This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My Boss asking for me to fix infected computer [Closed]

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

The office I work at has 3 computers, in which he allows his disabled clients to use for pleasure. I had warned him that the computers are not protected running off one network security monitoring company. Each computer must have their own AV install ed but he will not listen, and now I know for sure that one is infected, and the other 2 are possibably infected as well. I cannot explain everything that cause this, but for what I have seen, several tool bar helpers have been installed, and some sort of what looks like a russian firewall application, which at first used to say all my applications where infected. Once I seen, that, I ran MBAM, which reported 49 trojans where removed. I then did an online Scan, using Panda Active Scan, and that reported some more trojans. I could not have the AV scanner remove them because, the program wanted to me to purchase a full license. So I tried deleting them manually, but a few of them continue to reinstall itself. As your site ask's, here is my DDS.txt log DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 4:19:03 on 2012-12-18 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.510.130 [GMT -5:00] . . ============== Running Processes ================ . C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\user\Local Settings\Application Data\Yandex\Updater\praetorian.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.google.com/ uURLSearchHooks: {b4efb02b-cd4a-44b9-b5d9-aa486cdffab6} - uURLSearchHooks: {472734EA-242A-422b-ADF8-83D1E48CC825} - BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Praetorian] c:\documents and settings\user\local settings\application data\yandex\updater\praetorian.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab TCP: NameServer = 64.115.0.9 64.115.0.10 TCP: Interfaces\{07A278B3-9029-4675-BE09-61B75E3F6497} : DHCPNameServer = [removed] [removed] Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ============= SERVICES / DRIVERS =============== . R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2012-12-13 28552] R2 MBAMScheduler;MBAMScheduler;c:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2012-10-16 399432] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2012-8-29 676936] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-8-29 22856] S0 cerc6;cerc6; [x] . =============== Created Last 30 ================ . 2012-12-13 09:34:34 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys 2012-12-13 09:34:18 ——– d—–w- c:\program files\Panda Security 2012-12-12 08:59:52 ——– d—–w- c:\windows\system32\appmgmt . ==================== Find3M ==================== . 2012-12-12 11:40:12 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-12-12 11:40:12 697272 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-09-29 23:54:26 22856 —-a-w- c:\windows\system32\drivers\mbam.sys . ============= FINISH: 4:19:42,17 ===============
Hello and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!

First, let me say that typically we do not assist with work related computers, even if they are for your boss' clients personal enjoyment (semi work related). However, it does not appear that you have any kind of IT department to assist with this. Since you do not have any other form of support, I will be happy to try and assist you, but you AND your boss need to be aware that we cannot guarantee these machines can be cleaned with any degree of certainty. If these machines are attached to your work network, even using the same router, you risk possible infection of your work machines. I would be very cautious if that is the case. You are correct. Every machine should have it's own antivirus and firewall installed. (I can give you some suggestions when we are done for some free options for these machines personal use machines only - your business machines should be protected using enterprise/business antivirus solutions which are fully licensed).

I will help you with all 3 machines if you like, but we will need to do them one at a time please as it is too confusing to do more than one at a time.

There is a very suspicious file that does indeed appear to be a Trojan on this machine. In my research, it also appears to be a somewhat new one, and some of the scans are not yet detecting it as an infection, so I'm not sure the full extent of what it is designed to do - but it does appear to be of Russian origin. If this were a personal computer I would give you the following warning:

One or more of the identified infections is likely a backdoor Trojan and rootkit which can allow an attacker to gain control of the system, log keystrokes, steal passwords, access personal data, send malevolent outgoing traffic, and close the security warning messages displayed by some anti-virus and security programs.


If this computer is ever used for on-line banking, I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a known clean computer, change ALL your on-line passwords for email, banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.



Though the Trojan/Rootkit has been identified and can most likely be killed, because of it's back door functionality, Your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. If it were on my PC I would not hesitate for a moment to do so. Making this decision is based on what the computer is used for, and what information can be accessed from it.

Please read the following for more information:
How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

Considering the above information, please let me know if your choice is to reformat, or if you would like to procede wtih cleaning.


I'm assuming your boss will want to go ahead and try to clean the machine based on what you've said, so let's go ahead with what we'll need to do :)


Let's get another scan with one more tool so I can make sure there are no rootkits hiding on here before we move forward with the cleaning.




Please read carefully and follow these steps. There is a difference between what you see in one of the images below and what I need you to do.
We are only creating a log - I do NOT want you to "cure" or try to fix anything in this step. It is very important that you don't choose Cure when presented with that option.

  • Download TDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.


    🖼Click to load external image (Posted Image)

  • If an infected file is detected, the default action will be Cure but I want you to choose SKIP instead , click on Continue.


    🖼Click to load external image (Posted Image)

  • If a suspicious file is detected, the default action will be Skip, click on Continue.


    🖼Click to load external image (Posted Image)

  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.


    🖼Click to load external image (Posted Image)

  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI