Greetings,
For the last couple of days, I've had a nasty Rootkit as mentioned on Title, I do believe it also goes under the name ZeroAccess. It redirect my google searches, slows down my PC and crashes my internet browsers alot (I actually about to make this topic, but Firefox crashed). Under Process for Task Manager, it is named PING.EXE
I heard Combofix works wonders, but reading the Topic FAQ on your website says not to use it without permission, this rookit prevents the installiation of it anyway.
I've used the following virus programs with little/no luck:
Malwarebytes Anti-Malware
Spybot Search and Destroy (Actually disabled some of the code that the rootkit uses on my browser, I still get redirects but not as common as I did before)
TDSSKiller (It found NO threats)
Microsoft Security Essentials (It detects the virus, it says it has removed but 5 minutes later, it finds it again)
SUPERAntiSpyware
Avast
Microsoft Security Scanner.
Now I've had this problem before, but I managed to disable it, now I got another one. I will change my passwords to Forums, bank accounts etc once I get this removed.
I have Windows 7- 64bit.
DDS report on next post in thread
DDS Report:
mRun-x64: [SeePassword] C:\Program Files (x86)\SeePassword\SeePassword.exe
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRunOnce-x64: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…uot;ver=9.0.894
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Andrew\AppData\Roaming\Mozilla\Firefox\Profiles\p3o862tz.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.au/
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\1.118.0\npesnlaunch.dll
FF - plugin: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\GameSpy\Comrade\npcomrade.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\id Software\QuakeLive\npquakezero.dll
FF - plugin: C:\Users\Andrew\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
FF - plugin: C:\Users\Andrew\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Users\Andrew\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
.
============= SERVICES / DRIVERS ===============
.
R0 dc_fsf;dc_fsf;C:\Windows\system32\drivers\dc_fsf.sys –> C:\Windows\system32\drivers\dc_fsf.sys [?]
R0 dcrypt;dcrypt;C:\Windows\system32\drivers\dcrypt.sys –> C:\Windows\system32\drivers\dcrypt.sys [?]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\system32\DRIVERS\MpFilter.sys –> C:\Windows\system32\DRIVERS\MpFilter.sys [?]
R0 SCMNdisP;General NDIS Protocol Driver;C:\Windows\system32\DRIVERS\scmndisp.sys –> C:\Windows\system32\DRIVERS\scmndisp.sys [?]
R0 Soluto;Soluto;C:\Windows\system32\DRIVERS\Soluto.sys –> C:\Windows\system32\DRIVERS\Soluto.sys [?]
R1 AppleCharger;AppleCharger;C:\Windows\system32\DRIVERS\AppleCharger.sys –> C:\Windows\system32\DRIVERS\AppleCharger.sys [?]
R1 EIO64;EIO Driver;C:\Windows\system32\DRIVERS\EIO64.sys –> C:\Windows\system32\DRIVERS\EIO64.sys [?]
R1 ndistgb;TheGreenBow NDIS filter driver;C:\Windows\system32\DRIVERS\ndistgb.sys –> C:\Windows\system32\DRIVERS\ndistgb.sys [?]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-23 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-13 12368]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys –> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2011-8-12 140672]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe –> C:\Windows\system32\atiesrxx.exe [?]
R2 aswMonFlt;aswMonFlt;\??\C:\Windows\system32\drivers\aswMonFlt.sys –> C:\Windows\system32\drivers\aswMonFlt.sys [?]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2012-5-16 44768]
R2 BCUService;Browser Configuration Utility Service;C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2010-4-12 212232]
R2 GS In-Game Service;GS In-Game Service;C:\Program Files (x86)\GameTracker\GSInGameService.exe [2011-11-10 1677072]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-28 2343816]
R2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;H:\Games\Program Files\Tribes Ascend Beta\HiPatchService.exe [2012-2-11 8704]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-16 654408]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2012-5-16 1153368]
R2 TgbIke Starter;TgbIke Starter;C:\Windows\System32\tgbstarter.exe –> C:\Windows\System32\tgbstarter.exe [?]
R2 WSWNA3100;WSWNA3100;C:\Program Files (x86)\NETGEAR\WNA3100\WifiSvc.exe [2011-9-18 285152]
R3 Lycosa;Lycosa Keyboard;C:\Windows\system32\drivers\Lycosa.sys –> C:\Windows\system32\drivers\Lycosa.sys [?]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2010-8-12 15504]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys –> C:\Windows\system32\DRIVERS\Rt64win7.sys [?]
R4 IOMap;IOMap;\??\C:\Windows\system32\drivers\IOMap64.sys –> C:\Windows\system32\drivers\IOMap64.sys [?]
S1 vaoxqunb;vaoxqunb;\??\C:\Windows\system32\drivers\vaoxqunb.sys –> C:\Windows\system32\drivers\vaoxqunb.sys [?]
S2 BackupService;BackupService;C:\Users\Andrew\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe [2011-4-24 83512]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SolutoService;Soluto PCGenome Core Service;C:\Program Files\Soluto\SolutoService.exe [2012-4-24 584224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-6 257696]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys –> C:\Windows\system32\DRIVERS\atikmdag.sys [?]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys –> C:\Windows\system32\DRIVERS\atikmpag.sys [?]
S3 AppleChargerSrv;AppleChargerSrv;system32\AppleChargerSrv.exe –> system32\AppleChargerSrv.exe [?]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys –> C:\Windows\system32\drivers\AtihdW76.sys [?]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;H:\Games\Program Files\Dragon Age Origins\Dragon Age\bin_ship\daupdatersvc.service.exe [2011-8-15 25832]
S3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;C:\Windows\system32\DRIVERS\ManyCam_x64.sys –> C:\Windows\system32\DRIVERS\ManyCam_x64.sys [?]
S3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\system32\drivers\massfilter.sys –> C:\Windows\system32\drivers\massfilter.sys [?]
S3 MozillaMaintenance;Mozilla Maintenance Service;C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-5-16 129976]
S3 NisDrv;Microsoft Network Inspection System;C:\Windows\system32\DRIVERS\NisDrvWFP.sys –> C:\Windows\system32\DRIVERS\NisDrvWFP.sys [?]
S3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2012-3-26 291696]
S3 npggsvc;nProtect GameGuard Service;C:\Windows\system32\GameMon.des -service –> C:\Windows\system32\GameMon.des -service [?]
S3 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-24 370688]
S3 t3;Sound Blaster X-Fi Xtreme Audio (Vista);C:\Windows\system32\drivers\t3.sys –> C:\Windows\system32\drivers\t3.sys [?]
S3 tapoas;TAP-Win32 Adapter OAS;C:\Windows\system32\DRIVERS\tapoas.sys –> C:\Windows\system32\DRIVERS\tapoas.sys [?]
S3 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-1-18 2250616]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys –> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 vcd10bus;Virtual CD v10 Bus Enumerator;C:\Windows\system32\DRIVERS\vcd10bus.sys –> C:\Windows\system32\DRIVERS\vcd10bus.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe –> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
S3 ZTEusbnet;ZTE USB-NDIS miniport;C:\Windows\system32\DRIVERS\ZTEusbnet.sys –> C:\Windows\system32\DRIVERS\ZTEusbnet.sys [?]
SUnknown jkbhmbji;jkbhmbji; [x]
SUnknown jqmpmaub;jqmpmaub; [x]
.
=============== Created Last 30 ================
.
2012-05-18 17:31:32 50000 —-a-w- C:\Windows\System32\drivers\vaoxqunb.sys
2012-05-18 17:30:43 69000 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73E37F07-F850-4958-8F01-C03DD6BDF523}\offreg.dll
2012-05-18 06:34:04 8955792 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{73E37F07-F850-4958-8F01-C03DD6BDF523}\mpengine.dll
2012-05-17 06:36:41 8955792 —-a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-05-16 20:34:49 8955792 ——w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Updates\mpengine.dll
2012-05-16 12:20:12 69976 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2012-05-16 12:19:20 41184 —-a-w- C:\Windows\avastSS.scr
2012-05-16 12:19:05 ——– d—–w- C:\ProgramData\AVAST Software
2012-05-16 12:15:15 ——– d—–w- C:\Program Files\AVAST Software
2012-05-16 11:36:16 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com
2012-05-16 11:36:16 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2012-05-16 11:23:23 ——– d—–w- C:\Program Files (x86)\Spybot - Search & Destroy
2012-05-16 11:18:27 ——– d—–w- C:\ProgramData\RegRun
2012-05-16 11:18:16 2 –shatr- C:\Windows\winstart.bat
2012-05-16 11:18:01 ——– d—–w- C:\Program Files (x86)\UnHackMe
2012-05-16 09:38:25 53248 —-a-w- C:\Windows\SysWow64\unrar.dll
2012-05-16 09:38:24 4358144 —-a-w- C:\Windows\uncsetup.exe
2012-05-16 01:00:42 84992 —-a-w- C:\Windows\System32\asycfilt.dll
2012-05-16 01:00:42 67584 —-a-w- C:\Windows\SysWow64\asycfilt.dll
2012-05-15 18:31:49 ——– d—–w- C:\Windows\SysWow64\Wat
2012-05-15 18:31:49 ——– d—–w- C:\Windows\System32\Wat
2012-05-15 17:41:02 ——– d—–w- C:\Program Files (x86)\MSXML 4.0
2012-05-15 17:07:47 80896 —-a-w- C:\Windows\System32\imagehlp.dll
2012-05-15 17:07:47 22896 —-a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-05-15 17:07:47 220672 —-a-w- C:\Windows\System32\wintrust.dll
2012-05-15 17:07:47 172544 —-a-w- C:\Windows\SysWow64\wintrust.dll
2012-05-15 17:07:47 158720 —-a-w- C:\Windows\SysWow64\imagehlp.dll
2012-05-15 17:07:46 5120 —-a-w- C:\Windows\SysWow64\wmi.dll
2012-05-15 17:07:46 5120 —-a-w- C:\Windows\System32\wmi.dll
2012-05-15 07:32:49 142336 —-a-w- C:\Windows\System32\poqexec.exe
2012-05-15 07:32:48 123904 —-a-w- C:\Windows\SysWow64\poqexec.exe
2012-05-15 07:32:46 961024 —-a-w- C:\Windows\System32\CPFilters.dll
2012-05-15 07:32:46 642048 —-a-w- C:\Windows\SysWow64\CPFilters.dll
2012-05-15 07:32:45 850432 —-a-w- C:\Windows\SysWow64\sbe.dll
2012-05-15 07:32:45 259072 —-a-w- C:\Windows\System32\mpg2splt.ax
2012-05-15 07:32:45 199680 —-a-w- C:\Windows\SysWow64\mpg2splt.ax
2012-05-15 07:32:45 1118720 —-a-w- C:\Windows\System32\sbe.dll
2012-05-15 07:30:55 759296 —-a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2012-05-15 07:28:58 499200 —-a-w- C:\Windows\System32\drivers\afd.sys
2012-05-15 07:27:45 44544 —-a-w- C:\Windows\SysWow64\devrtl.dll
2012-05-15 07:26:13 1895280 —-a-w- C:\Windows\System32\drivers\tcpip.sys
2012-05-15 07:26:03 4582912 —-a-w- C:\Program Files\Windows NT\Accessories\wordpad.exe
2012-05-15 07:26:03 4247040 —-a-w- C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe
2012-05-15 07:26:03 2085376 —-a-w- C:\Windows\System32\ole32.dll
2012-05-15 07:26:03 1413632 —-a-w- C:\Windows\SysWow64\ole32.dll
2012-05-15 07:24:56 1732096 —-a-w- C:\Program Files\Windows Journal\NBDoc.DLL
2012-05-15 07:19:43 144384 —-a-w- C:\Windows\System32\cdd.dll
2012-05-15 07:17:35 954752 —-a-w- C:\Windows\SysWow64\mfc40.dll
2012-05-15 07:17:35 954288 —-a-w- C:\Windows\SysWow64\mfc40u.dll
2012-05-15 07:12:01 77312 —-a-w- C:\Windows\System32\packager.dll
2012-05-15 07:12:01 67072 —-a-w- C:\Windows\SysWow64\packager.dll
2012-05-15 07:00:37 927800 ——w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0B2251BA-5A07-4C7E-A396-F2FEE141A060}\gapaengine.dll
2012-05-15 06:59:27 167424 —-a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2012-05-15 06:59:27 164864 —-a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2012-05-15 06:59:25 12625408 —-a-w- C:\Windows\SysWow64\wmploc.DLL
2012-05-15 06:59:24 12625920 —-a-w- C:\Windows\System32\wmploc.DLL
2012-05-15 06:57:58 826368 —-a-w- C:\Windows\SysWow64\rdpcore.dll
2012-05-15 06:57:58 23552 —-a-w- C:\Windows\System32\drivers\tdtcp.sys
2012-05-15 06:57:58 204800 —-a-w- C:\Windows\System32\drivers\rdpwd.sys
2012-05-15 06:57:58 1031680 —-a-w- C:\Windows\System32\rdpcore.dll
2012-05-15 06:57:55 9216 —-a-w- C:\Windows\System32\rdrmemptylst.exe
2012-05-15 06:57:55 76288 —-a-w- C:\Windows\System32\rdpwsx.dll
2012-05-15 06:57:55 149504 —-a-w- C:\Windows\System32\rdpcorekmts.dll
2012-05-15 06:56:57 9728 —-a-w- C:\Windows\SysWow64\sscore.dll
2012-05-15 06:56:57 236032 —-a-w- C:\Windows\System32\srvsvc.dll
2012-05-15 06:55:57 148992 —-a-w- C:\Windows\System32\t2embed.dll
2012-05-15 06:55:56 109056 —-a-w- C:\Windows\SysWow64\t2embed.dll
2012-05-15 06:47:02 ——– d—–w- C:\Program Files (x86)\Microsoft Security Client
2012-05-15 06:46:56 ——– d—–w- C:\Program Files\Microsoft Security Client
2012-05-15 06:46:17 374664 —-a-w- C:\Windows\System32\drivers\netio.sys
2012-05-14 21:32:41 868848 —-a-w- C:\Windows\System32\drivers\sptd.sys
2012-05-07 11:11:48 ——– d—–w- C:\Users\Andrew\AppData\Local\id Software
2012-05-07 06:57:59 ——– d—–w- C:\Users\Andrew\AppData\Local\SniperV2
2012-05-07 06:00:21 102400 ——w- C:\Users\Andrew\AppData\Roaming\googleoez.exe
2012-05-06 10:08:19 ——– d—–w- C:\Users\Andrew\AppData\Roaming\.spoutcraft
2012-05-06 06:58:26 ——– d—–w- C:\Users\Andrew\AppData\Local\SniperV2 Demo
2012-04-29 11:16:23 ——– d—–w- C:\Users\Andrew\AppData\Roaming\puush
2012-04-29 02:03:23 ——– d—–w- C:\Program Files\TeamSpeak 3 Client
2012-04-28 23:12:36 ——– d—–w- C:\Program Files\Soluto
2012-04-25 02:37:08 ——– d—–w- C:\Users\Andrew\AppData\Local\The Witcher 2
2012-04-24 22:54:47 ——– d—–w- C:\Program Files\iPod
2012-04-24 22:54:45 ——– d—–w- C:\Program Files\iTunes
2012-04-21 12:15:14 ——– d—–w- C:\Program Files (x86)\Common Files\SourceTec
2012-04-20 22:21:04 23680 —-a-w- C:\Windows\System32\drivers\IOMap64.sys
2012-04-19 08:03:37 ——– d—–w- C:\Users\Andrew\AppData\Roaming\NVIDIA
2012-04-19 08:01:46 ——– d—–w- C:\Program Files (x86)\My Company Name
2012-04-19 08:00:08 16384 —-a-w- C:\Windows\System32\drivers\EIO64.sys
2012-04-19 07:49:43 ——– d—–w- C:\ProgramData\NVIDIA Corporation
2012-04-19 07:49:38 ——– d—–w- C:\Program Files\NVIDIA Corporation
2012-04-19 07:46:34 ——– d—–w- C:\Program Files (x86)\ASUS
.
==================== Find3M ====================
.
2012-05-17 08:01:58 214520 —-a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2012-05-17 08:01:58 214520 —-a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2012-05-17 08:01:56 214520 —-a-w- C:\Windows\SysWow64\PnkBstrB.exe
2012-05-14 21:21:31 70304 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-14 21:21:31 419488 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 15:00:17 8744608 —-a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-04-24 07:13:24 54728 —-a-w- C:\Windows\System32\drivers\Soluto.sys
2012-04-13 06:39:23 794408 —-a-w- C:\Windows\SysWow64\pbsvc.exe
2012-04-04 05:56:40 24904 —-a-w- C:\Windows\System32\drivers\mbam.sys
2012-04-02 05:34:04 5504880 —-a-w- C:\Windows\System32\ntoskrnl.exe
2012-04-02 04:46:44 3958128 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-04-02 04:46:44 3902320 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-04-02 03:01:19 3143680 —-a-w- C:\Windows\System32\win32k.sys
2012-03-20 10:44:12 98688 —-a-w- C:\Windows\System32\drivers\NisDrvWFP.sys
2012-03-20 10:44:12 203888 —-a-w- C:\Windows\System32\drivers\MpFilter.sys
2012-03-17 08:34:25 11561984 —-a-w- C:\Windows\SysWow64\aticaldd.dll
2012-03-17 08:34:06 120320 —-a-w- C:\Windows\System32\atitmm64.dll
2012-03-17 08:33:57 54784 —-a-w- C:\Windows\System32\atimpc64.dll
2012-03-17 08:33:57 54784 —-a-w- C:\Windows\System32\amdpcom64.dll
2012-03-17 08:33:43 13859840 —-a-w- C:\Windows\System32\aticaldd64.dll
2012-03-17 08:32:19 10856960 —-a-w- C:\Windows\System32\drivers\atikmdag.sys
2012-03-17 08:31:45 19392000 —-a-w- C:\Windows\SysWow64\atioglxx.dll
2012-03-17 08:31:16 6200320 —-a-w- C:\Windows\SysWow64\atidxx32.dll
2012-03-17 08:30:40 5954048 —-a-w- C:\Windows\SysWow64\atiumdag.dll
2012-03-17 08:30:15 59392 —-a-w- C:\Windows\System32\atiedu64.dll
2012-03-17 08:30:11 53248 —-a-w- C:\Windows\System32\drivers\ati2erec.dll
2012-03-17 08:29:54 7646208 —-a-w- C:\Windows\System32\atidxx64.dll
2012-03-17 08:29:51 44032 —-a-w- C:\Windows\SysWow64\aticalcl.dll
2012-03-17 08:29:12 33280 —-a-w- C:\Windows\SysWow64\atigktxx.dll
2012-03-17 08:29:06 46080 —-a-w- C:\Windows\SysWow64\aticalrt.dll
2012-03-17 08:29:01 496128 —-a-w- C:\Windows\System32\atieclxx.exe
2012-03-17 08:28:40 512000 —-a-w- C:\Windows\System32\atiadlxx.dll
2012-03-17 08:28:31 17408 —-a-w- C:\Windows\System32\atig6pxx.dll
2012-03-17 08:28:25 7551488 —-a-w- C:\Windows\System32\atiumd64.dll
2012-03-17 08:28:20 58880 —-a-w- C:\Windows\System32\coinst.dll
2012-03-17 08:28:20 159744 —-a-w- C:\Windows\System32\atiapfxx.exe
2012-03-17 08:28:01 51200 —-a-w- C:\Windows\System32\aticalrt64.dll
2012-03-17 08:28:00 25839104 —-a-w- C:\Windows\System32\atio6axx.dll
2012-03-17 08:26:57 53760 —-a-w- C:\Windows\SysWow64\atimpc32.dll
2012-03-17 08:26:57 53760 —-a-w- C:\Windows\SysWow64\amdpcom32.dll
2012-03-17 08:26:39 39936 —-a-w- C:\Windows\System32\atig6txx.dll
2012-03-17 08:26:21 235520 —-a-w- C:\Windows\System32\atiesrxx.exe
2012-03-17 08:26:19 791040 —-a-w- C:\Windows\SysWow64\aticfx32.dll
2012-03-17 08:26:11 33280 —-a-w- C:\Windows\SysWow64\atiuxpag.dll
2012-03-17 08:26:05 43520 —-a-w- C:\Windows\SysWow64\ati2edxx.dll
2012-03-17 08:26:04 4958208 —-a-w- C:\Windows\System32\atiumd6a.dll
2012-03-17 08:25:54 356352 —-a-w- C:\Windows\SysWow64\atiadlxy.dll
2012-03-17 07:55:58 75632 —-a-w- C:\Windows\System32\drivers\partmgr.sys
2012-03-03 06:29:57 1541120 —-a-w- C:\Windows\System32\DWrite.dll
2012-03-03 06:29:42 320512 —-a-w- C:\Windows\System32\d3d10_1core.dll
2012-03-03 06:29:42 197120 —-a-w- C:\Windows\System32\d3d10_1.dll
2012-03-03 06:29:42 1837568 —-a-w- C:\Windows\System32\d3d10warp.dll
2012-03-03 06:29:41 902656 —-a-w- C:\Windows\System32\d2d1.dll
2012-03-03 05:40:21 1074176 —-a-w- C:\Windows\SysWow64\DWrite.dll
2012-03-03 05:40:10 1170944 —-a-w- C:\Windows\SysWow64\d3d10warp.dll
2012-03-03 05:40:09 739840 —-a-w- C:\Windows\SysWow64\d2d1.dll
2012-03-03 05:40:09 218624 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll
2012-03-03 05:40:09 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll
2012-02-25 07:16:52 76888 —-a-w- C:\Windows\SysWow64\PnkBstrA.exe
2012-02-23 00:18:36 279656 ——w- C:\Windows\System32\MpSigStub.exe
2008-03-08 21:25:10 236 —-a-w- C:\Program Files (x86)\Common Files\dx.reg
.
============= FINISH: 11:45:32.48 ===============
Hi AWarGuy,
It looks like your DDS log was not posted in its entirety. I would like for you to run DDS again, then paste the entire contents of the log in your next post. If the log is too long, please upload the text file. Please also upload
attach.txt .
Please download aswMBR.exe and save it to your desktop.
Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
Click
Scan
Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet. You will also notice another file created on the desktop named MBR.dat . Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Thank you for your co-operation.
Attached is DDS report, attach.txt and aswMBR report
📎 aswMBR.txt
📎 Attach.txt
Please do the following
Refer to the
ComboFix User's Guide
Download ComboFix from one of these locations:
Link 1
Link 2
* IMPORTANT !!! Place ComboFix.exe on your Desktop
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
You can get help on disabling your protection programs here
Double click on ComboFix.exe & follow the prompts. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
———————————————————————————————
Ensure your AntiVirus and AntiSpyware applications are re-enabled.
———————————————————————————————
NOTE: If you encounter a message
"illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.
Well aswMBR found 4 infected files, can't I press the FixMBR now?
Besides, the virus is preventing me from INSTALLING ComboFix, it stops installing when it's about to finish.
No. aswMBR fixes MBR infections and as far as we know, you don't have an MBR infection. We are only using it for diagnostic information and to back up the MBR in case something goes wrong. Let's try booting into safe mode, then running ComboFix.
To boot into safe mode follow these steps:
Turn on or restart your computer As the computer is booting, press and hold your F8 Key This should bring up the Windows Advanced Options Menu Use your arrow keys to move to Safe Mode and press your Enter Key
Try running ComboFix and let me know if it works.
No luck on Safe mode, as it is about to finish installing, it closes straight away. I tested it on my laptop and it installed fine.
Can you explain what you mean by installing? Do you see the command prompt window? Do you see "Stage 1, Stage 2, Stage 3…" etc? Please check your C:\ drive for a log (combofix.txt).
What I mean is that, when I run the link you gave, as it extracts, when it reaches the final files to extact, it just closes. I didn't close it or anything:
Image shown:
[external image: Posted Image]
Thanks for the info.
Please download
Listparts .
Run the tool, click Scan and post the log (Result.txt) it makes.
Alrighty then, attached is the log saved.
📎 Result.txt
My PC is getting slower, got any other ideas of removing this rootkit?
Hi AWarGuy,
I need you to enable viewing of file extensions. If you need help doing this, follow
this guide. After doing so, please rename ComboFix to
iexplore.exe . Make sure there is only one
.exe at the end. Move ComboFix (now iexplore.exe) to your
C:\ drive. Restart your computer and boot into safe mode. Run ComboFix from the
C:\ drive and let me know if you have any luck.