Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Infected with Vundo/rayedutu.dll

  • This topic is locked This topic is locked
2 replies to this topic

#1 pputre


  • Members
  • 1 posts
  • Local time:07:09 AM

Posted 28 September 2009 - 02:09 PM


I think rayedutu.dll seems to be attaching and creating pop-ups and replacing ads on major websites (CNN/ESPN etc.) with 'You have Won' messages and annoying audio.video.

Pop-ups also rampant. Iexplore process does not termintae when closed and eats memory. Hijack this reports the DLL in


SSODL: damipaned

DDS (Ver_09-09-24.01) - NTFSx86
Run by pputre at 14:31:26.97 on Mon 09/28/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1313 [GMT -4:00]

AV: Symantec Endpoint Protection *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\BMC Software\AppSight\Bin\RI_svc.exe
C:\WINDOWS\System32\svchost.exe -k Cognizance
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\HPQ\IAM\bin\asghost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\pputre\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Settings,ProxyServer =
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar2.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: HP Credential Manager for ProtectTools: {df21f1db-80c6-11d3-9483-b03d0ec10000} - c:\program files\hpq\iam\bin\ItIeAddIN.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar2.dll
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [BelNotify] c:\windows\system32\rundll32.exe c:\progra~1\belarc\advisor\system\NPBelv32.dll,RunDll32_BelNotify
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [dulifafij] Rundll32.exe "c:\windows\system32\rayedutu.dll",a
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\inetrepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\program files\microsoft activesync\inetrepl.dll
Trusted Zone: allscripts.com\tops
Trusted Zone: google.com\mail
Trusted Zone: mylunchmoney.com\www
Trusted Zone: symantecliveupdate.com
Trusted Zone: symantecliveupdate.com
DPF: {06D59DC6-5304-432D-A1CE-67E531410F9F} - hxxp://ralfinance/BusinessPortal/UI/ResultViewer/Scripts/MBFWebBehaviors.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/TechConsole/x86/RescueControl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1243365264158
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://coradiant.webex.com/client/T23L/support/ieatgpc.cab
Handler: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - c:\program files\microsoft activesync\aatp.dll
WinCE Filter: image/bmp - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/gif - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/jpeg - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: image/xbm - {86F59FAE-FB3A-11D1-AA72-00C04FAE2D4B} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: text/asp - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll
WinCE Filter: text/html - {6C5C3074-FFAB-11d1-8EC4-00C04F98D57A} - c:\program files\microsoft activesync\cenetflt.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\windows\system32\rayedutu.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: damipaned - {5e770ff1-0aac-4849-95a2-c73b1dc9d67e} - c:\windows\system32\rayedutu.dll
STS: tokatiluy: {5e770ff1-0aac-4849-95a2-c73b1dc9d67e} - c:\windows\system32\rayedutu.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
LSA: Notification Packages = scecli AsWlnPkg

============= SERVICES / DRIVERS ===============

R1 NEOFLTR_540_11359;Juniper Networks TDI Filter Driver (NEOFLTR_540_11359);c:\windows\system32\drivers\NEOFLTR_540_11359.sys [2006-11-30 57559]
R2 AppSightInstallService;AppSight Install Service;c:\program files\bmc software\appsight\bin\RI_svc.exe [2008-6-23 36864]
R2 ASChannel;Local Communication Channel;c:\windows\system32\svchost.exe -k Cognizance [2004-8-4 14336]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-2-11 108392]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2009-2-11 108392]
R2 Symantec AntiVirus;Symantec Endpoint Protection;c:\program files\symantec\symantec endpoint protection\Rtvscan.exe [2009-2-11 2440120]
R2 udmpsvc;User Mode Process Dumper;system32\kktools\userdump.exe -Service --> system32\kktools\userdump.exe -Service [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-9-28 102448]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [2006-6-13 87936]
R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [2005-6-10 35968]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090927.019\NAVENG.SYS [2009-9-28 84912]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090927.019\NAVEX15.SYS [2009-9-28 1323568]
R3 udmpdrvr;User Mode Process Dumper Driver;c:\windows\system32\drivers\userdump.sys [2009-1-28 64384]
S0 icfmn;icfmn;c:\windows\system32\drivers\frezjce.sys --> c:\windows\system32\drivers\frezjce.sys [?]
S1 arlisvik;arlisvik;\??\c:\windows\system32\drivers\arlisvik.sys --> c:\windows\system32\drivers\arlisvik.sys [?]
S1 ctfqsmye;ctfqsmye;\??\c:\windows\system32\drivers\ctfqsmye.sys --> c:\windows\system32\drivers\ctfqsmye.sys [?]
S1 ctwwzbky;ctwwzbky;\??\c:\windows\system32\drivers\ctwwzbky.sys --> c:\windows\system32\drivers\ctwwzbky.sys [?]
S1 lmcrqiqj;lmcrqiqj;\??\c:\windows\system32\drivers\lmcrqiqj.sys --> c:\windows\system32\drivers\lmcrqiqj.sys [?]
S1 lxpshxmr;lxpshxmr;\??\c:\windows\system32\drivers\lxpshxmr.sys --> c:\windows\system32\drivers\lxpshxmr.sys [?]
S1 nbqbrpro;nbqbrpro;\??\c:\windows\system32\drivers\nbqbrpro.sys --> c:\windows\system32\drivers\nbqbrpro.sys [?]
S2 gupdate1c9863c34a6cf56;Google Update Service (gupdate1c9863c34a6cf56);c:\program files\google\update\GoogleUpdate.exe [2009-2-3 133104]
S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 ApsSrvService;AppSight Server;c:\program files\bmc software\appsight\bin\ApsSrv.exe [2008-6-23 315392]
S3 BBxService;AppSight Black Box Service;c:\program files\bmc software\appsight\bin\BBxService.exe [2008-6-23 767328]
S3 BEHRINGER_2902;usb-audio.de driver for BEHRINGER USB AUDIO;c:\windows\system32\drivers\BUSB2902.sys [2008-6-26 340480]
S3 HWACCESS;HWACCESS;c:\windows\system32\HWACCESS.SYS [2009-3-31 6808]
S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2009-6-17 17408]
S3 VirtDisk;XSS Virtual Disk Driver;c:\windows\sminst\virtdisk.sys [2006-6-13 56832]
S4 DbgSvc;Debug Diagnostic Service;c:\program files\debugdiag\DbgSvc.exe [2007-1-16 316256]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\microsoft visual studio 8\common7\ide\remote debugger\x86\msvsmon.exe [2005-9-23 2799808]

=============== Created Last 30 ================

2009-09-28 14:03 38,056 a------- c:\windows\system32\drivers\WGX.SYS
2009-09-28 11:57 50,176 a------- c:\windows\system32\proquota.exe
2009-09-28 11:57 50,176 a------- c:\windows\system32\dllcache\proquota.exe
2009-09-28 11:46 <DIR> a-dshr-- C:\cmdcons
2009-09-28 11:45 229,888 a------- c:\windows\PEV.exe
2009-09-28 11:45 161,792 a------- c:\windows\SWREG.exe
2009-09-28 11:45 98,816 a------- c:\windows\sed.exe
2009-09-28 09:06 693,760 a------- c:\windows\isRS-000.tmp
2009-09-27 18:06 <DIR> --d----- c:\windows\system32\XPSViewer
2009-09-27 18:05 117,760 a------- c:\windows\system32\prntvpt.dll
2009-09-27 18:05 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-27 18:05 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-27 18:05 1,676,288 a------- c:\windows\system32\xpssvcs.dll
2009-09-27 18:05 575,488 a------- c:\windows\system32\xpsshhdr.dll
2009-09-27 18:05 <DIR> --d----- C:\e4471fb14bcf2f47279d988c71
2009-09-27 18:05 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-09-27 18:05 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-27 17:05 153,088 -------- c:\windows\system32\dllcache\triedit.dll
2009-09-27 17:04 128,512 -------- c:\windows\system32\dllcache\dhtmled.ocx
2009-09-27 17:04 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
2009-09-27 16:31 578,560 a------- c:\windows\system32\dllcache\user32.dll
2009-09-27 16:04 1,529,241 a------- C:\SDFix.exe
2009-09-26 17:46 77,056 a------- c:\windows\system32\drivers\rtabjcmlyzryts.sys
2009-09-25 10:26 <DIR> --d----- c:\program files\Trend Micro
2009-09-22 12:58 81,736 a------- c:\windows\system32\lmdimon8.dll
2009-09-16 10:05 <DIR> --d----- c:\documents and settings\pputre\Tracing
2009-09-16 08:29 <DIR> --d----- c:\program files\Microsoft
2009-09-16 08:28 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-09-16 08:18 <DIR> --d----- c:\program files\common files\Windows Live
2009-09-05 18:31 268 a---h--- C:\sqmdata04.sqm
2009-09-05 18:31 244 a---h--- C:\sqmnoopt04.sqm

==================== Find3M ====================

2009-09-26 18:22 88,064 a------- c:\windows\system32\rayedutu.dll
2009-09-14 14:01 60,744 a------- c:\documents and settings\pputre\g2mdlhlpx.exe
2009-09-10 14:54 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 19,160 a------- c:\windows\system32\drivers\mbam.sys
2009-08-13 11:16 512,000 -------- c:\windows\system32\dllcache\jscript.dll
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-05 05:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-07-29 00:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 00:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-29 00:37 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-07-29 00:37 81,920 -------- c:\windows\system32\dllcache\fontsub.dll
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2009-07-18 12:05 3,069,440 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-18 12:05 1,509,888 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-07-17 15:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 15:01 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 23:43 10,841,088 a------- c:\windows\system32\dllcache\wmp.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\wmpdxm.dll
2009-07-13 23:43 286,208 a------- c:\windows\system32\dllcache\wmpdxm.dll
2005-09-09 20:55 7,155,864 a------- c:\program files\NGhost10.msi
2005-09-09 20:55 35 a------- c:\program files\SCSSDist.ini
2005-09-09 20:55 37,766,164 a------- c:\program files\Data1.cab
2009-06-27 08:35 49,664 a--sh--- c:\windows\system32\tasurizo.dll

============= FINISH: 14:32:00.42 ===============

ROOTREPEAL © AD, 2007-2009
Scan Start Time: 2009/09/28 14:35
Program Version: Version
Windows Version: Windows XP SP3

Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0xB41B2000 Size: 876544 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xB063D000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090927.019\EraserUtilRebootDrv.sys
Status: Locked to the Windows API!

Path: C:\Documents and Settings\pputre\Local Settings\Apps\2.0\HY1XTD47.Y0C\AZ93VZBA.Y0L\manifests\ReportBuilder.exe.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\pputre\Local Settings\Apps\2.0\HY1XTD47.Y0C\AZ93VZBA.Y0L\manifests\ReportBuilder.exe.manifest
Status: Locked to the Windows API!

Path: C:\Documents and Settings\pputre\Local Settings\Apps\2.0\HY1XTD47.Y0C\AZ93VZBA.Y0L\manifests\ReportBuilder.cdf-ms
Status: Locked to the Windows API!

Path: C:\Documents and Settings\pputre\Local Settings\Apps\2.0\HY1XTD47.Y0C\AZ93VZBA.Y0L\manifests\ReportBuilder.manifest
Status: Locked to the Windows API!

#: 012 Function Name: NtAlertResumeThread
Status: Hooked by "<unknown>" at address 0x89eec7b0

#: 013 Function Name: NtAlertThread
Status: Hooked by "<unknown>" at address 0x89ed2c98

#: 017 Function Name: NtAllocateVirtualMemory
Status: Hooked by "<unknown>" at address 0x89af2e28

#: 031 Function Name: NtConnectPort
Status: Hooked by "<unknown>" at address 0x89f165c0

#: 043 Function Name: NtCreateMutant
Status: Hooked by "<unknown>" at address 0x89f08658

#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0x89efc7e0

#: 083 Function Name: NtFreeVirtualMemory
Status: Hooked by "<unknown>" at address 0x89da4ec0

#: 089 Function Name: NtImpersonateAnonymousToken
Status: Hooked by "<unknown>" at address 0x89f07d30

#: 091 Function Name: NtImpersonateThread
Status: Hooked by "<unknown>" at address 0x89ec78c8

#: 108 Function Name: NtMapViewOfSection
Status: Hooked by "<unknown>" at address 0x89cd4508

#: 114 Function Name: NtOpenEvent
Status: Hooked by "<unknown>" at address 0x89f72378

#: 123 Function Name: NtOpenProcessToken
Status: Hooked by "<unknown>" at address 0x89e39198

#: 129 Function Name: NtOpenThreadToken
Status: Hooked by "<unknown>" at address 0x89dae6e0

#: 206 Function Name: NtResumeThread
Status: Hooked by "<unknown>" at address 0x89cc70a8

#: 213 Function Name: NtSetContextThread
Status: Hooked by "<unknown>" at address 0x8a914c80

#: 228 Function Name: NtSetInformationProcess
Status: Hooked by "<unknown>" at address 0x89db0828

#: 229 Function Name: NtSetInformationThread
Status: Hooked by "<unknown>" at address 0x89deec88

#: 253 Function Name: NtSuspendProcess
Status: Hooked by "<unknown>" at address 0x89f71ec8

#: 254 Function Name: NtSuspendThread
Status: Hooked by "<unknown>" at address 0x89ec05d0

#: 257 Function Name: NtTerminateProcess
Status: Hooked by "<unknown>" at address 0x8a8e6fd0

#: 258 Function Name: NtTerminateThread
Status: Hooked by "<unknown>" at address 0x89e390a0

#: 267 Function Name: NtUnmapViewOfSection
Status: Hooked by "<unknown>" at address 0x89e3d088

#: 277 Function Name: NtWriteVirtualMemory
Status: Hooked by "<unknown>" at address 0x89d7b1a0


Attached Files

Edited by pputre, 28 September 2009 - 02:36 PM.

BC AdBot (Login to Remove)


#2 etavares


    Bleepin' Remover

  • Malware Response Team
  • 15,514 posts
  • Gender:Male
  • Local time:07:09 AM

Posted 15 October 2009 - 05:11 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Upon completing the steps below another staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.

If you have already posted a DDS log, please do so again, as your situation may have changed.
Use the 'Add Reply' and add the new log to this thread.

Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Also, please subscribe to this topic, so you are notified when someone replies. Please continue to check manually on occasion, as every now and then the email may be caught by your spam filter.
To enable topic notifications you should do the following:
  • Click on the My Controls link at the top of the page to enter your control panel.
  • Scroll down to the Options category in the left hand side menu bar and click on the Email Settings link.
  • Put a checkmark in the checkbox labeled Enable 'Email Notification' by default?.
  • Set the If ticked, choose default type: menu option to Immediate Email Notification to have an email sent immediately when someone replied.
Information on A/V control HERE

If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators

#3 teacup61


    Bleepin' Texan!

  • Malware Response Team
  • 17,075 posts
  • Gender:Female
  • Location:Wills Point, Texas
  • Local time:06:09 AM

Posted 24 October 2009 - 03:16 PM

Due to the lack of feedback this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic
Please make a donation so I can keep helping people just like you.
Every little bit helps! :)
You can even use your credit card! Thank you!

Posted Image

Error reading poptart in Drive A: Delete kids y/n?

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users