Solved Hacktool.rootkit!inf

Infected file: c:\_OTM\movedfiles\05272010_091945\c_windows.old\Windows\system31\drivers\w cscd.sys
I move this file and it is not active in your system. I will have you remove the cleaning tools and logs they created shortly. If you look in Post #10, you will see where I did the script for you to run in OTM. then if you look at the results in Post #11, you can see that all the files were moved

As for slow- I'll be back later today with some entries you can stop in HijackThis. One reason for slowness is Norton. If you are close to the subscription renewal time, consider getting rid of Norton. you can get free AV, firewall and antispyware programs that do no eat up system resources like the Norton/Symantec programs do.

Turn the Norton auto-scan off.
 
Please reopen HijackThis to 'do system scan only.' Check each of the following entries if present:

C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\system32\SearchFilterHost.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GR469A~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

Close all Windows except HijackThis and click on "Fix Checked."

Boot into Safe Mode
  • Restart your computer and start pressing the F8 key on your keyboard.
  • Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.

Click on Start> Run> type in services.msc>double click on each of the following Services and set as instructed:
Apple Mobile Device> Set startup type to Manual
Bonjour Service> Manual
Google Update Service (gupdate)> Set to Disabled> Stop the Service
iPod Service> Manual

========================================
Follow through with any of these on the system:

1. Unchecking on Startup using the msconfig utility. These are on most systems- none need to start on boot and run in the background.
2. To change the Startup type for a related Service:
Start> Run> type in services.msc> double click the Service>> if you are going to use this, set it to Manual> if you aren't going to use this> set it to Disabled.

JAVA:
[1] UNCHECK all Java entries on the Startup menu: Start> Run> msconfig> enter> Selective Startup Startup tab.
[2] Open IE> Tools> Manage add-ons> right click on Java (tm) Plug-In 2 SSV Helper' (jp2ssv.dll> Click on and Disable Java Plugin2 and Java Quick Start.
[3]. Start> Run> services.msc> double click on JavaQuickStarterService> Change Startup Type to Disabled> Stop the Service
[4] Stop auto update:. Control Panel> Java> Update tab> UNCHECK 'check automatically for updates'> Apply> Click YES when asked to confirm> OK
[5]. Make sure only the current version of Java is in Add/Remove Programs in the Control Panel. Uninstall any other versions.

ADOBE READER
1. Use msconfig to UNCHECK all; Adobe Reader entries> Apply> OK
2. Open the Adobe Reader and Disable all Toolbars-unless you use the PDF feature frequently.
3. Change the Adobe LM Service to Manual Startup.
4. Only the most current version should be listed in Add/Remove Programs.

REAL PLAYER
1. UNCHECK all 'Real', Real Player' and 'Real One' entries on the Startup menu
2. If you use Real Player disable the auto-update feature in your Tools- Preferences- Automatic Services- AutoUpdate (In RealPlayer).
Right click on Start> Explore> Programs> Common> Real Update> right click> delete the file "realshed.exe"

QUICK TIME
1. Use msconfig to UNCHECK any QuickTime entries on Startup> Apply> OK
2. Disable tray icon: Right-click on the icon and select QuickTime Preferences > Browser Plugin. Clear the check box next to "QuickTime system tray icon," and then close the settings box. The icon won't appear anymore.
3. Rename the qttask.exe file:
Right click on Start> Explore> Programs> QuickTime directory> right click on qttask.exe> rename to qttask.exeold.

[B]ITUNES Big resource user![/B]
iTunesHelper.exe
Background task installed by Apple's iTunes music player and also by version 7 of QuickTime which now comes inseparably bundled with iTunes. It is thought that this task used to be a 3rd party add-on program in the early days of Apple's iPod when its iTunes software was incompatible with many CD-Writers. This task does not need to be installed as a startup since iTunes starts it up anyway when it needs it.
1. UNCHECK on Startup menu using msconfig. It uses nearly 6MB of memory.

BONJOUR/MDSRESPONDER
Usually installed by Apple for iTunes. But also 'pre-checked' to load with the new Adobe CS3 applications, "mDNSResponder.exe" is installed somewhere in the install process. Used in iTunes files sharing
IF you do not use this process, it is best to stop and unintall it: Here’s how to safely uninstall Bonjour and remove mDNSResponder.exe
1. Go to Start > Run > type the command below and hit OK.
“%PROGRAMFILES%\Bonjour\mDNSResponder.exe” -remove
2. Right click on Start> Explore> Programs> Bonjour> right click on mdnsNSP.dll> rename to> mdnsNSP.old
3. Restart your computer**** see note regarding reboot
5. Delete the Program Files\Bonjour folder
------------------------------------------------------------------------
Are you ready to remove the cleaning tools and the logs they created? See next reply.
 
Removing all of the tools we used and the files and folders they created
  • Uninstall ComboFix and all Backups of the files it deleted
  • Click START> then RUN
  • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    CF_Uninstall-1.jpg
  • Download OTCleanIt by OldTimer and save it to your Desktop.
  • Double click OTCleanIt.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.
  • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
  • Go to Start > All Programs > Accessories > System Tools
  • Click "System Restore".
  • Choose "Create a Restore Point" on the first screen then click "Next".
  • Give the Restore Point a name> click "Create".
  • Go back and follow the path to > System Tools.
    [*]Choose Disc Cleanup
    [*]Click "OK" to select the partition or drive you want.
    [*]Click the "More Options" Tab.
    [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


Empty the Recycle Bin

Let me know if I can be of more help.
 
The Norton is for another year. I would keep it on my lap top as it does not slow it.
For this old desk top would you please suggest some good free AV, firewall and antispyware program that will do.

I will go through your last two replies for HJT and removal, and will let you know how I did it.
 
All free, all good, all recommended: (choose only one AV and one firewall, 2 or more antispyware)

Have layered Security:
  • Antivirus Software(only one): Both of the following programs are free and known to be good:
    [o]Avira Free
    [o]Avast Home
  • Firewall (only one): Use bi-directional firewall. Both of the following programs are free and known to be good:
    [o]Comodo
    [o] Zone Alarm
  • Antispyware: I recommend all of the following:
    [o]Spywareblaster: SpywareBlaster protects against bad ActiveX. It places kill bits to stop bad Active X controls from being installed. Remember to update it regularly.
    [o]IE/Spyad This places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
    [o]MVPS Hosts files This replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer.
    [o]Google Toolbar Get the free google toolbar to help stop pop up windows.
 
I completed HJT report instructions.
----
Also as instructed in safe mode set to manual apple mobile device, bonjour service, iPod service, and disables Google update services (guupdate)
---
JAVA:
(2) In IE/Tools/Manage add-ons/ I don’t see Java (tm) Plug-In 2 SSV Helper' (jp2ssv.dll
But instead there is two times Java Plug-in 1.6.0_20
Further clicking on both, does not give an option Java Plugin2 and Java Quick Start
(3) no JavaQuickStarterService in services.msc
The version in add/ remove programs is 6 update 20

It seems that I am not properly handling msconfig, as I cannot find any entries for Java, Adobe, Real Player, Quick Time, (B)Itunes in safe boot or in regular start up for both admin and personal set up.
---
I followed the instructions for removing Bonjur folder, and think I did a good job with it.
----
I tried uninstalling ComboFix as instructed, where after Combofix / Uninstall and OK, it gives a message such as: There is a newer version of ComboFix available, Like to update or no? After choosing any of these two options the next window appears with following: Current date is 2101-06-03. ComboFix has expired. Click Yes to run in REDUCED FUNCIONALITY more Click no to exit.
I continued with instruction and ran OTCleantl which removed a few files from the desktop, but did not remove ComboFix shortcut from the desktop but the ComboFix icon is no longer in downloads.
----
System restore point.
After clicking system restore in system tools a Restore system files and settings window appears, with the options:
Recommended restore:
Or
Choose a different restore point:
Choosing any of the two and clicking next still does not give an option to create a restore point.
Thus I did not continue.
Waiting for your assistance on the issues.
Thank You!
 
Norton uninstalled.
Avira installed, and I chose to create restore points.
Ran scan, log posted:


Avira AntiVir Personal
Report file date: Thursday, June 03, 2010 17:12

Scanning for 2186174 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7
Windows version : (plain) [6.1.7600]
Boot mode : Normally booted
Username : Administrator
Computer name : BUBA-PC

Version information:
BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00
AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 11:37:38
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 11:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 17:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 22:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 08:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 18:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 16:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 15:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 10:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 15:09:46
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 15:10:22
VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 15:10:22
VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 15:10:22
VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 15:10:22
VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 15:10:22
VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 15:10:22
VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 15:10:22
VBASE013.VDF : 7.10.7.225 2048 Bytes 6/2/2010 15:10:22
VBASE014.VDF : 7.10.7.226 2048 Bytes 6/2/2010 15:10:22
VBASE015.VDF : 7.10.7.227 2048 Bytes 6/2/2010 15:10:22
VBASE016.VDF : 7.10.7.228 2048 Bytes 6/2/2010 15:10:22
VBASE017.VDF : 7.10.7.229 2048 Bytes 6/2/2010 15:10:22
VBASE018.VDF : 7.10.7.230 2048 Bytes 6/2/2010 15:10:23
VBASE019.VDF : 7.10.7.231 2048 Bytes 6/2/2010 15:10:23
VBASE020.VDF : 7.10.7.232 2048 Bytes 6/2/2010 15:10:23
VBASE021.VDF : 7.10.7.233 2048 Bytes 6/2/2010 15:10:23
VBASE022.VDF : 7.10.7.234 2048 Bytes 6/2/2010 15:10:23
VBASE023.VDF : 7.10.7.235 2048 Bytes 6/2/2010 15:10:24
VBASE024.VDF : 7.10.7.236 2048 Bytes 6/2/2010 15:10:24
VBASE025.VDF : 7.10.7.237 2048 Bytes 6/2/2010 15:10:24
VBASE026.VDF : 7.10.7.238 2048 Bytes 6/2/2010 15:10:24
VBASE027.VDF : 7.10.7.239 2048 Bytes 6/2/2010 15:10:24
VBASE028.VDF : 7.10.7.240 2048 Bytes 6/2/2010 15:10:24
VBASE029.VDF : 7.10.7.241 2048 Bytes 6/2/2010 15:10:24
VBASE030.VDF : 7.10.7.242 2048 Bytes 6/2/2010 15:10:24
VBASE031.VDF : 7.10.7.245 20992 Bytes 6/2/2010 15:10:25
Engineversion : 8.2.2.4
AEVDF.DLL : 8.1.2.0 106868 Bytes 6/3/2010 15:11:09
AESCRIPT.DLL : 8.1.3.31 1352058 Bytes 6/3/2010 15:11:08
AESCN.DLL : 8.1.6.1 127347 Bytes 6/3/2010 15:11:04
AESBX.DLL : 8.1.3.1 254324 Bytes 6/3/2010 15:11:11
AERDL.DLL : 8.1.4.6 541043 Bytes 6/3/2010 15:11:04
AEPACK.DLL : 8.2.1.1 426358 Bytes 3/19/2010 11:34:51
AEOFFICE.DLL : 8.1.1.0 201081 Bytes 6/3/2010 15:10:59
AEHEUR.DLL : 8.1.1.32 2720118 Bytes 6/3/2010 15:10:57
AEHELP.DLL : 8.1.11.5 242038 Bytes 6/3/2010 15:10:39
AEGEN.DLL : 8.1.3.10 377205 Bytes 6/3/2010 15:10:37
AEEMU.DLL : 8.1.2.0 393588 Bytes 6/3/2010 15:10:34
AECORE.DLL : 8.1.15.3 192886 Bytes 6/3/2010 15:10:33
AEBB.DLL : 8.1.1.0 53618 Bytes 6/3/2010 15:10:30
AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 11:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 11:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 15:47:40
AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 11:35:46
AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 11:39:51
AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 11:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 08:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 11:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 14:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 13:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 12:10:20
RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 13:14:29

Configuration settings for the scan:
Jobname.............................: Short system scan after installation
Configuration file..................: c:\program files\avira\antivir desktop\setupprf.dat
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: Intelligent file selection
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Thursday, June 03, 2010 17:12

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'avconfig.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'conhost.exe' - '1' Module(s) have been scanned
Scan process 'avshadow.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'setup.exe' - '1' Module(s) have been scanned
Scan process 'presetup.exe' - '1' Module(s) have been scanned
Scan process 'avira_antivir_personal_en.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
Scan process 'Dwm.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'taskhost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!

Start scanning boot sectors:

Starting to scan executable files (registry).
The registry was scanned ( '1049' files ).



End of the scan: Thursday, June 03, 2010 17:13
Used time: 00:47 Minute(s)

The scan has been done completely.

0 Scanned directories
1524 Files were scanned
0 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
1524 Files not concerned
4 Archives were scanned
0 Warnings
0 Notes






---
Zone Alarm installed, as well as Spywareblaster, MVPS Hosts files as well as Google Toolbar.
I don’t use IE, and because it looked quite complicated on the first glance I postponed with IE/Spyad installment.

----
The other icons on my personalized desktop left from our work are: ComboFix shortcut, Zip file: Attached, .txt files: DDS, Attach, mbam-log, I might extracted those through the procedures for convenient copy paste.
 
I ran AV on the user and it came across:
TR/Crypt.XPACK.Gen2
TR/Patched.GY.12
And was moved to quarantine
Log included:


Avira AntiVir Personal
Report file date: Thursday, June 03, 2010 18:36

Scanning for 2186174 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7
Windows version : (plain) [6.1.7600]
Boot mode : Normally booted
Username : SYSTEM
Computer name : BUBA-PC

Version information:
BUILD.DAT : 10.0.0.567 32097 Bytes 4/19/2010 15:07:00
AVSCAN.EXE : 10.0.3.0 433832 Bytes 4/1/2010 11:37:38
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/1/2010 11:57:04
LUKE.DLL : 10.0.2.3 104296 Bytes 3/7/2010 17:33:04
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/10/2010 22:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 08:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 11/19/2009 18:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 1/20/2010 16:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 1/26/2010 15:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 3/5/2010 10:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 4/15/2010 15:09:46
VBASE006.VDF : 7.10.7.218 2294784 Bytes 6/2/2010 15:10:22
VBASE007.VDF : 7.10.7.219 2048 Bytes 6/2/2010 15:10:22
VBASE008.VDF : 7.10.7.220 2048 Bytes 6/2/2010 15:10:22
VBASE009.VDF : 7.10.7.221 2048 Bytes 6/2/2010 15:10:22
VBASE010.VDF : 7.10.7.222 2048 Bytes 6/2/2010 15:10:22
VBASE011.VDF : 7.10.7.223 2048 Bytes 6/2/2010 15:10:22
VBASE012.VDF : 7.10.7.224 2048 Bytes 6/2/2010 15:10:22
VBASE013.VDF : 7.10.7.225 2048 Bytes 6/2/2010 15:10:22
VBASE014.VDF : 7.10.7.226 2048 Bytes 6/2/2010 15:10:22
VBASE015.VDF : 7.10.7.227 2048 Bytes 6/2/2010 15:10:22
VBASE016.VDF : 7.10.7.228 2048 Bytes 6/2/2010 15:10:22
VBASE017.VDF : 7.10.7.229 2048 Bytes 6/2/2010 15:10:22
VBASE018.VDF : 7.10.7.230 2048 Bytes 6/2/2010 15:10:23
VBASE019.VDF : 7.10.7.231 2048 Bytes 6/2/2010 15:10:23
VBASE020.VDF : 7.10.7.232 2048 Bytes 6/2/2010 15:10:23
VBASE021.VDF : 7.10.7.233 2048 Bytes 6/2/2010 15:10:23
VBASE022.VDF : 7.10.7.234 2048 Bytes 6/2/2010 15:10:23
VBASE023.VDF : 7.10.7.235 2048 Bytes 6/2/2010 15:10:24
VBASE024.VDF : 7.10.7.236 2048 Bytes 6/2/2010 15:10:24
VBASE025.VDF : 7.10.7.237 2048 Bytes 6/2/2010 15:10:24
VBASE026.VDF : 7.10.7.238 2048 Bytes 6/2/2010 15:10:24
VBASE027.VDF : 7.10.7.239 2048 Bytes 6/2/2010 15:10:24
VBASE028.VDF : 7.10.7.240 2048 Bytes 6/2/2010 15:10:24
VBASE029.VDF : 7.10.7.241 2048 Bytes 6/2/2010 15:10:24
VBASE030.VDF : 7.10.7.242 2048 Bytes 6/2/2010 15:10:24
VBASE031.VDF : 7.10.7.245 20992 Bytes 6/2/2010 15:10:25
Engineversion : 8.2.2.4
AEVDF.DLL : 8.1.2.0 106868 Bytes 6/3/2010 15:11:09
AESCRIPT.DLL : 8.1.3.31 1352058 Bytes 6/3/2010 15:11:08
AESCN.DLL : 8.1.6.1 127347 Bytes 6/3/2010 15:11:04
AESBX.DLL : 8.1.3.1 254324 Bytes 6/3/2010 15:11:11
AERDL.DLL : 8.1.4.6 541043 Bytes 6/3/2010 15:11:04
AEPACK.DLL : 8.2.1.1 426358 Bytes 3/19/2010 11:34:51
AEOFFICE.DLL : 8.1.1.0 201081 Bytes 6/3/2010 15:10:59
AEHEUR.DLL : 8.1.1.32 2720118 Bytes 6/3/2010 15:10:57
AEHELP.DLL : 8.1.11.5 242038 Bytes 6/3/2010 15:10:39
AEGEN.DLL : 8.1.3.10 377205 Bytes 6/3/2010 15:10:37
AEEMU.DLL : 8.1.2.0 393588 Bytes 6/3/2010 15:10:34
AECORE.DLL : 8.1.15.3 192886 Bytes 6/3/2010 15:10:33
AEBB.DLL : 8.1.1.0 53618 Bytes 6/3/2010 15:10:30
AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 11:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 11:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 15:47:40
AVREG.DLL : 10.0.3.0 53096 Bytes 4/1/2010 11:35:46
AVSCPLR.DLL : 10.0.3.0 83816 Bytes 4/1/2010 11:39:51
AVARKT.DLL : 10.0.0.14 227176 Bytes 4/1/2010 11:22:13
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 08:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 11:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 14:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 13:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 12:10:20
RCTEXT.DLL : 10.0.53.0 97128 Bytes 4/9/2010 13:14:29

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:, F:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Thursday, June 03, 2010 18:36

Starting search for hidden objects.

The scan of running processes will be started
Scan process 'SearchFilterHost.exe' - '34' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '37' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '39' Module(s) have been scanned
Scan process 'svchost.exe' - '39' Module(s) have been scanned
Scan process 'vssvc.exe' - '55' Module(s) have been scanned
Scan process 'avscan.exe' - '95' Module(s) have been scanned
Scan process 'avscan.exe' - '36' Module(s) have been scanned
Scan process 'avcenter.exe' - '82' Module(s) have been scanned
Scan process 'avgnt.exe' - '63' Module(s) have been scanned
Scan process 'Explorer.EXE' - '181' Module(s) have been scanned
Scan process 'Dwm.exe' - '36' Module(s) have been scanned
Scan process 'taskhost.exe' - '48' Module(s) have been scanned
Scan process 'winlogon.exe' - '38' Module(s) have been scanned
Scan process 'csrss.exe' - '16' Module(s) have been scanned
Scan process 'svchost.exe' - '56' Module(s) have been scanned
Scan process 'svchost.exe' - '61' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '116' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '65' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '45' Module(s) have been scanned
Scan process 'taskeng.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '45' Module(s) have been scanned
Scan process 'conhost.exe' - '24' Module(s) have been scanned
Scan process 'avshadow.exe' - '31' Module(s) have been scanned
Scan process 'svchost.exe' - '71' Module(s) have been scanned
Scan process 'avguard.exe' - '64' Module(s) have been scanned
Scan process 'svchost.exe' - '68' Module(s) have been scanned
Scan process 'sched.exe' - '50' Module(s) have been scanned
Scan process 'spoolsv.exe' - '85' Module(s) have been scanned
Scan process 'svchost.exe' - '96' Module(s) have been scanned
Scan process 'svchost.exe' - '86' Module(s) have been scanned
Scan process 'svchost.exe' - '165' Module(s) have been scanned
Scan process 'svchost.exe' - '108' Module(s) have been scanned
Scan process 'svchost.exe' - '96' Module(s) have been scanned
Scan process 'svchost.exe' - '48' Module(s) have been scanned
Scan process 'svchost.exe' - '55' Module(s) have been scanned
Scan process 'lsm.exe' - '31' Module(s) have been scanned
Scan process 'lsass.exe' - '69' Module(s) have been scanned
Scan process 'services.exe' - '42' Module(s) have been scanned
Scan process 'wininit.exe' - '35' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!
Boot sector 'F:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '348' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\Windows.old\Program Files\Windows Sidebar\wlsrvc.dll
[DETECTION] Is the TR/Patched.GY.12 Trojan
Begin scan in 'D:\'
Begin scan in 'F:\' <Transcend>
F:\System Volume Information\_restore{73A8B94A-004F-409C-8D7F-CAC68CD91880}\RP111\A0018885.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
--> Object
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan

Beginning disinfection:
F:\System Volume Information\_restore{73A8B94A-004F-409C-8D7F-CAC68CD91880}\RP111\A0018885.exe
[DETECTION] Is the TR/Crypt.XPACK.Gen2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '488c4d85.qua'.
C:\Windows.old\Program Files\Windows Sidebar\wlsrvc.dll
[DETECTION] Is the TR/Patched.GY.12 Trojan
[NOTE] The file was moved to the quarantine directory under the name '50566266.qua'.


End of the scan: Thursday, June 03, 2010 19:40
Used time: 1:00:28 Hour(s)

The scan has been done completely.

19640 Scanned directories
474957 Files were scanned
2 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
2 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
474955 Files not concerned
3902 Archives were scanned
0 Warnings
2 Notes
449760 Objects were scanned with rootkit scan
0 Hidden objects were found
 
I'm not sure what you're doing or why you're doing it. Running Avira was not indicated. It does not remove anything in System Volume- those are the restore points. When the old restore points are dropped after the system is clean, they are removed.the malware is out of the system- even though it appears that Avira is seeing it as malware.

Let's try the cleanup again, with no more scans at this time. This is a repeat of my Reply #28. I gave you some extra, but non-essential information about stopping some programs because you mentioned being slow. If you did a Combofix uninstall, there is not reason for that message to appear:
========================================
Removing all of the tools we used and the files and folders they created
  • Uninstall ComboFix and all Backups of the files it deleted
  • Click START> then RUN
  • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    CF_Uninstall-1.jpg
  • Download OTCleanIt by OldTimer and save it to your Desktop.
  • Double click OTCleanIt.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.
  • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
  • Go to Start > All Programs > Accessories > System Tools
  • Click "System Restore".
  • Choose "Create a Restore Point" on the first screen then click "Next".
  • Give the Restore Point a name> click "Create".
  • Go back and follow the path to > System Tools.
    [*]Choose Disc Cleanup
    [*]Click "OK" to select the partition or drive you want.
    [*]Click the "More Options" Tab.
    [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


Empty the Recycle Bin
 
After installing Avira, I believe it start running the scan itself, or I started unintentionally.

I again have a problem with restore point.
Start-All Programs- Accessories- System Tools- System Restore-does not give me a screen with the option to choose “Create a Restore Point”, what it does in the first screen it informs of following:
Restore System files and settings:
System restore can help…..
System restore does not effect….
Clicking on Next, it shows a new screen:
Restore your computer to the state it was before the select even
With some windows update
In it there is an option to scan for affected files or to click next again, which I did not do.
Please advice
 
System Restore Troubleshooting:

  • [1]: Make sure that the System Restore service is running
  • Click Start> Run> type compmgmt.msc> Enter> Expand Services> click System Restore Services..
    [o]If the Status of System Restore Service is not Started, click Start on the toolbar to start it.
  • Click Start> Run, type CMD> Enter>
    [o] Type Net Start at the command prompt to make sure that the System Restore Service is up and is running.
    [o] If the System Restore Service is not listed, type net start "System Restore Service", and then press Enter.

    [2]: Make sure that System Restore is enabled on the drives where you want System Restore enabled
  • Click Start> right-click My Computer> Properties> System Restore tab.
    [o]If the System Restore is enabled, the Status column of a drive will show Monitoring.
    [o]If not, Turn off System Restore on all drives, and then click OK to enable it.

    [3]:Make sure that you have sufficient disk space on all the drives where System Restore is enabled
  • Click Start> Run> type diskmgmt.msc> Enter> check each drive System Restore is monitoring.
    [o] If any drive has < than 50 MB, System Restore will suspend and remove all restore points to free disk space.
    [o]You should have already received a low free disk space message.
    [o] System Restore will resume monitoring when free disk space reaches 200 MB.
    Note: In most cases you do not have to have System Restore monitor Partitions/drives other than the one Windows is installed on. System Restore does not monitor data files.

    [4]: View the event logs to investigate System Restore service errors
  • Click Start> Run> type ]eventvwr.msc> Enter> Click System category.
  • Click Source tab to sort by name> find sr or srservice> Double-click each of these services.
  • See event description for any indication of the cause of the problem.

    [5]: Boot in safe mode and run the System Restore tool
  • Restart the computer. Immediately after the screen goes blank for the first time, or after the BIOS post ends, start taping the F8 key repeatedly. The Windows Advanced Options menu appears.
  • Select Safe Mode> ENTER. As files load they will scroll down the screen.
  • Log on to Administrator account. If a password was never set, leave the password blank and press ENTER or click the green arrow.
  • Click No in the safe mode information screen to start System Restore.
  • Select 'Restore my computer to an earlier time> Next> Choose available date from dates in BOLD print.
  • Click Next to begin restoring the system to a previous state.

My guess is that your hard drive is out of 'space':
C: is FIXED (NTFS) - 34 GiB total, 13.732 GiB free.
D: is FIXED (NTFS) - 40 GiB total, 16.746 GiB free.
Total hard drive space = 74GB
Total Percent free = 41%


System Requirements for Windows 7 Ultimate:
16 GB available hard disk space (32-bit)
Windows XP Mode requires an additional 1 GB of RAM, an additional 15 GB of available hard disk space,
For the download version, an additional 3GB is required.

There may be some recommendation of advisable HD size and RAM for Windows 7 Ultimate, but I couldn't find it.

By the way, you might want to create a shortcut for System Restore and put it on the Desktop:
All Programs> Accessories> System Tools> Do a right click on system Restore> Send To> Desktop to create a shortcut> Close

I think it's a pain to have to go the Accessories path. I keep the System Restore shortcut in my Quick launch Toolbar.
 
1)
*
After typing compmgmt.msc in Run, I don’t see any option for Expand Services nor System Restore Services.
But rather on the left side of the screen, Computer Management with System Tools, Task Schedule… and in the middle of the screen System Tools, Storage, Services and Applications.
In Services I can not find System Restore Services but only System Event Notification Service among others.
*
I typed Net Start at the command prompt following CMD on run. The command completed successfully, but no System restore Service is listed.
I do not know if I am doing the next step correctly but I followed and typed: net start “System Restore Service”, and got message: The syntax for this command is: NET START (service), so I typed: NET Start “System Restore Service” and got message: The service name is invalid. I also tried and typed only: just
System Restore Service with and without Net Start
Please assist
V
 
You mention
“System Requirements for Windows 7 Ultimate:
16 GB available hard disk space (32-bit)
Windows XP Mode requires an additional 1 GB of RAM, an additional 15 GB of available hard disk space,
For the download version, an additional 3GB is required.”
Why do I have a Windows XP Mode that requires more space, or is this something that is always there with Windows 7
 
Ved, the system requirement was a copy and paste from a Microsoft site. I can't answer the why question- you're going to have to explore that on your own.

I asked:
1. Did you turn off System Restore? There are no System Restore points. This error is related to that:
5/21/2010 1:55:11 PM, Error: volsnap [36] - The shadow copies of volume C: were aborted because the shadow copy storage could not grow due to a user imposed limit.
You answered:
1. System restores:
When I originally ran Norton Scan and when it found this virus, I was asked to turn off System Restore points prior to new scan. I did that, and after it I thought I switched the restore points back on. I just checked and Restore point for C: is on, but restore point for D: is off. Should I turn the restore point for D: back on?
You told me you turned System Restore off. So you did have the function. What did you do when you turned it off? In Windows 7, system Restore is located in system Protection. Windows creates the restore points automatically and the user can also create their own restore point.

I have a netbook with Windows 7. Doing a right click on Computer> Properties> System Protection brings up the SR screen. On mine, it shows protection On o on Drive C and Off[/b on the other drive which is Recovery. I click on Configure in which I can "configure restore settings, manage disc space and delete restore points."

The top section allows you to choose one of 2 ways you want 'restore' to save, then the last setting being 'Turn off system protection.' There is a slider in this section which allows how much disc space you want to give over to SR. It starts with 0 use on disc space and goes up in increments, the first slide move goes to 20%.

If you choose one of the first 2 options, you will have to determine how much disc space to allow. So if you want to use this function, you must give it space.

I am fairly new to Windows 7 and have the Starter on my mini. It's possible your setting might be different if you have the full version- but I would think they would be the same. So check these settings in accordance to what I've written above.

While I was there, I went ahead and created my own restore point> Apply> OK. I noticed that SR was turned off. I didn't turn it off and wonder if it's off by default.
 
You are absolutely right. Through Computer-Properties-System protection I get to SR Screen.
And for the Protection status it shows On for both Local Disk C (System) and for Local Disk D.
Beside option Configure, as you know , it gives an option to Create a restore point for the drives that have system protection turned on.

Further highlighting C and clicking Configure new screen shows:
On top:
*Restore system settings and previous version of files (option that is automatically chosen)
*Only restore previous versions of files
*Turn off system protection
In middle:
Disk Space Usage:
Current Usage set to 292.11MB
Max Usage:
2% (700.18MB)
At the bottom:
Option to Delete all restore points (this includes system settings and previous versions of files)

Highlighting D and clicking Configure new screen shows:
On top:
*Restore system settings and previous version of files (option that is automatically chosen)
*Only restore previous versions of files
*Turn off system protection
In middle:
Disk Space Usage:
Current Usage set to 181.78MB
Max Usage:
3% (1.07GB) (I have cleaned this drive)
At the bottom:
Option to Delete all restore points (this includes system settings and previous versions of files)

Please advice of what to do.
 
If I understand it correctly, previously you advise me to: set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points

Then I followed a guide lines to “create Restore Point” through the avenue which I flowed: all programs- accessories- system tooles, but for some reason I could not complete the instruction to create a new restore point.

Now, to my understanding you are telling me that the screen information tells you it’s working, but we still did not create a new restore point, if I am not mistaken, or whatever else we were supposed to do to complete this process.
 
Creating a Restore Point in windows 7:
  • Click on Start> right click on Computer> Properties
  • Select System Protection
  • Click on the Create button (near bottom)
  • Type a name for the Restore Point
  • Click on Create again to save the restore point.

I will modify the directions for Windows 7. Sorry for the confusion. Let me know if this works okay.
 
Following your instructions I have managed to create a new Restore Point in User – Drive C- and named it Restore Point 1.
Is this ok?
Should I also create a new Restore Point for Admin? Should I create a new restore point for drive D
What is the next step?
 
No, you're clean and we're through. If needed run Post #28 or 34 again.

As I understood it you had a problem with finding and setting a new restore points at the end.
 
I followed Post #28 and did a Clean Up in the system restore section for C.
When I completed that, I went back to Start-All programs-Accessories- System Tools and System Restore, but instead of giving me an option as it did just before, where among others I chose Disk Cleanup, instead as soon as I click System Restore the screen shows up: Starting System Restore and soon after it exchanges for the new screen, the same one that was bugging before reading: Restore system files and settings…. That further gives only an option to restore computer to the state it was before the selected event. For which it lists Restore Point 2 Type: Manual, created following your previous p[ost that I need to restore points for both drivers.
So, the point is that it does not let me, or I do not know how, to Clean Up Restore Point, which I wanted to do for D as I just did for C.
In addition to mention to empty Recycle Bin.
After Cleningup restore point for C nothing shows up in recycle bin, so I don’t know if I competed v=even the cleanup for C.
Please advice.
 
This is what I wrote up for Windows 7:
  • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.

    Creating a Restore Point in Windows 7:
  • Click on Start> right click on Computer> Properties
  • Select System Protection
  • Click on the Create button (near bottom)
  • Type a name for the Restore Point
  • Click on Create again to save the restore point.

    Deleting all but the most recent System Protection point in Windows

    7
  • Click Start, type Cleanmgr.exe and press ENTER
  • Select the drive-letter from the list and click OK
  • Click Clean up system files
    This restarts Disk Cleanup to run in elevated mode.
  • Select the drive-letter from the list and click OK
  • Click the More Options tab
    w7-srp2.png
  • Click the Clean up… button under System Restore and Shadow Copies.
  • Click OK.
or
Deleting all System Protection Points in Windows 7
  • Click Start> right-click (My)Computer> Properties
  • Click System protection link in the left pane
  • In the System Protection options, select a drive-letter and click Configure
    w7-srp1.png
  • Click Delete, and click Continue when prompted.
    [*] Click OK, OK.


See this site for reference: http://www.winhelponline.com/blog/how-to-delete-system-restore-points-windows-7/

Empty the Recycle Bin

I always remind people to take out the trash! IF there isn't any, okay.
You should be through now. Is it possible you have a Recovery or Repair on the D Drive- so it won't have restore points.
 
Back