This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

TDL3, Click.GiftLoad, svchost

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi folks, I have three viruses that I know of: TDL3, Click.GiftLoad and svchost. I originally had a blue screen generated by an iaStor.sys error. I called Dell because in the beginning I didn’t know I had a virus. One guy there realized that I wasn’t running two drives so he changed my BIOS from IRRT to ATA. So instead I started receiving a atapi.sys blue screen error. I don’t remember the exact order of the next steps. I ran Spybot and Malewarebytes and came up with a few viruses and deleted them. (That’s what I had always done and it had worked.) I couldn’t get rid of the Click.GiftLoad so searched for other options. I some points I tried running TDSSKiller but the program wouldn’t run. I was running Microsoft Security Essentials and called them. They ran their scanners and found Alureon.A. After running other scans of theirs they assured me that there were no other viruses even though I was getting browser redirects, my computer would hang and I could see svchost in the tast manager reach 100+ in memory usage. There may have been other steps in here that I don’t remember at the moment. I ran Spybot again and found Click.GiftLoad again along with Win32.Agent.ieu and Win32.FraudLoad.edt. I deleted them but… At this time, I can't even get my computer to boot up in safe mode. (So much for doing this myself.) What do I do next? Thanks
Hello Nick,

REGEDIT4

[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION]
"svchost.exe"=-


Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.

If you saved the file correctly it should look like this [external image: Posted Image]




Download DDS from one of the links below to your desktop

Link 1
Link 2

  • Double click the tool to run it.
  • A black Screen will open, just read the contents and do nothing.
  • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
  • Copy/Paste the contents of 'DDS.txt' into your post.
  • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)
The first issue I'm having is that I cannot see my desktop. (I'm writing this from another computer.) When I do a ctrl-alt-delete I can get to the Task Manager and from there the 'run' command. So I can get to a command line prompt.
From the command prompt I was able to start Notepad and type in the registry update. I located this new file Registry.reg and ran it and It updated the registry. I rebooted in safe mode. I can get to my desktop now. (Not sure if it's related or not.) I opened the Task Manager and I can see that svchost is still growing in memory usage. I'm going to log into my email from my infected computer and copy and paste and try again. (Mabye I typed something wrong.)
(I meant log into this forum from my infected computer… not email.) Ok, copy and pasted, saved, updated registry, rebooted, but svchost is still showing as growing in memory. I'm going to run DDS now.
I ran DDS, but I can't post to the forum from my infected computer. In all browsers (IE, Firefox, Chrome, Safari) it shows some type of error as to why the post didn't work.
I noticed that the attach.zip files actually made it into my 'My Controls' folder. So I uploaded a .zip of DDS and downloaded them to an uninfected computer and was able to post from there, finally!


.
DDS (Ver_11-03-05.01) - NTFSx86 NETWORK
Run by [removed] at 11:38:10.84 on Sat 04/23/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1012.662 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\NT\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = about:blank
uSearch Page =
uSearch Bar =
mSearchAssistant =
mWinlogon: Userinit=userinit.exe
BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - c:\program files\adobe\/Adobe Contribute CS4/contributeieplugin.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll
TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - c:\program files\adobe\/Adobe Contribute CS4/contributeieplugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [PPort11reminder] "c:\program files\scansoft\paperport\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini"
mRun: [picon] "c:\program files\common files\intel\privacy icon\PrivacyIconClient.exe" -startup
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
dRun: [D1T2EUR7FZ] c:\windows\temp\Qdp.exe
mExplorerRun: [Pfyonmnr] rundll32 "c:\windows\system32\openfilesr.dll",xrvglyyq
StartupFolder: c:\docume~1\nichol~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: Append Link Target to Existing PDF
IE: Append to Existing PDF
IE: Convert Link Target to Adobe PDF
IE: Convert link target to existing PDF
IE: Convert to Adobe PDF
IE: E&xport to Microsoft Excel
IE: {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - "c:\program files\fiddler2\Fiddler.exe"
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - c:\program files\eltima software\flash decompiler trillix\saveflash\iebt.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1258328864578
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1258344714109
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://www.popcap.com/webgames/popcaploader_v10.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: GoToAssist - c:\program files\citrix\gotoassist\615\G2AWinLogon.dll
Notify: itlntfy - itlnfw32.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
LSA: Authentication Packages = msv1_0 wvauth
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\docume~1\nichol~1\applic~1\mozilla\firefox\profiles\j9sj6lm5.default\
FF - prefs.js: browser.startup.homepage -
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin.dll
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin2.dll
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin3.dll
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin4.dll
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin5.dll
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin6.dll
FF - plugin: c:\program files\apple\quicktime\plugins\npqtplugin7.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
FF - Ext: FiddlerHook: [removed] - c:\program files\fiddler2\FiddlerHook
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Firebug: [removed] - %profile%\extensions\[removed]
FF - Ext: Flashbug: [removed] - %profile%\extensions\[removed]
.
============= SERVICES / DRIVERS ===============
.
R3 d553bus;Dell Wireless 5530 HSPA Mobile Broadband Minicard Device driver (WDM);c:\windows\system32\drivers\d553bus.sys [2009-11-15 281216]
R3 d553nd5;Dell Wireless 5530 HSPA Mobile Broadband Minicard NetworkAdapter (NDIS);c:\windows\system32\drivers\d553nd5.sys [2009-11-15 25984]
R3 d553unic;Dell Wireless 5530 HSPA Mobile Broadband Minicard NetworkAdapter (WDM);c:\windows\system32\drivers\d553unic.sys [2009-11-15 375424]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2009-3-24 244368]
S1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
S1 MpKsl793be200;MpKsl793be200;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl793be200.sys [2011-4-22 28752]
S1 MpKsleedf642a;MpKsleedf642a;\??\c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{889f137a-c6b0-41d9-b3b1-276bc212d204}\mpksleedf642a.sys –> c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{889f137a-c6b0-41d9-b3b1-276bc212d204}\MpKsleedf642a.sys [?]
S2 ASFAgent;ASF Agent;c:\program files\intel\asf agent\ASFAgent.exe [2007-4-19 133968]
S2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2009-4-27 293968]
S2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2009-6-26 812392]
S2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2009-6-26 26984]
S2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2009-7-16 376096]
S2 itlperf;Intel CPU;c:\windows\system32\svchost.exe -k itlsvc [2008-4-25 14336]
S2 SMManager;Smith Micro Connection Manager Service;c:\program files\dell\dell controlpoint\connection manager\SMManager.exe [2009-10-5 76288]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\common files\adobe\adobe version cue cs4\server\bin\VersionCueCS4.exe [2008-8-15 288112]
S3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2009-3-24 112128]
S3 AsfAlrt;AsfAlrt Service;c:\windows\system32\drivers\Asfalrt.sys [2007-4-19 42832]
S3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys –> c:\windows\system32\drivers\ccidflt.sys [?]
S3 cvusbdrv;Dell ControlVault;c:\windows\system32\drivers\cvusbdrv.sys [2009-3-24 33832]
S3 d553card;Dell Wireless 5530 HSPA Mobile Broadband Minicard i7;c:\windows\system32\drivers\d553card.sys [2009-11-15 356352]
S3 d553gps;Dell Wireless 5530 HSPA Mobile Broadband Minicard GPS Port;c:\windows\system32\drivers\d553gps.sys [2009-11-15 77352]
S3 d553mdfl;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem Filter;c:\windows\system32\drivers\d553mdfl.sys [2009-11-15 14976]
S3 d553mdfl2;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem 2 Filter;c:\windows\system32\drivers\d553mdfl2.sys [2009-11-15 14976]
S3 d553mdm;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem Driver;c:\windows\system32\drivers\d553mdm.sys [2009-11-15 365312]
S3 d553mdm2;Dell Wireless 5530 HSPA Mobile Broadband Minicard Modem 2 Driver;c:\windows\system32\drivers\d553mdm2.sys [2009-11-15 409216]
S3 d553scard;Dell Wireless 5530 HSPA Mobile Broadband Minicard PC SC Port;c:\windows\system32\drivers\d553scard.sys [2009-11-15 49192]
S3 DCamUSBAlaris;ALARIS QuickVideo weeCam USB;c:\windows\system32\drivers\DVC2USB.sys [1999-12-22 107052]
S3 NvtSp50;NvtSp50 NDIS Protocol Driver;c:\windows\system32\drivers\nvtsp50.sys –> c:\windows\system32\drivers\NvtSp50.sys [?]
S4 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2009-11-15 2058776]
.
=============== Created Last 30 ================
.
2011-04-22 17:25:04 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl03fcc5ff.sys
2011-04-22 17:15:31 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl65c566cd.sys
2011-04-22 17:08:51 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl29873748.sys
2011-04-22 16:10:25 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl95f61d5a.sys
2011-04-22 15:42:54 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl88d328dc.sys
2011-04-22 15:37:19 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl793be200.sys
2011-04-22 15:31:36 106496 –sha-r- c:\windows\system32\openfilesr.dll
2011-04-22 03:04:15 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl2d76a333.sys
2011-04-21 20:34:26 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsla0570058.sys
2011-04-21 19:12:50 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslcd658328.sys
2011-04-21 18:55:06 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl49904cf0.sys
2011-04-21 12:03:40 ——– d—–w- C:\ea
2011-04-21 11:59:33 ——– d—–w- c:\docume~1\alluse~1\applic~1\Applications
2011-04-21 10:00:44 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl68336500.sys
2011-04-21 00:45:33 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl79fdceba.sys
2011-04-20 20:50:52 ——– d—–w- c:\program files\ESET
2011-04-20 20:39:21 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl00335352.sys
2011-04-20 20:22:44 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl761badfd.sys
2011-04-20 20:06:40 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl58b3a59c.sys
2011-04-20 13:42:43 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslfae75b7a.sys
2011-04-20 13:21:21 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl53990351.sys
2011-04-20 13:17:50 266360 —-a-w- c:\windows\system32\TweakUI.exe
2011-04-20 12:25:03 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl4ccc6882.sys
2011-04-20 07:58:30 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl92571d43.sys
2011-04-20 06:39:37 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl47896d66.sys
2011-04-19 22:18:54 215040 —-a-w- c:\windows\system32\itlpfw32.dll
2011-04-19 20:46:59 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl56245a7c.sys
2011-04-19 19:39:22 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl00b11a61.sys
2011-04-19 19:34:36 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl22183cbc.sys
2011-04-19 19:25:48 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslc8cf86d0.sys
2011-04-19 19:12:12 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslc84d60a1.sys
2011-04-19 16:48:56 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl8c608f00.sys
2011-04-19 16:01:44 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl06d07e54.sys
2011-04-19 13:55:41 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslf6c25836.sys
2011-04-19 13:42:07 ——– d—–w- c:\program files\%APPDATA%
2011-04-19 13:41:20 232916 —h–w- c:\temp\8a702136-2fcf-42b5-a671-c7b38facb426\OfferApp-2538.exe
2011-04-19 05:12:37 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslc81f0422.sys
2011-04-19 05:09:55 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKsl5bba5794.sys
2011-04-19 03:58:34 28752 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\MpKslbe78ae41.sys
2011-04-19 03:38:31 7071056 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{a21b30de-1020-4493-98fc-83417a10bc33}\mpengine.dll
2011-04-15 08:12:46 ——– d—–w- c:\docume~1\alluse~1\applic~1\SecTaskMan
2011-04-15 08:12:42 ——– d—–w- c:\program files\Security Task Manager
2011-04-15 07:17:38 ——– d—–w- c:\docume~1\nichol~1\locals~1\applic~1\PackageAware
2011-04-14 20:58:35 ——– d—–w- c:\program files\PopCap Games
2011-04-06 06:19:59 6792528 —-a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-06 06:19:19 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-04-06 06:11:35 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-04-06 06:11:35 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2011-04-06 06:11:08 ——– d—–w- c:\program files\Microsoft Security Client
2011-03-31 15:06:28 ——– d—–w- c:\docume~1\nichol~1\applic~1\yWorks
2011-03-31 15:04:57 ——– d—–w- c:\program files\yWorks
.
==================== Find3M ====================
.
2011-04-18 10:41:33 73 —-a-w- c:\windows\system32\ssprs.dll
2011-04-18 10:41:33 205 —-a-w- c:\windows\system32\lsprst7.dll
2011-04-17 09:03:39 499712 —-a-w- c:\windows\system32\msvcp71.dll
2011-04-17 09:03:39 348160 —-a-w- c:\windows\system32\msvcr71.dll
2011-03-21 13:58:03 152064 —-a-w- c:\windows\system32\xvid.ax
2011-03-19 15:06:01 240640 —-a-w- c:\windows\system32\xvidvfw.dll
2011-03-19 15:04:28 650752 —-a-w- c:\windows\system32\xvidcore.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: FUJITSU_MHZ2160BJ_FFS_G2 rev.0085001C -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x86E7D4F0]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x86e837d0]; MOV EAX, [0x86e8384c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E13B9] -> \Device\Harddisk0\DR0[0x86F4E9C0]
3 CLASSPNP[0xF74E9FD7] -> nt!IofCallDriver[0x804E13B9] -> [0x86F5A9D8]
\Driver\atapi[0x86F71460] -> IRP_MJ_CREATE -> 0x86E7D4F0
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; MOV CX, 0x4; MOV BP, 0x7be; CMP BYTE [BP+0x0], 0x0; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x86E7D33B
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 11:40:05.15 ===============

Attachments:

  • [attachment removed: Attach.zip]
Hello Nick,

I am looking at the rootkit and also a trojan that steals banking information, if you do online banking from this computer you best use a clean computer and change your passwords and dont do any online banking until where done. You may want to keep an eye on your statements for any unauthorized entries.

Have to tell you that with the seriousness of whats going on with your system your best option is to format and reinstall windows, but this is up to you, it would guarantee a nice clean secure computer.

The rootkit that you have has disabled a lot of programs from running like TDSSKiller, with the variant you have it may have infected your master boot record. This is what we need to do.

Dont fix anything with this program, I just need to see the report

Download aswMBR.exe ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

[external image: Posted Image]
Click the "Scan" button to start scan


[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply





When you run Combofix, you will have to rename it in order for it to run, make sure when it asks you to install the Recovery Console that you do that as we may need to fix the master boot record from it

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2


[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
I'm ok with doing a format and reinstall of windows. I have my data backed up already. I've reinstalled this system before… but is there anything special we need to do given the viruses I have?
I think what I would do is to reset your router, its a pain but can guarantee its not infecting your other computers. There is a small hole on the back of most routers , you can use a paperclip to depress the button in the hole, generally hold for 10 seconds or so and this will set your router back to its default setting , then you will need to use your disk to set up your computers again,

If you need help with the windows install you can post here
http://forums.whatthetech.com/index.php?showforum=119

If you need help with setting up your router and network, you can post here
http://forums.whatthetech.com/index.php?showforum=128

Nick, the threats going around the last week or so have been real bad, prior to what you have we where able to run TDSSKiller to remove the rootkit and a few other scans to remove the leftovers but this one has disabled a lot of our tools from running, with what you have we would need to go in and redo the Master Boot Record and thats always a troublesome fix

Need anymore info please post back
Ok, as long as there's nothing special I need to do, I'll reinstall my system. While I was waiting for your response, I was following your previous instructions. ComboFix seemed to download Microsoft's Recovery Console, but then it looked like it just stopped working.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI