Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows Recovery Virus or SysWow64 - Whatever it is, I can't fix it.


  • This topic is locked This topic is locked
2 replies to this topic

#1 scmd892

scmd892

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:12:55 PM

Posted 31 May 2011 - 11:25 PM

Hey all,

First time here. A couple hours ago I came up with the Windows Recovery virus and shut the computer down, put it into safe mode and ran Malwarebyes. It came up with 4 infections. I removed them. Restarted into safe mode. Still coming up as everything is still changed and locked. I have ran Hijack This, Rkill, SuperAntispyware and read almost everything on the internet. I have ran the Unhide.exe it's not finding anything to unhide. I've changed the attributes through the folders to show all hidden, etc. but things are still coming up locked, my desktop is still gone, my taskbar icons are missing as are my start buttons/menus.

BIG ISSUE:

Anything that the websites come up with saying that they should appear in my %appdata% or registry, those keys are not there so I cannot delete them. When I try and remove the SysWow64 folder from my registry, it does not permit that either.


HERE IS THE DDS LOG:
.
DDS (Ver_11-05-19.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.7601.17514
Run by home at 0:18:25 on 2011-06-01
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://homepage.gateway.com/rdr.aspx?b=ACGW&l=0409&m=dx4831&r=17360110p106p0355v125k4911r22s
uURLSearchHooks: H - No File
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
StartupFolder: C:\Users\home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PDANET~1.LNK - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
StartupFolder: C:\Users\home\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\PDANET~1.LNK - C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
TCP: {5823C95B-1072-46CC-9FC4-2B210B3C844B} = 192.168.10.1
BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll
BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
BHO-X64: ZoneAlarm Security Engine Registrar: {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
BHO-X64: ZoneAlarm Security Engine Registrar - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB-X64: ZoneAlarm Security Engine: {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
TB-X64: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB-X64: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB-X64: {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
AppInit_DLLs-X64: avgrssta.dll
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2011-06-01 02:56:14 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2011-06-01 02:47:29 -------- d-----w- C:\Users\home\AppData\Roaming\SUPERAntiSpyware.com
2011-06-01 02:47:29 -------- d-----w- C:\Users\home\AppData\Roaming\SUPERAntiSpyware.com
2011-05-25 03:49:41 27520 ----a-w- C:\Windows\System32\drivers\Diskdump.sys
2011-05-19 23:00:41 -------- d-----w- C:\Users\home\AppData\Local\Amazon
2011-05-17 15:40:23 142336 ----a-w- C:\Windows\System32\poqexec.exe
2011-05-17 15:40:23 123904 ----a-w- C:\Windows\SysWow64\poqexec.exe
2011-05-17 15:17:40 15360 ----a-w- C:\Windows\System32\drivers\pneteth.sys
2011-05-17 15:17:39 -------- d-----w- C:\Program Files (x86)\PdaNet for Android
2011-05-17 15:17:24 3109320 ----a-w- C:\Users\home\PdaNetA300x64.exe
2011-05-15 02:22:13 -------- d-----w- C:\Users\home\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2011-05-15 02:22:13 -------- d-----w- C:\Users\home\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
2011-05-15 02:21:51 -------- d-----w- C:\Users\home\AppData\Roaming\HTC
2011-05-15 02:21:51 -------- d-----w- C:\Users\home\AppData\Roaming\HTC
2011-05-15 02:20:20 -------- d-----w- C:\Users\home\AppData\Local\Downloaded Installations
2011-05-15 02:20:08 -------- d-----w- C:\Program Files (x86)\Spirent Communications
2011-05-15 02:19:57 -------- d-----w- C:\Program Files (x86)\HTC
2011-05-11 23:49:46 -------- d-----w- C:\Users\home\AppData\Roaming\Windows Live Writer
2011-05-11 23:49:46 -------- d-----w- C:\Users\home\AppData\Roaming\Windows Live Writer
2011-05-11 23:49:43 -------- d-----w- C:\Users\home\AppData\Local\Windows Live Writer
2011-05-11 02:28:28 -------- d-----w- C:\45a0eea5648e79a87452b5aaade2
2011-05-10 22:39:51 5562240 ----a-w- C:\Windows\System32\ntoskrnl.exe
2011-05-10 22:39:50 3967872 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2011-05-10 22:39:50 3912576 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2011-05-10 22:39:49 98816 ----a-w- C:\Windows\System32\drivers\usbccgp.sys
2011-05-10 22:39:49 7936 ----a-w- C:\Windows\System32\drivers\usbd.sys
2011-05-10 22:39:49 52736 ----a-w- C:\Windows\System32\drivers\usbehci.sys
2011-05-10 22:39:49 343040 ----a-w- C:\Windows\System32\drivers\usbhub.sys
2011-05-10 22:39:49 325120 ----a-w- C:\Windows\System32\drivers\usbport.sys
2011-05-10 22:39:49 30720 ----a-w- C:\Windows\System32\drivers\usbuhci.sys
2011-05-10 22:39:49 25600 ----a-w- C:\Windows\System32\drivers\usbohci.sys
2011-05-06 02:28:01 -------- d-----w- C:\Users\home\.storybook
2011-05-06 02:27:54 -------- d-----w- C:\Program Files (x86)\Storybook
.
==================== Find3M ====================
.
2011-05-29 13:11:30 39984 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
2011-05-29 13:11:20 25912 ----a-w- C:\Windows\System32\drivers\mbam.sys
2011-05-07 00:27:43 317520 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
2011-03-29 18:00:00 92672 ----a-w- C:\Windows\System32\ff_vfw.dll
2011-03-20 06:37:07 112 ----a-w- C:\Users\home\AppData\Roaming\srvblck2.tmp
2011-03-20 06:37:07 112 ----a-w- C:\Users\home\AppData\Roaming\srvblck2.tmp
2011-03-12 12:08:49 1465344 ----a-w- C:\Windows\System32\XpsPrint.dll
2011-03-12 11:23:45 870912 ----a-w- C:\Windows\SysWow64\XpsPrint.dll
2011-03-11 06:41:37 189824 ----a-w- C:\Windows\System32\drivers\storport.sys
2011-03-11 06:41:34 166272 ----a-w- C:\Windows\System32\drivers\nvstor.sys
2011-03-11 06:41:34 1659776 ----a-w- C:\Windows\System32\drivers\ntfs.sys
2011-03-11 06:41:34 148352 ----a-w- C:\Windows\System32\drivers\nvraid.sys
2011-03-11 06:41:26 410496 ----a-w- C:\Windows\System32\drivers\iaStorV.sys
2011-03-11 06:41:12 27008 ----a-w- C:\Windows\System32\drivers\amdxata.sys
2011-03-11 06:41:12 107904 ----a-w- C:\Windows\System32\drivers\amdsata.sys
2011-03-11 06:34:51 1359872 ----a-w- C:\Windows\System32\mfc42u.dll
2011-03-11 06:34:50 1395712 ----a-w- C:\Windows\System32\mfc42.dll
2011-03-11 06:33:29 2565632 ----a-w- C:\Windows\System32\esent.dll
2011-03-11 06:30:28 96768 ----a-w- C:\Windows\System32\fsutil.exe
2011-03-11 05:33:59 1164288 ----a-w- C:\Windows\SysWow64\mfc42u.dll
2011-03-11 05:33:59 1137664 ----a-w- C:\Windows\SysWow64\mfc42.dll
2011-03-11 05:33:09 1699328 ----a-w- C:\Windows\SysWow64\esent.dll
2011-03-11 05:31:07 74240 ----a-w- C:\Windows\SysWow64\fsutil.exe
2011-03-08 06:29:32 976896 ----a-w- C:\Windows\System32\inetcomm.dll
2011-03-08 05:28:29 741376 ----a-w- C:\Windows\SysWow64\inetcomm.dll
2011-03-07 06:31:44 1188864 ----a-w- C:\Windows\System32\wininet.dll
2011-03-07 05:33:13 981504 ----a-w- C:\Windows\SysWow64\wininet.dll
2011-03-07 04:24:34 1638912 ----a-w- C:\Windows\System32\mshtml.tlb
2011-03-07 03:52:25 1638912 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2011-03-05 10:47:44 123392 ----a-w- C:\Windows\System32\lagarith.dll
2011-03-04 06:19:28 135168 ----a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll
2011-03-04 06:19:27 350208 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
2011-03-03 06:24:16 183296 ----a-w- C:\Windows\System32\dnsrslvr.dll
2011-03-03 06:21:57 30208 ----a-w- C:\Windows\System32\dnscacheugc.exe
2011-03-03 05:36:16 28672 ----a-w- C:\Windows\SysWow64\dnscacheugc.exe
.
============= FINISH: 0:18:47.27 ===============

Hey all,

I just wanted to let you know that it's gotten worse. Now I can't Windows to load past its startup menu with all the flowers and spinning icon. It just keeps flashing every few seconds.

Help?

EDIT: Posts merged ~Budapest

Edited by Budapest, 01 June 2011 - 04:50 PM.


BC AdBot (Login to Remove)

 


#2 m0le

m0le

    Can U Dig It?


  • Malware Response Instructor
  • 33,724 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:55 PM

Posted 09 June 2011 - 05:36 PM

Hi,

Welcome to Bleeping Computer. My name is m0le and I will be helping you with your log.
  • Please subscribe to this topic, if you haven't already. Click the Watch This Topic button at the top on the right.

  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.

  • Please reply to this post so I know you are there.
The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then I will close the topic.

Once I receive a reply then I will return with your first instructions.

Thanks :thumbup2:
[If I have helped you fix your PC then please donate. Thanks
jetian6yw.jpg
m0le is a proud member of UNITE

#3 m0le

m0le

    Can U Dig It?


  • Malware Response Instructor
  • 33,724 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:London, UK
  • Local time:06:55 PM

Posted 13 June 2011 - 06:57 PM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
[If I have helped you fix your PC then please donate. Thanks
jetian6yw.jpg
m0le is a proud member of UNITE




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users