I got this virus a week ago and have been unable to kill it using all the standard tools. I have followed the Prep Guide and ran all of the prescribed logs. I tried to post them to this forum but was unable to do so on my last attempts (three) getting a browser message that indicated "The connection to the server was reset while the page was loading.". I have tried to send the logs again with this post and am having same problem. I cannot even preview the post with the DDS file embedded in this post, and it won't work as an attachment either...don't know why. Let me try sending the other attachments and then rerun the DDS log. Is that ok?
Here is what I have tried, many of them several times;
Malwarebytes' AntiMalware
Super AntiSPyware
Spyware Terminator
HiJackThis
Hitman
TrendMicro HouseCall
Spybot S&D (which indicated I had click.giftload and MicrosoftWindoesSecurityCenter.AntivirusOverride infections...that keep coming back)
I have also turned off all browser plugins and extensions for Firefox. I am running Windows XP SP3, and have attempted to do a Windows Repair as well.
It seems to be also affecting my mouse movements when the computer has been on for awhile, and on reboots, the computer sometimes comes up with a background and no desktop icons.
Thanks in advance for your assistance with this!
Bond
OK, I ran DDS again. Every time I try to send it from this machine I get the browser error;
The connection was reset
The connection to the server was reset while the page was loading.
The site could be temporarily unavailable or too busy. Try again in a few moments.
If you are unable to load any pages, check your computer's network connection.
If your computer or network is protected by a firewall or proxy, make sure that Firefox is permitted to access the Web.
Of course, I have full internet access for all other sights! This is really strange...and frustrating.
I will attempt to send from a different machine to see what happens
Bond
OK, one more time from a different computer...my DDS logs from today.
Bond
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Tom at 6:33:28.56 on Wed 05/04/2011
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_25
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.642 [GMT -5:00]
.
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Firewall *Disabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe -k Akamai
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\AVAST Software\Avast\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\APC\APC PowerChute Personal Edition\dataserv.exe
C:\PROGRA~1\MICROS~2\Office14\OUTLOOK.EXE
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Tom.PHOTOCYCLE2\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Canon Easy-WebPrint EX BHO: {3785d0ad-bfff-47f6-bf5b-a587c162fed9} - c:\program files\canon\easy-webprint ex\ewpexbho.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Canon Easy-WebPrint EX: {759d9886-0c6f-4498-bab6-4a5f47c6c72f} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
EB: Canon Easy-WebPrint EX: {21347690-ec41-4f9a-8887-1f4aee672439} - c:\program files\canon\easy-webprint ex\ewpexhlp.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\tom.photocycle2\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [InCD] c:\program files\ahead\incd\InCD.exe
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [<NO NAME>]
mRun: [Display] c:\program files\apc\apc powerchute personal edition\DataCollectionLauncher.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [MsmqIntCert] regsvr32 /s mqrt.dll
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVMV0gtR0JZUzQtOU5USEQtUUE3WEQtQzJRSEgtTkZGS0o"&"inst=NzctNjA2NTM3MjgzLUJBKzEtS1YzKzctWEwrMS1UNC1GUDkrNi1TVDErMi1UQjkrMi1GTCs5LUYxME0rNS1YMjAxMCsyLVFJWDErNC1GMTBNMTBEKzEtTElDKzctRkwxMCsx"&"prod=90"&"ver=10.0.1325
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
StartupFolder: c:\docume~1\alluse~1.win\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll
Trusted Zone: intuit.com
Trusted Zone: intuit.com\ttlc
Trusted Zone: motive.com\pattta.att
Trusted Zone: motive.com\patttbc.att
Trusted Zone: netlibrary.com\www
Trusted Zone: netlibrary.com
DPF: {051D0E35-F4E3-4C8D-B411-AB0875F4C683} - hxxp://install.anark.com/client/version4/windows-ie/en/AMClient.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1304170742578
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1212689632781
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://access.motorola.com/dana-cached/setup/JuniperSetupSP1.cab
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
Notify: LBTWlgn - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\tom~1.pho\applic~1\mozilla\firefox\profiles\2iza4ljw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en&source=iglk
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\documents and settings\tom.photocycle2\application data\mozilla\firefox\profiles\2iza4ljw.default\extensions\ietab@ip.cn\plugins\npCoralIETab.dll
FF - plugin: c:\documents and settings\tom.photocycle2\local settings\application data\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.131.11\npGoogleOneClick5.dll
FF - plugin: c:\program files\google\update\1.2.133.33\npGoogleOneClick7.dll
FF - plugin: c:\program files\google\update\1.2.133.37\npGoogleOneClick7.dll
FF - plugin: c:\program files\google\update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\google\update\1.2.145.5\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPBelv32.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\virtual earth 3d\npVE3D.dll
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-4-10 64288]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-4-30 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-4-30 307288]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-1-22 98392]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2004-8-4 14336]
R2 APC Data Service;APC Data Service;c:\program files\apc\apc powerchute personal edition\dataserv.exe [2010-9-14 21880]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-4-30 19544]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-4-30 42184]
R2 cpuz134;cpuz134;c:\windows\system32\drivers\cpuz134_x32.sys [2010-11-28 20328]
R3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8xx.sys [2008-11-3 472644]
S2 gupdate1c90c36df2bed18;Google Update Service (gupdate1c90c36df2bed18);c:\program files\google\update\GoogleUpdate.exe [2008-9-1 133104]
S3 AmdTools;AMD Special Tools Driver;c:\windows\system32\drivers\amdtools.sys --> c:\windows\system32\drivers\AmdTools.sys [?]
S3 DrvAgent32;DrvAgent32;c:\windows\system32\drivers\DrvAgent32.sys [2010-12-21 23456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2008-9-1 133104]
S3 ivusb;Initio Driver for USB Default Controller;c:\windows\system32\drivers\ivusb.sys [2010-3-10 24216]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;\??\c:\program files\lavasoft\ad-aware\kernexplorer.sys --> c:\program files\lavasoft\ad-aware\KernExplorer.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\drivers\rtl8187b.sys --> c:\windows\system32\drivers\RTL8187B.sys [?]
S3 SjyPkt;SjyPkt;\??\c:\windows\system32\drivers\sjypkt.sys --> c:\windows\system32\drivers\SjyPkt.sys [?]
.
=============== Created Last 30 ================
.
2011-05-03 06:00:12 -------- d-----w- c:\program files\Quick Web Player
2011-05-03 05:59:42 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\PC Tools
2011-05-01 03:51:00 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-05-01 03:50:38 40112 ----a-w- c:\windows\avastSS.scr
2011-05-01 03:50:27 -------- d-----w- c:\program files\AVAST Software
2011-05-01 03:50:27 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\AVAST Software
2011-05-01 02:29:07 79872 -c----w- c:\windows\system32\dllcache\msxml6r.dll
2011-05-01 02:29:07 1306624 -c----w- c:\windows\system32\dllcache\msxml6.dll
2011-05-01 02:28:55 884712 ------w- c:\program files\msn\msncorefiles\install\msn9components\digcore.exe
2011-05-01 02:28:55 1327320 ------w- c:\program files\msn\msncorefiles\install\msnsusii.exe
2011-05-01 02:28:54 966656 ------w- c:\program files\msn\msncorefiles\oobe\obemetal.dll
2011-05-01 02:28:54 86016 ------w- c:\program files\msn\msncorefiles\oobe\obepopc.dll
2011-05-01 02:28:54 77824 ------w- c:\program files\msn\msncorefiles\oobe\obemtllc.dll
2011-05-01 02:28:54 229376 ------w- c:\program files\msn\msncorefiles\oobe\obelog.dll
2011-05-01 02:28:54 11053008 ------w- c:\program files\msn\msncorefiles\install\msn9components\msncli.exe
2011-05-01 02:27:34 -------- d-----w- c:\windows\ServicePackFiles
2011-05-01 02:25:23 19569 ----a-w- c:\windows\003473_.tmp
2011-04-30 01:21:57 19569 ----a-w- c:\windows\003476_.tmp
2011-04-29 23:47:13 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2011-04-29 23:47:13 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2011-04-29 23:47:11 48256 -c--a-w- c:\windows\system32\dllcache\w32.dll
2011-04-29 23:47:02 14336 -c--a-w- c:\windows\system32\dllcache\tsprof.exe
2011-04-29 23:47:01 10240 -c--a-w- c:\windows\system32\dllcache\tmigrate.dll
2011-04-29 23:47:00 455168 -c--a-w- c:\windows\system32\dllcache\tintsetp.exe
2011-04-29 23:47:00 44032 -c--a-w- c:\windows\system32\dllcache\tintlphr.exe
2011-04-29 23:47:00 19464 -c--a-w- c:\windows\system32\dllcache\tdspx.sys
2011-04-29 23:47:00 185344 -c--a-w- c:\windows\system32\dllcache\thawbrkr.dll
2011-04-29 23:45:53 10096640 -c--a-w- c:\windows\system32\dllcache\hwxcht.dll
2011-04-29 23:42:47 16384 -c--a-w- c:\windows\system32\dllcache\isignup.exe
2011-04-29 23:42:47 16384 ----a-w- c:\program files\internet explorer\connection wizard\isignup.exe
2011-04-29 23:40:26 7680 -c--a-w- c:\windows\system32\dllcache\inetmgr.exe
2011-04-29 23:39:22 88192 ----a-w- c:\windows\system32\drivers\irda.sys
2011-04-29 23:39:22 8192 ----a-w- c:\windows\system32\wshirda.dll
2011-04-29 23:39:22 28160 ----a-w- c:\windows\system32\irmon.dll
2011-04-29 23:39:22 151552 ----a-w- c:\windows\system32\irftp.exe
2011-04-29 23:32:25 18688 ----a-w- c:\windows\system32\drivers\irsir.sys
2011-04-29 23:30:47 19584 ----a-w- c:\windows\system32\drivers\rasirda.sys
2011-04-29 23:27:25 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2011-04-29 23:27:25 24661 ----a-w- c:\windows\system32\spxcoins.dll
2011-04-29 23:27:25 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2011-04-29 23:27:25 13312 ----a-w- c:\windows\system32\irclass.dll
2011-04-29 23:26:59 13753 ----a-r- c:\windows\SET17E.tmp
2011-04-29 23:26:58 1086058 ----a-r- c:\windows\SET172.tmp
2011-04-29 23:26:56 1042903 ----a-r- c:\windows\SET16F.tmp
2011-04-29 11:41:24 -------- d-----w- C:\32788R22FWJFW.0.tmp
2011-04-27 11:55:37 -------- d-----w- c:\docume~1\alluse~1.win\applic~1\SUPERAntiSpyware.com
.
==================== Find3M ====================
.
2011-04-14 10:07:59 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-14 07:40:22 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-03-19 13:24:46 6918144 ----a-w- c:\documents and settings\tom.photocycle2\PCPE_3.0.msi
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: ST3250820A rev.3.AAE -> Harddisk0\DR0 -> \Device\00000072
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8A7074F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a70d7d0]; MOV EAX, [0x8a70d84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x804EE120] -> \Device\Harddisk0\DR0[0x8A782AB8]
3 CLASSPNP[0xBA108FD7] -> ntkrnlpa!IofCallDriver[0x804EE120] -> \Device\00000075[0x8A763F18]
5 ACPI[0xB9F7F620] -> ntkrnlpa!IofCallDriver[0x804EE120] -> [0x8A784030]
\Driver\nvata[0x8A7663A8] -> IRP_MJ_CREATE -> 0x8A7074F0
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\00000071 -> \??\IDE#DiskST3250820A______________________________3.AAE___#20202020202020202020202051353146354A5A30#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
error: Read The parameter is incorrect.
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 6:35:21.89 ===============
Merged 3 posts. ~ OB
Attached File(s)
-
ark.txt (231.92K)
Number of downloads: 0 -
Attach.txt (13.79K)
Number of downloads: 0 -
Attach.txt (13.97K)
Number of downloads: 0
This post has been edited by Orange Blossom: 04 May 2011 - 10:49 PM

Help
This topic is locked


Back to top











