But then AVG started sending reports of blocking viruses at completely random times. My denial was shattered when it blocked one when I had just turned my computer on and the only program that was supposed to have been opened was WMPlayer - I was in the bathroom with wireless headphones at the time.
Using HJT again revealed nothing. I tried using Trend's RootkitBuster. It found a lot of items (that I now know might not have been infected at all), but couldn't get rid of a few, and now just makes a pitiful doubled "Installation Failed" message whenever I try to open it. And so I prepared to throw myself at your mercy.
The preparation document says to make sure your firewall is up and running, and, guess what... of course it had been deactivated, and when I tried putting it back up to full blast, it wouldn't even let me open the menu. This led me to try Microsoft's malware remover (more out of desperation than anything); it found two things it didn't like, but not the biggie.
Today, as I was running the programs, it seemed to get worse. Now my sound drivers don't work - I can run the windows tool to fix it so that I can get sound from DVDs and MP3s, but not from Firefox. And my homepage (www.google.com/ig) results in a 404 Not Found, with nginx underneath a page break.
So now that this topic is finally finished, I'm going to keep my computer completely off while I wait for a reply. Check all my emails at the office, reacquaint myself with my XBox, maybe actually clean my apartment.... I throw myself and my computer at your feet. I've learned when I'm over my head.
One thing: I had actually been considering upgrading to 64bit windows before this mess, so a full reformat is a real possibility. All my games come from Steam, CDs or are MMOs available for download, and this is PC is actually only 3 months old so there wouldn't be much loss. But if there's a way to save my MP3s, I'd be very grateful. I'm starting to be suspicious of the machine I use as a backup, and like an idiot chose not to save most of them to the Amazon cloud when I bought them.
The nice thing is that I work at a psychiatrist's office. They'll understand the withdrawl.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by Jeremy at 21:52:48 on 2012-02-06
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3326.2434 [GMT -6:00]
.
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\PROGRA~1\AVG\AVG10\avgchsvx.exe
C:\PROGRA~1\AVG\AVG10\avgrsx.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\AVG\AVG10\avgwdsvc.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files\AVG\AVG10\avgtray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Razer\Nostromo\RazerNostromoSysTray.exe
C:\Program Files\SmartTechnology\Software\ProfilerU.exe
C:\Program Files\SmartTechnology\Software\SaiMfd.exe
C:\Program Files\AVG\AVG10\avgnsx.exe
C:\Program Files\AVG\AVG10\avgemcx.exe
C:\Windows\system32\conhost.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/ig
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
mRun: [HDAudDeck] c:\program files\via\viaudioi\vdeck\VDeck.exe -r
mRun: [AVG_TRAY] c:\program files\avg\avg10\avgtray.exe
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [Razer Nostromo Driver] c:\program files\razer\nostromo\RazerNostromoSysTray.exe
mRun: [ProfilerU] c:\program files\smarttechnology\software\ProfilerU.exe
mRun: [SaiMfd] c:\program files\smarttechnology\software\SaiMfd.exe
StartupFolder: c:\users\jeremy\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab
TCP: DhcpNameServer = 192.168.15.1
TCP: Interfaces\{45E57C08-AB6D-43EF-8664-18EE4906B7C8} : DhcpNameServer = 192.168.15.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\jeremy\appdata\roaming\mozilla\firefox\profiles\r73v14eb.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2011-2-22 22992]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2011-3-16 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2011-1-7 248656]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2011-3-1 34896]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2011-4-5 297168]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928]
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2012-1-31 7391072]
R2 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2011-2-8 269520]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2011-3-8 378472]
R3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2011-5-27 134480]
R3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2011-2-10 24144]
R3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2011-2-10 21968]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32v.sys [2011-8-24 122984]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2009-11-17 232448]
R3 rzjoystk;Razer VJoystick;c:\windows\system32\drivers\rzjoystk.sys [2011-3-24 16896]
R3 RzSynapse;Razer Driver;c:\windows\system32\drivers\RzSynapse.sys [2011-7-14 127360]
R3 SaiK0CC3;SaiK0CC3;c:\windows\system32\drivers\SaiK0CC3.sys [2011-9-20 147264]
R3 SaiU0CC3;SaiU0CC3;c:\windows\system32\drivers\SaiU0CC3.sys [2011-9-20 41152]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2011-8-24 1119232]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia updatus\daemonu.exe [2011-8-24 2214504]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;d:\steam\steamapps\common\dragon age ultimate edition\bin_ship\DAUpdaterSvc.Service.exe [2012-1-1 25832]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-8-25 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2011-8-24 1343400]
S4 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\ToolbarUpdaterService.exe [2011-7-27 267488]
.
=============== Created Last 30 ================
.
2012-02-03 22:51:06 -------- d-----w- c:\programdata\DivX
2012-01-25 04:10:51 -------- d-----w- c:\users\jeremy\appdata\local\SmartTechnology
2012-01-25 03:23:12 -------- d-----w- c:\programdata\SmartTechnology
2012-01-25 03:23:06 -------- d-----w- c:\program files\SmartTechnology
2012-01-24 15:49:42 46144 ----a-w- c:\windows\system32\drivers\SaiBus.sys
2012-01-24 15:49:42 22720 ----a-w- c:\windows\system32\drivers\SaiMini.sys
2012-01-24 05:30:31 -------- d-----w- c:\users\jeremy\appdata\local\Mozilla
2012-01-13 21:01:39 -------- d-----w- c:\windows\system32\directx
2012-01-13 21:01:17 -------- d-----w- c:\program files\Microsoft XNA
2012-01-11 06:50:59 1288472 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 06:50:58 67072 ----a-w- c:\windows\system32\packager.dll
2012-01-11 06:50:58 1328128 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 06:50:57 514560 ----a-w- c:\windows\system32\qdvd.dll
.
==================== Find3M ====================
.
2012-01-24 17:17:24 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-12-06 18:50:08 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2011-12-06 18:50:08 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2011-11-24 04:25:27 2342912 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 21:53:32.52 ===============
GMER log:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-02-06 22:12:39
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdePort0 ADATA_SSD_S599_64GB rev.3.4.3
Running: 2poyjk34.exe; Driver: C:\Users\Jeremy\AppData\Local\Temp\pxryypog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0x825457A0]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateProcess [0x82545848]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0x825458E4]
SSDT \SystemRoot\system32\DRIVERS\AVGIDSShim.Sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0x82545980]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwSaveKey + 13D1 82E93369 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82ECCD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 139F 82ED4054 4 Bytes [A0, 57, 54, 82]
.text ntkrnlpa.exe!KeRemoveQueueEx + 166F 82ED4324 8 Bytes [48, 58, 54, 82, E4, 58, 54, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 16E3 82ED4398 4 Bytes [80, 59, 54, 82] {SBB BYTE [ECX+0x54], 0x82}
? C:\Users\Jeremy\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Windows\system32\svchost.exe[1116] kernel32.dll!WriteFile 755053EE 5 Bytes JMP 001D000A
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!GetCursorPos 74E9A4B3 5 Bytes JMP 016F000A
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!GetForegroundWindow 74EA335D 5 Bytes JMP 01F0000A
.text C:\Windows\system32\svchost.exe[1116] USER32.dll!WindowFromPoint 74EC6BE9 5 Bytes JMP 01D7000A
.text C:\Windows\system32\svchost.exe[1116] ole32.dll!CoCreateInstance 75339D0B 5 Bytes JMP 0092000A
.text C:\Program Files\Mozilla Firefox\firefox.exe[1164] ntdll.dll!LdrLoadDll 7716223E 5 Bytes JMP 65691B30 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.Sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\0000004c halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
---- Threads - GMER 1.0.15 ----
Thread System [4:3720] A3710F2E
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 TDL4@MBR code has been found <-- ROOTKIT !!!
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior
---- EOF - GMER 1.0.15 ----
Attached File(s)
-
Attach.zip (2.63K)
Number of downloads: 1

Help
This topic is locked

Back to top












