WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionSecurity Suite Help Please EmptySecurity Suite Help Please

more_horiz
I have read some of the other posts on security suite removal and can't get any of the solutions to work. I have downloaded all 3 Rkill applications and none of them will run. I have tried running combo-fix from the command line with the /killall switch and it will not run. Please help.

Thank you,

descriptionSecurity Suite Help Please EmptyRe: Security Suite Help Please

more_horiz
Tried OTL to generate a log for you but it will not run either.

descriptionSecurity Suite Help Please EmptyRe: Security Suite Help Please

more_horiz
Finally got combo-fix to run in safe mode. Here is the log. Do I need to do anything else? Thank you

ComboFix 10-08-22.07 - Kelly 08/23/2010 13:09:39.1.4 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2569 [GMT -4:00]
Running from: c:\documents and settings\Kelly\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Network Edition *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Kelly\Favorites\Advanced Solutions Inc..url
c:\documents and settings\Kelly\GoToAssistDownloadHelper.exe
c:\documents and settings\NetworkService\Local Settings\Application Data\dfkpcpvrk
c:\documents and settings\NetworkService\Local Settings\Application Data\dfkpcpvrk\noeaydxshdw.exe
c:\documents and settings\STCD\ltclr13n.dll
C:\Documents

.
((((((((((((((((((((((((( Files Created from 2010-07-23 to 2010-08-23 )))))))))))))))))))))))))))))))
.

2010-08-20 19:05 . 2010-08-22 14:35 664 ----a-w- c:\windows\system32\d3d9caps.dat
2010-08-10 01:16 . 2010-08-10 01:16 -------- d-----w- c:\program files\Common Files\Java
2010-08-10 01:13 . 2010-08-10 01:13 61440 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3df95c11-n\decora-sse.dll
2010-08-10 01:13 . 2010-08-10 01:13 503808 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-34d41486-n\msvcp71.dll
2010-08-10 01:13 . 2010-08-10 01:13 499712 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-34d41486-n\jmc.dll
2010-08-10 01:13 . 2010-08-10 01:13 348160 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-34d41486-n\msvcr71.dll
2010-08-10 01:13 . 2010-08-10 01:13 12800 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3df95c11-n\decora-d3d.dll
2010-07-28 01:41 . 2010-07-28 01:41 81920 ----a-w- c:\documents and settings\Kelly\Application Data\Autodesk\C3D 2010\enu\ContextualTabSelectorRules.dll
2010-07-28 01:37 . 2010-07-28 01:37 36864 ----a-w- c:\documents and settings\Kelly\Application Data\Autodesk\AutoCAD 2010\R18.0\enu\ContextualTabSelectorRules.dll
2010-07-28 01:35 . 2010-07-28 01:35 -------- d-----w- c:\program files\Raster Design 2010 OE
2010-07-28 00:26 . 2010-07-28 00:26 -------- d-----w- C:\Civil 3D Project Templates
2010-07-28 00:26 . 2010-08-20 12:11 -------- d-----w- c:\program files\AutoCAD Civil 3D 2010
2010-07-28 00:13 . 2010-08-06 14:12 -------- d-----w- c:\documents and settings\Kelly\Application Data\Autodesk
2010-07-28 00:13 . 2010-08-06 14:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Autodesk
2010-07-28 00:13 . 2010-07-28 01:35 -------- d-----w- c:\program files\AutoCAD 2010
2010-07-28 00:13 . 2010-07-28 01:06 -------- d-----w- c:\documents and settings\Kelly\Local Settings\Application Data\Autodesk
2010-07-28 00:11 . 2010-07-28 01:06 -------- d-----w- c:\program files\Autodesk

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-23 14:16 . 2010-06-09 07:15 1635968 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-08-18 16:22 . 2008-05-23 15:20 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2010-08-12 11:56 . 2008-05-16 23:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-10 01:13 . 2010-07-23 16:41 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-10 01:12 . 2008-05-16 23:30 -------- d-----w- c:\program files\Java
2010-07-28 01:33 . 2008-05-23 15:38 -------- d-----w- c:\program files\Common Files\Autodesk Shared
2010-07-23 16:42 . 2010-07-23 16:42 61440 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-69e9abc4-n\decora-sse.dll
2010-07-23 16:42 . 2010-07-23 16:42 503808 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-352ca979-n\msvcp71.dll
2010-07-23 16:42 . 2010-07-23 16:42 499712 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-352ca979-n\jmc.dll
2010-07-23 16:42 . 2010-07-23 16:42 348160 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-352ca979-n\msvcr71.dll
2010-07-23 16:42 . 2010-07-23 16:42 12800 ----a-w- c:\documents and settings\Kelly\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-69e9abc4-n\decora-d3d.dll
2010-07-06 17:21 . 2010-07-06 17:21 49664 ----a-w- c:\documents and settings\All Users\Application Data\Autodesk\C3D 2010\enu\Data\Reports\Net\BreakingToolsWrap.dll
2010-07-06 17:21 . 2010-07-06 17:21 1145344 ----a-w- c:\documents and settings\All Users\Application Data\Autodesk\C3D 2010\enu\Data\Reports\Net\C3DReport.dll
2010-07-06 17:21 . 2010-07-06 17:21 27648 ----a-w- c:\documents and settings\All Users\Application Data\Autodesk\C3D 2010\enu\C3DPipeNetworkRules.dll
2010-07-06 17:21 . 2010-07-06 17:21 819200 ----a-w- c:\documents and settings\All Users\Application Data\Autodesk\C3D 2010\enu\C3DStockSubassemblies.dll
2010-07-06 16:49 . 2010-07-06 16:49 2850816 ----a-w- c:\documents and settings\Kelly\Application Data\Autodesk\C3D 2010\enu\Support\C3D.dll
2010-06-30 12:31 . 2004-08-11 22:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-25 15:51 . 2008-07-16 18:08 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-06-24 12:15 . 2004-08-11 22:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:15 . 2004-08-11 22:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:15 . 2004-08-11 22:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-06-23 13:44 . 2004-08-11 22:00 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2004-08-11 22:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2004-08-11 22:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2004-08-11 22:12 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:41 . 2004-08-11 22:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2008-04-07 06:59 . 2008-06-11 19:38 67696 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2008-04-07 06:59 . 2008-06-11 19:38 54376 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2008-04-07 06:59 . 2008-06-11 19:38 34952 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2008-04-07 06:59 . 2008-06-11 19:38 46720 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2008-04-07 06:59 . 2008-06-11 19:38 172144 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-11-25 18:02 1230080 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-11-25 1230080]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-16 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-05 13590528]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-07-27 178712]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2007-09-11 1015808]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-07-09 2048352]
"NWTRAY"="NWTRAY.EXE" [2001-12-18 28672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-31 13:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwv1_0

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-01-11 23:54 623992 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Speed Launch]
2006-10-23 06:40 46200 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\acrobat_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Synchronizer]
2007-05-11 05:29 738968 ----a-w- c:\program files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 06:38 34672 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 ----a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter]
2008-02-26 20:16 17920 ----a-w- c:\dell\E-Center\EULALauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
2006-09-11 09:40 218032 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Default Manager]
2009-02-03 17:05 233304 ----a-w- c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-11-05 07:52 86016 ----a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-11-05 07:52 1657376 ----a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWTRAY]
2001-12-18 17:24 28672 ----a-r- c:\windows\system32\nwtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
2007-09-17 16:56 124200 ------w- c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-11 04:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2008-05-16 23:40 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:VNCTCP
"5900:UDP"= 5900:UDP:VNCUDP

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/23/2008 11:21 AM 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/23/2008 11:21 AM 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/23/2008 11:21 AM 108552]
R2 ASFIPmon;Broadcom ASF IP and SMBIOS Mailbox Monitor;c:\program files\Broadcom\ASFIPMon\AsfIpMon.exe [6/20/2007 3:30 PM 79168]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [5/23/2008 11:20 AM 297752]
R2 NVIDIA Performance Driver Service;NVIDIA Performance Driver Service;c:\program files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe [10/28/2008 7:44 AM 3575808]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/25/2009 12:22 PM 135664]
.
Contents of the 'Scheduled Tasks' folder

2010-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-25 16:22]

2010-08-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-25 16:22]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: mcgillengineers.com\vision
FF - ProfilePath - c:\documents and settings\Kelly\Application Data\Mozilla\Firefox\Profiles\pqdfela4.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - component: c:\documents and settings\Kelly\Application Data\Mozilla\Firefox\Profiles\pqdfela4.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-23 13:16
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A2EFACE]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xba0ecf28
\Driver\ACPI -> ACPI.sys @ 0xb9f7fcb8
\Driver\iaStor -> iaStor.sys @ 0xb9e96cfc
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Broadcom NetXtreme 57xx Gigabit Controller -> SendCompleteHandler -> NDIS.sys @ 0xb9d57bb0
PacketIndicateHandler -> NDIS.sys @ 0xb9d64a21
SendHandler -> NDIS.sys @ 0xb9d4287b
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\WININET.dll
c:\windows\system32\NOVNPNT.DLL
c:\windows\system32\MAPBASE.dll
c:\windows\system32\NWSHLXNT.dll
c:\windows\system32\NLS\ENGLISH\MAPBASER.DLL
c:\windows\system32\NLS\ENGLISH\NWSHLXNR.DLL
c:\windows\system32\NLS\ENGLISH\NOVNPNTR.DLL

- - - - - - - > 'lsass.exe'(772)
c:\windows\system32\WININET.dll
.
Completion time: 2010-08-23 13:19:27
ComboFix-quarantined-files.txt 2010-08-23 17:19

Pre-Run: 41,453,207,552 bytes free
Post-Run: 41,513,562,112 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional 3GB /3GB /fastdetect

- - End Of File - - FD61CA8346C872B15C5671943E9018C5

descriptionSecurity Suite Help Please EmptyRe: Security Suite Help Please

more_horiz
Bump

descriptionSecurity Suite Help Please EmptyRe: Security Suite Help Please

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum