I first noticed a problem with my computer yesterday. A windows type message displayed saying there was a 'delayed write' failure. This happened multiple times very quickly. No messages appeared that prompted me to download anything to fix this. When I opened firefox I found that when I google searched it displayed 'ssl search is off'. Sometimes when I clicked on search results I was redirected to random sites (this happened with both Chrome and Firefox). When I opened my virus scanner (Symantec) I found my scheduled scans had been removed. A full scan found no problems.
I also found my task manager had been disabled.
I tried to follow the advice in other threads on this forum.
I downloaded TDSSKiller but it would not run, even when renamed.
I followed advice at http://www.bleepingcomputer.com/forums/topic372491.html: in particular, in safemode I ran RKill and SUPERAntispyware. SUPERAntiSpyware found multiple problems (I will post log below).
On reboot (into safemode again) I found that I had access to the task manager again. I haven't seen any redirects, but I haven't tried searching much. I still get ssl search is off, and I still cannot run TDSSKiller (or fixTDSS).
I ran ESET online scanner and it found two problems and was unable to fix one of them. I couldn't find a log file, but the threats listed were:
C:\System Volume Information\_restore{EA627B52-0F52-40E0-9BE4-154495B1D3AE}\RP1067\A0102527.exe a variant of Win32/Kryptik.ALTW trojan cleaned by deleting - quarantined
Operating memory a variant of Win32/Olmarik.AYN trojan
I have tried to follow the preparation guide before posting this.
I will post DDS log.
When I tried to run GMER I got the following message:
Cannot create a stable subkey under a volatile parent key
When I click OK it does open GMER, but it doesn't give me the option to check/uncheck the things asked for in the Preparation guide (they are greyed out). I have not run this scan.
Any help would be greatly appreciated.
.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 10.5.1
Run by LCP at 8:03:52 on 2012-09-15
Microsoft Windows XP Professional 5.1.2600.3.1252.64.1033.18.956.203 [GMT -7:00]
.
AV: Symantec Endpoint Protection *Disabled/Updated* {FB06448E-52B8-493A-90F3-E43226D3305C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1:9421;<local>
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common
files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program
files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program
files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program
files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Akamai NetSession Interface] "c:\documents and settings\lcp\local settings\application
data\akamai\netsession_win.exe"
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [TPSMain] TPSMain.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe
mRun: [DDWMon] c:\program files\toshiba\toshiba direct disc writer\\ddwmon.exe
mRun: [topi] c:\program files\toshiba\toshiba online product information\topi.exe -startup
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ACU] "c:\program files\atheros\ACU.exe" -nogui
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN
mRun: [LogitechCommunicationsManager] "c:\program files\common
files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam10\QuickCam10.exe" /hide
mRun: [uQPiuYoYUryntvk.exe] c:\documents and settings\all users\application
data\uQPiuYoYUryntvk.exe
StartupFolder: c:\docume~1\lcp\startm~1\programs\startup\dropbox.lnk - c:\documents and
settings\lcp\application data\dropbox\bin\Dropbox.exe
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program
files\skype\toolbars\internet explorer\skypeieplugin.dll
Trusted Zone: skillport.com
Trusted Zone: skillwsa.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13
-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06
-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13
-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13
-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} -
hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.254 75.153.176.9
TCP: Interfaces\{160074AD-2638-4018-B510-521C919DA77A} : DhcpNameServer = 192.168.1.254
75.153.176.9
TCP: Interfaces\{A09524D2-C6E3-4258-8F7B-D9C9DF8CE40E} : NameServer = 192.168.2.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program
files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1
\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program
files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\lcp\application
data\mozilla\firefox\profiles\dwp5d2je.default\
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\lcp\application
data\mozilla\firefox\profiles\dwp5d2je.default\extensions\devicedetection@logitech.com\plugins\np
LogitechDeviceDetection.dll
FF - plugin: c:\documents and settings\lcp\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\lcp\application
data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\lcp\local settings\application
data\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\picasa3\npPicasa3.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
.
============= SERVICES / DRIVERS ===============
.
R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2012-7-11 116608]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe
[2009-5-14 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe
[2009-5-14 108392]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint
protection\Rtvscan.exe [2009-5-14 2440120]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2008-8-5 5888]
S1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
S1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-8-4 14336]
S2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2007-3-26 105856]
S2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [2007-2-19
134016]
S3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2012-7-25 245760]
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [2009-5-14 23888]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec
shared\eengine\EraserUtilRebootDrv.sys [2012-8-8 106656]
S3 hwmobile;Huawei FP Handset USB Modem and USB Serial;c:\windows\system32\drivers\hwusbser.sys
[2012-7-24 106624]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32
\drivers\IntcHdmi.sys [2008-8-5 110080]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance
service\maintenanceservice.exe [2012-5-5 114144]
S3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20120914.002\NAVENG.SYS [2012-9-14 92704]
S3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20120914.002\NAVEX15.SYS [2012-9-14
1601184]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-10-1 27064]
S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2008-8
-5 154624]
S3 V0260VID;Live! Cam Vista IM;c:\windows\system32\drivers\V0260Vid.sys [2009-10-6 162176]
S3 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2007-11-14 394952]
S4 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-7-13 160944]
.
=============== Created Last 30 ================
.
2012-09-15 04:22:05 -------- d-----w- c:\program files\ESET
2012-09-15 00:30:44 -------- d-----w- c:\documents and settings\lcp\application
data\SUPERAntiSpyware.com
2012-09-15 00:28:21 -------- d-----w- c:\program files\SUPERAntiSpyware
2012-09-15 00:28:21 -------- d-----w- c:\documents and settings\all
users\application data\SUPERAntiSpyware.com
2012-09-15 00:27:48 -------- d-----w- c:\documents and settings\all
users\application data\SUPERSetup
2012-09-14 23:57:56 -------- d-sh--w- C:\found.000
2012-09-07 23:35:21 73696 ----a-w- c:\program files\mozilla
firefox\breakpadinjector.dll
2012-09-03 21:12:14 938272 ----a-w- c:\windows\system32\drivers\LV302V32.SYS
2012-09-03 21:12:14 348160 ----a-w- c:\windows\system\msvcr71.dll
2012-09-03 21:12:13 527136 ----a-w- c:\windows\system32\LVUI2RC.dll
2012-09-03 21:12:13 264992 ----a-w- c:\windows\system32\lvcodec2.dll
2012-09-03 21:12:13 215840 ----a-w- c:\windows\system32\LVUI2.dll
2012-09-03 21:12:12 41504 ----a-w- c:\windows\system32\drivers\LVUSBSta.sys
2012-09-03 21:12:12 14240 ----a-w- c:\windows\system32\drivers\lv302af.sys
2012-09-03 21:12:12 13398 ----a-w- c:\windows\system32\Repository.reg
2012-09-03 21:12:12 129824 ----a-w- c:\windows\system32\lvci1051.dll
2012-09-03 20:50:34 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2012-09-03 20:50:34 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2012-08-22 19:56:12 -------- d-----w- c:\program files\SpeedFan
2012-08-17 16:28:29 -------- d-----w- C:\ds9
2012-08-17 00:12:24 -------- d-----w- C:\mono
.
==================== Find3M ====================
.
2012-08-06 14:55:15 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-06 14:55:14 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-06 13:58:51 78336 ----a-w- c:\windows\system32\browser.dll
2012-07-04 14:05:18 139784 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-07-03 13:40:15 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-28 21:33:05 667136 ----a-w- c:\windows\system32\wininet.dll
2012-06-28 21:33:05 61952 ----a-w- c:\windows\system32\tdc.ocx
2012-06-28 21:33:04 81920 ----a-w- c:\windows\system32\ieencode.dll
2012-06-28 12:46:29 369664 ----a-w- c:\windows\system32\html.iec
2011-01-22 23:09:47 2052096 -c--a-w- c:\program files\kdewin-installer-gui-latest.exe
2011-01-22 01:11:02 5933871 -c--a-w- c:\program files\LEdBeta(0.53)Build(6501)Std.exe
2010-03-21 10:23:24 7744980 -c--a-w- c:\program files\FreewarePrimoPDF.exe
2009-11-29 21:51:18 4938616 -c--a-w- c:\program files\Silverlight.exe
2009-10-10 08:02:52 144616 -c--a-w- c:\program files\RapportSetup.exe
2009-10-05 11:03:28 2020136 -c--a-w- c:\program files\SkypeSetup.exe
2009-10-02 15:39:52 570032 -c--a-w- c:\program files\GoogleVoiceAndVideoSetup.exe
2009-05-18 21:06:34 43083040 -c--a-w- c:\program files\AdbeRdr910_en_US_Std.exe
2009-05-17 09:54:51 12972544 -c--a-w- c:\program files\gs854w32.exe
2009-05-17 09:52:47 1502208 -c--a-w- c:\program files\gsv49w32.exe
2009-05-17 09:32:02 86335752 -c--a-w- c:\program files\basic-miktex-
2.7.3248.exe
2009-05-17 09:26:11 4652806 -c--a-w- c:\program files\TXCSetup_1StableRC1.exe
2009-05-17 08:29:52 21878064 -c--a-w- c:\program files\QuickTimeInstaller.exe
2009-05-17 07:38:31 16742799 -c--a-w- c:\program files\vlc-0.9.9-win32.exe
2009-05-17 07:35:02 16070968 -c--a-w- c:\program files\gimp-2.6.6-i686-
setup.exe
2009-05-17 07:30:24 10053112 -c--a-w- c:\program files\picasa3-setup.exe
2005-06-16 09:50:30 112876098 -c--a-w- c:\program files\Mathematica-
Student_5.1_Win.EXE
.
============= FINISH: 8:10:21.35 ===============
LOG FROM SuperAntiSpyware:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 09/14/2012 at 08:27 PM
Application Version : 5.5.1016
Core Rules Database Version : 9234
Trace Rules Database Version: 7046
Scan type : Complete Scan
Total Scan Time : 02:51:33
Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator
Memory items scanned : 412
Memory threats detected : 0
Registry items scanned : 34527
Registry threats detected : 3
File items scanned : 324743
File threats detected : 7
Disabled.SecurityCenterOption
HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#FIREWALLDISABLENOTIFY
HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER#UPDATESDISABLENOTIFY
Disabled.TaskManager
HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM#DISABLETASKMGR
Adware.Tracking Cookie
C:\Documents and Settings\LCP\Cookies\CAYRCTIJ.txt [ /imrworldwide.com ]
.kaspersky.122.2o7.net [ C:\DOCUMENTS AND SETTINGS\LCP\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\LCP\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
track.prd1.netshelter.net [ C:\DOCUMENTS AND SETTINGS\LCP\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.kontera.com [ C:\DOCUMENTS AND SETTINGS\LCP\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
.doubleclick.net [ C:\DOCUMENTS AND SETTINGS\LCP\LOCAL SETTINGS\APPLICATION DATA\GOOGLE\CHROME\USER DATA\DEFAULT\COOKIES ]
Trojan.Agent/Gen-RogueAntiSpy
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\UQPIUYOYURYNTVK.EXE


Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
This topic is locked

Back to top














