[Referred] Dns settings have been modified and regular check

Status
Not open for further replies.

Zipas

Posts: 8   +0
im not too concerned about being infected, but if it doesnt find anything, it doesnt mean im safe. pc is so old that it could have some bads hidden.

ive uninstalled mumble after scan, didnt run for me anyway, froze pc.

spyhunter noticed that dns settings have been modified. ive disabled network adapter some time ago since i use wireless. if its not the reason, i dont know why.

btw i dont run any printers, only scaner.

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5850

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

2011.02.23 10:52:54
mbam-log-2011-02-23 (10-52-54).txt

Scan type: Quick scan
Objects scanned: 149213
Time elapsed: 5 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


GMER 1.0.15.15530 - http://www.gmer.net
Rootkit quick scan 2011-02-23 10:14:35
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1200JB-00EVA0 rev.15.05R15
Running: 1ijrz1oj.exe; Driver: C:\DOCUME~1\Useris\LOCALS~1\Temp\ffryipod.sys


---- System - GMER 1.0.15 ----

SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xF749E2A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xF74A9910]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateProcessEx [0xF495482E]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwCreateSection [0xF4954652]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ZwLoadDriver [0xF495478C]
Code 8769B4F4 NlsAnsiCodePage
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) NtCreateSection
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/AVAST Software) ObMakeTemporaryObject

---- Devices - GMER 1.0.15 ----

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 870A4630
Device \Driver\atapi \Device\Ide\IdePort0 870A4630
Device \Driver\atapi \Device\Ide\IdePort1 870A4630
Device \Driver\atapi \Device\Ide\IdePort2 870A4630
Device \Driver\atapi \Device\Ide\IdePort3 870A4630
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-12 870A4630
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 87069F00
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target2Lun0 87069F00
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 87069F00
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target3Lun0 87069F00
Device \Driver\d347prt \Device\Scsi\d347prt1 87069F00
Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Ntfs \Ntfs 8733EA20

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)

Device \FileSystem\Fastfat \Fat aswSP.SYS (avast! self protection module/AVAST Software)
Device \FileSystem\Fastfat \Fat 85A98438

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat aswMon2.SYS (avast! File System Filter Driver for Windows XP/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Ip pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Tcp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\Udp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)
AttachedDevice \Driver\Tcpip \Device\RawIp pctgntdi.sys (PC Tools Generic TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/AVAST Software)

---- Modules - GMER 1.0.15 ----

Module _________ F7400000-F7418000 (98304 bytes)

---- EOF - GMER 1.0.15 ----



DDS (Ver_10-12-12.02) - NTFSx86
Run by Useris at 10:28:48,65 on 2011.02.23
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1257.370.1033.18.1023.509 [GMT 2:00]

AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: PC Tools Firewall Plus *Disabled*

============== Running Processes ===============

C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\Analog Devices\SoundMAX\smax4.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PeerBlock\peerblock.exe
C:\Program Files\DeskPins\DeskPins.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Useris\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://youtube.com/
uDefault_Search_URL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearch Bar = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
uRun: [Gadwin PrintScreen] c:\program files\gadwin systems\printscreen\PrintScreen.exe /nosplash
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [PeerBlock] c:\program files\peerblock\peerblock.exe
mRun: [TWCU] "c:\program files\tp-link\twcu\TWCU.exe" -nogui
mRun: [SoundMAXPnP] c:\program files\analog devices\soundmax\SMax4PNP.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [00PCTFW] "c:\program files\pc tools firewall plus\FirewallGUI.exe" -s
mRun: [SoundMax] "c:\program files\analog devices\soundmax\smax4.exe" /tray
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
StartupFolder: c:\docume~1\useris\startm~1\programs\startup\deskpins.lnk - c:\program files\deskpins\DeskPins.exe
uPolicies-explorer: NoSecurityTab = 1 (0x1)
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258146703592
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/webplayer/stage6/windows/DivXBrowserPlugin.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258147288248
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://active.macromedia.com/flash2/cabs/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
Hosts: 178.63.80.143 drivershq.com
Hosts: 178.63.80.143 www.drivershq.com
Hosts: 178.63.80.143 downloads.drivershq.com
Hosts: 178.63.80.143 devicedoctor.com
Hosts: 178.63.80.143 www.devicedoctor.com

Note: multiple HOSTS entries found. Please refer to Attach.txt

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\useris\applic~1\mozilla\firefox\profiles\yak0ni2f.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: browser.startup.homepage - hxxp://watchthemoviesforfree.com/
FF - component: c:\documents and settings\useris\application data\mozilla\firefox\profiles\yak0ni2f.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\useris\application data\mozilla\firefox\profiles\yak0ni2f.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCore.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Feed Filter: facebookfilter@chocolatesoftware.com - %profile%\extensions\facebookfilter@chocolatesoftware.com
FF - Ext: bit.ly preview: bitlypreview@jay.ridgeway - %profile%\extensions\bitlypreview@jay.ridgeway
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\java\jre6\lib\deploy\jqs\ff
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension

============= SERVICES / DRIVERS ===============

R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2005-12-6 155136]
R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2005-12-6 5248]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-11-20 64288]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-11-21 294608]
R1 pctgntdi;pctgntdi;c:\windows\system32\drivers\pctgntdi.sys [2009-12-19 233136]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-12-16 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-12-16 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-21 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-10-19 40384]
R2 PCTAppEvent;PCTAppEvent Driver;c:\windows\system32\drivers\PCTAppEvent.sys [2009-12-19 88040]
R2 PCToolsFirewallPlus;PC Tools Firewall Plus;c:\program files\pc tools firewall plus\FWService.exe [2009-12-19 818432]
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma~1\spyhun~1\SH4SER~1.EXE [2010-5-18 327064]
R3 pbfilter;pbfilter;c:\program files\peerblock\pbfilter.sys [2011-1-4 19056]
R3 PCTFW-PacketFilter;PCTools Firewall - Packet filter driver;c:\windows\system32\drivers\pctNdis-PacketFilter.sys [2009-12-19 70664]
R3 pctNDIS;PC Tools Driver;c:\windows\system32\drivers\pctNdis.sys [2009-12-19 58816]
R3 pctplfw;pctplfw;c:\windows\system32\drivers\pctplfw.sys [2009-12-19 115216]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-12-16 7408]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" --> c:\program files\lavasoft\ad-aware\AAWService.exe [?]
S3 cpuz130;cpuz130;\??\c:\docume~1\useris\locals~1\temp\cpuz130\cpuz_x32.sys --> c:\docume~1\useris\locals~1\temp\cpuz130\cpuz_x32.sys [?]
S3 HTCAND32;HTC Device Driver;c:\windows\system32\drivers\androidusb.sys --> c:\windows\system32\drivers\ANDROIDUSB.sys [?]
S3 KLIF;KLIF;\??\c:\windows\system32\zonelabs\avsys\klif.sys --> c:\windows\system32\zonelabs\avsys\KLIF.SYS [?]
S3 PCTFW-DNS;PCTools Firewall - DNS driver;c:\windows\system32\drivers\pctNdis-DNS.sys [2009-12-19 32680]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys --> c:\windows\system32\vsdatant.sys [?]

=============== Created Last 30 ================

2011-02-14 22:25:09 74072 ----a-w- c:\windows\system32\XAPOFX1_5.dll
2011-02-14 22:25:08 527192 ----a-w- c:\windows\system32\XAudio2_7.dll
2011-02-14 22:25:08 239960 ----a-w- c:\windows\system32\xactengine3_7.dll
2011-02-14 22:25:07 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-02-14 22:25:06 248672 ----a-w- c:\windows\system32\d3dx11_43.dll
2011-02-14 22:25:06 1868128 ----a-w- c:\windows\system32\d3dcsx_43.dll
2011-02-14 22:25:05 470880 ----a-w- c:\windows\system32\d3dx10_43.dll
2011-02-14 22:25:03 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-02-14 22:23:34 -------- d-----w- c:\docume~1\useris\applic~1\RIFT
2011-02-01 14:47:07 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2011-02-01 14:35:52 -------- d-----w- c:\docume~1\useris\locals~1\applic~1\Downloaded Installations
2011-01-30 12:57:00 103864 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll
2011-01-30 12:57:00 103864 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll

==================== Find3M ====================

2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2011-01-13 08:47:35 38848 ----a-w- c:\windows\avastSS.scr
2011-01-07 14:09:02 290048 ----a-w- c:\windows\system32\atmfd.dll
2010-12-31 13:10:33 1854976 ----a-w- c:\windows\system32\win32k.sys
2010-12-22 12:34:28 301568 ----a-w- c:\windows\system32\kerberos.dll
2010-12-20 23:59:20 916480 ----a-w- c:\windows\system32\wininet.dll
2010-12-20 23:59:19 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-12-20 23:59:19 1469440 ------w- c:\windows\system32\inetcpl.cpl
2010-12-20 17:26:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2010-12-20 12:55:26 385024 ----a-w- c:\windows\system32\html.iec
2010-12-09 15:15:09 718336 ----a-w- c:\windows\system32\ntdll.dll
2010-12-09 14:30:22 33280 ----a-w- c:\windows\system32\csrsrv.dll
2010-12-09 13:42:26 2148864 ------w- c:\windows\system32\ntoskrnl.exe
2010-12-09 13:07:07 2027008 ------w- c:\windows\system32\ntkrnlpa.exe

============= FINISH: 10:30:13,96 ===============



UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-12-12.02)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 2004.12.14 17:55:28
System Uptime: 2011.02.23 10:19:19 (0 hours ago)

Motherboard: Intel Corporation | | D865PERL
Processor: Intel(R) Pentium(R) 4 CPU 3.00GHz | J2E1 | 2992/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 112 GiB total, 12,514 GiB free.
D: is CDROM ()
E: is CDROM ()
F: is CDROM ()
G: is CDROM ()
H: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Atheros AR5005GS Wireless Network Adapter
Device ID: PCI\VEN_168C&DEV_0013&SUBSYS_2051168C&REV_01\4&2E98101C&0&10F0
Manufacturer: Atheros
Name: Atheros AR5005GS Wireless Network Adapter
PNP Device ID: PCI\VEN_168C&DEV_0013&SUBSYS_2051168C&REV_01\4&2E98101C&0&10F0
Service: AR5416

Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Intel(R) PRO/100 VE Network Connection
Device ID: PCI\VEN_8086&DEV_1050&SUBSYS_30208086&REV_01\4&2E98101C&0&40F0
Manufacturer: Intel
Name: Intel(R) PRO/100 VE Network Connection
PNP Device ID: PCI\VEN_8086&DEV_1050&SUBSYS_30208086&REV_01\4&2E98101C&0&40F0
Service: E100B

==== System Restore Points ===================

RP124: 2010.12.27 14:12:58 - System Checkpoint
RP125: 2010.12.29 14:46:27 - System Checkpoint
RP126: 2010.12.30 16:22:00 - System Checkpoint
RP127: 2011.01.04 18:52:14 - System Checkpoint
RP128: 2011.01.12 18:59:34 - Software Distribution Service 3.0
RP129: 2011.01.15 03:20:38 - System Checkpoint
RP130: 2011.01.20 07:57:41 - System Checkpoint
RP131: 2011.01.25 17:23:24 - System Checkpoint
RP132: 2011.01.29 15:32:32 - System Checkpoint
RP133: 2011.02.01 12:49:30 - System Checkpoint
RP134: 2011.02.01 16:37:33 - Installed HTC Sync.
RP135: 2011.02.01 16:47:07 - Installed Windows XP Wdf01007.
RP136: 2011.02.02 17:25:49 - Software Distribution Service 3.0
RP137: 2011.02.05 18:08:17 - System Checkpoint
RP138: 2011.02.06 18:12:04 - System Checkpoint
RP139: 2011.02.08 17:38:31 - System Checkpoint
RP140: 2011.02.10 19:13:27 - Software Distribution Service 3.0
RP141: 2011.02.12 19:43:45 - System Checkpoint
RP142: 2011.02.14 16:04:33 - System Checkpoint
RP143: 2011.02.15 00:23:12 - Installed RIFT
RP144: 2011.02.16 18:26:17 - System Checkpoint
RP145: 2011.02.18 19:38:13 - System Checkpoint
RP146: 2011.02.20 08:54:47 - System Checkpoint
RP147: 2011.02.21 14:46:42 - System Checkpoint
RP148: 2011.02.21 14:58:18 - Removed RIFT
RP149: 2011.02.21 15:00:05 - Removed HTC Driver Installer.
RP150: 2011.02.21 15:02:15 - Removed HTC Sync.
RP151: 2011.02.21 15:03:43 - Removed HTC BMP USB Driver.

==== Hosts File Hijack ======================

Hosts: 178.63.80.143 drivershq.com
Hosts: 178.63.80.143 www.drivershq.com
Hosts: 178.63.80.143 downloads.drivershq.com
Hosts: 178.63.80.143 devicedoctor.com
Hosts: 178.63.80.143 www.devicedoctor.com
Hosts: 178.63.80.143 uniblue.com
Hosts: 178.63.80.143 www.uniblue.com
Hosts: 178.63.80.143 download.uniblue.com
Hosts: 178.63.80.143 drivermax.com
Hosts: 178.63.80.143 www.drivermax.com
Hosts: 178.63.80.143 innovative-sol.com
Hosts: 178.63.80.143 www.innovative-sol.com
Hosts: 178.63.80.143 driverrobot.com
Hosts: 178.63.80.143 www.driverrobot.com
Hosts: 178.63.80.143 driverchecker.com
Hosts: 178.63.80.143 www.driverchecker.com
Hosts: 178.63.80.143 driveragent.com
Hosts: 178.63.80.143 www.driveragent.com
Hosts: 178.63.80.143 radarsync.com
Hosts: 178.63.80.143 www.radarsync.com
Hosts: 178.63.80.143 driver-soft.com
Hosts: 178.63.80.143 www.driver-soft.com

==== Installed Programs ======================

Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Photoshop 6.0
Adobe Reader 9.4.2
Adobe Shockwave Player 11
Adobe SVG Viewer 3.0
AIM 6
µTorrent
avast! Free Antivirus
Canon CanoScan Toolbox 4.5
CCleaner
Compatibility Pack for the 2007 Office system
DeskPins (remove only)
DiagramStudio 4.0
dirLock
DivX Setup
ffdshow
FLV Player 2.0 (build 25)
Full Tilt Poker.Net
Gadwin PrintScreen
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976002-v5)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
ImageDrive (Ahead Software)
InCD EasyWrite Reader (Ahead Software)
Intel(R) PRO Network Adapters and Drivers
Java Auto Updater
Java(TM) 6 Update 20
K-Lite Codec Pack 2.34 Full
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft WSE 2.0 Runtime
mIRC
Mozilla Firefox (3.6.13)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
Mumble and Murmur
NVIDIA Drivers
OmniPage SE 2.0
PC Tools Firewall Plus 6.0
PeerBlock 1.1 (r518)
QFolder
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Skype™ 3.8
SoundMAX
Spybot - Search & Destroy
SpyHunter
SUPERAntiSpyware Free Edition
TP-LINK Client Installation Program
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB973874)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB943729)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
VentriloMIX
VirtualCloneDrive
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
Wow Web Stats Client v2.4
Zune Desktop Theme

==== Event Viewer Messages From Past Week ========

2011.02.23 10:12:27, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.
2011.02.17 07:58:27, error: Service Control Manager [7034] - The SpyHunter 4 Service service terminated unexpectedly. It has done this 1 time(s).
2011.02.17 07:58:19, error: Service Control Manager [7034] - The SoundMAX Agent Service service terminated unexpectedly. It has done this 1 time(s).
2011.02.17 07:58:11, error: Service Control Manager [7034] - The Pml Driver HPZ12 service terminated unexpectedly. It has done this 1 time(s).
2011.02.17 02:12:20, error: ipnathlp [31008] - The DNS proxy agent was unable to read the local list of name-resolution servers from the registry. The data is the error code.
2011.02.16 16:12:23, error: Service Control Manager [7000] - The Lavasoft Ad-Aware Service service failed to start due to the following error: The system cannot find the path specified.

==== End Of File ===========================
 
Welcome to TechSpot! It is fairly easy to see where the problems are. I am going to start you out with very specific instructions:

You will need to do a DNS Flush, then reset your router.
Start> Run> type cmd> enter> at the C prompt type ipconfig /flushdns (note space before the /)

Exit the Command prompt when finished and shut the system down.-

  • [1]. Shut down your computer, and any other computer connected to your router.
    [2]. On the back of the router, there should be a small hole or button labelled RESET. Using a bent paper clip or similar item, hold that in continuously for twenty seconds.
    [3]. Unplug the router. Wait sixty seconds.
    [4].Now holding again the reset button, plug it back in. Continue holding the reset button for twenty seconds. Unplug the router again.
    [5].With the router unplugged, start your computer. Run MBAM again.
    [6].Connect to the router again. The turn the router back on.
    [7].When it stabilizes, reboot your workstation and try to access the internet. If you have any issues, access the Router configuration page and re-enter your authentication information.
    [8]. Reboot the system and test the internet. You may have to reconfigure the router settings based on your setup.
===================================
Let me know how that goes. When you have finished, please run the following:
Download Combofix to your desktop from one of these locations:
Link 1
Link 2
http://www.forospyware.com/sUBs/ComboFix.exe
  • Double click combofix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. It is strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode if needed.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Query- Recovery Console image
    RcAuto1.gif

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
    whatnext.png
  • .Click on Yes, to continue scanning for malware
  • .If Combofix asks you to update the program, allow
  • .Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • .Close any open browsers.
  • .Double click combofix.exe
    cf-icon.jpg
    & follow the prompts to run.
  • When the scan completes it will open a text window. Please paste that log in your next reply.
Re-enable your Antivirus software.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
 
how important is to flush dns? i have limited access to router and if improvement is not big enough, id rather not risk making more mess.

combofix asked to be updated but didnt mention anything about recovery console. tried starting few times, got to
'T' was unexpected at this time.
and stayed there. on longest try i left it for 46min, stil nothing.

sry for late reply
 
The settings have been modified:
uDefault_Search_URL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearch Bar = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
uInternet Connection Wizard,ShellNext = iexplore;uSearchURL
,(Default) = hxxp://www.google.com/keyword/%s
mSearchURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f


The Host files have been hijacked:
Hosts: 178.63.80.143drivershqq.com
Hosts: 178.63.80.143 www.drivershq.com
Hosts: 178.63.80.143 downloads.drivershq.com
Hosts: 178.63.80.143devicedoctorr.com
Hosts: 178.63.80.143 www.devicedoctor.com
Hosts: 178.63.80.143unibluee.com
Hosts: 178.63.80.143 www.uniblue.com
Hosts: 178.63.80.143 download.uniblue.com
Hosts: 178.63.80.143drivermaxx.com
Hosts: 178.63.80.143 www.drivermax.com
Hosts: 178.63.80.143 innovative-sol.com
Hosts: 178.63.80.143 www.innovative-sol.com
Hosts: 178.63.80.143driverrobott.com
Hosts: 178.63.80.143 www.driverrobot.com
Hosts: 178.63.80.143drivercheckerr.com
Hosts: 178.63.80.143 www.driverchecker.com
Hosts: 178.63.80.143driveragentt.com
Hosts: 178.63.80.143 www.driveragent.com
Hosts: 178.63.80.143radarsyncc.com
Hosts: 178.63.80.143 www.radarsync.com
Hosts: 178.63.80.143 driver-soft.com
Hosts: 178.63.80.143 www.driver-soft.com


Your searches are being routed to a site in Germany:
inetnumm: 178.63.80.128 - 178.63.80.191
netname: HETZNER-RZ1descr
cr: Hetznerner Online descr
scr: Datacenternter 12
country: DE


Your security program has alerted you that the DSN has been modified
This is called a DNS Changer malware infection.-handled by a DNS Flush, followed by a router reset.
That is my recommendation.
===============================================
Combofixofix determined there is already a Recovery Console installed, it won't ask you to install one:
**Please note: If the Microsoft Windows Recovery Console is already instalComboFixboFix will continue it's malware removal procedures.
My apology> this line is missing from my instructions. I have added it back in.
 
did dns flush as instructed, ran combofix but again it stops at
'T' was unexpected at this time.
and stays there for ~30min. unfortunately im not very patient.

i suppose there should be some kind of sign of progress on combofix, but how long do i have to wait for it to start? would be easier if i knew what to expect.

mbam came clean as it was before, DDS still has that section with host files unchanged.
 
Did you reset the router yet?

You will find an entire Combofix Tutorial on this site, with screen shots of what to expect:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix

NOTE: If, for some reason, Combofix refuses to run, try one of the following:
1. Run Combofix from Safe Mode.
2. Delete Combofix file, download fresh one, but rename combofix.exe to
your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
3. Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.


Please download and run the tool below named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
  • Rkill.com
  • Rkill.scr
  • Rkill.pif
  • Rkill.exe
  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

Once you've gotten one of them to run then try to immediately run the following>>>>.

Please download exeHelper by Raktor and save it to your desktop.
  • Double-click on exeHelper.com or exeHelper.scr to run the fix tool.
  • A black window should pop up, press any key to close once the fix is completed.
  • A log file called exehelperlog.txt will be created and should open at the end of the scan)
  • A copy of that log will also be saved in the directory where you ran exeHelper.com
  • Copy and paste the contents of exehelperlog.txt in your next reply.

Note: If the window shows a message that says "Error deleting file", please re-run the tool again before posting a log and then post the two logs together (they both will be in the one file).

*************************************
If normal mode still doesn't work, run BOTH tools from safe mode.

In case #2, please post BOTH logs, rKill and Combofix.

Patience is always requred in malware cleaning.
 
i did reset router when and how instructed.

saved combofix with different name then ran other 2.

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 2011.03.02 at 14:43:54.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:

C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE


Rkill completed on 2011.03.02 at 14:44:04.




exeHelper by Raktor
Build 20100414
Run at 14:44:49 on 03/02/11
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--



then ran combofix but still same screen for 20min.

'T' was unexpected at this time.

i have idea.. when spyhunter notified me about dns change, it asked me to save or restore. since i couldnt decide later and wasnt sure, i saved it. if i used system restore before i chose save, could i chose again? if so, how can i restore to said date? or can i restore in spyhunter itself?
 
Please read the following, then go to my next reply and run the script.

You have 2 firewalls running: Uninstall one of them:
PC Tools Firewall Plus>
PC Tools Firewall Plus added these drivers:
# pctNdis.sys - NDIS driver
# pctNdis-DNS.sys - NDIS - DNS driver

It can also notify the user about applications that tries to inject or modify another application without the user's knowledge. (This is probably responsible for the DNS change- my Edit)

The free firewall provides application logging of the firewall and network activity. Note that this will not work unless you modify the application rules to log the activity of every application:

PC Tools personal firewall also includes a built-in updater and the ability to block all network connections Click to view image. on the computer that it is securing

Change the default settings in the firewall Click to view image. program by unchecking the boxes for "Automatically allow known applications" and "Automatically allow applications with valid digital signatures." This will stop the firewall for auto-creating firewall rules for any program.

http://www.brighthub.com/computing/smb-security/articles/105343.aspx
Zone Alarm
I am removing ZoneAlarm processes with script you will run through Combofix.
You will need to go to Add/Remove Programs in the Control Panel and uninstall any ZoneAlarm entries.
The use Windows explorer to access My Computer> Local Drive(C)> Programs> find the ZoneAlarm folder and do a right click> Delete
====================================================
You have SpyHunter running: I strongly recommend you remove this program based on the reviews below:
You have probably not reviewed the performance of Spyhunter:
the memory usage by its SpyHunter4.exe is using 95MB which is a lot of memory compared to other anti-malware programs that also offer real-time protection. This memory usage by SpyHunter application is unacceptable especially if the program is idle in the notification area in Windows.
Any application that is not known to its database as "safe" is not allowed to open unless the user allows the execution or launching of the program.

In a testing of Spyhunter's performance, 314 malware samples to the system drive. SpyHunter's System Guard did not trigger any alert. I allowed it to scan the system drive that has 314 malware samples in a A directory for these malware samples was created and located on the Desktop. Spyhunter was then used to scan the directory. It found 7 threats only out of 314 malware samples.

It was concluded that at $40 for 1 year subscription of SpyHunter spyware detection tool, the program is overpriced especially if the detection and protection is very poor.
Source: http://www.brighthub.com/computing/smb-security/articles/76756.aspx
===============================================
You decided to uninstall Mumble which I guess is the open source, low-latency, high quality voice chat software primarily intended for use while gaming because it didn't work and froze the system.
===============================================
You disabled the network adapter saying that it was because you use a wireless connection- but it appears that you don't realize that you can't connect to a network without the adapter.
===============================================
Uninstall ComboFix and all Backups of the files it deleted
  • Click START> then RUN
  • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.

Download Combofix again, following my instructions exactly on renaming it. See if t will scan now. If it will not, go back to my Reply #4 and follow the steps for running RKill and exe. Then attempt the Combofix scan. When it is finished, please leave the log in your next reply.

Then go on to my next reply to run the script I have set up to run in Combofix:

Your impatience has been noted. The better you follow my directions, the most quickly this will go.
 
Check this site forJava Updates Update to the current v6u24 Uninstall Java(TM) 6 Update 20 in Add/Remove Programs as it is a vulnerability for the system.
=========================================
Please run this Custom CFScript:

  • [1]. Close any open browsers.
    [2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    [3]. Open notepad> click on Format> Uncheck 'Word Wrap'> and copy/paste the text in the code below into it:Be sure to scroll down to include ALL lines.
Code:
File::
c:\program files\lavasoft\ad-aware\aawservice.exe
c:\docume~1\useris\locals~1\temp\cpuz130\cpuz_x32.sys
c:\windows\system32\drivers\androidusb.sys
c:\windows\system32\zonelabs\avsys\klif.sys
c:\windows\system32\vsdatant.sys
DDS::
uDefault_Search_URL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
uSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearch Bar = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearchMigratedDefaultURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
mSearchURL = 687474703a2f2f7777772e476f6f676c652e636f6d2f
uPolicies-explorer: NoSecurityTab = 1 (0x1)
Hosts: 178.63.80.143 drivershq.com
Hosts: 178.63.80.143 www.drivershq.com
Hosts: 178.63.80.143 downloads.drivershq.com
Hosts: 178.63.80.143 devicedoctor.com
Hosts: 178.63.80.143 www.devicedoctor.com
Hosts: 178.63.80.143 uniblue.com
Hosts: 178.63.80.143 www.uniblue.com
Hosts: 178.63.80.143 download.uniblue.com
Hosts: 178.63.80.143 drivermax.com
Hosts: 178.63.80.143 www.drivermax.com
Hosts: 178.63.80.143 innovative-sol.com
Hosts: 178.63.80.143 www.innovative-sol.com
Hosts: 178.63.80.143 driverrobot.com
Hosts: 178.63.80.143 www.driverrobot.com
Hosts: 178.63.80.143 driverchecker.com
Hosts: 178.63.80.143 www.driverchecker.com
Hosts: 178.63.80.143 driveragent.com
Hosts: 178.63.80.143 www.driveragent.com
Hosts: 178.63.80.143 radarsync.com
Hosts: 178.63.80.143 www.radarsync.com
Hosts: 178.63.80.143 driver-soft.com
Hosts: 178.63.80.143 www.driver-soft.com
Extra::
File::
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
Firefox::
Firefox-:-Profile- c:\docume~1\useris\applic~1\mozilla\firefox\profiles\yak0ni2f.default\
Driver::
Lavasoft Ad-Aware Service
cpuz130
HTCAND32
KLIF
vsdatant
Save this as CFScript.txt, in the same location as ComboFix.exe
CFScriptB-4.gif


Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it will produce a log for you at C:\ComboFix.txt . Please paste in your next reply.
====================
 
i am not running spyhunter in background, only to scan once a while. but ill remove it as advices.

when i tried fixing mumble issue i found that i need to run 'prime95.exe' but honestly i dont remember what exactly it should have done. time it would take to run that program was unacceptable so i gave up on mumble.

i wasnt aware that i still have zonealarm, it was already removed from add/remove as well as from program files

changed automatic allow on pctools. was little tricky with enabling logging. i cant find advanced settings anywhere. only place i found to enable logging was profiles>advanced rules>all oher packets. but it doesnt seem to affect history.

network adapters:
Atheros AR5005GS wireless network adapter (enabled)
Intel(R) pro/100 ve network connection (disabled)
,
thats what i ment about disabling. it was showing icon that its not connected and it was bugging me.

ran combofix for 90min :dead: then another hour~ in safe mode....

same thing like always, stops at 'T' unexpected :/

i didnt point that out yet, but if you didnt say i had problem, i wouldnt know. its not visible at all.
 
thats what i ment about disabling. it was showing icon that its not connected and it was bugging me.
My wireless router is hard wired to my desktop. I use my laptop most of the time. The icon shows with the red x saying the Local Area Network isn't connected. Sometimes that icon will stay hidden, sometimes it shows. I ignore it- I don't disable the LAN.

same thing like always, stops at 'T' unexpected :/
I don't know what this means. But it could be this:
Please check you time and date settings. Be sure both are correct, the Time Zone is correct, click on Update Now for internet time. All found with right click on clock> Adjust Date/Time.

If you find anything wrong in date and time, set it correctly, reboot and then run Combofix in Normal Mode.

Regarding Zonelarm. I think ZA has it's own uninstaller and that should be used if available. I move the remaining files with the script.

Regarding Spyhunter: It is a running process:
============== Running Processes ===============

C:\PROGRA~1\ENIGMA~1\SPYHUN~1\SH4SER~1.EXE

There is also a running Service:
R2 SpyHunter 4 Service;SpyHunter 4 Service;c:\progra~1\enigma~1\spyhun~1\SH4SER~1.EXE [2010-5-18 327064]
R means Running
2 means Automatic

=======================================
I noticed this error in the DDS log:
2011.02.23 10:12:27, error: ipnathlp [31012] - The DNS proxy agent encountered an error while obtaining the local list of name-resolution servers. Some DNS or WINS servers may be inaccessible to clients on the local network. The data is the error code.

That could be what Spyhunter referred to.
======================================
You may not be aware of some of these things so you should probably review the installed programs, the Startup Menu using msconfig and the Startup Type of some Services. All of this is available for me to see in the logs.
 
i see, well when i run spyhunter, it helps itself into startup list, which i remove after each time. seems i didnt when i scanned. when i uninstalled spyhunter it was stil in program files, which i removed.

it seems its successfully synchronized on startup, but when i try to do it manualy, it says error.

not sure if you accept images, but here it goes.

http://i56.tinypic.com/dgpfsp.png
 
Are you trying to take SpyHunter off of the Startup menu?

To remove entries from Startup using the msconfig utility:
  • Click on Start> Run> type in msconfig> enter>
  • Click on Selective Startup
  • Choose the Startup tab:
    This is where you UNCHECK the Startup items. This does not remove the item or uninstall anything> it just stops it from starting on boot. It can be rechecked at any time if wanted.
  • To expand the Command Column, (this shows what the process 'belongs' to) hold left mouse button down on the dividing line on frame above Location and move to the right to expand.
    Uncheck all Spyhunter related entries
  • Click on Apply> OK when finished.

NOTE:
When you reboot the system the first time after making changes using the msconfig utility, a nag message comes up that can be ignored and closed after checking 'don't show this message again.'

Once you make changes to the Startup menu, you must remain in Selective Startup to retain those changed. If you go back to Normal Startup, everything you unchecked will be checked again and start on boot.
==================================
Click on Start> Run> type in services.msc> enter> Double click on SpyHunter 4 Service> Change Startup Type to Manual
Exit Services
 
spyhunter wasnt in services.msc

msconfig is familiar to me.

only items im not sure if i need on startup are - ctfmon, jusched, NvCpl.

also got SMax4PNP and smax4, both for sound, but not sure if both needed.
 
only items im not sure if i need on startup are - ctfmon, jusched, NvCpl.

None of these need to be on Startup:
1 ctfmon>> Ctfmon.exe activates the Alternative User Input Text Input Processor (TIP) and the Microsoft Office Language Bar. Taking this off startup won't work:
Remove Alternative User Input Services from Text Services
1. Click Start, point to Settings, and then click Control Panel.
2. In the Control Panel, double-click Text Services.NOTE: In Windows XP, click Date, Time, Language, and Regional Options, and then click Regional and Language Options. On the Languages tab, click Details.
3. Under Installed Services, select each input item that is listed, and then click Remove to remove the item. All items must be removed, one by one, except the following input service:
English (United States)- default Keyboard United States 101
2. jusched>> Java updater. Can be disabled: Control Panel> Java> Update tab> Uncheck 'automatically check for update> Yes to confirm> OK
3. NvCpl>> If full entry is NvCpl.dll>> Intializes the clock and memory settings on nVidia based graphics cards. Enable if you overclock your card. Otherwise not needed on Startup.
4. SMax4 is part of the SoundMAX software program. It is not necessary for sound to work on your computer it is not required to run on startup.
5. SMax4PNP>> SoundMax. up to you whether or not you want it to run on startup. Only required if you have custom settings for your sound, such as effects and environments
=================================
Have your original problems been resolved?
 
it says its still active so ill post here.

just had blue screen, heres what it said after restart

C:\DOCUME~1\Useris\LOCALS~1\Temp\WER790f.dir00\Mini032911-01.dmp
C:\DOCUME~1\Useris\LOCALS~1\Temp\WER790f.dir00\sysdata.xml
BCCode : 100000ea BCP1 : 85AB0020 BCP2 : 8703A008 BCP3 : F7912CBC
BCP4 : 00000001 OSVer : 5_1_2600 SP : 3_0 Product : 256_1

its probably not first time but it was soooo long ago i couldnt remember last time.

anything i should worry about?
 
These are minidump codes. They can help identify the problem driver. Please repost in the Windows BSOD forum on TechSpot.

You started this thread over a month ago, with long times in between posts. IF you are still having what you think is malware related, you will need to do new scans and leave new logs.

Removing all of the tools we used and the files and folders they created
  • Uninstall ComboFix and all Backups of the files it deleted
  • Click START> then RUN
  • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
    CF_Uninstall-1.jpg
  • Download OTCleanIt by OldTimer and save it to your Desktop.
  • Double click OTCleanIt.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

  • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
  • Go to Start > All Programs > Accessories > System Tools
  • Click "System Restore".
  • Choose "Create a Restore Point" on the first screen then click "Next".
  • Give the Restore Point a name> click "Create".
  • Go back and follow the path to > System Tools.
    [*]Choose Disc Cleanup
    [*]Click "OK" to select the partition or drive you want.
    [*]Click the "More Options" Tab.
    [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


Empty the Recycle Bin
 
Status
Not open for further replies.
Back