I'm comfortable working on computers, a big part of my job is supporting software and users. A friend of mine brought me his old Gateway desktop so I could get rid of the "virus" that was on it. Upon booting, I found malware ("XP Security Center" if I remember right, I unfortunately didn't write down the name). I ended up using ComboFix while researching how to remove the malware. ComboFix discovered and removed rootkit.zeroaccess.
Out-of-date scans (MBAM, SAS, MSE) say the system is clean, but the network connection is extemely slow (more on that later). In struggling to get the network connection revived, I've ran an XP Repair install and uninstalled/reinstalled the network driver. Web browsing is incredibly slow (both with IE7 and Firefox), especially any site that is laden with graphics or ads (google.com loads reasonably, but the image on bing.com takes quite a bit of time, microsoft.com, msn.com, etc take forever, if they even load)
This is an old system (2002), and I've still not found the exact drivers (they're not on Gateway's website that I can find). So the ones that I do find I'm not 100% sure they are correct. Because of this, I'm hesitant to reinstall XP (chipset drivers, graphics driver, network driver, sound driver, etc). I haven't checked with the owner if he has the original support CD, but knowing the situation, I'd be surprised if he did.
I am unable to update MBAM, SuperAntiSpyware or MSE online, so I can't do subsequent scans to make me believe it's clean. MSE was current just prior to the infection, and it passes the scan (but I belive it was running when the system was orginially infected, so not sure if I trust it). I had trouble getting MBAM to see the manually installed definition, so I don't trust it's scan. I was able to update SAS manually, but I'd still rather trust a scan based on an online update.
All this behavior makes me think something is still lurking?? I can get into more details if need be, but here's the basics:
Make and model of computer: Gateway MFAT XNIN NMZ 300S
How the computer is connected (wireless or wired): Wired
Make and model of Router: Linksys WRT160NL (two other computers are successfully connected, Win7 wired and WinXP wireless)
What type of internet you have: Cable
MiniToolBox results:
MiniToolBox by Farbar
Ran by Owner (administrator) on 16-12-2011 at 14:21:50
Microsoft Windows XP Home Edition Service Pack 3 (X86)
***************************************************************************
========================= IE Proxy Settings: ==============================
Proxy is not enabled.
No Proxy Server is set.
========================= Hosts content: =================================
127.0.0.1 localhost
========================= IP Configuration: ================================
Intel® PRO/100 VE Network Connection = Local Area Connection 6 (Connected)
# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip
# Interface IP Configuration for "Local Area Connection 6"
set address name="Local Area Connection 6" source=dhcp
set dns name="Local Area Connection 6" source=dhcp register=PRIMARY
set wins name="Local Area Connection 6" source=dhcp
popd
# End of interface IP configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : joel032276
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : tc.ph.cox.net
Ethernet adapter Local Area Connection 6:
Connection-specific DNS Suffix . : tc.ph.cox.net
Description . . . . . . . . . . . : Intel® PRO/100 VE Network Connection
Physical Address. . . . . . . . . : 00-07-E9-BF-A7-4E
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.105
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 68.105.28.12
68.105.29.12
68.105.28.11
Lease Obtained. . . . . . . . . . : Friday, December 16, 2011 1:48:25 PM
Lease Expires . . . . . . . . . . : Saturday, December 17, 2011 1:48:25 PM
Server: cdns2.cox.net
Address: 68.105.28.12
Name: google.com
Addresses: 74.125.227.52, 74.125.227.48, 74.125.227.49, 74.125.227.50
74.125.227.51
Pinging google.com [74.125.227.51] with 32 bytes of data:
Reply from 74.125.227.51: bytes=32 time=46ms TTL=57
Reply from 74.125.227.51: bytes=32 time=45ms TTL=57
Ping statistics for 74.125.227.51:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 45ms, Maximum = 46ms, Average = 45ms
Server: cdns2.cox.net
Address: 68.105.28.12
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
Pinging yahoo.com [72.30.2.43] with 32 bytes of data:
Reply from 72.30.2.43: bytes=32 time=40ms TTL=57
Reply from 72.30.2.43: bytes=32 time=38ms TTL=57
Ping statistics for 72.30.2.43:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 38ms, Maximum = 40ms, Average = 39ms
Server: cdns2.cox.net
Address: 68.105.28.12
Name: bleepingcomputer.com
Address: 208.43.87.2
Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
Request timed out.
Request timed out.
Ping statistics for 208.43.87.2:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 07 e9 bf a7 4e ...... Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.105 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.105 192.168.1.105 20
192.168.1.105 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.105 192.168.1.105 20
224.0.0.0 240.0.0.0 192.168.1.105 192.168.1.105 20
255.255.255.255 255.255.255.255 192.168.1.105 192.168.1.105 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None
========================= Event log errors: ===============================
Application errors:
==================
Error: (12/16/2011 01:28:55 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/16/2011 01:16:07 PM) (Source: Microsoft Security Client) (User: )
Description: mssecurityclientmsseces.exe2.1.1116.00x8024400aupdatecmainwindow__onsignatureupdatestatus0security essentialsNILNILNIL
Error: (12/16/2011 01:13:37 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024400a, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/16/2011 11:34:09 AM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/15/2011 10:58:14 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024400a, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/15/2011 09:06:45 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024400a, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/15/2011 07:57:35 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024400a, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/15/2011 07:21:22 PM) (Source: MPSampleSubmission) (User: )
Description: EventType mptelemetry, P1 8024402c, P2 endsearch, P3 search, P4 3.0.8402.0, P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094), P8 NIL, P9 mptelemetry0, P10 mptelemetry1.
Error: (12/15/2011 07:17:49 PM) (Source: MsiInstaller) (User: Owner)Owner
Description: Product: Intel® Network Connections -- The installed version of Intel PROSet is not supported for upgrades. You must uninstall it before installing this version.
Error: (12/15/2011 07:14:29 PM) (Source: MsiInstaller) (User: Owner)Owner
Description: Product: Intel® Network Connections -- The installed version of Intel PROSet is not supported for upgrades. You must uninstall it before installing this version.
System errors:
=============
Error: (12/16/2011 01:28:56 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (12/16/2011 01:28:56 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (12/16/2011 01:28:56 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (12/16/2011 01:28:56 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %NT AUTHORITY51
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\NETWORK SERVICE
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (12/16/2011 01:28:54 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %NT AUTHORITY59
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\SYSTEM
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Error: (12/16/2011 01:15:42 PM) (Source: Microsoft Antimalware) (User: )
Description: %JOEL03227660 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %JOEL03227651
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %JOEL032276602
Update Type: %JOEL032276604
User: JOEL032276\Owner
Current Engine Version: %JOEL032276605
Previous Engine Version: %JOEL032276606
Error code: %JOEL032276607
Error description: %JOEL032276608
Error: (12/16/2011 01:15:42 PM) (Source: Microsoft Antimalware) (User: )
Description: %JOEL03227660 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %JOEL03227651
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %JOEL032276602
Update Type: %JOEL032276604
User: JOEL032276\Owner
Current Engine Version: %JOEL032276605
Previous Engine Version: %JOEL032276606
Error code: %JOEL032276607
Error description: %JOEL032276608
Error: (12/16/2011 01:15:42 PM) (Source: Microsoft Antimalware) (User: )
Description: %JOEL03227660 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %JOEL03227651
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %JOEL032276602
Update Type: %JOEL032276604
User: JOEL032276\Owner
Current Engine Version: %JOEL032276605
Previous Engine Version: %JOEL032276606
Error code: %JOEL032276607
Error description: %JOEL032276608
Error: (12/16/2011 01:15:42 PM) (Source: Microsoft Antimalware) (User: )
Description: %JOEL03227660 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %JOEL03227651
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %JOEL032276602
Update Type: %JOEL032276604
User: JOEL032276\Owner
Current Engine Version: %JOEL032276605
Previous Engine Version: %JOEL032276606
Error code: %JOEL032276607
Error description: %JOEL032276608
Error: (12/16/2011 01:13:36 PM) (Source: Microsoft Antimalware) (User: )
Description: %NT AUTHORITY60 has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.117.787.0
Update Source: %NT AUTHORITY59
Update Stage: 3.0.8402.00
Source Path: 3.0.8402.01
Signature Type: %NT AUTHORITY602
Update Type: %NT AUTHORITY604
User: NT AUTHORITY\SYSTEM
Current Engine Version: %NT AUTHORITY605
Previous Engine Version: %NT AUTHORITY606
Error code: %NT AUTHORITY607
Error description: %NT AUTHORITY608
Microsoft Office Sessions:
=========================
Error: (12/16/2011 01:28:55 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024402cendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/16/2011 01:16:07 PM) (Source: Microsoft Security Client)(User: )
Description: mssecurityclientmsseces.exe2.1.1116.00x8024400aupdatecmainwindow__onsignatureupdatestatus0security essentialsNILNILNIL
Error: (12/16/2011 01:13:37 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024400aendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/16/2011 11:34:09 AM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024402cendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/15/2011 10:58:14 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024400aendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/15/2011 09:06:45 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024400aendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/15/2011 07:57:35 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024400aendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/15/2011 07:21:22 PM) (Source: MPSampleSubmission)(User: )
Description: mptelemetry8024402cendsearchsearch3.0.8402.0mpsigdwn.dll3.0.8402.0microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094)NILNILNIL
Error: (12/15/2011 07:17:49 PM) (Source: MsiInstaller)(User: Owner)Owner
Description: Product: Intel® Network Connections -- The installed version of Intel PROSet is not supported for upgrades. You must uninstall it before installing this version.(NULL)(NULL)(NULL)
Error: (12/15/2011 07:14:29 PM) (Source: MsiInstaller)(User: Owner)Owner
Description: Product: Intel® Network Connections -- The installed version of Intel PROSet is not supported for upgrades. You must uninstall it before installing this version.(NULL)(NULL)(NULL)
========================= Memory info: ===================================
Percentage of memory in use: 49%
Total physical RAM: 1021.8 MB
Available physical RAM: 513.64 MB
Total Pagefile: 2464.6 MB
Available Pagefile: 1987.45 MB
Total Virtual: 2047.88 MB
Available Virtual: 1977.71 MB
========================= Partitions: =====================================
2 Drive c: () (Fixed) (Total:38.28 GB) (Free:14.21 GB) NTFS
4 Drive e: () (Removable) (Total:0.99 GB) (Free:0.87 GB) FAT
========================= Users: ========================================
User accounts for \\JOEL032276
Administrator Guest HelpAssistant
kael Owner SUPPORT_388945a0
**** End of log ****
This post has been edited by Budapest: 16 December 2011 - 05:23 PM
Reason for edit: Moved from Networking ~Budapest

Help


Back to top









