Infection with no cure

#1 raulvola


Posted 26 January 2012 - 04:52 AM


I am frustrated with a virus infection impossible to clean.

As soon as XP start an offending message "A potential disk failure may cause loss of file, applications and documents stored on the hard disk. It's highly recommended to scan and solve HDD problems before continue using the PC. Scan and fix. Cancel and reboot" followed by many others "out of memory" etc pop-ups

I did this;

-Booting into XP safe mode.
-rKill.exe renamed and executed (black screen)
-TdssKiller.exe renamed and executed, detected and cleaned "RootKit.Boot.SST.b", detected unsigned files: cdrbsdrv, libusb0
-FixTDSS.exe renamed but is not running anymore. Closing with windows error
-Malwarebytes anti-malware renamed but is not running anymore. Closing with windows error

-Booting with Windows Offline beta defende
-detected and cleaned trojan "Win32/FakeSysdef"

But the infection remains.

I send you the log form DDS. GMER execute OK, only message 'unable to read MBR.sys' but i can't save log.


DDS log:

DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.18702
Run by raul at 22:25:41 on 2012-01-25
Microsoft Windows XP Professional 5.1.2600.3.1252.34.3082.18.3327.3014 [GMT 1:00]
AV: AntiVir Desktop *Enabled/Outdated* {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k netsvcs
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.es/
uInternet Connection Wizard,ShellNext = hxxp://$c
uInternet Settings,ProxyOverride = *.local
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\archivos de programa\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\archiv~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\archivos de programa\java\jre6\bin\ssv.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\archivos de programa\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\archivos de programa\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\archivos de programa\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SpybotSD TeaTimer] c:\archivos de programa\spybot - search & destroy\TeaTimer.exe
uRun: [swg] c:\archivos de programa\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
uRun: [KiesPDLR] c:\archivos de programa\samsung\kies\external\firmwareupdate\KiesPDLR.exe
mRun: [Six Engine] "c:\archivos de programa\asus\six engine\SixEngine.exe" -r
mRun: [Alcmtr] ALCMTR.EXE
mRun: [RegistrarUsrDNIeCertStoreDLL] c:\windows\system32\udcs.exe
mRun: [RegistrarCeresCertStoreDLL] c:\fnmt-rcm\uccs.exe
mRun: [<NO NAME>]
mRun: [avgnt] "c:\archivos de programa\avira\antivir desktop\avgnt.exe" /min
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit -login
mRun: [nwiz] c:\archivos de programa\nvidia corporation\nview\nwiz.exe /installquiet
mRun: [KiesHelper] c:\archivos de programa\samsung\kies\KiesHelper.exe /s
mRun: [KiesTrayAgent] c:\archivos de programa\samsung\kies\KiesTrayAgent.exe
mRun: [APSDaemon] "c:\archivos de programa\archivos comunes\apple\apple application support\APSDaemon.exe"
mRun: [QuickTime Task] "c:\archivos de programa\quicktime\qttask.exe" -atboottime
mRun: [ASUS Ai Charger] c:\archivos de programa\asus\asus ai charger\AiChargerAP.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [iTunesHelper] "c:\archivos de programa\itunes\iTunesHelper.exe"
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
IE: E&xportar a Microsoft Excel - c:\archiv~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\archivos de programa\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\archiv~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\archiv~1\spybot~1\SDHelper.dll
Trusted Zone: fnmt.es\www.cert
Trusted Zone: gob.es\agenciatributaria
DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {2DAB6EF1-66C3-427C-87CD-8DC448C47EAE} - hxxps://www5.aeat.es/es13/h/tgvicab.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1259949461890
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
DPF: {947B00D2-962D-4A35-9E48-98EE6A442B41} - hxxps://www1.agenciatributaria.gob.es/ADUA/internet/aded1503.cab
DPF: {A996E48C-D3DC-4244-89F7-AFA33EC60679} - hxxps://www.cert.fnmt.es/content/pages_std/ficheros_apps_usuarios/capicom.cab
DPF: {B785FA3C-1DE9-4D20-8396-613C486FE95E} - hxxps://www1.agenciatributaria.gob.es/es13/h/cactivex.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer =
TCP: Interfaces\{2E61F128-25D8-46B4-89BB-27606548353D} : NameServer =,
TCP: Interfaces\{2E61F128-25D8-46B4-89BB-27606548353D} : DhcpNameServer =
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
Hosts: www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R0 AiCharger;ASUS Charger Driver;c:\windows\system32\drivers\AiCharger.sys [2011-11-28 13224]
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2008-6-10 150568]
R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\drivers\VBoxNetAdp.sys [2009-12-17 99152]
R3 VBoxNetFlt;VBoxNetFlt Service;c:\windows\system32\drivers\VBoxNetFlt.sys [2009-12-17 110096]
S0 dfuqnlo;dfuqnlo;c:\windows\system32\drivers\hxsn.sys --> c:\windows\system32\drivers\hxsn.sys [?]
S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-5-15 28552]
S1 avgio;avgio;c:\archivos de programa\avira\antivir desktop\avgio.sys [2010-11-8 11608]
S1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2010-2-4 123280]
S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2010-2-4 41616]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\archivos de programa\avira\antivir desktop\sched.exe [2010-11-8 136360]
S2 AntiVirService;Avira AntiVir Guard;c:\archivos de programa\avira\antivir desktop\avguard.exe [2010-11-8 269480]
S2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-4-30 66616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate1c9e5f46834d5a6;Servicio Google Update (gupdate1c9e5f46834d5a6);c:\archivos de programa\google\update\GoogleUpdate.exe [2009-6-5 133104]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\archivos de programa\nvidia corporation\nvidia updatus\daemonu.exe [2011-10-24 2214504]
S3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\drivers\ssadadb.sys [2011-11-10 30312]
S3 gupdatem;Servicio de Google Update (gupdatem);c:\archivos de programa\google\update\GoogleUpdate.exe [2009-6-5 133104]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version;c:\windows\system32\drivers\libusb0.sys [2011-11-29 28160]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-1-24 40776]
S3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys [2011-11-15 16472]
S3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys [2011-11-15 11104]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\drivers\ssadbus.sys [2011-11-10 121064]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\drivers\ssadmdfl.sys [2011-11-10 12776]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\drivers\ssadmdm.sys [2011-11-10 136808]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\drivers\ssadserd.sys [2011-11-10 114280]
S3 TrojanKillerDriver;GridinSoft Trojan Killer Driver;c:\windows\system32\drivers\gtkdrv.sys [2012-1-4 16128]
S3 TrufosAlt;TrufosAlt;c:\windows\system32\drivers\TrufosAlt.sys [2012-1-25 309320]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2008-4-14 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2012-01-26 01:29:37 -------- d-----w- c:\windows\Microsoft Antimalware
2012-01-26 01:29:20 -------- d-----w- c:\windows\Windows Defender Offline
2012-01-25 16:03:21 -------- d-----w- C:\m5
2012-01-25 16:02:55 309320 ----a-w- c:\windows\system32\drivers\TrufosAlt.sys
2012-01-25 15:57:20 -------- d-----w- C:\m4
2012-01-24 22:17:57 -------- d--h--w- c:\archivos de programa\GridinSoft Trojan Killer
2012-01-24 22:09:23 -------- d-----w- C:\m3
2012-01-24 22:06:37 -------- d--h--w- c:\archivos de programa\Malwarebytes' Anti-Malware
2012-01-24 21:39:01 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-01-24 21:38:51 20464 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-24 21:38:03 10847608 ----a-w- C:\mbam-setup-
2012-01-24 16:35:06 -------- d-----w- C:\M2
2012-01-24 15:05:38 -------- d-----w- C:\Malwarebytes' Anti-Malware
2012-01-06 21:28:28 -------- d-----w- C:\ipadfotos
2012-01-04 14:28:36 16128 ----a-w- c:\windows\system32\drivers\gtkdrv.sys
2012-01-01 22:05:34 -------- d-----w- C:\eclipse
2012-01-01 21:33:57 -------- d--h--w- c:\documents and settings\raul\.android
2012-01-01 21:33:34 -------- d--h--w- c:\archivos de programa\Android
2012-01-01 20:57:10 -------- d--h--w- c:\documents and settings\raul\datos de programa\NVIDIA
2011-12-31 16:35:38 2106216 ----a-w- c:\windows\system32\D3DCompiler_43.dll
2011-12-31 16:35:38 1998168 ----a-w- c:\windows\system32\D3DX9_43.dll
2011-12-31 16:35:21 -------- d-----w- c:\windows\Logs
2011-12-31 16:17:25 -------- d--h--w- c:\archivos de programa\RailSimulator.com
==================== Find3M ====================
2011-10-31 10:22:56 4659712 ----a-w- c:\windows\system32\Redemption.dll
2011-10-31 10:22:42 90112 ----a-w- c:\windows\MAMCityDownload.ocx
2011-10-31 10:22:42 325552 ----a-w- c:\windows\MASetupCaller.dll
2011-10-31 10:22:42 30568 ----a-w- c:\windows\MusiccityDownload.exe
2011-10-31 10:22:36 821824 ----a-w- c:\windows\system32\dgderapi.dll
2011-10-31 10:22:36 319456 ----a-w- c:\windows\system32\DIFxAPI.dll
2011-10-31 10:22:36 20032 ----a-w- c:\windows\system32\drivers\dgderdrv.sys
============= FINISH: 22:26:43,53 ===============

#2 myrti



Posted 29 January 2012 - 10:15 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.
If you are unable to create a log because your computer cannot start up successfully please provide detailed information about the Windows version you are using: What we in particular need to know is version, edition and if it is a 32bit or a 64bit system. [/b]
If you are unsure about any of these caracteristics, just let us know and we'll help you figuring it out. Please also tell us if you have your Windows CD/DVD handy.

Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.
We need to create an OTL Report
  • Please download OTL from one of the following mirrors:
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • In the custom scan box paste the following:
  • Push the Posted Image button.
  • Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt<--Will be minimized

In the upper right hand corner of the topic you will see a button called Watch Topic.I suggest you click it and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

regards myrti

#3 raulvola

Posted 01 February 2012 - 05:01 AM

Finally i formatted the computer.

The worst infection i ever seen.

Please close this topic.

Best regards


Posted 01 February 2012 - 04:37 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

