Malware and Virus RemovalProblems removing malware/viruses? Get help from our Malware removal experts.
Mission Statement
WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.
Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.
I had trouble logging into Ebay/Paypal etc; and determined something was wrong when the status bar would freeze about halfway. This did not happen on other websites and it only happened on the one desktop machine. Other machines operated normally. I found your forums and ran some of the malware programs and did some general cleanup. What I'm left with is the mbr.log showing that I have malicious code and I'm to the point where I need some expert assistance if possible to insure this machine is clean and good to go. Kaspersky came back clean, Dr. Web comes back clean, McAfee shows no problems, Super Anti Spyware comes back good, and I ran TFC also. Any help is greatly appreciated!!
Rodney
As directed, here is my DDS:
DDS (Ver_09-12-01.01) - NTFSx86
Run by Carr at 0:20:18.90 on Sun 02/07/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_18
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.160 [GMT -5:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 7/1/2003 8:23:13 PM
System Uptime: 2/6/2010 8:57:35 PM (4 hours ago)
RP1560: 1/16/2010 1:17:46 AM - System Checkpoint
RP1561: 1/17/2010 1:50:32 AM - System Checkpoint
RP1562: 1/18/2010 3:01:53 AM - System Checkpoint
RP1563: 1/19/2010 3:47:52 AM - System Checkpoint
RP1564: 1/20/2010 4:47:55 AM - System Checkpoint
RP1565: 1/20/2010 7:21:37 AM - Software Distribution Service 3.0
RP1566: 1/21/2010 7:47:41 AM - System Checkpoint
RP1567: 1/22/2010 7:26:15 AM - Software Distribution Service 3.0
RP1568: 1/23/2010 7:44:10 AM - System Checkpoint
RP1569: 1/24/2010 8:44:09 AM - System Checkpoint
RP1570: 1/25/2010 8:56:41 AM - System Checkpoint
RP1571: 1/26/2010 9:45:17 AM - System Checkpoint
RP1572: 1/27/2010 9:58:59 AM - System Checkpoint
RP1573: 1/28/2010 10:43:43 AM - System Checkpoint
RP1574: 1/29/2010 11:43:43 AM - System Checkpoint
RP1575: 1/30/2010 12:43:48 PM - System Checkpoint
RP1576: 1/31/2010 1:43:40 PM - System Checkpoint
RP1577: 2/1/2010 2:59:58 PM - System Checkpoint
RP1578: 2/2/2010 4:54:54 PM - System Checkpoint
RP1579: 2/2/2010 8:17:43 PM - Removed ABBYY FineReader 6.0 Sprint
RP1580: 2/2/2010 8:20:13 PM - Removed Apple Software Update
RP1581: 2/2/2010 8:24:25 PM - Removed Dell Solution Center
RP1582: 2/2/2010 8:27:16 PM - Removed Google Earth.
RP1583: 2/2/2010 8:36:01 PM - Removed Paint Shop Pro 7
RP1584: 2/2/2010 8:39:17 PM - Removed Rhapsody Player Engine
RP1585: 2/2/2010 8:40:04 PM - Removed Spelling Dictionaries Support For Adobe Reader 8
RP1586: 2/3/2010 4:51:00 PM - avast! Free Antivirus Setup
RP1587: 2/4/2010 10:00:42 PM - System Checkpoint
RP1588: 2/5/2010 10:56:29 AM - Installed SUPERAntiSpyware Free Edition
RP1589: 2/6/2010 2:35:32 PM - System Checkpoint
RP1590: 2/6/2010 8:14:35 PM - Installed Java(TM) 6 Update 18
RP1591: 2/6/2010 8:21:46 PM - Removed J2SE Runtime Environment 5.0 Update 4
RP1592: 2/6/2010 8:40:26 PM - Removed J2SE Runtime Environment 5.0 Update 6
RP1593: 2/6/2010 8:41:08 PM - Removed Java 2 Runtime Environment, SE v1.4.1_01
==== Installed Programs ======================
µTorrent
AAC Decoder
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 8.2.0
Adobe Shockwave Player 11
ArcSoft MediaImpression
Audacity 1.2.3
AutoUpdate
avast! Free Antivirus
AVIcodec (remove only)
BACS
Banctec Service Agreement
BCM V.92 56K Modem
BitTornado 0.3.18
Broadcom Advanced Control Suite
CaseLinr 5.5
CD Wave Editor version 1.94
Critical Update for Windows Media Player 11 (KB959772)
Crystal Reports Basic Runtime for Visual Studio 2008
DAO
dBpowerAMP FLAC Codec
dBpowerAMP Music Converter
dBpowerAMP Shorten Codec
Dell Support
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
DP Editor Ver.1.0
Epson Copy Utility 3.4
Epson Event Manager
EPSON Perfection V30/V300 Photo Scanner Driver Update
EPSON Scan
ESPN Java Check
Eudora
Exif Launcher Ver.1.1
FinePixViewer Ver.1.1
FLAC Installer 1.1.0m (remove only)
FLV Player 1.3.3
Forté Agent
H.264 Decoder
Help and Support Customization
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel(R) Extreme Graphics Driver
Internet Explorer Q903235
Java Auto Updater
Java(TM) 6 Update 18
Lexmark Supplies Monitor
Lexmark Z55
LiveUpdate
Malwarebytes' Anti-Malware
McAfee SecurityCenter
Microsoft .NET Framework (English)
Microsoft .NET Framework (English) v1.0.3705
Microsoft .NET Framework 1.0 Hotfix (KB928367)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Access 2000 Runtime SR-1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Office 2000 SR-1 Professional
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MKV Splitter
Modem Helper
Monkey's Audio
Mozilla Firefox (3.6)
Nero 6 Ultra Edition
PartyCAD10
QuickTime
RealPlayer
Security Update for CAPICOM (KB931906)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB911565)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950759)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953838)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB963027)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Spybot - Search & Destroy
SUPERAntiSpyware Free Edition
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB969497)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC80CRTRedist - 8.0.50727.4053
Viewpoint Media Player (Remove Only)
VivTV
WebFldrs XP
WinAce Archiver 2.0
Window Washer
Windows Genuine Advantage v1.3.0254.0
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 9 Hotfix [See KB885492 for more information]
Windows XP Service Pack 3
WinRAR archiver
Xvid 1.1.2 final uninstall
YMPEG: Fast MPEG-1/2/VCD/SVCD Codec
==== Event Viewer Messages From Past Week ========
2/6/2010 4:21:25 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the IMAPI CD-Burning COM Service service to connect.
2/6/2010 4:21:25 PM, error: Service Control Manager [7000] - The IMAPI CD-Burning COM Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/6/2010 4:18:05 PM, error: Service Control Manager [7031] - The McAfee Personal Firewall Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Run the configured recovery program.
2/6/2010 4:18:04 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 4:18:03 PM, error: Service Control Manager [7034] - The LexBce Server service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 4:18:03 PM, error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
2/6/2010 4:15:52 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the McAfee SystemGuards service to connect.
2/6/2010 4:15:52 PM, error: Service Control Manager [7000] - The McAfee SystemGuards service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
2/5/2010 9:30:15 PM, error: Service Control Manager [7031] - The McAfee SystemGuards service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/5/2010 9:29:48 PM, error: Service Control Manager [7031] - The McAfee Proxy Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/5/2010 9:29:09 PM, error: Service Control Manager [7031] - The McAfee SystemGuards service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/5/2010 4:37:14 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
2/5/2010 11:05:55 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service McNASvc with arguments "" in order to run the server: {24F616A1-B755-4053-8018-C3425DC8B68A}
2/5/2010 11:05:11 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi Fips intelppm IPSec mfehidk MPFP MRxSmb NetBIOS NetBT RasAcd Rdbss SASDIFSV SASKUTIL Tcpip WS2IFSL
2/5/2010 11:05:11 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD Networking Support Environment service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2010 11:05:11 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2010 11:05:11 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2010 11:05:11 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
2/5/2010 11:04:38 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
2/5/2010 11:04:26 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
2/4/2010 9:43:44 PM, error: Service Control Manager [7024] - The Java Quick Starter service terminated with service-specific error 1 (0x1).
2/4/2010 9:43:43 PM, error: Service Control Manager [7031] - The McAfee Services service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/4/2010 9:43:43 PM, error: Service Control Manager [7031] - The McAfee Network Agent service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/3/2010 7:34:57 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
2/3/2010 6:13:30 PM, error: Service Control Manager [7034] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 3 time(s).
2/3/2010 6:03:56 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/3/2010 5:56:46 PM, error: Service Control Manager [7031] - The McAfee Real-time Scanner service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
2/3/2010 10:00:46 AM, error: Service Control Manager [7034] - The Window Washer Engine service terminated unexpectedly. It has done this 1 time(s).
2/2/2010 2:24:39 PM, error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the McAfee Real-time Scanner service, but this action failed with the following error: An instance of the service is already running.
2/2/2010 2:22:52 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the AudioSrv service.
==== End Of File ===========================
And here is the most recent mbr.log:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x03944E1A
malicious code @ sector 0x03944E1D !
PE file found in sector at 0x03944E33 !
Didn't find the information you thought to find? Check out these Similar Threads
I see you have P2P software ( Azures, Limewire, BitTorrent, uTorrent etc…) installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It may be contributing to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares and their infections.
References for the risk of these programs are here, and here.
I would strongly recommend that you uninstall them,
Note: Please be advised that continued use of these programs after being warned of the danger of infections from them, may result in the discontinued help of future cleaning of your system here at WindowsBBS Malware and Virus removal.
A Malware expert will have a look at your log in due course.
You're running two AV programs, Avast and McAfee.
One of them has to go.
Before you do anything, let me know, which one you want to keep (my vote goes for Avast).
I will gladly keep whatever you recommend, so Avast it is. McAfee came free with Comcast so that's why it is there. I added the Avast a few days ago after reading that it was recommended in another thread.
Please download ComboFix from Here or Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
Please, never rename Combofix unless instructed.
Close any open browsers.
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
NOTE 1. If Combofix asks you to install Recovery Console, please allow it. NOTE 2. If Combofix asks you to update the program, always do so.
Close any open browsers.
WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review.
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**
Make sure, you re-enable your security programs, when you're done with Combofix.
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
Download HijackThis: http://www.trendsecure.com/portal/en...kthis/download
by clicking on Installer under Version 2.0.2
[DO NOT download version 2.0.3 (beta)]
Install, and run it.
Post HijackTHis log. Do NOT attempt to fix anything!
NOTE. If you're using Vista, or 7, right click on HijackThis, and click Run as Administrator
Quick question-I'm to remove everything related to McAfee right? It comes up as Security Center and ask if I want to remove all items such as Virus Scan, Personal Firewall, Backup/Restore etc;
I just wanted to make sure whether to dump all this, or just the AV part.
ComboFix 10-02-07.05 - Carr 02/07/2010 17:19:20.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.638.408 [GMT -5:00]
Running from: c:\documents and settings\Carr\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((( Files Created from 2010-01-07 to 2010-02-07 )))))))))))))))))))))))))))))))
.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:39:25 PM, on 2/7/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
I posted the logs you requested a while back, but it told me the posts had to be approved by a moderator. Just didn't want you to think I had vanished....
* Doubleclick mbr.exe and follow prompts.
* A black DOS window will quickly appear then disappear.
* When mbr.exe is finished it will create a log on your desktop.
* Copy and paste contents of that log (mbr.log) file to your next reply.
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x03944E1A
malicious code @ sector 0x03944E1D !
PE file found in sector at 0x03944E33 !