152]

R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-9-22 22216]

S0 a320raid;a320raid;c:\windows\system32\drivers\a320raid.sys [2004-9-28 242130]

S0 AAC;AAC;c:\windows\system32\drivers\aac.sys [2005-5-11 47496]

S0 aar1210;aar1210;c:\windows\system32\drivers\aar1210.sys [2006-9-16 220104]

S0 aec6210;ACARD AEC6210UF UltraDMA33 Controller;c:\windows\system32\drivers\AEC6210.sys [2004-4-12 27648]

S0 aec6260;ACARD AEC6260 UltraDMA-66 Controller;c:\windows\system32\drivers\AEC6260.sys [2004-4-12 23726]

S0 aec6280;aec6280;c:\windows\system32\drivers\AEC6280.SYS [2004-4-12 22528]

S0 AEC6290;AEC6290;c:\windows\system32\drivers\AEC6290.SYS [2005-5-11 22528]

S0 AEC67160;AEC67160;c:\windows\system32\drivers\AEC67160.SYS [2005-5-11 18432]

S0 AEC671X;AEC671X;c:\windows\system32\drivers\AEC671X.SYS [2006-9-16 15086]

S0 AEC6880;AEC6880;c:\windows\system32\drivers\AEC6880.SYS [2005-5-11 31566]

S0 AEC6890;AEC6890;c:\windows\system32\drivers\AEC6890.SYS [2004-4-12 31566]

S0 aec68x5;aec68x5;c:\windows\system32\drivers\aec68X5.sys [2006-9-16 33982]

S0 elxstor;elxstor;c:\windows\system32\drivers\elxstor.sys [2005-8-19 282112]

S0 FASTSX;FASTSX;c:\windows\system32\drivers\fastsx.sys [2004-4-12 313472]

S0 fasttrak;fasttrak;c:\windows\system32\drivers\fasttrak.sys [2004-4-12 75520]

S0 fasttx2k2;fasttx2k2;c:\windows\system32\drivers\fasttx2k2.sys [2006-9-16 135680]

S0 HpCISSs;HpCISSs;c:\windows\system32\drivers\hpcisss.sys [2005-8-19 23552]

S0 Hpt366;Hpt366;c:\windows\system32\drivers\hpt366.sys [2004-4-12 22880]

S0 HPT371;HPT371;c:\windows\system32\drivers\hpt371.sys [2004-4-12 21877]

S0 hpt374;hpt374;c:\windows\system32\drivers\hpt374.sys [2004-4-12 117607]

S0 hptmv;hptmv;c:\windows\system32\drivers\hptmv.sys [2006-9-16 121865]

S0 hptpro;hptpro;c:\windows\system32\drivers\hptpro.sys [2004-4-15 9809]

S0 iteraid;ITERAID_Service_Install;c:\windows\system32\drivers\iteraid.sys [2004-4-12 24827]

S0 LSI_FC;LSI_FC;c:\windows\system32\drivers\lsi_fc.sys [2005-8-19 54784]

S0 LSI_SAS;LSI_SAS;c:\windows\system32\drivers\lsi_sas.sys [2006-9-16 54784]

S0 LSI_SCSI;LSI_SCSI;c:\windows\system32\drivers\lsi_scsi.sys [2006-9-16 54784]

S0 m5228;m5228;c:\windows\system32\drivers\m5228.sys [2004-4-12 38829]

S0 m5281;m5281;c:\windows\system32\drivers\m5281.sys [2006-9-16 41149]

S0 MegaIDE;MegaIDE;c:\windows\system32\drivers\MegaIDE.sys [2005-5-11 163277]

S0 megasas;megasas;c:\windows\system32\drivers\megasas.sys [2006-9-16 17408]

S0 mraid2k;mraid2k;c:\windows\system32\drivers\MRAID2K.SYS [2004-4-12 17110]

S0 nfrd960;nfrd960;c:\windows\system32\drivers\nfrd960.sys [2005-8-19 35840]

S0 PNP649R;PNP649R;c:\windows\system32\drivers\PnP649r.sys [2005-5-11 66889]

S0 Pnp680;SiI 680 ATA Controller;c:\windows\system32\drivers\Pnp680.sys [2006-9-16 37031]

S0 ql2300;QLogic Fibre Channel SCSI Miniport Driver;c:\windows\system32\drivers\ql2300.sys [2005-8-19 702464]

S0 RAIDSRC;RAIDSRC;c:\windows\system32\drivers\raidsrc.sys [2005-5-11 47164]

S0 S150SX8;S150SX8;c:\windows\system32\drivers\S150sx8.sys [2005-5-11 36864]

S0 SI3112r;Silicon Image SiI 3512 SATARaid Controller;c:\windows\system32\drivers\Si3112r.sys [2004-4-15 97530]

S0 SI3114;SiI-3114 SATALink Controller;c:\windows\system32\drivers\Si3114.sys [2006-9-16 54872]

S0 SI3124;SiI-3124 SATALink Controller;c:\windows\system32\drivers\Si3124.sys [2006-9-16 57856]

S0 SI3124r;SiI-3124 SATARaid Controller;c:\windows\system32\drivers\Si3124r.sys [2006-9-16 100881]

S0 SiSRaid1;SiSRaid1;c:\windows\system32\drivers\sisraid1.sys [2006-9-16 45568]

S0 SISRAIDS;SISRAIDS;c:\windows\system32\drivers\SISRAIDS.SYS [2005-5-11 29568]

S0 sptrak;sptrak;c:\windows\system32\drivers\Sptrak.sys [2006-9-16 41216]

S0 ULSATAS;ULSATAS;c:\windows\system32\drivers\ulsatas.sys [2005-5-11 129024]

S0 viapdsk;VIA ATA/ATAPI Host Controller;c:\windows\system32\drivers\viapdsk.sys [2004-4-12 29184]

S0 viaraid;viaraid;c:\windows\system32\drivers\viaraid.sys [2006-9-16 72192]

S0 viasraid;viasraid;c:\windows\system32\drivers\viasraid.sys [2006-9-16 77312]

S0 vmscsi;vmscsi;c:\windows\system32\drivers\vmscsi.sys [2004-4-12 11029]

S2 Xzeounuzs;Xzeounuzs;c:\program files\xzeounuzs\srvany.exe [2002-1-12 8192]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2002-1-2 1684736]

S3 AmdK6;AMD K6 Processor Driver;c:\windows\system32\drivers\amdk6.sys [2004-8-4 37376]

S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\e:\program files\lavasoft\ad-aware\kernexplorer.sys --> e:\program files\lavasoft\ad-aware\KernExplorer.sys [?]

S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2002-1-2 966912]

S3 RTL8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\drivers\rtl8192se.sys [2002-1-2 561280]

.

=============== Created Last 30 ================

.

2011-09-28 07:54:13 -------- d-sha-r- C:\cmdcons

2011-09-28 07:52:16 98816 ----a-w- c:\windows\sed.exe

2011-09-28 07:52:16 518144 ----a-w- c:\windows\SWREG.exe

2011-09-28 07:52:16 256000 ----a-w- c:\windows\PEV.exe

2011-09-28 07:52:16 208896 ----a-w- c:\windows\MBR.exe

2011-09-26 02:02:05 -------- d-----w- c:\documents and settings\administrator\application data\OpenOffice.org

2011-09-25 23:58:31 45568 -c----w- c:\windows\system32\dllcache\wab.exe

2011-09-24 14:07:47 -------- d-----w- C:\bt_bckup

2011-09-24 04:06:40 -------- d-sh--w- c:\documents and settings\administrator\PrivacIE

2011-09-24 03:58:30 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll

2011-09-24 03:57:49 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll

2011-09-24 03:56:36 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys

2011-09-24 03:54:19 139656 -c----w- c:\windows\system32\dllcache\rdpwd.sys

2011-09-24 03:54:17 105472 -c----w- c:\windows\system32\dllcache\mup.sys

2011-09-24 01:46:48 10496 -c----w- c:\windows\system32\dllcache\ndistapi.sys

2011-09-23 13:37:22 -------- d--h--w- c:\windows\PIF

2011-09-22 03:24:08 -------- d-----w- c:\windows\system32\appmgmt

2011-09-22 01:21:42 -------- d-----w- c:\windows\system32\scripting

2011-09-22 01:21:40 -------- d-----w- c:\windows\l2schemas

2011-09-22 01:21:39 -------- d-----w- c:\windows\system32\en

2011-09-22 01:21:38 -------- d-----w- c:\windows\system32\bits

2011-09-22 01:15:46 -------- d-----w- c:\windows\network diagnostic

2011-09-22 00:58:56 -------- d-sh--w- c:\documents and settings\administrator\IETldCache

2011-09-21 23:32:44 -------- d-----w- c:\documents and settings\administrator\application data\Malwarebytes

2011-09-21 23:32:20 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes

2011-09-21 23:32:10 22216 ----a-w- c:\windows\system32\drivers\mbam.sys

2011-09-21 22:42:17 -------- d-----w- c:\windows\ie8updates

2011-09-21 22:41:41 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll

2011-09-21 22:41:38 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll

2011-09-21 22:41:37 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll

2011-09-21 22:41:36 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll

2011-09-21 22:41:36 1991680 -c----w- c:\windows\system32\dllcache\iertutil.dll

2011-09-21 22:41:35 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll

2011-09-21 22:41:35 11081728 -c----w- c:\windows\system32\dllcache\ieframe.dll

2011-09-21 22:39:14 -------- dc-h--w- c:\windows\ie8

2011-09-21 15:06:44 73216 ------w- c:\windows\system32\drivers\atintuxx.sys

2011-09-21 14:20:16 272128 -c----w- c:\windows\system32\dllcache\bthport.sys

2011-09-21 14:20:15 272128 ------w- c:\windows\system32\drivers\bthport.sys

2011-09-21 14:17:32 357888 -c----w- c:\windows\system32\dllcache\srv.sys

2011-09-21 14:13:18 456320 -c----w- c:\windows\system32\dllcache\mrxsmb.sys

2011-09-21 14:12:28 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll

2011-09-21 14:10:42 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe

2011-09-21 14:07:25 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll

2011-09-21 14:07:24 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll

2011-09-21 14:02:49 -------- d-----w- c:\windows\ServicePackFiles

2011-09-21 13:49:12 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys

2011-09-21 13:31:57 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll

2011-09-21 13:30:47 5120 ----a-w- c:\windows\system32\xpsp4res.dll

2011-09-21 13:30:46 218112 -c----w- c:\windows\system32\dllcache\wordpad.exe

2011-09-21 13:27:19 -------- d--h--w- c:\windows\$hf_mig$

2011-09-21 13:17:42 21728 ----a-w- c:\windows\system32\wucltui.dll.mui

2011-09-21 13:17:42 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui

2011-09-21 13:17:42 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui

2011-09-21 13:17:41 15064 ----a-w- c:\windows\system32\wuapi.dll.mui

2011-09-21 12:54:51 101720 ----a-w- c:\windows\system32\drivers\SBREDrv.sys

2011-09-21 07:53:39 -------- d-----w- c:\documents and settings\all users\application data\SecTaskMan

2011-09-20 23:40:07 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys

2011-09-20 23:39:37 41184 ----a-w- c:\windows\avastSS.scr

2011-09-20 23:39:18 -------- d-----w- c:\documents and settings\all users\application data\AVAST Software

2011-09-19 06:58:07 -------- d-----w- c:\documents and settings\administrator\local settings\application data\Google

2011-09-09 09:12:13 599040 -c----w- c:\windows\system32\dllcache\crypt32.dll

.

==================== Find3M ====================

.

2011-09-09 09:12:13 599040 ----a-w- c:\windows\system32\crypt32.dll

2011-07-15 13:29:31 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2011-07-08 14:02:00 10496 ----a-w- c:\windows\system32\drivers\ndistapi.sys

.

============= FINISH: 16:21:38.89 ===============

4. Attach.txt

See attachment.

Best regards,

F.M.

attach.zip

Link to post
Share on other sites

  • Staff

Hi,

Next, please run a free online scan with the ESET Online Scanner

Note: You will need to use Internet Explorer for this scan.

  1. Tick the box next to YES, I accept the Terms of Use.
  2. Click Start
  3. When asked, allow the ActiveX control to install
  4. Click Start
  5. Make sure that the options Remove found threats and the option Scan unwanted applications is checked
  6. Click Scan
    Wait for the scan to finish
  7. Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  8. Copy and paste that log as a reply to this topic

Next, download my Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Let me know how things are running now and what issues remain.

Link to post
Share on other sites

Hi,

Thanks for your reply. I ran the ESET online scanner and your securitycheck program. I haven't been experiencing anymore IP Block messages, so I guess the problem is fixed...

The loggings are as followed.

1. ESET online scanner

ESETSmartInstaller@High as CAB hook log:

OnlineScanner.ocx - registred OK

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6528

# api_version=3.0.2

# EOSSerial=59b37967eb4a574f8132cb97ce86a56c

# end=stopped

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-10-08 07:58:32

# local_time=2011-10-08 01:43:32 (+0545, Nepal Standard Time)

# country="United States"

# lang=9

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=8192 67108863 100 0 1097 1097 0 0

# scanned=6735

# found=0

# cleaned=0

# scan_time=915

# version=7

# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)

# OnlineScanner.ocx=1.0.0.6528

# api_version=3.0.2

# EOSSerial=59b37967eb4a574f8132cb97ce86a56c

# end=finished

# remove_checked=true

# archives_checked=false

# unwanted_checked=true

# unsafe_checked=false

# antistealth_checked=true

# utc_time=2011-10-09 03:55:53

# local_time=2011-10-09 09:40:53 (+0545, Nepal Standard Time)

# country="United States"

# lang=9

# osver=5.1.2600 NT Service Pack 3

# compatibility_mode=8192 67108863 100 0 71553 71553 0 0

# scanned=33243

# found=0

# cleaned=0

# scan_time=2289

2. securitycheck

Results of screen317's Security Check version 0.99.21

Windows XP Service Pack 3

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Enabled!

avast! Free Antivirus

ESET Online Scanner v3

Antivirus up to date!

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

CCleaner

````````````````````````````````

Process Check:

objlist.exe by Laurent

AVAST Software Avast AvastSvc.exe

AVAST Software Avast avastUI.exe

``````````End of Log````````````

Link to post
Share on other sites

  • Staff

Hi,

Navigate to Start --> Run, and type Combofix /uninstall in the box that appears. Click OK afterward. Notice the space between the X and the /uninstall

This uninstalls all of ComboFix's components.

Delete SecurityCheck.

After that, navigate to Start --> Control Panel --> Add or Remove Programs, and uninstall the following program(s) (if present):

ESET Online Scanner v3

Restart your computer.

Let me know what issues remain.

-screen317

Link to post
Share on other sites

Hi,

I've uninstalled Combofix, deleted securitycheck and uninstaled ESET online scanner. As I said before the IP Block hasn't come up anymore for a while, my trial version of malwarebytes has also expired so I'm no longer protected if it will come up again.

I'm assuming that Combofix (or one of the other scanners) solved the issue. However I can't make it out from the loggings that I posted (I'm no expert :-) ).

So no further problems. Can you confirm that Combofix or one of the other toolings did 'something'?

Thanks again for all the help!

Best regards,

F.M.

Link to post
Share on other sites

  • Staff

Hi,

Yes, without going into too many details, all of the tools did "something." :)

I highly recommend the PRO version of MBAM; with it, it's likely that this issue would have been prevented in the first place.

Now that your computer seems to be in proper working order, please take the following steps to help prevent reinfection:

1) Download and install Javacool's SpywareBlaster, which will prevent malware from being installed on your computer. A tutorial on it can be found here.

2) Go to Windows Update frequently to get all of the latest updates (security or otherwise) for Windows.

3) Make sure your programs are up to date! Older versions may contain security risks. To find out what programs need to be updated, please run Secunia's Software Inspector.

4) WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:

  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an addon available for both Firefox and IE.

5) Be sure to update your Antivirus and Antispyware programs often!

Finally, please also take the time to read Tony Klein's excellent article on: So How Did I Get Infected in the First Place?

Safe surfing,

-screen317

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.