Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Unknown Disables & Spreads


  • This topic is locked This topic is locked
2 replies to this topic

#1 rumble_my_heart

rumble_my_heart

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:59 PM

Posted 19 April 2010 - 11:06 AM

I recently was getting my laptop up and running to a AMAZING condition. I had installed NOD32 and was running cleanmem and had uninstalled bitdefender due to a warning of virus files. I was looking for a program that i could use to save a record of all the program keys for my software since i was getting ready to backup the system and clean install. Im not sure if it was one of the files in the torrent that i had clicked on or if it was one of the rar files that was on a jump drive. webroot internet security 2010. Either way the damn computer started slowing down big time and I knew there was something wrong. I received a pop up telling me that I was infected with a trojan and that i needed to scan with the anti virus. instinctively i clicked scan and i realized that I didnt recognize the program that was running. I tried cancelling and another pop up came up telling me to buy the anti virus or go unprotected i chose no and another pop warning that i was infected came up. At that point i disabled the network connection and my network adapter. As soon as i did that I started taskmgr and saw that the CPU was being hogged by normal processes. I tried loading nod and it told me it was stopped because it was infected. One after another pop ups came up saying file after file was infected could not execute due to infection. I just turned off the computer. When I booted up again i could get the taskmgr to start then everything froze, I rebooted again and tried safe mode, and it wouldnt work either. 100% cpu no functionality. I got it to work finally with safe mode command prompt. I ran the programs from the before you start guide, both in safe mode CMD prompt and safe mode networking. I got the logs, now im running the gmr in regular safe mode and its taken about 4 hours and its still not done. So please PLEASE HELP my dad needs to take the computer with him on monday.
I forgot to say that i also restore the system after i couldnt get an antivirus to load. before i got it to load in safe mode so i restored back to before lo i removed bitdefender and then repaired the installation. by the time i did that i had come here so... i

DDS (Ver_10-03-17.01) - NTFSx86 MINIMAL
Run by LWR at 3:20:10.50 on Mon 04/19/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.503.335 [GMT -6:00]

AV: BitDefender Antivirus *On-access scanning enabled* (Outdated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
AV: Eset NOD32 antivirus system 2.50 *On-access scanning enabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20100403005344.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: MSN Toolbar BHO: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {BA52B914-B692-46c4-B683-905236F6F655} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll
TB: MSN Toolbar: {8dcb7100-df86-4384-8842-8fa844297b3f} - c:\program files\msn toolbar\platform\4.0.0379.0\npwinext.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: BitDefender Toolbar: {381ffde8-2394-4f90-b10d-fc6124a40f8c} - c:\program files\bitdefender\bitdefender 2010\IEToolbar.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [lxdnmon.exe] "c:\program files\lexmark 2600 series\lxdnmon.exe"
mRun: [Microsoft Default Manager] "c:\program files\microsoft\search enhancement pack\default manager\DefMgr.exe" -resume
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [BitDefender Antiphishing Helper] "c:\program files\bitdefender\bitdefender 2010\IEShow.exe"
mRun: [BDAgent] "c:\program files\bitdefender\bitdefender 2010\bdagent.exe"
mRun: [nod32kui] "c:\program files\eset\nod32kui.exe" /WAITSERVICE
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
StartupFolder: c:\docume~1\lwr\startm~1\programs\startup\palmon~1.lnk - c:\program files\palmone\register.exe
uPolicies-explorer: NoRecentDocsNetHood = 0 (0x0)
IE: {13C1DBF6-7535-495c-91F6-8C13714ED485} - c:\documents and settings\lwr\start menu\programs\absolute poker\Absolute Poker.lnk
IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\documents and settings\lwr\start menu\programs\imvu\Run IMVU.lnk
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
LSP: imon.dll
Trusted Zone: internet
Trusted Zone: mcafee.com
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} - hxxp://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} - hxxp://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} - hxxp://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {A4110378-789B-455F-AE86-3A1BFC402853} - hxxp://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-150-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} - hxxp://zone.msn.com/binframework/v10/StProxy.cab55579.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Notify: igfxcui - igfxsrvc.dll
Notify: TPSvc - TPSvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

============= SERVICES / DRIVERS ===============

R0 HWFProt;Hywave File Protector HWFProt;c:\windows\system32\drivers\HWFProt.sys [2008-1-6 43936]
R0 szkg5;szkg5;c:\windows\system32\drivers\SZKG.sys [2009-12-7 61328]
R0 szkgfs;szkgfs;c:\windows\system32\drivers\SZKGFS.sys [2010-2-24 173328]
S0 is3srv;is3srv;c:\windows\system32\drivers\is3srv.sys [2009-12-7 61328]
S0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-1-5 385536]
S1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-2-21 82952]
S1 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2010-4-8 123856]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2010-4-8 41680]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-3-18 135664]
S2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [2009-3-21 98984]
S2 McShield;McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-2-21 170144]
S2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-2-21 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-2-21 141792]
S2 nlsX86cc;NLS Service;c:\windows\system32\NLSSRV32.EXE [2010-2-2 65856]
S2 NOD32krn;NOD32 Kernel Service;c:\program files\eset\nod32krn.exe [2010-4-16 495616]
S2 NovacomD;Palm Novacom;c:\program files\palm\sdk\bin\novacom\x86\novacomd.exe [2010-2-17 34304]
S2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\tuneup utilities 2010\TuneUpUtilitiesService32.exe [2010-2-25 1047880]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-5-18 24652]
S2 WSWNDA3100;WSWNDA3100;c:\program files\netgear\wnda3100v2\WifiSvc.exe [2010-4-12 278528]
S3 ;Avg Firewall driver;\??\c:\windows\system32\drivers\avgtdix.sys --> c:\windows\system32\drivers\avgtdix.sys [?]
S3 AE1000;Linksys AE1000 Driver;c:\windows\system32\drivers\AE1000XP.sys [2010-4-13 816672]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\common files\bitdefender\bitdefender arrakis server\bin\arrakis3.exe [2009-10-19 183880]
S3 ATMFBUS;A600 USB Composite Device Driver;c:\windows\system32\drivers\atmfbus.sys --> c:\windows\system32\drivers\ATMFBUS.sys [?]
S3 ATMFCVsp;A600 Cricket CM Port;c:\windows\system32\drivers\atmfcvsp.sys --> c:\windows\system32\drivers\ATMFCVsp.sys [?]
S3 ATMFFLT;A600 USB Modem Installation CD;c:\windows\system32\drivers\atmfflt.sys --> c:\windows\system32\drivers\ATMFFLT.sys [?]
S3 ATMFMdm;A600 Cricket EVDO Modem;c:\windows\system32\drivers\atmfmdm.sys --> c:\windows\system32\drivers\ATMFMdm.sys [?]
S3 ATMFNET;A600 Cricket EVDO Network Adapter;c:\windows\system32\drivers\atmfnet.sys --> c:\windows\system32\drivers\ATMFNET.sys [?]
S3 ATMFNVsp;A600 Cricket NMEA Port Serial Port;c:\windows\system32\drivers\atmfnvsp.sys --> c:\windows\system32\drivers\ATMFNVsp.sys [?]
S3 ATMFVsp;A600 Cricket Diagnostics Port;c:\windows\system32\drivers\atmfvsp.sys --> c:\windows\system32\drivers\ATMFVsp.sys [?]
S3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys --> c:\windows\system32\drivers\avgfwdx.sys [?]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys --> c:\windows\system32\drivers\avgfwdx.sys [?]
S3 BCMH43XX;Broadcom 802.11 USB Network Adapter Driver;c:\windows\system32\drivers\bcmwlhigh5.sys [2010-4-12 632576]
S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2010-4-12 153448]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-2-21 55456]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-4-19 38224]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-2-21 152320]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-2-21 51688]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-2-21 312584]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-2-21 88480]
S3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [2010-2-21 88480]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-2-21 83496]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2010-4-12 50704]
S3 NUVision;Pinnacle DVC 80 Video;c:\windows\system32\drivers\nuvvid2.sys [2007-2-14 155264]
S3 PCX500;Cisco Wireless LAN Adapters Driver;c:\windows\system32\drivers\pcx500.sys [2007-1-12 169984]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\tuneup utilities 2010\TuneUpUtilitiesDriver32.sys [2010-2-25 10064]
S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2010-3-25 99728]
S3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2010-3-25 110608]

=============== Created Last 30 ================

2010-04-19 09:11:55 0 d-----w- c:\program files\Xenocode
2010-04-19 09:04:09 0 -c--a-w- c:\documents and settings\lwr\defogger_reenable
2010-04-19 07:12:03 0 dc----w- c:\docume~1\lwr\applic~1\Malwarebytes
2010-04-19 07:11:53 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-19 07:11:50 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-04-19 07:11:50 0 dc----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-04-19 07:11:49 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-04-19 02:47:00 0 d-----w- c:\windows\system32\wbem\Repository
2010-04-19 02:46:21 0 dc----w- c:\docume~1\lwr\applic~1\Bitdefender
2010-04-19 00:38:04 0 d-----w- c:\program files\Nsasoft
2010-04-18 08:28:27 0 d-----w- c:\program files\CleanMem
2010-04-18 08:14:07 0 dc----w- c:\docume~1\alluse~1\applic~1\Genie-Soft
2010-04-18 08:12:26 0 dc----w- c:\docume~1\lwr\applic~1\Genie-Soft
2010-04-18 08:08:52 0 d-----w- c:\program files\Genie-Soft
2010-04-17 01:25:23 0 dc----w- c:\docume~1\lwr\applic~1\Windows Search
2010-04-16 23:54:02 270336 ----a-w- c:\windows\system32\imon.dll
2010-04-16 23:54:01 502208 ----a-w- c:\windows\system32\drivers\amon.sys
2010-04-16 23:53:58 0 d-----w- c:\program files\Eset
2010-04-16 23:51:55 0 d-----w- c:\program files\Nod32
2010-04-16 22:55:32 0 d-----w- c:\program files\common files\Hewlett-Packard
2010-04-16 22:54:47 61440 ----a-w- c:\windows\system32\HPZinw12.exe
2010-04-16 22:54:46 69632 ----a-w- c:\windows\system32\HPZipm12.exe
2010-04-16 22:54:46 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2010-04-16 22:54:45 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2010-04-16 22:54:43 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2010-04-16 22:54:40 278584 ----a-w- c:\windows\system32\HPZidr12.dll
2010-04-16 22:51:24 0 d-----w- c:\program files\HP
2010-04-16 22:50:18 69417 ----a-w- c:\windows\hpoins05.dat
2010-04-16 22:50:18 19696 ------w- c:\windows\hpomdl05.dat
2010-04-16 22:42:05 0 dc----w- c:\temp\HP_WebRelease
2010-04-15 20:46:14 0 d-----w- c:\program files\PC Medkit
2010-04-15 14:27:41 376 -c--a-w- c:\documents and settings\lwr\Application Dataprivacy.xml
2010-04-15 14:25:50 52 ----a-w- c:\windows\system32\ashttpstats.csv
2010-04-15 00:22:24 0 d-----w- c:\program files\McAfee
2010-04-14 13:15:20 0 dc----w- C:\Combo-Fix
2010-04-14 12:39:47 0 d-----w- c:\windows\system32\NtmsData
2010-04-13 06:30:54 816672 ----a-r- c:\windows\system32\drivers\AE1000XP.sys
2010-04-13 06:30:54 226592 ----a-r- c:\windows\system32\RaCoInst.dll
2010-04-13 06:30:54 13931 ----a-r- c:\windows\system32\RaCoInst.dat
2010-04-13 06:27:44 0 dc----w- c:\docume~1\alluse~1\applic~1\Cisco Systems
2010-04-13 05:32:24 632576 ----a-w- c:\windows\system32\drivers\bcmwlhigh5.sys
2010-04-13 05:32:22 53299 ----a-w- c:\windows\system32\pthreadVC.dll
2010-04-13 05:32:22 281104 ----a-w- c:\windows\system32\wpcap.dll
2010-04-13 05:32:22 100880 ----a-w- c:\windows\system32\Packet.dll
2010-04-13 05:32:17 50704 ----a-w- c:\windows\system32\drivers\npf.sys
2010-04-13 05:31:36 0 d-----w- c:\program files\NETGEAR
2010-04-13 00:53:54 132 ----a-w- c:\windows\system32\rezumatenoi.dat
2010-04-13 00:03:36 385 ----a-w- c:\windows\system32\user_gensett.xml
2010-04-12 23:53:00 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2010-04-12 23:52:46 21504 ----a-w- c:\windows\system32\drivers\hidserv.dll
2010-04-12 23:26:49 153448 -c--a-w- c:\windows\system32\drivers\bdfm.sys
2010-04-12 23:24:07 291352 -c--a-w- c:\windows\system32\drivers\bdfsfltr.sys
2010-04-12 22:37:12 0 dc----w- c:\docume~1\lwr\applic~1\Windows Desktop Search
2010-04-12 22:33:16 29696 -c----w- c:\windows\system32\dllcache\mimefilt.dll
2010-04-12 22:33:15 98304 -c----w- c:\windows\system32\dllcache\nlhtml.dll
2010-04-12 22:33:15 192000 -c----w- c:\windows\system32\dllcache\offfilt.dll
2010-04-12 22:24:50 0 -c--a-w- C:\pcwords2.dat
2010-04-12 22:24:50 0 -c--a-w- C:\pcwords.dat
2010-04-12 22:24:50 0 -c--a-w- C:\pcconf.ini
2010-04-12 22:24:50 0 -c--a-w- C:\pc_sign.slf
2010-04-12 21:33:43 0 d-----w- c:\program files\BitDefender
2010-04-12 21:27:19 0 d-----w- c:\program files\common files\BitDefender
2010-04-12 19:55:16 0 d-----w- c:\program files\Softick
2010-04-12 18:19:34 0 d-----w- c:\program files\BitTorrent
2010-04-12 18:03:42 0 dc----w- c:\docume~1\lwr\applic~1\Downloaded Installations
2010-04-12 18:03:41 0 d-----w- c:\program files\gs
2010-04-12 18:03:25 0 d-----w- c:\program files\PlotSoft
2010-04-12 18:02:51 0 d-----w- c:\program files\Novacom
2010-04-12 01:50:51 0 d-----w- c:\program files\common files\Mcafee
2010-04-12 00:17:59 0 d-----w- c:\program files\STOPzilla!
2010-04-12 00:17:59 0 d-----w- c:\program files\common files\iS3
2010-04-12 00:17:58 0 dc----w- c:\docume~1\alluse~1\applic~1\STOPzilla!
2010-04-11 17:02:00 0 d-----w- c:\program files\Windows Desktop Search
2010-04-11 17:01:59 0 d-----w- c:\windows\system32\GroupPolicy
2010-04-11 10:33:57 0 dc----w- c:\docume~1\lwr\applic~1\DriverCure
2010-04-11 10:33:34 0 dc----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2010-04-11 10:33:34 0 dc----w- c:\docume~1\alluse~1\applic~1\DriverCure
2010-04-11 10:33:34 0 d-----w- c:\program files\ParetoLogic
2010-04-11 09:48:28 0 d-----w- c:\program files\RegWork
2010-04-10 20:41:49 26432 ----a-w- c:\windows\system32\nitrolocalmon.dll
2010-04-10 20:41:49 17728 ----a-w- c:\windows\system32\nitrolocalui.dll
2010-04-10 19:53:11 5885 -c--a-w- c:\documents and settings\lwr\.PSSettings.xml
2010-04-10 19:39:21 0 dc----w- c:\documents and settings\lwr\.PDFStudio
2010-04-09 07:51:12 0 dc----w- c:\docume~1\alluse~1\applic~1\PrettyGoodGames
2010-04-09 01:43:40 4136743 ----a-w- c:\windows\pfirewall.log.old
2010-04-08 22:02:34 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_WinUSB_01007.Wdf
2010-04-08 22:02:31 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2010-04-08 22:01:58 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2010-04-08 21:28:22 0 d-----w- c:\windows\Speeditup Free
2010-04-08 21:28:22 0 d-----w- c:\program files\Speeditup Free
2010-04-08 15:39:16 0 dc----w- c:\documents and settings\lwr\.VirtualBox
2010-04-08 15:35:56 123856 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys
2010-04-08 15:35:46 41680 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys
2010-04-08 15:35:17 0 d-----w- c:\program files\Sun
2010-04-08 15:19:42 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_user_01_07_00.Wdf
2010-04-08 15:18:21 581192 ----a-w- c:\windows\system32\WinUSBCoInstaller.dll
2010-04-08 15:18:21 1112288 ----a-w- c:\windows\system32\WdfCoInstaller01007.dll
2010-04-08 15:17:32 0 d-----w- c:\program files\Palm
2010-04-08 14:46:37 0 dc----w- c:\docume~1\lwr\applic~1\CanuckSoftware
2010-04-06 15:34:20 0 d-----w- c:\program files\Carbonite
2010-04-03 04:20:02 1374 ----a-w- c:\windows\imsins.BAK
2010-04-02 21:21:37 0 dcsha-r- C:\cmdcons
2010-04-02 21:17:06 98816 ----a-w- c:\windows\sed.exe
2010-04-02 21:17:06 77312 ----a-w- c:\windows\MBR.exe
2010-04-02 21:17:06 261632 ----a-w- c:\windows\PEV.exe
2010-04-02 21:17:06 161792 ----a-w- c:\windows\SWREG.exe
2010-04-02 20:45:53 0 d-----w- c:\program files\BlueTooth
2010-04-02 18:16:04 0 dcsh--w- c:\documents and settings\lwr\IECompatCache
2010-04-02 17:37:04 0 dc----w- c:\docume~1\lwr\applic~1\Samsung
2010-04-02 16:56:50 174592 ----a-w- c:\windows\system32\framedyn.dll
2010-04-02 16:56:12 0 d-----w- c:\windows\system32\Samsung_USB_Drivers
2010-04-02 16:55:50 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
2010-04-02 01:42:12 34 ------w- c:\windows\system32\oeminfo.ini
2010-04-02 00:51:36 0 d-----w- c:\windows\pss
2010-04-01 23:21:20 0 d-----r- c:\windows\system\New Briefcase
2010-04-01 19:32:48 0 dc----w- c:\temp\_PqiTemp_
2010-04-01 19:30:52 43 -c--a-w- c:\temp\users.dat
2010-04-01 19:30:52 0 dc----w- c:\temp\katies
2010-03-30 09:50:46 0 dc----w- c:\docume~1\lwr\applic~1\funkitron
2010-03-29 06:50:17 0 d-----w- c:\program files\palmOne
2010-03-29 05:54:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-28 17:23:34 0 dc----w- c:\docume~1\lwr\applic~1\EA
2010-03-28 09:36:56 0 dc----w- c:\docume~1\alluse~1\applic~1\Beanbag Studios
2010-03-28 08:09:40 0 dc----w- c:\docume~1\lwr\applic~1\WildTangent
2010-03-28 07:57:23 0 dc----w- c:\docume~1\alluse~1\applic~1\W3i
2010-03-28 07:57:23 0 d-----w- c:\program files\W3i
2010-03-26 02:06:30 99728 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys
2010-03-26 02:06:26 133648 ----a-w- c:\windows\system32\VBoxNetFltNotify.dll
2010-03-26 02:06:26 110608 ----a-w- c:\windows\system32\drivers\VBoxNetFlt.sys

==================== Find3M ====================

2010-04-08 16:17:11 23408 -c--a-w- c:\docume~1\lwr\applic~1\GDIPFONTCACHEV1.DAT
2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\vbscript.dll
2010-03-09 10:28:20 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 15:41:25 23408 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-03-06 00:16:42 17408 ----a-r- c:\windows\system32\SZIO5.dll
2010-03-06 00:14:16 442368 ----a-r- c:\windows\system32\SZBase5.dll
2010-03-06 00:13:44 540672 ----a-r- c:\windows\system32\SZComp5.dll
2010-02-25 17:03:02 30536 ----a-w- c:\windows\system32\TURegOpt.exe
2010-02-25 06:24:37 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-24 21:06:36 173328 ----a-r- c:\windows\system32\drivers\SZKGFS.sys
2010-02-24 13:11:07 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 15:10:28 2189952 ------w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2066816 ------w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33:11 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-02 18:35:30 65856 ----a-w- c:\windows\system32\NLSSRV32.EXE
2008-06-23 16:57:05 0 ----a-w- c:\program files\uninstall.dat
2008-03-23 19:35:54 0 ----a-w- c:\program files\temp01
2007-03-06 07:14:35 56 --sha-r- c:\windows\system32\D96B54960E.sys
2007-03-06 07:14:36 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-24 04:57:29 65536 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009062320090624\index.dat

============= FINISH: 3:21:07.23 ===============



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-19 06:42:01
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\LWR\LOCALS~1\Temp\kggoqfod.sys


---- System - GMER 1.0.15 ----

SSDT szkgfs.sys (STOPzilla Kernel Guard File System, x86-32 /iS3, Inc.) ZwTerminateProcess [0xF87C5710]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs szkgfs.sys (STOPzilla Kernel Guard File System, x86-32 /iS3, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs HWFProt.sys (Windows NT File System Protector Network Edition/Alfa Corporation)
AttachedDevice \FileSystem\Fastfat \Fat szkgfs.sys (STOPzilla Kernel Guard File System, x86-32 /iS3, Inc.)
AttachedDevice \FileSystem\Fastfat \Fat HWFProt.sys (Windows NT File System Protector Network Edition/Alfa Corporation)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXejrrpqlkbtojtlrccbctkjqsxuwjxehn.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXejrrpqlkbtojtlrccbctkjqsxuwjxehn.sys
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXstqcoffuyvxdetrlxxnelnhnehmgmnvp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXnwytprfcxxustkprqbrkeljipfcoapxs.dll
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys@start 1
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys@type 1
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys@imagepath \systemroot\system32\drivers\MSIVXejrrpqlkbtojtlrccbctkjqsxuwjxehn.sys
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys@group file system
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys\modules@MSIVXserv \\?\globalroot\systemroot\system32\drivers\MSIVXejrrpqlkbtojtlrccbctkjqsxuwjxehn.sys
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys\modules@MSIVXl \\?\globalroot\systemroot\system32\MSIVXstqcoffuyvxdetrlxxnelnhnehmgmnvp.dll
Reg HKLM\SYSTEM\ControlSet004\Services\MSIVXserv.sys\modules@MSIVXclk \\?\globalroot\systemroot\system32\MSIVXnwytprfcxxustkprqbrkeljipfcoapxs.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{69D43EF3-ACCE-4CD1-9798-5E6177B1B3F3}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{69D43EF3-ACCE-4CD1-9798-5E6177B1B3F3}@pakeafigcfkknlgfblkhkdgifcnkpcng 0x6A 0x61 0x62 0x66 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{69D43EF3-ACCE-4CD1-9798-5E6177B1B3F3}@oaagcbfndgojgmkllpgmnhjhhcbjeh 0x6A 0x61 0x62 0x66 ...
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@Rev 1
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@WFlags 0
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@ShowCmd 1
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@MinPos800x600(1).x -32000
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@MinPos800x600(1).y -32000
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@WinPos800x600(1).left 80
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@WinPos800x600(1).top 87
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@WinPos800x600(1).right 680
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@WinPos800x600(1).bottom 514
Reg HKCU\Software\Microsoft\Windows\ShellNoRoam\Bags\1551\Shell@ScrollPos800x600(1).y 2

---- EOF - GMER 1.0.15 ----

i have the malware log to this is the GMER from safe mode since the one from normal is still running PLEASE HELP ME!!its starting to slow down again as im typing


http://www.bleepingcomputer.com/forums/ind...=310132&hl=


I found that this case is very very similar but im still having major problems i still cant load normally

Attached Files


Edited by rumble_my_heart, 19 April 2010 - 01:27 PM.


BC AdBot (Login to Remove)

 


#2 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:11:59 PM

Posted 24 April 2010 - 03:22 PM

Hi rumble_my_heart,

Welcome to Bleeping Computer.

My name is mpascal, and I will be helping you fix your problem.

Before we begin, I would like to make a few things clear so that we can fix your problem as efficiently as possible:
  • Be sure to follow all my instructions carefully! If there is anything you don''t understand, don''t hesitate to ask.
  • Please do not do anything or perform other steps unless I have asked you to do so.
  • Please make sure you post all logs I ask you to, and make sure that the entire log gets posted.
  • Don't attach any logs unless asked. Posting them in the forums will make them easier to analyze.
  • If you are unsure of how to reply, or need help with anything regarding the website, please look here.

As it has been a few days, I'm going to need some fresh logs. Please run the following:

STEP 1 - MBAM

Open Malwarebyte's Anti-Malware.
  • Under the Updates tab, click Check for Updates. Let the updates install (if any).
  • After that, under the Scanner tab, click Perform Quick Scan and then Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

STEP 2 - GMER

Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.


  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and be sure to re-enable your anti-virus, Firewall and any other security programs you had disabled.
-- If you encounter any problems, try running GMER in safe mode.
-- If GMER crashes or keeps resulting in a BSODs, uncheck Devices on the right side before scanning
.

STEP 3 - OTL

Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • In the Custom Scans box, copy and paste the following:
    CODE
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    nvraid.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTListIt.Txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of the files, and post it with your next reply.
STEP 4 - Reply

Please reply with the following logs:
  • MBAM Log
  • OTL Log
  • GMER Log

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image


#3 mpascal

mpascal

    Math Nerd


  • Members
  • 1,653 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Canada
  • Local time:11:59 PM

Posted 29 April 2010 - 10:07 PM

Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.

Posted Image

Stay with your topic! Topics that go 4 days without a reply will be closed. PM me to reopen.

Please don't PM asking for support. Post on the forums instead.

My help is free, but if you wish to donate and help continue my fight against malware, click here: Posted Image





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users