I did the 8 steps, My logs are at the end of the post. Here is a brief rundown of my problems.
I just recently got an internet connection after not having one for a couple of years. While surfing in firefox, I got a notice from Window Security Essentials informing me of a threat. I thought it was somekind of hoax having never heard of Security Essentials, and was equally suspicious when I couldn't fix the problem offline and that I couldn't ctrl+alt+del or access internet browsers.
I later learned that Secuirty Essentials is a new program by windows, and that it was not a hoax (correct me if I'm wrong about security essentials). I restarted in safe mode, did system restore to the previous night. then ran my ussual AVG, Malware Bytes, Spybot scan. Only spybot encountered a problem, something called Firewall Open Ports, I corrected that problem with spybot.
My normal fixes didn't work entirely, and I've come to this board for help, I ran your 8 steps at this point. Here are my remaining symptoms.
Windows Firewall is disabled, and gives an error when I try to activate it.\
Firefox and IE wont load unless I'm connected to the internet
Sometimes after a reboot my start bar and desktop wont displaying, requiring another restart.
Slow computer speeds, slow boot ups and shutdowns.
Firefox redirects search engine links in google to other trash websites.
Any help is greatly appreciated, and I will stop attempting my own fixes now.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4728
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
10/1/2010 4:49:23 PM
mbam-log-2010-10-01 (16-49-23).txt
Scan type: Quick scan
Objects scanned: 148409
Time elapsed: 5 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-01 18:19:55
Windows 5.1.2600 Service Pack 3
Running: rkuxdn9x.exe; Driver: C:\DOCUME~1\NEILTH~1\LOCALS~1\Temp\kxtdqpod.sys
---- System - GMER 1.0.15 ----
SSDT sppf.sys ZwCreateKey [0xF74E40E0]
SSDT sppf.sys ZwEnumerateKey [0xF74FCDA4]
SSDT sppf.sys ZwEnumerateValueKey [0xF74FD132]
SSDT sppf.sys ZwOpenKey [0xF74E40C0]
SSDT sppf.sys ZwQueryKey [0xF74FD20A]
SSDT sppf.sys ZwQueryValueKey [0xF74FD08A]
SSDT sppf.sys ZwSetValueKey [0xF74FD29C]
INT 0x62 ? 89C0EBF8
INT 0x63 ? 89B9FBF8
INT 0x84 ? 89B9EBF8
INT 0x94 ? 89B9EBF8
INT 0xA4 ? 89B9EBF8
INT 0xB4 ? 89B9EBF8
---- Kernel code sections - GMER 1.0.15 ----
? sppf.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload BA5C38AC 5 Bytes JMP 89B9E1D8
.text a71keirc.SYS BA54F386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a71keirc.SYS BA54F3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a71keirc.SYS BA54F3C4 3 Bytes [00, 80, 02]
.text a71keirc.SYS BA54F3C9 1 Byte [30]
.text a71keirc.SYS BA54F3C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89C112D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F750FDDC] sppf.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F750FE30] sppf.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74E5042] sppf.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74E513E] sppf.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74E50C0] sppf.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74E5800] sppf.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74E56D6] sppf.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89B9E2D8
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlInitUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!swprintf] 001CBA86
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeSetEvent] C61AEB00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 001C8986
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 86C61200
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00001C8B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmFreeMappingAddress] 96868801
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 8800001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 001CB286
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmUnmapIoSpace] 88968B00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 8900001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IofCompleteRequest] 001CA496
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlCompareUnicodeString] C6168B00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IofCallDriver] 001CC186
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 428A0A00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] C286880C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoConnectInterrupt] 8B00001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoDetachDevice] 24A48DFA
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeInitializeEvent] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeCancelTimer] 8D3F0304
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] CB033043
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlInitAnsiString] 0673C13B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] C13B0003
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoQueueWorkItem] 8366FA72
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmMapIoSpace] 75000E7B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoReportDetectedDevice] 307B8D00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00AA840F
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 83660000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!NlsMbCodePageTag] 6A000E7A
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!PoRequestPowerIrp] C6647400
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 001CC386
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 4F8B0200
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!sprintf] 968D5140
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00001C98
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ObfDereferenceObject] 22F6E852
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 478B0000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 50016A40
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ZwClose] 1CB48E8D
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] E8510000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 000022E4
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 6A18538B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 868D5200
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoCreateDevice] 00001CA0
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 22D2E850
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 4B8B0000
I just recently got an internet connection after not having one for a couple of years. While surfing in firefox, I got a notice from Window Security Essentials informing me of a threat. I thought it was somekind of hoax having never heard of Security Essentials, and was equally suspicious when I couldn't fix the problem offline and that I couldn't ctrl+alt+del or access internet browsers.
I later learned that Secuirty Essentials is a new program by windows, and that it was not a hoax (correct me if I'm wrong about security essentials). I restarted in safe mode, did system restore to the previous night. then ran my ussual AVG, Malware Bytes, Spybot scan. Only spybot encountered a problem, something called Firewall Open Ports, I corrected that problem with spybot.
My normal fixes didn't work entirely, and I've come to this board for help, I ran your 8 steps at this point. Here are my remaining symptoms.
Windows Firewall is disabled, and gives an error when I try to activate it.\
Firefox and IE wont load unless I'm connected to the internet
Sometimes after a reboot my start bar and desktop wont displaying, requiring another restart.
Slow computer speeds, slow boot ups and shutdowns.
Firefox redirects search engine links in google to other trash websites.
Any help is greatly appreciated, and I will stop attempting my own fixes now.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4728
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
10/1/2010 4:49:23 PM
mbam-log-2010-10-01 (16-49-23).txt
Scan type: Quick scan
Objects scanned: 148409
Time elapsed: 5 minute(s), 18 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-10-01 18:19:55
Windows 5.1.2600 Service Pack 3
Running: rkuxdn9x.exe; Driver: C:\DOCUME~1\NEILTH~1\LOCALS~1\Temp\kxtdqpod.sys
---- System - GMER 1.0.15 ----
SSDT sppf.sys ZwCreateKey [0xF74E40E0]
SSDT sppf.sys ZwEnumerateKey [0xF74FCDA4]
SSDT sppf.sys ZwEnumerateValueKey [0xF74FD132]
SSDT sppf.sys ZwOpenKey [0xF74E40C0]
SSDT sppf.sys ZwQueryKey [0xF74FD20A]
SSDT sppf.sys ZwQueryValueKey [0xF74FD08A]
SSDT sppf.sys ZwSetValueKey [0xF74FD29C]
INT 0x62 ? 89C0EBF8
INT 0x63 ? 89B9FBF8
INT 0x84 ? 89B9EBF8
INT 0x94 ? 89B9EBF8
INT 0xA4 ? 89B9EBF8
INT 0xB4 ? 89B9EBF8
---- Kernel code sections - GMER 1.0.15 ----
? sppf.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload BA5C38AC 5 Bytes JMP 89B9E1D8
.text a71keirc.SYS BA54F386 35 Bytes [00, 00, 00, 00, 00, 00, 20, ...]
.text a71keirc.SYS BA54F3AA 24 Bytes [00, 00, 00, 00, 00, 00, 00, ...]
.text a71keirc.SYS BA54F3C4 3 Bytes [00, 80, 02]
.text a71keirc.SYS BA54F3C9 1 Byte [30]
.text a71keirc.SYS BA54F3C9 11 Bytes [30, 00, 00, 00, 5E, 02, 00, ...] {XOR [EAX], AL; ADD [EAX], AL; POP ESI; ADD AL, [EAX]; ADD [EAX], AL; ADD [EAX], AL}
.text ...
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89C112D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F750FDDC] sppf.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F750FE30] sppf.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74E5042] sppf.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74E513E] sppf.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74E50C0] sppf.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74E5800] sppf.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74E56D6] sppf.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 89B9E2D8
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlInitUnicodeString] 8800001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!swprintf] 001CBA86
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeSetEvent] C61AEB00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoCreateSymbolicLink] 001C8986
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoGetConfigurationInformation] 86C61200
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoDeleteSymbolicLink] 00001C8B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmFreeMappingAddress] 96868801
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoFreeErrorLogEntry] 8800001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoDisconnectInterrupt] 001CB286
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmUnmapIoSpace] 88968B00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ObReferenceObjectByPointer] 8900001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IofCompleteRequest] 001CA496
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlCompareUnicodeString] C6168B00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IofCallDriver] 001CC186
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmAllocateMappingAddress] 428A0A00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoAllocateErrorLogEntry] C286880C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoConnectInterrupt] 8B00001C
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoDetachDevice] 24A48DFA
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeWaitForSingleObject] 00000000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeInitializeEvent] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeCancelTimer] 8D3F0304
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlAnsiStringToUnicodeString] CB033043
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlInitAnsiString] 0673C13B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoBuildDeviceIoControlRequest] C13B0003
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoQueueWorkItem] 8366FA72
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmMapIoSpace] 75000E7B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoInvalidateDeviceRelations] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoReportDetectedDevice] 307B8D00
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoReportResourceForDetection] 00AA840F
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlxAnsiStringToUnicodeSize] 83660000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!NlsMbCodePageTag] 6A000E7A
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!PoRequestPowerIrp] C6647400
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!KeInsertByKeyDeviceQueue] 001CC386
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!PoRegisterDeviceForIdleDetection] 4F8B0200
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!sprintf] 968D5140
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!MmMapLockedPagesSpecifyCache] 00001C98
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ObfDereferenceObject] 22F6E852
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoGetAttachedDeviceReference] 478B0000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoInvalidateDeviceState] 50016A40
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ZwClose] 1CB48E8D
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ObReferenceObjectByHandle] E8510000
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!ZwCreateDirectoryObject] 000022E4
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoBuildSynchronousFsdRequest] 6A18538B
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!PoStartNextPowerIrp] 868D5200
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoCreateDevice] 00001CA0
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!RtlCopyUnicodeString] 22D2E850
IAT \SystemRoot\System32\Drivers\a71keirc.SYS[ntoskrnl.exe!IoAllocateDriverObjectExtension] 4B8B0000