Sisa722
Topic Starter
Hello,
I have been infected with a virus TDSS ROOT KIT/BACKDOOR INFECTION, and i would appreciate any help possible to remove this virus. I had started a topic about a month ago, but i have been traveling pretty much all of May and the topic was closed.
Here is the DDS file that i ran when i first started the topic. If you need me to run another one please let me know.
Thanks,
Rachel
—————————————————————————————————————————————————————————–
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:06:52.94 on Sun 04/03/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1013 [GMT -4:00]
.
AV: CA Anti-Virus *Disabled/Outdated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
SP: CA Anti-Spyware *Disabled/Outdated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Windows\system32\lxbccoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\system32\STacSV.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Rachel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [Aim6]
uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [Malwarebytes Anti-Malware Reboot] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] c:\program files\dell support center\gs_agent\custom\dsca.exe
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\rachel\appdata\roaming\micros~1\windows\startm~1\programs\startup\digsby.lnk - c:\program files\digsby\digsby.exe
StartupFolder: c:\users\rachel\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
uPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} - hxxps://login.imagesilo.com/Install/DocViewCtl/PVDMDocView400.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 adwarealert;adwarealert;c:\windows\system32\drivers\adwarealert.sys [2008-5-1 22512]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2008-9-9 26352]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2008-9-9 21104]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2008-9-9 161008]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-5-8 144696]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-7-23 21504]
R2 lxbc_device;lxbc_device;c:\windows\system32\lxbccoms.exe -service –> c:\windows\system32\lxbccoms.exe -service [?]
R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2008-9-9 255312]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-2-29 111104]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2008-9-9 185680]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2008-5-8 130280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\opencase\opencase media agent\MediaAgent.exe [2008-8-29 835208]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-29 30192]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-2-29 73728]
.
=============== File Associations ===============
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-04-03 14:37:02 6792528 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{85b4897c-a972-4c96-9297-70c6fce711a0}\mpengine.dll
2011-03-24 12:46:47 ——– d—–w- c:\program files\Digitech Systems
2011-03-24 12:13:26 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-24 12:13:26 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-24 12:13:26 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-11 18:12:03 ——– d—–w- c:\program files\iPod
2011-03-11 18:12:02 ——– d—–w- c:\program files\iTunes
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-03-11 18:03:18 ——– d—–w- c:\program files\Bonjour
2011-03-09 02:54:05 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-03-09 02:54:04 322560 —-a-w- c:\windows\system32\sbe.dll
2011-03-09 02:54:04 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 02:54:04 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-03-09 02:54:01 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-03-09 02:54:01 2067968 —-a-w- c:\windows\system32\mstscax.dll
.
==================== Find3M ====================
.
2011-02-18 21:36:58 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-02 22:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-15 01:08:57 257703058 —-a-w- c:\windows\DUMP4fa5.tmp
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD16 rev.04.0 -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8661E439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x866247d0]; MOV EAX, [0x8662484c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x81E61912] -> \Device\Harddisk0\DR0[0x85F812F0]
3 CLASSPNP[0x8819F8B3] -> ntkrnlpa!IofCallDriver[0x81E61912] -> [0x866ADB20]
\Driver\iaStor[0x86609E78] -> IRP_MJ_CREATE -> 0x8661E439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskWDC_WD1600BEVS-75RST0___________________04.01G04#4&20766cbe&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 18:07:56.68 ===============
I have been infected with a virus TDSS ROOT KIT/BACKDOOR INFECTION, and i would appreciate any help possible to remove this virus. I had started a topic about a month ago, but i have been traveling pretty much all of May and the topic was closed.
Here is the DDS file that i ran when i first started the topic. If you need me to run another one please let me know.
Thanks,
Rachel
—————————————————————————————————————————————————————————–
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 18:06:52.94 on Sun 04/03/2011
Internet Explorer: 8.0.6001.19019
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.1013 [GMT -4:00]
.
AV: CA Anti-Virus *Disabled/Outdated* {57B5C44D-AAB5-DBC9-741B-542BE5A132EA}
SP: CA Anti-Spyware *Disabled/Outdated* {ECD425A9-8C8F-D447-4EAB-6F599E267857}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Windows\system32\lxbccoms.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\system32\STacSV.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Rachel\Desktop\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - No File
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [DellAutomatedPCTuneUp] "c:\program files\dellautomatedpctuneup\PTAgnt.exe" /startup
uRun: [Aim6]
uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [pccguide.exe] "c:\program files\trend micro\internet security 14\pccguide.exe"
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [Malwarebytes Anti-Malware Reboot] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [dscactivate] c:\program files\dell support center\gs_agent\custom\dsca.exe
mRun: [DELL Webcam Manager] "c:\program files\dell\dell webcam manager\DellWMgr.exe" /s
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe"
mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\users\rachel\appdata\roaming\micros~1\windows\startm~1\programs\startup\digsby.lnk - c:\program files\digsby\digsby.exe
StartupFolder: c:\users\rachel\appdata\roaming\micros~1\windows\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
uPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: RunStartupScriptSync = 1 (0x1)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
DPF: {ACF93F61-9F60-4C1E-A015-E3B3812BD58C} - hxxps://login.imagesilo.com/Install/DocViewCtl/PVDMDocView400.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: x-excid - {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\windows\downloaded program files\mimectl.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 adwarealert;adwarealert;c:\windows\system32\drivers\adwarealert.sys [2008-5-1 22512]
R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2008-9-9 26352]
R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2008-9-9 21104]
R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2008-9-9 161008]
R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2008-5-8 144696]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-7-23 21504]
R2 lxbc_device;lxbc_device;c:\windows\system32\lxbccoms.exe -service –> c:\windows\system32\lxbccoms.exe -service [?]
R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2008-9-9 255312]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI Service;c:\windows\system32\drivers\IntcHdmi.sys [2008-2-29 111104]
R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2008-9-9 185680]
R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2008-5-8 130280]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 OpenCASE Media Agent;OpenCASE Media Agent;c:\program files\opencase\opencase media agent\MediaAgent.exe [2008-8-29 835208]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-2-29 30192]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-2-29 73728]
.
=============== File Associations ===============
.
regfile=regedit.exe "%1" %*
scrfile="%1" %*
.
=============== Created Last 30 ================
.
2011-04-03 14:37:02 6792528 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{85b4897c-a972-4c96-9297-70c6fce711a0}\mpengine.dll
2011-03-24 12:46:47 ——– d—–w- c:\program files\Digitech Systems
2011-03-24 12:13:26 797696 —-a-w- c:\windows\system32\FntCache.dll
2011-03-24 12:13:26 288768 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-03-24 12:13:26 1068544 —-a-w- c:\windows\system32\DWrite.dll
2011-03-11 18:12:03 ——– d—–w- c:\program files\iPod
2011-03-11 18:12:02 ——– d—–w- c:\program files\iTunes
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin7.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin6.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin5.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin4.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin3.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin2.dll
2011-03-11 18:08:47 159744 —-a-w- c:\program files\internet explorer\plugins\npqtplugin.dll
2011-03-11 18:03:18 ——– d—–w- c:\program files\Bonjour
2011-03-09 02:54:05 429056 —-a-w- c:\windows\system32\EncDec.dll
2011-03-09 02:54:04 322560 —-a-w- c:\windows\system32\sbe.dll
2011-03-09 02:54:04 177664 —-a-w- c:\windows\system32\mpg2splt.ax
2011-03-09 02:54:04 153088 —-a-w- c:\windows\system32\sbeio.dll
2011-03-09 02:54:01 677888 —-a-w- c:\windows\system32\mstsc.exe
2011-03-09 02:54:01 2067968 —-a-w- c:\windows\system32\mstscax.dll
.
==================== Find3M ====================
.
2011-02-18 21:36:58 4184352 —-a-w- c:\windows\system32\usbaaplrc.dll
2011-02-02 22:11:20 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-01-20 16:08:16 478720 —-a-w- c:\windows\system32\dxgi.dll
2011-01-20 16:08:06 219648 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-01-20 16:08:06 189952 —-a-w- c:\windows\system32\d3d10core.dll
2011-01-20 16:08:06 160768 —-a-w- c:\windows\system32\d3d10_1.dll
2011-01-20 16:08:06 1029120 —-a-w- c:\windows\system32\d3d10.dll
2011-01-20 16:07:58 37376 —-a-w- c:\windows\system32\cdd.dll
2011-01-20 16:07:42 258048 —-a-w- c:\windows\system32\winspool.drv
2011-01-20 16:07:16 586240 —-a-w- c:\windows\system32\stobject.dll
2011-01-20 16:06:38 2873344 —-a-w- c:\windows\system32\mf.dll
2011-01-20 16:06:35 26112 —-a-w- c:\windows\system32\printfilterpipelineprxy.dll
2011-01-20 16:04:54 98816 —-a-w- c:\windows\system32\mfps.dll
2011-01-20 16:04:54 209920 —-a-w- c:\windows\system32\mfplat.dll
2011-01-20 14:28:38 1554432 —-a-w- c:\windows\system32\xpsservices.dll
2011-01-20 14:27:50 876032 —-a-w- c:\windows\system32\XpsPrint.dll
2011-01-20 14:26:30 667648 —-a-w- c:\windows\system32\printfilterpipelinesvc.exe
2011-01-20 14:25:25 847360 —-a-w- c:\windows\system32\OpcServices.dll
2011-01-20 14:24:26 135680 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-01-20 14:15:10 979456 —-a-w- c:\windows\system32\MFH264Dec.dll
2011-01-20 14:14:39 357376 —-a-w- c:\windows\system32\MFHEAACdec.dll
2011-01-20 14:14:03 302592 —-a-w- c:\windows\system32\mfmp4src.dll
2011-01-20 14:14:03 261632 —-a-w- c:\windows\system32\mfreadwrite.dll
2011-01-20 14:12:46 1172480 —-a-w- c:\windows\system32\d3d10warp.dll
2011-01-20 14:11:34 486400 —-a-w- c:\windows\system32\d3d10level9.dll
2011-01-20 13:47:51 683008 —-a-w- c:\windows\system32\d2d1.dll
2011-01-15 01:08:57 257703058 —-a-w- c:\windows\DUMP4fa5.tmp
2011-01-08 08:47:50 34304 —-a-w- c:\windows\system32\atmlib.dll
2011-01-08 06:28:49 292352 —-a-w- c:\windows\system32\atmfd.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: WDC_WD16 rev.04.0 -> Harddisk0\DR0 -> \Device\Ide\iaStor0
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8661E439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x866247d0]; MOV EAX, [0x8662484c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 ntkrnlpa!IofCallDriver[0x81E61912] -> \Device\Harddisk0\DR0[0x85F812F0]
3 CLASSPNP[0x8819F8B3] -> ntkrnlpa!IofCallDriver[0x81E61912] -> [0x866ADB20]
\Driver\iaStor[0x86609E78] -> IRP_MJ_CREATE -> 0x8661E439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x147; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
detected disk devices:
\Device\Ide\IAAStorageDevice-0 -> \??\IDE#DiskWDC_WD1600BEVS-75RST0___________________04.01G04#4&20766cbe&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user != kernel MBR !!!
sectors 312581806 (+255): user != kernel
Warning: possible TDL4 rootkit infection !
TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
.
============= FINISH: 18:07:56.68 ===============