Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

DDS Log file after trojan downloader virus detected and removed by MSE


  • This topic is locked This topic is locked
18 replies to this topic

#1 Aberk

Aberk

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 23 May 2012 - 12:20 PM

I hope I am posting this in the right place this time...

Microsoft Security Essentials found a trojan downloader virus, and supposedly removed it. But I wonder if I am still infected...

Here is the DDS notepad log...

I have deleted what I think might be personal information and replaced it with this symbol: [!]


.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: [!] BrowserJavaVersion: 1.6.0_31
Run by [!] at 9:42:53 on 2012-05-23
Microsoft® Windows Vista™ Home Basic [!] [GMT -7:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Microsoft Security Essentials *Enabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\alg.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\system32\vssvc.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\DllHost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\System32\mobsync.exe
C:\Program Files\Cricket\Cricket Broadband 1.0\Cricket Broadband.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://my.juno.com/s/search?r=minisearch
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
uDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T3646
uSearch Bar = hxxp://my.juno.com/s/search?r=minisearch
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T3646
mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T3646
mDefault_Search_URL = hxxp://my.netzero.net/s/search?r=minisearch
mSearch Page = hxxp://my.netzero.net/s/search?r=minisearch
uSearchURL,(Default) = hxxp://my.juno.com/s/search?r=minisearch
mSearchAssistant = hxxp://my.netzero.net/s/search?r=minisearch
uURLSearchHooks: URLSearchHook Class: {37d2cdbf-2af4-44aa-8113-bd0d2da3c2b8} - c:\program files\juno\SearchEnh1.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Pop-up Blocker: {52706ef7-d7a2-49ad-a615-e903858cf284} - c:\program files\juno\qsacc\X1IEBHO.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\windows\system32\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
TB: ZeroBar: {f0f8ecbe-d460-4b34-b007-56a92e8f84a7} - c:\program files\netzero\Toolbar.dll
TB: JunoBar: {5854fac4-5bf0-47dd-b5a9-a5ea8cff3cf4} - c:\program files\juno\Toolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [Juno_uoltray] c:\program files\juno\exec.exe regrun
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /minimized /regrun
uRun: [Google Update] "c:\users\kleinman\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Skytel] Skytel.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [NapsterShell] c:\program files\napster\napster.exe /systray
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
StartupFolder: c:\users\[!]\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\bigfix.lnk - c:\program files\bigfix\bigfix.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Display All Images with Full Quality - "c:\program files\juno\qsacc\appres.dll/228"
IE: Display Image with Full Quality - "c:\program files\juno\qsacc\appres.dll/227"
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Trusted Zone: juno.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
TCP: Interfaces\{23E276F1-429E-4BC4-B6F4-45546D63B2A8} : NameServer = 10.133.20.11 10.132.20.11
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\[!]\appdata\roaming\mozilla\firefox\profiles\08ohaqrs.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\amazon\mp3 downloader\npAmazonMP3DownloaderPlugin.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll
FF - plugin: c:\users\[!]\appdata\local\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\users\[!]\appdata\roaming\mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\users\[!]\appdata\roaming\mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2012-3-20 171064]
R1 MpKsl36393188;MpKsl36393188;c:\programdata\microsoft\microsoft antimalware\definition updates\{66420a21-e69f-4790-b9dc-6bf586cdfce3}\MpKsl36393188.sys [2012-5-20 29904]
R1 MpKslc0491d16;MpKslc0491d16;c:\programdata\microsoft\microsoft antimalware\definition updates\{a9180fa1-1d57-43b4-b619-66518928e8d3}\MpKslc0491d16.sys [2012-5-23 29904]
R3 ATMFBUS;A600 USB Composite Device Driver;c:\windows\system32\drivers\ATMFBUS.sys [2010-1-13 47360]
R3 ATMFCVsp;A600 Cricket CM Port;c:\windows\system32\drivers\ATMFCVsp.sys [2010-1-13 153600]
R3 ATMFMdm;A600 Cricket EVDO Modem;c:\windows\system32\drivers\ATMFMdm.sys [2010-1-13 153472]
R3 ATMFNET;A600 Cricket EVDO Network Adapter;c:\windows\system32\drivers\ATMFNET.sys [2010-1-13 103424]
R3 ATMFNVsp;A600 Cricket NMEA Port Serial Port;c:\windows\system32\drivers\ATMFNVsp.sys [2010-1-13 153600]
R3 ATMFVsp;A600 Cricket Diagnostics Port;c:\windows\system32\drivers\ATMFVsp.sys [2010-1-13 153472]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2012-5-23 40776]
S3 ATMFFLT;A600 USB Modem Installation CD;c:\windows\system32\drivers\ATMFFLT.sys [2010-1-13 13312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-1-20 179712]
S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2012-3-20 74112]
.
=============== Created Last 30 ================
.
2012-05-23 16:13:32 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-05-23 14:06:00 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9180fa1-1d57-43b4-b619-66518928e8d3}\offreg.dll
2012-05-23 14:06:00 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9180fa1-1d57-43b4-b619-66518928e8d3}\MpKslc0491d16.sys
2012-05-23 13:34:12 6737808 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{a9180fa1-1d57-43b4-b619-66518928e8d3}\mpengine.dll
2012-05-20 20:06:18 29904 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{66420a21-e69f-4790-b9dc-6bf586cdfce3}\MpKsl36393188.sys
2012-05-20 20:06:17 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{66420a21-e69f-4790-b9dc-6bf586cdfce3}\offreg.dll
2012-05-20 14:43:01 6737808 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-05-20 14:43:01 6737808 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{66420a21-e69f-4790-b9dc-6bf586cdfce3}\mpengine.dll
2012-05-19 14:25:11 -------- d-----w- c:\program files\Microsoft Small Business
2012-05-19 14:20:11 -------- d-----w- c:\program files\Microsoft SQL Server
2012-05-19 14:06:04 -------- d-----w- c:\users\[!]\appdata\local\Microsoft Help
2012-05-15 17:53:34 -------- d-s---w- c:\users\[!]\Google Drive
2012-04-26 21:21:42 -------- d-----w- c:\users\[!]\dwhelper
2012-04-26 20:44:38 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{763d2b67-acdc-42fc-8372-af6de64c99bc}\gapaengine.dll
2012-04-26 20:17:35 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-26 20:17:35 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-04-26 20:17:35 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-26 20:17:34 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-26 19:57:48 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-26 19:57:44 157352 ----a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-04-26 19:57:44 129976 ----a-w- c:\program files\mozilla firefox\maintenanceservice.exe
.
==================== Find3M ====================
.
2012-05-05 18:12:38 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-05-05 18:12:38 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-26 20:11:55 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-04 22:56:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-21 03:44:12 74112 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-21 03:44:12 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
============= FINISH: 9:44:34.46 ===============

BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:05:13 PM

Posted 23 May 2012 - 12:23 PM

Hello and Welcome to Bleeping Computer!!

My name is Gringo and I'll be glad to help you with your computer problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of hartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.

Security Check

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.



Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 23 May 2012 - 12:37 PM

Okay, I will do that.

Here is the log from Malwarebytes...

Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.05.23.05

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421


5/23/2012 9:15:00 AM
mbam-log-2012-05-23 (09-15-00).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 327593
Time elapsed: 1 hour(s), 16 minute(s), 43 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)

#4 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 23 May 2012 - 12:39 PM

Results of screen317's Security Check version 0.99.34
Windows Vista Service Pack 2 x86 (UAC is enabled)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
Microsoft Security Essentials
WMI entry may not exist for antivirus; attempting automatic update.
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes Anti-Malware version 1.61.0.1400
Java™ 6 Update 31
Java version out of date!
Adobe Flash Player 11.2.202.235
Adobe Reader X (10.1.3)
Mozilla Firefox (12.0)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
``````````End of Log````````````

#5 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:05:13 PM

Posted 23 May 2012 - 12:56 PM

OK I will be waiting for the combofix report


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#6 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 23 May 2012 - 01:17 PM

ComboFix 12-05-23.05 - Kleinman 05/23/2012 10:48:47.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.895.251 [GMT -7:00]
Running from: c:\users\Kleinman\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\_ctypes.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\_elementtree.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\_hashlib.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\_socket.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\_ssl.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\pyexpat.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\pysqlite2._sqlite.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\python26.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\pythoncom26.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\PyWinTypes26.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\select.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32api.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32com.shell.shell.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32crypt.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32event.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32file.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32gui.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32inet.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\win32process.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._controls_.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._core_.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._gdi_.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._html2.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._misc_.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._windows_.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wx._wizard.pyd
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wxbase293u_net_vc.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wxbase293u_vc.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wxmsw293u_adv_vc.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wxmsw293u_core_vc.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wxmsw293u_html_vc.dll
c:\users\Kleinman\AppData\Local\Temp\_MEI34922\wxmsw293u_webview_vc.dll
c:\windows\system32\drivers\etc\hosts.ics
D:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2012-04-23 to 2012-05-23 )))))))))))))))))))))))))))))))
.
.
2012-05-23 17:56 . 2012-05-23 17:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-05-23 14:06 . 2012-05-23 14:06 29904 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9180FA1-1D57-43B4-B619-66518928E8D3}\MpKslc0491d16.sys
2012-05-23 14:06 . 2012-05-23 14:06 56200 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9180FA1-1D57-43B4-B619-66518928E8D3}\offreg.dll
2012-05-23 13:34 . 2012-05-08 16:40 6737808 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9180FA1-1D57-43B4-B619-66518928E8D3}\mpengine.dll
2012-05-20 14:43 . 2012-05-08 16:40 6737808 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-19 14:25 . 2012-05-19 14:31 -------- d-----w- c:\program files\Microsoft Small Business
2012-05-19 14:20 . 2012-05-19 14:22 -------- d-----w- c:\program files\Microsoft SQL Server
2012-05-19 14:06 . 2012-05-19 14:06 -------- d-----w- c:\users\Kleinman\AppData\Local\Microsoft Help
2012-05-15 17:53 . 2012-05-20 13:49 -------- d-s---w- c:\users\Kleinman\Google Drive
2012-04-26 21:21 . 2012-05-17 16:12 -------- d-----w- c:\users\Kleinman\dwhelper
2012-04-26 20:44 . 2012-04-26 20:35 713784 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{763D2B67-ACDC-42FC-8372-AF6DE64C99BC}\gapaengine.dll
2012-04-26 20:17 . 2012-02-29 15:11 5120 ----a-w- c:\windows\system32\wmi.dll
2012-04-26 20:17 . 2012-02-29 15:11 172032 ----a-w- c:\windows\system32\wintrust.dll
2012-04-26 20:17 . 2012-02-29 15:09 157696 ----a-w- c:\windows\system32\imagehlp.dll
2012-04-26 20:17 . 2012-02-29 13:32 12800 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2012-04-26 20:13 . 2012-04-26 20:13 -------- d-----w- c:\program files\Common Files\Java
2012-04-26 19:57 . 2012-04-26 19:57 -------- d-----w- c:\program files\Mozilla Maintenance Service
2012-04-26 19:57 . 2012-04-26 19:57 157352 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice_installer.exe
2012-04-26 19:57 . 2012-04-26 19:57 129976 ----a-w- c:\program files\Mozilla Firefox\maintenanceservice.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-05-05 18:12 . 2012-04-13 16:10 419488 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-05-05 18:12 . 2011-06-13 13:45 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-26 20:11 . 2010-05-07 20:28 472808 ----a-w- c:\windows\system32\deployJava1.dll
2012-04-04 22:56 . 2012-03-14 17:40 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-03-21 03:44 . 2012-03-21 03:44 74112 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-03-21 03:44 . 2012-03-21 03:44 171064 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-03-01 20:34 . 2012-03-14 16:04 6552120 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F174D2EC-ACB5-4DF4-9A41-695DE89B5ED4}\mpengine.dll
2012-04-26 19:57 . 2012-03-12 17:17 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-05-03 01:31 579072 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-05-03 01:31 579072 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-05-03 01:31 579072 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-05-03 01:31 579072 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Juno_uoltray"="c:\program files\Juno\exec.exe" [2006-10-21 1624064]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"AnyDVD"="c:\program files\SlySoft\AnyDVD\AnyDVDtray.exe" [2010-10-02 4537280]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-02-29 17148552]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-05-03 11396840]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-12-12 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-12 8530464]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-12 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2007-09-19 4702208]
"Skytel"="Skytel.exe" [2007-08-03 1826816]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-12-07 69216]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-08-26 30192]
"NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-27 931200]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2008-01-19 40072]
.
c:\users\Kleinman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2006-10-26 98632]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
BigFix.lnk - c:\program files\BigFix\bigfix.exe [2008-2-26 2342912]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-05 257696]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-05-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-13 18:12]
.
2012-05-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 20:50]
.
2012-05-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-13 20:50]
.
2012-05-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212098578-3481688397-481139802-1000Core.job
- c:\users\Kleinman\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-11 18:08]
.
2012-05-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1212098578-3481688397-481139802-1000UA.job
- c:\users\Kleinman\AppData\Local\Google\Update\GoogleUpdate.exe [2012-05-11 18:08]
.
.
------- Supplementary Scan -------
.
uStart Page = https://login.yahoo.com/config/login_verify2?&.src=ym
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=T3646
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://my.juno.com/s/search?r=minisearch
IE: Display All Images with Full Quality - "c:\program files\Juno\qsacc\appres.dll/228"
IE: Display Image with Full Quality - "c:\program files\Juno\qsacc\appres.dll/227"
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
Trusted Zone: juno.com
FF - ProfilePath - c:\users\Kleinman\AppData\Roaming\Mozilla\Firefox\Profiles\08ohaqrs.default\
FF - prefs.js: browser.startup.homepage - www.google.com
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-05-23 11:00
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(492)
c:\program files\SlySoft\AnyDVD\ADvdDiscHlp.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\System32\rundll32.exe
c:\windows\RtHDVCpl.exe
c:\windows\System32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2012-05-23 11:05:29 - machine was rebooted
ComboFix-quarantined-files.txt 2012-05-23 18:05
.
Pre-Run: 69,004,771,328 bytes free
Post-Run: 68,917,940,224 bytes free
.
- - End Of File - - 0C7D9D80BF3145895EFCED71E94B776A

#7 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 23 May 2012 - 01:20 PM

After combofix finished, I am now having this error message appear when I try to double click on the Firefox icon to get on the internet:

C;\Program Files/Mozilla Firefox/firefox.exe
Illegal operation attempted on a registry key that has been marked for deletion.

I had to right click on the Firefox icon on the desktop and then click on run as Administrator to get it to open and work.

How do I fix this problem?

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:05:13 PM

Posted 23 May 2012 - 01:47 PM

read note 2 from the combofix instructions and restart the computer


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 23 May 2012 - 02:47 PM

Thanks. Double clicking Firefox works again.

Out of curiosity, what were all the files combofix deleted? Were they viruses? Do you think any more viruses are still lurking on this computer?

Edited by Aberk, 23 May 2012 - 02:48 PM.


#10 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:05:13 PM

Posted 23 May 2012 - 08:47 PM

Greetings

I want you to run these next,

tdsskiller:

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to your Desktop.
  • doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • it will ask to download extra definitions - ALLOW IT
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and aswMBR

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#11 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 24 May 2012 - 08:37 AM

0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-05-24 06:10:22
-----------------------------
06:10:22.555 OS Version: Windows 6.0.6002 Service Pack 2
06:10:22.555 Number of processors: 1 586 0x7F02
06:10:22.556 ComputerName: KLEINMAN-PC UserName: Kleinman
06:10:33.692 Initialize success
06:16:43.578 AVAST engine defs: 12052400
06:16:59.369 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005d
06:16:59.387 Disk 0 Vendor: ST316081 4.AA Size: 152627MB BusType: 6
06:16:59.421 Disk 0 MBR read successfully
06:16:59.425 Disk 0 MBR scan
06:16:59.782 Disk 0 Windows VISTA default MBR code
06:16:59.822 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 9781 MB offset 63
06:16:59.854 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 142843 MB offset 20033055
06:16:59.898 Disk 0 scanning sectors +312576705
06:17:00.018 Disk 0 scanning C:\Windows\system32\drivers
06:17:36.452 Service scanning
06:17:54.107 Service MpKsl4d523197 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{271A910F-A88A-492F-8CAA-6B1282EA8B62}\MpKsl4d523197.sys **LOCKED** 32
06:18:27.093 Modules scanning
06:18:48.995 Disk 0 trace - called modules:
06:18:49.017 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys
06:18:49.017 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x847896b8]
06:18:49.017 3 CLASSPNP.SYS[863a68b3] -> nt!IofCallDriver -> [0x8389ba60]
06:18:49.017 5 acpi.sys[8060d6bc] -> nt!IofCallDriver -> \Device\0000005d[0x84216b88]
06:18:50.037 AVAST engine scan C:\Windows
06:18:56.135 AVAST engine scan C:\Windows\system32
06:24:09.355 AVAST engine scan C:\Windows\system32\drivers
06:24:36.962 AVAST engine scan C:\Users\Kleinman
06:32:44.186 AVAST engine scan C:\ProgramData
06:34:16.644 Scan finished successfully
06:34:58.206 Disk 0 MBR has been saved successfully to "C:\Users\Kleinman\Desktop\MBR.dat"
06:34:58.296 The log file has been saved successfully to "C:\Users\Kleinman\Desktop\aswMBR.txt"

#12 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 24 May 2012 - 08:39 AM

I also ran TDSS Killer, but it wouldn't let me copy and paste the report using the right click feature on my mouse.

Here's what the main page said:

No Threats Found

Duration: :45

Processed: 392 Objects

Found: 0 Threats

Neutralized: 0 Threats

Quarantined: 0 Objects

#13 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:05:13 PM

Posted 24 May 2012 - 11:35 AM

Greetings

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Open Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

Save it to your desktop as CFScript.txt

Refering to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#14 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:05:13 PM

Posted 27 May 2012 - 06:25 AM

Greetings


I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools




Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#15 Aberk

Aberk
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Local time:02:13 PM

Posted 27 May 2012 - 02:29 PM

I'm sorry about that. I ran out of bandwidth from all the downloading involved, and so my internet connection has been throttled down to a snail's pace, making it very frustrating for me to do anything on the internet right now. I will send you a private message once Cricket Broadband restores my internet account to full broadband capabilities. I think it will be about a week or two before they do that.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users