BleepingComputer.com: System Check got me; RKILL and Malwarebytes not working

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

System Check got me; RKILL and Malwarebytes not working

#16 User is offline   martian421 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 03-February 12

Posted 16 February 2012 - 07:06 PM

EDIT, working on this and will get back.

All instructions have been followed and i have a few queries:

Appears the files are no longer locked using the Inherit program, but why do they still show as "hidden files" (the color of the ICON is lighter than the other icons i see)? I also see a folder in my C drive called "ProgramData". Was this folder created by the malware/virus? i don't ever recall seeing this in the past.

i'm also getting an error message stating that my recycle bin in my C drive is corrupt. is this another effect from the malware/virus?

Thanks!

This post has been edited by martian421: 16 February 2012 - 08:11 PM


#17 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,524
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 16 February 2012 - 08:32 PM

Hello

Appears the files are no longer locked using the Inherit program, but why do they still show as "hidden files" (the color of the ICON is lighter than the other icons i see)? I also see a folder in my C drive called "ProgramData". Was this folder created by the malware/virus? i don't ever recall seeing this in the past.
Run this for the hidden files and that folder is a legit folder

i'm also getting an error message stating that my recycle bin in my C drive is corrupt. is this another effect from the malware/virus? - http://www.vistax64.com/tutorials/131294-recycle-bin-corrupted-cannot-delete-file-folder.html


Gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#18 User is offline   martian421 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 10
  • Joined: 03-February 12

Posted 16 February 2012 - 09:35 PM

Gringo, also just ran Avira Antivirus and it found 15 virus's on my PC. log below:



Avira Free Antivirus
Report file date: Thursday, February 16, 2012 20:08

Scanning for 3470339 virus strains and unwanted programs.

The program is running as an unrestricted full version.
Online services are available:

Licensee : Avira AntiVir Personal - Free Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows 7
Windows version : (Service Pack 1) [6.1.7601]
Boot mode : Normally booted
Username : SYSTEM
Computer name : DUDU-PC

Version information:
BUILD.DAT : 12.0.0.898 41963 Bytes 1/31/2012 14:50:00
AVSCAN.EXE : 12.1.0.20 492496 Bytes 2/17/2012 00:02:19
AVSCAN.DLL : 12.1.0.18 54224 Bytes 2/17/2012 00:02:19
LUKE.DLL : 12.1.0.19 68304 Bytes 2/17/2012 00:02:19
AVSCPLR.DLL : 12.1.0.22 100048 Bytes 2/17/2012 00:02:19
AVREG.DLL : 12.1.0.29 228048 Bytes 2/17/2012 00:02:19
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 01:18:34
VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 16:07:39
VBASE002.VDF : 7.11.19.170 14374912 Bytes 12/20/2011 04:31:21
VBASE003.VDF : 7.11.21.238 4472832 Bytes 2/1/2012 04:31:23
VBASE004.VDF : 7.11.21.239 2048 Bytes 2/1/2012 04:31:24
VBASE005.VDF : 7.11.21.240 2048 Bytes 2/1/2012 04:31:24
VBASE006.VDF : 7.11.21.241 2048 Bytes 2/1/2012 04:31:24
VBASE007.VDF : 7.11.21.242 2048 Bytes 2/1/2012 04:31:24
VBASE008.VDF : 7.11.21.243 2048 Bytes 2/1/2012 04:31:24
VBASE009.VDF : 7.11.21.244 2048 Bytes 2/1/2012 04:31:24
VBASE010.VDF : 7.11.21.245 2048 Bytes 2/1/2012 04:31:24
VBASE011.VDF : 7.11.21.246 2048 Bytes 2/1/2012 04:31:24
VBASE012.VDF : 7.11.21.247 2048 Bytes 2/1/2012 04:31:24
VBASE013.VDF : 7.11.22.33 1486848 Bytes 2/3/2012 04:31:25
VBASE014.VDF : 7.11.22.56 687616 Bytes 2/3/2012 04:31:26
VBASE015.VDF : 7.11.22.92 178176 Bytes 2/6/2012 04:31:26
VBASE016.VDF : 7.11.22.154 144896 Bytes 2/8/2012 04:31:26
VBASE017.VDF : 7.11.22.220 183296 Bytes 2/13/2012 00:02:19
VBASE018.VDF : 7.11.23.34 202752 Bytes 2/15/2012 00:02:19
VBASE019.VDF : 7.11.23.35 2048 Bytes 2/15/2012 00:02:19
VBASE020.VDF : 7.11.23.36 2048 Bytes 2/15/2012 00:02:19
VBASE021.VDF : 7.11.23.37 2048 Bytes 2/15/2012 00:02:19
VBASE022.VDF : 7.11.23.38 2048 Bytes 2/15/2012 00:02:19
VBASE023.VDF : 7.11.23.39 2048 Bytes 2/15/2012 00:02:19
VBASE024.VDF : 7.11.23.40 2048 Bytes 2/15/2012 00:02:19
VBASE025.VDF : 7.11.23.41 2048 Bytes 2/15/2012 00:02:19
VBASE026.VDF : 7.11.23.42 2048 Bytes 2/15/2012 00:02:19
VBASE027.VDF : 7.11.23.43 2048 Bytes 2/15/2012 00:02:19
VBASE028.VDF : 7.11.23.44 2048 Bytes 2/15/2012 00:02:19
VBASE029.VDF : 7.11.23.45 2048 Bytes 2/15/2012 00:02:19
VBASE030.VDF : 7.11.23.46 2048 Bytes 2/15/2012 00:02:19
VBASE031.VDF : 7.11.23.84 92672 Bytes 2/16/2012 00:02:19
Engineversion : 8.2.10.4
AEVDF.DLL : 8.1.2.2 106868 Bytes 2/12/2012 04:31:30
AESCRIPT.DLL : 8.1.4.5 442745 Bytes 2/12/2012 04:31:30
AESCN.DLL : 8.1.8.2 131444 Bytes 2/12/2012 04:31:30
AESBX.DLL : 8.2.4.5 434549 Bytes 2/12/2012 04:31:30
AERDL.DLL : 8.1.9.15 639348 Bytes 9/9/2011 04:16:06
AEPACK.DLL : 8.2.16.3 799094 Bytes 2/12/2012 04:31:30
AEOFFICE.DLL : 8.1.2.25 201084 Bytes 2/12/2012 04:31:30
AEHEUR.DLL : 8.1.3.31 4395383 Bytes 2/17/2012 00:02:19
AEHELP.DLL : 8.1.19.0 254327 Bytes 2/12/2012 04:31:28
AEGEN.DLL : 8.1.5.21 409971 Bytes 2/12/2012 04:31:28
AEEXP.DLL : 8.1.0.22 70005 Bytes 2/17/2012 00:02:19
AEEMU.DLL : 8.1.3.0 393589 Bytes 9/2/2011 04:46:01
AECORE.DLL : 8.1.25.4 201079 Bytes 2/17/2012 00:02:19
AEBB.DLL : 8.1.1.0 53618 Bytes 9/2/2011 04:46:01
AVWINLL.DLL : 12.1.0.17 27344 Bytes 9/23/2011 17:13:18
AVPREF.DLL : 12.1.0.17 51920 Bytes 9/23/2011 16:53:57
AVREP.DLL : 12.1.0.17 179408 Bytes 9/23/2011 16:55:01
AVARKT.DLL : 12.1.0.23 209360 Bytes 2/17/2012 00:02:19
AVEVTLOG.DLL : 12.1.0.17 169168 Bytes 9/23/2011 16:34:37
SQLITE3.DLL : 3.7.0.0 398288 Bytes 9/16/2011 07:05:58
AVSMTP.DLL : 12.1.0.17 62928 Bytes 9/23/2011 17:03:47
NETNT.DLL : 12.1.0.17 17104 Bytes 9/23/2011 17:58:06
RCIMAGE.DLL : 12.1.0.17 4450000 Bytes 9/23/2011 18:37:25
RCTEXT.DLL : 12.1.1.16 96208 Bytes 2/17/2012 00:02:19

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging.............................: default
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: extended

Start of the scan: Thursday, February 16, 2012 20:08

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting search for hidden objects.

The scan of running processes will be started
Scan process 'SearchFilterHost.exe' - '35' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '37' Module(s) have been scanned
Scan process 'firefox.exe' - '104' Module(s) have been scanned
Scan process 'svchost.exe' - '36' Module(s) have been scanned
Scan process 'vssvc.exe' - '55' Module(s) have been scanned
Scan process 'avscan.exe' - '90' Module(s) have been scanned
Scan process 'avcenter.exe' - '85' Module(s) have been scanned
Scan process 'wmiprvse.exe' - '39' Module(s) have been scanned
Scan process 'swxcacls.exe' - '26' Module(s) have been scanned
Scan process 'conhost.exe' - '28' Module(s) have been scanned
Scan process 'cmd.exe' - '25' Module(s) have been scanned
Scan process 'Inherit.exe' - '44' Module(s) have been scanned
Scan process 'AUDIODG.EXE' - '44' Module(s) have been scanned
Scan process 'svchost.exe' - '46' Module(s) have been scanned
Scan process 'svchost.exe' - '61' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '62' Module(s) have been scanned
Scan process 'svchost.exe' - '45' Module(s) have been scanned
Scan process 'SUPERANTISPYWARE.EXE' - '96' Module(s) have been scanned
Scan process 'avgnt.exe' - '68' Module(s) have been scanned
Scan process 'ForceField.exe' - '84' Module(s) have been scanned
Scan process 'wfcrun32.exe' - '62' Module(s) have been scanned
Scan process 'WinPatrol.exe' - '32' Module(s) have been scanned
Scan process 'igfxsrvc.exe' - '29' Module(s) have been scanned
Scan process 'vpnui.exe' - '80' Module(s) have been scanned
Scan process 'concentr.exe' - '42' Module(s) have been scanned
Scan process 'igfxpers.exe' - '33' Module(s) have been scanned
Scan process 'hkcmd.exe' - '29' Module(s) have been scanned
Scan process 'svchost.exe' - '40' Module(s) have been scanned
Scan process 'SASCORE.EXE' - '27' Module(s) have been scanned
Scan process 'svchost.exe' - '64' Module(s) have been scanned
Scan process 'sched.exe' - '41' Module(s) have been scanned
Scan process 'spoolsv.exe' - '84' Module(s) have been scanned
Scan process 'IswSvc.exe' - '74' Module(s) have been scanned
Scan process 'Explorer.EXE' - '178' Module(s) have been scanned
Scan process 'Dwm.exe' - '34' Module(s) have been scanned
Scan process 'svchost.exe' - '87' Module(s) have been scanned
Scan process 'vpnagent.exe' - '61' Module(s) have been scanned
Scan process 'svchost.exe' - '90' Module(s) have been scanned
Scan process 'svchost.exe' - '159' Module(s) have been scanned
Scan process 'svchost.exe' - '124' Module(s) have been scanned
Scan process 'svchost.exe' - '92' Module(s) have been scanned
Scan process 'conhost.exe' - '24' Module(s) have been scanned
Scan process 'avshadow.exe' - '31' Module(s) have been scanned
Scan process 'avguard.exe' - '67' Module(s) have been scanned
Scan process 'svchost.exe' - '44' Module(s) have been scanned
Scan process 'svchost.exe' - '55' Module(s) have been scanned
Scan process 'lsm.exe' - '31' Module(s) have been scanned
Scan process 'lsass.exe' - '73' Module(s) have been scanned
Scan process 'services.exe' - '42' Module(s) have been scanned
Scan process 'winlogon.exe' - '31' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'wininit.exe' - '35' Module(s) have been scanned
Scan process 'csrss.exe' - '18' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned

Starting to scan executable files (registry).
The registry was scanned ( '491' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0001.dta
[DETECTION] Is the TR/Alureon.FK.99 Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0004.dta
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0005.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0008.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0009.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0001.dta
[DETECTION] Is the TR/Alureon.FK.99 Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0004.dta
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0005.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0008.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0009.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0001.dta
[DETECTION] Is the TR/Alureon.FK.99 Trojan
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0004.dta
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0005.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0008.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0009.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan

Beginning disinfection:
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0009.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '4a4d1dc5.qua'.
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0008.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '52da3262.qua'.
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0005.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '0085688a.qua'.
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0004.dta
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '66b22748.qua'.
C:\TDSSKiller_Quarantine\05.02.2012_09.39.46\mbr0000\tdlfs0000\tsk0001.dta
[DETECTION] Is the TR/Alureon.FK.99 Trojan
[NOTE] The file was moved to the quarantine directory under the name '23360a76.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0009.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '5c2d3817.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0008.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '1095145d.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0005.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '6c8d540d.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0004.dta
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '41d77b40.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.44.35\mbr0000\tdlfs0000\tsk0001.dta
[DETECTION] Is the TR/Alureon.FK.99 Trojan
[NOTE] The file was moved to the quarantine directory under the name '58bf40da.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0009.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '34e36cea.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0008.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '455a557f.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0005.dta
[DETECTION] Is the TR/Rootkit.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '4b4065b8.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0004.dta
[DETECTION] Is the TR/Rootkit.Gen2 Trojan
[NOTE] The file was moved to the quarantine directory under the name '0e691cfa.qua'.
C:\TDSSKiller_Quarantine\02.02.2012_16.35.25\mbr0000\tdlfs0000\tsk0001.dta
[DETECTION] Is the TR/Alureon.FK.99 Trojan
[NOTE] The file was moved to the quarantine directory under the name '07621851.qua'.


End of the scan: Thursday, February 16, 2012 21:33
Used time: 1:23:22 Hour(s)

The scan has been done completely.

16237 Scanned directories
298702 Files were scanned
15 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 Files were deleted
0 Viruses and unwanted programs were repaired
15 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
298687 Files not concerned
1368 Archives were scanned
0 Warnings
15 Notes
347249 Objects were scanned with rootkit scan
0 Hidden objects were found

#19 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,524
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 16 February 2012 - 09:46 PM

Hello

al the files were in this folder - C:\TDSSKiller_Quarantine so they are not a problem and you can even remove the folder so it does not happen again



Gringo
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

#20 User is offline   gringo_pr 

  • Bleepin Gringo
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 85,524
  • Joined: 03-July 08
  • Gender:Male
  • Location:Puerto rico

Posted 19 February 2012 - 01:43 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
I will be online from 5-31 to 6-4 in a very limited amount

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic


Please Only Copy And Paste Reports Into Topic - Do Not Attach

My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->Posted Image<-- Don't worry every little bit helps.

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users