Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I cannot remove Antivirus Soft Malware


  • This topic is locked This topic is locked
2 replies to this topic

#1 P.G.

P.G.

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:47 AM

Posted 15 February 2010 - 04:44 PM

Hello

Yesterday evening I found myself infected with Antivirus Soft. After searching Google for a while, I stumbled upon this website and a guide to remove it. After following the steps thoroughly and even downloading and using the suggested Malware program, Antivirus Soft is still active and is even acting more aggressive on my computer. I attempted to restart the process with the rkill program only to see that it no longer works. That's when I came here.

Following the Preparation guide I have run into an issue as well. Many of the checkboxes shown are unselectable and grayed-out. I am running this all in Safe-Mode (with networking) and I'm not certain if that's the cause. I cannot use the program outside of Safe-Mode due to Antivirus Soft closing it.

That being said, when I complete my GMER log it tells me,

NO SYSTEM MODIFICATION HAS BEEN FOUND

I am very confused as to what my next step is.. and I hope that you all are able to assist me given that a GMER log is not possible to create..

I do not know if this is relevant, but I picked up this Malware from the website mangafox.com.

In advance, thank you very much for the assistance. This is turning out to be a very stressful event for me so I cannot express what it mean to find this website!


Here is the requested DDS log to be posted

DDS (Ver_09-12-01.01) - NTFSX64 NETWORK
Run by Siamak Kuntz at 13:07:24.42 on Mon 02/15/2010
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1033.18.3998.3294 [GMT -8:00]

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Siamak Kuntz\Downloads\Defogger(2).exe
C:\Users\Siamak Kuntz\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~2\yahoo!\companion\installs\cpn\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~2\yahoo!\companion\installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files (x86)\java\jre1.6.0_07\bin\ssv.dll
BHO: Microsoft Live Search Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files (x86)\msn\toolbar\3.0.0541.0\msneshellx.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~2\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Microsoft Live Search Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files (x86)\msn\toolbar\3.0.0541.0\msneshellx.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~2\yahoo!\companion\installs\cpn\yt.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [LightScribe Control Panel] c:\program files (x86)\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [HPAdvisor] c:\program files (x86)\hewlett-packard\hp advisor\HPAdvisor.exe autorun=AUTORUN
uRun: [Messenger (Yahoo!)] "c:\program files (x86)\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [BitTorrent DNA] "c:\users\siamak kuntz\program files (x86)\dna\btdna.exe"
uRun: [Steam] "c:\program files (x86)\steam\Steam.exe" -silent
uRun: [drmjwuwx] c:\users\siamak kuntz\appdata\local\xbwgoq\gqyysftav.exe
mRun: [QPService] "c:\program files (x86)\hp\quickplay\QPService.exe"
mRun: [UpdateLBPShortCut] "c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5"
mRun: [UpdatePSTShortCut] "c:\program files (x86)\cyberlink\dvd suite\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\dvd suite" updatewithcreateonce "software\cyberlink\PowerStarter"
mRun: [UCam_Menu] "c:\program files (x86)\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\youcam" updatewithcreateonce "software\cyberlink\youcam\2.0"
mRun: [QlbCtrl.exe] "c:\program files (x86)\hewlett-packard\hp quick launch buttons\QlbCtrl.exe" /Start
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [UpdateP2GoShortCut] "c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0"
mRun: [UpdatePDIRShortCut] "c:\program files (x86)\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0"
mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre1.6.0_07\bin\jusched.exe"
mRun: [HP Health Check Scheduler] c:\program files (x86)\hewlett-packard\hp health check\HPHC_Scheduler.exe
mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe
mRun: [hpWirelessAssistant] c:\program files (x86)\hewlett-packard\hp wireless assistant\HPWAMain.exe
mRun: [QuickTime Task] "c:\program files (x86)\quicktime\QTTask.exe" -atboottime
mRun: [TrojanScanner] "c:\program files (x86)\trojan remover\Trjscan.exe" /boot
StartupFolder: c:\progra~3\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files (x86)\common files\adobe\calibration\Adobe Gamma Loader.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~2\micros~2\office12\EXCEL.EXE/3000
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~2\java\jre16~1.0_0\bin\ssv.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files (x86)\common files\lightscribe\LSRunOnce.exe"
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
mRun-x64: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe
mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide

================= FIREFOX ===================

FF - ProfilePath - c:\users\siamak~1\appdata\roaming\mozilla\firefox\profiles\lr6nad45.default\
FF - component: c:\users\siamak kuntz\appdata\roaming\mozilla\firefox\profiles\lr6nad45.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll
FF - plugin: c:\users\siamak kuntz\program files (x86)\dna\plugins\npbtdna.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - truec:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

S2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-1-20 27648]
S2 Norton Internet Security;Norton Internet Security;"c:\program files (x86)\norton internet security\engine\16.0.0.125\ccsvchst.exe" /s "norton internet security" /m "c:\program files (x86)\norton internet security\engine\16.0.0.125\dimaster.dll" /prefetch:1 --> c:\program files (x86)\norton internet security\engine\16.0.0.125\ccSvcHst.exe [?]
S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files (x86)\sminst\BLService.exe [2009-4-20 365952]
S3 CAXHWAZL;CAXHWAZL;c:\windows\system32\drivers\CAXHWAZL.sys [2007-10-31 293376]
S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-9-5 93184]
S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2009-4-20 193840]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-6-29 126976]
S3 NETw3v64;Intel® PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\drivers\NETw3v64.sys [2008-1-20 3154432]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\gamemon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk60x64.sys [2006-11-2 273408]

=============== Created Last 30 ================

2010-02-15 21:07:05 0 ----a-w- c:\users\siamak kuntz\defogger_reenable
2010-02-15 11:56:55 0 d-----w- c:\users\siamak~1\appdata\roaming\Malwarebytes
2010-02-15 11:56:49 22104 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-15 11:56:49 0 d-----w- c:\programdata\Malwarebytes
2010-02-15 11:56:49 0 d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2010-02-15 11:03:17 77312 ----a-w- c:\windows\syswow64\ztvunace26.dll
2010-02-15 11:03:17 75264 ----a-w- c:\windows\syswow64\unacev2.dll
2010-02-15 11:03:17 69632 ----a-w- c:\windows\syswow64\ztvcabinet.dll
2010-02-15 11:03:17 162304 ----a-w- c:\windows\syswow64\ztvunrar36.dll
2010-02-15 11:03:17 153088 ----a-w- c:\windows\syswow64\UNRAR3.dll
2010-02-15 11:03:16 0 d-----w- c:\users\siamak~1\appdata\roaming\Simply Super Software
2010-02-15 11:03:16 0 d-----w- c:\programdata\Simply Super Software
2010-02-15 11:03:15 0 d-----w- c:\program files (x86)\Trojan Remover
2010-02-13 09:48:03 0 d-----w- c:\program files (x86)\common files\Steam
2010-02-13 09:47:59 0 d-----w- c:\program files (x86)\Steam
2010-01-23 05:49:14 0 d-----w- c:\windows\PCHEALTH
2010-01-23 05:47:22 0 d-----w- c:\program files\Microsoft Office
2010-01-23 04:48:59 0 d-----w- c:\users\siamak~1\appdata\roaming\GetRightToGo

==================== Find3M ====================

2010-01-14 19:12:06 212352 ------w- c:\windows\system32\MpSigStub.exe
2009-12-28 12:45:26 13824 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:44:32 1570816 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:42:34 25600 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:42:32 38400 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:42:32 143360 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:42:28 15872 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:41:43 93184 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:41:22 54272 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:39:08 76800 ----a-w- c:\windows\system32\avicap32.dll
2009-12-28 12:39:08 108544 ----a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:35:50 11776 ----a-w- c:\windows\syswow64\tsbyuv.dll
2009-12-28 12:35:00 1314816 ----a-w- c:\windows\syswow64\quartz.dll
2009-12-28 12:32:34 22528 ----a-w- c:\windows\syswow64\msyuv.dll
2009-12-28 12:32:32 31744 ----a-w- c:\windows\syswow64\msvidc32.dll
2009-12-28 12:32:32 123904 ----a-w- c:\windows\syswow64\msvfw32.dll
2009-12-28 12:32:25 13312 ----a-w- c:\windows\syswow64\msrle32.dll
2009-12-28 12:31:22 82944 ----a-w- c:\windows\syswow64\mciavi32.dll
2009-12-28 12:31:01 50176 ----a-w- c:\windows\syswow64\iyuv_32.dll
2009-12-28 12:28:43 91136 ----a-w- c:\windows\syswow64\avifil32.dll
2009-12-28 12:28:43 65024 ----a-w- c:\windows\syswow64\avicap32.dll
2009-12-18 13:12:34 1032704 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 13:08:01 86528 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 13:05:50 833024 ----a-w- c:\windows\syswow64\wininet.dll
2009-12-18 13:05:36 1174528 ----a-w- c:\windows\syswow64\urlmon.dll
2009-12-18 13:04:20 146432 ----a-w- c:\windows\syswow64\occache.dll
2009-12-18 13:03:13 671232 ----a-w- c:\windows\syswow64\mstime.dll
2009-12-18 13:02:57 3585024 ----a-w- c:\windows\syswow64\mshtml.dll
2009-12-18 13:02:56 458240 ----a-w- c:\windows\syswow64\msfeeds.dll
2009-12-18 13:02:11 28160 ----a-w- c:\windows\syswow64\jsproxy.dll
2009-12-18 13:01:57 6069248 ----a-w- c:\windows\syswow64\ieframe.dll
2009-12-18 13:01:57 270848 ----a-w- c:\windows\syswow64\iertutil.dll
2009-12-18 13:01:57 193024 ----a-w- c:\windows\syswow64\iepeers.dll
2009-12-18 13:01:56 78336 ----a-w- c:\windows\syswow64\ieencode.dll
2009-12-18 13:01:56 389120 ----a-w- c:\windows\syswow64\iedkcs32.dll
2009-12-18 13:01:56 380928 ----a-w- c:\windows\syswow64\ieapfltr.dll
2009-12-18 13:01:56 230400 ----a-w- c:\windows\syswow64\ieaksie.dll
2009-12-18 10:35:23 32768 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-18 10:14:30 26624 ----a-w- c:\windows\syswow64\ieUnatt.exe
2009-12-08 20:59:29 4691032 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-19 18:31:37 86016 ----a-w- c:\windows\inf\infstrng.dat
2009-08-19 18:31:37 51200 ----a-w- c:\windows\inf\infpub.dat
2009-08-19 18:31:34 86016 ----a-w- c:\windows\inf\infstor.dat
2009-04-20 23:44:09 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-01-21 03:21:59 174 --sha-w- c:\program files\desktop.ini
2008-01-21 03:21:59 174 --sha-w- c:\program files (x86)\desktop.ini
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 15:14:56 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 15:14:56 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 10:52:12 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 10:52:10 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-04-20 23:44:08 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

============= FINISH: 13:09:11.14 ===============

Attached Files


Edited by P.G., 15 February 2010 - 04:52 PM.


BC AdBot (Login to Remove)

 


#2 P.G.

P.G.
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:10:47 AM

Posted 15 February 2010 - 07:04 PM

Hello again

I've read the rules on several times over and I'm aware that double posting drops my priority and that the Staff members here specifically look for 0 post threads, but I'm not doing this for a b.u.m.p. I'm writing because my issue with Antivirus Soft has been resolved. In combination with the guide posted by this website found a working solution when I added a manual removal written on another FAQ. ^^; Yes, I read to be patient and that the Moderators would get to me, but I just couldn't help myself.


smile.gif Please feel free to lock or delete this thread. Thank you for your time and the thoroughly written guides on bleepingcomputer.com

#3 aommaster

aommaster

    I !<3 malware


  • Malware Response Team
  • 5,294 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Dubai
  • Local time:07:47 PM

Posted 15 February 2010 - 08:19 PM

Hello, P.G..
Glad to know the guides here at BC helped smile.gif

Since your problem appears to be resolved, this thread will now be closed. If you need this topic reopened, please send me a PM with the address of this thread. If you should have a new issue, please start a new topic. This applies only to the original topic starter. Everyone else please begin a New Topic.

My website: http://aommaster.com
unite_blue.png
Please do not send me PM's requesting for help. The forums are there for a reason : )
If I am helping you and do not respond to your thread for 48 hours, please send me a PM





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users