.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.13
Run by Bill at 18:46:15 on 2012-07-10
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.155 [GMT -5:00]
.
AV: Microsoft Security Essentials *Enabled/Outdated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\ctfmon.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
.
============== Pseudo HJT Report ===============
.
uInternet Connection Wizard,ShellNext = iexplore
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [Motive SmartBridge] c:\progra~1\sbcsel~1\smartb~1\MotiveSB.exe
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [BJCFD] c:\program files\broadjump\client foundation\CFD.exe
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - {4C171D40-8277-11D5-AD55-00010333D0AD} - c:\program files\yahoo!\messenger\yhexbmes.dll
IE: {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - {552781AF-37E4-4FEE-920A-CED9E648EADD} - c:\program files\common files\microsoft shared\encarta search bar\ENCSBAR.DLL
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {1340C00E-B1FF-4117-B993-E58FF774A605} - hxxp://www.playrealbaseball.com/include/launchRBO_v1.1.0.0.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader.cab
DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - hxxp://go.divx.com/plugin/DivXBrowserPlugin.cab
DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1235576987612
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} - hxxp://download.yahoo.com/dl/installs/ymail/ymmapi.dll
DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{8DB93102-3E82-493A-B435-CAFAF162BDBD} : DhcpNameServer = 209.18.47.61 209.18.47.62
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\bill\application data\mozilla\firefox\profiles\e5j4nr6x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?FORM=IEFM1&q=
FF - plugin: c:\documents and settings\bill\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.50917.0\npctrlui.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2010-7-1 54752]
S2 NAVAPEL;NAVAPEL;\??\c:\program files\navnt\navapel.sys --> c:\program files\navnt\NAVAPEL.SYS [?]
S2 RPCM;Remote Procedure Manager(TPM);c:\program files\common files\microsoft shared\speech\csvde.exe --> c:\program files\common files\microsoft shared\speech\csvde.exe [?]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2008-8-21 18688]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2008-8-21 8320]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-6-18 23680]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-7-5 113120]
S3 NAVAP;NAVAP;\??\c:\program files\navnt\navap.sys --> c:\program files\navnt\NAVAP.sys [?]
S3 PORTMON;PORTMON;\??\c:\sys\portmsys.sys --> c:\sys\PORTMSYS.SYS [?]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2008-5-6 11520]
.
=============== Created Last 30 ================
.
2012-07-10 20:31:07 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2012-07-10 20:10:04 0 ----a-w- c:\windows\system32\REN13.tmp
2012-07-10 20:10:04 0 ----a-w- c:\windows\system32\REN12.tmp
2012-07-10 19:11:02 88892788 ----a-w- c:\windows\PreSymantecRemoval.reg
2012-07-10 17:06:12 -------- d-----w- C:\drvrtmp
2012-07-06 00:07:22 -------- d-----w- c:\program files\Microsoft ATS
2012-07-05 19:01:06 -------- d-----w- c:\program files\ACW
2012-07-03 20:55:56 116224 ----a-w- c:\windows\system32\dllcache\xrxwiadr.dll
2012-07-03 20:55:53 23040 ----a-w- c:\windows\system32\dllcache\xrxwbtmp.dll
2012-07-03 20:55:52 18944 ----a-w- c:\windows\system32\dllcache\xrxscnui.dll
2012-07-03 20:55:48 27648 ----a-w- c:\windows\system32\dllcache\xrxftplt.exe
2012-07-03 20:55:43 4608 ----a-w- c:\windows\system32\dllcache\xrxflnch.exe
2012-07-03 20:55:35 99865 ----a-w- c:\windows\system32\dllcache\xlog.exe
2012-07-03 20:55:15 16970 ----a-w- c:\windows\system32\dllcache\xem336n5.sys
2012-07-03 20:55:12 19455 ----a-w- c:\windows\system32\dllcache\wvchntxx.sys
2012-07-03 20:55:03 12063 ----a-w- c:\windows\system32\dllcache\wsiintxx.sys
2012-07-03 20:55:01 8192 ----a-w- c:\windows\system32\dllcache\wshirda.dll
2012-07-03 20:54:12 8832 ----a-w- c:\windows\system32\dllcache\wmiacpi.sys
2012-07-03 20:54:06 154624 ----a-w- c:\windows\system32\dllcache\wlluc48.sys
2012-07-03 20:54:02 34890 ----a-w- c:\windows\system32\dllcache\wlandrv2.sys
2012-07-03 20:52:58 397502 ----a-w- c:\windows\system32\dllcache\vpctcom.sys
2012-07-03 20:51:57 94720 ----a-w- c:\windows\system32\dllcache\umaxud32.dll
2012-07-03 20:50:59 315520 ----a-w- c:\windows\system32\dllcache\trid3d.dll
2012-07-03 20:49:59 36640 ----a-w- c:\windows\system32\dllcache\t2r4mini.sys
2012-07-03 20:48:59 24660 ----a-w- c:\windows\system32\dllcache\spxupchk.dll
2012-07-03 20:47:59 45568 ----a-w- c:\windows\system32\dllcache\smb3w.dll
2012-07-03 20:46:52 161568 ----a-w- c:\windows\system32\dllcache\sgsmusb.sys
2012-07-03 20:45:57 75392 ----a-w- c:\windows\system32\dllcache\s3savmxm.sys
2012-07-03 20:44:57 79104 ----a-w- c:\windows\system32\dllcache\rocket.sys
2012-07-03 20:43:57 35328 ----a-w- c:\windows\system32\dllcache\psisload.dll
2012-07-03 20:42:58 26153 ----a-w- c:\windows\system32\dllcache\pcmlm56.sys
2012-07-03 20:41:53 198144 ----a-w- c:\windows\system32\dllcache\nv3.sys
2012-07-03 20:40:58 15872 ----a-w- c:\windows\system32\dllcache\ne2000.sys
2012-07-03 20:39:55 49024 ----a-w- c:\windows\system32\dllcache\mstape.sys
2012-07-03 20:39:50 12416 ----a-w- c:\windows\system32\dllcache\msriffwv.sys
2012-07-03 20:39:39 2944 ----a-w- c:\windows\system32\dllcache\msmpu401.sys
2012-07-03 20:39:36 22016 ----a-w- c:\windows\system32\dllcache\msircomm.sys
2012-07-03 20:39:35 98304 ----a-w- c:\windows\system32\dllcache\msir3jp.dll
2012-07-03 15:03:45 -------- d-----w- c:\program files\Microsoft Network Monitor 3
2012-07-02 20:25:29 6762896 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{8183c216-5d3e-4dd0-bc1a-522ed58f8d75}\mpengine.dll
2012-07-02 17:52:15 -------- d-----w- c:\program files\Trend Micro
2012-06-30 20:50:58 -------- d-----w- c:\documents and settings\all users\application data\Sophos
2012-06-30 18:50:20 -------- d-----w- C:\Sys
2012-06-29 23:21:32 208896 ----a-w- c:\windows\MBR.exe
2012-06-29 23:21:31 98816 ----a-w- c:\windows\sed.exe
2012-06-29 23:21:31 518144 ----a-w- c:\windows\SWREG.exe
2012-06-29 23:21:31 256000 ----a-w- c:\windows\PEV.exe
2012-06-29 17:24:30 475648 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.scr
2012-06-29 17:24:30 1061888 ----a-w- c:\windows\system32\MyDefragScreenSaver_v4.3.1.exe
2012-06-29 17:24:29 -------- d-----w- c:\program files\MyDefrag v4.3.1
2012-06-29 16:06:07 35200 ----a-w- c:\windows\system32\dllcache\msgame.sys
2012-06-29 16:06:04 6016 ----a-w- c:\windows\system32\dllcache\msfsio.sys
2012-06-29 16:04:59 26442 ----a-w- c:\windows\system32\dllcache\lanepic5.sys
2012-06-29 16:03:58 100992 ----a-w- c:\windows\system32\dllcache\icam5usb.sys
2012-06-29 16:02:58 289887 ----a-w- c:\windows\system32\dllcache\hsf_fall.sys
2012-06-29 16:01:58 454912 ----a-w- c:\windows\system32\dllcache\fxusbase.sys
2012-06-29 16:00:59 61952 ----a-w- c:\windows\system32\dllcache\eqnloop.exe
2012-06-29 15:59:59 6729 ----a-w- c:\windows\system32\dllcache\disrvci.dll
2012-06-29 15:58:59 44032 ----a-w- c:\windows\system32\dllcache\cnusd.dll
2012-06-29 15:57:59 871388 ----a-w- c:\windows\system32\dllcache\bcmdm.sys
2012-06-29 15:26:20 25992 ----a-w- c:\windows\system32\pgdfgsvc.exe
2012-06-29 15:21:47 -------- d-----w- c:\program files\Microsoft Security Client
2012-06-29 14:52:50 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-29 14:52:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
==================== Find3M ====================
.
.
============= FINISH: 18:48:38.21 ===============
I will attach attach.txt, ark.txt and the first TDSSKiller log that found the rootkit. I have screenshots of the browser window during its opening as well as the after the "webpage cannot be displayed" if that will help.
Thank you in advance for your time and help.
Don


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top












