The computer was running MS Security Essentials, which did (and still does) nothing to prevent or cure this.
The computer was also running Comodo Internet Security (but not Comodo AV), which let me block the most obvious bad file, hts.exe, and sandbox ping.exe. So the computer is no longer doing a zillion connections to external sites.
BUT... There are a couple of us working on this computer, and due to confusion (AKA panic), ComboFix was run without waiting for your instructions (it was found via Googling not your site, and we'd used it quite some time ago on a different PC to wonderful result...) ComboFix hung at Stage_4 and after a few hours of nothing happening the computer was rebooted.
AFTER all of the above, we found your site and followed your steps. Below is DDS.txt log. Attached are DDS file Attach.ext and GMER log ark.txt (This is zipped as ark.zip, because it is 620 KB, too large to upload as-is.)
Current status:
Task Manager does not show the virus running, but lots of things aren't working right. For instance, I can't copy+paste files via Explorer, or attach a USB stick (hoping to copy the log files). And the computer boots with Start/Task bar hidden. Plus some programs don't work (can't run IE, but can run Chrome). But at this point, I can't tell if the odd behavior is due to the virus, or ComboFix or DeFogger or GMER or Comodo's actions, or perhaps all of these... Upon reboot, Task Manager shows just a bare minimum of services running, which is also odd; perhaps certain system files are blocked or deleted?
At the end of GMER run, there were a bunch of messages saying various files could not be saved, yet the GMER file seems complete ("EOF" at end of it) and I could save it to the desktop as ark.txt, so I don't know what the "can't save" messages mean.
And, when I run PSPad (text editor) to view the log files, I get this message, in case it means something: "Error: Support for JScript active scripting not found. Install WSH with requested language support." That might be a PSPad-specific error, and maybe it is because of something Comodo blocked. Or it might be the virus/rootkit in action.
I will appreciate suggestions of next steps.
DDS.txt:
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_24
Run by johnh at 16:58:39 on 2011-12-23
.
============== Running Processes ===============
.
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\arservice.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService2.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\V0230Mon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\HP\KBD\KBD.EXE
c:\windows\system\hpsysdrv.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\johnh\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Orbitdownloader\orbitdm.exe
C:\Documents and Settings\johnh\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.advisor.com/
uSearch Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uInternet Settings,ProxyOverride = *.local
mSearchAssistant = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktop
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: hpWebHelper Class: {aaae832a-5fff-4661-9c8f-369692d1dcb9} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\plugin\WebHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Grab Pro: {c55bbcd6-41ad-48ad-9953-3609c48eacc7} - c:\program files\orbitdownloader\GrabPro.dll
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE
mRun: [PCDrProfiler]
mRun: [HPBootOp] "c:\program files\hewlett-packard\hp boot optimizer\HPBootOp.exe" /run
mRun: [HP Software Update] c:\program files\hp\hp software update\HPwuSchd2.exe
mRun: [CTHelper] CTHELPER.EXE
mRun: [CTxfiHlp] CTXFIHLP.EXE
mRun: [<NO NAME>]
mRun: [V0230Mon.exe] c:\windows\V0230Mon.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
mRun: [KernelFaultCheck] watcher_disabled.
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
uPolicies-explorer: NoStrCmpLogical = 01000000
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: {E2D4D26B-0180-43a4-B05F-462D6D54C789} - c:\windows\pchealth\helpctr\vendors\cn=hewlett-packard,l=cupertino,s=ca,c=us\iebutton\support.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
LSP: mswsock.dll
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15026/CTSUEng.cab
DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} - hxxp://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1172275233468
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} - hxxps://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15028/CTPID.cab
TCP: Interfaces\{102151AB-4698-43CA-882D-8D7EC1F90321} : NameServer = 208.67.222.222,208.67.220.220
TCP: Interfaces\{892900FC-9814-4488-99C0-81491C1EE93D} : DhcpNameServer = 16.92.3.242 16.92.3.243 16.81.3.243 16.118.3.243
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 relog_ap
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\johnh\application data\mozilla\firefox\profiles\hc36xvux.default\
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\johnh\application data\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\johnh\application data\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\johnh\local settings\application data\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\nitro pdf\reader\npdf.dll
FF - plugin: c:\program files\nitro pdf\reader\npnitromozilla.dll
.
============= SERVICES / DRIVERS ===============
.
R? cmdAgent;COMODO Internet Security Helper Service
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? McrdSvc;Media Center Extender Service
R? Media Center 15 Service;Media Center 15 Service
R? Media Center 16 Service;Media Center 16 Service
R? PSI;PSI
R? V0230Vfx;V0230Vfx
R? V0230VID;Live! Cam Video IM Pro
R? WDC_SAM;WD SCSI Pass Thru driver
S? cmdGuard;COMODO Internet Security Sandbox Driver
S? cmdHlp;COMODO Internet Security Helper Driver
S? MpFilter;Microsoft Malware Protection Driver
S? NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2
.
=============== File Associations ===============
.
txtfile="c:\program files\pspad editor\PSPad.exe" "%1"
.
=============== Created Last 30 ================
.
2011-12-23 22:28:43 -------- d-sha-r- C:\cmdcons
2011-12-23 22:26:26 98816 ----a-w- c:\windows\sed.exe
2011-12-23 22:26:26 518144 ----a-w- c:\windows\SWREG.exe
2011-12-23 22:26:26 256000 ----a-w- c:\windows\PEV.exe
2011-12-23 22:26:26 208896 ----a-w- c:\windows\MBR.exe
2011-12-23 22:26:10 -------- d-s---w- C:\ComboFix
2011-12-23 17:09:37 356352 ----a-w- c:\documents and settings\johnh\local settings\application data\hst.exe
2011-12-23 16:49:44 6823496 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ab5afac1-765e-466c-8a64-9a3df8fe4e18}\mpengine.dll
2011-12-15 17:14:01 -------- d-----w- c:\program files\iPod
2011-12-15 17:13:59 -------- d-----w- c:\program files\iTunes
2011-12-15 17:13:59 -------- d-----w- c:\documents and settings\all users\application data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-12-15 17:12:46 -------- d-----w- c:\program files\Bonjour
.
==================== Find3M ====================
.
2011-12-03 00:13:05 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys
2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-11-04 19:20:51 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec
2011-11-01 16:07:10 1288704 ----a-w- c:\windows\system32\ole32.dll
2011-10-28 05:31:48 33280 ----a-w- c:\windows\system32\csrsrv.dll
2011-10-25 13:37:08 2148864 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-10-25 12:52:02 2027008 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-10-15 01:38:00 456192 ----a-w- c:\windows\system32\encdec.dll
2011-10-10 14:22:41 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-07 17:48:01 31704 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2011-10-07 17:48:00 492768 ----a-w- c:\windows\system32\drivers\cmdGuard.sys
2011-10-07 17:47:59 18056 ----a-w- c:\windows\system32\drivers\cmderd.sys
2011-10-07 17:47:11 33984 ----a-w- c:\windows\system32\cmdcsr.dll
2011-10-07 17:47:10 300200 ----a-w- c:\windows\system32\guard32.dll
2011-09-28 07:06:50 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 18:41:20 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 18:41:20 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 18:41:14 20480 ----a-w- c:\windows\system32\oleaccrc.dll
.
============= FINISH: 16:59:30.09 ===============
Attached File(s)
-
ark.zip (20.69K)
Number of downloads: 5 -
Attach.txt (15.55K)
Number of downloads: 1

Help
This topic is locked


Back to top












