This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virus Help

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently, my computer has become very slow and I've been getting random popups, even when I'm not on the internet. Even though I'm signed in as an administrator, I can no longer access anything in control panel. (for example, when I click "add/remove programs," an error pops up saying "Error in C:\Windows\System32\Shell32.DLL Missing Entry: CONTROL_RUNDLL" I have already run Spybot-Search & Destroy as well as Avira Antivirus, and both came up with a list of around 10 viruses. However, after fixing these, the exact same problems have continued. I attached my Gmer and attach.txt files. However, my DDS file just hangs when I try to attach it. When I try to copy/paste any of my logs and click "post new topic", I get redirected to a connection failure page that reads ""The connection to the server was reset while the page was loading." Thanks in advance for any help!
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 5 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hello joe4sure72.

You have a backdoor infection.

[external image: Posted Image]Backdoor Threat

IMPORTANT NOTE: Unfortunatly One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you do want to continue you should do the following


  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hello mowman! Thank you so much for your help. I do not use this computer for any financial transactions, so I would much rather attempt to disinfect than reformat/reinstall. However, what is the likelihood that my computer can become 100% secure and virus free again, or is that impossible to tell? I attached both my OTL.txt and Extras.txt logs because again, I get redirected to a "The connection to the server was reset while the page was loading" page when I simply copy/paste them.
Hello joe4sure72.Please do the following

Download Combofix from either of the links below. You must rename it to combo.com before saving it.
Save it to your desktop. Change the save as file type to "all files"

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".

Link 1
Link 2

———————————————————–


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–

  • NOTE: If ComboFix asks to install the Recovery Console, please ALLOW it to do so.

    ———————————————————–

  • Double click on the renamed ComboFix.exe & follow the prompts. When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.

———————————————————–

Hello mowman!

So I followed all of the steps you gave me in your post above. At first, ComboFix said that I had rootkit and told me to write down on a piece of paper these three things.

C:\WINDOWS\system32\PRAGMAsrcr.dat
C:\WINDOWS\system32\pragmaserf.dll
C:\WINDOWS\system32\pragmabbr.dll

However, it never asked me to retype these 3 again. It rebooted my computer two times and ended up with this log.


ComboFix 10-04-28.03 - Administrator 04/28/2010 17:10:13.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.594 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\combo.com
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC
c:\documents and settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC\enemies-names.txt
c:\documents and settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC\newupdate1142C.exe
c:\documents and settings\Administrator\Application Data\APManager
c:\documents and settings\Administrator\Application Data\APManager\files
c:\documents and settings\Administrator\Application Data\APManager\iplog
c:\documents and settings\Administrator\Application Data\APManager\languages\Czech.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Danish.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Dutch.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\English.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\French.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\German.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Italian.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Portuguese.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Slovak.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\Spanish.lng
c:\documents and settings\Administrator\Application Data\APManager\languages\template.lng
c:\documents and settings\Administrator\Application Data\APManager\settings.ini
c:\documents and settings\Administrator\Application Data\APManager\uninstall.exe
c:\documents and settings\Administrator\Application Data\APManager\wallpaper.jpg
c:\documents and settings\Administrator\Application Data\ezLife
c:\documents and settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Digital Protection.lnk
c:\documents and settings\Administrator\Desktop\Digital Protection Support.lnk
c:\documents and settings\Administrator\Desktop\Digital Protection.lnk
c:\documents and settings\Administrator\Local Settings\Application Data\ave.exe
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\741wXJ8y2.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\7MvWGE3n.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\aKHGghL.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\g13TyP1oS.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\kYRv2BV.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\n0UNw4.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\ndx088b.jpg
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\TestBrowser.html
c:\documents and settings\Administrator\Local Settings\Temporary Internet Files\udP647J.jpg
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\About.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Activate.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Buy.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Digital Protection Support.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Digital Protection.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Scan.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Settings.lnk
c:\documents and settings\Administrator\Start Menu\Programs\Digital Protection\Update.lnk
c:\documents and settings\All Users\Application Data\fiosejgfse.dll
c:\documents and settings\All Users\Application Data\pragmamfeklnmal.dll
c:\documents and settings\All Users\Favorites\_favdata.dat
c:\documents and settings\LocalService\Application Data\ezLife
c:\program files\Digital Protection
c:\program files\Digital Protection\about.ico
c:\program files\Digital Protection\activate.ico
c:\program files\Digital Protection\buy.ico
c:\program files\Digital Protection\dighook.dll
c:\program files\Digital Protection\help.ico
c:\program files\Digital Protection\scan.ico
c:\program files\Digital Protection\settings.ico
c:\program files\Digital Protection\splash.mp3
c:\program files\Digital Protection\update.ico
c:\program files\Digital Protection\virus.mp3
c:\program files\ezLife
c:\program files\ezLife\ezLife\1.5.2.0\uninstall.exe
c:\program files\Smart-Ads-Solutions
c:\program files\Smart-Ads-Solutions\SmartAds\1.5.2.0\uninstall.exe
c:\windows\irudifemeyu.dll
c:\windows\PRAGMAwkbdribipy
c:\windows\PRAGMAwkbdribipy\PRAGMAc.dll
c:\windows\PRAGMAwkbdribipy\PRAGMAcfg.ini
c:\windows\PRAGMAwkbdribipy\PRAGMAd.sys
c:\windows\system32\6to4v32.dll
c:\windows\system32\certstore.dat
c:\windows\system32\ctfmon .exe
c:\windows\system32\kutyrlijof.exe
c:\windows\system32\nizdzwmssthtutmk.dll
c:\windows\system32\nwiz .exe
c:\windows\system32\pragmabbr.dll
c:\windows\system32\pragmaserf.dll
c:\windows\system32\PRAGMAsrcr.dat
c:\windows\system32\rundll32 .exe
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job

Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_PRAGMAwkbdribipy
——-\Legacy_PRAGMAwkbdribipy
——-\Legacy_6TO4
——-\Service_6to4


((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-29 )))))))))))))))))))))))))))))))
.

2010-04-28 02:54 . 2010-04-28 02:55 ——– d—–w- c:\program files\ERUNT
2010-04-27 04:33 . 2010-04-27 04:33 ——– d—–w- c:\documents and settings\Administrator\Application Data\Avira
2010-04-27 04:23 . 2010-04-27 04:23 ——– d—–w- c:\program files\Avira
2010-04-27 04:23 . 2010-04-27 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-04-27 04:23 . 2010-03-01 17:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-04-27 04:23 . 2010-02-16 21:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-04-27 04:23 . 2009-05-11 19:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-04-27 04:23 . 2009-05-11 19:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-04-27 03:42 . 2010-04-27 03:42 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\program files\Conduit
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\WeFiBar
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\program files\WeFiBar
2010-04-27 03:28 . 2008-12-30 23:38 13824 ——w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jasj80uq.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}\components\FFAlert.dll
2010-04-27 03:28 . 2008-12-30 23:38 114688 ——w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jasj80uq.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}\components\npmozax.dll
2010-04-27 03:06 . 2010-04-27 03:07 ——– d—–w- c:\program files\WeFi
2010-04-27 03:04 . 2010-04-29 00:18 823808 —-a-w- c:\windows\system32\drivers\evffxswk.sys
2010-04-27 03:03 . 2010-04-27 03:03 118 —-a-w- C:\tujserrew.bat
2010-04-27 03:03 . 2010-04-27 03:03 162304 —-a-w- c:\windows\Amogia.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-28 23:46 . 2009-09-29 21:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-14 07:55 . 2008-07-17 03:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-11 12:38 . 2008-04-23 00:16 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2008-07-12 19:10 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2008-07-12 19:09 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:06 . 2008-07-12 19:09 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-02-24 13:11 . 2008-04-14 08:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 16:10 . 2008-04-14 08:00 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 04:01 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:27 . 2008-04-14 08:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 11:36 . 2008-07-12 19:09 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
.
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\Avira\AntiVir Desktop\avgnt .exe
c:\program files\Common Files\Ahead\Lib\nerocheck .exe
c:\program files\Common Files\Ahead\Lib\nmbgmonitor .exe
c:\program files\HP\HP Software Update\hpwuschd2 .exe
c:\program files\HP\hpcoretech\hpcmpmgr .exe
c:\program files\Java\jre6\bin\jusched .exe
c:\windows\ime\imjp8_1\imjpmig .exe
c:\windows\system32\IME\PINTLGNT\imscinst .exe
c:\windows\system32\IME\TINTLGNT\tintsetp .exe

——- Sigcheck ——-

[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk.disabled [2009-5-11 1808]
HP Image Zone Fast Start.lnk.disabled [2009-5-11 798]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-08-19 20:26 77824 -c–a-w- c:\windows\SOUNDMAN.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"QZAIB7KITK"=c:\windows\Amogia.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" /min
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"MSPY2002"=c:\windows\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [9/29/2009 2:16 PM 13696]

— Other Services/Drivers In Memory —

*Deregistered* - evffxswk
.
Contents of the 'Scheduled Tasks' folder
.
.
——- Supplementary Scan ——-
.
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
- - - - ORPHANS REMOVED - - - -

AddRemove-Mozilla Firefox (3.5.3) - c:\program files\Mozilla Firefox\uninstall\helper.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-28 17:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\evffxswk]

.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3912)
c:\windows\system32\WININET.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\sched.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Viewpoint\Common\ViewpointService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2010-04-28 17:21:17 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-29 00:21

Pre-Run: 21,152,985,088 bytes free
Post-Run: 21,571,284,992 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - 302CCE8B292AA848E4B42B6BC07A80EC
Hello joe4sure72.Please do the following

COMBOFIX-Script

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    http://forums.whatthetech.com/Virus_Help_t111788.html
    
    Collect::
    c:\windows\system32\drivers\evffxswk.sys
    C:\tujserrew.bat
    c:\windows\Amogia.exe
    
    RenV::
    c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
    c:\program files\Avira\AntiVir Desktop\avgnt .exe
    c:\program files\Common Files\Ahead\Lib\nerocheck .exe
    c:\program files\Common Files\Ahead\Lib\nmbgmonitor .exe
    c:\program files\HP\HP Software Update\hpwuschd2 .exe
    c:\program files\HP\hpcoretech\hpcmpmgr .exe
    c:\program files\Java\jre6\bin\jusched .exe
    c:\windows\ime\imjp8_1\imjpmig .exe
    c:\windows\system32\IME\PINTLGNT\imscinst .exe
    c:\windows\system32\IME\TINTLGNT\tintsetp .exe
     
    Registry:: 
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "QZAIB7KITK"=-
    [-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\evffxswk]
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • If you need help to disable your protection programs see here.
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *sfcfiles*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
Hello mowman!

I don't know if this matters at all, but the icon for my ComboFix looks like a rectangular window rather than an image of a cat.

Anyway, CFScript…

ComboFix 10-04-29.04 - Administrator 04/29/2010 18:49:41.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.497 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\combo.com
Command switches used :: c:\docume~1\ADMINI~1\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

file zipped: C:\tujserrew.bat
file zipped: c:\windows\Amogia.exe
file zipped: c:\windows\system32\drivers\evffxswk.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\tujserrew.bat
c:\windows\Amogia.exe
c:\windows\system32\driVERs\evffxswk.sys
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_evffxswk
——-\Service_evffxswk


((((((((((((((((((((((((( Files Created from 2010-03-28 to 2010-04-30 )))))))))))))))))))))))))))))))
.

2010-04-30 01:35 . 2010-04-30 01:35 ——– d–h–w- c:\windows\PIF
2010-04-28 02:54 . 2010-04-28 02:55 ——– d—–w- c:\program files\ERUNT
2010-04-27 04:33 . 2010-04-27 04:33 ——– d—–w- c:\documents and settings\Administrator\Application Data\Avira
2010-04-27 04:23 . 2010-04-27 04:23 ——– d—–w- c:\program files\Avira
2010-04-27 04:23 . 2010-04-27 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2010-04-27 04:23 . 2010-03-01 17:05 124784 —-a-w- c:\windows\system32\drivers\avipbb.sys
2010-04-27 04:23 . 2010-02-16 21:24 60936 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2010-04-27 04:23 . 2009-05-11 19:49 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2010-04-27 04:23 . 2009-05-11 19:49 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-04-27 03:42 . 2010-04-27 03:42 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\program files\Conduit
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\WeFiBar
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\Conduit
2010-04-27 03:28 . 2010-04-27 03:28 ——– d—–w- c:\program files\WeFiBar
2010-04-27 03:28 . 2008-12-30 23:38 13824 ——w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jasj80uq.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}\components\FFAlert.dll
2010-04-27 03:28 . 2008-12-30 23:38 114688 ——w- c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\jasj80uq.default\extensions\{ee1a404c-5714-451f-9365-a94936993d19}\components\npmozax.dll
2010-04-27 03:06 . 2010-04-27 03:07 ——– d—–w- c:\program files\WeFi

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-28 23:46 . 2009-09-29 21:58 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-04-14 07:55 . 2008-07-17 03:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-03-11 12:38 . 2008-04-23 00:16 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2008-07-12 19:10 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2008-07-12 19:09 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:06 . 2008-07-12 19:09 430080 —-a-w- c:\windows\system32\vbscript.dll
2010-02-24 13:11 . 2008-04-14 08:00 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 16:10 . 2008-04-14 08:00 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2008-04-14 04:01 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:27 . 2008-04-14 08:00 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 11:36 . 2008-07-12 19:09 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
.
c:\program files\Avira\AntiVir Desktop\avgnt .exe

——- Sigcheck ——-

[-] 2008-07-12 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-04-29_00.18.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-30 01:55 . 2010-04-30 01:55 16384 c:\windows\Temp\Perflib_Perfdata_780.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-10-31 7634944]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk.disabled [2009-5-11 1808]
HP Image Zone Fast Start.lnk.disabled [2009-5-11 798]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [N/A]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2008-08-19 20:26 77824 -c–a-w- c:\windows\SOUNDMAN.EXE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" /min
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
"MSPY2002"=c:\windows\system32\IME\PINTLGNT\ImScInst.exe /SYNC
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"PHIME2002A"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
"PHIME2002ASync"=c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=

R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [9/29/2009 2:16 PM 13696]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [4/26/2010 9:23 PM 135336]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [9/10/2009 9:56 PM 24652]
S3 WefiEngSvc;WeFi Engine Service;c:\program files\WeFi\WefiEngSvc.exe [2/24/2010 5:08 AM 133976]
.
.
——- Supplementary Scan ——-
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-29 18:56
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2672)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
.
**************************************************************************
.
Completion time: 2010-04-29 19:02:10 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-30 02:02
ComboFix2.txt 2010-04-29 00:22

Pre-Run: 21,453,889,536 bytes free
Post-Run: 21,466,017,792 bytes free

- - End Of File - - 4A8BA23763BC7385BEAABEA4C0C215A5



SystemLook

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 19:09 on 29/04/2010 by Administrator (Administrator - Elevation successful)

========== filefind ==========

Searching for "*sfcfiles*"
C:\WINDOWS\system32\sfcfiles.dll –a— 1614848 bytes [19:20 12/07/2008] [19:20 12/07/2008] 362BC5AF8EAF712832C58CC13AE05750

-=End Of File=-
Hello joe4sure72.Combofix is running fine so the icon is not a problem

Your Avira antivirus is infected so you will need to uninstall it and then reinstall it.Go to Add/Remove programs and select uninstall.Then remove any remaining avira folders from c:\program files.Download and install a fresh copy from here http://www.free-av.com/

Next we need to replace a file.Do you have your xp installation disc,if so please do the following.

Insert your XP Installation disk

then you will need to do the following:

Go to Start > Run.In the Run box, type in cmd and hit enter.

This opens the command prompt window.

Now type in the following red text exactly as seen. (if your cd drive is not D - change it to the appropriate letter)

expand D:\i386\sfcfiles.dll c:\windows\system32

There are two spaces in there, so I have pointed out below where they are.

ExpandSPACED:\i386\sfcfiles.dllSPACEc:\windows\system32

If done correctly, it will say "one file(s) expanded successfully".


You already have Malwarebytes installed.Please update,run a quick scan and post the log.


I need you to run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


In your next reply please post the following.

  • How the Avira reinstall went
  • How the file replacement went
  • MBAM log
  • Eset log
Hello mowman! 1. The Avira reinstall went according to plan. 2. I can not find my XP installation disk. Are there any alternative methods I can use to replace the file? 3. I am unaware that I have Malwarebytes installed. I did a "my computer" search for "Malwarebytes", but it turned up no results. Where would Malwarebytes be located? 4. The eset scan turned up 25 infected files. Here's the eset log… C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Application Data\0869C220B4407F533205A7C785AE3FBC\newupdate1142C.exe.vir Win32/Adware.AntimalwareDoctor application C:\Qoobox\Quarantine\C\Documents and Settings\Administrator\Local Settings\Application Data\ave.exe.vir probably a variant of Win32/Kryptik.EAQ trojan C:\Qoobox\Quarantine\C\Program Files\Digital Protection\dighook.dll.vir a variant of Win32/Kryptik.DZI trojan C:\Qoobox\Quarantine\C\WINDOWS\PRAGMAwkbdribipy\PRAGMAc.dll.vir Win32/Olmarik.YA trojan C:\Qoobox\Quarantine\C\WINDOWS\PRAGMAwkbdribipy\PRAGMAd.sys.vir Win32/Olmarik.YA trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\6to4v32.dll.vir Win32/Wimpixo.AA trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\kutyrlijof.exe.vir Win32/Adware.GooochiBiz.AE.Gen application C:\Qoobox\Quarantine\C\WINDOWS\system32\pragmabbr.dll.vir Win32/Olmarik.YA trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\pragmaserf.dll.vir Win32/Olmarik.YA trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\atapi.sys.vir Win32/Patched.EQ trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\evffxswk.sys.vir Win32/Rootkit.Kryptik.BB trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021379.dll Win32/Olmarik.YA trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021380.dll Win32/Olmarik.YA trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021402.sys Win32/Patched.EQ trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021443.exe Win32/Adware.AntimalwareDoctor application C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021449.exe probably a variant of Win32/Kryptik.EAQ trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021463.dll a variant of Win32/Kryptik.DZI trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021471.dll Win32/Olmarik.YA trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021473.sys Win32/Olmarik.YA trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021474.dll Win32/Wimpixo.AA trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP183\A0021476.exe Win32/Adware.GooochiBiz.AE.Gen application C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP184\A0021608.exe Win32/TrojanDownloader.FakeAlert.AQI trojan C:\System Volume Information\_restore{00C90978-816D-4D23-A63C-880DA07CC82E}\RP184\A0021617.sys Win32/Rootkit.Kryptik.BB trojan D:\Nero_v7_9_6_0_Ultra_Edition_Incl_CD_Key_Tutorials\New Nero 7.10.1.0 All Language and Keygen\Nero-7.10.1.0_cht_trial.exe Win32/Toolbar.AskSBar application D:\Nero_v7_9_6_0_Ultra_Edition_Incl_CD_Key_Tutorials\New Nero 7.10.1.0 All Language and Keygen\Nero-7.10.1.0_eng_trial.exe Win32/Toolbar.AskSBar application
Hello joe4sure72

Regarding the file replacement,you can either borrow an xp cd or copy over that file from another computer that has the same operating system.

Delete these two files.

D:\Nero_v7_9_6_0_Ultra_Edition_Incl_CD_Key_Tutorials\New Nero 7.10.1.0 All Language and Keygen\Nero-7.10.1.0_cht_trial.exe
D:\Nero_v7_9_6_0_Ultra_Edition_Incl_CD_Key_Tutorials\New Nero 7.10.1.0 All Language and Keygen\Nero-7.10.1.0_eng_trial.exe

As an example of how to do this if you are unsure.

To delete C:\WINDOWS\system32\badfile.dll
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on badfile.dll and from the menu that appears, click on 'Delete'



Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please
Hello mowman!

1. I just borrowed a copy of a Windows XP CD. However, when I followed the steps in your previous post, I get a command prompt error saying that it can't "open the input file"

Here is a screenshot:
[external image: Posted Image]

Here is a screenshot of what's on the CD
[external image: Posted Image]

And here, I just did a quick search for "sfc" files.
[external image: Posted Image]

What do I do? Thanks!


2. Ok I deleted those 2 files. They were the only two in the folder "New Nero [removed] All Language and Keygen" though, so should I just go ahead and delete the entire folder?

3. The scan found 2 infected objects. Here is the log

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4057

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

5/1/2010 12:32:26 PM
mbam-log-2010-05-01 (12-32-26).txt

Scan type: Quick scan
Objects scanned: 125191
Time elapsed: 9 minute(s), 11 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe" /START "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Administrator\Desktop\AP Manager.lnk (Rogue.APManager) -> Quarantined and deleted successfully.
Hello joe4sure72.
At the command prompt please type in the following.

expand E:\i386\sfcfiles.dl_ c:\windows\system32

There are two spaces in there, so I have pointed out below where they are.

ExpandSPACEE:\i386\sfcfiles.dl_SPACEc:\windows\system32

If done correctly, it will say "one file(s) expanded successfully".

Let me know how that goes and tell me how the computer is running now.Thanks
Hello mowman!

The expanding was successful this time. It didn't say "one file(s) expanded successfully"; it did, however, show a 1941% increase in bytes. Here's the screenshot of the command prompt

[external image: Posted Image]

The computer is running a lot better than before. I'm not getting any more random popups and page redirects. I can also access every administrative tool in control panel now. However, I feel that the computer is still running quite a bit slower than it did before the infections. Thanks so much!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI