This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] tidserv request 2 removal

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

good evening

you can try it in safe mode but I don't know if it will give me the info I will need

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.


try it and if it don't give me the info then we will keep trying in normal mode

gringo
I mangage to get it to save without using safe mode


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-10 13:11:25
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\axlyapob.sys


—- System - GMER 1.0.15 —-

SSDT 89C99778 ZwAlertResumeThread
SSDT 89CC93F8 ZwAlertThread
SSDT 892C3008 ZwAllocateVirtualMemory
SSDT 89D8FE90 ZwAssignProcessToJobObject
SSDT 89BD9DD8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA7CA9130]
SSDT 89275098 ZwCreateMutant
SSDT 892640A0 ZwCreateSymbolicLinkObject
SSDT 89CF7560 ZwCreateThread
SSDT 89DDF7D8 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA7CA93B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA7CA9910]
SSDT 8921B008 ZwDuplicateObject
SSDT 89CD80E0 ZwFreeVirtualMemory
SSDT 89D8F8A0 ZwImpersonateAnonymousToken
SSDT 89D0C2D0 ZwImpersonateThread
SSDT 89CA06C0 ZwLoadDriver
SSDT 89DC3D58 ZwMapViewOfSection
SSDT 89DDE768 ZwOpenEvent
SSDT 89D7C940 ZwOpenProcess
SSDT 89CF8940 ZwOpenProcessToken
SSDT 89CB9EF8 ZwOpenSection
SSDT 89CB83D8 ZwOpenThread
SSDT 89245058 ZwProtectVirtualMemory
SSDT 892D3150 ZwResumeThread
SSDT 89CD9EF8 ZwSetContextThread
SSDT 89DC3880 ZwSetInformationProcess
SSDT 89D707E8 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA7CA9B60]
SSDT 89D72EF8 ZwSuspendProcess
SSDT 89CCAA38 ZwSuspendThread
SSDT 89CAB8E0 ZwTerminateProcess
SSDT 89CA2B40 ZwTerminateThread
SSDT 89CEF190 ZwUnmapViewOfSection
SSDT 892C3098 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwCallbackReturn + 2F90 8050482C 4 Bytes CALL 98DA1F38
.text ntkrnlpa.exe!ZwCallbackReturn + 2FD4 80504870 5 Bytes [E0, B8, CA, 89, 40] {LOOPNZ 0xffffffffffffffba; RETF 0x4089}
.text ntkrnlpa.exe!ZwCallbackReturn + 2FDA 80504876 2 Bytes [CA, 89]
? SYMEFA.SYS The system cannot find the file specified. !
init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xA8831280]
.rsrc C:\WINDOWS\system32\DRIVERS\rasacd.sys entry point in ".rsrc" section [0xB9D9AC14]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\Explorer.EXE[292] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B6000A
.text C:\WINDOWS\Explorer.EXE[292] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00C0000A
.text C:\WINDOWS\Explorer.EXE[292] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B5000C
.text C:\WINDOWS\System32\svchost.exe[856] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 0099000A
.text C:\WINDOWS\System32\svchost.exe[856] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 009A000A
.text C:\WINDOWS\System32\svchost.exe[856] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 0098000C
.text C:\WINDOWS\System32\svchost.exe[856] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 01BC000A

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 890D0AC8

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\DRIVERS\rasacd.sys suspicious modification
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Now we have got it!!!

I need to find a good copy.

SystemLook:

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
:filefind
*rasacd*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

let me have this log

gringo
SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 17:38 on 10/04/2010 by User (Administrator - Elevation successful) ========== filefind ========== Searching for "*rasacd*" C:\WINDOWS\system32\dllcache\rasacd.sys –a–c 8832 bytes [12:00 14/04/2008] [23:22 07/04/2010] FE0D99D6F31E4FAD8159F690D68DED9C C:\WINDOWS\system32\drivers\rasacd.sys –a— 8832 bytes [12:00 14/04/2008] [23:22 07/04/2010] FE0D99D6F31E4FAD8159F690D68DED9C -=End Of File=-
now we can do this again if you have any questions let me know

Create and Run Batch File

Open Notepad and copy/paste the entire contents of the codebox below, into Notepad:
@echo off
copy /y C:\WINDOWS\system32\dllcache\rasacd.sys c:\
del %0
Save the file to your DESKTOP as "fix.bat". Make sure to save it with the quotes.
Choose to Save type as - All Files and where to save - Desktop - then close the Notepad file.
It should look like this: 🖼Click to load external image (Posted Image)
Double-click on fix.bat to run it.

Print out these instructions to use while in the Recovery Console: (This is for XP only)
  • Restart your computer.
  • Before Windows loads, you will be prompted to choose which Operating System to start.
  • Use the up and down arrow key to select Microsoft Windows Recovery Console
  • You must enter which Windows installation to log onto. Type 1 and press 'Enter'.
  • At the C:\Windows prompt, type the following bolded entries, and press 'Enter' (note the spaces):

    cd c:\windows\system32\drivers
    ren rasacd.sys rasacd.old
    copy c:\rasacd.sys c:\windows\system32\drivers
    exit


    You should see a message '1 file copied'. If you did not see that message, try again and ensure there is a space after the word copy and another space between the file paths.

    NOTE**(if you do not see 1 file copied on the screen, even after ensuring the commands are correct, rename the file back to it's original name by typing the following command then hitting Enter.
    ren atapi.old atapi.sys
    you should NOT be prompted to overwrite an existing file, but if you are, select No then type exit to restart and notify me of your results)

  • Type exit and press 'Enter'. Your computer should reboot.

rerun gMER again with the last instructions

gringo
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-10 21:07:23
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\axlyapob.sys


—- System - GMER 1.0.15 —-

SSDT 89C0E270 ZwAlertResumeThread
SSDT 89B4F230 ZwAlertThread
SSDT 89D25008 ZwAllocateVirtualMemory
SSDT 89B2B4D8 ZwAssignProcessToJobObject
SSDT 89B9F6D0 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xA6E6F130]
SSDT 89B2B220 ZwCreateMutant
SSDT 89C03A20 ZwCreateSymbolicLinkObject
SSDT 89C13D18 ZwCreateThread
SSDT 89BD7758 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xA6E6F3B0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xA6E6F910]
SSDT 89D0D100 ZwDuplicateObject
SSDT 89D020C0 ZwFreeVirtualMemory
SSDT 89B5B218 ZwImpersonateAnonymousToken
SSDT 89B5B2B8 ZwImpersonateThread
SSDT 89BF6C50 ZwLoadDriver
SSDT 89B512B8 ZwMapViewOfSection
SSDT 892EC0B8 ZwOpenEvent
SSDT 89CC5008 ZwOpenProcess
SSDT 89D19570 ZwOpenProcessToken
SSDT 89BDDE18 ZwOpenSection
SSDT 89CC5078 ZwOpenThread
SSDT 89B2B408 ZwProtectVirtualMemory
SSDT 89C25DC8 ZwResumeThread
SSDT 89B8D270 ZwSetContextThread
SSDT 899EE228 ZwSetInformationProcess
SSDT 89BDDD10 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xA6E6FB60]
SSDT 899E21A0 ZwSuspendProcess
SSDT 89B33218 ZwSuspendThread
SSDT 89436730 ZwTerminateProcess
SSDT 89B332B8 ZwTerminateThread
SSDT 899EE318 ZwUnmapViewOfSection
SSDT 89D25078 ZwWriteVirtualMemory

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

—- Files - GMER 1.0.15 —-

File C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Common Client\_lck\_FOI_7074E3A1A4CF4499BC5C0DCC7E426F3BG 0 bytes
File C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\mrcFramework\common.dat-journal 0 bytes

—- EOF - GMER 1.0.15 —-
Good afternoon

that looks like we got it!! are you still getting redirects??

first I want you to delete Norman TDSS Cleaner

update combofix

I would like you to download an updated virsion of combofix.

Delete the version of combofix you have now on your desktop and download a new one from here

Link 1
Link 2
Link 3
**Note: It is important that it is saved directly to your desktop**

1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note:Do not mouseclick combofix's window while it's running. That may cause it to stall

"information and logs"

  • In your next post I need the following

  • Are You Still Getting Rediects??
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
Have'nt had any redirects so far - no other problems noticed

ComboFix 10-04-10.02 - User 11/04/2010 8:33.3.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.61.1033.18.2038.1482 [GMT 10:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton AntiVirus *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2010-03-10 to 2010-04-10 )))))))))))))))))))))))))))))))
.

2010-04-10 22:22 . 2009-10-25 18:32 1647984 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVEX32A.DLL
2010-04-10 22:22 . 2010-02-03 09:00 84912 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVENG.SYS
2010-04-10 22:22 . 2010-02-03 09:00 1324720 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVEX15.SYS
2010-04-10 22:22 . 2009-10-25 18:32 177520 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\NAVENG32.DLL
2010-04-10 22:22 . 2009-12-09 09:00 2747440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\CCERASER.DLL
2010-04-10 22:22 . 2009-10-25 18:32 371248 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\EECTRL.SYS
2010-04-10 22:22 . 2009-10-25 18:32 259440 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\ECMSVR32.DLL
2010-04-10 22:22 . 2009-10-25 18:32 102448 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100410.004\ERASER.SYS
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- c:\windows\system32\drivers\rasacd.sys
2010-04-10 08:14 . 2010-04-07 23:22 8832 —-a-w- C:\rasacd.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-06 22:11 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\ATAPI.SYS
2010-04-06 22:11 . 2008-04-14 12:00 96512 —-a-w- C:\atapi.sys
2010-04-05 22:15 . 2010-04-05 22:15 ——– d—–w- C:\tds old log
2010-04-05 21:30 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSvix86.sys
2010-04-05 21:30 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\Scxpx86.dll
2010-04-05 21:30 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSxpx86.dll
2010-04-05 21:30 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSviA64.sys
2010-04-05 21:30 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSXpx86.sys
2010-04-04 07:41 . 2010-04-04 07:41 ——– d—–w- c:\program files\Sophos
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Application Data\AdobeUM
2010-04-03 08:33 . 2010-04-03 08:33 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-04-02 10:13 . 2010-04-02 10:13 ——– d—–w- c:\documents and settings\NetworkService\Application Data\AdobeUM
2010-03-26 08:42 . 2009-10-28 22:37 343088 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSvix86.sys
2010-03-26 08:42 . 2009-10-28 22:37 811896 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\Scxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 488312 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSxpx86.dll
2010-03-26 08:42 . 2009-10-28 22:37 466992 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSviA64.sys
2010-03-26 08:42 . 2009-10-28 22:37 329592 —-a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100326.001\IDSXpx86.sys
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\program files\EwisoftWeb
2010-03-21 21:46 . 2010-03-21 21:46 ——– d—–w- c:\documents and settings\All Users\Application Data\EwisoftWeb

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-10 11:25 . 2009-03-10 06:23 ——– d—–w- c:\documents and settings\User\Application Data\AdobeUM
2010-04-09 09:59 . 2009-02-02 11:49 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-04-09 09:58 . 2009-02-02 11:49 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-07 23:22 . 2008-04-14 12:00 8832 —-a-w- c:\windows\system32\drivers\rasacd.old
2010-04-06 04:27 . 2008-04-14 12:00 96512 —-a-w- c:\windows\system32\drivers\atapi.old
2010-04-04 10:53 . 2009-01-23 07:06 ——– d—–w- c:\documents and settings\User\Application Data\LimeWire
2010-04-04 10:18 . 2009-05-21 03:39 ——– d—–w- c:\program files\Ultra QuickTime Converter
2010-04-02 06:15 . 2009-02-04 01:01 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-04-02 06:15 . 2009-06-01 10:11 5918776 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-03-29 13:46 . 2009-02-04 01:01 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-29 13:45 . 2009-02-04 01:01 20824 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 21:44 . 2009-11-11 08:00 79488 —-a-w- c:\documents and settings\User\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-02-26 23:26 . 2010-02-26 23:26 ——– d—–w- c:\documents and settings\User\Application Data\AVG8
2010-02-25 07:43 . 2010-02-25 07:43 ——– d—–w- c:\program files\Trymedia
2010-02-25 06:24 . 2008-04-14 12:00 916480 ——w- c:\windows\system32\wininet.dll
2010-02-11 11:08 . 2009-05-17 02:26 ——– d—–w- c:\program files\Google
2010-01-18 03:36 . 2009-01-19 10:15 86480 —-a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-04-13 14:10 . 2009-05-26 07:47 96512 —-a-w- c:\program files\atapi.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-04-05_03.41.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-10 22:12 . 2010-04-10 22:12 16384 c:\windows\Temp\Perflib_Perfdata_708.dat
+ 2010-04-10 22:12 . 2010-04-10 22:12 16384 c:\windows\Temp\Perflib_Perfdata_68c.dat
- 2008-04-14 12:00 . 2010-04-05 00:31 75452 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-04-06 10:16 75452 c:\windows\system32\perfc009.dat
+ 2008-04-14 12:00 . 2010-04-07 23:22 8832 c:\windows\system32\dllcache\rasacd.sys
- 2008-04-14 12:00 . 2010-04-04 01:25 8832 c:\windows\system32\dllcache\rasacd.sys
+ 2008-04-14 12:00 . 2010-04-06 10:16 450960 c:\windows\system32\perfh009.dat
- 2008-04-14 12:00 . 2010-04-05 00:31 450960 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-17 39408]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-21 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-21 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-21 137752]
"HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2004-01-14 409600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"PE2CKFNT SE"="c:\program files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe" [1998-07-03 25088]

c:\documents and settings\User\Start Menu\Programs\Startup\
OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2009-3-8 51360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-10-24 217194]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2009-1-20 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 40048]
Adobe Reader Synchronizer.lnk - c:\program files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 734872]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
Photo Express Calendar Checker SE.lnk - c:\program files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe [2009-3-8 55296]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\programs\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\rmiregistry.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1233:UDP"= 1233:UDP:Windows Media Format SDK (svchost.exe)
"1232:UDP"= 1232:UDP:Windows Media Format SDK (svchost.exe)

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1008000.029\SymEFA.sys [28/01/2010 10:22 AM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NAV\1008000.029\BHDrvx86.sys [28/01/2010 10:22 AM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1008000.029\cchpx86.sys [28/01/2010 10:21 AM 482432]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100402.001\IDSXpx86.sys [6/04/2010 7:30 AM 329592]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe [28/01/2010 10:21 AM 117640]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [26/08/2009 6:00 PM 102448]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [19/01/2009 2:15 PM 222976]
S2 gupdate1c9d697d19c9338;Google Update Service (gupdate1c9d697d19c9338);c:\program files\Google\Update\GoogleUpdate.exe [17/05/2009 12:32 PM 133104]
S3 ASPI;Advanced SCSI Programming Interface Driver;c:\windows\system32\drivers\aspi32.sys [21/05/2009 1:21 PM 16512]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\30.tmp –> c:\windows\system32\30.tmp [?]
.
Contents of the 'Scheduled Tasks' folder

2010-04-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 01:34]

2010-04-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-05-17 02:26]

2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]

2010-04-10 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-17 02:32]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.abc.net.au/
mSearch Bar = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
IE: Easy-WebPrint Add To Print List - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint High Speed Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Preview - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
IE: Easy-WebPrint Print - c:\program files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-11 08:37
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\30.tmp"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(1372)
c:\windows\system32\WININET.dll
c:\oplimit\oahook32.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-11 08:39:39
ComboFix-quarantined-files.txt 2010-04-10 22:39
ComboFix2.txt 2010-04-05 03:47

Pre-Run: 229,047,300,096 bytes free
Post-Run: 229,051,482,112 bytes free

- - End Of File - - FE88AF22A3ABFC54FEE40B8070F36FF9
Good evening

Those logs are looking very good!!

TFC(Temp File Cleaner):

  • Please download TFC to your desktop,
  • Save any unsaved work. TFC will close all open application windows.
  • Double-click TFC.exe to run the program.
  • If prompted, click "Yes" to reboot.
Note: Save your work. TFC will automatically close any open programs, let it run uninterrupted. It shouldn't take longer take a couple of minutes, and may only take a few seconds. Only if needed will you be prompted to reboot.

: Malwarebytes' Anti-Malware :

  • Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
    • If you accidently close it, the log file is saved here and will be named like this:
    • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.


:Kaspersky scan:

  • Please go to Kaspersky website and perform an online antivirus scan.

    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button: Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • Log From Kaspersky
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
The current Kaspersky Online Scanner is unavailable Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3976 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 11/04/2010 9:30:42 AM mbam-log-2010-04-11 (09-30-42).txt Scan type: Quick scan Objects scanned: 101120 Time elapsed: 5 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
ok then try this one

Go here to run an online scannner from ESET.
  • Note: You will need to use Internet explorer for this scan
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\Eset\Eset Online Scanner\log.txt
  • Copy and paste that log as a reply to this topic and also let me know how things are now.


gringo
No problems so far ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=2b5a5baffb99bf4095cb4e266f44cd27 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-04-11 05:15:55 # local_time=2010-04-11 03:15:55 (+1000, AUS Eastern Standard Time) # country="Australia" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1024 16777215 100 0 0 0 0 0 # compatibility_mode=3587 16777189 100 94 1998444 19202323 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=90188 # found=4 # cleaned=0 # scan_time=6007 C:\Documents and Settings\User\Local Settings\Application Data\Identities\{12F96E70-0131-4552-96AE-FF60D3A0F15B}\Microsoft\Outlook Express\Deleted Items.dbx a variant of Win32/Kryptik.AVH trojan 00000000000000000000000000000000 I C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP602\A0100309.exe Win32/Adware.Trymedia application 00000000000000000000000000000000 I C:\System Volume Information\_restore{73A33F07-BC91-4598-8C13-8C53AB26F040}\RP638\A0107122.dll a variant of Win32/Cimag.CD trojan 00000000000000000000000000000000 I E:\programs\Nero-8.1.1.4_eng_trial.exe Win32/Toolbar.AskSBar application 00000000000000000000000000000000 I
Good Evening

Well my friend I think we did it!!!

C:\Documents and Settings\User\Local Settings\Application Data\Identities\{12F96E70-0131-4552-96AE-FF60D3A0F15B}\Microsoft\Outlook Express\Deleted Items.dbx a variant of Win32/Kryptik.AVH trojan 00000000000000000000000000000000 I
this is in your email programs, in the deleted box - you should empty it

the rest is in system restore (we will take care of that now) and the other is part of the nero program

Here is where we say goodbye, I will give you some last advice to stay safe..

I will leave this open for a few days if you have any problems come back here and let me know.

The following procedure will implement some cleanup procedures. It will also reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point.

:Uninstall ComboFix:

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box ComboFix /Uninstall and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.
  • [external image: Posted Image]

:DeFogger:

  • To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

:remove tools:
  • Let's clear out the programmes we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if used inappropriately.


    Please download OTCleanIt and save it to desktop. This tool will remove all the tools we used to clean your pc.
  • Double-click OTCleanIt.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
Note: If you receive a warning from your firewall or other security programs regarding OTCleanIt attempting to contact the internet, please allow it to do so.

:Make your Internet Explorer more secure:

please visit this page that gives instructions to do this
http://surfthenetsafely.com/ieseczone8.htm

:Turn On Automatic Updates:

Turn On Automatic Updates
1. Click Start, click Run, type sysdm.cpl, and then press ENTER.
2. Click the Automatic Updates tab, and then click to select one of the following options. We recommend that you select the Automatic (recommended) Automatically download recommended updates for my computer and install them

If you click this setting, click to select the day and time for scheduled updates to occur. You can schedule Automatic Updates for any time of day. Remember, your computer must be on at the scheduled time for updates to be installed. After you set this option, Windows recognizes when you are online and uses your Internet connection to find updates on the Windows Update Web site or on the Microsoft Update Web site that apply to your computer. Updates are downloaded automatically in the background, and you are not notified or interrupted during this process. An icon appears in the notification area of your taskbar when the updates are being downloaded. You can point to the icon to view the download status. To pause or to resume the download, right-click the icon, and then click Pause or Resume. When the download is completed, another message appears in the notification area so that you can review the updates that are scheduled for installation. If you choose not to install at that time, Windows starts the installation on your set schedule.

or visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

:antispyware programs:
  • you have a couple of good antispyware programs on this computer but you still can try some of these others to see if you like them also

    I would reccomend the download and installation of some or all of the following programs (all free), and the updating of them regularly:
  • WinPatrol As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
  • Malwarebytes' Anti-Malware - Malwarebytes' Anti-Malware is a new and powerful anti-malware tool. It is
    totally free but for real-time protection you will have to pay a small one-time fee.
  • Spyware Blaster - By altering your registry, this program stops harmful sites from installing things like ActiveX Controls on your machines.

please read this great article by miekiemoes How to prevent Malware:
and
this great article by Tony Klein So How Did I Get Infected In First Place

Now you have followed my advice - it's time to lodge a complaint against what you have suffered………

Malware Complaints
If you were infected …. Stand Up and be Counted.

I'd be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can then be closed.

My help is free, however, if you wish to make a small donation to show appreciation and to help me continue the fight against Malware, then click here:[external image: Posted Image]



Gringo

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI