This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

KeyLogger and Locked Files on Virus Scan

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

That's weird - I have my list of programs but I don't have run or access to "my computer"…that are is blank… I don't know what time it is for you but I'm sure at this point it is very late - let's try again tomorrow…Thank you for all your help today and lets hope it goes smoother tomorrow!! :) - what should I do to get access to my computer or run command?
You can run unhide.exe and see if that brings back you menu items. We will likely have to run it again after we get everything else sorted out so don't expect all your files to miraculously show up when you run it, but let's cross our fingers that at least that will work. If that does not work at all, then I'd like you to go ahead and boot in to safe mode with networking again and then re-run Combofix. It will prompt you for an update which you should allow. Do not do ANYTHING else while it runs. Post the resulting log. (It may reboot the machine which is normal) If you are unable to do that - then post and let me know. I will be in meetings all day tomorrow - so it will be after work before I'll be able to respond but I will do so as soon as I'm able.
Ok - so after spending the morning redoing the instructions from yesterday - over and over and over - I finally have most of the computer back - all programs show and the desktop is back to normal….But I can't use google - only IE and when I do it keeps redirecting me to weird spammy pages unless I type the exact address in to the http bar. System Fix is still showing in the program lists on the start menu - and I was able to run rkill and malwarebytes in safe mode but it found no infections. I'm running combofix now - it didn't want to run because of AVG and Microsoft Essentials - but I couldn't get either program to disable, I tried deleting them from the system but it wouldn't let me…I'll post it when it's done Nicole
ComboFix 11-12-13.03 - Phil 12/14/2011 14:27:46.1.4 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3039.2209 [GMT -5:00]
Running from: e:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
e:\docume~1\Phil\LOCALS~1\Temp\AdskCleanup.0001.dir.0001\~de87df.tmp
e:\docume~1\Phil\LOCALS~1\Temp\AdskCleanup.0001.dir.0001\~df394b.tmp
e:\documents and settings\Phil\Application Data\Microsoft\Internet Explorer\Quick Launch\System Fix.lnk
e:\documents and settings\Phil\Local Settings\Temp\AdskCleanup.0001.dir.0001\~de87df.tmp
e:\documents and settings\Phil\Local Settings\Temp\AdskCleanup.0001.dir.0001\~df394b.tmp
e:\documents and settings\Phil\Start Menu\Programs\System Fix
e:\documents and settings\Phil\Start Menu\Programs\System Fix\System Fix.lnk
e:\documents and settings\Phil\Start Menu\Programs\System Fix\Uninstall System Fix.lnk
G:\Autorun.inf
.
.
((((((((((((((((((((((((( Files Created from 2011-11-14 to 2011-12-14 )))))))))))))))))))))))))))))))
.
.
2011-12-14 20:01 . 2011-12-14 20:01 29904 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\MpKsl2513e80b.sys
2011-12-14 20:01 . 2011-12-14 20:01 56200 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\offreg.dll
2011-12-14 12:43 . 2011-11-21 10:47 6823496 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\mpengine.dll
2011-12-14 12:31 . 2011-12-14 12:31 ——– d—–w- e:\windows\system32\wbem\Repository
2011-12-14 12:31 . 2011-12-14 12:31 ——– d—–w- e:\documents and settings\All Users\Application Data\AVG10
2011-12-14 12:30 . 2011-12-14 12:30 ——– d—–w- e:\documents and settings\Phil\Application Data\AVG Secure Search
2011-12-14 12:30 . 2011-12-14 12:30 ——– d—–w- E:\$AVG
2011-12-14 12:30 . 2011-12-14 12:31 ——– d—–w- e:\program files\AVG Secure Search
2011-12-14 12:30 . 2011-12-14 12:30 ——– d–h–w- e:\program files\Common Files\AVG Secure Search
2011-12-07 02:55 . 2011-12-07 02:55 ——– d–h–w- e:\windows\PIF
2011-12-07 02:52 . 2011-12-13 19:48 ——– d—–w- e:\documents and settings\Administrator
2011-11-22 12:59 . 2011-11-22 12:59 ——– d—–w- e:\documents and settings\Phil\Local Settings\Application Data\VS Revo Group
2011-11-22 12:59 . 2009-12-30 16:20 27064 —-a-w- e:\windows\system32\drivers\revoflt.sys
2011-11-22 12:59 . 2011-11-22 12:59 ——– d–h–w- e:\program files\VS Revo Group
2011-11-22 11:48 . 2011-08-31 22:00 22216 —ha-w- e:\windows\system32\drivers\mbam.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-21 10:47 . 2011-08-15 23:56 6823496 —-a-w- e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-11-17 14:00 . 2011-05-18 12:05 414368 —-a-w- e:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 12:42 . 2011-10-24 12:42 20909356 —-a-w- E:\GEDC0052.zip
2011-10-10 14:22 . 2010-12-09 01:05 692736 —h–w- e:\windows\system32\inetcomm.dll
2011-09-28 07:06 . 2004-08-04 12:00 599040 —-a-w- e:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2007-10-09 17:03 611328 —-a-w- e:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2004-08-04 12:00 220160 —ha-w- e:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2004-08-04 12:00 20480 —-a-w- e:\windows\system32\oleaccrc.dll
1997-06-23 08:00 123664 –sha-w- e:\windows\system32\Msjint35.dll
1997-06-23 17:06 24848 –sha-w- e:\windows\system32\Msjter35.dll
1997-06-23 17:06 252176 –sha-w- e:\windows\system32\Msrd2x35.dll
1997-06-23 17:06 287504 –sha-w- e:\windows\system32\Msxbse35.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "e:\program files\Yahoo!\Companion\Installs\cpn0\YTNavAssist.dll" [2011-01-21 213816]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{A31F34A1-EBD2-45A2-BF6D-231C1B987CC8}]
[HKEY_CLASSES_ROOT\YTNavAssist.YTNavAssistPlugin]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2011-05-30 15:33 2495816 —-a-w- e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll" [2011-05-30 2495816]
.
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cdloader"="e:\documents and settings\Phil\Application Data\mjusbsp\cdloader2.exe" [2011-08-23 50592]
"RCUI"="e:\progra~1\RINGCE~1\RINGCE~1\RCUI.exe" [2010-11-23 500992]
"RCHotKey"="e:\progra~1\RINGCE~1\RINGCE~1\RCHotKey.exe" [2010-11-23 38144]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG_TRAY"="e:\program files\AVG\AVG10\avgtray.exe" [2011-09-10 2338656]
"NvCplDaemon"="e:\windows\system32\NvCpl.dll" [2006-10-31 7634944]
"nwiz"="nwiz.exe" [2006-10-31 1622016]
"NvMediaCenter"="e:\windows\system32\NvMcTray.dll" [2006-10-31 86016]
"RTHDCPL"="RTHDCPL.EXE" [2009-08-24 18702336]
"LXBXCATS"="e:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="e:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"FaxCenterServer4_in_1"="e:\program files\Lexmark 7100 Series\fm3032.exe" [2004-12-06 286720]
"EzPrint"="e:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"Microsoft Default Manager"="e:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]
"boincmgr"="e:\program files\BOINC\boincmgr.exe" [2010-09-23 4543232]
"boinctray"="e:\program files\BOINC\boinctray.exe" [2010-09-23 58112]
"HPWQTOOLBOX"="e:\program files\Hewlett-Packard\HP Deskjet 9800 Series\Toolbox\HPWQTBX.exe" [2005-06-03 335872]
"MpsOnn"="e:\windows\System32\spool\DRIVERS\W32X86\3\MpsOnn.exe" [2007-05-27 28232]
"Adobe ARM"="e:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="e:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"MSC"="e:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
.
e:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoCAD Startup Accelerator.lnk - e:\program files\Common Files\Autodesk Shared\acstart16.exe [2004-2-24 10872]
subst.lnk - e:\windows\system32\subst.exe [2004-8-4 9216]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0e:\progra~1\AVG\AVG10\avgchsvx.exe /sync\0e:\progra~1\AVG\AVG10\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- e:\program files\Messenger\msmsgs.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"e:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"e:\\Program Files\\AVG\\AVG10\\avgmfapx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"e:\\WINDOWS\\system32\\lxbxcoms.exe"=
"e:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxbxPSWX.EXE"=
"e:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"e:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"e:\\Program Files\\RingCentral\\RingCentral Call Controller\\RCUI.exe"=
"e:\\Documents and Settings\\Phil\\Application Data\\mjusbsp\\magicJack.exe"=
"e:\\Program Files\\AVG\\AVG10\\avgdiagex.exe"=
"e:\\Program Files\\AVG\\AVG10\\avgnsx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
R0 AVGIDSEH;AVGIDSEH;e:\windows\system32\drivers\AVGIDSEH.sys [9/13/2010 3:27 PM 22992]
R1 Avgtdix;AVG TDI Driver;e:\windows\system32\drivers\avgtdix.sys [11/9/2010 10:20 PM 297168]
R1 BIOS;BIOS;e:\windows\system32\drivers\BIOS.sys [12/8/2010 1:53 PM 13696]
R1 MpKsl2513e80b;MpKsl2513e80b;e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4F678CED-A1DD-4F4F-871B-9C0AC760CDC8}\MpKsl2513e80b.sys [12/14/2011 3:01 PM 29904]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;e:\windows\system32\drivers\lne100v5.sys [12/8/2010 8:51 AM 36224]
S0 Avgrkx86;AVG Anti-Rootkit Driver;e:\windows\system32\DRIVERS\avgrkx86.sys –> e:\windows\system32\DRIVERS\avgrkx86.sys [?]
S1 Avgldx86;AVG AVI Loader Driver;e:\windows\system32\DRIVERS\avgldx86.sys –> e:\windows\system32\DRIVERS\avgldx86.sys [?]
S1 MpKsl78bf1b8c;MpKsl78bf1b8c;\??\e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7FDE7CDA-1824-4018-96CA-88626BF90FC5}\MpKsl78bf1b8c.sys –> e:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{7FDE7CDA-1824-4018-96CA-88626BF90FC5}\MpKsl78bf1b8c.sys [?]
S2 AVGIDSAgent;AVGIDSAgent;"e:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" –> e:\program files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [?]
S2 avgwd;AVG WatchDog;e:\program files\AVG\AVG10\avgwdsvc.exe [2/8/2011 4:33 AM 269520]
S2 gupdate;Google Update Service (gupdate);e:\program files\Google\Update\GoogleUpdate.exe [12/13/2010 9:35 AM 136176]
S3 Ambfilt;Ambfilt;e:\windows\system32\drivers\Ambfilt.sys [12/8/2010 1:56 PM 1684736]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;e:\program files\AVG\AVG10\Toolbar\ToolbarBroker.exe [5/12/2011 8:38 AM 1025352]
S3 AVGIDSDriver;AVGIDSDriver;e:\windows\system32\DRIVERS\AVGIDSDriver.Sys –> e:\windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
S3 AVGIDSFilter;AVGIDSFilter;e:\windows\system32\DRIVERS\AVGIDSFilter.Sys –> e:\windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
S3 AVGIDSShim;AVGIDSShim;e:\windows\system32\DRIVERS\AVGIDSShim.Sys –> e:\windows\system32\DRIVERS\AVGIDSShim.Sys [?]
S3 gupdatem;Google Update Service (gupdatem);e:\program files\Google\Update\GoogleUpdate.exe [12/13/2010 9:35 AM 136176]
S3 McComponentHostService;McAfee Security Scan Component Host Service;"e:\program files\McAfee Security Scan\2.1.121\McCHSvc.exe" –> e:\program files\McAfee Security Scan\2.1.121\McCHSvc.exe [?]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSL2513E80B
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-14 e:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-12-13 14:35]
.
2011-12-14 e:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- e:\program files\Google\Update\GoogleUpdate.exe [2010-12-13 14:35]
.
2011-12-14 e:\windows\Tasks\MP Scheduled Scan.job
- e:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride =
IE: Google Sidewiki… - e:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_70C5B381380DB17F.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.2.1
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - e:\program files\AVG\AVG10\Toolbar\IEToolbar.dll
.
.
——- File Associations ——-
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-Adobe Flash Player ActiveX - e:\windows\system32\Macromed\Flash\FlashUtil10w_ActiveX.exe
AddRemove-Google Chrome - e:\program files\Google\Chrome\Application\14.0.835.186\Installer\setup.exe
AddRemove-McAfee Security Scan - e:\program files\McAfee Security Scan\uninstall.exe
AddRemove-{2318C2B1-4965-11d4-9B18-009027A5CD4F} - e:\program files\Google\Google Toolbar\Component\GoogleToolbarManager_4E7D715D860E20E1.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-12-14 15:02
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 e:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE255"): The system cannot find the file specified.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3248)
e:\windows\system32\WININET.dll
e:\progra~1\RINGCE~1\RINGCE~1\RCHotKeyHook.dll
e:\windows\system32\ieframe.dll
e:\windows\system32\mshtml.dll
e:\windows\system32\msls31.dll
e:\windows\system32\jscript.dll
e:\windows\system32\webcheck.dll
e:\windows\system32\WPDShServiceObj.dll
e:\windows\system32\PortableDeviceTypes.dll
e:\windows\system32\PortableDeviceApi.dll
e:\windows\system32\ImgUtil.dll
e:\windows\system32\pngfilt.dll
e:\windows\system32\Dxtrans.dll
e:\windows\system32\Dxtmsft.dll
.
———————— Other Running Processes ————————
.
e:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
e:\program files\Java\jre6\bin\jqs.exe
e:\windows\system32\nvsvc32.exe
e:\windows\System32\snmp.exe
e:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
e:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
e:\windows\RTHDCPL.EXE
e:\windows\system32\lxbxcoms.exe
e:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
e:\program files\BOINC\boinc.exe
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\documents and settings\All Users\Application Data\BOINC\projects\www.worldcommunitygrid.org\wcg_c4cw_lmps_6.40_windows_intelx86
e:\program files\Common Files\Java\Java Update\jucheck.exe
e:\program files\AutoCAD 2005\acad.exe
e:\docume~1\Phil\LOCALS~1\Temp\AdskCleanup.0001
e:\program files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
e:\program files\Common Files\Autodesk Shared\WSCommCntr1.exe
e:\program files\Adobe\Reader 10.0\Reader\AcroRd32.exe
e:\program files\Adobe\Reader 10.0\Reader\AcroRd32.exe
.
**************************************************************************
.
Completion time: 2011-12-14 15:19:03 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-14 20:18
ComboFix2.txt 2011-12-12 11:39
.
Pre-Run: 466,974,113,792 bytes free
Post-Run: 467,246,444,544 bytes free
.
- - End Of File - - F2D9C9872D794DB1B28D9466DE367536
Back when you ran DDS did it create a file on your desktop called attach.txt? If so can you open that and copy/paste the contents for me? One thing that has me a bit puzzled is that you show as running Windows from your E drive and not your C drive as would be more typical. Have you renamed the drives on your system and/or is that normal for what you typically see on your computer? I know last night you mentioned your C drive showed as empty (even though we know it wasn't) ant that's why I'm asking. I'm trying to determine if you've don't some renaming or are running from external drives (which is OK) or if that is a symptom the malware is presenting in conjunction with the other items you've mentioned.
My E drive is the C drive - For whatever reason when I installed Windows it named it E and I haven't been able to figure out how to change it - I know it's not important but it's frustrating to try and tell people when I'm not available to fix or modify the computer that "yes, I know there is no C drive, but no, the computer is not broken…I said E"…I tried to fix it but I was told I would have to repartition and wipe and othe various tasks that seemed too much! I do see a C drive - which we've never had before - but it just has one folder in it - BentleyDownloads - with set up files for Windows Bentley System In in it - I've seen the bentley system folder before but I din't know what it is….but my husband informed me that it's necessary to view his Autocad files - why it's on it's own frive though i don't know - I believe it is also on the E drive The external drive is the I - but we don't run from thaat - however I do scan it regularly to ensure nothing hides there - but it turned out it was disconencted the last six months :( so it wouldn't have deen affected. This morning I awaoke to still no google, but Microsoft Essentials was running (cause I can't disable or delete it not because I'm a bad listener) and it found a "Trojan:Win32/Fakesysdef" - so I guess we are getting closer if my anti-virus is now able to see it??? I do have all my files and folders back - but some (like Google) don't work, some say they are empty (like Yahoo! Games) and the "System Fix" is still in the program bar so I would guess it's still on the comp. I can also search the internet now with out the wierd spam redirect i was getting yesterday. I couldn't find an attach.txt file - do you want a new dds amd GMer log?
It's just fine that it's called the E drive. No worries at all. I just wanted to be 100% sure that was normal and not another weird manifestation of this malware. System Fix is not normally this stubborn, but malware is often modified to resist our efforts to remove it and I wanted to ensure that this wasn't some odd new change to what we've seen before. The E drive thing is actually good news. I hadn't really been worried about it before (as I'd seen it in logs previously) but given the stubborn nature of this one I just thought it would be a good time to ask.
No need to run DDS and get the attach file now that I know about the E drive. That answers the question on that one.

I can definitely see something going on in the Combofix logs, but the problem is that it doesn't tell us exactly what it is, so we are going to do need to do a little more work here.

I believe GMER crashed the system previously. But let's go ahead and try doing it a little differently.

It would be wise to try and get RKill to run successfully before you try to run any of the following. This could take several attempts as you know so please be patient. With System Fix I have found that continuing to try and run programs even if they seem to not want to run may actually eventually (after 4-5 tries) actually get them to run. But there are no hard and fast rules with this infection. Again with RKill the thing you want to remember is after running it, try not to reboot the computer and run the tool immediately after it successfully runs.


If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that may have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one - make sure it is UNCHECKED)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and paste it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




Please read carefully and follow these steps.

Scan With RootKitUnHooker

  • Please choose one link and download Rootkit Unhooker and save it to your desktop.

    Link 1
    Link 2
    Link 3
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:/ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"



Finally, in Microsoft Security Essentials:
  • Please open it and click on the History tab
  • please look for that most recent threat found that you've been seeing and highlight it
  • When you do this, in the bottom of the screen you'll notice a section that should have a scroll bar to the right hand section
  • If you scroll to the very bottom of the section it will show you the location of where that suspicious file was located under a section called Items
  • Please use your mouse to highlight the location of the file and then click on Control + C. (Note: You won't be able to right-click and copy here)
  • Then you can use Control + V to paste that into your reply. If you are unable to do this, then please carefully copy the file location down and note it in your reply to me.


If you have any trouble with any of these instructions you can try the next one. These are NOT dependent on each other.

I will be in and out of meetings today but will keep and eye on the thread as best I can during the day. You can post logs as you get them and I'll do my best to respond as quick as I can. *Crossing fingers*
I am at work all day - will give this a try tonight - I just got a frantic phone call that all the pop ups about massive system errors and viruses has started again :( He says his desktop is filled with them. I had him disconnect the internet and the external drive we've been backing up to until I get there - I will let you know how it goes and post the logs tonight - but I don't get home until 8pm. Thanks, Nicole
Ok - Rkill still doesn't seem to completly work. The only one I can get to open is the dos one, but it immediatly brings up an "error" message (which I ignore) and a Windows message telling me the program has encountered a problem and shut down send or dont send an error report (which i also ignore). it runs for a few telling me the process is in use by another program and it can't do anything with it and then it just stops doing stuff - sometimes it'll just sit there with a blinking cursor 10 minutes or so before I shut it down.

The gmer log is here - though when I download it and open it all those options that are supposeed to be checked on the side are not checked and won't let me check it:

GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-12-16 06:49:58
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: E:\DOCUME~1\Phil\LOCALS~1\Temp\fwddapow.sys


—- Files - GMER 1.0.15 —-

File E:\WINDOWS\$NtUninstallKB30344$\1843862383 0 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\@ 2048 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\bckfg.tmp 852 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\cfg.ini 322 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\Desktop.ini 4608 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\keywords 0 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\kwrd.dll 223744 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\L 0 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\L\niseemng 297168 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\lsflt7.ver 5176 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U 0 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U\00000001.@ 2048 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U\00000002.@ 224768 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U\00000004.@ 1024 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U\80000000.@ 1024 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U\80000004.@ 12800 bytes
File E:\WINDOWS\$NtUninstallKB30344$\1843862383\U\80000032.@ 98304 bytes
File E:\WINDOWS\$NtUninstallKB30344$\4046811598 0 bytes

—- EOF - GMER 1.0.15 —-

TDSkiller won't open at all - no reasson given, like my google icon it simply does nothing when i click it or try to right click and then open.

Root Kit Unhooker also does not run, a window comes up that states "please wait a few minutes, initializing" but nothing happens, it has an indicator bar, but nothing is showing up on it.


I also get an error box when I try to open these programs - states error loading/opening driver".
Would wiping the machine take care of the issue?


This is the last Microsoft Essential Scan on 12/14:
Category: Trojan

Description: This program is dangerous and executes commands from an attacker.

Recommended action: Remove this software immediately.

Security Essentials detected programs that may compromise your privacy or damage your computer. You can still access the files that these programs use without removing them (not recommended). To access these files, select the Allow action and click Apply actions. If this option is not available, log on as administrator or ask the security administrator for help.

Items:
file:E:\Documents and Settings\All Users\Application Data\dsnLDPYFOb5KGM.exe
file:E:\Documents and Settings\All Users\Application Data\VcJqacIyhU.exe
file:e:\documents and settings\phil\Desktop\System Fix.lnk
folder:e:\documents and settings\phil\Start Menu\Programs\System Fix\

Get more information about this item online.
That gives me a lot more information than we've had before believe it or not. Let's give this a shot and see if this infection is as smart as it thinks it is. We are going to try and manually remove (via Combofix) all those entries that Microsoft Security Essentials is finding but not removing.


1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix (if you can't disable them, I'm including a switch in this fix to kill all non-essential processes so hopefully Combofix will kill any Antivirus processes that you can't disable manually).

3. Open notepad and copy/paste the text in the quotebox below into it:

KillAll::
File::
E:\Documents and Settings\All Users\Application Data\dsnLDPYFOb5KGM.exe
E:\Documents and Settings\All Users\Application Data\VcJqacIyhU.exe
e:\documents and settings\phil\Desktop\System Fix.lnk
e:\documents and settings\phil\Start Menu\Programs\System Fix\


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe. ComboFix may request an update; please allow it.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.



And yes, to answer your question, reformatting the hard drive would certainly take care of the problem, but you would need to be very careful that any personal data you put back on the machine is scanned by at least 3 different sources to ensure it is not infected before you load it back onto the reformatted machine to insure that you do not load infected data back onto a newly clean machine. There is still a reasonable chance we can solve this with a little persistence without needing to do that - but obviously the choice is yours.
I can't thank you enough for all your help and time! I would have liked to tackle this nasty bug until the end but he's going crazy without being able to complete his work and I have a final due this weekend I haven't even started thanks to this virus…we are in the process of wiping and starting over. I only copied a few of the Autocad files he needs - everything else is wiped. I'm an Apple user, so most of our important files and pics are on my computer….the major issue was his Autocad work. This computer is all that pays the bills! So close, but not enough time :( I do still have a few questions if that's ok… 1. If you were installing free virus, spyware, malware, etc. programs what would you install? 2. What are the best paid ones? 3. Which would you use? 4. What's the best web browser for people who aren't smart enough to avoid web pages that are potentially harmful? 5. Are we better off backing up to an always connected external hard drive or some internet back-up company? Thanks, Nicole
Paid is not always better when it comes to antivirus programs. I personally use Microsoft Security Essentials. I believe it is just as good as the paid ones. The important thing to remember is that no program will protect you from everything. Malware is being developed and released faster than we can develop fixes for things. Malware developers will always be ahead of us.

I also use Malwarebytes. I personally like the paid version (home users have a 1 time fee for a lifetime license) with some very good additional protection features, but the free version is also quite good. In the free version you do need to remember to update and run it regularly. The paid version can be set to do this on a schedule automatically.

I know you are on Windows XP - but it may be time to consider moving to Windows 7. It is definitely more secure and it also offers the ability to do a full disk image to an external hard drive in the event you were to need it . That disk image includes not only your files - but the full operating system as well. If you were to find yourself infected - you could be up and running again in a matter of minutes. Wiping and reinstalling all your programs on XP can take hours to days depending on what you have on a system. Certainly, it's just a suggestion, but one you may want to consider. If you stay on XP, please be sure to visit the MS update site very regularly and install any and all updates (critical and non-critical) for the best protection possible). In XP the firewall is also not very good. Windows 7 has a much better one.

No browser is fail safe. I personally like Chrome. If you install the Web of Trust add-on from the Chrome Store it gives you a visual indicator when you may be going to a potentially bad site. If you combine this with the paid version of Malwarebytes which blocks known bad sites or sites with links to known bad sites, you will significantly reduce your potential for infections.

Keeping the most exploited software up to date is your best defense. Keep your Java, Adobe, Windows and antivirus programs up to date at all times.

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

I would suggest you read:
Tony Klein's excellent article: How I got Infected in the First Place
PC Safety and Security–What Do I Need?
How to Prevent Malware

Please let me know if you have any other questions or need any other help with this. I'll be glad to help if I can.
Thanks! I have to say, some of us in the house know where to take our browser and where not to o.O. I would upgrade everything, but that same someone prefers to live in the stone age and continue to use archaic software and programs… I will read the article and download the software you recommend. Since the Apple I spend so little time with Windows I'm still stuck on Spybot and CCleaner…and I hear what you're saying, I've been formatting my setup for over an hour now. I upgraded his machine last year to a custom built that's supposed to handle the Autocad and internet at the same time, but Windows XP is certainly dragging! I will post if anything goes wrong with the installation, and again, thank you so much! I can't tell you how fabulous this site and your help is! Nicole

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI