"D:\WINDOWS\system32\wuauclt.exe (5256):\memory_001b0000";"Trojan horse Agent_r.XJ";"Object is inaccessible."
"D:\WINDOWS\system32\wuauclt.exe (5256)";"Trojan horse Agent_r.XJ";""
"D:\WINDOWS\system32\svchost.exe (1588):\memory_001a0000";"Trojan horse Agent_r.XJ";"Object is inaccessible."
"D:\WINDOWS\system32\svchost.exe (1588)";"Trojan horse Agent_r.XJ";""
"D:\WINDOWS\explorer.exe (1984):\memory_001a0000";"Trojan horse Agent_r.XJ";"Object is inaccessible."
"D:\WINDOWS\explorer.exe (1984)";"Trojan horse Agent_r.XJ";""
I did a search for this virus and found that it was the TDSS rootkit. I downloaded TDSSKiller ver. 2.4.21 but it would install to 80% and then crash with the MS grey box stating that a problem was encountered and it had to shut down. I tried renaming it to some random name.com as suggested. That did not change anything.
I also did an online scan with ESET. It found nothing. I then downloaded Malwarebytes which also found nothing. Finally I downloaded and ran SpywareDoctor which found a few tracking cookies but nothing else.
So I came here for advice. I downloaded and ran dss.scr (renamed zewyihle.exe). The file is attached/pasted. I could not attach ark.txt from gmer since it was 15MB and the site does not accept rar files for upload. Any help will be greatly appreciated.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Kevin at 15:39:30.29 on Wed 04/20/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3032.2081 [GMT -6:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
============== Running Processes ===============
.
D:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
D:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
D:\WINDOWS\System32\WLTRYSVC.EXE
D:\WINDOWS\System32\bcmwltry.exe
D:\WINDOWS\system32\spoolsv.exe
d:\program files\idt\xpm09_6162v012\wdm\STacSV.exe
svchost.exe
F:\Program Files (x86)\avgwdsvc.exe
D:\WINDOWS\system32\dlbxcoms.exe
D:\WINDOWS\Explorer.EXE
F:\Program Files (x86)\PC Tools Security\pctsAuxs.exe
F:\Program Files (x86)\PC Tools Security\pctsSvc.exe
D:\Program Files\IDT\WDM\sttray.exe
D:\WINDOWS\system32\AESTFltr.exe
D:\Program Files\DellTPad\Apoint.exe
D:\WINDOWS\system32\WLTRAY.exe
D:\WINDOWS\system32\igfxpers.exe
D:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
D:\WINDOWS\system32\igfxsrvc.exe
F:\Program Files (x86)\PC Tools Security\pctsGui.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\DellTPad\ApMsgFwd.exe
D:\Program Files\DellTPad\HidFind.exe
F:\Program Files (x86)\avgnsx.exe
F:\Program Files (x86)\avgemcx.exe
D:\Program Files\DellTPad\Apntex.exe
D:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
D:\WINDOWS\system32\svchost.exe -k imgsvc
D:\WINDOWS\system32\RUNDLL32.EXE
F:\Program Files (x86)\Identity Protection\Agent\Bin\AVGIDSAgent.exe
F:\Program Files (x86)\avgchsvx.exe
F:\Program Files (x86)\avgrsx.exe
F:\Program Files (x86)\avgcsrvx.exe
D:\WINDOWS\system32\wuauclt.exe
D:\Documents and Settings\Kevin\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://my.yahoo.com/
uURLSearchHooks: H - No File
mURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - f:\program files (x86)\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - d:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - f:\program files (x86)\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - f:\progra~2\spybot~1\SDHelper.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - d:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - f:\program files (x86)\toolbar\IEToolbar.dll
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - f:\program files (x86)\toolbar\IEToolbar.dll
uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe
uRun: [Eraser] f:\program files (x86)\eraser\eraser.exe -hide
mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
mRun: [AESTFltr] %SystemRoot%\system32\AESTFltr.exe /NoDlg
mRun: [Apoint] d:\program files\delltpad\Apoint.exe
mRun: [Broadcom Wireless Manager UI] d:\windows\system32\WLTRAY.exe
mRun: [IgfxTray] d:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] d:\windows\system32\hkcmd.exe
mRun: [Persistence] d:\windows\system32\igfxpers.exe
mRun: [ISUSPM Startup] d:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "d:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [AVG_TRAY] f:\program files (x86)\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "d:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [ISTray] "f:\program files (x86)\pc tools security\pctsGui.exe" /hideGUI
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - f:\progra~2\spybot~1\SDHelper.dll
LSP: d:\program files\common files\pc tools\lsp\PCTLsp.dll
Trusted Zone: care360.com
Trusted Zone: questdiagnostics.com
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {69D1E588-02F8-4C00-B311-5C581402C247} - hxxps://cas2.questdiagnostics.com/EREQ_SSLcabs/DGXDPCtr.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - f:\program files (x86)\toolbar\IEToolbar.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - f:\program files (x86)\avgpp.dll
Notify: igfxcui - igfxdev.dll
Hosts: 127.0.0.1 www.spywareinfo.com
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;d:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;d:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R0 PCTCore;PCTools KDS;d:\windows\system32\drivers\PCTCore.sys [2011-4-20 239168]
R0 pctDS;PC Tools Data Store;d:\windows\system32\drivers\pctDS.sys [2011-4-20 338880]
R0 pctEFA;PC Tools Extended File Attributes;d:\windows\system32\drivers\pctEFA.sys [2011-4-20 656320]
R1 Avgldx86;AVG AVI Loader Driver;d:\windows\system32\drivers\avgldx86.sys [2010-9-7 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;d:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;d:\windows\system32\drivers\avgtdix.sys [2010-9-7 299984]
R2 AVGIDSAgent;AVGIDSAgent;f:\program files (x86)\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
R2 avgwd;AVG WatchDog;f:\program files (x86)\avgwdsvc.exe [2010-10-22 265400]
R2 sdAuxService;PC Tools Auxiliary Service;f:\program files (x86)\pc tools security\pctsAuxs.exe [2011-4-20 366840]
R2 sdCoreService;PC Tools Security Service;f:\program files (x86)\pc tools security\pctsSvc.exe [2011-4-20 1150936]
R2 yksvc;Marvell Yukon Service;RUNDLL32.EXE ykx32coinst,serviceStartProc --> RUNDLL32.EXE ykx32coinst,serviceStartProc [?]
R3 AESTAud;AE Audio Service;d:\windows\system32\drivers\AESTAud.sys [2010-8-26 113024]
R3 AVGIDSDriver;AVGIDSDriver;d:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-19 123472]
R3 AVGIDSFilter;AVGIDSFilter;d:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-19 30288]
R3 AVGIDSShim;AVGIDSShim;d:\windows\system32\drivers\AVGIDSShim.sys [2010-8-19 26192]
R3 OA009Afx;Provides a software interface to control audio effects of OA009 camera.;d:\windows\system32\drivers\OA009Afx.sys [2010-8-26 148056]
R3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;d:\windows\system32\drivers\OA009Ufd.sys [2010-8-26 133632]
R3 OA009Vid;Creative Camera OA009 Function Driver;d:\windows\system32\drivers\OA009Vid.sys [2010-8-26 271552]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;d:\windows\system32\drivers\RTS5121.sys [2010-8-26 160256]
S3 AMBFilt;Creative AMB Service;d:\windows\system32\drivers\AMBFilt.sys [2010-8-26 1656960]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;f:\program files (x86)\toolbar\ToolbarBroker.exe [2010-10-28 517448]
S3 Rts516xIR;Realtek IR Driver;d:\windows\system32\drivers\rts516xir.sys --> d:\windows\system32\drivers\Rts516xIR.sys [?]
.
=============== Created Last 30 ================
.
2011-04-20 20:26:11 -------- d-----w- d:\docume~1\kevin\locals~1\applic~1\Temp
2011-04-20 19:05:43 656320 ----a-w- d:\windows\system32\drivers\pctEFA.sys
2011-04-20 19:05:43 338880 ----a-w- d:\windows\system32\drivers\pctDS.sys
2011-04-20 19:05:41 251560 ----a-w- d:\windows\system32\drivers\pctgntdi.sys
2011-04-20 19:05:34 239168 ----a-w- d:\windows\system32\drivers\PCTCore.sys
2011-04-20 19:05:34 160448 ----a-w- d:\windows\system32\drivers\PCTAppEvent.sys
2011-04-20 19:05:23 70536 ----a-w- d:\windows\system32\drivers\pctplsg.sys
2011-04-20 19:05:14 -------- d-----w- d:\program files\common files\PC Tools
2011-04-20 19:05:14 -------- d-----w- d:\docume~1\kevin\applic~1\PC Tools
2011-04-20 18:58:49 -------- d-----w- d:\docume~1\alluse~1\applic~1\PC Tools
2011-04-20 17:04:40 -------- d-----w- d:\program files\ESET
2011-04-19 23:31:31 -------- d-----w- d:\docume~1\kevin\applic~1\Malwarebytes
2011-04-19 23:31:26 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2011-04-19 23:31:21 20952 ----a-w- d:\windows\system32\drivers\mbam.sys
2011-04-19 23:31:21 -------- d-----w- d:\program files\Malwarebytes' Anti-Malware
2011-04-19 23:09:02 -------- d-----w- d:\windows\system32\wbem\repository\FS
2011-04-19 23:09:02 -------- d-----w- d:\windows\system32\wbem\Repository
2011-04-19 23:08:43 -------- d-----w- d:\windows\system32\images
2011-04-19 23:08:43 -------- d-----w- d:\windows\system32\html
2011-04-19 23:08:43 -------- d-----w- d:\documents and settings\kevin\WINDOWS
2011-04-19 21:32:08 -------- d-----w- d:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-19 19:58:10 -------- d-----w- D:\ComboFix
2011-04-07 17:40:58 306688 ----a-w- d:\windows\IsUninst.exe
.
==================== Find3M ====================
.
2011-03-07 05:33:50 692736 ----a-w- d:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- d:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- d:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- d:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- d:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ------w- d:\windows\system32\inetcpl.cpl
2011-02-22 11:41:59 385024 ----a-w- d:\windows\system32\html.iec
2011-02-17 12:32:12 5120 ----a-w- d:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- d:\windows\system32\atmfd.dll
2011-02-09 13:53:52 270848 ----a-w- d:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- d:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- d:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- d:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- d:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- d:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- d:\windows\system32\shimgvw.dll
2005-11-15 22:03:54 434176 ----a-w- d:\program files\SOAPware.Support.EScripts.dll
2005-09-26 15:36:00 147456 ----a-w- d:\program files\SOAPware.Support.Helpers.dll
2005-09-19 19:32:00 24576 ----a-w- d:\program files\AxInterop.SW_USERSLib.dll
2005-09-19 19:32:00 13312 ----a-w- d:\program files\Interop.SW_USERSLib.dll
2005-09-19 19:07:00 8192 ----a-w- d:\program files\AxInterop.SW_CHARTRACKLib.dll
2005-09-19 19:07:00 10240 ----a-w- d:\program files\Interop.SW_CHARTRACKLib.dll
2005-09-19 19:06:00 45056 ----a-w- d:\program files\AxInterop.SW_CHARTDATAACCESSLib.dll
2005-09-19 19:06:00 40960 ----a-w- d:\program files\Interop.SW_CHARTDATAACCESSLib.dll
2005-07-29 05:20:00 294982 ----a-w- d:\program files\SW_Users.ocx
2005-07-29 05:01:00 81998 ----a-w- d:\program files\SW_ChartRack.ocx
2005-07-29 05:00:00 512090 ----a-w- d:\program files\SW_ChartDataAccess.ocx
2004-08-12 17:18:00 9216 ----a-w- d:\program files\Interop.BUGZSCOUTLib.dll
2004-03-01 20:58:18 561424 ----a-w- d:\program files\common files\dao360.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: TOSHIBA_MK3265GSX rev.GJ002D -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys >>UNKNOWN [0x8AB0B4F0]<<
d:\windows\system32\drivers\PCTCore.sys PC Tools Kernel Driver Suite
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8ab117d0]; MOV EAX, [0x8ab1184c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x808181A6] -> \Device\Harddisk0\DR0[0x8AA5DAB8]
3 CLASSPNP[0xBA0E8FD7] -> ntkrnlpa!IofCallDriver[0x808181A6] -> [0x8AB1E920]
5 PCTCore[0xB9EAD099] -> ntkrnlpa!IofCallDriver[0x808181A6] -> [0x8AB22D98]
\Driver\atapi[0x8AB75E18] -> IRP_MJ_CREATE -> 0x8AB0B4F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8AB0B33B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 15:41:25.29 ===============
Attach.txt (17.09K)
Number of downloads: 1

Help
This topic is locked

Back to top


















