Dr.Zoidberg
Topic Starter
Hello, i just got this nasty infection that happend few days [on 03/5/2012 6:29:31 PM by ESET report] ago in my pc, and my ESET Smart Security 4.2 can't handle it
PROBLEMS:
——————————-
- Obvious security risk
- Every few minutes pc has this unusual FPS/LAG spike
*** [While playing games, and other HW intensive stuff]
*** [Made my League of Legends client crash with my pc]
- ESET Smart Security 4.2 Web protection is disabled what i think by this trojan, it reports "Non-Fuctional" and Personal firewall "No filtering mode defined. The personal firewall is malfunctioning. A computer restart may be required."
*** I have tried restarting multiple times and no luck
CAUSE:
——————————-
What i think and my ESET reports is a Win32/Sirefef.DA trojan that keeps injecting its self into operating memory over and over again. It allso reported infection in file C:\Windows\System32\drivers\csc.sys [Win32/Sirefef.DA trojan] which i successfully deleted. Yet again it appears in operating memory, and Web protection is still "off"
DDS LOGS:
——————————-
DDS:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by [removed] at 16:14:06.74 on 08/05/2012
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.3.1
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.1.1033.18.2047.770 [GMT 2:00]
.
AV: ESET Smart Security 4.2 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
SP: ESET Smart Security 4.2 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
c:\xampp\apache\bin\httpd.exe
C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hi-Rez Studios\HiPatchService.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\xampp\apache\bin\httpd.exe
C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
C:\Program Files\A4Tech\Mouse\Amoumain.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\DAEMON Tools Lite\DTLite.exe
C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
c:\xampp\mysql\bin\mysqld.exe
C:\Program Files\Nitro PDF\Reader 2\NitroPDFReaderDriverService2.exe
C:\Windows\system32\PnkBstrA.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conhost.exe
C:\Program Files\Winamp\winamp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\explorer.exe
C:\Windows\system32\wbengine.exe
C:\Windows\System32\vds.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
C:\Program Files\Pando Networks\Media Booster\PMB.exe
C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.54\deploy\LoLLauncher.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Users\Ilija\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = my.daemon-search.com
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft
shared\windows live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer
\skypeieplugin.dll
BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.0 runtime\bin
\jp2ssv.dll
TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\DTLite.exe" -autorun
uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe" /MINIMIZED
uRun: [OfficeSyncProcess] "c:\program files\microsoft office\office14\MSOSYNC.EXE"
mRun: [RTHDVCPL] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [RivaTunerStartupDaemon] "c:\program files\rivatuner v2.24 msi master overclocking arena 2009 edition
\RivaTunerWrapper.exe" /S
mRun: [egui] "c:\program files\eset\eset smart security\egui.exe" /hide /waitservice
mRun: [BCSSync] "c:\program files\microsoft office\office14\BCSSync.exe" /DelayServices
mRun: [WheelMouse] c:\program files\a4tech\mouse\Amoumain.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office14\EXCEL.EXE/3000
IE: Se&nd; to OneNote - c:\progra~1\micros~2\office14\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office
\office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office
\office14\ONBttnIELinkedNotes.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars
\internet explorer\skypeieplugin.dll
LSP: mswsock.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab
TCP: {2642EACE-45B8-4563-A17D-0C8C0F5D81BF} = 192.168.1.1
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared
\office14\MSOXMLMF.DLL
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer
\skypeieplugin.dll
Notify: ecojink - c:\windows\system32\config\systemprofile\appdata\local\ecojink.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office14\GROOVEEX.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\ilija\appdata\roaming\mozilla\firefox\profiles\1xvemov3.default\
FF - prefs.js: browser.startup.homepage - about:home
FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL
FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\battlelog web plugins\0.80.0\npesnlaunch.dll
FF - plugin: c:\program files\battlelog web plugins\sonar\0.70.0\npesnsonar.dll
FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\nitro pdf\reader 2\npdf.dll
FF - plugin: c:\program files\nitro pdf\reader 2\npnitromozilla.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - plugin: c:\program files\oracle\javafx 2.0 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\program files\pando networks\media booster\npPandoWebPlugin.dll
FF - plugin: c:\users\ilija\appdata\locallow\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: c:\users\ilija\appdata\roaming\mozilla\firefox\profiles\1xvemov3.default\extensions\{000f1ea4-5e08-4564-a29b-
29076f63a37a}\plugins\npsoe.dll
FF - plugin: c:\users\ilija\appdata\roaming\mozilla\firefox\profiles\1xvemov3.default\extensions
\[removed]\plugins\npBP4FUpdater.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_235.dll
FF - plugin: c:\windows\system32\npdeployJava1.dll
FF - plugin: c:\windows\system32\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
P2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files\hi-rez studios\HiPatchService.exe [2012-3
-20 8704]
R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-9-10 18432]
R2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x32.sys [2011-6-11 21992]
R2 eamonm;eamonm;c:\windows\system32\drivers\eamonm.sys [2010-12-21 137144]
R2 ekrn;ESET Service;c:\program files\eset\eset smart security\ekrn.exe [2011-1-12 810144]
R2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\nitro pdf\reader
2\NitroPDFReaderDriverService2.exe [2011-12-20 196904]
R2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files\nvidia corporation\nvidia update core\daemonu.exe [2012-4
-21 1262912]
R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [2011-9-29 21632]
R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\drivers\Rt86win7.sys [2011-3-21 362600]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework
\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 epfwwfp;epfwwfp;c:\windows\system32\drivers\epfwwfp.sys [2010-12-21 41336]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-6-29 135664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash
\FlashPlayerUpdateService.exe [2012-4-16 257696]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-14 229888]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-6-29 135664]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\microsoft
office\office14\GROOVE.EXE [2010-1-21 30963576]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012
-5-3 129976]
S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared
\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2011-6-17 15872]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-6-17 52224]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\microsoft sql server\100\shared\sqladhlp.exe
[2009-7-23 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009-3-30 239336]
.
=============== File Associations ===============
.
regfile="regedit.exe" "%1"
.
=============== Created Last 30 ================
.
2012-05-08 02:43:17 ——– d—–w- c:\program files\Unlocker
2012-05-08 00:54:38 ——– d—–w- c:\users\ilija\appdata\local\{E29B60FB-F63A-444E-8EC6-280FFC5947FC}
2012-05-08 00:53:17 ——– d—–w- c:\users\ilija\appdata\local\{9A8FC17E-A818-4650-B976-2ED84657849C}
2012-05-08 00:45:25 ——– d—–w- c:\users\ilija\appdata\local\{7EFB9C29-33A8-436B-8FF2-DB1A286F29B9}
2012-05-08 00:43:49 ——– d—–w- c:\users\ilija\appdata\local\{04B11819-096E-4742-942B-2E0DA31530B9}
2012-05-07 22:42:28 ——– d—–w- c:\users\ilija\appdata\local\{AAA0595A-FE57-4FB4-A788-EF6B9E910D61}
2012-05-07 22:41:07 ——– d—–w- c:\users\ilija\appdata\local\{55103010-5EAE-4C44-A181-BF13B5A1B97A}
2012-05-06 16:54:56 ——– d—–w- c:\users\ilija\appdata\local\{14DB7CFF-8780-4AD8-A9D8-7810D8D2ED99}
2012-05-06 16:53:41 ——– d—–w- c:\users\ilija\appdata\local\{8F3DD621-AA2B-43FD-A3AA-B262AB26B0CA}
2012-05-03 16:50:07 ——– d—–w- c:\program files\Mozilla Maintenance Service
2012-05-03 16:50:04 129976 —-a-w- c:\program files\mozilla firefox\maintenanceservice.exe
2012-05-03 16:50:03 157352 —-a-w- c:\program files\mozilla firefox\maintenanceservice_installer.exe
2012-05-03 16:39:15 0 –sha-w- c:\windows\system32\dds_trash_log.cmd
2012-05-02 19:52:17 ——– d—–w- c:\users\ilija\appdata\local\{681786E8-3D5B-475F-9B7D-10906A341A5B}
2012-05-02 19:52:06 ——– d—–w- c:\users\ilija\appdata\local\{86C88F4E-1F75-48C9-93B9-6D340117FF2F}
2012-04-27 10:12:46 6734704 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{f585db1b-5bbc-
4549-bedf-0752121d7e41}\mpengine.dll
2012-04-25 13:22:41 ——– d—–w- c:\users\ilija\appdata\local\My Games
2012-04-21 00:54:21 19584320 —-a-w- c:\windows\system32\nvoglv32.dll
2012-04-21 00:54:21 11348288 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2012-04-21 00:54:20 5981504 —-a-w- c:\windows\system32\nvcuda.dll
2012-04-21 00:54:20 2524992 —-a-w- c:\windows\system32\nvcuvid.dll
2012-04-21 00:54:20 2444608 —-a-w- c:\windows\system32\nvcuvenc.dll
2012-04-21 00:54:20 17551680 —-a-w- c:\windows\system32\nvcompiler.dll
2012-04-20 14:07:17 ——– d—–w- c:\progra~2\Battle.net
2012-04-18 15:39:15 ——– d—–w- c:\users\ilija\appdata\local\{26144760-0C85-48DE-B2C4-F36270523087}
2012-04-18 15:38:55 ——– d—–w- c:\users\ilija\appdata\local\{DBE42FDB-73CE-46D9-8AD6-7A004E9A8410}
2012-04-16 21:00:52 ——– d—–w- c:\program files\GOG.com
2012-04-16 15:39:13 419488 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-16 15:37:54 ——– d—–w- c:\users\ilija\appdata\local\{551B4A65-2537-4D28-91CF-D0CC2EC27A2B}
2012-04-16 15:37:42 ——– d—–w- c:\users\ilija\appdata\local\{5E06D4F0-F373-4741-BB5D-06603B205CA4}
2012-04-15 18:50:34 ——– d—–w- c:\users\ilija\appdata\local\{889DF813-0FDC-4124-BDE3-93A8931F0B37}
2012-04-15 18:50:23 ——– d—–w- c:\users\ilija\appdata\local\{4D73F780-EE1A-4EB7-954B-20120E32C606}
2012-04-15 08:06:03 ——– d—–w- c:\users\ilija\appdata\local\{56C1ABB5-922A-4D48-82FE-EA2E4A353095}
2012-04-14 20:05:48 ——– d—–w- c:\users\ilija\appdata\local\{A04B2113-B277-4B17-B088-7E680F701B37}
2012-04-12 01:04:14 ——– d—–w- C:\BrickForce
.
==================== Find3M ====================
.
2012-05-04 22:16:27 70304 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-04-03 17:16:00 881984 —-a-w- c:\windows\system32\nvgenco32.dll
2012-04-03 17:16:00 8029504 —-a-w- c:\windows\system32\nvwgf2um.dll
2012-04-03 17:16:00 61248 —-a-w- c:\windows\system32\OpenCL.dll
2012-04-03 17:16:00 2367808 —-a-w- c:\windows\system32\nvapi.dll
2012-04-03 17:16:00 15279424 —-a-w- c:\windows\system32\nvd3dum.dll
2012-04-03 17:16:00 1000256 —-a-w- c:\windows\system32\nvdispco32.dll
2012-04-03 15:03:05 645440 —-a-w- c:\windows\system32\nvvsvc.exe
2012-04-03 15:03:05 62272 —-a-w- c:\windows\system32\nvshext.dll
2012-04-03 15:03:05 108352 —-a-w- c:\windows\system32\nvmctray.dll
2012-04-03 15:01:56 2759488 —-a-w- c:\windows\system32\nvsvc.dll
2012-04-03 15:01:45 3914048 —-a-w- c:\windows\system32\nvcpl.dll
2012-04-03 05:16:04 423744 —-a-w- c:\windows\system32\nvStreaming.exe
2012-02-23 08:18:36 237072 ——w- c:\windows\system32\MpSigStub.exe
.
============= FINISH: 16:14:52.72 ===============
P.S.
——————————-
I also included a ESET Detected Threat log and a picture of Quarantine log, and that Trojan virus keep injecting its self every 50s or soo.