My Asus eeepc 1000h, with Windows XP SP3, as become infected with the Portuguese version of the Ukash Virus.
A "Policia de Segurança Publica", or PSP (Public Security Police) false warning, completely overtook the screen, making all keyboard shortcuts or software unavailable, unless payment of 100€!!
Luckily, there's another pc in the house, so after five minutes on Google, I managed to identify the problem and gained access once again to the normal operating system environment, after using the Safe Windows Mode.
I hard deleted a ctfmon.exe file, residing in the WINDOWS\SYSTEM32 folder, and subsequent entries in the startup menu, with Ccleaner.
That seems to have solved the problem for the moment...
But how can I be sure of the complete removal of the virus? I've read numerous entries, about a recurrence of the same, and therefore would like your help, in order to prevent the same thing happening.
I've attached the required logs from dds and gmer and the scan result from DDS is at the end of the post.
Thanks for all your time.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 10.4.0
Run by Zombie at 17:29:48 on 2012-07-07
Microsoft Windows XP Professional 5.1.2600.3.1252.351.1033.18.2039.1376 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\CM93v3 SDK\System\cmapsvc.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
D:\PORTABLE\PROCESSEXPLORER\PROCEXP.EXE
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Microsoft SQL Server\MSSQL10_50.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Cracked License Manager 10\lmgrd.exe
C:\Cracked License Manager 10\ARCGIS.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
D:\portable\Appetizer essential\Appetizer.exe
D:\portable\FirefoxPortable\FirefoxPortable.exe
D:\portable\FirefoxPortable\App\firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = hxxp://picasa.google.com/support/bin/answer.py?hl=pt_PT&answer=93773
uInternet Settings,ProxyServer = socks=127.0.0.1:38190
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre7\bin\ssv.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
mRun: [<NO NAME>]
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [SoundMan] SOUNDMAN.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\arcgis~1.lnk - c:\cracked license manager 10\start_lic_mgr_invisible.vbs
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\arcgis~1.lnk - c:\cracked license manager 10\start_lic_mgr_invisible.vbs
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Transferir com Mipony - file://c:\program files\mipony\browser\IEContext.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
TCP: DhcpNameServer = 192.168.3.1
TCP: Interfaces\{333F58B2-BB92-4AD9-BD67-699C14392F92} : DhcpNameServer = 192.168.3.1
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
IFEO: taskmgr.exe - "d:\portable\processexplorer\PROCEXP.EXE"
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-1-22 612184]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-1-22 337880]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-1-22 20696]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-1-22 44768]
R2 C-Map Service;C-Map Service;c:\program files\cm93v3 sdk\system\cmapsvc.exe [2010-3-23 544768]
R3 PROCEXP151;PROCEXP151;\??\c:\windows\system32\drivers\procexp151.sys --> c:\windows\system32\drivers\PROCEXP151.SYS [?]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2012-1-22 704384]
S1 vcdrom;Virtual CD-ROM Device Driver;\??\c:\documents and settings\zombie\desktop\virtual\vcdrom.sys --> c:\documents and settings\zombie\desktop\virtual\VCdRom.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Serviço Google Update (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-4-27 116648]
S3 gupdatem;Serviço Google Update (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-4-27 116648]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2012-2-25 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2012-2-25 11104]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2012-4-12 104752]
S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\drivers\vboxnetflt.sys --> c:\windows\system32\drivers\VBoxNetFlt.sys [?]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe [2010-4-3 44896]
S4 RsFx0150;RsFx0150 Driver;c:\windows\system32\drivers\RsFx0150.sys [2010-4-3 240608]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\microsoft sql server\mssql10_50.sqlexpress\mssql\binn\SQLAGENT.EXE [2010-4-3 367456]
.
=============== Created Last 30 ================
.
2012-07-07 15:38:55 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-07-07 15:38:52 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-07-07 15:38:52 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-07-07 14:18:51 -------- d-----w- c:\documents and settings\zombie\application data\Guetd
2012-07-07 14:18:51 -------- d-----w- c:\documents and settings\zombie\application data\Eqqi
2012-07-07 00:33:26 -------- d-----w- c:\program files\Geosoft
2012-07-07 00:27:20 -------- d-----w- c:\windows\Geosoft_Installer
2012-07-05 15:22:44 -------- d-----w- c:\program files\G-Raster
2012-07-05 08:26:29 -------- d-----w- c:\documents and settings\zombie\application data\Mobile Atlas Creator
2012-06-26 15:46:46 -------- d-----w- c:\program files\common files\DataEast
2012-06-26 15:46:46 -------- d-----w- c:\documents and settings\zombie\application data\DataEast
2012-06-26 15:46:31 -------- d-----w- c:\program files\DataEast
2012-06-13 20:17:14 -------- d-----w- c:\program files\AZPR
2012-06-13 14:44:22 -------- d-----r- C:\Sandbox
2012-06-13 14:41:53 -------- d-----w- c:\program files\Sandboxie
2012-06-12 14:58:25 -------- d-----w- c:\program files\PDF24
2012-06-12 14:50:23 -------- d-----w- c:\documents and settings\zombie\local settings\application data\PDF24
2012-06-12 14:28:00 -------- d-----w- c:\documents and settings\zombie\local settings\application data\Tekmap_Consulting
2012-06-12 14:22:04 -------- d-----w- c:\program files\Tekmap
2012-06-12 14:00:21 -------- d-----w- c:\program files\DeepVision
2012-06-12 11:01:10 -------- d-----w- c:\program files\Ocean Ecology
2012-06-11 15:13:46 -------- d-----w- c:\documents and settings\all users\application data\TranscoordPro
2012-06-11 15:13:21 -------- d-----w- c:\program files\Transcoord Pro
2012-06-11 15:13:13 286720 ------w- c:\windows\Setup1.exe
2012-06-11 15:13:12 73216 ----a-w- c:\windows\ST6UNST.EXE
2012-06-11 06:20:46 -------- d-----w- c:\program files\Dropbox
.
==================== Find3M ====================
.
2012-04-27 17:20:59 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-04-27 17:20:58 772552 ----a-w- c:\windows\system32\npdeployJava1.dll
2012-04-27 17:20:58 687560 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-27 15:35:32 3993600 ----a-w- c:\program files\GUTC3.tmp
2012-04-12 17:21:14 104752 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2012-04-12 17:21:12 91952 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2012-04-12 17:21:12 158512 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
.
============= FINISH: 17:33:45,45 ===============


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top




















