I came from this topic to here.
I have pop-up banners in Firefox and Internet Explorer appearing in the right corner of my browser. After several tryouts with scanners they don't want to go away. In these scans it was visible I have a backdoor Trojan on my pc. To clean it, I was sent here.
I hope somebody can help curing my pc!
This is the DDS log, and please see attachment for the attach.txt log.
I couldn't create a GMER Log because my windows is a 64 bit version.
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_23
Run by MI at 1:33:06 on 2012-05-28
.
============== Running Processes ===============
.
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uWindow Title = Windows Internet Explorer wordt aangeboden door MSN and Bing
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Aanmelden - Help: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: {A057A204-BACC-4D26-8287-79A187E26987} - No File
uRun: [SoftAuto.exe] "C:\Program Files (x86)\Creative\Software Update 3\SoftAuto.exe"
uRun: [Akamai NetSession Interface] "C:\Users\MI\AppData\Local\Akamai\netsession_win.exe"
uRun: [Xvid] C:\Program Files (x86)\Xvid\CheckUpdate.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
StartupFolder: C:\Users\MI\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\VIIKII~1.LNK - C:\Program Files (x86)\ViiKiiDesktopPlugin\ViiKiiDesktopPlugin.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} - hxxps://oas.support.microsoft.com/ActiveX/MSDcode.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://download.divx.com/player/DivXBrowserPlugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {C342F4EE-6D48-4239-A55D-CF2D0D1F3BC6} - hxxp://music.global.cyworld.com/Content/package/skcaset.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} - hxxp://cache.hyves-static.net/statics/Aurigma/ImageUploader4.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{63950901-CDDF-4C45-BD3E-1C2F1F38FFC4} : DhcpNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: DivX Plus Web Player HTML5 <video>: {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO-X64: Increase performance and video formats for your HTML5 <video> - No File
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Windows Live Aanmelden - Help: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: {A057A204-BACC-4D26-8287-79A187E26987} - No File
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
Hosts: 176.9.75.3 www.google-analytics.com.
Hosts: 176.9.75.3 ad-emea.doubleclick.net.
Hosts: 176.9.75.3 www.statcounter.com.
Hosts: 108.163.215.51 www.google-analytics.com.
Hosts: 108.163.215.51 ad-emea.doubleclick.net.
.
Note: multiple HOSTS entries found. Please refer to Attach.txt
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\MI\AppData\Roaming\Mozilla\Firefox\Profiles\3pwznh6q.default\
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCMListControl.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npcyworld.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\nppeeraod.dll
FF - plugin: C:\Windows\npcyworld.dll
FF - plugin: C:\Windows\nppeeraod.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
.
=============== Created Last 30 ================
.
2012-05-27 10:34:41 8955792 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0BCC68E9-7BDF-49AA-B4AF-F816EF87C391}\mpengine.dll
2012-05-25 21:49:23 8955792 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-25 20:15:48 -------- d-----w- C:\Program Files (x86)\ESET
2012-05-24 20:38:10 -------- d-----w- C:\Users\MI\AppData\Roaming\AVI ReComp
2012-05-24 20:34:06 696832 ----a-w- C:\Windows\System32\xvidcore.dll
2012-05-24 20:34:06 645632 ----a-w- C:\Windows\SysWow64\xvidcore.dll
2012-05-24 20:34:06 255488 ----a-w- C:\Windows\System32\xvidvfw.dll
2012-05-24 20:34:06 240640 ----a-w- C:\Windows\SysWow64\xvidvfw.dll
2012-05-24 20:34:06 173568 ----a-w- C:\Windows\System32\xvid.ax
2012-05-24 20:34:06 153088 ----a-w- C:\Windows\SysWow64\xvid.ax
2012-05-24 20:34:02 -------- d-----w- C:\Program Files (x86)\Xvid
2012-05-24 20:33:25 -------- d-----w- C:\Program Files (x86)\AviSynth 2.5
2012-05-24 20:32:14 -------- d-----w- C:\Program Files (x86)\AVI ReComp
2012-05-21 19:04:19 -------- d-----w- C:\Windows\SysWow64\Adobe
2012-05-20 15:33:55 -------- d-----w- C:\Users\MI\AppData\Roaming\SUPERAntiSpyware.com
2012-05-20 15:33:07 -------- d-----w- C:\ProgramData\SUPERAntiSpyware.com
2012-05-20 15:33:07 -------- d-----w- C:\Program Files\SUPERAntiSpyware
2012-05-05 20:47:27 -------- d-----w- C:\Windows\SysWow64\Wat
2012-05-05 20:47:27 -------- d-----w- C:\Windows\System32\Wat
2012-05-05 11:45:54 927800 ------w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{439537DA-4D30-41A8-8CE5-EACCB7CCD9E3}\gapaengine.dll
2012-05-05 11:44:55 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe
2012-05-05 11:44:55 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-05-05 11:44:55 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-05-05 11:43:14 -------- d-----w- C:\Program Files (x86)\Microsoft Security Client
2012-05-05 11:43:13 -------- d-----w- C:\Program Files\Microsoft Security Client
2012-05-05 10:46:13 -------- d-sh--w- C:\Windows\System32\%APPDATA%
2012-05-03 20:52:35 -------- d-----w- C:\Windows\System32\SPReview
2012-05-03 20:52:01 -------- d-----w- C:\Windows\System32\EventProviders
2012-05-03 20:49:01 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-05-03 20:49:00 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-05-03 20:49:00 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2012-05-03 20:49:00 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-05-03 20:49:00 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-05-03 20:49:00 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-05-03 20:49:00 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-05-03 20:45:59 584192 ----a-w- C:\Windows\SysWow64\gpprefcl.dll
2012-05-03 20:44:59 93696 ----a-w- C:\Windows\SysWow64\fms.dll
2012-05-03 20:43:54 606208 ----a-w- C:\Windows\SysWow64\wbem\fastprox.dll
2012-05-03 20:43:54 363008 ----a-w- C:\Windows\SysWow64\wbemcomn.dll
2012-05-03 20:42:44 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
2012-05-03 20:26:16 723456 ----a-w- C:\Windows\System32\EncDec.dll
2012-05-03 20:26:16 534528 ----a-w- C:\Windows\SysWow64\EncDec.dll
2012-05-03 20:24:26 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2012-05-03 20:24:26 2048 ----a-w- C:\Windows\System32\tzres.dll
2012-05-03 20:24:14 1731920 ----a-w- C:\Windows\System32\ntdll.dll
2012-05-03 20:24:14 -------- d-sh--w- C:\Users\MI\AppData\Local\{5c9ce6d3-52ff-ca64-83a3-dc3769b8c19e}
2012-05-03 20:24:13 1292080 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-05-03 20:24:08 77312 ----a-w- C:\Windows\System32\packager.dll
2012-05-03 20:24:08 67072 ----a-w- C:\Windows\SysWow64\packager.dll
.
==================== Find3M ====================
.
2012-05-21 18:10:54 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-21 18:10:54 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-03 21:11:07 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2012-05-03 21:11:06 175616 ----a-w- C:\Windows\System32\msclmd.dll
2012-04-04 13:56:40 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-03-31 06:05:57 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-03-20 18:44:12 98688 ----a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-20 18:44:12 203888 ----a-w- C:\Windows\System32\drivers\MpFilter.sys
2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-03-03 06:35:38 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2012-03-03 05:31:19 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll
2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll
2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl
2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb
2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll
2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll
2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2010-05-26 08:17:42 460088 ----a-w- C:\Program Files (x86)\setup.exe
.
============= FINISH: 1:33:26,71 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top











