PING.exe is running and using up most of my CPU. I kill it manually through Process Explorer but it restarts itself and a few minutes later I have to kill it again. I'm also getting Google search result redirects in Chrome (but not in Firefox), and random tabs opening to malicious sites in Firefox occasionally.
Also, when I start up my computer, it wants to run Autochk to check the disk for integrity. But it says there are corrupted files on C: and that I should run System Restore. I have to manually skip Autochk in order to get my computer to fully boot up. If I try to run System Restore, I get a message saying there are corrupt files on C: and that I should run Chkdsk on the next start up. So both of these things are telling me to run the other, yet they're both saying they can't run because of corrupt files on C:.
Last night I noticed another issue as well. I use XAMPP to run a local test server to build websites that use Apache & MySQL. I'm not able to access any of my sites on localhost. This worked fine before the Blaster infection. Now if I enter any localhost address into a browser it just endlessly tries to connect to the site and nothing ever happens.
Before seeking help here I ran Mbam, Hitman Pro, Spybod S&D, Prevx, and Anti ZeroAccess.
My original post can be found here: http://www.bleepingcomputer.com/forums/topic428422.html/page__pid__2479518#entry2479518
My DDS log is below:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_24
Run by Mike at 13:32:01 on 2011-11-19
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3582.1592 [GMT -6:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Tablet\Pen\Pen_TouchService.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\aestsrv.exe
C:\xampp\apache\bin\httpd.exe
C:\Windows\system32\svchost.exe -k apphost
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Users\Mike\AppData\Roaming\Mozilla\Firefox\Profiles\nx0wy19i.default\extensions\startup.service@mozilla.com\svc.exe
C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
C:\Windows\System32\svchost.exe -k ipripsvc
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\xampp\mysql\bin\mysqld.exe
C:\Windows\system32\PnkBstrA.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\System32\tcpsvcs.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Windows\system32\STacSV.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\system32\svchost.exe -k iissvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
C:\Program Files\Tablet\Pen\Pen_Tablet.exe
C:\xampp\apache\bin\httpd.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Everything\Everything.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\SAMSUNG\Kies\KiesTrayAgent.exe
C:\Program Files\Extensis\Suitcase Fusion 2\FMCore.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\Program Files\doubleTwist 2.0\DoubleTwist.DeviceHelper.exe
C:\Program Files\SAMSUNG\Kies\External\FirmwareUpdate\KiesPDLR.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Mike\AppData\Local\Programs\Google\MusicManager\MusicManager.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\RescueTime\RescueTime.exe
C:\Users\Mike\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\Users\Mike\AppData\Local\Nemo Documents\NemoDocs.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
C:\Program Files\Process Explorer\procexp.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Users\Mike\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\System32\ping.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\REGSVR32.exe
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5080701
uSearch Page = hxxp://searchbox.digsby.com/
uStart Page = hxxp://www.us.hsbc.com/1/2/1/
uWindow Title = Internet Explorer
mDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=5080701
mSearch Page = hxxp://searchbox.digsby.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://searchbox.digsby.com/search?q=%s
mSearchAssistant = hxxp://searchbox.digsby.com/ie
mURLSearchHooks: H - No File
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagItBHO.dll
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\adobe contribute cs5\plugins\ieplugin\contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AskBar BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - AskBar BHO
BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DivX HiQ: {593ddec6-7468-4cdd-90e1-42dadaa222e9} - c:\program files\divx\divx plus web player\npdivx32.dll
BHO: PodcastBHO Class: {65134fdf-f8a5-4b3d-91d9-cdf273cfd578} - c:\program files\common files\doubletwist\IEPodcastPlugin.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Google Gears Helper: {e0fefe40-fbf9-42ae-ba58-794ca7e3fb53} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
TB: Foxit Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} -
TB: Cloudberry Twitter plugin: {844ca498-7e43-4eb9-937f-083da08110be} - mscoree.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagItIEAddin.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\adobe contribute cs5\plugins\ieplugin\contributeieplugin.dll
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [FMCore.exe] "c:\program files\extensis\suitcase fusion 2\FMCore.exe" -standalone
uRun: [Google Update] "c:\users\mike\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [RocketDock] "c:\program files\rocketdock\RocketDock.exe"
uRun: [AdobeBridge]
uRun: [doubleTwist] "c:\program files\doubletwist 2.0\doubleTwist.DeviceHelper.exe"
uRun: [KiesPDLR] c:\program files\samsung\kies\external\firmwareupdate\KiesPDLR.exe
uRun: [MusicManager] "c:\users\mike\appdata\local\programs\google\musicmanager\MusicManager.exe"
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [Everything] "c:\program files\everything\Everything.exe" -startup
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24\RivaTunerWrapper.exe" /S
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [SwitchBoard] c:\program files\common files\adobe\switchboard\SwitchBoard.exe
mRun: [AdobeCS5ServiceManager] "c:\program files\common files\adobe\cs5servicemanager\CS5ServiceManager.exe" -launchedbylogin
mRun: [AdobeCS5.5ServiceManager] "c:\program files\common files\adobe\cs5.5servicemanager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [KiesHelper] c:\program files\samsung\kies\KiesHelper.exe /s
mRun: [KiesTrayAgent] c:\program files\samsung\kies\KiesTrayAgent.exe
StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\dropbox.lnk - c:\users\mike\appdata\roaming\dropbox\bin\Dropbox.exe
StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\magicd~1.lnk - c:\program files\magicdisc\MagicDisc.exe
StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\nemodo~1.lnk - c:\users\mike\appdata\local\nemo documents\NemoDocs.exe
StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\rivatu~1.lnk - c:\program files\rivatuner v2.24\RivaTunerWrapper.exe
StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\autoru~1\doomi.lnk - c:\program files\doomi\Doomi.exe
StartupFolder: c:\users\mike\appdata\roaming\micros~1\windows\startm~1\programs\startup\autoru~1\rtmnot~1.lnk - c:\program files\rtmnotifier\RtmNotifier.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\colorv~1.lnk - c:\program files\colorvision\utility\ColorVisionStartup.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\everno~1.lnk - c:\windows\installer\{f761359c-9ced-45ae-9a51-9d6605cd55c4}\Evernote.ico
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\launchy.lnk - c:\program files\launchy\Launchy.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\rescue~1.lnk - c:\program files\rescuetime\RescueTime.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\autoru~1\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
uPolicies-explorer: HideSCABattery = 0 (0x0)
uPolicies-explorer: HideSCANetwork = 0 (0x0)
uPolicies-explorer: HideSCAVolume = 0 (0x0)
uPolicies-explorer: NoResolveTrack = 0 (0x0)
uPolicies-explorer: NoStartMenuMyGames = 1 (0x1)
uPolicies-explorer: NoStartMenuMyMusic = 1 (0x1)
uPolicies-explorer: NoUserFolderInStartMenu = 0 (0x0)
uPolicies-explorer: StartMenuLogOff = 1 (0x1)
uPolicies-explorer: TaskbarNoThumbnail = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Add to Evernote 4.0 - c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://c:\program files\evernote\evernote\EvernoteIE.dll/204
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
IE: {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - {0B4350D1-055F-47A3-B112-5F2F2B0D6F08} - c:\program files\google\google gears\internet explorer\0.5.36.0\gears.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: mswsock.dll
Trusted Zone: kuaiche.com\software
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8} : DhcpNameServer = 192.168.1.1
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\16474777966696 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\16474777966696 : DhcpNameServer = 192.168.5.1
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\2375942554136303 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\2375942554136303 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\255444 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\255444 : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\35D656C6C696F64747 : DhcpNameServer = 68.87.72.134 68.87.77.134
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\36F6163686 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\36F6163686 : DhcpNameServer = 209.103.224.2 209.103.224.3
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\45F657A6F6572737D27657563747 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\47F657A6F6572737370716D27657563747 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\47F657A6F6572737370716D27657563747 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\7456F62776567237029436560234275616D6027455543545 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\7456F62776567237029436560234275616D6027455543545 : DhcpNameServer = 68.87.72.130 68.87.77.130
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\7796E63747F6E63736166656 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\E4F627478637964656D27657563747 : NameServer = 8.8.8.8,8.8.4.4
TCP: Interfaces\{7EFEA5AB-A576-420F-95A8-AB9C1BEA7BC8}\E4F627478637964656D27657563747 : DhcpNameServer = 208.59.247.45 208.59.247.46
TCP: Interfaces\{8E5CBEF3-FB94-442C-A834-1E909606F943} : NameServer = 8.8.8.8,8.8.4.4
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\intuit\quickbooks 2009\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
AppInit_DLLs: avgrsstx.dll
IFEO: taskmgr.exe - "c:\program files\process explorer\PROCEXP.EXE"
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\
FF - prefs.js: browser.startup.homepage - chrome://speeddial/content/speeddial.xul
FF - prefs.js: keyword.URL - hxxp://www.google.com/search?btnG=Google+Search&q=
FF - prefs.js: network.proxy.type - 0
FF - component: c:\program files\google\google gears\firefox\lib\ff36\gears.dll
FF - component: c:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll
FF - component: c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\extensions\{6ac85730-7d0f-4de0-b3fa-21142dd85326}\platform\winnt\components\ColorZilla.dll
FF - component: c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc_fireftp.dll
FF - component: c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\extensions\{e0b8c461-f8fb-49b4-8373-fe32e9252800}\platform\winnt_x86-msvc\components\enbar.dll
FF - component: c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\extensions\refractor@developer.mozilla.org\components\prism.dll
FF - component: c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\extensions\support@lastpass.com\platform\winnt_x86-msvc\components\lpxpcom.dll
FF - plugin: c:\program files\common files\doubletwist\NPPodcast.dll
FF - plugin: c:\program files\divx\divx ovs helper\npovshelper.dll
FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.17\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.27\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60310.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npigl.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\onlive\firefoxplugin\npolgdet.dll
FF - plugin: c:\program files\opera\program\plugins\np_gp.dll
FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\opera\program\plugins\npigl.dll
FF - plugin: c:\program files\tabletplugins\npwacom.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\program files\veetle\vlcbroadcast\npvbp.dll
FF - plugin: c:\program files\vlc\npvlc.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\programdata\id software\quakelive\npquakezero.dll
FF - plugin: c:\users\mike\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\users\mike\appdata\local\huludesktop\instances\0.9.8.1\nphdplg.dll
FF - plugin: c:\users\mike\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\mike\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\windows\system32\wat\npWatWeb.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-12 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-8-12 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-12 108552]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 165264]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2010-12-2 142592]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2011-3-28 73728]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2010-2-24 29416]
R2 Firefox Service;Firefox Service;c:\users\mike\appdata\roaming\mozilla\firefox\profiles\nx0wy19i.default\extensions\startup.service@mozilla.com\svc.exe [2011-8-6 83456]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\seagate\seagatemanager\sync\FreeAgentService.exe [2009-5-1 181544]
R2 iPodDrv;iPodDrv;c:\windows\system32\drivers\iPodDrv.sys [2011-3-9 6656]
R2 iprip;RIP Listener;c:\windows\system32\svchost.exe -k ipripsvc [2009-7-13 20992]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-11-17 1153368]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-1-7 378984]
R2 TabletServicePen;TabletServicePen;c:\program files\tablet\pen\Pen_Tablet.exe [2011-4-29 4869488]
R2 TeamViewer5;TeamViewer 5;c:\program files\teamviewer\version5\TeamViewer_Service.exe [2009-12-17 185640]
R2 TouchServicePen;Wacom Consumer Touch Service;c:\program files\tablet\pen\Pen_TouchService.exe [2011-4-29 416112]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-7-15 24652]
R3 DlinkUDSMBus;UDS Master Bus of Kernel USB Software Bus by TCP;c:\windows\system32\drivers\DlinkUDSMBus.sys [2008-8-18 73600]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 14336]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2011-4-29 16240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c8eb8257110c30;Google Update Service (gupdate1c8eb8257110c30);c:\program files\google\update\GoogleUpdate.exe [2008-7-21 133104]
S2 XAMPP;XAMPP Service;c:\xampp\service.exe [2007-12-20 60928]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2011-11-16 30312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\common files\bcl technologies\easypdf 5\bepldr.exe [2007-8-22 151552]
S3 cpuz134;cpuz134;c:\program files\cpuid\pc wizard 2010\pcwiz_x32.sys [2010-12-16 20328]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys [2011-5-8 20032]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2008-7-21 133104]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.2;c:\windows\system32\drivers\libusb0.sys [2010-2-19 32256]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-11-17 41272]
S3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2009-6-18 43392]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2010-10-24 54144]
S3 NisSrv;Microsoft Network Inspection;c:\program files\microsoft security client\antimalware\NisSrv.exe [2010-11-11 206360]
S3 SandraAgentSrv;SiSoftware Deployment Agent Service;c:\program files\sisoftware\sisoftware sandra lite 2011b\RpcAgentSrv.exe [2010-12-20 93848]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-11-16 121192]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-11-16 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-11-16 136680]
S3 SwitchBoard;Adobe SwitchBoard;c:\program files\common files\adobe\switchboard\SwitchBoard.exe [2010-2-19 517096]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-4-26 1343400]
.
=============== Created Last 30 ================
.
2011-11-19 19:23:17 53760 ----a-w- c:\windows\system32\u53vwSos6.com
2011-11-19 01:47:34 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{48c5a5f1-65ff-4f41-b13c-bce8a8a7a7d3}\offreg.dll
2011-11-19 01:47:27 6668624 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{48c5a5f1-65ff-4f41-b13c-bce8a8a7a7d3}\mpengine.dll
2011-11-18 23:04:24 23624 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2011-11-18 23:03:58 -------- d-----w- c:\programdata\Hitman Pro
2011-11-18 03:37:26 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-11-18 00:14:04 -------- d-----w- c:\program files\Spybot - Search & Destroy
2011-11-17 05:20:28 -------- d-----w- c:\users\mike\appdata\local\Programs
2011-11-17 02:52:28 136680 ----a-w- c:\windows\system32\drivers\ssadmdm.sys
2011-11-17 02:52:28 10344 ----a-w- c:\windows\system32\drivers\ssadwhnt.sys
2011-11-17 02:52:28 10344 ----a-w- c:\windows\system32\drivers\ssadwh.sys
2011-11-17 02:52:27 30312 ----a-w- c:\windows\system32\drivers\ssadadb.sys
2011-11-17 02:52:27 12776 ----a-w- c:\windows\system32\drivers\ssadmdfl.sys
2011-11-17 02:52:27 121192 ----a-w- c:\windows\system32\drivers\ssadbus.sys
2011-11-17 02:52:27 10472 ----a-w- c:\windows\system32\drivers\ssadcmnt.sys
2011-11-17 02:52:27 10472 ----a-w- c:\windows\system32\drivers\ssadcm.sys
2011-11-17 02:51:57 12488 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
2011-11-17 02:51:56 14920 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
2011-11-17 02:51:56 132424 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
2011-11-17 02:51:56 12616 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
2011-11-17 02:51:56 104648 ----a-w- c:\windows\system32\drivers\sscdbus.sys
2011-11-16 22:22:38 -------- d-----w- c:\users\mike\appdata\roaming\Malwarebytes
2011-11-16 22:22:24 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-11-16 22:22:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-11-12 22:42:31 -------- d-----w- c:\program files\focus booster
2011-11-10 22:48:01 -------- d-----w- c:\programdata\Phase One
2011-11-04 01:22:38 12616 ----a-w- c:\windows\system32\drivers\sscdcm.sys
2011-11-04 01:22:38 12488 ----a-w- c:\windows\system32\drivers\sscdwh.sys
2011-11-04 01:20:09 -------- d-----w- c:\users\mike\appdata\local\Samsung
2011-11-04 01:18:00 4659712 ----a-w- c:\windows\system32\Redemption.dll
2011-11-04 01:17:40 -------- d-----w- c:\program files\MarkAny
2011-11-04 01:17:02 -------- d-----w- c:\users\mike\appdata\roaming\Samsung
2011-11-02 03:56:02 -------- d--h--w- c:\program files\common files\EAInstaller
2011-11-01 00:41:51 -------- d-----w- c:\users\mike\appdata\roaming\Day 1 Studios
2011-11-01 00:41:36 -------- d-----w- c:\users\mike\appdata\local\SKIDROW
2011-10-31 01:32:51 -------- d-----w- c:\program files\Phase One
.
==================== Find3M ====================
.
2011-11-10 23:39:43 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2010-03-15 17:31:51 4032840 ----a-w- c:\program files\LookInMyPC.exe
2009-12-12 20:02:08 354304 ----a-w- c:\program files\Ultimate Windows Tweaker.exe
2009-03-26 02:36:36 897024 ----a-w- c:\program files\TweaksLogon.exe
2007-10-27 15:49:56 3306341 ----a-w- c:\program files\Simple CSS.exe
2003-06-16 21:23:22 131072 ----a-w- c:\program files\T2DXi.dll
2003-06-16 21:17:50 4317184 ----a-w- c:\program files\Triangle II.dll
2003-06-03 18:33:38 90112 ----a-w- c:\program files\Triangle II.exe
2002-12-17 09:00:00 82253 ----a-w- c:\program files\unins000.exe
2006-05-03 09:06:54 163328 --sha-r- c:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 --sha-r- c:\windows\system32\msfDX.dll
2008-03-16 12:30:52 216064 --sha-r- c:\windows\system32\nbDX.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.1.7600 Disk: WDC_WD32 rev.11.0 -> Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x888FEF10]<<
_asm { MOV EAX, [ESP+0x4]; MOV ECX, [EAX+0x28]; PUSH EBP; MOV EBP, [ECX+0x4]; PUSH ESI; MOV ESI, [ESP+0x10]; PUSH EDI; MOV EDI, [ESI+0x60]; MOV AL, [EDI]; CMP AL, 0x16; JNZ 0x36; PUSH ESI; }
1 ntkrnlpa!IofCallDriver[0x83075428] -> \Device\Harddisk0\DR0[0x8781B250]
3 CLASSPNP[0x8CFB459E] -> ntkrnlpa!IofCallDriver[0x83075428] -> [0x888CBEF8]
\Driver\00001713[0x8881B8E8] -> IRP_MJ_CREATE -> 0x888FEF10
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
user != kernel MBR !!!
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 13:39:50.52 ===============
I also ran GMER and I've attached the log file here. While it was running a notice popped up saying that C:\$MFT was corrupted.
Also all the checkboxes were grayed out except for "services", "registry", and "files". They were all unchecked except for these three.
Update: When PING.exe isn't taking up most of the CPU resources, now either IExplore (I never ever use Internet Explorer for web browsing) is or another process I've never seen called u53vwsos6.com is taking up most of the resources. This just started happening. PING.exe is still the culprit some or most of the time though.
Merged 3 posts. ~ OB
Attached File(s)
-
Attach.txt (14.78K)
Number of downloads: 0 -
GMER.log (388.38K)
Number of downloads: 0
This post has been edited by Orange Blossom: 20 November 2011 - 01:29 PM

Help
This topic is locked

Back to top











