This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Self-help Troubles

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

some problems here:

reading up how we did the first gmer scan (quite a while ago) i noticed that system protection and tracing was not tagged as we did the first time 'round.

Check the first five settings (see below)

System Protection and Tracing
Processes
Save created processes to the log
Drivers
Save loaded drivers to the log

so i tagged "system protection and tracing" as well and clicked "ok". the desktop remained blank but for the mouse cursor.
at that point i forced a shutdown and the box rebooted into gmer-safe-mode.
without tinkering around with the settings (system protection and tracing still untagged) i went straight for the rootkit scan which started fine but while scanning the drivers the desktop went blank again, no harddisk activity to be noted…
fortunately i'm not stuck with gmer: choosing "restart" xp reboots properly.
i retried the steps just to be sure, the results are the same…
Must have been a surprise having GMER "stuck" in that reboot cycle, but you caught on to the right way using GMER and Restart. Could you redo the steps, but step back a bit on the settings. Reset the five settings as designed (these are to create the requested logs), then do a full reboot. Then reboot using the GMER Safe Boot method and try one more time. The settings need to be added to the driver instructions first.
was quite a surprise, yes…
i proceeded as you advised, changing the settings first in normal mode, rebooting, going into gmer safemode. unfortunately that didn't do the trick either… the desktop goes blank as it did before.
i then tried to isolate what might have caused the problem.
- safemode without changing the settings, rootkitscan - failed
- changing the settings, rebooting, rootkitscan in normal mode - worked
it seems to be the safemode that causes the trouble, stopping during the scan of the devices-section.
i was able to spot it scanning \Dfs before the desktop goes black.
here is the gmer-log from normal mode, hope it helps.

GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-07-05 13:34:05
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess

—- Kernel code sections - GMER 1.0.12 —-

.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ F0, 61, 9C, F0, 80, C4, 9C, … ]
? srescan.sys Das System kann die angegebene Datei nicht finden.
? C:\WINDOWS\System32\DRIVERS\update.sys
.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ F0, 61, 9C, F0, 80, C4, 9C, … ]

—- Devices - GMER 1.0.12 —-

Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F97C085A] avgtdi.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F97C085A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F97C085A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F97C085A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F09D78A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F97C085A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F09D78A0] vsdatant.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06846B0] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [F068484C] tfsnifs.sys

—- EOF - GMER 1.0.12 —-
Not all setups I have found are amenable to GMER Safe Mode. I will be reviewing our cleaning process for now, to determine what remains unchecked. Are you experiencing any issues on the system at this time?


Best to ask opinions of other scan tools, as each has it's own set of patterns it checks, though we won't just keep throwing scan after scan here. For the moment, from log reviews only the continuing variation with GMER showing a call interrupt (like someone hanging up the telephone on you) remains.

Go here for an online AV scan (requires IE to run). If your AV alerts you while the scan installs ignore this - Panda's Active Scan method is often mistaken for infection activity.

Scan "Local Disks" and when finished save the scan log and then post the log here. To save the log first select the See Report button, then select the Save report button, and post that log back here.
hi jintan, the system seems stable, no issues whatsoever. panda just reported the tools we used. here's the log: Incident Status Location Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Dokumente und Einstellungen\anto\Desktop\ComboFix.exe[nircmd.exe] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Dokumente und Einstellungen\anto\Desktop\Flash_Disinfector.exe[nircmd.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\system32\nircmd.exe
Yes, you can now delete all those files and that folder, as well as the other tools we added to your system. Do you know if this system was installed with SP2, or the SP2 upgrade was added after? It would be best if it was reinstalled but that would only be available with the later upgraded install. Back in April there was a security alert related to Zone Alarm's srescan.sys device driver, and since GMER reflects some questionable activity I would like to suggest you uninstall and reinstall Zone Alarm now, and before we remove GMER there run a post ZA install scan as a precaution.
the system was installed without SP2 and online for quite a while like that… when i first laid hand on it some months ago i was quite surprised to find it running quite hassle-free (on first looks that is) and installed SP2.
meanwhile i slipstreamed the install-cd however and i think i will go for a clean install as soon as i find the time.
for now i deleted the files and folders we created, reinstalled zonealarm and did a gmer-scan. here's the log.

GMER 1.0.12.12244 - http://www.gmer.net
Rootkit scan 2007-07-06 15:43:49
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateFile
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateSection
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT \SystemRoot\System32\vsdatant.sys ZwLoadKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenFile
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT \SystemRoot\System32\vsdatant.sys ZwReplaceKey
SSDT \SystemRoot\System32\vsdatant.sys ZwRequestWaitReplyPort
SSDT \SystemRoot\System32\vsdatant.sys ZwRestoreKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \SystemRoot\System32\vsdatant.sys ZwSetInformationFile
SSDT \SystemRoot\System32\vsdatant.sys ZwSetValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwTerminateProcess

—- Kernel code sections - GMER 1.0.12 —-

.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ F0, 21, 98, F0, 80, 84, 98, … ]
? srescan.sys Das System kann die angegebene Datei nicht finden.
? C:\WINDOWS\System32\DRIVERS\update.sys
.text ntoskrnl.exe!_abnormal_termination + 104 804E2760 12 Bytes [ F0, 21, 98, F0, 80, 84, 98, … ]

—- Devices - GMER 1.0.12 —-

Device \Driver\BTHUSB \Device\00008f IRP_MJ_CREATE [F0A8CBB0] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_CLOSE [F0AB8990] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_DEVICE_CONTROL [F0A8AF00] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_INTERNAL_DEVICE_CONTROL [F0A8BA70] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_CLEANUP [F0A8C920] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_POWER [F0AB9EE0] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_SYSTEM_CONTROL [F0ABA7B0] bthport.sys
Device \Driver\BTHUSB \Device\00008f IRP_MJ_PNP [F0AB93B0] bthport.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CREATE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLOSE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_DEVICE_CONTROL [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL [F980685A] avgtdi.sys
Device \Driver\Tcpip \Device\Ip IRP_MJ_CLEANUP [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_DEVICE_CONTROL [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL [F980685A] avgtdi.sys
Device \Driver\Tcpip \Device\Tcp IRP_MJ_CLEANUP [F09938A0] vsdatant.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_CREATE [F0A8CBB0] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_CLOSE [F0AB8990] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_DEVICE_CONTROL [F0A8AF00] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_INTERNAL_DEVICE_CONTROL [F0A8BA70] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_CLEANUP [F0A8C920] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_POWER [F0AB9EE0] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_SYSTEM_CONTROL [F0ABA7B0] bthport.sys
Device \Driver\BTHUSB \Device\000091 IRP_MJ_PNP [F0AB93B0] bthport.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CREATE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLOSE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_DEVICE_CONTROL [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL [F980685A] avgtdi.sys
Device \Driver\Tcpip \Device\Udp IRP_MJ_CLEANUP [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_DEVICE_CONTROL [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL [F980685A] avgtdi.sys
Device \Driver\Tcpip \Device\RawIp IRP_MJ_CLEANUP [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSE [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_DEVICE_CONTROL [F09938A0] vsdatant.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL [F980685A] avgtdi.sys
Device \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLEANUP [F09938A0] vsdatant.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06276B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06276B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06276B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06276B0] tfsnifs.sys
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer IRP_MJ_FILE_SYSTEM_CONTROL [F06276B0] tfsnifs.sys
Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL [F062784C] tfsnifs.sys

—- EOF - GMER 1.0.12 —-
Well, at this point I cannot say this system has had all infection removed, as much as I would like to. I recognize the pattern and some of the methods used, and when it took so many steps to bring those hidden "eraseme" files to surface I sensed there is an added unwanted function remaining. However, nearly all logs, except GMER, show clear of infection activity or files, so as such there is no more indication of infection. . As you do have that slipstreamed copy for the reinstall it is still not a wrong choice to make. I would appreciate additional information if possible, as I would like to have available what might be available to do what we do here.


This first step is intended to ensure that all access rights are available if any have been altered. As it includes allowing rights not normally provided to some system functions it is not really a recommended maneuver for normal repair situations. Download and install subinacl from here

Create a file named reset.cmd in C:\Program Files\Windows Resource Kits\Tools folder and edit it to read as in the below code box (i.e. open reset.cmd with Notepad and copy and paste all the info in the code box and save your changes).

subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=administrators=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=administrators=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=administrators=f
subinacl /subdirectories %SystemDrive% /grant=administrators=f

subinacl /subkeyreg HKEY_LOCAL_MACHINE /grant=system=f
subinacl /subkeyreg HKEY_CURRENT_USER /grant=system=f
subinacl /subkeyreg HKEY_CLASSES_ROOT /grant=system=f
subinacl /subdirectories %SystemDrive% /grant=system=f

When you have done this, open a Command Prompt (Start > Run and type cmd.exe and ok) and enter the following commands one at a time and hit Enter after each.

cd\
cd "C:\Program Files\Windows Resource Kits\Tools"
reset.cmd


When the command has been processed, close the command prompt.



Next I would appreciate some registry information. As the file will be a few Mb's in size you can either upload it to any of the free large file upload sites, or if your email permits larger file attachments just send me a copy.

Open Notepad and copy and paste the following bold text into it:

regedit /e startup.txt
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet"
start notepad startup.txt


Save this file as look.bat, choose to save as type *all files and place it on your desktop. Then click look.bat to run the scan. Once the scan has completed, and it will take a bit of time, please send it to [removed] as an attachment. Please place "Submitted Files - msnoob" as the email Subject.




Also there is an essential system file there that has been very involved in the processes we have been checking, and is not the same size I had expected for this file. This could be due to being part or a non-English language system, but best to get it checked out. Please locate the following file, and either email a zipped copy to me, or again upload it to the site where we have been uploading all along. Be careful not to make an changes to this file - perhaps copy it to your desktop first before working with it.

C:\WINDOWS\system32\kernel32.dll


As you would now make those changes to access permissions there if you can it would be good to delete your existing copy of ComboFix, and double-check by downloading ComboFix.exe again from here to your desktop, and click the downloaded file to run the repair.

When the command window opens, select 1 (and Enter). Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.
hi jintan, did all of the above, sent you a mail with the requested files and did a scan with a fresh comb ofix download. heres the log:

"anto" - 2007-07-07 12:33:04 - ComboFix 07-07-04.4 - Service Pack 2


((((((((((((((((((((((((( Files Created from 2007-06-07 to 2007-07-07 )))))))))))))))))))))))))))))))


2007-07-07 12:32 51,200 –a—— C:\WINDOWS\nircmd.exe
2007-07-07 11:56 d——– C:\Programme\Windows Resource Kits
2007-07-06 14:20 75,512 –a—— C:\WINDOWS\zllsputility.exe
2007-07-06 14:19 1,087,216 –a—— C:\WINDOWS\system32\zpeng24.dll
2007-07-06 14:19 d——– C:\WINDOWS\system32\ZoneLabs
2007-07-06 08:32 d——– C:\WINDOWS\system32\ActiveScan
2007-07-04 09:16 d——– C:\WINDOWS\ERUNT
2007-06-30 21:43 drahs—- C:\autorun.inf
2007-06-30 13:44 853 –a—— C:\reboot.cmd
2007-06-30 13:44 68,096 –a—— C:\diff.exe
2007-06-30 13:44 103,424 –a—— C:\grep.exe
2007-06-30 13:39 d——– C:\DiagHelp
2007-06-29 21:41 d——– C:\Programme\EVEREST Ultimate Edition
2007-06-29 00:58 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Kaspersky Lab
2007-06-27 09:59 d——– C:\WINDOWS\system32\Kaspersky Lab
2007-06-27 09:36 d——– C:\Programme\regbackup
2007-06-26 08:34 d——– C:\WINDOWS\BDOSCAN8
2007-06-25 23:01 d——– C:\DOKUME~1\anto\ricerche di mercato
2007-06-18 09:26 d——– C:\gmer
2007-06-18 09:10 d——– C:\getservice
2007-06-13 14:52 d——– C:\Programme\ht
2007-06-13 13:46 10,872 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-13 09:45 d——– C:\pulire
2007-06-12 10:05 d——– C:\program files
2007-06-12 09:43 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2007-06-12 09:42 d——– C:\DOKUME~1\anto\.housecall6.6
2007-06-11 16:27 d——– C:\DOKUME~1\anto\ANWEND~1\Comodo
2007-06-11 16:26 d——– C:\DOKUME~1\ALLUSE~1\ANWEND~1\Comodo
2007-06-11 16:20 d——– C:\Programme\Comodo
2007-06-11 16:06 8,192 –a—— C:\WINDOWS\system32\wshirda.dll
2007-06-11 16:06 27,136 –a—— C:\WINDOWS\system32\irmon.dll
2007-06-11 16:06 154,112 –a—— C:\WINDOWS\system32\irftp.exe


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

2007-07-06 12:22:39 4,212 —h–w C:\WINDOWS\system32\zllictbl.dat
2007-07-06 06:58:14 ——– d—–w C:\Programme\Spybot
2007-06-25 15:31:48 ——– d—–w C:\Programme\JKDefrag
2007-06-25 11:36:29 48,486 —-a-w C:\WINDOWS\system32\perfc007.dat
2007-06-25 11:36:29 316,888 —-a-w C:\WINDOWS\system32\perfh007.dat
2007-06-11 11:48:27 ——– d—–w C:\Programme\Startup Optimizer
2007-06-11 10:40:11 ——– d—–w C:\Programme\SyncBack
2007-05-29 15:33:50 ——– d—–w C:\Programme\CCleaner
2007-05-29 14:46:36 ——– d—–w C:\Programme\ClamWin
2007-05-29 09:14:44 ——– d—–w C:\DOKUME~1\anto\ANWEND~1\.clamwin
2007-05-16 15:11:44 683,520 —-a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-25 14:22:27 144,896 —-a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:13:24 2,854,400 —-a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 —-a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 —-a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 —-a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 —-a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 —-a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 —-a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 —-a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 —-a-w C:\WINDOWS\system32\wups2.dll


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
2005-05-31 01:04 853672 –a—— C:\Programme\Spybot\SDHelper.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-05-15 12:03]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 09:58 C:\WINDOWS\system32\bthprops.cpl]
"ZoneAlarm Client"="C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Programme\Grisoft\AVGAntiSpyware7.5\shellexecutehook.dll" [2007-05-30 14:29]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 nwprovau

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\2kadiras]
2kadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\9xadiras]
9xadiras.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ClamWin]
"C:\Programme\ClamWin\bin\ClamTray.exe" –logon

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
C:\WINDOWS\system32\dla\tfswctrl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
C:\WINDOWS\System32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCTVOICE]
pctspk.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZCfgSvc.exe]
C:\WINDOWS\System32\ZCfgSvc.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\System32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HotKeysCmds"=C:\WINDOWS\System32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\rundisabled]
"QuickTime Task"="C:\Programme\QuickTime\qttask.exe" -atboottime
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs BthServ


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3a5fda0-0df4-11dc-8c7f-00904bb1fd80}]
AutoRun\command- explorer.exe /n,/e,\


Contents of the 'Scheduled Tasks' folder
2007-01-15 18:05:04 C:\WINDOWS\tasks\AppleSoftwareUpdate.job

**************************************************************************

catchme 0.3.915 W2K/XP/Vista - rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-07-07 12:35:49
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 2007-07-07 12:36:59
C:\ComboFix-quarantined-files.txt … 2007-07-07 12:36
C:\ComboFix2.txt … 2007-07-01 17:52
C:\ComboFix3.txt … 2007-06-30 23:13

— E O F —
I received the information, thanks. The kernel32 file was different in size due to the language differences, but for myself this is good to know - eliminates one area of mystery. The registry information did not reveal, of course in as much as I could search specific known locations, much additional information of infection. If the information is an accurate example then the infection does appear t be removed. Only services of note were the ones we disabled early on. Explorer has a practice of recording to the registry activities as a user assist tool. They are encoded with a simple code, so I checked quite a bit of that to see if infection left any footprints to follow. There was showing an installation of a Hotbar infection as far as outright infection. The record records chronologically, so it showed a progression from regular system and program use to torrent activity (NapMx for one, which was fairly new to me - folks just won't let WinMx die easily I guess), to activity I believe you may know to be the source of the infections here, to networking repairs measures on to the tools we used. When infection is provided an open door past security through use of keygens and other illegal softwares actions, it also gains access quickly to sensitive system areas, where it makes changes that are difficult to correct. Right off most tend to quickly locate and offload to it's own servers any stored personal data and software and game keys/registration codes. Worse is the actions of one impact the systems of others, as infection establishes web communications to broadcast itself through IRC and other methods, and sends out flood traffic to shutdown legitimate sites. The GMER tool we used here was the target of that type of attack recently. I can tell from the actions you have done in this repair process you have some good skills, which in some way I had thought to perhaps encourage you to use by thinking about joining in on malware removal efforts. But the keygens and other activity indicates just a slight difference in plans here. So as you indicated, you have a slipstreamed disk to now load (hopefully without any Adobe/Norton etc. software that has been altered, if you are smart), and we'll just call it a day here.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI