Hi Everyone,
A couple of days ago I had decided to clean my pc from infections. I started reading topics on the internet about removing infections, and followed their directions. In the process I downloaded many tools, and many infections were deleted. when it seemed everything is fine, I removed everything downloaded and chose to keep the following programs: Advanced System Care Pro 5, Malwarebytes Anti Malware, and Avast Antivirus.
As a last check I downloaded ComboFix and did a scan; it produced the following log:
Please find the Log attached, it seems to be too long to be posted in the topic.
I downloaded the Recovery Console, and new scans don’t show any infections.
I installed aswMBR and the scan showed the following Log:
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-03-24 11:58:23 ----------------------------- 11:58:23.109 OS Version: Windows 5.1.2600 Service Pack 2 11:58:23.109 Number of processors: 2 586 0x403 11:58:23.109 ComputerName: USER-42137CEAB2 UserName: 11:58:24.937 Initialize success 11:58:25.375 AVAST engine defs: 12032302 11:59:12.234 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-e 11:59:12.234 Disk 0 Vendor: STM3250318AS CC38 Size: 238475MB BusType: 3 11:59:12.296 Disk 0 MBR read successfully 11:59:12.296 Disk 0 MBR scan 11:59:12.312 Disk 0 Windows XP default MBR code 11:59:12.312 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 49999 MB offset 63 11:59:12.328 Disk 0 Partition - 00 0F Extended LBA 188465 MB offset 102398310 11:59:12.359 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 188465 MB offset 102398373 11:59:12.359 Disk 0 scanning sectors +488376000 11:59:12.453 Disk 0 scanning C:\WINDOWS\system32\drivers 11:59:21.781 Service scanning 11:59:31.125 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys **LOCKED** 32 11:59:34.109 Modules scanning 11:59:37.781 Disk 0 trace - called modules: 11:59:37.828 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x863921e8]< \Device\Harddisk0\DR0[0x86338ab8] 11:59:37.859 3 CLASSPNP.SYS[f761705b] -> nt!IofCallDriver -> \Device\0000007b[0x8633c3b8] 11:59:37.875 5 ACPI.sys[f7477620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-e[0x86383d98] 11:59:37.890 \Driver\atapi[0x863889c8] -> IRP_MJ_CREATE -> 0x863921e8 11:59:39.203 AVAST engine scan C:\WINDOWS 11:59:42.578 AVAST engine scan C:\WINDOWS\system32 12:01:36.671 AVAST engine scan C:\WINDOWS\system32\drivers 12:01:47.875 AVAST engine scan C:\Documents and Settings\AdministratorMMD 12:02:18.359 AVAST engine scan C:\Documents and Settings\All Users 12:02:46.109 Scan finished successfully 12:03:14.937 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\AdministratorMMD\Desktop\MBR.dat" 12:03:14.953 The log file has been saved successfully to "C:\Documents and Settings\AdministratorMMD\Desktop\aswMBR.txt"
It shows that there is a problem with the following:
“11:59:31.125 Service sptd C:\WINDOWS\System32\Drivers\sptd.sys LOCKED 32”
“11:59:37.828 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x863921e8]<<”
“11:59:37.890 \Driver\atapi[0x863889c8] → IRP_MJ_CREATE → 0x863921e8”
[ol]- The first is probably from a program Deamon Tools Or Alcohol 120% which I had installed before as what a google search showed, should I delete it since I don’t have them anymore? I don’t know if I should fix the other two as well.
- Do I need any more Program checks to insure that my system is clean? and Can you please help me with the process.
- I searched and the anti-wares installed doesn’t seem to conflict however any recommendations. And should I download any other programs to keep my system safe?
[/ol]
I would appreciate your assistant and support.