attaching first. not writing anything, for fear of comp crash. would write in a reply to this post, from another comp
dds report looks like this:
MZ ÿÿ ¸ @ € º ´ Í!¸LÍ!This program cannot be run in DOS mode.$ PE L +I à 2 n h @ 0 ² Ô ´ .code è PEC2FO à.rsrc ê à ¸¨$R Pdÿ5 d‰% 3À‰PECompact2 VÒËK¬ÇÑžç†ì¸oTN
Ã<Ð_À@ƒt½•‰HŽÓw,KÚÄíØ{²³Y®wCÈd•Aýœ§Ej]…vWªbÚ°Í.çÏ“cF §(C&{Ÿ™;Ùçy U2ø)[)g*æ®u¼¬ÅŠ¡0«äœ¬Mõ•呎sÿ¼
PKÚŸ}C’b{/¬p=øžÏ_¯ýI«ÐÅѶ_÷º²À'Ô Ö`ãVS™JYg«ØÇĹ¡¹ç|_KwžÈD;6àИ•¢ož†OªñGÞSÌ·c7äK €ÓgB-‘6XfvâôžÑ-§pÄǼšŽš]úPméÚUuó ¤;âê’Çïÿ&ƲoÉÉYú-00
+—=ïC<%
PÀ@3²©8Õê:sm·•ÙØ÷—¼X¿ƒ—•Ý:ºTï} ØÖ† Ø‘Gþ›ÇR¨¦>mý£‘¯§-Æ.Ð:¤ºäùåä§2 +]>hÌD¹Ò …t;èaPMòUN·2=~xlûð@µ°]êl³æz¼ŒMô›X¸•x;æá»c$ã÷¯'iNVmŽ=U_
͉ä({|¼/è$Ø×ÉÍOrI…?k"<ß5]›””0»gNù±Øžü@ÏÔß/‹¾+2jJÚn”é
ƒÓî-~¾¯â Z:í-vQUU5wð_WÔµ±lŠôw"íÇtUð”ÒÅ~Ý6 ¨Úˆ%·S]³XÀÑ‘‚al(¾åeìTd¬k»X‹Þ>‘¿‹D™Lì‚@ѸˆaYNÛ‹!¡'¾nú*ÑÁªFhaÆT~À·/¸EƱú!âÉ*¡ Z´$}”«0N:²·º™+0o%ÎÇCM¾EZþÉÄŒØ0ÝFØÏ°OhÏ‘¬¾ûÀ2[´u5ÅÕÈN¼·5ñD´¸hVR»k¢§*£ò&-›ìd’ÍMyÙ¯ƒI±²« ‚‹>"io_o1DÇ¢øˆ^.n+(!ó³2ì:dÆ–5V“Øíl
¤Ò‡H%‹kÄQ«ˆV©³®+ã
Åaèþ:˜ØÝv™š—'vã‘Aé.q°%iŸ¯¹—8ÐaÙvZÑ\‡‹G¨¾¦>ZW±”¥ŸÖŒ{èuùë¼xpÞÐÛï09\ð@Fð÷\
;®ê[@eáem² ⨴0&ër˜Z%aÄ#â®'y7º†¼Ï$2< ÿO©Ý,Íîa#ÃZuEnFî
,±ÒOéÅT‹¶4K¥d–ãóÑ'{‚ôõÃ80Œbô‚Í O•ÜW DËô¥øMgAìJfƒ0`>Ó(ýd»év¤n [Íd?QyT¾é¬
ÓIjÙí¨wn•ÁnšþÎÞZˆÍ…rmú‡¹3Ð<Æ“BJ½žŸ%[*3€ë°+W=²t~J.gCËU¨"~WȆ²âûBxP¶šfgO±:þåUN¹èÝã|ˆÃÛÁR§iˆô.?Ë_ÐÑÇJå—ó᱇Å/{M_ÿçÅ:z§Yºª6¨Æ E
ž"0k^äΜ'‰Ž’_€ª
q
XÏRJÂÆ aH— !dHS
`ÝL¶—˜\á¤W‚„8„LÔSd&Cî``ÃâÁCÀLe]`»Í¨Í
à ×JÌ9À¨¥ˆíw©ÒJ!˜'S—›!¢ p†à5$ì™D‡Xt.oŸè—ãt¿k璘T€ÿ¬$6¿§m’‹^&£L2—¤‘£èþPü-ªtcqÖFU~´Q >5Xh.Ó›—=–ÚQÚ?+¦ò=Vp‚kŒz¿OµU/4ËfŽˆ^ÁklFjdäÞ½C€´?â¼%â’æ´¯N!Z2y—ZÎ^q\<\Q®MiÚq]Ó4zû?âŒÃ¾˜ØT¹ÄˆÇõuзËUjò>'ï~wbýGò†·–Mª¬Žø›=#›B'AÝs»ÔÏÃ@ÿVîý?ÔVÖ-æ7á×Çqai¿…sgßóCÞ)]4{O§S[ÜK…ZÔi$\û‚ÏxÍ¥·žÎ’ŠÔ{â1‰öæêqµ@Qr:… ê«99Kx†^kØ?¤2ÀuK¾ÏñyÓ|w]†ªÝ
qløß¼¯/wb²
FÎÎ:¿ô®<õ²!WÄI‡Þq2©¡çÛK[)@7EOªÔ[ÃâsœâŸ$îÍÀÕÿ!Dô°ŸkhF+jÆ$Ѐ‘“/òèÆãS¬dMpU´Œl"¿Ìü7ܪTqA%¤,c0Ú
5ýíaw¡×V~.ýÇ‹‡ŸËêWYA9²a0°
¶|«9\Hµ{t´uè*GÕ¶ÔŒì/³´ñ#Œ©(ÒìZš€÷ G/WB‰º úSuÑVCQÛ "„½ÞŽéT?-¨ü-yã%´g?äžÀx™:¡›TôÝe——¾ÀD²ÞÑPŽïa §yqm90èRC±ÁÛ‡ò`˜w¦äYZ³€»ëéÿŽktA;‘CÈÏÏì+ú÷Øz‘|{·°Wˆ/ÈÖµ8nÖ`ßë!¥xŠþÕ.Œ[¶vï\’È«A)²ç ß=Á9Ð'¹¹,¡÷†-Áƒ¼î÷”Ôär‰‡ bз9=ÏRv«!@ íîv.71Fn—Fã‡Z®Ñõ$ú’ɳ!Óûv9_t‘ ¼fÝmí*âf¡BÇI&¡E»vK$½…‡$¹
›?žòÞ[é’%ü}Å÷y@½BÉ·Iãò÷¡b~ìBì=ÞÑØ& VÃÃߣ~!¹dª>5A
4è¸Xw][èF3Îü¬üË{!øIRš{´pqÞð(~Z«‘pÉ÷è5¬HÝ1örl•1£ê‰ô^GÓäçM[ƒƒ‰¸Ý]

WÉ“·Z™_¦Éÿ¦ÅRmuø”ðI4&Ço÷~¸Â€ëQ,ƒ“#]8ÅóçÕYÀ©û}ìdêÞF½Í?ë÷¯~œ»^½ØŠé…^-y6)lˆÅMó:ŠýÜ»œ‡m ½Šÿ/BçÞ·ÛÙ-_§ò†‚1mÚdÑ=Qu4¯©«_fxAî€w;GŸš/ñÒˆ¼;ðt[êS>ÛÂ˃ùœÛê[Ö}èõZÏ6$ŽÚÿª'i|¾MÂ6ÃjŽMãБä©V~it÷þ}$6o æBvãû¡'ìñ=V[˜€êe+ú¥ª7f›“I…Z.áwHåx_: Qó
‘î|.ÉÚØ·-æ[QI'jèX“•_K൵B\ÖÅQ½Š¾Ô'7,$äÐäXH8—]Œ×ZO¥Ö2abìs‘Rzåè>ûØÞß?Ãñxº_×€ ËÈw¹Ä¡cšE3_ƒ¨GÕ‘
ºH¤…¿qÖ Õ»“*h3GÝŸw\¯êè½Kl?`–4‘b=k¸hÜ|’Iûs‰éŠÂ¾|ÍþU®Ç‹ñ¾\–æW4f
^‚¼ F
&XÃ[\#H¶_×ß9õ\1‘h^ôþƒª?Ýß €Ûþ{«–½C§Ýv ƒHyh“ô£4yD¥î¼£ÝÅeåc]o#+Ôf‹m*¯\뉶I0P&²Œœ°L×Cp!Ýüš¶Ðé×ÚÆÚó™‰ÎØ M¶ û¿~MWQ9[LŠ Zÿ/¶‡ØN#÷¾cÚ3ò`¾Q¿×>ħ®³:4e¿¨ç©$zqû–Íø¤C‡
°=î4S½ÍªKZh€}¡î
ÎH™~":Äñ ÍP»1X³X?c¶b¥¨…–Ä’‰l_ý½ëHÞ½)¸ýÍ÷[bA¹7wn>l˜k™´þNOƼ—2™›‚®Ï\m|Ñžš@.B±sCÇ]øÚØØR†ÕQ3x {êÒCZ†l¸)Wþ^™ WR†ÒÉÉ>STxq¦%°XÞ¤3zû(1Ü €H€ú1ÏÞ„6vzX»½Œ
Xô0õ
s—É€jV™Ï¨¨[U»®UÕ67ˆ”“VíŠFÓÓ`Æ‘¦yžAsµu–æ:¤àê;<
@õšj×p-9ô¿žÈƒ×RŸÃÌaû•Ùœ1íêøA6E`NñàÉÆ¬'`L•ÌöøûÚðèºqáäÆC\±BR ¼N+dýs¼©÷¥FŠüœ
H=¬xÚüZðBµf‚}‰ØÎT«`ÁØÿëyókÚ.*ìO10‘¤hHI1âŒ!Ì·VÌ#m”_LxY)
“()TÝÕ˜ù£Læ1ü’N°ô”Kæz•¥ÎIÕÜY^eªÖîØ‡²ãa¶6ìÂ"µnT"[?*ׇ»ÚsÖ+Då|¦´ÆÓ)ÀˆjoáF§;ù_
3ZëRoˆˆƒ8ˆó þÿ»?ÿÿÿÿÿó ÿˆˆ»ˆˆˆˆˆó oþÿÿÿÿÿˆˆÿó ˆˆƒ8ˆŒÌÇó ÿþÿ»?ÿÿÌÿó oˆˆ»8ˆˆÌxó þÿ»?ÿÿÌÿó ÿˆˆ»8ˆˆÌxó oþÿ»?ÿüÌÿó ˆˆ»ˆˆˆ‡xó ÿþÿÿÿÿÿÌÿó oÿÿÿÿÿÿÌÿÿó ÿÿÿÿÿÿÿÿÿó ÿÿÿÿÿÿÿÿÿÿó ÿÿÿÿÿÿÿÿø ø ð è è ð è è ð è è ð è è ð è è ð è è ð è è ð è è ð ø ø ÿÿÿÿ è
+(á||¾’” áHé``ƒì0‹D$4HSUV¾¿/ŒÞÓãxW=xçÖÓâ‰Aȸ78Ðà3í+rÞÖ6‰|$ l
Æ@Ë>\¾8¾T³<#ãtã" (û,ù ‹ó«_LÁH¶q€QÁædò(‰ƒõÌÈÿ̉S9À˜Tw_^ ]3À[ƒÄ0ÂPÿå»ÑfÉ#~«àÍÁá˪‚‘0=Ä
sjF§æàžóAQ‹
'ØçëЯÙ;uó*ƒîp¿’+ùÁï®e‰9h¬D¹-ƒ*P Ãã
Ǧ„Ÿ7ë&ßî!¦éGD`;T‚jþÂùÓBëÝ+Ãó‹ÙÁÂàˉ
M5‘ÈòÂŒ¯dîÐ*ÁêäÑ;òsLÄ‘0ºLèÑÐ.èuÒs
”)DT׬H 3Ò!̜™‰,?‚(ÈHäJƒ0âEéþ«ß•H+ÂOòIy)‰n#Œ#‚ñC‰\,Æ0„ÈÁéŒ ;ñ†x½US»Š*ÚÌuU≜’).§éӇϗ–ÁãùW&å"ì…é$qº) èäOäôƒÒ
…É„YÕ¿‘FçÂJ± ÕHÈ+AŠ:œ9ÿ‰ ¾¹’éoPƒçõX%˜
éUäõÁýñýFÑ,IÑB+0ýDrò2„`ž‰)¡Z…z”D%ë}žT#`{+

ãÖà\L 3í®üHé‚3D!úת\¸QR]È*\.y†3¼7(½1
dÂë!œaψ.™Gö-ÝëÅ0»"Õ½ƒ™yX7.™Ý
ëns^\¢,0)Áu¤‹”
€úÓç+ï&݃‰ %ÍĶyîCû|õ·ž Õ œÀ«¯¤VmÐs,µ›×!Ñr³áƒíÌuªêêx@Húav¸ÚPÜ~?Ñù’åûÍ,`·0}Ó?å‹LAÉ gм
ëE—H
˜’Äš. Ñèí;ðrÝ6†Â@éÛ¤Ñ |ˆ‚“JÉå$~0ë4v¥àV€ø‡lª\„ÑfdƒP0‰ îÅý(.¥øÿäM¹ ƒÃ;éwH<+ý¢!ŠXEìKˆ)AG…Ûf]ú‚èŸrÞœ”ÓŸë¹%¸IË̬þìOYW®x4ÐG™¹ K÷ù¾˜ì,j8h3<À™÷þ×TìºÉp9} ‹CÂ=r\'RjÿЋ7Ä·˜NéÔQVrRüèƒÇ WÚR´ÛŸ4Š)÷ÚŒK°€ƒ>\UŸÑ_”ÆžD™7ÂíPµ¤Á@Iœù )AÀÁÄ£†ßÚ
ˆ³Ø£¤Š…!4OK5cË’
H˜ ö¨4dþˆ]Ø4óh* ×|!y0‘'FU„ÂëæƒŽßè§À´p"@š8@!¯8
‹ÇÔÜ8 „{€SWVUè]íLTµC
‹FüƒÀÇo/ÞgVäv€›ò½1/2«Hƒ{HtÀsD…wö¹#ƒ~F&{@”óòòX#/‘o¦Ñ?˜ÿQèeFß0‹N,‰+Kj@™’QFâ•7!‰…'
VèMö br½…ÀÍ”²Á(@,U’SÙš4-ëOO fQF GÀnt{‹•ªTÍl®
Du©Š:ë-÷cÁW€tàRážÔQ…˜1P?ЉL & ÈAâRÏ?Ò°© –
bj…«ˆÀfH1ë7$Þ%DuCÚ@ðñ÷ÆéÃë+š‰Bˆ%ÂÒ³ò”Ö|Wi78Éÿµ‘3¦;´@FÇ]^_[ÃU´ìÂÙüI»è [ëh?à9ËQÿ“"©‰E¼V…Ý~ÃÓKû·ÁtRû¯ÕÿuüDD3«ZƒÂë䫯¬uůÉЃG¯EÐÍOÁf*MÈ?C½Âð‰ëSô™#])Vèñ\
G>$ÉÀX
fÁèÂÀ†Äh½ÎÎ~¹‚AëÈ^YH¾Ft5;*ª0Å«÷¦aéxýx—QŽ„9ø€4ƒìfvRPè§ÐËbYŽIÁ?W5æ³
åÄA~ú'›P”ÞÍ(Cí±–tMàs˜^b}(KÉøÁÄù,ó¥-ƒá¶Eÿ{ú¤RöÑ¡«ñªlZÎ`;Ú2=42¦Ãu¢Z¢ˆãU"œ€šGÁðQRV#‘r‘Š‘ÖP‰»¦¿.}ì&5nH+È…6*²&^ _2|C`Q»˜ÐHôR²K}\K¨†‹/ÇoQÙì,©È@t2[µFºˆ)36ÿmØëMZaú;}ñu…ùëÚd@øÇ4ÿªƒ›à›+IÇ^rrÚ-@]¤--–@Ë´kùb› ]¤‚9Å\¶Ct$sèC˜Q=NMÎ~…ÿ!z{PWQSèzeHHˆÝøH© ëÅΪmsvb]fä\"Ç E‰ƒk±dЮ!öFÄ‹“KïN@kÒƒôäY…\À09N´ëN"cGëzÉÎ} ±U=…Ò>»Ö1ö
òÇTn'ŠÏظtDRR'©% %œ#œjë‹MÁÖAtÖfóàQ@ã,IÈšZhalo¬M¹9%‹T"»ë¬ˆœÕ®„Qü^o×ó*0+ñ‰´Ðè¤;MfAëó¾6˜kIümÒ„ JE¹@<@H|ƒÇ'¡ÏÁé``áæQevP¶K:ûЍƒö,£ˆÂYˆç¡Ë¥…e‘…Y
K4z/"!§•%!3Oô¯¸Ï„ÓJ”{²¸€F-«ð‹V4+‰¦zeHwŽAp licatèon er=¹ð§;î /uþÜ.Theß
×# È Ì @ À Ä ¸-Rðˆž ‰A‹T$‹RÆéƒÂ+‰Jü3ÀøxV4d ƒÄUSQWVR˜W ‹SR‹èj@h ÿsj ‹K‹ÿÐZ‹øPR‹3‹C ‹‰K ‹C‹‰Kò‹KCPWVÿÑZXC‹øR‹ð‹FüƒÀ+ð‰V‹K‰Nÿ׉…? ‹ð‹KZëh € j Wÿ‹ÆZ^_Y[]ÿà
gmer report:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-17 11:50:46
Windows 6.0.6002 Service Pack 2
Running: gmer.exe; Driver: C:\Users\Kunal\AppData\Local\Temp\pxldqpow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys ZwOpenProcess [0x9E2F5B4C]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys ZwOpenThread [0x9E2F5C3A]
SSDT \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys ZwTerminateProcess [0x9E2F5AB0]
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 9C53DBB8
AttachedDevice \Driver\tdx \Device\Tcp bdftdif.sys
AttachedDevice \Driver\tdx \Device\Udp bdftdif.sys
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Services - GMER 1.0.15 ----
Service system32\drivers\parport.sys (*** hidden *** ) [MANUAL] Parport <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport@EventMessageFile %SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\parport.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\Eventlog\System\Parport@TypesSupported 7
Reg HKLM\SYSTEM\CurrentControlSet\Services\Parport@DisplayName Parallel port driver
Reg HKLM\SYSTEM\CurrentControlSet\Services\Parport@Group Parallel arbitrator
Reg HKLM\SYSTEM\CurrentControlSet\Services\Parport@ImagePath \SystemRoot\system32\drivers\parport.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\Parport@ErrorControl 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\Parport@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\Parport@Type 1
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\System\Parport@EventMessageFile %SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\parport.sys
Reg HKLM\SYSTEM\ControlSet002\Services\Eventlog\System\Parport@TypesSupported 7
Reg HKLM\SYSTEM\ControlSet002\Services\Parport@DisplayName Parallel port driver
Reg HKLM\SYSTEM\ControlSet002\Services\Parport@Group Parallel arbitrator
Reg HKLM\SYSTEM\ControlSet002\Services\Parport@ImagePath \SystemRoot\system32\drivers\parport.sys
Reg HKLM\SYSTEM\ControlSet002\Services\Parport@ErrorControl 1
Reg HKLM\SYSTEM\ControlSet002\Services\Parport@Start 3
Reg HKLM\SYSTEM\ControlSet002\Services\Parport@Type 1
---- EOF - GMER 1.0.15 ----
Hello,
I had initially posted into another forum here: http://www.bleepingcomputer.com/forums/t/302937/rootkit-trojan/
As suggested there, I tried running Defogger (it did the disabling)
However, DDS did not run successfully. Upon clicking it, it directly opens a notepad file titled DDS which is filled with illegible characters and runs into great lengths (I've copy pasted a part of the file in the previous post of this topic)
GMER was able to run, and report is copy pasted in the previous post.
As soon as i connected to the internet, the symptoms mentioned in the previous topic (http://www.bleepingcomputer.com/forums/topic302937.html) re occurred: ie Windows Explorer stops working and then tries to restart. Also, Task Scheduler, Desktop Windows Manager and Bit Defender Agent stop working.
PS - I googled for DDS not running, and came across this http://www.bleepingcomputer.com/forums/t/297865/cant-run-ddsscr-opens-in-notepad/
I also have AutoCAD 2008 installed on this laptop, and I re looked at the DDS file and it is identified as an AutoCAD Script. I dont know if this is causing the error in running DDS, since I have AutoCAD also installed on my desktop and on that the DDS ran fine (The desktop's issues are being looked at separately in this topic: http://www.bleepingcomputer.com/forums/t/302287/multiple-malwares/ )
Thank you for your help,
Regards,
Kunal
Edited by boopme, 17 March 2010 - 12:06 PM.