Greetings from link
dds logs identify tdl4. gmer would not complete - got a blue screen crash message regarding shutting down to protect itself, tried to write to read only memory...
Anything that was done to remove this was done over a year ago so I'm starting fresh here and don't know all the history.
Any help and guidance I can get in removing this and getting back to "normal" with this machine would be great!
DDS output follows. Also see attached.
dds.txt-
----
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Tara at 0:58:21 on 2012-01-13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1278.680 [GMT -5:00]
.
AV: McAfee VirusScan *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall Plus *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\user.exe
C:\WINDOWS\drweb.exe
C:\WINDOWS\sysedit.exe
C:\WINDOWS\spoolsv.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\avp.exe
C:\WINDOWS\system.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\spoolsv.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\lsass.exe
C:\WINDOWS\win32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\nvsvc32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\winlogon.exe
C:\WINDOWS\csrss.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\csrss.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\mdm.exe
C:\WINDOWS\avp32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\win32.exe
C:\WINDOWS\debug.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\setup.exe
C:\WINDOWS\user.exe
C:\WINDOWS\mdm.exe
C:\WINDOWS\taskmgr.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\taskmgr.exe
C:\WINDOWS\cmd.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Logitech Vid\vid.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\user.exe
C:\WINDOWS\drweb.exe
C:\WINDOWS\sysedit.exe
C:\WINDOWS\spoolsv.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\avp.exe
C:\WINDOWS\system.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\spoolsv.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\lsass.exe
C:\WINDOWS\win32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\nvsvc32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\winlogon.exe
C:\WINDOWS\csrss.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\csrss.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\mdm.exe
C:\WINDOWS\avp32.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\win32.exe
C:\WINDOWS\debug.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\setup.exe
C:\WINDOWS\user.exe
C:\WINDOWS\mdm.exe
C:\WINDOWS\taskmgr.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\taskmgr.exe
C:\WINDOWS\cmd.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcupdate.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uDefault_Page_URL = hxxp://www.talkamerica.net/members
uSearch Bar = hxxp://bfc.myway.com/search/de_srchlft.html
uInternet Settings,ProxyServer = http=127.0.0.1:23012
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: H - No File
BHO: c:\windows\system32\xyjnfi1.dll: {b1b220c1-a503-59bd-f413-03b53a2c8954} - c:\windows\system32\xyjnfi1.dll
TB: McAfee VirusScan: {ba52b914-b692-46c4-b683-905236f6f655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Logitech Vid] "c:\program files\logitech\logitech vid\vid.exe" -bootmode
uRun: [Fnehiporerew] rundll32.exe "c:\windows\dsxpne.dll",Startup
uRun: [rbufryrj] c:\docume~1\tara\locals~1\temp\ybvccjlyg\rdljexltsbl.exe
uRun: [uPc+MV0NqzaXms] rundll32.exe c:\windows\system32\tte808.dll, SystemServer
uRun: [HNUiOXRre] c:\docume~1\tara\locals~1\temp\user.exe
uRun: [MKasc] c:\windows\drweb.exe
uRun: [MKetc] c:\windows\sysedit.exe
uRun: [MKeuf] c:\windows\spoolsv.exe
uRun: [HNUiOXRme] c:\docume~1\tara\locals~1\temp\avp.exe
uRun: [MKexe] c:\windows\system.exe
uRun: [HNUiOXRruf] c:\docume~1\tara\locals~1\temp\spoolsv.exe
uRun: [HNUiOXRpuc] c:\docume~1\tara\locals~1\temp\lsass.exe
uRun: [MKfPc] c:\windows\win32.exe
uRun: [HNUiOXRpw+] c:\docume~1\tara\locals~1\temp\nvsvc32.exe
uRun: [HNUiOXRssc] c:\docume~1\tara\locals~1\temp\winlogon.exe
uRun: [MKayc] c:\windows\csrss.exe
uRun: [HNUiOXRnyc] c:\docume~1\tara\locals~1\temp\csrss.exe
uRun: [HNUiOXRpZ] c:\docume~1\tara\locals~1\temp\mdm.exe
uRun: [MKZSc] c:\windows\avp32.exe
uRun: [HNUiOXRsPc] c:\docume~1\tara\locals~1\temp\win32.exe
uRun: [MKaoc] c:\windows\debug.exe
uRun: [HNUiOXRrvc] c:\docume~1\tara\locals~1\temp\setup.exe
uRun: [MKee] c:\windows\user.exe
uRun: [MKcZ] c:\windows\mdm.exe
uRun: [MKerb] c:\windows\taskmgr.exe
uRun: [HNUiOXRrrb] c:\docume~1\tara\locals~1\temp\taskmgr.exe
uRun: [MKaZ] c:\windows\cmd.exe
mRun: [SunJavaUpdateSched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe
mRun: [CTSysVol] c:\program files\creative\sound blaster live! 24-bit\surround mixer\CTSysVol.exe /r
mRun: [P17Helper] Rundll32 P17.dll,P17Helper
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [VSOCheckTask] "c:\progra~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
mRun: [MCAgentExe] c:\progra~1\mcafee.com\agent\mcagent.exe
mRun: [MCUpdateExe] c:\progra~1\mcafee.com\agent\mcupdate.exe
mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [VirusScan Online] c:\program files\mcafee.com\vso\mcvsshld.exe
mRun: [OASClnt] c:\program files\mcafee.com\vso\oasclnt.exe
mRun: [MPFExe] c:\progra~1\mcafee.com\person~1\MpfTray.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\logitech webcam software\LWS.exe" /hide
mRun: [uPc+MV0NqzaXms] rundll32.exe c:\windows\system32\tte808.dll, SystemServer
mRun: [HNUiOXRre] c:\docume~1\tara\locals~1\temp\user.exe
mRun: [MKasc] c:\windows\drweb.exe
mRun: [MKetc] c:\windows\sysedit.exe
mRun: [MKeuf] c:\windows\spoolsv.exe
mRun: [HNUiOXRme] c:\docume~1\tara\locals~1\temp\avp.exe
mRun: [MKexe] c:\windows\system.exe
mRun: [HNUiOXRruf] c:\docume~1\tara\locals~1\temp\spoolsv.exe
mRun: [HNUiOXRpuc] c:\docume~1\tara\locals~1\temp\lsass.exe
mRun: [MKfPc] c:\windows\win32.exe
mRun: [HNUiOXRpw+] c:\docume~1\tara\locals~1\temp\nvsvc32.exe
mRun: [HNUiOXRssc] c:\docume~1\tara\locals~1\temp\winlogon.exe
mRun: [MKayc] c:\windows\csrss.exe
mRun: [HNUiOXRnyc] c:\docume~1\tara\locals~1\temp\csrss.exe
mRun: [HNUiOXRpZ] c:\docume~1\tara\locals~1\temp\mdm.exe
mRun: [MKZSc] c:\windows\avp32.exe
mRun: [HNUiOXRsPc] c:\docume~1\tara\locals~1\temp\win32.exe
mRun: [MKaoc] c:\windows\debug.exe
mRun: [HNUiOXRrvc] c:\docume~1\tara\locals~1\temp\setup.exe
mRun: [MKee] c:\windows\user.exe
mRun: [MKcZ] c:\windows\mdm.exe
mRun: [MKerb] c:\windows\taskmgr.exe
mRun: [HNUiOXRrrb] c:\docume~1\tara\locals~1\temp\taskmgr.exe
mRun: [MKaZ] c:\windows\cmd.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\nkbmon~1.lnk - c:\program files\nikon\pictureproject\NkbMonitor.exe
uPolicies-explorer: NoFolderOptions = 1 (0x1)
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} - hxxp://office.microsoft.com/officeupdate/content/opuc2.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {670821E0-76D1-11D4-9F60-009027A966BF} - hxxp://racing.youbet.com/wr_6_1/controls/ybrequest.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131332817281
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://connect.dhs.gov/dana-cached/setup/JuniperSetupSP1.cab
TCP: DhcpNameServer = 192.168.10.1
TCP: Interfaces\{1C96217E-8E66-4D2A-A395-532C2FAE70BB} : DhcpNameServer = 192.168.10.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
STS: c:\windows\system32\xyjnfi1.dll: {b1b220c1-a503-59bd-f413-03b53a2c8954} - c:\windows\system32\xyjnfi1.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\tara\application data\mozilla\firefox\profiles\t20kb9i7.default\
FF - prefs.js: browser.startup.homepage - hxxps://login.yahoo.com/config/mail?.src=ym&.intl=us
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\java\j2re1.4.2_03\bin\NPOJI610.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype extension for Firefox: {B13721C7-F507-4982-B2E5-502A71474FED} - c:\program files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
.
============= SERVICES / DRIVERS ===============
.
P2 McShield;McAfee.com McShield;c:\progra~1\mcafee.com\vso\mcshield.exe [2005-4-16 221184]
R1 MPFIREWL;MPFIREWL;c:\windows\system32\drivers\MpFirewall.sys [2005-9-6 80640]
R2 McDetect.exe;McAfee WSC Integration;c:\program files\mcafee.com\agent\Mcdetect.exe [2005-8-24 126976]
R2 McTskshd.exe;McAfee Task Scheduler;c:\progra~1\mcafee.com\agent\mctskshd.exe [2005-8-24 122368]
R3 NaiAvFilter1;NaiAvFilter1;c:\windows\system32\drivers\naiavf5x.sys [2005-8-24 114464]
S3 mcupdmgr.exe;McAfee SecurityCenter Update Manager;c:\progra~1\mcafee.com\agent\mcupdmgr.exe [2005-4-16 245760]
.
=============== Created Last 30 ================
.
2012-01-13 01:49:22 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2012-01-13 01:49:22 12160 ----a-w- c:\windows\system32\dllcache\mouhid.sys
2012-01-13 01:49:09 14592 ----a-w- c:\windows\system32\drivers\kbdhid.sys
2012-01-13 01:49:09 14592 ----a-w- c:\windows\system32\dllcache\kbdhid.sys
.
==================== Find3M ====================
.
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: SAMSUNG_SP0802N rev.TK100-28 -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A443566]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8a449624]; MOV EAX, [0x8a4496a0]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E13B9] -> \Device\Harddisk0\DR0[0x8A4CF3B0]
3 CLASSPNP[0xF76B7FD7] -> nt!IofCallDriver[0x804E13B9] -> [0x8A412A00]
\Driver\atapi[0x8A4A5B10] -> IRP_MJ_CREATE -> 0x8A443566
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x137; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskSAMSUNG_SP0802N_________________________TK100-28#5&2713bb34&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8A4433B2
user != kernel MBR !!!
sectors 156249998 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 1:04:43.70 ===============
----
attach.txt (12.26K)
Number of downloads: 1

Help
This topic is locked


Back to top












