Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Trojan.BCMiner and ZAccess


  • This topic is locked This topic is locked
12 replies to this topic

#1 phroz

phroz

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 13 August 2012 - 10:03 AM

I get redirects from google and eventually my computer won't let me start any other programs. I've tried to get rid of this myself, but seem to have made no progress. Any help would be appreciated.


.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_26
Run by m2mj at 7:39:52 on 2012-08-13
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3061.2371 [GMT -7:00]
.
AV: AVG Anti-Virus Free *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\System32\svchost.exe" -k LocalServiceDns
C:\Windows\system32\conhost.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://companyweb
uDefault_Page_URL = hxxp://companyweb
uURLSearchHooks: H - No File
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
mURLSearchHooks: H - No File
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: PlusIEEventHelper Class: {551a852f-39a6-44a7-9c13-afbec9185a9d} - c:\program files\nuance\pdf viewer plus\bin\PlusIEContextMenu.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.7.7725.1624\swg.dll
BHO: Bing Bar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\microsoft\bingbar\7.1.382.0\BingExt.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn\YTSingleInstance.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Bing Bar: {8dcb7100-df86-4384-8842-8fa844297b3f} - "c:\program files\microsoft\bingbar\7.1.382.0\BingExt.dll"
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
{e7df6bff-55a5-4eb7-a673-4ed3e9456d39}
EB: iOpus iMacros: {0483894e-2422-45e0-8384-021aff1af3cd} - c:\program files\imacros\imacros.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [cdloader] "c:\users\m2mj\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK
uRun: [GoogleDriveSync] "c:\program files\google\drive\googledrivesync.exe" /autostart
uRun: [PaperPortAnywhere] "c:\program files\nuance\paperport anywhere\PaperPortAnywhere.exe"
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [NetFxUpdate_v1.1.4322] "c:\windows\microsoft.net\framework\v1.1.4322\netfxupdate.exe" 1 v1.1.4322 GAC + NI NID
mRun: [Sprint SmartView] "c:\program files\sprint\sprint smartview\SprintSV.exe" -a
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [hpqSRMon] c:\program files\hp\digital imaging\bin\hpqSRMon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [dlebmon.exe] "c:\program files\dell p513w\dlebmon.exe"
mRun: [EzPrint] "c:\program files\dell p513w\ezprint.exe"
mRun: [LogMeIn Hamachi Ui] "c:\program files\logmein hamachi\hamachi-2-ui.exe" --auto-start
mRun: [ISUSPM] c:\programdata\flexnet\connect\11\\isuspm.exe -scheduler
mRun: [PaperPort PTD] "c:\program files\nuance\paperport\pptd40nt.exe"
mRun: [IndexSearch] "c:\program files\nuance\paperport\IndexSearch.exe"
mRun: [PPort14reminder] "c:\program files\nuance\paperport\ereg\ereg.exe" -r "c:\programdata\scansoft\paperport\14\config\ereg\Ereg.ini"
mRun: [PDFProHook] c:\program files\nuance\pdf viewer plus\pdfpro7hook.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
StartupFolder: c:\users\m2mj\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\netgea~1.lnk - c:\program files\netgear\wg111v3\WG111v3.exe
uPolicies-system: ConnectHomeDirToRoot = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
IE: Open with PDF Viewer 7 - c:\program files\nuance\pdf viewer plus\bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
IE: {0483894E-2422-45E0-8384-021AFF1AF3CD} - {0483894E-2422-45E0-8384-021AFF1AF3CD} - c:\program files\imacros\imacros.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://qb.webex.com/client/v_mywebex-qb20/ra/ieatgpc1.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
TCP: Interfaces\{4B8F20E6-C392-400F-97E2-8076DACECE4A} : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
TCP: Interfaces\{4B8F20E6-C392-400F-97E2-8076DACECE4A}\2596368644F66756D27657563747 : DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.33.1
TCP: Interfaces\{E79BDB9E-1B29-4F80-A556-A1F71054F0E7} : DhcpNameServer = 209.18.47.61 209.18.47.62
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: avgrsstx.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\m2mj\appdata\roaming\mozilla\firefox\profiles\suckz8s2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B5da29a4d-e037-482c-b0dd-d42d54a397a8%7D&mid=628dcd2654d2cd6f0c47e84e378dc9c8-57087d0cee5ea2042e08339ba583dc1963f58809&ds=AVG&v=10.2.0.3&lang=us&pr=fr&d=2012-04-04%2018%3A38%3A59&sap=ku&q=
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\common files\avg secure search\sitesafetyinstaller\11.2.0\npsitesafety.dll
FF - plugin: c:\program files\google\update\1.3.21.115\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll
FF - plugin: c:\program files\nuance\pdf viewer plus\bin\nppdf.dll
FF - plugin: c:\program files\nuance\pdf viewer plus\bin\nppdf.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
.
============= SERVICES / DRIVERS ===============
.
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-1-2 243152]
R1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\drivers\vwififlt.sys [2009-7-13 48128]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\logmein hamachi\hamachi-2.exe [2012-6-27 1385896]
R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2009-12-9 273448]
R3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\drivers\wg111v3.sys [2012-4-5 376832]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-1-2 216400]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-1-2 29712]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-7-15 921952]
S2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136]
S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.382.0\BBSvc.EXE [2012-4-16 193616]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-5-24 21992]
S2 dleb_device;dleb_device;c:\windows\system32\dlebcoms.exe -service --> c:\windows\system32\dlebcoms.exe -service [?]
S2 dlebCATSCustConnectService;dlebCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\dlebserv.exe [2009-7-1 98984]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-2 135664]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files\nuance\paperport\PDFProFiltSrvPP.exe [2011-10-28 219496]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-8 250056]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.382.0\SeaPort.EXE [2012-4-16 240208]
S3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\common files\bcl technologies\easypdf 5\bepldr.exe [2006-11-14 147456]
S3 CASprint;Sprint Con App Svc;c:\program files\sprint\sprint smartview\ConAppsSvc.exe [2008-3-5 118784]
S3 ExpressAccountsService;Express Accounts;c:\program files\nch software\expressaccounts\expressaccounts.exe [2012-5-20 3081220]
S3 ExpressInvoiceService;Express Invoice;c:\program files\nch software\expressinvoice\expressinvoice.exe [2012-5-20 2041860]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-2 135664]
S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-9 52224]
.
=============== Created Last 30 ================
.
2012-08-11 01:06:05 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-09 04:12:54 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-08-02 07:50:55 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2012-08-02 07:50:42 -------- d-----w- c:\programdata\FUJIFILM
2012-08-02 07:50:33 -------- d-----w- c:\program files\FUJIFILM
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2012-08-02 07:46:18 159744 ----a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2012-08-02 07:45:30 -------- d-----w- c:\users\m2mj\appdata\local\Apple
2012-07-14 19:51:50 -------- d-----w- c:\users\m2mj\appdata\roaming\Zeon
2012-07-14 19:43:58 -------- d-----w- c:\users\m2mj\My PaperPort.com
2012-07-14 19:31:29 -------- d-----w- c:\users\m2mj\appdata\local\OfficeDrop
2012-07-14 19:31:18 -------- d-----w- c:\programdata\Tarma Installer
2012-07-14 19:30:08 -------- d-----w- c:\programdata\Zeon
2012-07-14 19:04:40 -------- d-----w- c:\users\m2mj\appdata\roaming\Nuance
2012-07-14 19:04:18 -------- d-----w- c:\users\m2mj\appdata\roaming\.oit
2012-07-14 19:03:37 -------- d-----w- c:\windows\PIXTRAN
2012-07-14 19:03:32 -------- d-----w- c:\program files\common files\ScanSoft Shared
2012-07-14 19:03:31 -------- d-----w- c:\programdata\Nuance
2012-07-14 19:03:31 -------- d-----w- c:\program files\Nuance
.
==================== Find3M ====================
.
2012-08-03 00:56:16 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-03 00:56:16 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-03 20:46:44 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 7:39:59.43 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 10:57 AM

Please run the following

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ---------------------------------------------------------------------------------------------
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.

    ---------------------------------------------------------------------------------------------

NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#3 phroz

phroz
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 13 August 2012 - 11:41 AM

Here's the log from ComboFix.


ComboFix 12-08-13.01 - m2mj 08/13/2012 9:30.1.2 - x86
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3061.1924 [GMT -7:00]
Running from: c:\users\m2mj\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Anti-Virus Free *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\m2mj\AppData\Local\Temp\_MEI28282\_ctypes.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\_elementtree.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\_hashlib.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\_socket.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\_ssl.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\pyexpat.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\pysqlite2._sqlite.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\python26.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\pythoncom26.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\PyWinTypes26.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\select.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\unicodedata.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32api.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32com.shell.shell.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32crypt.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32event.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32file.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32inet.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32pdh.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\win32process.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\windows._cacheinvalidation.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._controls_.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._core_.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._gdi_.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._html2.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._misc_.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._windows_.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wx._wizard.pyd
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wxbase293u_net_vc.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wxbase293u_vc.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wxmsw293u_adv_vc.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wxmsw293u_core_vc.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wxmsw293u_html_vc.dll
c:\users\m2mj\AppData\Local\Temp\_MEI28282\wxmsw293u_webview_vc.dll
c:\users\m2mj\AppData\Roaming\.#
C:\WinDir
c:\windir\Addins\NitroPDF.ppa
c:\windir\Startup\NitroPDF.dot
c:\windir\XLStart\NitroPDF.xla
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\@
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\L\00000004.@
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\L\201d3dde
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\00000004.@
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\00000008.@
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\000000cb.@
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\80000000.@
c:\windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\80000032.@
c:\windows\system32\URTTemp
c:\windows\system32\URTTemp\regtlib.exe
.
Infected copy of c:\windows\system32\services.exe was found and disinfected
Restored copy from - c:\32788r22fwjfw\HarddiskVolumeShadowCopy9_!Windows!System32!services.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-07-13 to 2012-08-13 )))))))))))))))))))))))))))))))
.
.
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\WCPM\AppData\Local\temp
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\jbraun\AppData\Local\temp
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\jabraun\AppData\Local\temp
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\gary\AppData\Local\temp
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2012-08-13 16:37 . 2012-08-13 16:37 -------- d-----w- c:\users\admin\AppData\Local\temp
2012-08-11 01:06 . 2012-08-11 01:06 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-09 04:12 . 2012-08-09 04:12 -------- d-sh--w- c:\windows\system32\%APPDATA%
2012-08-04 16:07 . 2012-08-04 16:07 -------- d-----w- c:\users\Default\AppData\Local\Google
2012-08-02 07:50 . 2007-03-12 23:42 3495784 ----a-w- c:\windows\system32\d3dx9_33.dll
2012-08-02 07:50 . 2012-08-02 07:50 -------- d-----w- c:\programdata\FUJIFILM
2012-08-02 07:50 . 2012-08-02 07:50 -------- d-----w- c:\program files\FUJIFILM
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
2012-08-02 07:46 . 2012-08-02 07:46 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
2012-08-02 07:45 . 2012-08-02 07:46 -------- d-----w- c:\program files\QuickTime
2012-08-02 07:45 . 2012-08-02 07:45 -------- d-----w- c:\programdata\Apple Computer
2012-08-02 07:45 . 2012-08-02 07:45 -------- d-----w- c:\program files\Common Files\Apple
2012-08-02 07:45 . 2012-08-02 07:45 -------- d-----w- c:\users\m2mj\AppData\Local\Apple
2012-08-02 07:45 . 2012-08-02 07:45 -------- d-----w- c:\program files\Apple Software Update
2012-08-02 07:45 . 2012-08-02 07:45 -------- d-----w- c:\programdata\Apple
2012-07-14 19:51 . 2012-07-14 19:51 -------- d-----w- c:\users\m2mj\AppData\Roaming\Zeon
2012-07-14 19:43 . 2012-07-14 19:43 -------- d-----w- c:\users\m2mj\My PaperPort.com
2012-07-14 19:31 . 2012-08-02 08:58 -------- d-----w- c:\users\m2mj\AppData\Local\OfficeDrop
2012-07-14 19:31 . 2012-07-14 19:31 -------- d-----w- c:\programdata\Tarma Installer
2012-07-14 19:30 . 2012-07-14 19:30 -------- d-----w- c:\programdata\Zeon
2012-07-14 19:04 . 2012-07-14 19:51 -------- d-----w- c:\users\m2mj\AppData\Roaming\Nuance
2012-07-14 19:04 . 2012-07-15 14:33 -------- d-----w- c:\users\m2mj\AppData\Roaming\.oit
2012-07-14 19:04 . 2012-07-14 19:04 -------- d-----w- c:\programdata\ScanSoft
2012-07-14 19:03 . 2012-08-11 17:46 -------- d-----w- c:\windows\PIXTRAN
2012-07-14 19:03 . 2012-07-14 19:30 -------- d-----w- c:\program files\Common Files\ScanSoft Shared
2012-07-14 19:03 . 2012-07-14 20:21 -------- d-----w- c:\programdata\Nuance
2012-07-14 19:03 . 2012-07-14 19:31 -------- d-----w- c:\program files\Nuance
2012-07-14 19:03 . 2012-07-14 19:03 -------- d-----w- c:\programdata\Macrovision
2012-07-14 19:03 . 2012-07-14 19:03 -------- d-----w- c:\programdata\FLEXnet
2012-07-14 18:51 . 2012-07-14 18:51 -------- d-----w- c:\program files\Microsoft.NET
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-03 00:56 . 2012-05-08 14:17 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-03 00:56 . 2011-05-26 15:13 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-07-03 20:46 . 2011-05-24 19:39 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-04-14 16:26 . 2011-05-26 15:06 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveBlacklistedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSharedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncedOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\GDriveSyncingOverlay]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2012-07-20 22:17 556376 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-12-30 39408]
"cdloader"="c:\users\m2mj\AppData\Roaming\mjusbsp\cdloader2.exe" [2012-02-01 50592]
"GoogleDriveSync"="c:\program files\Google\Drive\googledrivesync.exe" [2012-07-20 12218904]
"PaperPortAnywhere"="c:\program files\Nuance\PaperPort Anywhere\PaperPortAnywhere.exe" [2011-10-20 2412032]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2009-04-23 1314816]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-18 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-18 173592]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-18 150552]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2012-04-05 2077536]
"NetFxUpdate_v1.1.4322"="c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe" [2004-08-11 106496]
"Sprint SmartView"="c:\program files\Sprint\Sprint SmartView\SprintSV.exe" [2008-03-10 17672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-23 150528]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"dlebmon.exe"="c:\program files\Dell P513w\dlebmon.exe" [2011-01-24 770728]
"EzPrint"="c:\program files\Dell P513w\ezprint.exe" [2011-01-24 139944]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
"ISUSPM"="c:\programdata\FLEXnet\Connect\11\\isuspm.exe" [2010-05-21 324976]
"PaperPort PTD"="c:\program files\Nuance\PaperPort\pptd40nt.exe" [2011-10-29 38824]
"IndexSearch"="c:\program files\Nuance\PaperPort\IndexSearch.exe" [2011-10-29 51120]
"PPort14reminder"="c:\program files\Nuance\PaperPort\Ereg\Ereg.exe" [2011-05-16 333088]
"PDFProHook"="c:\program files\Nuance\PDF Viewer Plus\pdfpro7hook.exe" [2011-07-01 607592]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-03-27 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]
.
c:\users\jabraun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\users\m2mj\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]
McAfee Security Scan Plus.lnk - c:\program files\McAfee Security Scan\2.0.181\SSScheduler.exe [2010-1-15 255536]
NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2009-11-6 2469888]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ConnectHomeDirToRoot"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
R3 BBUpdate;BBUpdate;c:\program files\Microsoft\BingBar\7.1.382.0\SeaPort.exe [x]
R3 bepldr;BCL easyPDF SDK 5 Loader;c:\program files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe [x]
R3 CASprint;Sprint Con App Svc;c:\program files\Sprint\Sprint SmartView\ConAppsSvc.exe [x]
R3 ExpressAccountsService;Express Accounts;c:\program files\NCH Software\ExpressAccounts\expressaccounts.exe [x]
R3 ExpressInvoiceService;Express Invoice;c:\program files\NCH Software\ExpressInvoice\expressinvoice.exe [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [x]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [x]
S1 AvgTdiX;AVG Free Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [x]
S2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [x]
S2 BBSvc;BingBar Service;c:\program files\Microsoft\BingBar\7.1.382.0\BBSvc.exe [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [x]
S2 dleb_device;dleb_device;c:\windows\system32\dlebcoms.exe [x]
S2 dlebCATSCustConnectService;dlebCATSCustConnectService;c:\windows\system32\spool\DRIVERS\W32X86\3\\dlebserv.exe [x]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [x]
S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files\Nuance\PaperPort\PDFProFiltSrvPP.exe [x]
S3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [x]
S3 RTL8187B;NETGEAR WG111v3 Wireless-G USB Adapter Win7 Driver;c:\windows\system32\DRIVERS\wg111v3.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
GPSvcGroup REG_MULTI_SZ GPSvc
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-05-08 00:56]
.
2012-08-13 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 01:27]
.
2012-08-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-02-03 01:27]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://companyweb
IE: Open with PDF Viewer 7 - c:\program files\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62 192.168.1.1
FF - ProfilePath - c:\users\m2mj\AppData\Roaming\Mozilla\Firefox\Profiles\suckz8s2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B5da29a4d-e037-482c-b0dd-d42d54a397a8%7D&mid=628dcd2654d2cd6f0c47e84e378dc9c8-57087d0cee5ea2042e08339ba583dc1963f58809&ds=AVG&v=10.2.0.3&lang=us&pr=fr&d=2012-04-04%2018%3A38%3A59&sap=ku&q=
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
Toolbar-Locked - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\spool\DRIVERS\W32X86\3\dlebserv.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\AVG\AVG9\avgtray.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\windows\system32\sppsvc.exe
c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2012-08-13 09:44:04 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-13 16:44
.
Pre-Run: 164,470,161,408 bytes free
Post-Run: 166,032,396,288 bytes free
.
- - End Of File - - 19516E5F55EF9B3292D276608856ADFF

#4 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 11:52 AM

looks better,

please run the following:

Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <-- very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Go here to run an online scanner from ESET.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activeX control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan completes, press the LIST OF THREATS FOUND button
  • Press EXPORT TO TEXT FILE , name the file ESETSCAN and save it to your desktop
  • Include the contents of this report in your next reply.
  • Press the BACK button.
  • Press Finish

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#5 phroz

phroz
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 13 August 2012 - 01:51 PM

Here are the logs

Malwarebytes Anti-Malware 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.13.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
m2mj :: WCPM-PC [administrator]

8/13/2012 10:07:14 AM
mbam-log-2012-08-13 (10-07-14).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 324668
Time elapsed: 7 minute(s), 23 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\assembly\GAC\Desktop.ini (Trojan.0access) -> Quarantined and deleted successfully.

(end)






C:\Qoobox\Quarantine\C\Windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\00000004.@.vir Win32/Conedex.D trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\000000cb.@.vir Win32/Conedex.E trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\80000000.@.vir a variant of Win32/Sirefef.FA trojan
C:\Qoobox\Quarantine\C\Windows\Installer\{bcaecf89-41c7-2c02-4c29-b63c82c4fbc4}\U\80000032.@.vir a variant of Win32/Sirefef.FD trojan
C:\Qoobox\Quarantine\C\Windows\System32\services.exe.vir Win32/Sirefef.FC trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0001.dta Win32/Olmarik.AYI trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0002.dta Win64/Olmarik.AK trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0003.dta Win32/Olmarik.AYH trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0004.dta Win64/Olmarik.AL trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0005.dta a variant of Win32/Rootkit.Kryptik.LA trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0006.dta Win64/Olmarik.AK trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0010.dta Win32/Olmarik.AFK trojan
C:\TDSSKiller_Quarantine\10.08.2012_18.05.12\mbr0000\tdlfs0000\tsk0011.dta Win64/Olmarik.AK trojan

#6 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 02:06 PM

The items found by ESET are all in quarantine, so they cant harm the computer,


Please do the following:

  • Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.


NEXT



Please download Farbar Service Scanner and run it
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#7 phroz

phroz
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 13 August 2012 - 03:24 PM

Here are the logs and the attached file.


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-13 12:46:49
-----------------------------
12:46:49.419 OS Version: Windows 6.1.7601 Service Pack 1
12:46:49.419 Number of processors: 2 586 0x170A
12:46:49.419 ComputerName: WCPM-PC UserName: m2mj
12:47:02.049 Initialize success
12:49:06.122 AVAST engine defs: 12081301
12:50:21.579 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
12:50:21.579 Disk 0 Vendor: WDC_WD2500AAJS-75M0A0 02.03E02 Size: 238418MB BusType: 3
12:50:21.595 Disk 0 MBR read successfully
12:50:21.595 Disk 0 MBR scan
12:50:21.595 Disk 0 Windows VISTA default MBR code
12:50:21.595 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63
12:50:21.611 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 81920
12:50:21.626 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 223377 MB offset 30801920
12:50:21.626 Disk 0 scanning sectors +488279202
12:50:21.689 Disk 0 scanning C:\Windows\system32\drivers
12:50:30.547 Service scanning
12:50:49.080 Modules scanning
12:50:57.270 Disk 0 trace - called modules:
12:50:57.301 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS halmacpi.dll intelide.sys PCIIDEX.SYS atapi.sys
12:50:57.301 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85f62ac8]
12:50:57.301 3 CLASSPNP.SYS[8b00459e] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0x85e8a030]
12:50:58.330 AVAST engine scan C:\Windows
12:51:00.546 AVAST engine scan C:\Windows\system32
12:53:09.807 AVAST engine scan C:\Windows\system32\drivers
12:53:22.225 AVAST engine scan C:\Users\m2mj
13:04:54.153 AVAST engine scan C:\ProgramData
13:06:22.621 Scan finished successfully
13:30:48.622 Disk 0 MBR has been saved successfully to "C:\Users\m2mj\Desktop\MBR.dat"
13:30:48.622 The log file has been saved successfully to "C:\Users\m2mj\Desktop\aswMBR.txt"







Farbar Service Scanner Version: 06-08-2012
Ran by m2mj (administrator) on 13-08-2012 at 13:32:05
Running from "C:\Users\m2mj\Downloads"
Microsoft Windows 7 Professional Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============
BITS Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to retrieve start type of BITS. The value does not exist.
The ImagePath of BITS service is OK.
The ServiceDll of BITS service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys
[2011-08-10 17:36] - [2011-06-20 22:34] - 1290624 ____A (Microsoft Corporation) 04E4A7D53A7ACE02E8C55B17A498F631

C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

Attached Files

  • Attached File  MBR.zip   572bytes   1 downloads


#8 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 03:44 PM

please do the following:

Visit ADOBE and download the latest version of Acrobat Reader (version X)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT


Your Java is out of date, so go to Start > Control Panel > Programs and Features > scroll down to the Java installation and Remove it, now download the latest Java version 7 update 5 and install it: http://java.com/en/download/index.jsp


NEXT


Your BITS registry key is missing so your Windows Updates wont work, so please download the attached reg fix and save it to your desktop, right click it and "Run as Administrator", allow it to merge into your registry (then delete the file as you wont need it again)





Please let me know how the computer is running now and if there are any outstanding issues

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#9 phroz

phroz
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 13 August 2012 - 04:47 PM

Have done all of the steps, the computer seems to be fine for now. Will reply if something comes up again, thanks for the help.

#10 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 04:51 PM

We just have some housekeeping to do now,

Please do the following:


You can delete the DDS and all the Farbar logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Press the WinKey +R to open a run box
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

Posted Image


If there are any logs/tools remaining on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe. KeePass is a small utility that allows you to manage all your passwords.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at this well written article:
    PC Safety and Security--What Do I Need?.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#11 phroz

phroz
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:01:39 PM

Posted 13 August 2012 - 05:27 PM

All right everything has been done and the computer is all good, thanks so much for the help.

#12 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 06:23 PM

you are welcome

stay safe :hello:

~CB

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015


#13 CatByte

CatByte

    bleepin' tiger


  • Malware Response Team
  • 14,664 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Location:Canada
  • Local time:04:39 PM

Posted 13 August 2012 - 06:23 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Microsoft MVP - 2010, 2011, 2012, 2013, 2014, 2015





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users