Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

TDSS-like rootkit; google redirect, reinstall after TDSS-Killer


  • This topic is locked This topic is locked
3 replies to this topic

#1 shotgunderek

shotgunderek

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:47 PM

Posted 17 May 2010 - 04:27 AM

Hello; this is my first post to this forum so I hope I am following all of the rules properly. Somehow, my computer was recently hit by a blast of viruses - I have no idea what happened. Suddenly .exe files were closing themselves and I was getting false virus alerts from something that desperately wanted me to install it. Then AVG alerted me to a keylogger and several of my online accounts were compromised.

I've run MBAM and Trojan Remover but neither detect any problems. TDSS Killer identifies the infection, and supposedly "deletes" it, but it is still infected upon reboot. Other than google redirects and slow browsing I have not experienced any problems but many of the other programs I received in this fun "bundle" were particularly malicious, so I'm worried. Below are the relevant logs:


DDS (Ver_10-03-17.01) - NTFSx86
Run by Derk at 2:21:45.29 on Mon 05/17/2010
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3582.2746 [GMT -7:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\Drivers\WTSRV.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\WTClient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\AIM\aim.exe
C:\Documents and Settings\Derk\Desktop\tweak\Core Temp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Z:\steam\steam.exe
c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe
C:\Program Files\Silicon Image\SiISATARaid\SATARaid.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Documents and Settings\Derk\Local Settings\Application Data\Google\Update\1.2.183.23\GoogleCrashHandler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
\\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Documents and Settings\Derk\Desktop\Super Computer Utilities\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
uURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
uURLSearchHooks: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
mURLSearchHooks: AOLTBSearch Class: {ea756889-2338-43db-8f07-d1ca6fb9c90d} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: AOLSearchHook Class: {54eb34ea-e6be-4cfd-9f4f-c4a0c2eafa22} - c:\program files\aim search\AOLSearch.dll
BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: AIM Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
TB: Veoh Browser Plug-in: {d0943516-5076-4020-a3b5-aefaf26ab263} - c:\program files\veoh networks\veoh\plugins\reg\VeohToolbar.dll
TB: Veoh Web Player Video Finder: {0fbb9689-d3d7-4f7a-a2e2-585b10099bfc} - c:\program files\veoh networks\veohwebplayer\VeohIEToolbar.dll
uRun: [AIM] c:\program files\aim\aim.exe -cnetwait.odl
uRun: [Core Temp] c:\documents and settings\derk\desktop\tweak\Core Temp.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [Steam] "z:\steam\steam.exe" -silent
uRun: [Google Update] "c:\documents and settings\derk\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.09\RivaTuner.exe" /S
mRun: [WTClient] WTClient.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TrojanScanner] c:\program files\trojan remover\Trjscan.exe /boot
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg311v3\wlancfg5.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\sataraid.lnk - c:\program files\silicon image\siisataraid\SATARaid.exe
IE: &AIM Search - c:\program files\aol\aim toolbar 5.0\resources\en-us\local\search.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\derk\applic~1\mozilla\firefox\profiles\srp8613w.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.aol.com/aolcom/search?invocationType=tbff50ie7&query=
FF - prefs.js: browser.startup.homepage - hxxp://shirt.woot.com/|http://www.teefury.com/
FF - prefs.js: keyword.URL - hxxp://search.aol.com/aolcom/search?invocationType=TB50TRFF;homepage=no;search=yesab&query=
FF - component: c:\documents and settings\derk\application data\mozilla\firefox\profiles\srp8613w.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\winnt_x86-msvc\components\ipc.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\derk\local settings\application data\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\veoh networks\veoh\plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\veoh networks\veohwebplayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-7 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-7 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-7 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-7 308064]
R2 cpuz132;cpuz132;c:\windows\system32\drivers\cpuz132_x32.sys [2010-3-4 12672]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2008-6-6 24652]
R3 ALSysIO;ALSysIO;\??\c:\docume~1\derk\locals~1\temp\alsysio.sys --> c:\docume~1\derk\locals~1\temp\ALSysIO.sys [?]
R3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\drivers\PTSimBus.sys [2007-6-7 18944]
S0 rwgnmlq;rwgnmlq; [x]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;x:\steam\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe --> x:\steam\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2005-8-2 32512]
S3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\drivers\PTSimHid.sys [2007-4-23 10752]
S3 usbxbox;usbxbox;\??\c:\windows\system32\usbxbox.sys --> c:\windows\system32\usbxbox.sys [?]

=============== Created Last 30 ================

2010-05-17 09:18:41 36488 ----a-w- c:\windows\system32\drivers\klmdb.sys
2010-05-17 09:18:38 95360 ----a-w- c:\windows\system32\drivers\tsk7.tmp
2010-05-17 08:55:55 20 ----a-w- c:\documents and settings\derk\defogger_reenable
2010-05-17 07:08:00 95360 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-05-16 00:28:17 0 d-----w- c:\windows\system32\scripting
2010-05-16 00:28:17 0 d-----w- c:\windows\l2schemas
2010-05-16 00:28:16 0 d-----w- c:\windows\system32\en
2010-05-16 00:28:16 0 d-----w- c:\windows\system32\bits
2010-05-16 00:23:58 0 d-----w- c:\windows\network diagnostic
2010-05-16 00:20:13 0 d-----w- c:\windows\EHome
2010-05-16 00:20:00 0 d-----w- c:\program files\Western Digital Corporation
2010-05-16 00:08:42 0 d-----w- c:\program files\Silicon Image
2010-05-15 23:55:45 0 d-----w- c:\windows\system32\MpEngineStore
2010-05-15 23:54:27 0 d-----w- C:\146dfd68449a15fd268b5d407e
2010-05-15 23:25:03 0 d-----w- c:\windows\system32\NtmsData
2010-05-12 18:00:03 0 d-----w- C:\Get
2010-05-09 20:50:05 0 d-----w- c:\docume~1\derk\applic~1\Auslogics
2010-05-09 20:49:58 0 d-----w- c:\program files\Auslogics
2010-05-09 20:47:45 0 d-----w- c:\program files\Windows Installer Clean Up
2010-05-09 02:12:53 0 d-----w- c:\program files\Steam
2010-05-09 01:10:31 2551 ----a-w- c:\windows\inijivuluy.dll
2010-05-09 00:08:47 2551 ----a-w- c:\windows\etadevip.dll
2010-05-08 08:16:24 0 d-----w- C:\spoolerlogs
2010-05-08 08:11:39 2551 ----a-w- c:\windows\ejewavate.dll
2010-05-08 08:09:25 50990 ----a-w- c:\windows\system32\uoqvukmxjdcguqj.exe
2010-05-08 08:08:57 0 d-----w- c:\docume~1\derk\applic~1\A354FA7AEAC5406F1055F547B7CD86C9
2010-05-07 23:10:09 0 d--h--w- C:\$AVG
2010-05-07 23:07:42 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-07 23:07:36 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-07 23:07:16 0 d-----w- c:\windows\system32\drivers\Avg
2010-05-07 23:06:56 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-07 23:05:23 0 d-----w- c:\program files\AVG
2010-05-07 23:05:10 0 d-----w- c:\docume~1\alluse~1\applic~1\avg9
2010-05-07 23:03:43 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-05-07 23:03:43 75264 ----a-w- c:\windows\system32\unacev2.dll
2010-05-07 23:03:43 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-05-07 23:03:43 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-05-07 23:03:43 153088 ----a-w- c:\windows\system32\UNRAR3.dll
2010-05-07 23:03:42 0 d-----w- c:\program files\Trojan Remover
2010-05-07 23:03:42 0 d-----w- c:\docume~1\derk\applic~1\Simply Super Software
2010-05-07 23:03:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Simply Super Software
2010-05-07 23:01:45 0 d-----w- c:\docume~1\derk\applic~1\Malwarebytes
2010-05-07 23:01:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-07 23:01:40 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-05-07 23:01:40 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-05-07 23:01:40 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-05-05 07:59:26 0 ----a-w- c:\documents and settings\derk\ntuser.tmp
2010-04-17 20:46:00 0 d-----w- c:\docume~1\derk\applic~1\UDP Software

==================== Find3M ====================

2010-05-16 00:06:38 15600 ----a-w- c:\windows\gdrv.sys
2010-05-15 07:01:33 218808 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-05-15 06:55:55 137256 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-03-29 07:50:50 138056 ----a-w- c:\docume~1\derk\applic~1\PnkBstrK.sys
2010-03-29 07:50:18 2434856 ----a-w- c:\windows\system32\pbsvc_bc2.exe
2010-02-26 05:43:57 667136 ----a-w- c:\windows\system32\wininet.dll
2010-02-26 05:43:54 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-02-22 07:35:16 278120 ----a-w- c:\windows\system32\nvmccs.dll
2010-02-22 07:35:16 154216 ----a-w- c:\windows\system32\nvsvc32.exe
2010-02-22 07:35:16 145000 ----a-w- c:\windows\system32\nvcolor.exe
2010-02-22 07:35:16 13670504 ----a-w- c:\windows\system32\nvcpl.dll
2010-02-22 07:35:16 110696 ----a-w- c:\windows\system32\nvmctray.dll
2010-02-22 07:34:58 81920 ----a-w- c:\windows\system32\nvwddi.dll
2010-02-22 05:18:39 6431872 ----a-w- c:\windows\system32\nv4_disp.dll
2010-02-22 05:18:39 61440 ----a-w- c:\windows\system32\OpenCL.dll
2010-02-22 05:18:39 592488 ----a-w- c:\windows\system32\nvudisp.exe
2010-02-22 05:18:39 4075520 ----a-w- c:\windows\system32\nvcuda.dll
2010-02-22 05:18:39 2646632 ----a-w- c:\windows\system32\nvcuvenc.dll
2010-02-22 05:18:39 2183470 ----a-w- c:\windows\system32\nvdata.bin
2010-02-22 05:18:39 215656 ----a-w- c:\windows\system32\nvcodins.dll
2010-02-22 05:18:39 215656 ----a-w- c:\windows\system32\nvcod.dll
2010-02-22 05:18:39 2030184 ----a-w- c:\windows\system32\nvcuvid.dll
2010-02-22 05:18:39 14757888 ----a-w- c:\windows\system32\nvoglnt.dll
2010-02-22 05:18:39 11647592 ----a-w- c:\windows\system32\nvcompiler.dll
2010-02-22 05:18:39 1097728 ----a-w- c:\windows\system32\nvapi.dll
2010-02-16 14:08:49 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
2006-03-15 21:19:34 212992 ----a-w- c:\windows\inf\wg311v3\CopyWHQLDriver.exe
2006-01-27 00:55:10 280576 ----a-w- c:\windows\inf\wg311v3\WG311v3.sys
2005-10-06 22:17:34 280576 ----a-w- c:\windows\inf\wg311v3\WG311v3XP.sys

============= FINISH: 2:22:55.79 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 km2357

km2357

  • Malware Response Team
  • 1,784 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:47 PM

Posted 19 May 2010 - 01:30 PM

Hello and welcome to Bleeping Computer.

My name is km2357 and I will be helping you to remove any infection(s) that you may have.

I will be giving you a series of instructions that need to be followed in the order in which I give them to you.

If for any reason you do not understand an instruction or are just unsure then please do not guess, simply post back with your questions/concerns and we will go through it again.

Please do not start another thread or topic, I will assist you at this thread until we solve your problems.

Lastly the fix may take several attempts and my replies may take some time but I will stick with it if you do the same.

Sorry for the delay in replying, the forum is very busy. If you still need help, please post fresh DDS Logs (DDS and Attach.txt)

MalWare Removal University Master

Member of ASAP
unite_Invision.png


#3 km2357

km2357

  • Malware Response Team
  • 1,784 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:47 PM

Posted 22 May 2010 - 11:49 AM

shotgunderek? Do you still need help?

MalWare Removal University Master

Member of ASAP
unite_Invision.png


#4 km2357

km2357

  • Malware Response Team
  • 1,784 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:47 PM

Posted 25 May 2010 - 01:23 PM

Due to the lack of feedback, this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.

MalWare Removal University Master

Member of ASAP
unite_Invision.png





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users