I wanted to add also that I tried the TDSSKiller.exe and it would only open 80% and then attempt to send an error message to Microsoft. Once or twice it did appear to scan but I don't trust the results since it did not run smoothly. It would not initialize more than 80% each time.
Quote
Then post your DDS and GMER logs as a reply to this topic. Once you have done that I will remove my reply and consolidate the posts so that you retain your correct place in the queue.
If you can produce at least some of the logs, then please explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the reply and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.
Just a quick reply to let you know that I'm running the scans and I'll post as soon as they complete. The first scan, dds, ran perfectly but the GMER made my computer shut down with a blue screen with some warning about how windows had to shut down to protect my computer. Not sure. The computer needed to be restarted. I'll run the GMER again tonight and post the logs in the morning. Thanks.
Quote
Interesting side note: I could not post this log from my infected computer. It would not finalize the posting. Not sure why.
I even tried to email it to myself so I could post it from another computer but it would not attach the dds files. I did manage to put the dds report on my flash drive and move it over to other computer and so here it is. Please let me know what the next step is and thanks again, Budapest, for pointing me in the right direction.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Owner at 5:47:56.37 on Wed 04/20/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.265 [GMT -7:00]
.
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\IObit\Smart Defrag 2\SmartDefrag.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Documents and Settings\Owner\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uURLSearchHooks: H - No File
mURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [CTSVolFE] "c:\program files\creative\mixer\CTSVolFE.exe" /r
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [AtiPTA] Atiptaxx.exe
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\setup_~1.lnk - c:\documents and settings\owner\desktop\virus removal tool\setup_9.0.0.722_17.04.2011_20-51\startup.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1218402402026
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\8cgp1bn2.default\
FF - prefs.js: browser.startup.homepage - hxxp://google.com
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
.
---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
.
============= SERVICES / DRIVERS ===============
.
R0 78145522;78145522 Boot Guard Driver;c:\windows\system32\drivers\78145522.sys [2011-4-17 37392]
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-4-9 13496]
R1 78145521;78145521;c:\windows\system32\drivers\78145521.sys [2011-4-17 128016]
R1 setup_9.0.0.722_17.04.2011_20-51drv;setup_9.0.0.722_17.04.2011_20-51drv;c:\windows\system32\drivers\7814552.sys [2011-4-17 315408]
S2 gupdate1c9a6a464519d8c;Google Update Service (gupdate1c9a6a464519d8c);c:\program files\google\update\GoogleUpdate.exe [2009-3-16 133104]
S3 ati2mpad;ati2mpad;c:\windows\system32\drivers\ati2mpad.sys [2002-2-18 303360]
S3 AtiBt829;WDM Video Capture For AIW (AtiBt829);c:\windows\system32\drivers\AtiBt829.sys [2010-12-9 46464]
S3 ATITVAUDIO;WDM TVAudio (ATITVSnd);c:\windows\system32\drivers\ATITVSnd.sys [2010-12-9 17152]
S3 ATIXBAR;ATI Video Audio Crossbar (ATIXBar);c:\windows\system32\drivers\atixbar.sys [2010-12-9 23552]
S3 XDva377;XDva377;\??\c:\windows\system32\xdva377.sys --> c:\windows\system32\XDva377.sys [?]
S3 XDva379;XDva379;\??\c:\windows\system32\xdva379.sys --> c:\windows\system32\XDva379.sys [?]
.
=============== Created Last 30 ================
.
2011-04-17 19:06:55 37392 ----a-w- c:\windows\system32\drivers\78145522.sys
2011-04-17 19:06:55 315408 ----a-w- c:\windows\system32\drivers\7814552.sys
2011-04-17 19:06:55 128016 ----a-w- c:\windows\system32\drivers\78145521.sys
2011-04-16 21:48:52 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-04-16 21:48:51 781272 ----a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-04-16 21:48:51 728024 ----a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-04-16 21:48:51 1975768 ----a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
2011-04-16 21:48:51 1893336 ----a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-04-16 21:48:51 1874904 ----a-w- c:\program files\mozilla firefox\mozjs.dll
2011-04-16 21:48:51 15832 ----a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-04-16 21:48:51 142296 ----a-w- c:\program files\mozilla firefox\libEGL.dll
2011-04-16 21:45:07 -------- d-----w- c:\docume~1\alluse~1\applic~1\HBLiteSA
2011-04-16 21:45:07 -------- d-----w- c:\docume~1\alluse~1\applic~1\2ACA5CC3-0F83-453D-A079-1076FE1A8B65
2011-04-16 21:45:06 -------- d-----w- c:\docume~1\owner\applic~1\HBLite
2011-04-16 18:38:41 -------- d-----w- c:\docume~1\owner\applic~1\SUPERAntiSpyware.com
2011-04-16 18:38:41 -------- d-----w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2011-04-16 17:39:28 -------- d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2011-04-16 04:46:11 -------- d-----w- c:\program files\WiseFixer
2011-04-16 02:44:54 -------- d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2011-04-16 01:36:35 -------- d-sha-r- C:\cmdcons
2011-04-16 01:30:33 389120 ----a-w- c:\windows\system32\CF19145.exe
2011-04-16 01:29:34 389120 ----a-w- c:\windows\system32\CF18884.exe
2011-04-09 22:03:12 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-04-09 22:03:12 13496 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-04-07 01:34:27 138056 ----a-w- c:\docume~1\owner\applic~1\PnkBstrK.sys
2011-04-07 01:04:39 -------- d-----w- c:\program files\EA Games
2011-04-02 01:51:47 -------- d-----w- c:\docume~1\owner\applic~1\DDMSettings
2011-04-02 01:47:59 -------- d-----w- c:\program files\common files\DivX Shared
2011-03-25 01:48:50 -------- d-----w- c:\docume~1\owner\applic~1\Unity
.
==================== Find3M ====================
.
2011-04-07 01:34:17 189248 ----a-w- c:\windows\system32\PnkBstrB.exe
2011-04-07 01:34:01 75136 ----a-w- c:\windows\system32\PnkBstrA.exe
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ------w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 ----a-w- c:\windows\system32\html.iec
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-03 04:40:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-02-03 02:19:39 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
2008-08-13 17:32:34 284160 ----a-w- c:\program files\common files\mdn.exe
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD400BB-00CAA1 rev.17.07W17 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x82F484E7]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x82f4e7d0]; MOV EAX, [0x82f4e84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x82FD0AB8]
3 CLASSPNP[0xF85F7FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x82FDF8D8]
\Driver\atapi[0x82F87E20] -> IRP_MJ_CREATE -> 0x82F484E7
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x82F48332
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 5:49:52.54 ===============
EDIT: Please be patient. There are over 380 unanswered topics in this forum at present and the current average wait time to receive help is 8 days. ~Budapest
This post has been edited by Budapest: 23 April 2011 - 05:57 PM

Help
This topic is locked

Back to top

















