Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Persistantly Hacked


  • This topic is locked This topic is locked
4 replies to this topic

#1 blackbeltjawa

blackbeltjawa

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:03 PM

Posted 17 July 2014 - 03:24 AM

Mod edit: moved to Appropriate forum ~~ boopme

Through HD swaps, formats reinstalls... always gets back to me, my IP I cannot change.
 
DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 8.0.7600.16385
Run by PZ at 3:16:48 on 2014-07-17
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.8157.6052 [GMT -5:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Spybot - Search and Destroy *Enabled/Outdated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Windows\system32\viakaraokesrv.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\WUDFHost.exe
C:\hiren\hiren\HBCD\HBCDMenu.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\PZ\AppData\Local\Temp\HBCD\HijackThis.exe
C:\Windows\explorer.exe
C:\Users\PZ\AppData\Local\Temp\HBCD\TotalCmd\TOTALCMD.EXE
C:\Windows\SysWOW64\notepad.exe
C:\Users\PZ\Downloads\install_reader11_en_mssa_aaa_aih.exe
C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
C:\Users\PZ\Downloads\spybot-2.4.exe
C:\Users\PZ\AppData\Local\Temp\is-AE8OT.tmp\spybot-2.4.tmp
C:\Users\PZ\Downloads\spybot-2.4.exe
C:\Users\PZ\AppData\Local\Temp\is-JO9N4.tmp\spybot-2.4.tmp
C:\Users\PZ\AppData\Local\Temp\is-Q0KB4.tmp\_isetup\_setup64.tmp
E:\Programs\Spybot - Search & Destroy 2\SDTray.exe
E:\Programs\Spybot - Search & Destroy 2\SDWSCSvc.exe
E:\Programs\Spybot - Search & Destroy 2\SDFSSvc.exe
E:\Programs\Spybot - Search & Destroy 2\SDUpdSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uRun: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
mRun: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
mRun: [SDTray] "E:\Programs\Spybot - Search & Destroy 2\SDTray.exe"
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MCAFEE~1.LNK - C:\Program Files (x86)\McAfee Security Scan\3.0.285\SSScheduler.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 24.159.64.23 24.178.162.3 71.9.127.107
TCP: Interfaces\{E64E57BD-EBE2-485D-BDB9-963394B4057C} : DHCPNameServer = 24.159.64.23 24.178.162.3 71.9.127.107
Notify: SDWinLogon - SDWinLogon.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2008-1-1 82560]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2008-1-1 42624]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-12-6 239616]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2013-12-6 344064]
R2 AODDriver4.2.0;AODDriver4.2.0;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\aoddriver2.sys [2013-9-19 59648]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;E:\Programs\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-7-17 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;E:\Programs\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-7-17 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service;E:\Programs\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-7-17 171928]
R2 VIAKaraokeService;VIA Karaoke digital mixer Service;C:\Windows\System32\ViakaraokeSrv.exe [2008-1-1 27792]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2008-1-1 46136]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2014-7-15 94208]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2008-1-1 565352]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2008-1-1 56448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;C:\Windows\System32\drivers\viahduaa.sys [2008-1-1 2206352]
R3 VUSB3HUB;VIA USB 3 Root Hub Service;C:\Windows\System32\drivers\ViaHub3.sys [2014-7-17 231112]
R3 xhcdrv;VIA USB eXtensible Host Controller Service;C:\Windows\System32\drivers\xhcdrv.sys [2014-7-17 301256]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2012-7-9 104912]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2012-7-8 123856]
S3 McComponentHostService;McAfee Security Scan Component Host Service;C:\Program Files (x86)\McAfee Security Scan\3.0.285\McCHSvc.exe [2012-9-5 234776]
S3 pwdrvio;pwdrvio;C:\Windows\System32\pwdrvio.sys [2014-7-17 19032]
S3 pwdspio;pwdspio;C:\Windows\System32\pwdspio.sys [2014-7-17 12384]
.
=============== Created Last 30 ================
.
2014-07-17 08:09:23 21040 ----a-w- C:\Windows\System32\sdnclean64.exe
2014-07-17 08:09:22 -------- d-----w- C:\ProgramData\Spybot - Search & Destroy
2014-07-17 08:06:35 -------- d-----w- C:\ProgramData\McAfee Security Scan
2014-07-17 08:06:35 -------- d-----w- C:\Program Files (x86)\McAfee Security Scan
2014-07-17 08:05:36 -------- d-----w- C:\Users\PZ\AppData\Local\Adobe
2014-07-17 07:38:52 231112 ----a-w- C:\Windows\System32\drivers\ViaHub3.sys
2014-07-17 07:28:02 -------- d-----w- C:\$RECYCLE.BIN
2014-07-17 07:24:52 1186161 ----a-w- C:\Windows\unins000.exe
2014-07-17 07:22:50 98816 ----a-w- C:\Windows\sed.exe
2014-07-17 07:22:50 256000 ----a-w- C:\Windows\PEV.exe
2014-07-17 07:22:50 208896 ----a-w- C:\Windows\MBR.exe
2014-07-17 07:10:45 2966720 ----a-w- C:\Windows\System32\pwNative.exe
2014-07-17 07:10:45 19032 ------w- C:\Windows\System32\pwdrvio.sys
2014-07-17 07:10:45 12384 ------w- C:\Windows\System32\pwdspio.sys
2014-07-17 07:02:51 -------- d-----w- C:\Users\PZ\AppData\Roaming\uTorrent
2014-07-17 01:19:19 -------- d-----w- C:\tails
2014-07-16 07:55:13 -------- d-----w- C:\hiren
2014-07-15 20:33:49 -------- d-----w- C:\Users\PZ\AppData\Roaming\tor
2014-07-15 20:24:23 -------- d-----w- C:\Program Files (x86)\WMIdiag
2014-07-15 19:03:36 -------- d-----w- C:\Users\PZ\AppData\Local\NETGEARGenie
2014-07-15 19:03:32 369168 ----a-w- C:\Windows\System32\wpcap.dll
2014-07-15 19:03:32 35344 ----a-w- C:\Windows\System32\drivers\npf.sys
2014-07-15 19:03:32 106000 ----a-w- C:\Windows\System32\packet.dll
2014-07-15 19:02:44 -------- d-----w- C:\ProgramData\Cisco Systems
2014-07-15 17:11:01 270496 ------w- C:\Windows\System32\MpSigStub.exe
2014-07-15 17:11:01 10924376 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{8BBE31B3-BCF6-4F1B-A257-DF0A802E6BC1}\mpengine.dll
2014-07-15 16:25:18 -------- d-----w- C:\Windows\Downloaded Installations
2014-07-15 16:25:08 -------- d-----w- C:\Program Files (x86)\ASUS
2014-07-15 16:22:41 99176 ----a-w- C:\Windows\SysWow64\PresentationHostProxy.dll
2014-07-15 16:22:41 49472 ----a-w- C:\Windows\SysWow64\netfxperf.dll
2014-07-15 16:22:41 48960 ----a-w- C:\Windows\System32\netfxperf.dll
2014-07-15 16:22:41 444752 ----a-w- C:\Windows\System32\mscoree.dll
2014-07-15 16:22:41 320352 ----a-w- C:\Windows\System32\PresentationHost.exe
2014-07-15 16:22:41 297808 ----a-w- C:\Windows\SysWow64\mscoree.dll
2014-07-15 16:22:41 295264 ----a-w- C:\Windows\SysWow64\PresentationHost.exe
2014-07-15 16:22:41 1942856 ----a-w- C:\Windows\System32\dfshim.dll
2014-07-15 16:22:41 1130824 ----a-w- C:\Windows\SysWow64\dfshim.dll
2014-07-15 16:22:41 109912 ----a-w- C:\Windows\System32\PresentationHostProxy.dll
2014-07-15 16:22:04 -------- d-----w- C:\Program Files\Ventrilo
2014-07-15 16:21:54 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2014-07-15 16:21:45 -------- d-----w- C:\ProgramData\Package Cache
2014-07-15 16:18:30 -------- d-----w- C:\Program Files (x86)\Tor Browser
2014-07-15 16:15:38 -------- d-----w- C:\Users\PZ\AppData\Local\Google
2014-07-15 16:15:04 -------- d-----w- C:\Users\PZ\AppData\Local\Deployment
2014-07-15 16:15:04 -------- d-----w- C:\Users\PZ\AppData\Local\Apps
2014-07-15 16:14:32 -------- d-----w- C:\Program Files (x86)\Steam
2014-07-15 16:14:32 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
.
==================== Find3M  ====================
.
.
============= FINISH:  3:16:54.30 ===============
 
 
 
Thats after combofix.... I am DLing kasp, spybot, and some microsoft app that another user recomended.
Im getting an Upload Skipped (no file was selected for upload) error on my attach.txt.... so here is another list
 
hyjack this
 

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:53:24 AM, on 7/17/2014
Platform: Windows 7  (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal
 
Running processes:
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
E:\Programs\Universal-USB-Installer-1.9.5.4.exe
C:\hiren\hiren\HBCD\HBCDMenu.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\PZ\Downloads\install_reader11_en_mssd_aaa_aih.exe
C:\Users\PZ\AppData\Local\Temp\HBCD\HijackThis.exe
 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: VIA Karaoke digital mixer Service (VIAKaraokeService) - Unknown owner - C:\Windows\system32\viakaraokesrv.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
 
--
End of file - 4859 bytes
 
 
 
combofix
 

ComboFix 14-07-17.01 - PZ 07/17/2014   2:23.1.6 - x64
Microsoft Windows 7 Home Premium   6.1.7600.0.1252.1.1033.18.8157.6976 [GMT -5:00]
Running from: c:\hiren\hiren\HBCD\Programs\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\SysWow64\Packet.dll
c:\windows\SysWow64\wpcap.dll
.
.
(((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_NPF
.
.
(((((((((((((((((((((((((   Files Created from 2014-06-17 to 2014-07-17  )))))))))))))))))))))))))))))))
.
.
2014-07-17 07:10 . 2012-08-20 14:48 19032 ------w- c:\windows\system32\pwdrvio.sys
2014-07-17 07:10 . 2012-08-20 14:48 2966720 ----a-w- c:\windows\system32\pwNative.exe
2014-07-17 07:10 . 2012-08-20 14:48 12384 ------w- c:\windows\system32\pwdspio.sys
2014-07-17 07:02 . 2014-07-17 07:21 -------- d-----w- c:\users\PZ\AppData\Roaming\uTorrent
2014-07-17 01:19 . 2014-07-17 01:19 -------- d-----w- C:\tails
2014-07-17 01:07 . 2014-07-17 01:08 -------- d-----w- c:\users\PZ\AppData\Roaming\Ventrilo
2014-07-16 07:55 . 2014-07-16 07:55 -------- d-----w- C:\hiren
2014-07-15 20:33 . 2014-07-15 20:33 -------- d-----w- c:\users\PZ\AppData\Roaming\tor
2014-07-15 20:24 . 2014-07-15 20:24 -------- d-----w- c:\program files (x86)\WMIdiag
2014-07-15 19:03 . 2014-07-15 19:04 -------- d-----w- c:\users\PZ\AppData\Local\NETGEARGenie
2014-07-15 19:03 . 2014-07-15 19:03 369168 ----a-w- c:\windows\system32\wpcap.dll
2014-07-15 19:03 . 2014-07-15 19:03 35344 ----a-w- c:\windows\system32\drivers\npf.sys
2014-07-15 19:03 . 2014-07-15 19:03 106000 ----a-w- c:\windows\system32\packet.dll
2014-07-15 19:02 . 2014-07-15 19:02 -------- d-----w- c:\programdata\Cisco Systems
2014-07-15 17:11 . 2014-07-14 09:12 10924376 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{8BBE31B3-BCF6-4F1B-A257-DF0A802E6BC1}\mpengine.dll
2014-07-15 17:11 . 2014-03-31 14:35 270496 ------w- c:\windows\system32\MpSigStub.exe
2014-07-15 16:50 . 2014-07-15 16:50 -------- d-----w- c:\programdata\ATI
2014-07-15 16:25 . 2014-07-15 16:25 -------- d-----w- c:\windows\Downloaded Installations
2014-07-15 16:25 . 2014-07-15 16:25 -------- d-----w- c:\program files (x86)\ASUS
2014-07-15 16:22 . 2014-07-15 16:22 -------- d-----w- c:\program files (x86)\Microsoft.NET
2014-07-15 16:22 . 2009-11-25 16:47 99176 ----a-w- c:\windows\SysWow64\PresentationHostProxy.dll
2014-07-15 16:22 . 2009-11-25 16:47 49472 ----a-w- c:\windows\SysWow64\netfxperf.dll
2014-07-15 16:22 . 2009-11-25 16:47 48960 ----a-w- c:\windows\system32\netfxperf.dll
2014-07-15 16:22 . 2009-11-25 16:47 297808 ----a-w- c:\windows\SysWow64\mscoree.dll
2014-07-15 16:22 . 2009-11-25 16:47 295264 ----a-w- c:\windows\SysWow64\PresentationHost.exe
2014-07-15 16:22 . 2009-11-25 16:47 1130824 ----a-w- c:\windows\SysWow64\dfshim.dll
2014-07-15 16:22 . 2009-11-25 16:47 109912 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2014-07-15 16:22 . 2009-11-25 16:47 444752 ----a-w- c:\windows\system32\mscoree.dll
2014-07-15 16:22 . 2009-11-25 16:47 320352 ----a-w- c:\windows\system32\PresentationHost.exe
2014-07-15 16:22 . 2009-11-25 16:47 1942856 ----a-w- c:\windows\system32\dfshim.dll
2014-07-15 16:22 . 2014-07-15 16:22 -------- d-----w- c:\program files\Ventrilo
2014-07-15 16:21 . 2014-07-15 16:21 -------- d-----w- c:\program files (x86)\Common Files\Wise Installation Wizard
2014-07-15 16:21 . 2014-07-15 16:23 -------- d-----w- c:\programdata\Package Cache
2014-07-15 16:18 . 2014-07-15 23:38 -------- d-----w- c:\program files (x86)\Tor Browser
2014-07-15 16:15 . 2014-07-15 16:16 -------- d-----w- c:\program files (x86)\Google
2014-07-15 16:15 . 2014-07-15 16:16 -------- d-----w- c:\users\PZ\AppData\Local\Google
2014-07-15 16:15 . 2014-07-15 16:15 -------- d-----w- c:\users\PZ\AppData\Local\Deployment
2014-07-15 16:15 . 2014-07-15 16:15 -------- d-----w- c:\users\PZ\AppData\Local\Apps
2014-07-15 16:14 . 2014-07-17 01:09 -------- d-----w- c:\program files (x86)\Steam
2014-07-15 16:14 . 2014-07-15 16:50 -------- d-----w- c:\program files (x86)\Common Files\Steam
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown 
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2013-12-06 389120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="c:\program files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" [2012-08-09 5263504]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-12-06 766208]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R3 pwdrvio;pwdrvio;c:\windows\system32\pwdrvio.sys;c:\windows\SYSNATIVE\pwdrvio.sys [x]
R3 pwdspio;pwdspio;c:\windows\system32\pwdspio.sys;c:\windows\SYSNATIVE\pwdspio.sys [x]
S0 amd_sata;amd_sata;c:\windows\system32\DRIVERS\amd_sata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_sata.sys [x]
S0 amd_xata;amd_xata;c:\windows\system32\DRIVERS\amd_xata.sys;c:\windows\SYSNATIVE\DRIVERS\amd_xata.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x]
S2 AODDriver4.2.0;AODDriver4.2.0;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S2 VIAKaraokeService;VIA Karaoke digital mixer Service;c:\windows\system32\viakaraokesrv.exe;c:\windows\SYSNATIVE\viakaraokesrv.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys;c:\windows\SYSNATIVE\drivers\viahduaa.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-07-15 16:16 1091912 ----a-w- c:\program files (x86)\Google\Chrome\Application\35.0.1916.153\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2014-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-07-15 16:15]
.
2014-07-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2014-07-15 16:15]
.
.
--------- X64 Entries -----------
.
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 24.159.64.23 24.178.162.3 71.9.127.107
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\ASUS\APRP\aprp.exe
.
**************************************************************************
.
Completion time: 2014-07-17  02:29:01 - machine was rebooted
ComboFix-quarantined-files.txt  2014-07-17 07:29
.
Pre-Run: 74,435,600,384 bytes free
Post-Run: 74,088,300,544 bytes free
.
- - End Of File - - 5B98C29D10B7380ECFC0AE26ACD8C45E                                            
A36C5E4F47E84449FF07ED3517B43A31

Edited by boopme, 17 July 2014 - 08:22 AM.


BC AdBot (Login to Remove)

 


m

#2 blackbeltjawa

blackbeltjawa
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:03 PM

Posted 17 July 2014 - 03:34 AM

I either want these problems fixed, or a guide on how to interconnect with my attackers.



#3 Machiavelli

Machiavelli

    Agent 007


  • Malware Response Instructor
  • 3,875 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:03 PM

Posted 21 July 2014 - 09:15 AM

Hello and Welcome on board blackbeltjawa,

my Name is Machiavelli and I will assist you with your problem.
If you booted into safe mode on your computer then print my instructions!
I'm in the 'Malware Staff Team' and will provide you with advice:

To remove Malware on a computer can be very complicated. Malware (malicious software) is able to hide and so I may not be able to find it so easily. In order to remove Malware from you Computer, you need to follow my instructions carefully. Don't be worried if you don't know what to do. just ask me! Please stay in contact with me until the problem is fixed.

Below are a few tips:
  • Removing Malware is usually very difficult.
    We need to search and analyse a lot of files. As this is done in our free time, please be patient especially if I don't answer every day!
  • Please follow these instructions
    If you don't follow the instructions your computer may crash. If you fix your PC by yourself, this can be very risky!
  • Please stay in contact with me until your problem is resolved
    As Malware may not be totally removed in one session or in one day, please stay in contact with me until the problem is resolved.
  • Please don't run any other tools without consulting with me as this can complicate finding and removing all Malware
    Don't run any tools while I'm fixing your PC. That is counter productive and again, will only complicate finding and removing all Malware!
  • Read my post completely
    If you don't do so, you may make mistakes that could result in your System crashing by your own actions!
 

Please download FRST (by Farbar) from the link below and save it to your Desktop.

Download Mirror #1

If you are unsure whether you have 32-Bit or 64-Bit Windows, see here
  • Disable all anti-virus and anti-malware software to prevent them inhibiting FRST in any way. If you are unsure how to do this, see THIS.
  • Double-click FRST.exe/FRST64.exe (depending on which version you downloaded) to run it. (if you have Windows Vista / Windows 7 / Windows 8: Please do a Right click on the FRST icon and select Run as Administrator)
  • When the disclaimer appears, click Yes.
  • Click Scan to start FRST.
  • When FRST finishes scanning, two logs, FRST.txt and Addition.txt will open.
  • Copy (Ctrl+C) and Paste (Ctrl+V) the contents of both of these logs into your next post please.

~Machiavelli

If I don't reply within 24 hours please PM me!

  • Every topic with no replies within 5 days will be closed.
  • If you like my help here please give me feedback.

unite_blue.png
 
 


#4 blackbeltjawa

blackbeltjawa
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Local time:09:03 PM

Posted 21 July 2014 - 04:20 PM

I ended up wiping every drive on my lan with killdisk, reformating, reinstalling windows... and I switched my cable modem and reset all of my routers. So far I have had no further issues. If they persist I would love your assistance, Ill repost having followed your instructions should I sense any further intrusion. 



#5 Machiavelli

Machiavelli

    Agent 007


  • Malware Response Instructor
  • 3,875 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:09:03 PM

Posted 21 July 2014 - 04:32 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

~Machiavelli

If I don't reply within 24 hours please PM me!

  • Every topic with no replies within 5 days will be closed.
  • If you like my help here please give me feedback.

unite_blue.png
 
 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users