Antivirus System Pro knocked me off the Internet - any ideas on getting back on?

View previous topic View next topic Go down

Antivirus System Pro knocked me off the Internet - any ideas on getting back on?

Post by yeknom-ecaps on Sun Nov 29, 2009 10:00 pm

Antivirus System Pro reappeared on my PC - was locked out of everything but finally was able to get Malwarebytes Anti-Malware to run which detected things that were deleted on re-boot. Antivirus System Pro no longer pops up and system seems to run ok. Ran Malwarebytes again, also ran Avira antivirus and Ad-Aware have been run and re-run and are clean.

Issue is that I am no longer able to connect to the Internet - though I do connect to the Access Point ok. Any idea what Antivirus Pro did to knock me off? The three other PCs (2 wireless and one direct wired) all connect to the internet ok through the same router.

XP
Linksys WRT54GS router

disabled and reenabled - no coonection past access point
retyped in access code - no connection past access point
"repair" option completes succesfully - no connection past acces point

any ideas?

yeknom-ecaps
Novice
Novice

Posts Posts : 39
Joined Joined : 2009-07-03
OS OS : xp
Points Points : 27227
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus System Pro knocked me off the Internet - any ideas on getting back on?

Post by Dr Jay on Sun Nov 29, 2009 11:23 pm

Please download ComboFix from [You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

[You must be registered and logged in to see this link.]

Rename ComboFix.exe to commy.exe before you save it to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found [You must be registered and logged in to see this link.]
  • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console


Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13714
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302072
# Likes # Likes : 10

View user profile

Back to top Go down

Re: Antivirus System Pro knocked me off the Internet - any ideas on getting back on?

Post by yeknom-ecaps on Mon Nov 30, 2009 2:24 am

Here is Combo-Fix run log

ComboFix 09-11-29.03 - Tom 11/29/2009 21:07.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.455 [GMT -5:00]
Running from: c:\documents and settings\Tom\desktop\commy.exe
Command switches used :: /stepdel
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AVG Anti-Virus Free *On-access scanning enabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-10-28 to 2009-11-30 )))))))))))))))))))))))))))))))
.

2009-11-28 19:07 . 2009-11-28 20:05 -------- d-----w- c:\documents and settings\Tom\Local Settings\Application Data\qrfxip
2009-11-15 16:35 . 2009-09-10 19:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-15 16:35 . 2009-11-15 16:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-15 16:35 . 2009-09-10 19:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-15 04:56 . 2009-11-15 04:56 389120 ----a-w- c:\windows\system32\CF7635.exe
2009-11-15 04:56 . 2009-11-15 04:54 389120 ----a-w- c:\windows\system32\CF7325.exe
2009-11-07 20:48 . 2009-11-14 19:23 79488 ----a-w- c:\documents and settings\Tom\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-28 22:46 . 2009-10-21 00:43 3695616 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2009-11-15 17:12 . 2009-08-25 19:01 -------- d-----w- c:\program files\QuickTime
2009-11-15 07:58 . 2008-03-09 03:35 -------- d-----w- c:\program files\VisualTaskTips
2009-11-15 07:45 . 2009-08-25 19:03 -------- d-----w- c:\program files\iTunes
2009-11-15 07:45 . 2008-03-10 04:21 -------- d-----w- c:\program files\IconLock
2009-10-09 23:34 . 2009-10-09 23:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-10-09 23:34 . 2009-10-09 23:34 -------- d-----w- c:\documents and settings\Tom\Application Data\Office Genuine Advantage
2009-10-01 01:48 . 2008-11-15 21:07 27152 ----a-w- c:\documents and settings\Tom\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-24 23:37 . 2009-09-24 23:37 -------- d-----w- c:\windows\Fonts\Fonts
2009-09-24 23:35 . 2009-09-24 23:35 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-09-24 23:35 . 2009-09-24 23:35 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-09-24 23:35 . 2009-09-24 23:35 116472 ------w- c:\windows\system32\pxcpyi64.exe
2009-09-24 23:35 . 2009-09-24 23:35 129784 ------w- c:\windows\system32\pxafs.dll
2009-09-24 23:35 . 2009-09-24 23:35 43528 ------w- c:\windows\system32\drivers\PxHelp20.sys
2009-09-24 23:35 . 2009-09-24 23:35 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-09-11 14:18 . 2004-08-03 23:56 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\msasn1.dll
.
Code:
<pre>
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Globe Software\StatBar\statbar .exe
c:\program files\Google\GoogleToolbarNotifier\googletoolbarnotifier .exe
c:\program files\IconLock\iconlock .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Lavasoft\Ad-Aware\aawtray .exe
c:\program files\Messenger\msmsgs .exe
c:\program files\QuickTime\qttask        .exe
c:\program files\VisualTaskTips\visualtasktips .exe
</pre>

------- Sigcheck -------

[-] 2005-01-28 17:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[-] 2005-01-28 17:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\system32\mspmsnsv.dll
[-] 2005-01-28 17:44 . 140EF97B64F560FD78643CAE2CDAD838 . 25088 . . [10.0.3790.3802] . . c:\windows\system32\dllcache\mspmsnsv.dll
[-] 2004-08-03 23:56 . C086483E3DBA8C1C0A687EC8D5B3D4C1 . 52224 . . [9.0.1.56] . . c:\windows\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll
.
((((((((((((((((((((((((((((( SnapShot_2009-11-15_06.42.26 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-29 17:46 . 2009-11-29 17:46 16384 c:\windows\temp\Perflib_Perfdata_b54.dat
+ 2007-11-13 11:31 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
- 2007-11-13 11:31 . 2009-07-14 11:03 46080 c:\windows\system32\tzchange.exe
+ 2008-03-10 00:53 . 2009-05-26 11:40 17272 c:\windows\system32\spmsg.dll
- 2008-03-10 00:53 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll
+ 2009-11-15 02:00 . 2009-11-29 17:46 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2009-11-15 02:00 . 2009-11-15 02:00 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-03-09 03:19 . 2009-11-15 02:00 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-03-09 03:19 . 2009-11-29 17:46 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-11-28 19:29 . 2009-11-29 17:46 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-03-09 03:19 . 2009-11-15 02:00 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-30 01:06 . 2009-07-31 15:05 1372672 c:\windows\system32\msxml6.dll
+ 2004-08-03 23:56 . 2009-07-31 04:35 1172480 c:\windows\system32\msxml3.dll
+ 2008-08-23 22:14 . 2009-07-31 15:05 1372672 c:\windows\system32\dllcache\msxml6.dll
+ 2004-08-03 23:56 . 2009-07-31 04:35 1172480 c:\windows\system32\dllcache\msxml3.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StatBar"="c:\program files\Globe Software\StatBar\StatBar.exe" [2003-07-25 335872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask .exe -atboottime" [X]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-05-09 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-10-21 520024]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-09 1519616]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-04-10 16126464]

c:\documents and settings\Tom\Start Menu\Programs\Startup\
3DO Registration.lnk - c:\program files\3DO\Heroes3\Register\Remind32.exe [2008-9-26 67584]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-3-15 113664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
taskmanager.lnk - c:\windows\system32\taskmgr.exe [2004-8-3 135680]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/21/2009 6:18 AM 64160]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [9/16/2008 11:03 AM 169312]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [7/3/2009 2:59 PM 108289]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [3/7/2009 1:35 AM 54752]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [1/18/2009 4:34 PM 1028432]
R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [12/31/2008 1:12 PM 693512]
R3 m4301a;Linksys Wireless-B USB Network Adapter v4.0 Driver;c:\windows\system32\drivers\m4301A.sys [12/21/2004 3:16 PM 141990]
R3 WUSB54GV4SRV;Linksys Wireless-G USB Network Adapter Driver;c:\windows\system32\drivers\rt2500usb.sys [3/16/2008 11:02 AM 79616]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [8/5/2009 9:48 PM 704864]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [12/31/2008 1:12 PM 910600]
.
Contents of the 'Scheduled Tasks' folder

2009-08-19 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 00:43]

2009-10-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2009-11-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 19:07]

2009-11-29 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-07-03 02:18]
.
.
------- Supplementary Scan -------
.
uStart Page = [You must be registered and logged in to see this link.]
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: Search Current News - [You must be registered and logged in to see this link.] files\powershell-xp3\search5.htm
IE: Search Encyclopedia - [You must be registered and logged in to see this link.] files\powershell-xp3\search4.htm
IE: Search for Images - [You must be registered and logged in to see this link.] files\powershell-xp3\search3.htm
IE: Search Newsgroups - [You must be registered and logged in to see this link.] files\powershell-xp3\search2.htm
IE: Search the Web - [You must be registered and logged in to see this link.] files\powershell-xp3\search.htm
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Ad-Aware - c:\documents and settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}\Ad-AwareAE.exe REMOVE=TRUE MODIFY=FALSE
AddRemove-NVIDIA Drivers - c:\windows\system32\nvudisp.exe UninstallGUI
AddRemove-RealJukebox 1.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-RealPlayer 6.0 - c:\program files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
AddRemove-Tweak UI 2.10 - c:\windows\system32\mshta.exe [You must be registered and logged in to see this link.]



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-11-29 21:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, [You must be registered and logged in to see this link.]

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x864F2618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf75d4f28
\Driver\ACPI -> ACPI.sys @ 0xf7447cb8
\Driver\atapi -> atapi.sys @ 0xf73d9852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: -> SendCompleteHandler -> 0x0
PacketIndicateHandler -> 0x0
SendHandler -> 0x0
user & kernel MBR OK

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1096)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(1160)
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(3436)
c:\windows\system32\WININET.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-11-29 21:21
ComboFix-quarantined-files.txt 2009-11-30 02:21
ComboFix2.txt 2009-11-16 03:37
ComboFix3.txt 2009-11-16 02:34
ComboFix4.txt 2009-11-15 06:47
ComboFix5.txt 2009-11-30 02:05

Pre-Run: 38,738,219,008 bytes free
Post-Run: 38,816,124,928 bytes free

Current=5 Default=5 Failed=4 LastKnownGood=6 Sets=1,2,3,4,5,6
- - End Of File - - E90747B36B6A8CBE971D11EA3C1556AF

yeknom-ecaps
Novice
Novice

Posts Posts : 39
Joined Joined : 2009-07-03
OS OS : xp
Points Points : 27227
# Likes # Likes : 0

View user profile

Back to top Go down

Re: Antivirus System Pro knocked me off the Internet - any ideas on getting back on?

Post by Dr Jay on Mon Nov 30, 2009 2:56 am

Still having issues browsing the internet?

Please download Malwarebytes Anti-Malware from [You must be registered and logged in to see this link.].

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Full Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • Please save the log to a location you will remember.
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.


Dr. Jay (DJ)


[You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.] ~ [You must be registered and logged in to see this link.]

Dr Jay
Head Administrator
Head Administrator

Posts Posts : 13714
Joined Joined : 2009-09-06
Gender Gender : Male
OS OS : Windows 10 Home & Pro
Protection Protection : Bitdefender Total Security
Points Points : 302072
# Likes # Likes : 10

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum