I'm having some real trouble here. Recently I was infected with what I believe to be some sort of rootkit. My computer would start crashing because of a generic win32 process. I started to look into it and noticed svchost.exe using lots of memory. So I did a command (cmd): netstat -on
Sure enough, svchost.exe was sending requests to all sorts of IPs.
Started to do some more searching on the Internet, came across all sorts of tools. Some ran well, others did not. When running ComboFix, I would see an entry in my log under the gmer section:
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys >>UNKNOWN [0x8A7c7c76]<<
So I started searching, and found information here on this site.
When I run GMER by itself with all the items ticked as shown in your preparation guide, my computer eventually crashes. I watch all the services running increase in memory usage until the machine just freezes. So ran them individually. I haven't finished running the Files scan in GMER yet, but wanted to get some input from you guys before I go too much further. I've been trying to clean this for several days now and it just keeps coming back.
I've uninstalled my JRE and even Java updates all together in hopes it would help. It didn't, I'm still infected.
I am running Windows XP SP3.
Any help would be greatly appreciated.
EDIT: I didn't post logs because I saw in a recent post gringo_pr asked the user not to do that. Since it conflicted with the Preparation guide, I decided I better not until someone asks for them.
Thanks for the response Orange Blossom.
Here are the DDS and ComboFix logs.
I haven't had a chance to get a good log from GMER yet.
As soon as I can, I will post that as well.
Merged posts and removed my reply. ~ OB
I have a GMER log now that I ran in Safe Mode.
It does not contain IAT/EAT or Files.
I tried running separate scan for Files, looked like it completed, but would not save.
I tried to copy, but couldn't get Notepad to open up and my system just froze.
I was able to scroll through the log, but it only had entries for Visual Studio.NET and Sonic Disc Burning stuff, so I don't think it was complete.
I am still unable to get any Windows Updates or hit the Windows Update site.
I no longer have a mysterious browser window popping up with consumernews24.com though - so I guess that's good.
I downloaded a trial version of Kaspersky Anti-Virus 2011, it didn't find anything.
I've run Malwarebytes, originally it found 2 Trojans, but it no longer finds anything either.
I've checked my LAN settings, no proxy has been setup or anything like that, it looks good.
Any help would greatly be appreciated.
(Sorry if this is a bump, but I wanted to provide the GMER log and give more information)
EDIT: Another post merged ~BP
Edited by Budapest, 02 October 2010 - 03:22 PM.