Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.



  • This topic is locked This topic is locked
2 replies to this topic

#1 me86


  • Members
  • 1 posts
  • Local time:08:36 PM

Posted 23 February 2010 - 04:23 PM

Popups with various warnings about viruses in my computer and asking me 2 buy the new version of this fake antivirus

DDS (Ver_09-12-01.01) - NTFSx86
Run by Veronica at 21:41:13,48 on 22/02/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Home Edition 5.1.2600.3.1252.34.3082.18.1013.283 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Archivos de programa\AVG\AVG9\avgchsvx.exe
C:\Archivos de programa\AVG\AVG9\avgrsx.exe
C:\Archivos de programa\AVG\AVG9\avgcsrvx.exe
C:\Archivos de programa\Archivos comunes\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Archivos de programa\AVG\AVG9\avgwdsvc.exe
C:\Archivos de programa\Bonjour\mDNSResponder.exe
C:\Archivos de programa\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Archivos de programa\Java\jre6\bin\jqs.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Archivos de programa\AVG\AVG9\avgnsx.exe
C:\Archivos de programa\System Control Manager\MSIService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Archivos de programa\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\Archivos de programa\MSI\MSI Q-Face\webtest.exe
C:\Archivos de programa\System Control Manager\MGSysCtrl.exe
C:\Archivos de programa\iTunes\iTunesHelper.exe
C:\Archivos de programa\Java\jre6\bin\jusched.exe
C:\Archivos de programa\ESET\ESET NOD32 Antivirus\egui.exe
C:\Archivos de programa\Windows Live\Messenger\msnmsgr.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\AV\Antivir.exe
C:\Archivos de programa\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Archivos de programa\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Archivos de programa\iPod\bin\iPodService.exe
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Archivos de programa\Mozilla Firefox\firefox.exe
C:\Archivos de programa\AVG\AVG9\avgtray.exe
D:\Mis documentos\Descargas\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.terra.com.pe/
uInternet Connection Wizard,ShellNext = hxxp://www.msi.com.tw/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\archivos de programa\archivos comunes\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\archivos de programa\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Aplicación auxiliar de inicio de sesión: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\archivos de programa\archivos comunes\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: &UpdateCheck.dll: {d34d56e9-b37b-4c37-a854-1ac144592d5c} - c:\windows\system32\UpdateCheck.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\archivos de programa\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\archivos de programa\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe
uRun: [msnmsgr] "c:\archivos de programa\windows live\messenger\msnmsgr.exe" /background
uRun: [MSMSGS] "c:\archivos de programa\messenger\msmsgs.exe" /background
uRun: [ares] "c:\archivos de programa\ares\Ares.exe" -h
uRun: [AV] c:\archivos de programa\av\Antivir.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
mRun: [Q-Face agent] c:\archivos de programa\msi\msi q-face\webtest.exe
mRun: [MGSysCtrl] c:\archivos de programa\system control manager\MGSysCtrl.exe
mRun: [Adobe Reader Speed Launcher] "c:\archivos de programa\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [AdobeCS4ServiceManager] "c:\archivos de programa\archivos comunes\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin
mRun: [AppleSyncNotifier] c:\archivos de programa\archivos comunes\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [QuickTime Task] "c:\archivos de programa\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\archivos de programa\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\archivos de programa\java\jre6\bin\jusched.exe"
mRun: [egui] "c:\archivos de programa\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
mRun: [USBAntiVirus.exe] c:\archivos de programa\usbantivirus\USBAntiVirus.exe -Hide
mRun: [AVG9_TRAY] c:\archiv~1\avg\avg9\avgtray.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\menini~1\progra~1\inicio\blueto~1.lnk - c:\archivos de programa\toshiba\bluetooth toshiba stack\TosBtMng.exe
IE: E&xportar a Microsoft Excel - c:\archiv~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\archivos de programa\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\archiv~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\archiv~1\micros~2\office12\REFIEBAR.DLL
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\veronica\datosd~1\mozilla\firefox\profiles\hlk6v1xn.default\
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\archivos de programa\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-2-14 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-2-14 28424]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-2-14 360584]
R2 avg9wd;AVG Free WatchDog;c:\archivos de programa\avg\avg9\avgwdsvc.exe [2010-2-14 285392]
R2 ekrn;ESET Service;c:\archivos de programa\eset\eset nod32 antivirus\ekrn.exe [2009-11-16 735960]
R2 Micro Star SCM;Micro Star SCM;c:\archivos de programa\system control manager\MSIService.exe [2008-12-20 159744]
R3 MSILiveVirtualCamera;MSI Live Virtual Camera;c:\windows\system32\drivers\MSILiveVirtualCamera.sys [2007-1-29 449408]
R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RTS5121.sys [2008-12-19 156160]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2008-12-19 704384]

=============== Created Last 30 ================

2010-02-23 02:35:24 0 ----a-w- c:\documents and settings\veronica\defogger_reenable
2010-02-23 02:14:23 0 d-----w- c:\docume~1\alluse~1\datosd~1\ReviverSoft
2010-02-14 22:46:56 0 d-----w- c:\docume~1\alluse~1\datosd~1\AVG Security Toolbar
2010-02-14 22:42:47 0 d--h--w- C:\$AVG
2010-02-14 22:42:33 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-14 22:42:33 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-14 22:42:22 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-14 22:42:14 0 d-----w- c:\windows\system32\drivers\Avg
2010-02-14 22:41:56 0 d-----w- c:\docume~1\alluse~1\datosd~1\avg9
2010-02-14 22:00:08 0 d-----w- c:\archivos de programa\USBAntiVirus
2010-02-08 01:46:18 0 d-----w- c:\archivos de programa\ESET
2010-02-02 01:27:12 0 d-----w- c:\archivos de programa\archivos comunes\Uninstall
2010-02-02 01:27:07 625664 ----a-w- c:\windows\system32\UpdateCheck.dll
2010-02-02 01:26:56 0 d-----w- c:\archivos de programa\AV
2010-01-24 23:50:56 664 ----a-w- c:\windows\system32\d3d9caps.dat

==================== Find3M ====================

2010-02-23 01:22:13 2048 --s-a-w- c:\windows\bootstat.dat
2010-02-23 01:22:08 1062526976 --sha-w- C:\hiberfil.sys
2010-02-23 01:22:07 1598029824 --sha-w- C:\pagefile.sys
2010-02-17 05:19:07 3670016 ----a-w- c:\documents and settings\veronica\ntuser.dat
2010-02-15 00:02:26 500092 ----a-w- c:\windows\system32\perfh00A.dat
2010-02-15 00:02:25 87522 ----a-w- c:\windows\system32\perfc00A.dat
2010-02-15 00:02:25 68940 ----a-w- c:\windows\system32\perfc009.dat
2010-02-15 00:02:25 436236 ----a-w- c:\windows\system32\perfh009.dat
2010-02-14 22:42:33 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-02-14 22:42:33 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-02-14 22:42:22 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-02-02 01:27:07 625664 ----a-w- c:\windows\system32\UpdateCheck.dll
2010-01-05 00:17:46 29634504 ----a-w- c:\windows\system32\MRT.exe
2009-12-29 22:04:33 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-12-29 22:04:33 149280 ----a-w- c:\windows\system32\javaws.exe
2009-12-29 22:04:33 145184 ----a-w- c:\windows\system32\javaw.exe
2009-12-29 22:04:33 145184 ----a-w- c:\windows\system32\java.exe
2009-12-21 19:06:30 916480 ----a-w- c:\windows\system32\wininet.dll
2009-12-21 19:06:29 1208832 ----a-w- c:\windows\system32\urlmon.dll
2009-12-21 19:06:28 5942784 ----a-w- c:\windows\system32\mshtml.dll
2009-12-21 19:06:28 206848 ----a-w- c:\windows\system32\occache.dll
2009-12-21 19:06:24 594432 ----a-w- c:\windows\system32\msfeeds.dll
2009-12-21 19:06:24 55296 ----a-w- c:\windows\system32\msfeedsbs.dll
2009-12-21 19:06:23 25600 ----a-w- c:\windows\system32\jsproxy.dll
2009-12-21 19:06:23 1985536 ----a-w- c:\windows\system32\iertutil.dll
2009-12-21 19:06:21 184320 ----a-w- c:\windows\system32\iepeers.dll
2009-12-21 19:06:21 11070464 ----a-w- c:\windows\system32\ieframe.dll
2009-12-21 19:06:17 387584 ----a-w- c:\windows\system32\iedkcs32.dll
2009-12-21 13:19:49 173056 ----a-w- c:\windows\system32\ie4uinit.exe
2009-12-04 02:46:35 2145248 ----a-w- c:\windows\system32\FNTCACHE.DAT

============= FINISH: 21:41:50,81 ===============

Attached Files

BC AdBot (Login to Remove)


#2 Starbuck


    'r Brudiwr

  • Malware Response Team
  • 4,150 posts
  • Gender:Male
  • Location:Midlands, UK
  • Local time:01:36 AM

Posted 25 February 2010 - 12:25 PM

Hi me86 and welcome to Bleeping Computer.

Step 1
Please download Malwarebytes Anti-Malware and save it to your desktop.
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Full Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

Step 2
  • Download OTL to your desktop.
    if you have problems, try this download link:
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check

    Now copy the lines in the codebox below.
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
  • right click in the Custom Scans/Fixes window (under the blue bar) and choose Paste.

  • Click the Run Scan button.

  • Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them with your next reply.

In your next reply, please submit:
MBAM scan report
Both reports from OTL



#3 Starbuck


    'r Brudiwr

  • Malware Response Team
  • 4,150 posts
  • Gender:Male
  • Location:Midlands, UK
  • Local time:01:36 AM

Posted 15 March 2010 - 07:59 PM

Due to the lack of feedback, this Topic will now be closed.

If you need this topic reopened, please request this by sending one of the Moderating team or an Administrator
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users