[Referred] Dns settings have been modified and regular check

By Zipas
Feb 23, 2011
Topic Status:
Not open for further replies.
  1. im not too concerned about being infected, but if it doesnt find anything, it doesnt mean im safe. pc is so old that it could have some bads hidden.

    ive uninstalled mumble after scan, didnt run for me anyway, froze pc.

    spyhunter noticed that dns settings have been modified. ive disabled network adapter some time ago since i use wireless. if its not the reason, i dont know why.

    btw i dont run any printers, only scaner.

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 5850

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    2011.02.23 10:52:54
    mbam-log-2011-02-23 (10-52-54).txt

    Scan type: Quick scan
    Objects scanned: 149213
    Time elapsed: 5 minute(s), 23 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit quick scan 2011-02-23 10:14:35
    Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1200JB-00EVA0 rev.15.05R15
    Running: 1ijrz1oj.exe; Driver: C:\DOCUME~1\Useris\LOCALS~1\Temp\ffryipod.sys


    ---- System - GMER 1.0.15 ----

    SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xF749E2A8]
    SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xF74A9910]

    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xF495482E]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0xF4954652]
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0xF495478C]
    Code 8769B4F4 NlsAnsiCodePage
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) NtCreateSection
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
    Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

    ---- Devices - GMER 1.0.15 ----

    Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 870A4630
    Device \Driver\atapi \Device\Ide\IdePort0 870A4630
    Device \Driver\atapi \Device\Ide\IdePort1 870A4630
    Device \Driver\atapi \Device\Ide\IdePort2 870A4630
    Device \Driver\atapi \Device\Ide\IdePort3 870A4630
    Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-12 870A4630
    Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 87069F00
    Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 87069F00
    Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 87069F00
    Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target3Lun0 87069F00
    Device \Driver\d347prt \Device\Scsi\d347prt1 87069F00
    Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
    Device \FileSystem\Ntfs \Ntfs 8733EA20

    AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

    Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/AVAST Software)
    Device \FileSystem\Fastfat \Fat 85A98438

    AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
    AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
    AttachedDevice \Driver\Tcpip \Device\Ip pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
    AttachedDevice \Driver\Tcpip \Device\Tcp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
    AttachedDevice \Driver\Tcpip \Device\Udp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
    AttachedDevice \Driver\Tcpip \Device\RawIp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
    AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

    ---- Modules - GMER 1.0.15 ----

    Module _________ F7400000-F7418000 (98304 bytes)

    ---- EOF - GMER 1.0.15 ----



    DDS (Ver_10-12-12.02) - NTFSx86
    Run by Useris at 10:28:48,65 on 2011.02.23
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Professional 5.1.2600.3.1257.370.1033.18.1023.509 [GMT 2:00]

    AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: PC Tools Firewall Plus *Disabled*

    ============== Running Processes ===============

    C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\acs.exe
    svchost.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\PC Tools Firewall Plus\FWService.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
    C:\Program Files\Analog Devices\SoundMAX\smax4.exe
    C:\Program Files\Alwil Software\Avast5\avastUI.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\PeerBlock\peerblock.exe
    C:\Program Files\DeskPins\DeskPins.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Useris\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://youtube.com/
    uDefault_Search_URL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearch Bar = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    mSearchURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
    uRun: [Gadwin PrintScreen] c:\program files\gadwin systems\printscreen\PrintScreen.exe /nosplash
    uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [PeerBlock] c:\program files\peerblock\peerblock.exe
    mRun: [TWCU] "c:\program files\tp-link\twcu\TWCU.exe" -nogui
    mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
    mRun: [SoundMax] "c:\program files\analog devices\soundmax\smax4.exe" /tray
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    StartupFolder: c:\docume~1\useris\startm~1\programs\startup\deskpins.lnk - c:\program files\deskpins\DeskPins.exe
    uPolicies-explorer: NoSecurityTab = 1 (0x1)
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258146703592
    DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258147288248
    DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://active.macromedia.com/flash2/cabs/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
    Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
    SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
    Hosts: 178.63.80.143 drivershq.com
    Hosts: 178.63.80.143 www.drivershq.com
    Hosts: 178.63.80.143 downloads.drivershq.com
    Hosts: 178.63.80.143 devicedoctor.com
    Hosts: 178.63.80.143 www.devicedoctor.com

    Note: multiple HOSTS entries found. Please refer to Attach.txt

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\useris\applic~1\mozilla\firefox\profiles\yak0ni2f.default\
    FF - prefs.js: browser.search.selectedEngine - Search the Web
    FF - prefs.js: browser.startup.homepage - hxxp://watchthemoviesforfree.com/
    FF - component: c:\documents and settings\useris\application data\mozilla\firefox\profiles\yak0ni2f.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
    FF - component: c:\documents and settings\useris\application data\mozilla\firefox\profiles\yak0ni2f.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
    FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
    FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
    FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
    FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: Feed Filter: facebookfilter@chocolatesoftware.com - %profile%\extensions\facebookfilter@chocolatesoftware.com
    FF - Ext: bit.ly preview: bitlypreview@jay.ridgeway - %profile%\extensions\bitlypreview@jay.ridgeway
    FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension

    ============= SERVICES / DRIVERS ===============

    R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2005-12-6 155136]
    R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2005-12-6 5248]
    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-20 64288]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-11-21 294608]
    R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-12-19 233136]
    R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
    R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-21 17744]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-10-19 40384]
    R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-12-19 88040]
    R2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2009-12-19 818432]
    R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma~1\spyhun~1\SH4SER~1.EXE [2010-5-18 327064]
    R3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2011-1-4 19056]
    R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2009-12-19 70664]
    R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2009-12-19 58816]
    R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-12-19 115216]
    R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]
    S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
    S3 cpuz130;cpuz130;\??\c:\docume~1\useris\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\useris\locals~1\temp\cpuz130\cpuz_x32.sys [?]
    S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\androidusb.sys --> c:\windows\system32\drivers\ANDROIDUSB.sys [?]
    S3 KLIF;KLIF;\??\c:\windows\system32\zonelabs\avsys\klif.sys --> c:\windows\system32\zonelabs\avsys\KLIF.SYS [?]
    S3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\system32\drivers\pctNdis-DNS.sys [2009-12-19 32680]
    S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys --> c:\windows\system32\vsdatant.sys [?]

    =============== Created Last 30 ================

    2011-02-14 22:25:09 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
    2011-02-14 22:25:08 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
    2011-02-14 22:25:08 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
    2011-02-14 22:25:07 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
    2011-02-14 22:25:06 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
    2011-02-14 22:25:06 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
    2011-02-14 22:25:05 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
    2011-02-14 22:25:03 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
    2011-02-14 22:23:34 -------- d-----w- c:\docume~1\useris\applic~1\RIFT
    2011-02-01 14:47:07 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
    2011-02-01 14:35:52 -------- d-----w- c:\docume~1\useris\locals~1\applic~1\Downloaded Installations
    2011-01-30 12:57:00 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
    2011-01-30 12:57:00 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll

    ==================== Find3M ====================

    2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
    2011-01-13 08:47:35 38848 ----a-w- c:\windows\avastSS.scr
    2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
    2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
    2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
    2010-12-20 23:59:20 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-12-20 23:59:19 43520 ----a-w- c:\windows\system32\licmgr10.dll
    2010-12-20 23:59:19 1469440 ------w- c:\windows\system32\inetcpl.cpl
    2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
    2010-12-20 12:55:26 385024 ----a-w- c:\windows\system32\html.iec
    2010-12-09 15:15:09 718336 ----a-w- c:\windows\system32\ntdll.dll
    2010-12-09 14:30:22 33280 ----a-w- c:\windows\system32\csrsrv.dll
    2010-12-09 13:42:26 2148864 ------w- c:\windows\system32\ntoskrnl.exe
    2010-12-09 13:07:07 2027008 ------w- c:\windows\system32\ntkrnlpa.exe

    ============= FINISH: 10:30:13,96 ===============



    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_10-12-12.02)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 2004.12.14 17:55:28
    System Uptime: 2011.02.23 10:19:19 (0 hours ago)

    Motherboard: Intel Corporation | | D865PERL
    Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | J2E1 | 2992/200mhz

    ==== Disk Partitions =========================

    A: is Removable
    C: is FIXED (NTFS) - 112 GiB total, 12,514 GiB free.
    D: is CDROM ()
    E: is CDROM ()
    F: is CDROM ()
    G: is CDROM ()
    H: is CDROM ()

    ==== Disabled Device Manager Items =============

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Atheros AR5005GS Wireless Network Adapter
    Device ID: PCI\VEN_168C&DEV_0013&SUBSYS_2051168C&REV_01\4&2E98101C&0&10F0
    Manufacturer: Atheros
    Name: Atheros AR5005GS Wireless Network Adapter
    PNP Device ID: PCI\VEN_168C&DEV_0013&SUBSYS_2051168C&REV_01\4&2E98101C&0&10F0
    Service: AR5416

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Intel(R) PRO/100 VE Network Connection
    Device ID: PCI\VEN_8086&DEV_1050&SUBSYS_30208086&REV_01\4&2E98101C&0&40F0
    Manufacturer: Intel
    Name: Intel(R) PRO/100 VE Network Connection
    PNP Device ID: PCI\VEN_8086&DEV_1050&SUBSYS_30208086&REV_01\4&2E98101C&0&40F0
    Service: E100B

    ==== System Restore Points ===================

    RP124: 2010.12.27 14:12:58 - System Checkpoint
    RP125: 2010.12.29 14:46:27 - System Checkpoint
    RP126: 2010.12.30 16:22:00 - System Checkpoint
    RP127: 2011.01.04 18:52:14 - System Checkpoint
    RP128: 2011.01.12 18:59:34 - Software Distribution Service 3.0
    RP129: 2011.01.15 03:20:38 - System Checkpoint
    RP130: 2011.01.20 07:57:41 - System Checkpoint
    RP131: 2011.01.25 17:23:24 - System Checkpoint
    RP132: 2011.01.29 15:32:32 - System Checkpoint
    RP133: 2011.02.01 12:49:30 - System Checkpoint
    RP134: 2011.02.01 16:37:33 - Installed HTC Sync.
    RP135: 2011.02.01 16:47:07 - Installed Windows XP Wdf01007.
    RP136: 2011.02.02 17:25:49 - Software Distribution Service 3.0
    RP137: 2011.02.05 18:08:17 - System Checkpoint
    RP138: 2011.02.06 18:12:04 - System Checkpoint
    RP139: 2011.02.08 17:38:31 - System Checkpoint
    RP140: 2011.02.10 19:13:27 - Software Distribution Service 3.0
    RP141: 2011.02.12 19:43:45 - System Checkpoint
    RP142: 2011.02.14 16:04:33 - System Checkpoint
    RP143: 2011.02.15 00:23:12 - Installed RIFT
    RP144: 2011.02.16 18:26:17 - System Checkpoint
    RP145: 2011.02.18 19:38:13 - System Checkpoint
    RP146: 2011.02.20 08:54:47 - System Checkpoint
    RP147: 2011.02.21 14:46:42 - System Checkpoint
    RP148: 2011.02.21 14:58:18 - Removed RIFT
    RP149: 2011.02.21 15:00:05 - Removed HTC Driver Installer.
    RP150: 2011.02.21 15:02:15 - Removed HTC Sync.
    RP151: 2011.02.21 15:03:43 - Removed HTC BMP USB Driver.

    ==== Hosts File Hijack ======================

    Hosts: 178.63.80.143 drivershq.com
    Hosts: 178.63.80.143 www.drivershq.com
    Hosts: 178.63.80.143 downloads.drivershq.com
    Hosts: 178.63.80.143 devicedoctor.com
    Hosts: 178.63.80.143 www.devicedoctor.com
    Hosts: 178.63.80.143 uniblue.com
    Hosts: 178.63.80.143 www.uniblue.com
    Hosts: 178.63.80.143 download.uniblue.com
    Hosts: 178.63.80.143 drivermax.com
    Hosts: 178.63.80.143 www.drivermax.com
    Hosts: 178.63.80.143 innovative-sol.com
    Hosts: 178.63.80.143 www.innovative-sol.com
    Hosts: 178.63.80.143 driverrobot.com
    Hosts: 178.63.80.143 www.driverrobot.com
    Hosts: 178.63.80.143 driverchecker.com
    Hosts: 178.63.80.143 www.driverchecker.com
    Hosts: 178.63.80.143 driveragent.com
    Hosts: 178.63.80.143 www.driveragent.com
    Hosts: 178.63.80.143 radarsync.com
    Hosts: 178.63.80.143 www.radarsync.com
    Hosts: 178.63.80.143 driver-soft.com
    Hosts: 178.63.80.143 www.driver-soft.com

    ==== Installed Programs ======================

    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player 10 Plugin
    Adobe Photoshop 6.0
    Adobe Reader 9.4.2
    Adobe Shockwave Player 11
    Adobe SVG Viewer 3.0
    AIM 6
    µTorrent
    avast! Free Antivirus
    Canon CanoScan Toolbox 4.5
    CCleaner
    Compatibility Pack for the 2007 Office system
    DeskPins (remove only)
    DiagramStudio 4.0
    dirLock
    DivX Setup
    ffdshow
    FLV Player 2.0 (build 25)
    Full Tilt Poker.Net
    Gadwin PrintScreen
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB2158563)
    Hotfix for Windows XP (KB2443685)
    Hotfix for Windows XP (KB915800-v4)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976002-v5)
    Hotfix for Windows XP (KB976098-v2)
    Hotfix for Windows XP (KB979306)
    Hotfix for Windows XP (KB981793)
    ImageDrive (Ahead Software)
    InCD EasyWrite Reader (Ahead Software)
    Intel(R) PRO Network Adapters and Drivers
    Java Auto Updater
    Java(TM) 6 Update 20
    K-Lite Codec Pack 2.34 Full
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional with FrontPage
    Microsoft Silverlight
    Microsoft VC9 runtime libraries
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft WSE 2.0 Runtime
    mIRC
    Mozilla Firefox (3.6.13)
    MSXML 4.0 SP2 (KB973688)
    MSXML 4.0 SP3 Parser
    MSXML 4.0 SP3 Parser (KB973685)
    Mumble and Murmur
    NVIDIA Drivers
    OmniPage SE 2.0
    PC Tools Firewall Plus 6.0
    PeerBlock 1.1 (r518)
    QFolder
    Security Update for CAPICOM (KB931906)
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Windows Internet Explorer 8 (KB2183461)
    Security Update for Windows Internet Explorer 8 (KB2360131)
    Security Update for Windows Internet Explorer 8 (KB2416400)
    Security Update for Windows Internet Explorer 8 (KB2482017)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB972260)
    Security Update for Windows Internet Explorer 8 (KB974455)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB981332)
    Security Update for Windows Internet Explorer 8 (KB982381)
    Security Update for Windows Media Player (KB2378111)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player (KB975558)
    Security Update for Windows Media Player (KB978695)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB2079403)
    Security Update for Windows XP (KB2121546)
    Security Update for Windows XP (KB2160329)
    Security Update for Windows XP (KB2229593)
    Security Update for Windows XP (KB2259922)
    Security Update for Windows XP (KB2279986)
    Security Update for Windows XP (KB2286198)
    Security Update for Windows XP (KB2296011)
    Security Update for Windows XP (KB2296199)
    Security Update for Windows XP (KB2347290)
    Security Update for Windows XP (KB2360937)
    Security Update for Windows XP (KB2387149)
    Security Update for Windows XP (KB2393802)
    Security Update for Windows XP (KB2419632)
    Security Update for Windows XP (KB2423089)
    Security Update for Windows XP (KB2436673)
    Security Update for Windows XP (KB2440591)
    Security Update for Windows XP (KB2443105)
    Security Update for Windows XP (KB2476687)
    Security Update for Windows XP (KB2478960)
    Security Update for Windows XP (KB2478971)
    Security Update for Windows XP (KB2479628)
    Security Update for Windows XP (KB2483185)
    Security Update for Windows XP (KB2485376)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950759)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953838)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956390)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371-v2)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975561)
    Security Update for Windows XP (KB975562)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977816)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978338)
    Security Update for Windows XP (KB978542)
    Security Update for Windows XP (KB978601)
    Security Update for Windows XP (KB978706)
    Security Update for Windows XP (KB979309)
    Security Update for Windows XP (KB979482)
    Security Update for Windows XP (KB979559)
    Security Update for Windows XP (KB979683)
    Security Update for Windows XP (KB979687)
    Security Update for Windows XP (KB980195)
    Security Update for Windows XP (KB980218)
    Security Update for Windows XP (KB980232)
    Security Update for Windows XP (KB980436)
    Security Update for Windows XP (KB981322)
    Security Update for Windows XP (KB981852)
    Security Update for Windows XP (KB981957)
    Security Update for Windows XP (KB981997)
    Security Update for Windows XP (KB982132)
    Security Update for Windows XP (KB982214)
    Security Update for Windows XP (KB982665)
    Security Update for Windows XP (KB982802)
    Skype™ 3.8
    SoundMAX
    Spybot - Search & Destroy
    SpyHunter
    SUPERAntiSpyware Free Edition
    TP-LINK Client Installation Program
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB973874)
    Update for Windows Internet Explorer 8 (KB976662)
    Update for Windows Internet Explorer 8 (KB976749)
    Update for Windows XP (KB2141007)
    Update for Windows XP (KB2345886)
    Update for Windows XP (KB2467659)
    Update for Windows XP (KB943729)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    VC80CRTRedist - 8.0.50727.4053
    Ventrilo Client
    VentriloMIX
    VirtualCloneDrive
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Genuine Advantage Validation Tool (KB892130)
    Windows Internet Explorer 8
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3
    WinRAR archiver
    World of Warcraft
    Wow Web Stats Client v2.4
    Zune Desktop Theme

    ==== Event Viewer Messages From Past Week ========

    2011.02.23 10:12:27, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.
    2011.02.17 07:58:27, error: Service Control Manager [7034] - The SpyHunter 4 Service service terminated unexpectedly. It has done this 1 time(s).
    2011.02.17 07:58:19, error: Service Control Manager [7034] - The SoundMAX Agent Service service terminated unexpectedly. It has done this 1 time(s).
    2011.02.17 07:58:11, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
    2011.02.17 02:12:20, error: ipnathlp [31008] - The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
    2011.02.16 16:12:23, error: Service Control Manager [7000] - The Lavasoft Ad-Aware Service service failed to start due to the following error: The system cannot find the path specified.

    ==== End Of File ===========================
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    Welcome to TechSpot! It is fairly easy to see where the problems are. I am going to start you out with very specific instructions:

    You will need to do a DNS Flush, then reset your router.
    Start> Run> type cmd> enter> at the C prompt type ipconfig /flushdns (note space before the /)

    Exit the Command prompt when finished and shut the system down.-

    • [1]. Shut down your computer, and any other computer connected to your router.
      [2]. On the back of the router, there should be a small hole or button labelled RESET. Using a bent paper clip or similar item, hold that in continuously for twenty seconds.
      [3]. Unplug the router. Wait sixty seconds.
      [4].Now holding again the reset button, plug it back in. Continue holding the reset button for twenty seconds. Unplug the router again.
      [5].With the router unplugged, start your computer. Run MBAM again.
      [6].Connect to the router again. The turn the router back on.
      [7].When it stabilizes, reboot your workstation and try to access the internet. If you have any issues, access the Router configuration page and re-enter your authentication information.
      [8]. Reboot the system and test the internet. You may have to reconfigure the router settings based on your setup.
    ===================================
    Let me know how that goes. When you have finished, please run the following:
    Download Combofix to your desktop from one of these locations:
    Link 1
    Link 2
    • Double click combofix.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. It is strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode if needed.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
    • Query- Recovery Console image
      [​IMG]
    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
      [​IMG]
    • .Click on Yes, to continue scanning for malware
    • .If Combofix asks you to update the program, allow
    • .Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • .Close any open browsers.
    • .Double click combofix.exe[​IMG] & follow the prompts to run.
    • When the scan completes it will open a text window. Please paste that log in your next reply.
    Re-enable your Antivirus software.
    Notes:
    1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
    2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
    3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
    4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
  3. Zipas

    Zipas Newcomer, in training Topic Starter

    how important is to flush dns? i have limited access to router and if improvement is not big enough, id rather not risk making more mess.

    combofix asked to be updated but didnt mention anything about recovery console. tried starting few times, got to
    and stayed there. on longest try i left it for 46min, stil nothing.

    sry for late reply
  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    The settings have been modified:
    uDefault_Search_URL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearch Bar = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    uInternet Connection Wizard,ShellNext = iexplore;uSearchURL
    ,(Default) = hxxp://www.google.com/keyword/%s
    mSearchURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f


    The Host files have been hijacked:
    Hosts: 178.63.80.143drivershqq.com
    Hosts: 178.63.80.143 www.drivershq.com
    Hosts: 178.63.80.143 downloads.drivershq.com
    Hosts: 178.63.80.143devicedoctorr.com
    Hosts: 178.63.80.143 www.devicedoctor.com
    Hosts: 178.63.80.143unibluee.com
    Hosts: 178.63.80.143 www.uniblue.com
    Hosts: 178.63.80.143 download.uniblue.com
    Hosts: 178.63.80.143drivermaxx.com
    Hosts: 178.63.80.143 www.drivermax.com
    Hosts: 178.63.80.143 innovative-sol.com
    Hosts: 178.63.80.143 www.innovative-sol.com
    Hosts: 178.63.80.143driverrobott.com
    Hosts: 178.63.80.143 www.driverrobot.com
    Hosts: 178.63.80.143drivercheckerr.com
    Hosts: 178.63.80.143 www.driverchecker.com
    Hosts: 178.63.80.143driveragentt.com
    Hosts: 178.63.80.143 www.driveragent.com
    Hosts: 178.63.80.143radarsyncc.com
    Hosts: 178.63.80.143 www.radarsync.com
    Hosts: 178.63.80.143 driver-soft.com
    Hosts: 178.63.80.143 www.driver-soft.com


    Your searches are being routed to a site in Germany:
    inetnumm: 178.63.80.128 - 178.63.80.191
    netname: HETZNER-RZ1descr
    cr: Hetznerner Online descr
    scr: Datacenternter 12
    country: DE


    Your security program has alerted you that the DSN has been modified
    This is called a DNS Changer malware infection.-handled by a DNS Flush, followed by a router reset.
    That is my recommendation.
    ===============================================
    Combofixofix determined there is already a Recovery Console installed, it won't ask you to install one:
    **Please note: If the Microsoft Windows Recovery Console is already instalComboFixboFix will continue it's malware removal procedures.
    My apology> this line is missing from my instructions. I have added it back in.
  5. Zipas

    Zipas Newcomer, in training Topic Starter

    did dns flush as instructed, ran combofix but again it stops at
    and stays there for ~30min. unfortunately im not very patient.

    i suppose there should be some kind of sign of progress on combofix, but how long do i have to wait for it to start? would be easier if i knew what to expect.

    mbam came clean as it was before, DDS still has that section with host files unchanged.
  6. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    Did you reset the router yet?

    You will find an entire Combofix Tutorial on this site, with screen shots of what to expect:
    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    NOTE: If, for some reason, Combofix refuses to run, try one of the following:
    1. Run Combofix from Safe Mode.
    2. Delete Combofix file, download fresh one, but rename combofix.exe to
    your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    3. Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.


    Please download and run the tool below named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click Rkill and choose Run as Administrator

    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    • Rkill.com
    • Rkill.scr
    • Rkill.pif
    • Rkill.exe
    • Double-click on the Rkill desktop icon to run the tool.
    • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.

    Once you've gotten one of them to run then try to immediately run the following>>>>.

    Please download exeHelper by Raktor and save it to your desktop.
    • Double-click on exeHelper.com or exeHelper.scr to run the fix tool.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file called exehelperlog.txt will be created and should open at the end of the scan)
    • A copy of that log will also be saved in the directory where you ran exeHelper.com
    • Copy and paste the contents of exehelperlog.txt in your next reply.

    Note: If the window shows a message that says "Error deleting file", please re-run the tool again before posting a log and then post the two logs together (they both will be in the one file).

    *************************************
    If normal mode still doesn't work, run BOTH tools from safe mode.

    In case #2, please post BOTH logs, rKill and Combofix.

    Patience is always requred in malware cleaning.
  7. Zipas

    Zipas Newcomer, in training Topic Starter

    i did reset router when and how instructed.

    saved combofix with different name then ran other 2.

    This log file is located at C:\rkill.log.
    Please post this only if requested to by the person helping you.
    Otherwise you can close this log when you wish.

    Rkill was run on 2011.03.02 at 14:43:54.
    Operating System: Microsoft Windows XP


    Processes terminated by Rkill or while it was running:

    C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE


    Rkill completed on 2011.03.02 at 14:44:04.




    exeHelper by Raktor
    Build 20100414
    Run at 14:44:49 on 03/02/11
    Now searching...
    Checking for numerical processes...
    Checking for sysguard processes...
    Checking for bad processes...
    Checking for bad files...
    Checking for bad registry entries...
    Resetting filetype association for .exe
    Resetting filetype association for .com
    Resetting userinit and shell values...
    Resetting policies...
    --Finished--



    then ran combofix but still same screen for 20min.

    i have idea.. when spyhunter notified me about dns change, it asked me to save or restore. since i couldnt decide later and wasnt sure, i saved it. if i used system restore before i chose save, could i chose again? if so, how can i restore to said date? or can i restore in spyhunter itself?
  8. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    Please read the following, then go to my next reply and run the script.

    You have 2 firewalls running: Uninstall one of them:
    PC Tools Firewall Plus>
    Zone Alarm
    I am removing ZoneAlarm processes with script you will run through Combofix.
    You will need to go to Add/Remove Programs in the Control Panel and uninstall any ZoneAlarm entries.
    The use Windows explorer to access My Computer> Local Drive(C)> Programs> find the ZoneAlarm folder and do a right click> Delete
    ====================================================
    You have SpyHunter running: I strongly recommend you remove this program based on the reviews below:
    ===============================================
    You decided to uninstall Mumble which I guess is the open source, low-latency, high quality voice chat software primarily intended for use while gaming because it didn't work and froze the system.
    ===============================================
    You disabled the network adapter saying that it was because you use a wireless connection- but it appears that you don't realize that you can't connect to a network without the adapter.
    ===============================================
    Uninstall ComboFix and all Backups of the files it deleted
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    Download Combofix again, following my instructions exactly on renaming it. See if t will scan now. If it will not, go back to my Reply #4 and follow the steps for running RKill and exe. Then attempt the Combofix scan. When it is finished, please leave the log in your next reply.

    Then go on to my next reply to run the script I have set up to run in Combofix:

    Your impatience has been noted. The better you follow my directions, the most quickly this will go.
  9. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    Check this site forJava Updates Update to the current v6u24 Uninstall Java(TM) 6 Update 20 in Add/Remove Programs as it is a vulnerability for the system.
    =========================================
    Please run this Custom CFScript:

    • [1]. Close any open browsers.
      [2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      [3]. Open notepad> click on Format> Uncheck 'Word Wrap'> and copy/paste the text in the code below into it:Be sure to scroll down to include ALL lines.
    Code:
    File::
    c:\program files\lavasoft\ad-aware\aawservice.exe
    c:\docume~1\useris\locals~1\temp\cpuz130\cpuz_x32.sys
    c:\windows\system32\drivers\androidusb.sys
    c:\windows\system32\zonelabs\avsys\klif.sys
    c:\windows\system32\vsdatant.sys
    DDS::
    uDefault_Search_URL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearch Bar = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    mSearchURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
    uPolicies-explorer: NoSecurityTab = 1 (0x1)
    Hosts: 178.63.80.143 drivershq.com
    Hosts: 178.63.80.143 www.drivershq.com
    Hosts: 178.63.80.143 downloads.drivershq.com
    Hosts: 178.63.80.143 devicedoctor.com
    Hosts: 178.63.80.143 www.devicedoctor.com
    Hosts: 178.63.80.143 uniblue.com
    Hosts: 178.63.80.143 www.uniblue.com
    Hosts: 178.63.80.143 download.uniblue.com
    Hosts: 178.63.80.143 drivermax.com
    Hosts: 178.63.80.143 www.drivermax.com
    Hosts: 178.63.80.143 innovative-sol.com
    Hosts: 178.63.80.143 www.innovative-sol.com
    Hosts: 178.63.80.143 driverrobot.com
    Hosts: 178.63.80.143 www.driverrobot.com
    Hosts: 178.63.80.143 driverchecker.com
    Hosts: 178.63.80.143 www.driverchecker.com
    Hosts: 178.63.80.143 driveragent.com
    Hosts: 178.63.80.143 www.driveragent.com
    Hosts: 178.63.80.143 radarsync.com
    Hosts: 178.63.80.143 www.radarsync.com
    Hosts: 178.63.80.143 driver-soft.com
    Hosts: 178.63.80.143 www.driver-soft.com
    Extra::
    File::
    c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
    c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
    c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
    Firefox::
    Firefox-:-Profile- c:\docume~1\useris\applic~1\mozilla\firefox\profiles\yak0ni2f.default\
    Driver::
    Lavasoft Ad-Aware Service
    cpuz130
    HTCAND32
    KLIF
    vsdatant
    
    
    Save this as CFScript.txt, in the same location as ComboFix.exe
    [​IMG]

    Referring to the picture above, drag CFScript into ComboFix.exe

    When finished, it will produce a log for you at C:\ComboFix.txt . Please paste in your next reply.
    ====================
  10. Zipas

    Zipas Newcomer, in training Topic Starter

    i am not running spyhunter in background, only to scan once a while. but ill remove it as advices.

    when i tried fixing mumble issue i found that i need to run 'prime95.exe' but honestly i dont remember what exactly it should have done. time it would take to run that program was unacceptable so i gave up on mumble.

    i wasnt aware that i still have zonealarm, it was already removed from add/remove as well as from program files

    changed automatic allow on pctools. was little tricky with enabling logging. i cant find advanced settings anywhere. only place i found to enable logging was profiles>advanced rules>all oher packets. but it doesnt seem to affect history.

    network adapters:
    Atheros AR5005GS wireless network adapter (enabled)
    Intel(R) pro/100 ve network connection (disabled)
    ,
    thats what i ment about disabling. it was showing icon that its not connected and it was bugging me.

    ran combofix for 90min :dead: then another hour~ in safe mode....

    same thing like always, stops at 'T' unexpected :/

    i didnt point that out yet, but if you didnt say i had problem, i wouldnt know. its not visible at all.
  11. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    My wireless router is hard wired to my desktop. I use my laptop most of the time. The icon shows with the red x saying the Local Area Network isn't connected. Sometimes that icon will stay hidden, sometimes it shows. I ignore it- I don't disable the LAN.

    I don't know what this means. But it could be this:
    Please check you time and date settings. Be sure both are correct, the Time Zone is correct, click on Update Now for internet time. All found with right click on clock> Adjust Date/Time.

    If you find anything wrong in date and time, set it correctly, reboot and then run Combofix in Normal Mode.

    Regarding Zonelarm. I think ZA has it's own uninstaller and that should be used if available. I move the remaining files with the script.

    Regarding Spyhunter: It is a running process:
    There is also a running Service:

    R means Running
    2 means Automatic

    =======================================
    I noticed this error in the DDS log:
    2011.02.23 10:12:27, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.

    That could be what Spyhunter referred to.
    ======================================
    You may not be aware of some of these things so you should probably review the installed programs, the Startup Menu using msconfig and the Startup Type of some Services. All of this is available for me to see in the logs.
     
  12. Zipas

    Zipas Newcomer, in training Topic Starter

    i see, well when i run spyhunter, it helps itself into startup list, which i remove after each time. seems i didnt when i scanned. when i uninstalled spyhunter it was stil in program files, which i removed.

    it seems its successfully synchronized on startup, but when i try to do it manualy, it says error.

    not sure if you accept images, but here it goes.

    http://i56.tinypic.com/dgpfsp.png
  13. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    Are you trying to take SpyHunter off of the Startup menu?

    To remove entries from Startup using the msconfig utility:
    • Click on Start> Run> type in msconfig> enter>
    • Click on Selective Startup
    • Choose the Startup tab:
      This is where you UNCHECK the Startup items. This does not remove the item or uninstall anything> it just stops it from starting on boot. It can be rechecked at any time if wanted.
    • To expand the Command Column, (this shows what the process 'belongs' to) hold left mouse button down on the dividing line on frame above Location and move to the right to expand.
      Uncheck all Spyhunter related entries
    • Click on Apply> OK when finished.

    NOTE:
    When you reboot the system the first time after making changes using the msconfig utility, a nag message comes up that can be ignored and closed after checking 'don't show this message again.'

    Once you make changes to the Startup menu, you must remain in Selective Startup to retain those changed. If you go back to Normal Startup, everything you unchecked will be checked again and start on boot.
    ==================================
    Click on Start> Run> type in services.msc> enter> Double click on SpyHunter 4 Service> Change Startup Type to Manual
    Exit Services
  14. Zipas

    Zipas Newcomer, in training Topic Starter

    spyhunter wasnt in services.msc

    msconfig is familiar to me.

    only items im not sure if i need on startup are - ctfmon, jusched, NvCpl.

    also got SMax4PNP and smax4, both for sound, but not sure if both needed.
  15. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    None of these need to be on Startup:
    1 ctfmon>> Ctfmon.exe activates the Alternative User Input Text Input Processor (TIP) and the Microsoft Office Language Bar. Taking this off startup won't work:
    Remove Alternative User Input Services from Text Services
    1. Click Start, point to Settings, and then click Control Panel.
    2. In the Control Panel, double-click Text Services.NOTE: In Windows XP, click Date, Time, Language, and Regional Options, and then click Regional and Language Options. On the Languages tab, click Details.
    3. Under Installed Services, select each input item that is listed, and then click Remove to remove the item. All items must be removed, one by one, except the following input service:
    English (United States)- default Keyboard United States 101
    2. jusched>> Java updater. Can be disabled: Control Panel> Java> Update tab> Uncheck 'automatically check for update> Yes to confirm> OK
    3. NvCpl>> If full entry is NvCpl.dll>> Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card. Otherwise not needed on Startup.
    4. SMax4 is part of the SoundMAX software program. It is not necessary for sound to work on your computer it is not required to run on startup.
    5. SMax4PNP>> SoundMax. up to you whether or not you want it to run on startup. Only required if you have custom settings for your sound, such as effects and environments
    =================================
    Have your original problems been resolved?
  16. Zipas

    Zipas Newcomer, in training Topic Starter

    it says its still active so ill post here.

    just had blue screen, heres what it said after restart

    its probably not first time but it was soooo long ago i couldnt remember last time.

    anything i should worry about?
  17. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +35

    These are minidump codes. They can help identify the problem driver. Please repost in the Windows BSOD forum on TechSpot.

    You started this thread over a month ago, with long times in between posts. IF you are still having what you think is malware related, you will need to do new scans and leave new logs.

    Removing all of the tools we used and the files and folders they created
    • Uninstall ComboFix and all Backups of the files it deleted
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
      [​IMG]
    • Download OTCleanIt by OldTimer and save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
    • Go to Start > All Programs > Accessories > System Tools
    • Click "System Restore".
    • Choose "Create a Restore Point" on the first screen then click "Next".
    • Give the Restore Point a name> click "Create".
    • Go back and follow the path to > System Tools.
      [*]Choose Disc Cleanup
      [*]Click "OK" to select the partition or drive you want.
      [*]Click the "More Options" Tab.
      [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


    Empty the Recycle Bin
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.