http://www.bleepingcomputer.com/forums/topic407532.html/page__gopid__2319709#entry2319709.
I finished running TDSS Fix Tool and it gave the "infected mbr detected" message. I have attached the DDS attach log.
Additional information is after being affected I have read and followed the uninstall guide but am still having alot of issues. I have run the MalewareByte program and it has not found any infection. I could not get TDSSKill to run. After having tried all steps in self help guide I requested more help. Following is the dds.txt file:
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Owner at 20:29:55 on 2011-07-03
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.410 [GMT -7:00]
.
AV: Webroot AntiVirus with Spy Sweeper *Enabled/Updated* {77E10C7F-2CCA-4187-9394-BDBC267AD597}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
.
============== Running Processes ===============
.
C:\Program Files\Webroot\Security\Current\Framework\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\OPHALDCS.EXE
C:\Program Files\Motorola Media Link\NServiceEntry.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Security\current\plugins\antimalware\AEI.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Documents and Settings\Owner\Desktop\FixTDSS.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\system32\AESTFltr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Webroot\Security\Current\Framework\WRTray.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\PdaNet for Android\PdaNetPC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.6406.1642\swg.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
mRun: [IDTSysTrayApp] "sttray.exe"
mRun: [AESTFltr] "%SystemRoot%\system32\AESTFltr.exe" /NoDlg
mRun: [SynTPEnh] "%ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe"
mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe"
mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe"
mRun: [Persistence] "c:\windows\system32\igfxpers.exe"
mRun: [hpWirelessAssistant] "c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe"
mRun: [WebrootTrayApp] "c:\program files\webroot\security\current\framework\WRTray.exe"
mRun: [SysTrayApp] "%ProgramFiles%\IDT\WDM\sttray.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [EvtMgr6] "c:\program files\logitech\setpointp\SetPoint.exe" /launchGaming
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\pdanet~1.lnk - c:\program files\pdanet for android\PdaNetPC.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1283140671727
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 8.8.8.8
TCP: Interfaces\{818B78DC-1563-4867-BA73-6F8795F2A12E} : DhcpNameServer = 8.8.8.8
Notify: igfxcui - igfxdev.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
============= SERVICES / DRIVERS ===============
.
R0 FixTDSS;TDSS Fixtool driver;c:\windows\system32\drivers\FixTDSS.sys [2011-7-3 26872]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 DeviceMonitorService;DeviceMonitorService;c:\program files\motorola media link\NServiceEntry.exe [2010-9-17 87336]
R2 hlemu;hlemu;c:\windows\system32\drivers\hlemu.sys [2011-4-9 97792]
R2 LBeepKE;Logitech Beep Suppression Driver;c:\windows\system32\drivers\LBeepKE.sys [2011-2-6 10448]
R2 MotoHelper;MotoHelper Service;c:\program files\motorola\motohelper\MotoHelperService.exe [2010-9-3 202048]
R2 SSFMONM;ssfmonm;c:\windows\system32\drivers\ssfmonm.sys [2010-8-30 45584]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\security\current\plugins\antimalware\AEI.exe [2010-8-30 3907248]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\security\current\framework\WRConsumerService.exe [2011-6-14 3363168]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2011-2-27 618896]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2010-8-29 113664]
R3 LEqdUsb;Logitech SetPoint Unifying KMDF USB Filter;c:\windows\system32\drivers\LEqdUsb.sys [2010-8-24 40912]
R3 LHidEqd;Logitech SetPoint Unifying KMDF HID Filter;c:\windows\system32\drivers\LHidEqd.sys [2010-8-24 10448]
R3 pneteth;PdaNet Broadband;c:\windows\system32\drivers\pneteth.sys [2010-8-29 13312]
S1 MpKsl0b8ffa29;MpKsl0b8ffa29;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7b6721df-dd2e-428f-8367-c0983edd21a5}\mpksl0b8ffa29.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{7b6721df-dd2e-428f-8367-c0983edd21a5}\MpKsl0b8ffa29.sys [?]
S1 MpKsl26722041;MpKsl26722041;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e96efb03-1c83-44ad-bd94-3307101756a9}\mpksl26722041.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{e96efb03-1c83-44ad-bd94-3307101756a9}\MpKsl26722041.sys [?]
S1 MpKsl31cd1448;MpKsl31cd1448;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c415453e-f798-4e03-905f-44970185198c}\mpksl31cd1448.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{c415453e-f798-4e03-905f-44970185198c}\MpKsl31cd1448.sys [?]
S1 MpKsl5f61f02b;MpKsl5f61f02b;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fce2e55b-d0f2-4e08-8eef-cb76786563e4}\mpksl5f61f02b.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fce2e55b-d0f2-4e08-8eef-cb76786563e4}\MpKsl5f61f02b.sys [?]
S1 MpKsl6632606e;MpKsl6632606e;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fce2e55b-d0f2-4e08-8eef-cb76786563e4}\mpksl6632606e.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{fce2e55b-d0f2-4e08-8eef-cb76786563e4}\MpKsl6632606e.sys [?]
S1 MpKsl8ed8e61a;MpKsl8ed8e61a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2146f87a-bea6-4cd0-91f6-49050f50a56b}\mpksl8ed8e61a.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2146f87a-bea6-4cd0-91f6-49050f50a56b}\MpKsl8ed8e61a.sys [?]
S1 MpKslbc535921;MpKslbc535921;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{36119a8b-a383-4885-b33a-45e7935f4b46}\mpkslbc535921.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{36119a8b-a383-4885-b33a-45e7935f4b46}\MpKslbc535921.sys [?]
S1 MpKslbd973cc1;MpKslbd973cc1;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a8f386fa-eaf9-4a81-97fa-4670b8d6f887}\mpkslbd973cc1.sys --> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a8f386fa-eaf9-4a81-97fa-4670b8d6f887}\MpKslbd973cc1.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-3-27 136176]
S3 androidusb;ADB Interface Driver;c:\windows\system32\drivers\androidusb.sys [2010-8-29 31312]
S3 pnetmdm;PdaNet Modem;c:\windows\system32\drivers\pnetmdm.sys [2010-8-29 9472]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-07-04 02:48:36 -------- d-----w- c:\documents and settings\owner\application data\FixTDSS
2011-07-04 02:48:35 26872 ----a-w- c:\windows\system32\drivers\FixTDSS.sys
2011-07-04 00:47:21 711728 ----a-w- c:\windows\isRS-000.tmp
2011-07-03 23:56:11 -------- d--h--w- c:\windows\PIF
2011-07-03 08:23:58 -------- d-sha-r- C:\cmdcons
2011-07-03 08:15:28 98816 ----a-w- c:\windows\sed.exe
2011-07-03 08:15:28 518144 ----a-w- c:\windows\SWREG.exe
2011-07-03 08:15:28 256000 ----a-w- c:\windows\PEV.exe
2011-07-03 08:15:28 208896 ----a-w- c:\windows\MBR.exe
2011-07-03 08:14:08 -------- d-----w- C:\ComboFix
2011-07-03 08:05:36 -------- d-----w- c:\documents and settings\all users\application data\RegCure
2011-07-03 05:03:37 -------- d-----w- c:\documents and settings\owner\local settings\application data\PCHealth
2011-07-03 04:51:03 -------- d-----w- c:\documents and settings\all users\application data\PC Tools
2011-07-03 04:48:11 -------- d-----w- c:\program files\GridinSoft Trojan Killer
2011-07-03 04:39:05 28752 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2146f87a-bea6-4cd0-91f6-49050f50a56b}\MpKsl94338c51.sys
2011-07-03 04:17:47 -------- d-----w- C:\TDSSKiller_Quarantine
2011-07-03 04:14:25 -------- d-----w- c:\documents and settings\owner\application data\Malwarebytes
2011-07-03 04:13:40 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-03 04:13:38 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2011-07-03 04:13:33 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-03 04:13:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-06-27 16:41:13 7074640 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{2146f87a-bea6-4cd0-91f6-49050f50a56b}\mpengine.dll
2011-06-18 22:10:59 -------- d-----w- c:\windows\SxsCaPendDel
2011-06-14 18:06:38 -------- d-----w- c:\program files\iPod
2011-06-14 18:06:02 -------- d-----w- c:\program files\iTunes
2011-06-14 16:17:18 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
==================== Find3M ====================
.
2011-05-23 20:09:30 45584 ----a-w- c:\windows\system32\drivers\ssfmonm.sys
2011-05-23 20:09:30 24496 ----a-w- c:\windows\system32\drivers\sshrmd.sys
2011-05-23 20:09:30 181008 ----a-w- c:\windows\system32\drivers\ssidrv.sys
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ----a-w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
2011-04-20 17:12:14 365456 ----a-w- c:\windows\Unwash6.exe
2011-04-10 04:33:09 191488 ----a-w- c:\windows\system32\hlvdd.dll
2011-04-06 23:20:16 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 23:20:16 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 23:20:16 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 23:20:16 107808 ----a-w- c:\windows\system32\dns-sd.exe
.
============= FINISH: 20:33:43.04 ===============
Attached File(s)
-
attach.txt (20.72K)
Number of downloads: 0 -
dds.txt (15.28K)
Number of downloads: 0
This post has been edited by hvdcman: 03 July 2011 - 11:05 PM

Help
This topic is locked

Back to top











