This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] repost - very slow pc

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Apologies to CatByte who took the time to answer my original problem. I had to travel for work and had no time to check back here hence the thread was closed. Will try again… My PC is hanging often, struggle to complete tasks without having to restart etc. My antivirus recently came back with a number of suspect files (trojans, a dialer. exe? amongst others). I have used the steps as outlined in help pages here with one exception… my PC cannot complete the rootkit check with the GMER scanner: I have tried several times and it crashes/hangs etc. Find below the docs as requested: Malware scan: Malwarebytes' Anti-Malware 1.44 Database version: 3647 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.11 27/01/2010 21:32:04 mbam-log-2010-01-27 (21-32-04).txt Scan type: Quick Scan Objects scanned: 129049 Time elapsed: 6 minute(s), 35 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2d2bee6e-3c9a-4d58-b9ec-458edb28d0f6} (Rogue.DriveCleaner) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Jamilla\Local Settings\Temp\cpyeuw.dll (Trojan.Dropper) -> Quarantined and deleted successfully. DDS scan: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 22:33:07.03 on 27/01/2010 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.119 [GMT 0:00] AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\Explorer.EXE svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe svchost.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\WINDOWS\eHome\ehRecvr.exe C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe svchost.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Apoint\Apoint.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\ICO.EXE C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Documents and Settings\Jamilla\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.soulpath.net/ uSearch Page = hxxp://www.google.com uSearch Bar = hxxp://www.google.com/ie uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s mSearchAssistant = hxxp://www.google.com/ie BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [SsAAD.exe] c:\progra~1\sony\sonics~1\SsAAD.exe uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1 mRun: [Apoint] c:\program files\apoint\Apoint.exe mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [Mouse Suite 98 Daemon] ICO.EXE mRun: [SonyPowerCfg] "c:\program files\sony\vaio power management\SPMgr.exe" mRun: [ISBMgr.exe] c:\program files\sony\isb utility\ISBMgr.exe mRun: [Switcher.exe] c:\program files\sony\wireless switch setting utility\Switcher.exe mRun: [VAIO Update 2] "c:\program files\sony\vaio update 2\VAIOUpdt.exe" /Stationary mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe mPolicies-explorer: NoResolveTrack = 1 (0x1) IE: Add RSS Support Site to VAIO Information FLOW - c:\program files\sony\vaio information flow\aiesc.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL Trusted Zone: sony-europe.com Trusted Zone: sonystyle-europe.com Trusted Zone: vaio-link.com DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll Notify: VESWinlogon - VESWinlogon.dll ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-1-27 11608] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-1-27 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-1-27 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-1-27 55656] R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328] R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -svaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlservr.exe -sVAIO_VEDB [?] R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2006-8-15 226304] S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.exe -i vaio_vedb –> c:\program files\microsoft sql server\mssql$vaio_vedb\binn\sqlagent.EXE -i VAIO_VEDB [?] S4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2006-8-15 1120960] =============== Created Last 30 ================ 2010-01-27 21:23 –d—– c:\docume~1\jamilla\applic~1\Malwarebytes 2010-01-27 21:23 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2010-01-27 21:23 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-01-27 21:23 19,160 a——- c:\windows\system32\drivers\mbam.sys 2010-01-27 21:23 –d—– c:\program files\Malwarebytes' Anti-Malware 2010-01-27 19:53 55,656 a——- c:\windows\system32\drivers\avgntflt.sys 2010-01-27 19:53 –d—– c:\program files\Avira 2010-01-27 19:53 –d—– c:\docume~1\alluse~1\applic~1\Avira 2010-01-26 20:30 –d—– c:\docume~1\jamilla\applic~1\Auslogics 2010-01-26 20:29 –d—– c:\program files\Auslogics 2010-01-19 16:14 471,552 -c—— c:\windows\system32\dllcache\aclayers.dll ==================== Find3M ==================== 2010-01-05 10:00 832,512 a——- c:\windows\system32\wininet.dll 2010-01-05 10:00 78,336 a——- c:\windows\system32\ieencode.dll 2010-01-05 10:00 17,408 a——- c:\windows\system32\corpol.dll 2009-11-21 15:51 471,552 a——- c:\windows\apppatch\aclayers.dll 2008-10-10 10:51 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101020081011\index.dat ============= FINISH: 22:33:16.93 =============== Attach doc is zipped and attached as directed in DDS software Thank you very very much for your time!

Attachments:

[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
Hi

Thank you very much for the help so far!

Had some issues getting combofix done, but managed after a few attempts. PC is still slow, hanging, sometimes crashing and needing a restart. Log is below:

ComboFix 10-02-17.02 - Jamilla 18/02/2010 16:54:25.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.502.153 [GMT 0:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-908647375-1921791325-1944005035-500
c:\windows\pchealth\UploadLB\Binaries\uploadm.exe
c:\windows\pchealth\UploadLB\Config\config.xml
c:\windows\pchealth\UploadLB . . . . failed to delete

.
original MBR restored successfully !
.
((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))
.

2010-01-29 15:45 . 2010-01-29 15:45 ——– d—–w- c:\documents and settings\Jamilla\Local Settings\Application Data\Chromium
2010-01-29 15:45 . 2010-01-29 15:51 ——– d—–w- c:\program files\SRWare Iron
2010-01-29 15:45 . 2008-05-02 10:41 3493888 —ha-w- c:\documents and settings\Jamilla\Application Data\U3\temp\Launchpad Removal.exe
2010-01-29 15:44 . 2010-01-29 15:45 ——– d—–w- c:\documents and settings\Jamilla\Application Data\U3
2010-01-27 21:23 . 2010-01-27 21:23 ——– d—–w- c:\documents and settings\Jamilla\Application Data\Malwarebytes
2010-01-27 21:23 . 2010-01-27 21:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-27 21:23 . 2010-01-29 16:07 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-27 19:53 . 2009-03-30 09:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-27 19:53 . 2009-02-13 11:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-27 19:53 . 2010-01-30 19:53 56816 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-01-27 19:53 . 2009-02-13 11:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-27 19:53 . 2010-01-27 19:53 ——– d—–w- c:\program files\Avira
2010-01-27 19:53 . 2010-01-27 19:53 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-01-26 20:30 . 2010-01-26 20:30 ——– d—–w- c:\documents and settings\Jamilla\Application Data\Auslogics
2010-01-26 20:29 . 2010-01-26 20:29 ——– d—–w- c:\program files\Auslogics

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-27 19:44 . 2006-08-15 16:48 ——– d—–w- c:\program files\Google
2010-01-05 10:00 . 2006-08-15 03:23 832512 —-a-w- c:\windows\system32\wininet.dll
2010-01-05 10:00 . 2006-08-15 03:23 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-01-05 10:00 . 2006-08-15 03:22 17408 —-a-w- c:\windows\system32\corpol.dll
2009-12-31 16:50 . 2006-08-15 03:23 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-16 18:43 . 2006-08-15 11:35 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2006-08-15 03:22 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-04 18:22 . 2006-08-15 03:23 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-11-27 17:11 . 2006-08-15 03:23 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2006-08-15 03:23 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2006-08-15 03:23 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2006-08-15 03:22 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
2009-11-21 15:51 . 2006-08-15 03:22 471552 —-a-w- c:\windows\AppPatch\aclayers.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-17 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-04-05 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-04-05 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-04-05 118784]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 45056]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-08-10 217088]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2006-02-14 176128]
"VAIO Update 2"="c:\program files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 151552]
"RTHDCPL"="RTHDCPL.EXE" [2005-09-22 14854144]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-06-20 15:11 73728 —-a-w- c:\windows\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
2006-07-30 17:00 98304 —-a-r- c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec Core LC"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"3246:TCP"= 3246:TCP:Services
"2479:TCP"= 2479:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"5913:TCP"= 5913:TCP:Services

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [27/01/2010 19:53 108289]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe -sVAIO_VEDB [?]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [15/08/2006 03:24 226304]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB –> c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE -i VAIO_VEDB [?]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.soulpath.net/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add RSS Support Site to VAIO Information FLOW - c:\program files\Sony\VAIO Information FLOW\aiesc.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Trusted Zone: sony-europe.com
Trusted Zone: sonystyle-europe.com
Trusted Zone: vaio-link.com
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
MSConfigStartUp-SkyTel - SkyTel.EXE
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
AddRemove-HijackThis - c:\documents and settings\Jamilla\Desktop\HijackThis.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-18 17:00
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x823CACC8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf8599f28
\Driver\ACPI -> 0x823cacc8
\Driver\atapi -> atapi.sys @ 0xf8380852
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: LAN-Express AS IEEE 802.11g PCI-E Adapter -> SendCompleteHandler -> 0x8244d690
PacketIndicateHandler -> NDIS.sys @ 0xf8299a21
SendHandler -> NDIS.sys @ 0xf828dd44
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x0950E4C1
malicious code @ sector 0x0950E4C4 !
PE file found in sector at 0x0950E4DA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(768)
c:\windows\system32\VESWinlogon.dll

- - - - - - - > 'explorer.exe'(3088)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\windows\system32\ICO.EXE
c:\windows\RTHDCPL.EXE
c:\program files\Apoint\Apntex.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\eHome\ehRecvr.exe
c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\eHome\ehmsas.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-02-18 17:03:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-02-18 17:03

Pre-Run: 28,890,181,632 bytes free
Post-Run: 28,850,388,992 bytes free

- - End Of File - - 4C7BA643A005D76DA7ABB974805B55E4
Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    [external image: Posted Image]
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.

Note: If GMER doesn't run, do this before trying it again.

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

After cleaning
To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.
Hi Completing the gmer scan is causing issues…. I have tried 5+ times and have managed to complete the scan a couple of times. However, as soon as I try to copy or save the log the PC freezes. Actually, one time I saved it to the desktop as outlined, before the computer froze. However, when I restarted the PC the file had disappeared? Odd… I tried the defogger as requested and I think that has allowed the scans to complete but I can't seem to get the log file to save at all. The PC is much as before, although I have had 2 blue screens since starting this gmer scan process. I will continue to try and complete and get a log to you, is there anything I can do to help the issues? Thanks again!
If it keeps crashing your pc, don't try it anymore.

Please download Rooter.exe… Copyrighted © by… Eric_71. Save it to your desktop.

  • Double-click on Rooter.exe icon on your desktop, to execute.
    If you recieve the "Open File" security warning, press Run. The Rooter interface will appear, with a variety of options displayed.
  • To run the Scan… press the Scan…button.
  • Notepad will open with a file created called "Rooter#.txt" … located at %systemdrive%\Rooter$\Rooter#.txt. (# is the number assigned to the report)
    The location of the report file is shown in the bottom display window.
  • Press the Close button, to close the Rooter window.
Please copy and paste the contents of Rooter#.txt in you next reply.
Hi again OK, here is the rooter log: Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully … . Windows XP . (5.1.2600) Service Pack 3 [32_bits] - x86 Family 6 Model 14 Stepping 8, GenuineIntel . [wscsvc] (Security Center) RUNNING (state:4) [SharedAccess] RUNNING (state:4) Windows Firewall -> Enabled . Internet Explorer 7.0.5730.11 . C:\ [Fixed-NTFS] .. ( Total:37 Go - Free:26 Go ) D:\ [Fixed-NTFS] .. ( Total:29 Go - Free:29 Go ) E:\ [Removable] F:\ [Removable] G:\ [CD_Rom] . Scan : 19:53.06 Path : C:\Documents and Settings\Jamilla\Desktop\Rooter.exe User : Jamilla ( Administrator -> YES ) . ———————-\\ Processes . Locked [System Process] (0) ______ System (4) ______ \SystemRoot\System32\smss.exe (688) ______ \??\C:\WINDOWS\system32\csrss.exe (740) ______ \??\C:\WINDOWS\system32\winlogon.exe (768) ______ C:\WINDOWS\system32\services.exe (812) ______ C:\WINDOWS\system32\lsass.exe (824) ______ C:\WINDOWS\system32\svchost.exe (1020) ______ C:\WINDOWS\system32\svchost.exe (1064) ______ C:\WINDOWS\System32\svchost.exe (1104) ______ C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (1152) ______ C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (1412) ______ C:\WINDOWS\Explorer.EXE (1428) ______ C:\WINDOWS\system32\svchost.exe (1520) ______ C:\WINDOWS\system32\svchost.exe (1592) ______ C:\WINDOWS\system32\spoolsv.exe (1804) ______ C:\Program Files\Avira\AntiVir Desktop\sched.exe (1876) ______ C:\WINDOWS\system32\svchost.exe (1972) ______ C:\Program Files\Avira\AntiVir Desktop\avguard.exe (520) ______ C:\WINDOWS\eHome\ehRecvr.exe (536) ______ C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe (628) ______ C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (1220) ______ C:\WINDOWS\system32\svchost.exe (1336) ______ C:\WINDOWS\system32\svchost.exe (1472) ______ C:\Program Files\Sony\VAIO Event Service\VESMgr.exe (1636) ______ C:\WINDOWS\system32\igfxext.exe (192) ______ C:\WINDOWS\system32\igfxsrvc.exe (212) ______ C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe (348) ______ C:\WINDOWS\ehome\mcrdsvc.exe (460) ______ C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe (1508) ______ C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe (2084) ______ C:\WINDOWS\System32\alg.exe (2472) ______ C:\Program Files\Apoint\Apoint.exe (2664) ______ C:\WINDOWS\ehome\ehtray.exe (2676) ______ C:\WINDOWS\system32\hkcmd.exe (2700) ______ C:\WINDOWS\system32\igfxpers.exe (2712) ______ C:\WINDOWS\system32\ICO.EXE (2732) ______ C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (2796) ______ C:\Program Files\Sony\ISB Utility\ISBMgr.exe (2828) ______ C:\WINDOWS\eHome\ehmsas.exe (2844) ______ C:\WINDOWS\RTHDCPL.EXE (2956) ______ C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (2968) ______ C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe (3096) ______ C:\Program Files\Apoint\Apntex.exe (3164) ______ C:\WINDOWS\System32\svchost.exe (3176) ______ C:\Program Files\SRWare Iron\iron.exe (2896) ______ C:\Program Files\SRWare Iron\iron.exe (3472) ______ C:\Documents and Settings\Jamilla\Desktop\Rooter.exe (2160) . ———————-\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:8504907264) \Device\Harddisk0\Partition2 –[ MBR ]– (Start_Offset:8504939520 | Length:40007761920) \Device\Harddisk0\Partition0 (Start_Offset:48512701440 | Length:31511047680) \Device\Harddisk0\Partition3 (Start_Offset:48512733696 | Length:31511015424) . ———————-\\ Scheduled Tasks . C:\WINDOWS\Tasks\desktop.ini C:\WINDOWS\Tasks\SA.DAT . ———————-\\ Registry . . ———————-\\ Files & Folders . ———————-\\ Scan completed at 19:53.09 . C:\Rooter$\Rooter_1.txt - (19/02/2010 | 19:53.09)
Download mbr.exe by GMER from here and save it to your Desktop.
Go to Start > Run…,enter the following into the textbox and click OK:

cmd

When the Command Window opens enter the following and then hit :

cd Desktop


Finally enter the following and hit again:

mbr > output.txt

This should create a text file on your Desktop called output.txt - i'd like a copy of the contents in your next reply.
Hi Again I think I misunderstood your previous email and decided to do a clean reinstall! Took me a day of messing about but seem to be OK now. Logged in to say thanks for help anyway and saw your latest message! :smack: :smack: But seriously, thank you very much for the help you provided… I will be contributing through Paypal to help keep this place running, you provide a stellar service. Thanks again, Matt
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI