BleepingComputer.com: lost "rookie"

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

lost "rookie" as per "BOOPME"

#1 User is offline   bubba1980 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 23-January 12

Posted 29 January 2012 - 12:51 AM

posting dds logs.....Attached File  attach.txt (6.93K)
Number of downloads: 2

Agian i thank you all for your help
Marty

Attached File(s)

  • Attached File  dds.txt (9.58K)
    Number of downloads: 9


#2 User is offline   bubba1980 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 23-January 12

Posted 29 January 2012 - 12:56 AM

oops almost forgot the other file:


Copyright© 2011 AVAST Software
Run date: 2012-01-28 01:33:02
-----------------------------
01:33:02.447 OS Version: Windows 6.0.6002 Service Pack 2
01:33:02.447 Number of processors: 2 586 0x203
01:33:02.447 ComputerName: THEHENDERSON-PC UserName: the hendersons
01:33:02.993 Initialize success
01:36:36.620 AVAST engine defs: 12012701
01:36:41.393 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000058
01:36:41.393 Disk 0 Vendor: Hitachi_ ST2O Size: 305245MB BusType: 6
01:36:41.409 Disk 0 MBR read successfully
01:36:41.409 Disk 0 MBR scan
01:36:41.424 Disk 0 unknown MBR code
01:36:41.424 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 14336 MB offset 2048
01:36:41.440 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 145453 MB offset 29362176
01:36:41.471 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 145454 MB offset 327249920
01:36:41.487 Disk 0 scanning sectors +625139712
01:36:41.549 Disk 0 scanning C:\Windows\system32\drivers
01:36:48.460 Service scanning
01:36:49.458 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
01:36:50.098 Modules scanning
01:36:55.121 Disk 0 trace - called modules:
01:36:55.152 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys ndis.sys nvmfdx32.sys
01:36:55.152 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86249ac8]
01:36:55.168 3 CLASSPNP.SYS[8a3aa8b3] -> nt!IofCallDriver -> [0x85db4508]
01:36:55.168 5 acpi.sys[8060e6bc] -> nt!IofCallDriver -> \Device\00000058[0x85db49d0]
01:36:55.870 AVAST engine scan C:\Windows
01:37:05.214 AVAST engine scan C:\Windows\system32
01:39:18.532 AVAST engine scan C:\Windows\system32\drivers
01:39:27.908 AVAST engine scan C:\Users\the hendersons
01:39:55.192 Disk 0 MBR has been saved successfully to "C:\Users\the hendersons\Desktop\MBR.dat"
01:39:55.192 The log file has been saved successfully to "C:\Users\the hendersons\Desktop\aswMBR.txt"

#3 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 02 February 2012 - 02:25 PM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

Please Download
TDSSKiller.zip

>>> Double-click on TDSSKiller.exe to run the application.
  • Click on the Start Scan button and wait for the scan and disinfection process to be over.
  • If an infected file is detected, the default action will be Cure, click on Continue
    Posted Image
  • If a suspicious file is detected, the default action will be Skip, click on Continue
    Posted Image
  • If you are asked to reboot the computer to complete the process, click on the Reboot Now button. A report will be automatically saved at the root of the System drive ((usually C:\) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt" (for example, C:\TDSSKiller.2.2.0_20.12.2009_15.31.43_log.txt). Please copy and paste the contents of that file here.
  • If no reboot is required, click on Report. A log file will appear. Please copy and paste the contents of that file in your next reply.


Download http://public.avast.com/~gmerek/aswMBR.exe (aswMBR.exe) ( 511KB ) to your desktop. Double click the aswMBR.exe to run it

  • Click the "Scan" button to start scan.
  • Upon completion of the scan, click Save log, and save it to your desktop. (Note - do not select any Fix at this time) <- IMPORTANT
  • Please post the contents of that log in your next reply.
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

===

Please post the logs for my review.

#4 User is offline   bubba1980 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 23-January 12

Posted 03 February 2012 - 09:31 PM

my computer finaly crashed..... wiped hard drive and installed XP, seems to be good now! I want to say thanks you all for the help!!
Marty.

#5 User is offline   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,061
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 04 February 2012 - 09:08 AM

Thank you for the feed back.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users