hey guys so i have been attempting to get rid of a large amount of rootkits on my laptop for a few months now and last night i felt like i had it for sure…. after attempts on numerous malware protection and various anit viruses i tried the new Avast that my friend told me about recently a lot of anti viruses and things like malware bytes and spyboy search and destroy was not finding the rootkits that i knew were there….. avast managed to find 665 rootkits however it did not let me remove them or move them to chest….. when i tried to restart my computer it simply would not work! i couldt get in safe mode or normally so i had to reset to the point before avast was installed idk if this is a symptom of having rootkits on your comp but it has given me hell for the last few months and this my 2nd web forum site that i have come onto to seek help the first one was the Kaspersky Lab site and they didnt seem to want to help me after giving me a few directions
please help
i have windows vista 32 bit
p.s. i also notice that sometimes my sound doesnt work at all? however if i system restore to a month or so back the volume does work (it doesnt have the red X beside the volume icon in the bottom right hand corner) and i cant system restore to the point where i didnt have these virus issues
thanks for your time!
apologize for the double post but here is the D.D.S. i wouldnt be shocked if it didnt find anythin tho but im 100% sure there are rootkits…
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 22:48:08.99 on Mon 06/20/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_12
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\ehome\ehtray.exe
C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10n_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QZGLF4LA\index[1].scr
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k hpdevmgmt
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
mStart Page = hxxp://www.toshibadirect.com/dpdstart
mURLSearchHooks: N/A: {edd4f682-e67a-4175-bb45-c4066da2f7d9} - c:\program files\ourbabymaker_27\bar\1.bin\27SrcAs.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: {0631bff0-6846-48ca-982d-d62d7f376e97} - No File
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - No File
BHO: {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - No File
BHO: {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - No File
BHO: {201f27d4-3704-41d6-89c1-aa35e39143ed} - No File
BHO: {2EECD738-5844-4a99-B4B6-146BF802613B} - No File
BHO: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
BHO: {4be65d6a-a340-403d-9a23-70d640283b38} - No File
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Toolbar BHO: {588b75f1-89a0-4956-bd69-3f6e90394909} - c:\progra~1\ourbabymaker_27\bar\1.bin\27bar.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No File
BHO: {631acb68-57c3-48af-9cc5-fcec0837ffd3} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: {724d43a9-0d85-11d4-9908-00400523e39a} - No File
BHO: Search Assistant BHO: {825b4dd6-b751-4d90-802a-eae6754c1c7e} - c:\program files\ourbabymaker_27\bar\1.bin\27SrcAs.dll
BHO: {9030D464-4C02-4ABF-8ECC-5164760863C6} - No File
BHO: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\prxtbPag2.dll
BHO: {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - No File
BHO: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
BHO: {a916eefe-6a17-4d7d-a131-2738b260bb55} - No File
BHO: {a91abe53-e3e7-48fa-a7ca-dc9de9f8a883} - No File
BHO: {AA58ED58-01DD-4d91-8333-CF10577473F7} - No File
BHO: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - No File
BHO: {beea7fa9-d1f4-49a2-9b1f-6fb7a2d9bc2a} - No File
BHO: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
BHO: {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File
BHO: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File
BHO: {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - No File
BHO: {d5e9b421-c309-41de-9014-800a2adcdeb0} - No File
BHO: {d6a34acb-76fa-4a14-88ea-5d54797a2028} - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No File
BHO: {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - No File
BHO: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - No File
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: PageRage Toolbar: {9565115d-c7d6-46d3-bd63-b67b481a4368} - c:\program files\pagerage\prxtbPag2.dll
TB: OurBabymaker: {e0b0df9f-34a3-4db1-becc-621697348607} - c:\program files\ourbabymaker_27\bar\1.bin\27bar.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {724d43a0-0d85-11d4-9908-00400523e39a} - No File
TB: {c95a4e8e-816d-4655-8c79-d736da1adb6d} - No File
TB: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - No File
TB: {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
TB: {7d216e01-5ac0-4268-b014-7c35c769b312} - No File
TB: {0b84b4b4-8af8-4f1f-91fe-074a666f6425} - No File
TB: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No File
TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Google Update] "c:\users\owner\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [ATICustomerCare] "c:\program files\ati\aticustomercare\ATICustomerCare.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
mRunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
IE: Crawler Search
IE: Translate this web page with Babylon
IE: Translate with Babylon
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: %systemroot%\system32\GameLink.dll
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
AppInit_DLLs: c:\progra~1\google\google~1\GoogleDesktopNetwork3.dll
.
============= SERVICES / DRIVERS ===============
.
R? AMD FUEL Service;AMD FUEL Service
R? AMD Reservation Manager;AMD Reservation Manager
R? BFOHI;BFOHI
R? cg08;cg08
R? EULPXNGN;EULPXNGN
R? fssfltr;fssfltr
R? fsssvc;Windows Live Family Safety Service
R? gupdate;Google Update Service (gupdate)
R? MEMSWEEP2;MEMSWEEP2
R? MpKsl509e8d64;MpKsl509e8d64
R? MpKsl606cbc91;MpKsl606cbc91
R? npggsvc;nProtect GameGuard Service
R? OurBabyMaker_27Service;OurBabymaker Service
R? TeamViewer6;TeamViewer 6
R? test.sys;test.sys
R? TpChoice;Touch Pad Detection Filter driver
R? XDva317;XDva317
R? XDva321;XDva321
R? XDva323;XDva323
R? XDva327;XDva327
R? XDva345;XDva345
R? XDva346;XDva346
R? XDva347;XDva347
R? XDva348;XDva348
R? XDva349;XDva349
R? XDva359;XDva359
R? XDva362;XDva362
R? XDva366;XDva366
R? XDva367;XDva367
R? XDva370;XDva370
S? amdiox86;AMD IO Driver
S? gdwfpcd;G DATA WFP CD
S? nnfwdk;Nielsen WFP Driver
S? SCREAMINGBDRIVER;Screaming Bee Audio
.
=============== File Associations ===============
.
txtfile=c:\windows\notepad.exe %1
.
=============== Created Last 30 ================
.
2011-06-21 02:04:14 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{e6af8c61-df02-4986-b8ad-d79bcdb249d9}\mpengine.dll
2011-06-20 01:57:14 ——– d—–w- c:\progra~2\AVAST Software
2011-06-20 01:52:26 ——– d—–w- c:\program files\uTorrentBar
2011-05-29 23:42:33 ——– d—–w- c:\users\owner\appdata\local\PMB Files
2011-05-29 23:42:31 ——– d—–w- c:\progra~2\PMB Files
.
==================== Find3M ====================
.
2011-06-21 05:57:48 8192 —-a-w- c:\windows\system32\WlS0WndH.dll
2011-06-21 05:57:44 47104 —-a-w- c:\windows\system32\Sens.dll
2011-06-21 05:57:43 8704 —-a-w- c:\windows\system32\SensApi.dll
2011-06-21 05:57:42 559616 —-a-w- c:\windows\system32\netlogon.dll
2011-06-21 05:57:35 176640 —-a-w- c:\windows\system32\scecli.dll
2011-06-21 05:57:34 40448 —-a-w- c:\windows\system32\psbase.dll
2011-06-21 05:57:34 23040 —-a-w- c:\windows\system32\pstorsvc.dll
2011-06-21 05:57:32 18944 —-a-w- c:\windows\system32\keyiso.dll
2011-06-21 05:57:14 5120 —-a-w- c:\windows\system32\security.dll
2011-06-21 05:57:09 305664 —-a-w- c:\windows\system32\scesrv.dll
2011-01-02 16:07:06 702464 —-a-w- c:\program files\Uninstall Guffins.dll
2011-01-02 16:01:44 679936 —-a-w- c:\program files\Uninstall DailyBibleGuide.dll
.
============= FINISH: 22:49:26.63 ===============
1 last bit of info before i get off for the night, i remember that most of the rootkits were found somewhere in
C:\Windows\winsxs
and its funny i open that folder up and it sort of closes itself and its as if my comp is forced to log off and in….. real strange
bump… is any1 going to help?
nobody knows how to get rid of rootkits? gg comp i guess lol
Hi rukan23,
My name is
Tomk . I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
I will be working on your Malware issues, this may or may not, solve other issues you have with your machine. The fixes are specific to your problem and should only be used for the issues on this machine. Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear. It's often worth reading through these instructions and printing them for ease of reference. If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry. Please reply to this thread. Do not start a new topic.
Sorry it has taken so long to get a response…. but helpers look for logs with zero replies. You responded to your own topic 4 times which makes it look like you are being helped. I'm guessing that you didn't read the how to get help topic?
Anyhow… let's get started.
Scan with CKScanner:
Please download CKScanner from here to your Desktop.
Make sure that
CKScanner.exe is on the your Desktop before running the application!
Right-click on CKScanner.exe and select Run as Administrator ] then click Search For Files . After a very short time, when the cursor hourglass disappears, click Save List To File . A message box will verify the file saved Double-click on the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.
Due to inactivity this topic will be closed.
If you need help please start a new thread.
New members follow the instructions here
http://forums.whatthetech.com/you_Infected_t106388.html and start a new topic