Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jul 1 2009, 07:32 AM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 6 Joined: 1-July 09 Member No.: 347,181 |
I knew something was wrong after I visited a p2p site. I ran AVG it found some trojans and put them in the virus vault. I tried to run Malwarebytes but it won't start. I tried to download spyware doctor, the free one, it downloads but will not upload updates so cannot make it work. I tried to run spybot s&d but it will not run. Some crazy trojans or viruses. Anyway, I'd like to get rid of them. I thought if I started in safe mode, maybe I could run, or download and run Malwarebytes. That took care of some problems I had in the past. So here I am talking to the Pro's, what do you think? I can get around my computer ok, I am not good with tech lingo or instructions. I just don't know what certain things mean, so I guess I'll need some coaching to fix this. I cannot even get to the sites I want because of the redirection. Maybe if I use Yahoo instead of Google. |
|
|
|
Jul 1 2009, 07:35 AM
Post
#2
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,540 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Lets try SAS
Please download ATF Cleaner by Atribune & save it to your desktop. alternate download link DO NOT use yet. Please download and install SUPERAntiSpyware Free
Double-click ATF-Cleaner.exe to run the program.
ATF-Cleaner must be "Run as an Administrator". Scan with SUPERAntiSpyware as follows:
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook Happy Valentines Day!!! |
|
|
|
Jul 1 2009, 07:02 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 6 Joined: 1-July 09 Member No.: 347,181 |
Rigel,\
the first time I tried to download superanti, I recieved an error message, Microsoft has encountered a problem and must shut down. I tried and succeded in downloading it from another site, but when I clicked on it on my desktop, I recieved that same error message. I almost forgot, I cannot boot into safe mode using the F8 method. I have tried about a dozen times, I finally discovered that NUM lock has to be off for the F keys to work. I still cannot boot. What happens is I tap F8, the boot screen comes up, the computer beeps as I tap F8 until that screen turns to the welcome screen thats when the beeps stop. The only time I've heard those beeps is when I'm trying to type or do something that the computer won't let me do. I hope I'm not competely screwed here. This post has been edited by hookturn: Jul 1 2009, 07:22 PM |
|
|
|
Jul 1 2009, 07:58 PM
Post
#4
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,540 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Let's try one more tool...
Install RootRepeal Click here - Official Rootrepeal Site, and download RootRepeal.zip. I recommend downloading to your desktop. Fatdcuk at Malwarebytes posted a comprehensive tutorial - Self Help guide can be found here if needed.: Malwarebytes Removal and Self Help Guides. Click RootRepeal.exe to open the scanner. Click the Report tab, now click on Scan. A Window will open asking what to include in the scan. Check the following items: Drivers Files Processes SSDT Stealth Objects Hidden Services Click OK Scan your C Drive (Or your current system drive) and click OK. The scan will begin. This my take a moment, so please be patient. When the scan completes, click Save Report. Name the log RootRepeal.txt and save it to your Documents folder - (Default folder). Paste the log into your next reply. Note: If RootRepeal doesnt want to start, please select Setting - Options and move the Disk Access Slider to the High position. -------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook Happy Valentines Day!!! |
|
|
|
Jul 2 2009, 07:32 AM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 6 Joined: 1-July 09 Member No.: 347,181 |
Well, I tried to past the file but could not so here is the whole thing. I sure appreciate the time your taking, what a mess I have.
Thanks very much ROOTREPEAL © AD, 2007-2009 ================================================== Scan Time: 2009/07/02 05:21 Program Version: Version 1.3.0.0 Windows Version: Windows XP SP3 ================================================== Drivers ------------------- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xEB290000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xF7D4B000 Size: 8192 File Visible: No Signed: - Status: - Name: MSIVXjpyavhkdpaswexvkdvegwxiqltkylexe.sys Image Path: C:\WINDOWS\system32\drivers\MSIVXjpyavhkdpaswexvkdvegwxiqltkylexe.sys Address: 0xEC5A2000 Size: 184320 File Visible: - Signed: - Status: Hidden from Windows API! Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xF79AF000 Size: 49152 File Visible: No Signed: - Status: - Name: srescan.sys Image Path: srescan.sys Address: 0xF7681000 Size: 81920 File Visible: No Signed: - Status: - Hidden/Locked Files ------------------- Path: C:\hiberfil.sys Status: Locked to the Windows API! Path: C:\WINDOWS\system32\MSIVXcount Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\MSIVXncympwilgqvmihtpiutlatdntobwweoo.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\MSIVXtexnowbekollqwpvwuxnrclkixbppjoa.dll Status: Invisible to the Windows API! Path: C:\WINDOWS\system32\drivers\MSIVXjpyavhkdpaswexvkdvegwxiqltkylexe.sys Status: Invisible to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\MPSampleSubmit\msivxjpyavhkdpaswexvkdvegwxiqltkylexe.sys.xor Status: Invisible to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\MPSampleSubmit\msivxtexnowbekollqwpvwuxnrclkixbppjoa.dll.xor Status: Invisible to the Windows API! Path: C:\Documents and Settings\gary crehan\My Documents\Downloads\Programs\OOO_23~1.EXE:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} Status: Visible to the Windows API, but not on disk. Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\7KW12LAY\maindetails;tile=4;sz=300x250%2C300x600%2C160x600%2C171x600;p=tr;r=afc;g=th;g=ac;tt=f;g=cr;id=tt0099160;g=dr;k=i;coo=usa;g=baa;k=c ;ord=2352401503115692[2].5 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\7KW12LAY\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950694213&PageId=1230950694213&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\7KW12LAY\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950764996&PageId=1230950764996&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\7KW12LAY\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950768587&PageId=1230950768587&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\7KW12LAY\com®speed=-1&name=ATAtracker&random=1230950761388&PageId=1230950761388&channel=dvd&ct=js&r=http$3A$2F$2Fwww$2Erottentomatoes$2Ecom$2Fm$2Falienator$2F&property=rottentomatoes& Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\7KW12LAY\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950769597&PageId=1230950769597&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDU7KH6Z\ag1001;channel=ag1001;site=ag;id=ag1001;gender=0;age=0000;income=00;gendera ge=0_0000;ageincome=0000_00;genderincome=0_00;user=0_0000_00;type=category;dcopt =ist;tile=1;sz[2] Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDU7KH6Z\ag1001;channel=ag1001;site=ag;id=ag1001;gender=0;age=0000;income=00;gendera ge=0_0000;ageincome=0000_00;genderincome=0_00;user=0_0000_00;type=category;tile= 5;sz=120x90;or[2] Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDU7KH6Z\activity;src=1062251;met=1;v=1;pid=32023591;aid=210526060;ko=0;cid=30372000 ;rid=30389877;rv=1;×tamp=1237288620000;eid1=2;ecn1=1;etm1=10;&_dc_ck=try[1].gif Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\CDU7KH6Z\activity;src=1062251;met=1;v=1;pid=32023591;aid=210526060;ko=0;cid=30372000 ;rid=30389877;rv=1;×tamp=1237288925734;eid1=2;ecn1=0;etm1=30;&_dc_ck=try[1].gif Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\ER8REROX\activity;src=1062251;met=1;v=1;pid=32023591;aid=210526060;ko=0;cid=30372000 ;rid=30389877;rv=1;×tamp=1237288885734;eid1=2;ecn1=1;etm1=10;&_dc_ck=try[1].gif Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\JTGV5AAC\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950693815&PageId=1230950693815&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\JTGV5AAC\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950699861&PageId=1230950699861&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\K5KXMPMF\ag1001;channel=ag1001;site=ag;id=ag1001;gender=0;age=0000;income=00;gendera ge=0_0000;ageincome=0000_00;genderincome=0_00;user=0_0000_00;type=category;tile= 4;sz=120x90;or[2] Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KAET7TZJ\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950694555&PageId=1230950694555&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KAET7TZJ\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950700601&PageId=1230950700601&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KAET7TZJ\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950764559&PageId=1230950764559&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KAET7TZJ\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950765255&PageId=1230950765255&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\KAET7TZJ\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950768997&PageId=1230950768997&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\MFWJAZW3\ag1001;channel=ag1001;site=ag;id=ag1001;gender=0;age=0000;income=00;gendera ge=0_0000;ageincome=0000_00;genderincome=0_00;user=0_0000_00;type=category;tile= 2;sz=160x600,3[2] Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\MFWJAZW3\activity;src=1062251;met=1;v=1;pid=32023591;aid=210526060;ko=0;cid=30372000 ;rid=30389877;rv=1;×tamp=1237288895734;eid1=2;ecn1=0;etm1=10;&_dc_ck=try[1].gif Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\OI1IAWEJ\519&PageId=1230950693519&channel=dvd&ct=js&r=http$3A$2F$2Fwww$2Egoogle$2Ecom$2Fsearch$3Fhl$3Den$26q$3DAlienator+$26btnG$3DGoogle+Search$26aq$3Df$26oq$3D&property=rottentomatoes& Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\OI1IAWEJ\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950696532&PageId=1230950696532&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\OI1IAWEJ\r=http%243A%242F%242Fwww%242Egoogle%242Ecom%242Fsearch%243Fh[1].com®speed=-1&random=1230950699371&PageId=1230950699371&channel=dvd&property=rottentomatoes&tile=1230950703309 Status: Locked to the Windows API! Path: C:\Documents and Settings\gary crehan\Local Settings\Temp\Temporary Internet Files\Content.IE5\OI1IAWEJ\r=http%243A%242F%242Fwww%242Erottentomatoes%242Ecom%242Fm%24[1].com®speed=-1&random=1230950766291&PageId=1230950766291&channel=dvd&property=rottentomatoes&tile=1230950774115 Status: Locked to the Windows API! SSDT ------------------- #: 031 Function Name: NtConnectPort Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c4fc0 #: 037 Function Name: NtCreateFile Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c1c80 #: 041 Function Name: NtCreateKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dc170 #: 046 Function Name: NtCreatePort Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c5580 #: 047 Function Name: NtCreateProcess Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4d9900 #: 048 Function Name: NtCreateProcessEx Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4d9b10 #: 050 Function Name: NtCreateSection Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4ddb10 #: 056 Function Name: NtCreateWaitablePort Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c5670 #: 062 Function Name: NtDeleteFile Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c2210 #: 063 Function Name: NtDeleteKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dc9f0 #: 065 Function Name: NtDeleteValueKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dc7a0 #: 068 Function Name: NtDuplicateObject Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4d9280 #: 098 Function Name: NtLoadKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dcf10 #: 099 Function Name: NtLoadKey2 Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dcf90 #: 116 Function Name: NtOpenFile Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c2070 #: 122 Function Name: NtOpenProcess Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4db180 #: 128 Function Name: NtOpenThread Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4daf40 #: 192 Function Name: NtRenameKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dd6f0 #: 193 Function Name: NtReplaceKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dd150 #: 200 Function Name: NtRequestWaitReplyPort Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c4be0 #: 204 Function Name: NtRestoreKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dd540 #: 210 Function Name: NtSecureConnectPort Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c5190 #: 224 Function Name: NtSetInformationFile Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4c2440 #: 247 Function Name: NtSetValueKey Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4dc4e0 #: 255 Function Name: NtSystemDebugControl Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4da200 #: 257 Function Name: NtTerminateProcess Status: Hooked by "C:\WINDOWS\System32\vsdatant.sys" at address 0xec4da080 Stealth Objects ------------------- Object: Hidden Module [Name: MSIVXtexnowbekollqwpvwuxnrclkixbppjoa.dll] Process: svchost.exe (PID: 760) Address: 0x10000000 Size: 61440 Object: Hidden Module [Name: MSIVXncympwilgqvmihtpiutlatdntobwweoo.dll] Process: iexplore.exe (PID: 2980) Address: 0x10000000 Size: 241664 Hidden Services ------------------- Service Name: MSIVXserv.sys Image Path: C:\WINDOWS\system32\drivers\MSIVXjpyavhkdpaswexvkdvegwxiqltkylexe.sys ==EOF== |
|
|
|
Jul 2 2009, 12:06 PM
Post
#6
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,540 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
One thing you should know:
You have been infected by a nasty rootkit {TDSS Variant}. This rootkit may steal personal information from your computer and can monitor traffic as you surf. If you do on-line banking. shopping, or other financial transactions, you need to contact your bank to monitor your account -and- change all passwords immediately. I also recommend changing the password on your router - if applicable. Do to the nature of rootkits, some members elect to reformat their computer verses trying to clean it. If you wish to do that, please let me know. We continue: Rerun Rootrepeal. After the scan completes, go to the files tab and find these files:
Next right mouse click on it and select *wipe file* option only then immediately reboot the computer. Rerun Malwarebytes in full mode. - Let me know if you need any help with these steps. -------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook Happy Valentines Day!!! |
|
|
|
Jul 2 2009, 10:47 PM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 6 Joined: 1-July 09 Member No.: 347,181 |
Everything worked. I ran Malwarebytes and it found 24 various problems, trojans, rootkits, here's the log. After the first run I ran again and found nothing. I am going to run superantispyware, and then probably run spyware doctor and see if they pick up anything.
What in your opinion is the best anit spyware/malware/background running program. This is the second time Malwarebytes has saved me from an fdisk. Thank you very very much. Do you think I should do anything else? How can I tell if anythings been missed? Here's the log Malwarebytes' Anti-Malware 1.38 Database version: 2365 Windows 5.1.2600 Service Pack 3 7/2/2009 7:37:46 PM mbam-log-2009-07-02 (19-37-46).txt Scan type: Full Scan (A:\|C:\|D:\|) Objects scanned: 153516 Time elapsed: 47 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 1 Registry Data Items Infected: 3 Folders Infected: 5 Files Infected: 12 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PluginVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\PluginVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.228,85.255.112.93 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.228,85.255.112.93 -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\Tcpip\Parameters\NameServer (Trojan.DNSChanger) -> Data: 85.255.112.228,85.255.112.93 -> Quarantined and deleted successfully. Folders Infected: c:\documents and settings\gary crehan\Application Data\MalwareRemovalBot (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. c:\documents and settings\gary crehan\application data\malwareremovalbot\Log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. c:\documents and settings\gary crehan\application data\malwareremovalbot\Settings (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. c:\documents and settings\gary crehan\Start Menu\Programs\PluginVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\PluginVideo (Trojan.DNSChanger) -> Quarantined and deleted successfully. Files Infected: c:\program files\pluginvideo\Uninstall.exe (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\RECYCLER\s-1-5-21-842925246-1500820517-725345543-1004\Dc9.exe (Rogue.Installer) -> Quarantined and deleted successfully. c:\system volume information\_restore{bcb6c1d0-44aa-45ec-a0ff-0b4319fdcc58}\RP614\A0183766.exe (Rogue.Installer) -> Quarantined and deleted successfully. c:\documents and settings\gary crehan\application data\malwareremovalbot\Log\2009 Jul 02 - 05_48_04 PM_078.log (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. c:\documents and settings\gary crehan\start menu\Programs\pluginvideo\Uninstall.lnk (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\tempo-7407015.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully. c:\WINDOWS\Temp\tempo-7407375.tmp (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\WINDOWS\Tasks\MalwareRemovalBot Scheduled Scan.job (Rogue.MalwareRemovalBot) -> Quarantined and deleted successfully. C:\WINDOWS\system32\MSIVXcount (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\system32\MSIVXncympwilgqvmihtpiutlatdntobwweoo.dll (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\system32\MSIVXtexnowbekollqwpvwuxnrclkixbppjoa.dll (Trojan.Agent) -> Quarantined and deleted successfully. c:\WINDOWS\system32\drivers\MSIVXjpyavhkdpaswexvkdvegwxiqltkylexe.sys (Trojan.Agent) -> Quarantined and deleted successfully. |
|
|
|
Jul 3 2009, 11:25 AM
Post
#8
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,540 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Go ahead and post the Superantispyware log. I like Malwarebytes and use Comodo Internet security.
Please download Dr.Web CureIt and save it to your desktop. DO NOT perform a scan yet. alternate download link Note: The file will be randomly named (i.e. 5mkuvc4z.exe). Reboot your computer in "Safe Mode" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". Scan with Dr.Web CureIt as follows:
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook Happy Valentines Day!!! |
|
|
|
Jul 3 2009, 08:41 PM
Post
#9
|
|
|
New Member ![]() Group: Members Posts: 6 Joined: 1-July 09 Member No.: 347,181 |
it found a trojan, the program deleted it. The scan took 4 hrs! sorry by I cannot copy and past the file, I can't open it because it's a .cvs file. It won't past.
In my start up program I have ViRL2009/ViRL2009.exe |
|
|
|
Jul 3 2009, 09:20 PM
Post
#10
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,540 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Please download SmitfraudFix
Double-click SmitfraudFix.exe Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply. Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. http://www.beyondlogic.org/consulting/proc...processutil.htm -------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook Happy Valentines Day!!! |
|
|
|
Jul 4 2009, 12:41 PM
Post
#11
|
|
|
New Member ![]() Group: Members Posts: 6 Joined: 1-July 09 Member No.: 347,181 |
Here it is.
SmitFraudFix v2.423 Scan done at 10:39:21.14, Sat 07/04/2009 Run from C:\Documents and Settings\gary crehan\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\alg.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Spyware Doctor\pctsAuxs.exe C:\Program Files\Spyware Doctor\pctsSvc.exe C:\Program Files\Spyware Doctor\pctsTray.exe C:\Program Files\Spyware Doctor\TFEngine\TFService.exe C:\Program Files\Outlook Express\msimn.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Download Manager\IDMan.exe C:\Documents and Settings\gary crehan\Desktop\SmitfraudFix\Policies.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\system32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\gary crehan »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GARYCR~1\LOCALS~1\Temp »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\gary crehan\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GARYCR~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» o4Patch !!!Attention, following keys are not inevitably infected!!! o4Patch Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, following keys are not inevitably infected!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix !!!Attention, following keys are not inevitably infected!!! Agent.OMZ.Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, following keys are not inevitably infected!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix !!!Attention, following keys are not inevitably infected!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "LoadAppInit_DLLs"=dword:00000001 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," »»»»»»»»»»»»»»»»»»»»»»»» RK [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Realtek RTL8139 Family PCI Fast Ethernet NIC - Packet Scheduler Miniport DNS Server Search Order: 93.188.161.105 DNS Server Search Order: 93.188.166.105 HKLM\SYSTEM\CCS\Services\Tcpip\..\{43252817-8600-432C-8449-536184CD37AD}: DhcpNameServer=93.188.161.105 93.188.166.105 HKLM\SYSTEM\CS1\Services\Tcpip\..\{43252817-8600-432C-8449-536184CD37AD}: DhcpNameServer=93.188.161.105 93.188.166.105 HKLM\SYSTEM\CS3\Services\Tcpip\..\{43252817-8600-432C-8449-536184CD37AD}: DhcpNameServer=93.188.161.105 93.188.166.105 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=93.188.161.105 93.188.166.105 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End |
|
|
|
Jul 4 2009, 01:44 PM
Post
#12
|
|
![]() BC 1st Responder ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 10,540 Joined: 21-October 04 From: South Carolina - USA Member No.: 3,905 |
Please print out and follow these instructions: "How to use SDFix". <- This program is for Windows 2000/XP ONLY.
When using this tool, you must use the Administrator's account or an account with "Administrative rights"
-------------------- "In a world where you can be anything, be yourself." ~ unknown Become a BleepingComputer fan: Facebook Happy Valentines Day!!! |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 9th February 2010 - 12:23 PM |