This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Generic.Malware.dld!. and Trojan.Inject.IA

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been infected with some kind of virus or trojan that infects the process services.exe and every time I connect to the internet it launches 2 svchost.exe processes and downloads something . I scanned it with Bitdefender and here is what it found :

=>D:\WINDOWS\system32\services.exe (memory dump) Infected: Generic.Malware.dld!!.D9A32FD4
=>D:\WINDOWS\system32\services.exe (memory dump) Disinfection failed
=>D:\WINDOWS\system32\svchost.exe (memory dump) Infected: Win32.Worm.Agent.PZM
=>D:\WINDOWS\system32\svchost.exe (memory dump) Disinfection failed
=>D:\WINDOWS\system32\svchost.exe (memory dump) Infected: Trojan.Inject.IA
=>D:\WINDOWS\system32\svchost.exe (memory dump) Disinfection failed
=>D:\WINDOWS\system32\svchost.exe (full dump) Infected: Trojan.Inject.IA
=>D:\WINDOWS\system32\svchost.exe (full dump) Disinfection failed

and here is the HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:08:17, on 08.03.2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
C:\Programs\DESKTO~1\TLDL.EXE
D:\Program Files\Softwin\BitDefender10\bdagent.exe
J:\Program Files\VMware\VMware Workstation\vmware-tray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\WINDOWS\system32\vmnat.exe
D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
D:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
J:\Program Files\VMware\VMware Workstation\vmware-authd.exe
D:\WINDOWS\system32\vmnetdhcp.exe
D:\WINDOWS\System32\alg.exe
D:\WINDOWS\system32\msiexec.exe
D:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
D:\Program Files\Softwin\BitDefender10\vsserv.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
C:\Programs\Trend Micro\HijackThis\HijackThis.exe
D:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Programs\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: RUPK - {604B283A-4E26-4504-98E7-72859F949547} - D:\PROGRA~1\PROGRA~1\HITWAR~1\sypcms.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Programs\Megaupload\Mega Manager\MegaIEMn.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Desktop Lock Loader] C:\Programs\DESKTO~1\TLDL.EXE /BOOT
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Babylon Client] C:\Programs\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [BDMCon] "D:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "D:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [vmware-tray] "J:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Psi.lnk = D:\Program Files\Psi\psi.exe
O8 - Extra context menu item: Download all links with IDM - C:\Programs\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Programs\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Programs\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Programs\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Programs\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Programs\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: j:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: j:\program files\vmware\vmware workstation\vsocklib.dll
O12 - Plugin for .mpg: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE8E9B5C-9D0B-4D0E-81B1-2E9D587E4D94}: NameServer = 10.10.0.2,62.162.111.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{F711C6A1-4631-4BF0-951C-287F0764B281}: NameServer = 78.157.16.14,78.157.16.32
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - D:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Easy File & Folder Protector (ACDService) - Unknown owner - D:\PROGRAM FILES\PROGRAMI OD INTERNET\EASY FILE & FOLDER PROTECTOR\EFPAP.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - D:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: BroadWave (BroadWaveService) - NCH Software - D:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - Unknown owner - D:\WINDOWS\SYSTEM32\DWRCS.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - D:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Malware Defender Service (MalwareDefenderService) - TorchSoft - c:\programs\malware defender\mdservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - D:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - Lanovation - D:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Shadow IM Sniffer 4.01 (SLSpyService) - Unknown owner - C:\doks\software\Safety-lab\SIMS\SIMSService.exe (file missing)
O23 - Service: Tenable Nessus - Tenable Network Security - C:\Programs\hack\Nessus\nessusd.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - J:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - J:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - D:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - D:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - D:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

–
End of file - 9552 bytes
Hi Shade191,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Before seeing your post i have scanned my computer with Ad-Aware and it found many Trojans and Malware and I deleted all of them . My processes are know clean . But like before cleaning my computer I cannot open Malwarebytes' Anti-Malware and Ad-aware freezes . I can open them and run them smoothly only when i rename the main executable . I cannot open some AV and antimalware sites , something is blocking them , some of that sites are bitdefender and Malwarebytes' Anti-Malware website so i cannot update Malwarebytes' Anti-Malware. Just to know , I was able to update Ad-Aware and thats why i scanned my system with it. Another thing is that when i connect to internet there are many outgoing smtp connection , i can see this with netstat and it looks like this :

Proto Local Address Foreign Address State
TCP vasil:1791 [removed]:http TIME_WAIT
TCP vasil:1792 [removed]:http TIME_WAIT
TCP vasil:1797 [removed]:http TIME_WAIT
TCP vasil:1800 [removed]:http TIME_WAIT
TCP vasil:1809 [removed]:smtp TIME_WAIT
TCP vasil:1824 [removed]:smtp TIME_WAIT
TCP vasil:1826 [removed]:smtp TIME_WAIT
TCP vasil:1828 [removed]:smtp TIME_WAIT
TCP vasil:1840 [removed]:smtp TIME_WAIT
TCP vasil:1844 [removed]:smtp TIME_WAIT
TCP vasil:1847 [removed]:smtp TIME_WAIT
TCP vasil:1848 [removed]:smtp TIME_WAIT
TCP vasil:1849 [removed]:smtp TIME_WAIT
TCP vasil:1858 [removed]:smtp TIME_WAIT
TCP vasil:1859 [removed]:smtp TIME_WAIT
TCP vasil:1866 [removed]:smtp TIME_WAIT
TCP vasil:1867 [removed]:smtp TIME_WAIT
TCP vasil:1871 [removed]:smtp TIME_WAIT
TCP vasil:1872 [removed]:smtp TIME_WAIT
TCP vasil:1880 [removed]:smtp TIME_WAIT
TCP vasil:1885 [removed]:smtp TIME_WAIT
TCP vasil:1891 [removed]:smtp TIME_WAIT

The state is TIME_WAIT because i copied this when i disconnected from the internet.
So the problem is why i have outgoing connections , why a cannot open some programs and why i cannot access AV website when my processes are clean and after cleaning Ad-aware finds nothing but .

Here is HijackThis log after cleaning my system with Ad-Aware :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 03:43, on 2009-03-09
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\csrss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\spoolsv.exe
C:\Programs\DESKTO~1\TLDL.EXE
D:\Program Files\Softwin\BitDefender10\bdagent.exe
J:\Program Files\VMware\VMware Workstation\vmware-tray.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\wdfmgr.exe
D:\WINDOWS\system32\vmnat.exe
D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
D:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
D:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
J:\Program Files\VMware\VMware Workstation\vmware-authd.exe
D:\WINDOWS\system32\vmnetdhcp.exe
D:\Program Files\Softwin\BitDefender10\vsserv.exe
D:\WINDOWS\System32\alg.exe
C:\Programs\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Programs\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: RUPK - {604B283A-4E26-4504-98E7-72859F949547} - D:\PROGRA~1\PROGRA~1\HITWAR~1\sypcms.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Programs\Megaupload\Mega Manager\MegaIEMn.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - D:\PROGRA~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Desktop Lock Loader] C:\Programs\DESKTO~1\TLDL.EXE /BOOT
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "D:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [Babylon Client] C:\Programs\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [BDMCon] "D:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "D:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [vmware-tray] "J:\Program Files\VMware\VMware Workstation\vmware-tray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "D:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Psi.lnk = D:\Program Files\Psi\psi.exe
O8 - Extra context menu item: Download all links with IDM - C:\Programs\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download FLV video content with IDM - C:\Programs\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Download with IDM - C:\Programs\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Translate with &Babylon - res://C:\Programs\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Programs\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Programs\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - D:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: j:\program files\vmware\vmware workstation\vsocklib.dll
O10 - Unknown file in Winsock LSP: j:\program files\vmware\vmware workstation\vsocklib.dll
O12 - Plugin for .mpg: D:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE8E9B5C-9D0B-4D0E-81B1-2E9D587E4D94}: NameServer = 10.10.0.2,62.162.111.100
O17 - HKLM\System\CCS\Services\Tcpip\..\{F711C6A1-4631-4BF0-951C-287F0764B281}: NameServer = 78.157.16.14,78.157.16.32
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - D:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: ABBYY FineReader 9.0 PE Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - D:\Program Files\Common Files\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe
O23 - Service: Easy File & Folder Protector (ACDService) - Unknown owner - D:\PROGRAM FILES\PROGRAMI OD INTERNET\EASY FILE & FOLDER PROTECTOR\EFPAP.exe
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - D:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - D:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: BroadWave (BroadWaveService) - NCH Software - D:\Program Files\NCH Swift Sound\BroadWave\broadwave.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - Unknown owner - D:\WINDOWS\SYSTEM32\DWRCS.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - D:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Malware Defender Service (MalwareDefenderService) - TorchSoft - c:\programs\malware defender\mdservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - D:\WINDOWS\system32\oodag.exe
O23 - Service: PnkBstrA - Unknown owner - D:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PrismXL - Lanovation - D:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - D:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Shadow IM Sniffer 4.01 (SLSpyService) - Unknown owner - C:\doks\software\Safety-lab\SIMS\SIMSService.exe (file missing)
O23 - Service: Tenable Nessus - Tenable Network Security - C:\Programs\hack\Nessus\nessusd.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - D:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: VMware Agent Service (ufad-ws60) - VMware, Inc. - J:\Program Files\VMware\VMware Workstation\vmware-ufad.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - J:\Program Files\VMware\VMware Workstation\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - D:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware NAT Service - VMware, Inc. - D:\WINDOWS\system32\vmnat.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - D:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - D:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

–
End of file - 9417 bytes

And yes , I have run ATF Cleaner.
Just for information, my Windows OS is located in D partition.
Shade191,

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop as Worknow.com


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on Worknow.com & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Just for information I have run combofix before . Now i renamed it to Worknow.com and ran it , but it didn't ask me for installing Microsoft Windows Recovery Console . I have run netstat again and this is what i found : Proto Local Address Foreign Address State TCP vasil:microsoft-ds 10.10.12.123:1399 ESTABLISHED TCP vasil:microsoft-ds 10.10.12.123:1401 ESTABLISHED TCP vasil:1222 [removed].static.heraklesdata.net:smtp ESTA BLISHED TCP vasil:1283 mail.dreamgate.co.jp:smtp ESTABLISHED TCP vasil:2653 s3.ucoz.net:http TIME_WAIT TCP vasil:2671 [removed]:61068 SYN_SENT TCP vasil:2672 [removed]:44593 SYN_SENT TCP vasil:2670 192.168.139.232:34254 SYN_SENT TCP vasil:2673 192.168.233.26:18851 SYN_SENT Somthing is SYN_SENTing to nonstandard ports , but I have closed all programs . I have attached ComboFix.txt .

Attachments:

Shade191,

FindAWF

Click here to download FindAWF.exe and save it to your desktop.
  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to Press any key to continue.
  • Press 1 and then Enter, and the FindAWF tool will begin scanning your computer for the infected AWF files and the backups the trojan created.
  • It may take a few minutes to complete so be patient.
  • When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or to the same location as FindAWF.exe.
  • Copy and paste the contents of the AWF.txt file in your next reply.

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
Here is tha AWF log : Find AWF report by noahdfear ©2006 Version 1.40 The current date is: 09.03.2009 The current time is: 20:01:51,71 bak folders found ~~~~~~~~~~~ Directory of D:\WINDOWS\SYSTEM32\BAK 04.08.2004 00:56 15.360 ctfmon.exe 1 File(s) 15.360 bytes Directory of D:\PROGRA~1\SOFTWIN\BITDEF~2\BAK 09.06.2005 10:28 9.728 bdnagent.exe 11.03.2005 17:53 90.112 bdoesrv.exe 06.04.2005 13:09 33.280 bdswitch.exe 3 File(s) 133.120 bytes Directory of D:\PROGRA~1\SONYER~1\MOBILE2\APPLIC~1\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\COMPIL~3\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\GWBASIC\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\JUSTBA~1.01\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\LIBERT~1.03\BAK 0 File(s) 0 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 15360 Aug 4 2004 "D:\WINDOWS\system32\ctfmon.exe" 15360 Aug 4 2004 "D:\WINDOWS\system32\bak\ctfmon.exe" 15360 Aug 4 2004 "J:\WINDOWS\system32\ctfmon.exe" 9728 Jun 9 2005 "D:\Program Files\Softwin\BitDefender9\bak\bdnagent.exe" 37132 Feb 20 2007 "D:\Program Files\Softwin\BitDefender9\Quarantine\bdnagent.exe" 90112 Mar 11 2005 "D:\Program Files\Softwin\BitDefender9\bak\bdoesrv.exe" 37132 Feb 20 2007 "D:\Program Files\Softwin\BitDefender9\Quarantine\bdoesrv.exe" 33280 Apr 6 2005 "D:\Program Files\Softwin\BitDefender9\bak\bdswitch.exe" end of report I have attached the LopR.txt file .

Attachments:

Shade191,

Well. We didn't find the LOP I was looking for but it appears that we found the source of your problems. You download cracks. Just a word to the wise. Cracked security programs are virtually guaranteed to get you into trouble. I suggest that you uninstall it and install one of the really good free programs. Enough said about that. Now let's get you cleaned up.

Fix AWF Infection Step 2
Copy the file paths in the quote box below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

"D:\WINDOWS\system32\bak\ctfmon.exe"
"D:\Program Files\Softwin\BitDefender9\bak\bdnagent.exe"
"D:\Program Files\Softwin\BitDefender9\bak\bdoesrv.exe"
"D:\Program Files\Softwin\BitDefender9\bak\bdswitch.exe"

  • Double-click on the FindAWF.exe file to run it.
  • It will open a command prompt and ask you to "Press any key to continue".
  • Press 2 then Enter
  • Notepad will open a file named FindAWF.txt. It will appear with instructions to click below the line and paste the list of files to be restored.
  • Right click below this line and select Edit, Paste, to paste the list of files copied to the clipboard earlier. Save and close the document.
  • The program will proceed to move the legit files and will perform another scan for bak folders.
  • It may take a few minutes to complete, so please be patient.
  • When it is complete, it will open a text file in Notepad called AWF.txt.
  • Please copy and paste the contents of the AWF.txt file in your next reply.

Download the diagnostic tool MGADiag and save it to your desktop.

  • Double-click on MGADiag.exe.
  • Click Run and Run again.
  • Click Continue, then Copy.
  • Paste the report in your next reply.
Here is the AWF log : Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: 10.03.2009 The current time is: 1:58:08,43 bak folders found ~~~~~~~~~~~ Directory of D:\WINDOWS\SYSTEM32\BAK 04.08.2004 00:56 15.360 ctfmon.exe 1 File(s) 15.360 bytes Directory of D:\PROGRA~1\SOFTWIN\BITDEF~2\BAK 09.06.2005 10:28 9.728 bdnagent.exe 11.03.2005 17:53 90.112 bdoesrv.exe 06.04.2005 13:09 33.280 bdswitch.exe 3 File(s) 133.120 bytes Directory of D:\PROGRA~1\SONYER~1\MOBILE2\APPLIC~1\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\COMPIL~3\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\GWBASIC\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\JUSTBA~1.01\BAK 0 File(s) 0 bytes Directory of J:\PROGRA~2\LIBERT~1.03\BAK 0 File(s) 0 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 15360 Aug 4 2004 "D:\WINDOWS\system32\ctfmon.exe" 15360 Aug 4 2004 "D:\WINDOWS\system32\bak\ctfmon.exe" 15360 Aug 4 2004 "J:\WINDOWS\system32\ctfmon.exe" 9728 Jun 9 2005 "D:\Program Files\Softwin\BitDefender9\bdnagent.exe" 9728 Jun 9 2005 "D:\Program Files\Softwin\BitDefender9\bak\bdnagent.exe" 37132 Feb 20 2007 "D:\Program Files\Softwin\BitDefender9\Quarantine\bdnagent.exe" 90112 Mar 11 2005 "D:\Program Files\Softwin\BitDefender9\bdoesrv.exe" 90112 Mar 11 2005 "D:\Program Files\Softwin\BitDefender9\bak\bdoesrv.exe" 37132 Feb 20 2007 "D:\Program Files\Softwin\BitDefender9\Quarantine\bdoesrv.exe" 33280 Apr 6 2005 "D:\Program Files\Softwin\BitDefender9\bdswitch.exe" 33280 Apr 6 2005 "D:\Program Files\Softwin\BitDefender9\bak\bdswitch.exe" end of report Here is the MGADiag log : Diagnostic Report (1.9.0006.1): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-J64QY-6M3F6-MT24D Windows Product Key Hash: q9FFsbXEWm4Zz2LJSt3d3f37v5Y= Windows Product ID: 55274-642-4227893-23121 Windows Product ID Type: 1 Windows License Type: Volume Windows OS version: 5.1.2600.2.00010100.2.0.pro ID: {D2085E76-4030-4C0B-8E74-40E3620DC050}(3) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.7.36.0 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-230-1_E2AD56EA-765-b063_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-8009_E2AD56EA-766-2ee7_E2AD56EA-148-80004005_16E0B333-89-80004005 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A WGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Notifications Data–> Cached Result: N/A, hr = 0x80070002 Version: N/A, hr = 0x80070002 WGATray.exe Signed By: N/A, hr = 0x80070002 OGAAddin.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 114 Blocked VLK 2 Microsoft Office XP Professional with FrontPage - 114 Blocked VLK 2 OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: 025D1FF3-230-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32) Default Browser: D:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Disabled Active scripting: Allowed Script ActiveX controls marked as safe for scripting: Allowed File Scan Data–> Other data–> Office Details: {D2085E76-4030-4C0B-8E74-40E3620DC050}1.9.0006.15.1.2600.2.00010100.2.0.prox32*****-*****-*****-*****-MT24D55274-642-4227893-231211S-1-5-21-1547161642-527237240-725345543VIAP4VT8+ American Megatrends Inc.P1.4020040408000000.000000+000776A399F01842E53042F0409Central European Standard Time(GMT+01:00)03114 Licensing Data–> N/A HWID Data–> N/A OEM Activation 1.0 Data–> BIOS string matches: no Marker string from BIOS: N/A Marker string from OEMBIOS.DAT: N/A, hr = 0x80004005 OEM Activation 2.0 Data–> N/A
Shade191, Before we continue, I am obligated to ask you about your windows validation. The product key in the report you provided points to a well known pirated key. Where did you get your copy of Windows?
Shade191, I have had a struggle with this because there have been some known cases of "non-legitimate" copies of Windows being pre-installed on new computers. A new computer should come with windows disk and that will allow you to get a legal validation. I understand that is not your case. :( The bottom line here is, your operating system is, intentionally or not, a pirated copy. Therefore, per this boards Terms of Use, this thread will be closed. When you can return with a valid copy of windows, I would encourage you to do so as there are still some nasty viruses on your computer that are "contagious" and therefore you are a threat to everyone you come into contact with on your own network and the internet at large. I would plead with you to shut this computer down and leave it disconnected from any network, removable media, and the internet until such time as you are clean. Good Luck.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI