I am having problems getting rid of a rootkit that I discovered this morning. I imediatley used ComboFix because that has always fixed my problems. Unfortunately, it didn't this time. I got an error informing me there was a root kit and that the computer needed to restart, I clicked ok and when it rebooted combofix started again but didn't start a new scan or anything. I apologize, but I do not have the messages saved. So I went to your website and followed the instructions for posting on this forum. Here is the DDS log:
.
DDS (Ver_11-05-19.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_22
Run by Jordan at 14:35:29 on 2011-05-26
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3037.2137 [GMT -4:00]
.
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\svchost.exe -k Akamai
C:\Program Files\Virtual Vertex\Muster 6\dispatcher.exe
C:\Program Files\Virtual Vertex\Muster 6\renderclient.exe
C:\Program Files\Visioneer\OneTouch 4.0\OtService.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Windows\explorer.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\ScanSoft\OmniPage15\OpWare15.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ScanSoft\OmniPage15\OpAgent.exe
C:\Program Files\Virtual Vertex\Muster 6\Notificator.exe
C:\Program Files\NETGEAR\WNA1000\WNA1000.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Jordan\Desktop\dds.scr
C:\Windows\system32\WSCRIPT.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [OpAgent] "c:\program files\scansoft\omnipage15\OpAgent.exe" /agent
uRun: [updatesst] "c:\programdata\security essentials ultimate pack\SecEls.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "c:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [Opware15] "c:\program files\scansoft\omnipage15\Opware15.exe"
mRun: [ScanSoft OmniPage 15-reminder] "c:\program files\scansoft\omnipage15\ereg\ereg.exe" -r "c:\programdata\scansoft\omnipage15.0\ereg\Ereg.ini
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\users\jordan\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\muster~1.lnk - c:\program files\virtual vertex\muster 6\Notificator.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wna1000\WNA1000.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\servic~1.lnk - c:\program files\virtual vertex\muster 6\ServiceControls.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
Trusted Zone: se-2011-download.com
Trusted Zone: se-2011-payment.com
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
============= SERVICES / DRIVERS ===============
.
R1 jswpslwf;JumpStart Wireless Filter Driver;c:\windows\system32\drivers\jswpslwf.sys [2008-10-1 20384]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2009-7-13 20992]
R2 Muster_Dispatcher_6;Muster Dispatcher Service 6;c:\program files\virtual vertex\muster 6\dispatcher.exe [2011-1-12 18944]
R2 Muster_Renderclient_6;Muster Render Client Service 6;c:\program files\virtual vertex\muster 6\renderclient.exe [2011-1-12 19968]
R2 TabletServiceWacom;TabletServiceWacom;c:\program files\tablet\wacom\Wacom_Tablet.exe [2011-3-3 4807536]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-6-10 139776]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 DNIMp50;DNIMp50 NDIS Protocol Driver;c:\windows\system32\drivers\DNIMP50.sys [2006-11-16 21504]
S3 DNISp50;DNISp50 NDIS Protocol Driver;c:\windows\system32\drivers\DNISP50.sys [2006-11-16 20480]
S3 jswpsapi;Jumpstart Wifi Protected Setup;c:\program files\netgear\wna1000\jswpsapi.exe [2008-2-29 942080]
S3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2011-3-3 10752]
S3 WNA1000;NETGEAR WNA1000 USB2.0 Wireless Card Service;c:\windows\system32\drivers\WNA1000.sys [2009-1-13 453120]
.
=============== Created Last 30 ================
.
2011-05-26 18:32:19 -------- d-s---w- C:\ComboFix
2011-05-26 14:55:06 -------- d-----w- c:\programdata\Security Essentials Ultimate Pack
2011-05-23 20:07:45 -------- d-sh--w- C:\$RECYCLE.BIN
2011-05-23 07:06:17 -------- d-----w- c:\users\jordan\appdata\local\Diagnostics
2011-05-20 19:34:37 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-16 01:09:57 -------- d-----w- c:\users\jordan\appdata\roaming\OpenOffice.org
2011-05-16 01:09:02 -------- d-----w- c:\program files\OpenOffice.org 3
2011-05-16 01:08:31 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-05-10 20:25:16 -------- d-----w- c:\program files\SC
2011-05-10 19:19:03 5732688 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2011-05-10 19:19:02 7071056 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{2adb6eed-bfcb-4f59-b995-35d422c9f177}\mpengine.dll
2011-05-10 19:16:59 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-05-10 00:21:29 -------- d-----w- c:\program files\MSXML 4.0
2011-05-10 00:21:20 95744 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-05-10 00:21:20 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2011-05-10 00:21:20 221696 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-05-10 00:21:20 123392 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-05-10 00:20:49 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2011-05-09 23:19:11 98816 ----a-w- c:\windows\sed.exe
2011-05-09 23:19:11 89088 ----a-w- c:\windows\MBR.exe
2011-05-09 23:19:11 256512 ----a-w- c:\windows\PEV.exe
2011-05-09 23:19:11 161792 ----a-w- c:\windows\SWREG.exe
2011-05-07 23:20:07 -------- d-----w- c:\users\jordan\appdata\local\Mozilla
2011-05-05 19:36:30 -------- d-----w- c:\program files\NETGEAR
2011-05-05 19:36:11 -------- d-----w- c:\programdata\NETGEAR
.
==================== Find3M ====================
.
2011-03-11 05:40:24 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2011-03-11 05:40:24 1137664 ----a-w- c:\windows\system32\mfc42.dll
2009-11-20 04:08:02 3749224 ----a-w- c:\program files\common files\adlmint_libFNP.dll
2009-11-20 04:08:02 2941288 ----a-w- c:\program files\common files\adlmint.dll
.
============= FINISH: 14:35:41.15 ===============
I am running windows 7 and everytime it boots I have to wait for a 'security'check that takes 400 seconds to go through. The message talks about the system not being able to start work properly and needs to do a check and 'tune-up'. Then it advices me to register my anti virus software (I have none). Please help, it is my work computer and I can't afford to loose it.
EDIT: Posts merged ~Budapest
Attached File(s)
-
Attach.txt (12.72K)
Number of downloads: 0 -
ark.txt (13.67K)
Number of downloads: 1
This post has been edited by Budapest: 29 May 2011 - 05:00 PM

Help
This topic is locked

Back to top
button.









