Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

WUDFhost.exe running twice and svchost.exe using TONS of memory - 64 bit Windows 7 Ultimate Malware?


  • This topic is locked This topic is locked
10 replies to this topic

#1 Pr0metheus

Pr0metheus

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 06 October 2009 - 10:37 PM

Hello

I've recently been having some problems with my internet connection, namely it would begin going very very slowly and eventually prevent me from connecting altogether. I noticed a few odd things going on in my processes.

An Instance of svchost.exe would start off at about 90,000 K, and would escalate to 150,000 K +. I ran the process explorer and found that two instances of WUDFhost.exe (and dwm.exe, which I have since disabled) were utilizing that svchost.exe process. When I terminated the process tree for that svchost my screen would blink. Approximately 30 seconds after terminating the process my screen would blink again, and 4 processes (svchost.exe, WUDFhost.exe, WUDFhost.exe, and dwm.exe) would return. This would happen once more, then would not return after the third time I ended the process tree.

No connectivity problems were present after terminating these processes. I am using ESET NOD32 antivirus, and it did not detect the errors. I recently installed Malwarebytes, which detected a few 'infected' files that ESET missed, and removed them. I do not remember the specific names of the files removed.

I was unable to run the rootrepeal program because I am using a 64 bit operating system. I found a few links that said 64 bit windows is not vulnerable to root kits, although I'm not sure if I believe that. Here are the requested logs. Thank you in advance for your help.


DDS (Ver_09-09-29.01) - NTFSx86
Run by XPS-MTJ at 20:08:01.00 on Tue 10/06/2009
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4094.2675 [GMT -7:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
C:\Program Files (x86)\LogMeIn\x64\LMIGuardian.exe
C:\Windows\system32\rundll32.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\rundll32.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\VoxOx\VoxOx.exe
C:\Program Files (x86)\TechSmith\SnagIt 8\SnagIt32.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\TechSmith\SnagIt 8\TSCHelp.exe
C:\Program Files (x86)\iPod\bin\iPodService.exe
C:\Windows\system32\taskmgr.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Users\XPS-MTJ\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files (x86)\techsmith\snagit 8\SnagItBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files (x86)\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files (x86)\techsmith\snagit 8\SnagItIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [VoxOxNG] c:\program files (x86)\voxox\VoxOx.exe -b
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files (x86)\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\snagit~1.lnk - c:\program files (x86)\techsmith\snagit 8\SnagIt32.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Customize Menu - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.1.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files (x86)\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files (x86)\microsoft office\office12\GrooveShellExtensions.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\xps-mtj\appdata\roaming\mozilla\firefox\profiles\hrj28lnx.default\
FF - component: c:\program files (x86)\siber systems\ai roboform\firefox\components\rfproxy_31.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\users\xps-mtj\appdata\roaming\mozilla\firefox\profiles\hrj28lnx.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\users\xps-mtj\appdata\roaming\mozilla\firefox\profiles\hrj28lnx.default\extensions\technicianconsole@logmeinrescue.com\platform\winnt\plugins\npRescue.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys --> c:\windows\system32\drivers\vwififlt.sys [?]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\x86\ekrn.exe [2009-5-14 731840]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys --> c:\windows\system32\drivers\epfwwfpr.sys [?]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\logmein\x64\rainfo.sys [2008-7-24 15928]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\lmirfsdriver.sys --> c:\windows\system32\drivers\LMIRfsDriver.sys [?]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\oem02dev.sys --> c:\windows\system32\drivers\OEM02Dev.sys [?]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\oem02vfx.sys --> c:\windows\system32\drivers\OEM02Vfx.sys [?]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys --> c:\windows\system32\drivers\vwifimp.sys [?]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys --> c:\windows\system32\drivers\yk62x64.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys --> c:\windows\system32\drivers\usbaapl64.sys [?]

=============== Created Last 30 ================

2009-10-06 17:20 <DIR> --d----- c:\users\xps-mtj\appdata\roaming\Malwarebytes
2009-10-06 17:20 38,224 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-06 17:20 <DIR> --d----- c:\programdata\Malwarebytes
2009-10-06 17:20 <DIR> --d----- c:\program files (x86)\Malwarebytes' Anti-Malware
2009-10-06 17:20 <DIR> --d----- c:\progra~3\Malwarebytes
2009-10-06 16:57 <DIR> --d----- c:\programdata\SecTaskMan
2009-10-06 16:57 <DIR> --d----- c:\progra~3\SecTaskMan
2009-10-06 16:12 <DIR> --d----- c:\programdata\Google
2009-10-06 15:20 301,568 a------- c:\windows\system32\cmd.execf
2009-10-06 14:57 <DIR> --d----- c:\program files (x86)\Trend Micro
2009-10-04 01:35 <DIR> --d----- c:\programdata\EPSON
2009-10-04 01:35 <DIR> --d----- c:\progra~3\EPSON
2009-10-03 21:39 47,582 a------- C:\404.jpg
2009-10-01 10:42 7,704 a------- C:\unauthcall.pcap
2009-09-29 11:21 21,023 a------- C:\upness.jpg
2009-09-28 14:40 206,848 a------- C:\DIDs Aremove.xls
2009-09-28 14:32 2,318,569 a------- C:\DID_Numbers11.xls
2009-09-28 14:22 2,103,435 a------- C:\DID_Numbers2.xls
2009-09-27 17:58 107,368 a------- c:\windows\system32\GEARAspi.dll
2009-09-27 17:57 <DIR> --d----- c:\program files (x86)\iPod
2009-09-27 17:57 <DIR> --d----- c:\program files (x86)\iTunes
2009-09-25 12:40 28,900 a------- C:\98 Why!.jpg
2009-09-24 14:28 207,360 a------- C:\DIDs.xls
2009-09-24 14:05 9,900,743 a------- C:\DID_Numbers.xls
2009-09-23 10:41 68,287 a------- C:\setlink.jpg
2009-09-21 23:55 36,270 a------- C:\71 Facebook Religion.jpg
2009-09-21 23:28 14,192 a------- C:\88 Someone Punch This Kid.jpg
2009-09-21 16:57 <DIR> --d----- C:\Troubleshooting
2009-09-21 16:43 31,194,247 a------- C:\tmcap.pcap
2009-09-18 17:20 485,282,879 a------- c:\windows\MEMORY.DMP
2009-09-18 15:06 <DIR> --d----- c:\users\xps-mtj\appdata\roaming\MPEG Streamclip
2009-09-17 01:17 <DIR> --d----- c:\program files (x86)\iPhone Configuration Utility
2009-09-17 01:16 <DIR> --d----- c:\programdata\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
2009-09-17 01:16 <DIR> --d----- c:\progra~3\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
2009-09-17 01:13 <DIR> --d----- c:\users\xps-mtj\appdata\roaming\AVS4YOU
2009-09-17 01:13 <DIR> --d----- c:\programdata\AVS4YOU
2009-09-17 01:13 <DIR> --d----- c:\progra~3\AVS4YOU
2009-09-17 01:12 <DIR> --d----- c:\program files (x86)\common files\AVSMedia
2009-09-17 01:12 1,700,352 a------- c:\windows\system32\GdiPlus.dll
2009-09-17 01:12 974,848 a------- c:\windows\system32\mfc70.dll
2009-09-17 01:12 487,424 a------- c:\windows\system32\msvcp70.dll
2009-09-17 01:12 344,064 a------- c:\windows\system32\msvcr70.dll
2009-09-17 01:12 24,576 a------- c:\windows\system32\msxml3a.dll
2009-09-17 01:12 <DIR> --d----- c:\program files (x86)\AVS4YOU
2009-09-14 11:29 68,101 a------- C:\DestGroupWWUnlim.csv
2009-09-13 23:48 <DIR> --d----- c:\program files (x86)\common files\Adobe Systems Shared
2009-09-13 23:16 <DIR> --d----- c:\program files (x86)\Microsoft Office Outlook Connector
2009-09-13 23:15 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
2009-09-13 23:14 20 a------- c:\windows\΄χή
2009-09-10 14:22 <DIR> --d----- C:\MOH
2009-09-10 11:21 8,520 a------- c:\windows\system32\ractrlkeyhook.dll
2009-09-09 16:28 495 a------- C:\regtosip02.pcap

==================== Find3M ====================

2009-10-06 10:28 149,287 a------- c:\programdata\nvModes.dat
2009-10-06 10:28 149,287 a------- c:\progra~3\nvModes.dat
2009-08-26 23:31 347,648 a------- c:\windows\apppatch\apppatch64\AcLayers.dll
2009-08-26 23:31 135,168 a------- c:\windows\apppatch\apppatch64\AcXtrnal.dll
2009-08-06 09:54 4,332,032 a------- c:\windows\system32\PSP MixBass2.dll
2009-08-03 16:51 88,374,330 a------- C:\Cisco-config-assistant-win-k9-2_0-en.exe
2009-08-03 16:18 1,017,525 a------- C:\P0S3-07-5-00.zip
2009-08-03 15:39 676 a------- C:\SIPmacaddress.zip
2009-08-03 15:38 2,272 a------- C:\SIPDefault.zip
2009-08-03 15:32 685,624 a------- C:\P0S3-8-12-00.zip
2009-07-25 05:23 411,368 a------- c:\windows\system32\deploytk.dll
2009-07-13 22:37 291,294 a------- c:\windows\inf\perflib\0409\perfi.dat
2009-07-13 22:37 291,294 a------- c:\windows\inf\perflib\0409\perfh.dat
2009-07-13 22:37 31,548 a------- c:\windows\inf\perflib\0409\perfd.dat
2009-07-13 22:37 31,548 a------- c:\windows\inf\perflib\0409\perfc.dat
2009-07-13 21:54 174 a--sh--- c:\program files (x86)\desktop.ini
2009-07-13 18:40 52,736 a------- c:\windows\apppatch\apppatch64\apihex64.dll
2009-07-13 18:40 309,248 a------- c:\windows\apppatch\apppatch64\AcGenral.dll
2009-07-13 18:40 111,104 a------- c:\windows\apppatch\apppatch64\acspecfc.dll
2009-07-13 18:39 10,240 a------- c:\windows\write.exe
2009-07-13 18:39 61,952 a------- c:\windows\splwow64.exe
2009-07-13 18:39 427,008 a------- c:\windows\regedit.exe
2009-07-13 18:39 193,536 a------- c:\windows\notepad.exe
2009-07-13 18:39 733,696 a------- c:\windows\HelpPane.exe
2009-07-13 18:39 16,896 a------- c:\windows\hh.exe
2009-07-13 18:39 2,868,224 a------- c:\windows\explorer.exe
2009-07-13 18:39 15,360 a------- c:\windows\fveupdate.exe
2009-07-13 18:38 71,168 a------- c:\windows\bfsvc.exe
2009-07-13 18:26 21,584 a------- c:\windows\system32\BOOTVID.DLL
2009-07-13 18:23 5,070,848 a------- c:\windows\system32\AuthFWSnapin.dll
2009-07-13 18:22 107,008 a------- c:\windows\system32\NAPHLPR.DLL
2009-07-13 18:22 46,080 a------- c:\windows\system32\NAPCRYPT.DLL
2009-07-13 18:20 3,954,768 a------- c:\windows\system32\ntkrnlpa.exe
2009-07-13 18:20 3,899,472 a------- c:\windows\system32\ntoskrnl.exe
2009-07-13 18:20 91,728 a------- c:\windows\system32\MigAutoPlay.exe
2009-07-13 18:20 126,976 a------- c:\windows\system32\AuthFWWizFwk.dll
2009-07-13 18:19 52,816 a------- c:\windows\system32\PSHED.DLL
2009-07-13 18:17 249,680 a------- c:\windows\system32\bcryptprimitives.dll
2009-07-13 18:17 242,936 a------- c:\windows\system32\rsaenh.dll
2009-07-13 18:17 156,728 a------- c:\windows\system32\dssenh.dll
2009-07-13 18:17 102,448 a------- c:\windows\system32\wbem\Win32_Tpm.dll
2009-07-13 18:17 1,289,712 a------- c:\windows\system32\ntdll.dll
2009-07-13 18:17 143,936 a------- c:\windows\system32\basecsp.dll
2009-07-13 18:15 1,386,496 a------- c:\windows\system32\msxml6.dll
2009-07-13 18:14 171,520 a------- c:\windows\system32\BioCredProv.dll
2009-07-13 18:11 54,272 a------- c:\windows\system32\WsmRes.dll
2009-07-13 18:10 2,560 a------- c:\windows\system32\uxlibres.dll
2009-07-13 18:10 1,164,800 a------- c:\windows\system32\UIRibbonRes.dll
2009-07-13 18:10 2,048 a------- c:\windows\system32\tzres.dll
2009-07-13 18:10 108,544 a------- c:\windows\system32\tapiui.dll
2009-07-13 18:10 7,168 a------- c:\windows\system32\spwizres.dll
2009-07-13 18:10 8,338,432 a------- c:\windows\system32\spwizimg.dll
2009-07-13 18:10 2,560 a------- c:\windows\system32\sfc.dll
2009-07-13 18:10 68,608 a------- c:\windows\system32\nlsbres.dll
2009-07-13 18:08 6,917,120 a------- c:\windows\system32\NlsLexicons0c1a.dll
2009-07-13 18:07 18,944 a------- c:\windows\system32\netevent.dll
2009-07-13 18:07 2,048 a------- c:\windows\system32\netmsg.dll
2009-07-13 18:07 2,048 a------- c:\windows\system32\neth.dll
2009-07-13 18:07 2,048 a------- c:\windows\system32\msxml6r.dll
2009-07-13 18:07 2,048 a------- c:\windows\system32\msxml3r.dll
2009-07-13 18:07 60,928 a------- c:\windows\system32\msvcrt40.dll
2009-07-13 18:07 268,800 a------- c:\windows\system32\msshavmsg.dll
2009-07-13 18:07 8,192 a------- c:\windows\system32\msorc32r.dll
2009-07-13 18:07 60,416 a------- c:\windows\system32\msobjs.dll
2009-07-13 18:07 25,088 a------- c:\windows\system32\msimsg.dll
2009-07-13 18:07 4,608 a------- c:\windows\system32\msidntld.dll
2009-07-13 18:05 3,072 a------- c:\windows\system32\icmp.dll
2009-07-13 18:05 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll
2009-07-13 18:05 925,184 a------- c:\windows\system32\FXSRESM.dll
2009-07-13 18:04 2,560 a------- c:\windows\system32\dpnlobby.dll
2009-07-13 18:04 2,048 a------- c:\windows\system32\dpnaddr.dll
2009-07-13 18:04 372,224 a------- c:\windows\system32\dmdskres.dll
2009-07-13 18:04 2,048 a------- c:\windows\system32\dmdskres2.dll
2009-07-13 18:04 1,297,408 a------- c:\windows\system32\comres.dll
2009-07-13 18:04 514,048 a------- c:\windows\system32\shellstyle.dll
2009-07-13 18:00 291,294 a------- c:\windows\inf\perflib\0000\perfi.dat
2009-07-13 18:00 291,294 a------- c:\windows\inf\perflib\0000\perfh.dat
2009-07-13 18:00 31,548 a------- c:\windows\inf\perflib\0000\perfd.dat
2009-07-13 18:00 31,548 a------- c:\windows\inf\perflib\0000\perfc.dat
2009-07-13 16:25 293,888 a------- c:\windows\system32\atmfd.dll
2009-07-13 16:16 14,336 a------- c:\windows\system32\wowreg32.exe
2009-07-13 16:16 7,680 a------- c:\windows\system32\instnm.exe
2009-07-13 16:15 2,048 a------- c:\windows\system32\user.exe
2009-07-13 16:15 25,088 a------- c:\windows\system32\mode.com
2009-07-13 16:15 16,384 a------- c:\windows\system32\tree.com
2009-07-13 16:15 20,992 a------- c:\windows\system32\more.com
2009-07-13 16:15 35,840 a------- c:\windows\system32\format.com
2009-07-13 16:15 13,824 a------- c:\windows\system32\diskcomp.com
2009-07-13 16:15 11,264 a------- c:\windows\system32\diskcopy.com
2009-07-13 16:15 11,776 a------- c:\windows\system32\chcp.com
2009-07-13 16:11 3,584 a---h--- c:\windows\system32\api-ms-win-security-lsalookup-l1-1-0.dll
2009-07-13 16:11 3,072 a---h--- c:\windows\system32\api-ms-win-security-sddl-l1-1-0.dll
2009-07-13 16:10 6,144 a---h--- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2009-07-13 16:10 4,608 a---h--- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2009-07-13 16:10 3,584 a---h--- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2009-07-13 16:10 3,072 a---h--- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2009-07-13 16:06 43,131 a------- c:\windows\mib.bin
2009-07-13 14:03 49,179 a------- c:\windows\system32\sqlwoa.dll
2009-06-10 13:44 9,633,792 a--shr-- c:\windows\fonts\StaticCache.dat

============= FINISH: 20:08:51.88 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:25 AM

Posted 23 October 2009 - 03:43 PM

Hi

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems just let me know in your next reply or simply post a Hijackthis log.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:25 AM

Posted 26 October 2009 - 07:04 PM

Hello.

Are you still there?

If you are please follow the instructions in my previous post.

If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

Please reply back telling us so. If you don't reply within 5-7 from the last day I replied initially, the topic will need to be closed.

Thanks for understanding.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 Pr0metheus

Pr0metheus
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 28 October 2009 - 12:57 PM

I cannot run the root repeal because I'm using windows 7 64 bit. It gives me this error:
"Error - RootRepeal does not suppor 64-bit OSs!"

Here are the logs requested from DDS. I was getting extremely slow internet speeds while on WiFi at my work. It seemed to be fine at home, but I noticed 2 WUDFHost.exe processes running under an svchost.exe process that was using 95k+ memory (which seemed abnormal to me). Let me know if you need anything else. I'm pretty tech savvy, just not good with troubleshooting viruses.

Thanks again.


DDS (Ver_09-10-26.01) - NTFSX64
Run by XPS-MTJ at 10:32:09.02 on Wed 10/28/2009
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_15
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.4094.2610 [GMT -7:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files (x86)\Bonjour\mDNSResponder.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\System32\rundll32.exe
C:\Program Files (x86)\VoxOx\VoxOx.exe
C:\Program Files (x86)\TechSmith\SnagIt 8\SnagIt32.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Java\jre6\bin\jusched.exe
C:\Program Files (x86)\TechSmith\SnagIt 8\TSCHelp.exe
C:\Program Files (x86)\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\taskmgr.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Users\XPS-MTJ\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

mLocal Page = c:\windows\syswow64\blank.htm
uInternet Settings,ProxyOverride = *.local
BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files (x86)\techsmith\snagit 8\SnagItBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files (x86)\microsoft office\office12\GrooveShellExtensions.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\roboform.dll
TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files (x86)\techsmith\snagit 8\SnagItIEAddin.dll
TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
uRun: [VoxOxNG] c:\program files (x86)\voxox\VoxOx.exe -b
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files (x86)\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files (x86)\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [DELL Webcam Manager] "c:\program files (x86)\dell\dell webcam manager\DellWMgr.exe" /s
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\snagit~1.lnk - c:\program files (x86)\techsmith\snagit 8\SnagIt32.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-explorer: NoWelcomeScreen = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: Customize Menu - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: Fill Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html
IE: RoboForm Toolbar - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: Save Forms - file://c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files (x86)\siber systems\ai roboform\RoboFormComFillForms.html
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - c:\program files (x86)\siber systems\ai roboform\RoboFormComSavePass.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files (x86)\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
DPF: {254AA86E-5655-4518-AA87-185D7CC41801} - hxxps://secure.logmeinrescue.com/US/TechConsole/x86/RescueControl.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.1.cab
DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} - hxxps://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files (x86)\microsoft office\office12\GrooveSystemServices.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~2\common~1\skype\SKYPE4~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files (x86)\microsoft office\office12\GrooveShellExtensions.dll
BHO-X64: HelperObject Class: {00C6482D-C502-44C8-8409-FCE54AD9C208} - c:\program files (x86)\techsmith\snagit 8\x64\SnagItBHO64.dll
TB-X64: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - c:\program files (x86)\techsmith\snagit 8\x64\SnagItIEAddin64.dll
TB-X64: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
TB-X64: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File
mRun-x64: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun-x64: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start

================= FIREFOX ===================

FF - ProfilePath - c:\users\xps-mtj\appdata\roaming\mozilla\firefox\profiles\hrj28lnx.default\
FF - component: c:\program files (x86)\siber systems\ai roboform\firefox\components\rfproxy_31.dll
FF - plugin: c:\program files (x86)\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll
FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npRLCT4Player.dll
FF - plugin: c:\program files (x86)\viewpoint\viewpoint media player\npViewpoint.dll
FF - plugin: c:\users\xps-mtj\appdata\roaming\mozilla\firefox\profiles\hrj28lnx.default\extensions\logmeinclient@logmein.com\plugins\npRACtrl.dll
FF - plugin: c:\users\xps-mtj\appdata\roaming\mozilla\firefox\profiles\hrj28lnx.default\extensions\technicianconsole@logmeinrescue.com\platform\winnt\plugins\npRescue.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 59904]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\x86\ekrn.exe [2009-5-14 731840]
R2 epfwwfpr;epfwwfpr;c:\windows\system32\drivers\epfwwfpr.sys [2009-5-14 121152]
R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\drivers\OEM02Dev.sys [2007-10-10 266624]
R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\drivers\OEM02Vfx.sys [2007-3-5 12288]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\drivers\usbaapl64.sys [2009-8-28 49152]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x64.sys [2009-6-10 389120]
S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\drivers\vwifimp.sys [2009-7-13 17920]

=============== Created Last 30 ================

2009-10-26 23:43:47 0 d-----w- C:\Scripting
2009-10-26 18:42:20 65536 ----a-w- C:\Telcentris 2009 GSC Support Contact Escalation List .xls
2009-10-22 21:40:20 0 d-----w- C:\Demo Agreements
2009-10-21 22:17:15 3623760 ----a-r- C:\2345-12560-001.sip.ld
2009-10-21 17:33:10 59835 ----a-w- C:\image001.png
2009-10-21 01:09:29 17296 ----a-w- C:\TelCentris - SIP Trunk Provisioning.xlsx
2009-10-15 05:40:34 311808 ----a-w- c:\windows\system32\msv1_0.dll
2009-10-15 05:40:34 257024 ----a-w- c:\windows\syswow64\msv1_0.dll
2009-10-15 05:39:58 0 d-----w- c:\windows\PCHEALTH
2009-10-15 04:23:21 46592 ----a-w- c:\windows\system32\msasn1.dll
2009-10-15 04:23:21 34816 ----a-w- c:\windows\syswow64\msasn1.dll
2009-10-15 04:23:11 5958656 ----a-w- c:\windows\syswow64\mshtml.dll
2009-10-15 04:23:10 64512 ----a-w- c:\windows\syswow64\msfeedsbs.dll
2009-10-14 22:22:54 0 d-----w- c:\users\xps-mtj\appdata\roaming\tmp
2009-10-14 22:22:54 0 d-----w- c:\users\xps-mtj\appdata\roaming\Reallusion
2009-10-14 21:55:15 74 --sh--r- c:\windows\CT4CET.bin
2009-10-14 21:54:53 0 d-----w- c:\program files (x86)\common files\Reallusion
2009-10-14 21:54:28 5627904 ----a-w- c:\windows\syswow64\LiveCamVirtual.ocx
2009-10-14 21:53:51 499712 ------w- c:\windows\syswow64\msvcp71.dll
2009-10-14 21:53:51 348160 ------w- c:\windows\syswow64\msvcr71.dll
2009-10-14 21:53:51 1060864 ------w- c:\windows\syswow64\MFC71.DLL
2009-10-14 21:53:45 0 d-----w- c:\program files (x86)\Creative Live! Cam
2009-10-14 21:53:23 0 d-----w- c:\program files (x86)\Dell
2009-10-14 21:53:16 0 d-----w- c:\program files (x86)\Creative
2009-10-13 23:43:37 26524743 ----a-r- C:\2345-17960-001.sip.ld
2009-10-09 23:41:34 107656 ----a-w- C:\authcodewsilence.wav
2009-10-09 22:59:09 63962 ----a-w- C:\authcodewsilence.mp3
2009-10-07 18:58:08 0 d-----w- c:\windows\syswow64\AGEIA
2009-10-07 18:54:55 0 d-----w- C:\NVIDIA
2009-10-07 07:12:37 4728141 ----a-w- C:\Telecommunications-Technologies-Reference.pdf
2009-10-07 00:20:57 0 d-----w- c:\users\xps-mtj\appdata\roaming\Malwarebytes
2009-10-07 00:20:51 22104 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-07 00:20:51 0 d-----w- c:\programdata\Malwarebytes
2009-10-07 00:20:51 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2009-10-06 23:57:33 0 d-----w- c:\programdata\SecTaskMan
2009-10-06 23:12:08 0 d-----w- c:\programdata\Google
2009-10-06 22:30:13 149280 ----a-w- c:\windows\syswow64\javaws.exe
2009-10-06 22:30:13 145184 ----a-w- c:\windows\syswow64\javaw.exe
2009-10-06 22:30:13 145184 ----a-w- c:\windows\syswow64\java.exe
2009-10-06 22:20:58 301568 ----a-w- c:\windows\syswow64\cmd.execf
2009-10-06 21:57:30 0 d-----w- c:\program files (x86)\Trend Micro
2009-10-04 08:36:00 108032 ----a-w- c:\windows\system32\E_ILMEEA.DLL
2009-10-04 08:35:59 81408 ----a-w- c:\windows\system32\E_IBCBEEA.DLL
2009-10-04 08:35:44 0 d-----w- c:\programdata\EPSON
2009-10-04 04:39:50 47582 ----a-w- C:\404.jpg
2009-10-02 17:47:53 238960 ------w- c:\windows\system32\MpSigStub.exe
2009-10-01 17:42:20 7704 ----a-w- C:\unauthcall.pcap
2009-09-29 18:21:31 21023 ----a-w- C:\upness.jpg
2009-09-28 21:40:56 206848 ----a-w- C:\DIDs Aremove.xls
2009-09-28 21:32:09 2318569 ----a-w- C:\DID_Numbers11.xls
2009-09-28 21:22:37 2103435 ----a-w- C:\DID_Numbers2.xls

==================== Find3M ====================

2009-10-23 22:42:05 69540 ----a-w- c:\program files\ccback.pdf
2009-10-23 22:41:51 225050 ----a-w- c:\program files\authdoc.pdf
2009-10-23 17:21:20 93316 ----a-w- c:\program files\mjpriv_2310200909260500.pdf
2009-10-07 17:01:15 149287 ----a-w- c:\programdata\nvModes.dat
2009-10-02 04:32:07 982600 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2009-09-14 07:40:08 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2009-09-10 18:21:44 8520 ----a-w- c:\windows\syswow64\ractrlkeyhook.dll
2009-09-03 07:36:39 1975296 ----a-w- c:\windows\system32\CertEnroll.dll
2009-09-03 07:04:15 1320960 ----a-w- c:\windows\syswow64\CertEnroll.dll
2009-08-29 07:45:05 12625920 ----a-w- c:\windows\system32\wmploc.DLL
2009-08-29 06:59:32 11406336 ----a-w- c:\windows\syswow64\wmp.dll
2009-08-29 06:54:52 12625408 ----a-w- c:\windows\syswow64\wmploc.DLL
2009-08-29 02:42:52 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-08-21 20:17:58 541216 ----a-w- c:\windows\system32\nvuninst.exe
2009-08-19 20:35:00 991744 ----a-w- c:\windows\syswow64\nvapi.dll
2009-08-18 06:33:52 1193832 ----a-w- c:\windows\syswow64\FM20.DLL
2009-08-12 03:05:37 22840 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-06 16:54:17 4332032 ----a-w- c:\windows\syswow64\PSP MixBass2.dll
2009-08-03 23:51:34 88374330 ----a-w- C:\Cisco-config-assistant-win-k9-2_0-en.exe
2009-08-03 23:18:21 1017525 ----a-w- C:\P0S3-07-5-00.zip
2009-08-03 22:39:14 676 ----a-w- C:\SIPmacaddress.zip
2009-08-03 22:38:57 2272 ----a-w- C:\SIPDefault.zip
2009-08-03 22:32:52 685624 ----a-w- C:\P0S3-8-12-00.zip
2009-08-03 06:17:37 2868224 ----a-w- c:\windows\explorer.exe
2009-08-03 05:35:50 2613248 ----a-w- c:\windows\syswow64\explorer.exe
2009-07-30 20:51:42 148480 ----a-w- c:\windows\system32\t2embed.dll
2009-07-30 20:51:38 100864 ----a-w- c:\windows\system32\fontsub.dll
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 05:37:38 31548 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 05:37:38 291294 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:54:24 174 --sha-w- c:\program files\desktop.ini
2009-07-14 04:54:24 174 --sha-w- c:\program files (x86)\desktop.ini
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 01:00:34 291294 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 01:00:32 31548 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 20:44:08 9633792 --sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\history\history.ie5\index.dat
2009-07-14 04:55:03 32768 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat
2009-07-14 04:55:03 16384 --sha-w- c:\windows\syswow64\config\systemprofile\appdata\roaming\microsoft\windows\cookies\index.dat
2009-07-14 01:39:53 398848 --sha-w- c:\windows\winsxs\amd64_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_4d4d1f2f696639a2\WinMail.exe
2009-07-14 01:14:45 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 10:33:22.17 ===============

Attached Files



#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:25 AM

Posted 28 October 2009 - 04:06 PM

Hello.

This may not be malware related.

RR didn't work as you know since you are using 64bit.

That process is legitimate. Regarding some information on it: http://www.pcpitstop.com/libraries/process...DFHost.exe.html

It's using a lot of resources since it's running at the background. This process should not be deleted. We'll see if it's caused by malware.

Update and Scan with MalwareBytes Anti-Malware
  • Launch Malwarebytes' Anti-Malware
  • Go to the Update tab
  • Select Check for Update and let MBAM download and install any available updates.
  • After the update is complete go to the Scanner tab.
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


Run Scan with Kaspersky

Please do a scan with Kaspersky Online Scanner. Please note: Kaspersky requires Java Runtime Environment (JRE) be installed before scanning for malware, as ActiveX is no longer being used.)

If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Open the Kaspersky WebScanner
    page.
  • Click on the Posted Image button on the main page.
  • The program will launch and fill in the Information section on the left.
  • Read the "Requirements and Limitations" then press the Posted Image button.
  • The program will begin downloading the latest program and definition files. It may take a while so please be patient and let it finish.
  • Once the files have been downloaded, click on the Posted Image ...button.
    In the scan settings make sure the following are selected:
    • Detect malicious programs of the following categories:
      Viruses, Worms, Trojan Horses, Rootkits
      Spyware, Adware, Dialers and other potentially dangerous programs
    • Scan compound files (doesn't apply to the File scan area):
      Archives
      Mail databases
      By default the above items should already be checked.
    • Click the Posted Image button, if you made any changes.
  • Now under the Scan section on the left:

    Select My Computer
  • The program will now start and scan your system. This will run for a while, be patient and let it finish.
  • Once the scan is complete, click on View scan report
  • Now, click on the Save Report as button.
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
You can refer to this animation by sundavis if needed.

Take a new DDS run as well and post back with both DDS and Attach logs in your next reply.

~Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#6 Pr0metheus

Pr0metheus
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 28 October 2009 - 04:54 PM

Malwarebytes did not find anything, and the Kaspersky scanner is giving me the following error:

Update has failed. Program has failed to start. Close the Kaspersky Online Scanner 7.0 window and open it again to install the program.

You must be online to update the Kaspersky Online Scanner 7 database. With the latest database updates, you can find new viruses and other threats. Please go online to use Kaspersky Online Scanner 7. [ERROR: Invalid file signature]

I tried running it in firefox, and IE and Opera (in admin mode for the last two, but UAC is off).

#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:25 AM

Posted 28 October 2009 - 05:15 PM

Try ESET Online scan...

Run ESET Online Scan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image
You can refer to this animation by neomage if needed.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 Pr0metheus

Pr0metheus
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 28 October 2009 - 05:24 PM

I'll run the ESET scan, but my computer has their full licensed version if that's better (NOD32). I'll run them both right now.

Thanks,

-Matt Johnson

#9 Pr0metheus

Pr0metheus
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:11:25 PM

Posted 28 October 2009 - 10:16 PM

Both of them came up with nothing. Perhaps I'm just being a PC hypochondriac....

#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:25 AM

Posted 30 October 2009 - 03:00 PM

Sorry for the delay.

Doesn't seem malware related. Take a new DDS run and post the log in your next reply. Any problems left?

~EB
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:25 AM

Posted 04 November 2009 - 12:31 PM

Hello.

Since the problem appears to be resolved, this topic is now Closed.
If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.

This applies only to the original topic starter

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users