Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Multiple Virus Symptoms

  • Please log in to reply
1 reply to this topic

#1 fadedlight1212


  • Members
  • 2 posts
  • Local time:10:48 PM

Posted 17 August 2010 - 10:36 AM

First off, this is the first time I have ever tried posting like this, so if I do it wrong I apologize and please let me know what I need to change.

OK so I got a virus on my computer and I had been trying to take it off myself. I was able to fix some of the symptoms but not all and now am having some fun new issues. This started with with a fake anti-spyware app the called itself "Security Suite" hijacking system and running at startup. Also, regedit was disabled as well as folder options. Also the internet would not connect. I restarted in Safe Mode with networking, cleared out c:\documents and settings\[usename]\local settings\temp and c:\documents and settings\[usename]\local settings\temporary internet files. I also went into the c:\documents and settingins\[username]\Local settings\Application data &c:\documents and settingins\[username]s\Application data and removed any folder that looked suspicious such as folders named random characters (i.e. nxpkvvjl). Next, I opened MSCONFIG, startup tab, and deselected any unknown processes (checked each on on laptop/google to make sure none were essential). I opened Internet Options>Connections>LAN Settings and disabled the proxy (I don't use one but something had set a proxy up). I then ran MBAM full scan, told it to fix issues it found and restarted.

That seemed to remove the "Security Suite" app or at least it didn't start. Unfortunately the other issues still persisted. I searched online for a bit and found a fix was to use RKILL (renamed as iExplore.exe) and then run Spybot Search and Destroy, tried that, issues persisted. Spybot did find 7 items, fixed 4 right away and said to have cleaned up 3 more at startup. I then found a vbs script made by Doug Knox to re-enable registry editing. Opened regedit and found a key in HKCU\Software\Microsoft\Windows\Current Version\Policies that was called nofolderoptions and had a value of 1. I deleted it and after logging out and back in was able to access folder options again.

At this point I tried to go online and Google search but found I was being redirected to scam websites. So, I navigated to C:\WINDOWS\system32\drivers\etc\ and opened the hosts file with notepad. It was redirecting google traffic to an IP I later tracked to a server in Luxembourg. I deleted the entries, pasted in a copy of a free host file i found and saved the file. After this Google worked again.

And that brings me to where I'm at now. The current symptoms I am experiencing are:
* At startup, the registry editing and folder options gets disabled and I have to run the vbs script i found to re-enabled registry editing followed by deleting the nofolderoptions key that re-appears in HKCU\Software\Microsoft\Windows\Current Version\Policies.
*Spybot TeaTimer tells me something that looks like a long hexadecimal string is trying change registry but if I click deny the PC freezes.
*I have to release and renew my IP every minute or so or browser pages won't load (have tried Explorer, Firefox, and Chrome - all have issue).

System Specs:
Windows XP Professional Version 2002 SP 3
4 GB of RAM (windows sees 3.25 GB)
Intel Core 2 Duo 2.66 GHz
nVidia 8800 graphics card (eVGA model)
Asus P5K-VM motherboard

Any help would be sincerely appreciated as I am not looking forward to backing up 400 GB of files so I can rebuild.

Edited by hamluis, 17 August 2010 - 10:59 AM.
Moved from XP forum to Am I Infected ~ Hamluis.

BC AdBot (Login to Remove)


#2 fadedlight1212

  • Topic Starter

  • Members
  • 2 posts
  • Local time:10:48 PM

Posted 17 August 2010 - 11:59 AM

K i also ran the DDS and GMER deals talked about on this site. DDS ran fine, will post log below (can't figure out how to add an attachment here so i can't attach zipfile). GMER ran ok for a bit but then froze. let it sit for an hour, nothing changed so I restarted PC, got BSOD. Now having to run safe mode with networking, regular boot BSODs now since trying to run GMER.

DDS log:

DDS (Ver_10-03-17.01) - NTFSx86
Run by Neil at 9:15:57.35 on Tue 08/17/2010
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2566 [GMT -7:00]

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Neil\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = http=
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: c:\windows\system32\gqmcx89us.dll: {c2ba40a2-75f1-51bd-f413-04b15a2c8950} - c:\windows\system32\gqmcx89us.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden
uRun: [Google Update] "c:\documents and settings\neil\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [jhaefi8fioasghiusagu4huginfajgkhfig] c:\docume~1\neil\locals~1\temp\wininst.exe
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [nwiz] nwiz.exe /installquiet
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DivXUpdate] "c:\program files\divx\divx update\DivXUpdate.exe" /CHECKNOW
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
dRun: [mcexecwin] rundll32.exe c:\windows\temp\fugxx1kt7.dll, RestoreWindows
dRun: [hs38tughg8asegushgjfgd4f] c:\windows\temp\vm0x6vt.exe
dRun: [jhaefi8fioasghiusagu4huginfajgkhfig] c:\windows\temp\gdi32.exe
dRun: [Tgapoqez] rundll32.exe "c:\windows\kbdfat.dll",Startup
dRun: [siwweoub] c:\documents and settings\networkservice\local settings\application data\ursvlxbgk\wjkgxnbshdw.exe
dRun: [hjytlmut] c:\documents and settings\networkservice\local settings\application data\ddujfllkq\nponqnrshdw.exe
uPolicies-system: DisableRegistryTools = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1274322697828
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
STS: c:\windows\system32\gqmcx89us.dll: {c2ba40a2-75f1-51bd-f413-04b15a2c8950} - c:\windows\system32\gqmcx89us.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

============= SERVICES / DRIVERS ===============

S0 cerc6;cerc6; [x]
S2 akuleglfs;Shell Installer;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S2 bzadbv;Security Installer;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S2 dksibidhb;Center Windows;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S2 kanun;Security Helper;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S2 ysuylog;Config Center;c:\windows\system32\svchost.exe -k netsvcs [2008-4-14 14336]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-3-10 1684736]
S4 PEVSystemStart;PEVSystemStart;c:\combofix\PEV.cfxxe [2010-7-12 256512]

=============== Created Last 30 ================

2010-08-17 04:14:23 139 ----a-w- c:\windows\wininit.ini
2010-08-17 03:56:15 0 d-----w- c:\program files\Spybot - Search & Destroy
2010-08-17 03:56:15 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-08-16 21:50:40 257024 ----a-w- c:\windows\system32\0.6277840222868085.exe
2010-08-16 20:05:45 2838 ----a-w- c:\windows\arawipezupe.dll
2010-08-16 20:01:45 30000 ----a-w- c:\windows\system32\gqmcx89us.dll
2010-08-13 21:20:14 120 ----a-w- c:\windows\Cxofusezej.dat
2010-08-13 21:20:14 0 ----a-w- c:\windows\Jtuvegefim.bin
2010-08-13 21:18:49 193024 ----a-w- c:\windows\Vkuxia.exe
2010-08-13 21:18:44 75776 --sha-r- c:\windows\system32\qasfu.dll
2010-08-13 21:18:42 782848 ----a-w- c:\windows\system32\drivers\pigipgl.sys
2010-08-13 21:18:41 5 ----a-w- C:\zrpt.xml
2010-08-09 05:41:33 0 d-----w- c:\program files\The KMPlayer
2010-08-01 20:02:06 218464 ----a-w- c:\windows\system32\PnkBstrB.xtr
2010-08-01 19:59:40 138056 ----a-w- c:\docume~1\neil\applic~1\PnkBstrK.sys
2010-08-01 17:23:45 0 d-----w- c:\program files\Realtime Worlds
2010-07-19 01:52:56 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-07-19 01:52:56 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys

==================== Find3M ====================

2010-08-17 07:01:16 361344 ----a-w- c:\windows\system32\drivers\tcpip.sys
2010-08-01 20:02:15 138624 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-08-01 20:02:06 218464 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-08-01 19:59:22 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-08-01 04:01:36 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
2010-07-16 04:18:18 246784 ----a-w- c:\windows\system32\muwwp.dll
2010-07-16 04:18:04 294912 ----a-w- c:\windows\system32\quwwp.dll
2010-07-14 00:43:22 40581 ----a-w- c:\windows\system32\duwwp.exe
2010-06-09 16:20:22 2444656 ----a-w- c:\windows\system32\pbsvc_apb.exe
2006-06-23 22:48:00 32768 ----a-w- c:\windows\inf\UpdateUSB.exe
2008-04-14 12:00:00 157130 --sha-r- c:\windows\system32\vgygevz.dll

============= FINISH: 9:16:04.67 ===============

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users