This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] I've been infected with Trojan.DNS_changer, Trojan.V

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

One of my family members downloaded a file from the internet which contained a virus called Trojan. I managed to get rid of most of the virus before it left any permanent damages (atleast thats what i hope) I usually use the anti-virus program Spyware doctor to scan for viruses, and that is what i did for this virus, alot showed up with the names "Trojan.DNS_changer, Trojan.Virtumonde, and Trojan.TDSServ". I also downloaded SpyHunter, VundoFix, Malwarebytes' Anti-Malware, and ATF-Cleaner" which i have been scanning with regularly and the some of the viruses keep popping up even after i fix them.

I tried all that i could with no luck, i would deeply appreciate some help on this.

My recent hijackthis file:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:33:48 AM, on 11/16/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlogin.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [xsjfn83jkemfofght] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\winlogin.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\RunOnce: [LabelMaker2.0] regsvr32 C:\Program Files\Common Files\MySoftware\regdll.dll /s (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [LabelMaker2.0] regsvr32 C:\Program Files\Common Files\MySoftware\regdll.dll /s (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {37A273C2-5129-11D5-BF37-00A0CCE8754B} (TTestGenXInstallObject) - http://asp.mathxl.com/wizmodules/testgen/i…GenXInstall.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {95D88B35-A521-472B-A182-BB1A98356421} (Pearson Installation Assistant 2) - http://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} (OCXDownloadChecker Control) - http://70.54.181.82:81/cab/OCXChecker_8000.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab57176.cab
O16 - DPF: {EEC9DBCC-04AD-4A1B-BEA7-C6DAD9515D5A} (Pearson MyEconLab Player Control) - http://asp.mathxl.com/books/_Players/EconPlayer.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = GGPOSER2.local
O17 - HKLM\Software\..\Telephony: DomainName = GGPOSER2.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = GGPOSER2.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = GGPOSER2.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = GGPOSER2.local
O20 - AppInit_DLLs: vmfcub.dll pnzjen.dll ekzdfu.dll zdawfg.dll rpqlep.dll ihmfqh.dll
O20 - Winlogon Notify: pmnmmNdA - pmnmmNdA.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: QuickBooks Database Manager Service (QBCFMonitorService) - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QuickBooksDB17 - iAnywhere Solutions, Inc. - C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 10691 bytes
Hello

Disable resident protections (Antivirus…); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)
——————–\\ Lop S&D; 4.2.4-9c XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : Intel® Pentium® 4 CPU 3.00GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A02
USER : Administrator ( Not Administrator ! )
BOOT : Normal boot
Antivirus : Symantec AntiVirus Corporate Edition 10.1.5.5000 (Not Activated)
C:\ (Local Disk) - NTFS - Total:149 Go (Free:126 Go)
D:\ (CD or DVD)
E:\ (CD or DVD)
G:\ (USB) - FAT32 - Total:3811 Mo (Free:3 Go)

"C:\Lop SD" ( MAJ : 01-11-2008|16:30 )
Option : [1] ( Sun 11/16/2008| 9:02 )

——————–\\ Listing folders in APPLIC~1

[07/19/2007|07:52] C:\DOCUME~1\99\APPLIC~1\ Google
[07/13/2007|05:08] C:\DOCUME~1\99\APPLIC~1\ Identities
[07/18/2007|06:57] C:\DOCUME~1\99\APPLIC~1\ InstallShield
[07/24/2007|07:50] C:\DOCUME~1\99\APPLIC~1\ Macromedia
[07/18/2007|06:55] C:\DOCUME~1\99\APPLIC~1\ Microsoft
[07/19/2007|07:48] C:\DOCUME~1\99\APPLIC~1\ Real

[07/05/2007|10:24] C:\DOCUME~1\admin\APPLIC~1\ Identities
[07/05/2007|11:31] C:\DOCUME~1\admin\APPLIC~1\ Microsoft
[07/05/2007|11:49] C:\DOCUME~1\admin\APPLIC~1\ U3

[02/03/2008|08:57] C:\DOCUME~1\ADMINI~1\APPLIC~1\ 3M
[05/08/2008|03:26] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Adobe
[10/31/2008|03:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Apple Computer
[11/14/2008|10:08] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Azureus
[11/26/2007|04:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Design Science
[02/23/2008|09:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\ DivX
[10/24/2008|12:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\ DVD Flick
[04/28/2008|09:04] C:\DOCUME~1\ADMINI~1\APPLIC~1\ dvdcss
[01/12/2008|10:01] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Google
[09/24/2008|12:23] C:\DOCUME~1\ADMINI~1\APPLIC~1\ GTek
[11/16/2007|10:11] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Help
[07/13/2007|05:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Identities
[07/19/2007|06:59] C:\DOCUME~1\ADMINI~1\APPLIC~1\ InstallShield
[06/25/2008|11:00] C:\DOCUME~1\ADMINI~1\APPLIC~1\ LimeWire
[11/14/2007|12:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Macromedia
[06/12/2008|10:03] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Malwarebytes
[10/18/2008|01:54] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Microsoft
[09/16/2008|11:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Mozilla
[07/19/2007|07:44] C:\DOCUME~1\ADMINI~1\APPLIC~1\ PC Tools
[04/19/2008|05:36] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Real
[09/15/2008|11:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Research In Motion
[09/15/2008|11:37] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Roxio
[06/12/2008|07:52] C:\DOCUME~1\ADMINI~1\APPLIC~1\ STOPzilla!
[11/30/2007|05:58] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Sun
[06/08/2008|03:30] C:\DOCUME~1\ADMINI~1\APPLIC~1\ SystemRequirementsLab
[11/14/2007|01:13] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Talkback
[03/30/2008|09:34] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Template
[11/17/2007|03:46] C:\DOCUME~1\ADMINI~1\APPLIC~1\ U3
[11/15/2007|08:10] C:\DOCUME~1\ADMINI~1\APPLIC~1\ vlc
[11/14/2008|07:07] C:\DOCUME~1\ADMINI~1\APPLIC~1\ Winamp
[11/19/2007|06:49] C:\DOCUME~1\ADMINI~1\APPLIC~1\ WinRAR

[11/23/2007|06:44] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Azureus
[11/23/2007|06:40] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Identities
[11/23/2007|06:43] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Macromedia
[11/23/2007|06:42] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Microsoft
[11/23/2007|06:41] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Mozilla
[11/23/2007|06:40] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Real
[11/23/2007|06:41] C:\DOCUME~1\ADMINI~1.210\APPLIC~1\ Talkback

[10/27/2008|10:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ {3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[11/12/2008|12:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Adobe
[11/25/2007|05:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple
[01/28/2008|04:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Apple Computer
[11/14/2007|06:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Azureus
[07/18/2007|06:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ BVRP Software
[09/03/2008|10:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ COMMON FILES
[06/28/2008|04:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Fugazo
[09/17/2008|06:59] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Google
[09/24/2008|12:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ GTek
[06/12/2008|02:54] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ InstallShield
[09/03/2008|11:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Intuit
[06/12/2008|10:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Malwarebytes
[11/10/2008|10:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Messenger Plus!
[04/28/2008|08:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Microsoft
[07/22/2007|07:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Mozilla
[09/15/2008|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Roxio
[06/12/2008|07:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ SITEguard
[09/15/2008|11:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Sonic
[06/12/2008|09:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ STOPzilla!
[07/13/2007|09:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Symantec
[11/16/2008|09:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ TEMP
[11/18/2007|11:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Trymedia
[07/05/2007|12:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ Windows Genuine Advantage
[11/14/2007|05:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ WLInstaller

[07/06/2007|03:15] C:\DOCUME~1\aziz\APPLIC~1\ Identities
[07/12/2007|09:06] C:\DOCUME~1\aziz\APPLIC~1\ Microsoft
[07/12/2007|08:45] C:\DOCUME~1\aziz\APPLIC~1\ Symantec

[07/05/2007|10:15] C:\DOCUME~1\DEFAUL~1\APPLIC~1\ Microsoft

[09/03/2008|11:03] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Microsoft
[01/07/2008|08:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Mozilla
[09/16/2008|11:44] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Roxio
[01/07/2008|08:54] C:\DOCUME~1\LOCALS~1\APPLIC~1\ Talkback

[06/13/2008|02:00] C:\DOCUME~1\NETWOR~1\APPLIC~1\ Microsoft

[09/03/2008|11:06] C:\DOCUME~1\QBDATA~1\APPLIC~1\ Microsoft

[07/12/2007|04:48] C:\DOCUME~1\test\APPLIC~1\ Identities
[07/13/2007|09:18] C:\DOCUME~1\test\APPLIC~1\ Microsoft

——————–\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[11/14/2008 03:00 PM][–a——] C:\WINDOWS\tasks\Norton Security Scan.job
[11/13/2008 11:39 AM][–a——] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[11/16/2008 01:54 AM][–ah—–] C:\WINDOWS\tasks\SA.DAT
[08/04/2004 07:00 AM][-r-h—–] C:\WINDOWS\tasks\desktop.ini

——————–\\ Listing Folders in C:\Program Files

[02/03/2008|08:56] C:\Program Files\ 3M
[11/12/2008|12:05] C:\Program Files\ Adobe
[08/13/2008|02:09] C:\Program Files\ Apple Software Update
[07/19/2007|07:11] C:\Program Files\ Avanquest update
[11/16/2008|01:32] C:\Program Files\ Azureus
[09/17/2008|07:02] C:\Program Files\ Bonjour
[11/14/2008|08:12] C:\Program Files\ Common Files
[07/05/2007|10:12] C:\Program Files\ ComPlus Applications
[11/19/2007|06:52] C:\Program Files\ DAEMON Tools
[11/01/2008|10:36] C:\Program Files\ DivX
[07/14/2008|08:00] C:\Program Files\ DVD Flick
[11/11/2008|10:32] C:\Program Files\ Enigma Software Group
[11/16/2008|01:29] C:\Program Files\ ERUNT
[02/22/2008|08:58] C:\Program Files\ ffdshow
[05/08/2008|03:25] C:\Program Files\ FLV Player
[09/17/2008|06:59] C:\Program Files\ Google
[11/16/2008|02:29] C:\Program Files\ Hijackthis
[11/14/2008|08:49] C:\Program Files\ InstallShield Installation Information
[06/12/2008|02:51] C:\Program Files\ Intel
[10/16/2008|02:03] C:\Program Files\ Internet Explorer
[09/03/2008|11:00] C:\Program Files\ Intuit
[10/27/2008|10:05] C:\Program Files\ iPod
[10/27/2008|10:05] C:\Program Files\ iTunes
[11/16/2008|01:59] C:\Program Files\ Java
[06/12/2008|10:03] C:\Program Files\ Malwarebytes' Anti-Malware
[11/26/2007|04:57] C:\Program Files\ MathType
[09/03/2008|01:04] C:\Program Files\ Messenger
[09/16/2008|06:32] C:\Program Files\ Messenger Plus! Live
[11/17/2007|03:47] C:\Program Files\ Microsoft ActiveSync
[11/15/2007|05:41] C:\Program Files\ Microsoft CAPICOM 2.1.0.2
[07/05/2007|10:15] C:\Program Files\ microsoft frontpage
[11/25/2007|11:18] C:\Program Files\ Microsoft Office
[07/12/2007|05:11] C:\Program Files\ Microsoft Visual Studio
[07/13/2007|05:10] C:\Program Files\ Microsoft Windows Small Business Server
[03/30/2008|09:33] C:\Program Files\ Microsoft Works
[09/03/2008|12:58] C:\Program Files\ Movie Maker
[11/16/2008|02:52] C:\Program Files\ Mozilla Firefox
[11/25/2007|11:18] C:\Program Files\ MSECache
[01/07/2008|02:24] C:\Program Files\ MSN
[07/05/2007|10:11] C:\Program Files\ MSN Gaming Zone
[11/15/2007|05:39] C:\Program Files\ MSXML 4.0
[07/18/2007|06:56] C:\Program Files\ MySoftware
[09/03/2008|12:53] C:\Program Files\ NetMeeting
[04/10/2008|11:29] C:\Program Files\ Norton Security Scan
[07/05/2007|10:11] C:\Program Files\ Online Services
[09/03/2008|12:53] C:\Program Files\ Outlook Express
[04/12/2008|01:30] C:\Program Files\ Picasa2
[08/21/2008|03:59] C:\Program Files\ PowerISO
[11/11/2008|11:50] C:\Program Files\ Project64 1.6
[09/11/2008|11:49] C:\Program Files\ QuickTime
[07/19/2007|07:43] C:\Program Files\ Real
[09/15/2008|11:27] C:\Program Files\ Research In Motion
[09/15/2008|11:34] C:\Program Files\ Roxio
[11/14/2007|12:54] C:\Program Files\ Samsung
[09/23/2008|08:33] C:\Program Files\ Spyware Doctor
[10/06/2008|08:12] C:\Program Files\ Sun
[07/13/2007|09:37] C:\Program Files\ Symantec
[11/11/2008|02:54] C:\Program Files\ Symantec AntiVirus
[06/08/2008|03:30] C:\Program Files\ SystemRequirementsLab
[11/16/2008|02:33] C:\Program Files\ Trend Micro
[07/05/2007|10:24] C:\Program Files\ Uninstall Information
[07/12/2007|10:04] C:\Program Files\ v8100
[11/15/2007|07:07] C:\Program Files\ VideoLAN
[11/12/2008|08:58] C:\Program Files\ Winamp
[11/14/2007|05:38] C:\Program Files\ Windows Live
[09/06/2008|12:50] C:\Program Files\ Windows Media Connect 2
[09/06/2008|02:06] C:\Program Files\ Windows Media Player
[09/03/2008|12:53] C:\Program Files\ Windows NT
[07/05/2007|10:14] C:\Program Files\ WindowsUpdate
[11/19/2007|06:48] C:\Program Files\ WinRAR
[07/05/2007|10:15] C:\Program Files\ xerox

——————–\\ Listing Folders in C:\Program Files\Common Files

[02/05/2008|11:03] C:\Program Files\Common Files\ Adobe
[09/03/2008|11:01] C:\Program Files\Common Files\ AnswerWorks 4.0
[09/11/2008|11:48] C:\Program Files\Common Files\ Apple
[11/17/2007|03:47] C:\Program Files\Common Files\ Designer
[09/15/2008|11:29] C:\Program Files\Common Files\ InstallShield
[09/03/2008|11:02] C:\Program Files\Common Files\ Intuit
[06/12/2008|05:11] C:\Program Files\Common Files\ iS3
[05/02/2008|01:26] C:\Program Files\Common Files\ Microsoft Shared
[07/05/2007|10:13] C:\Program Files\Common Files\ MSSoap
[07/19/2007|06:59] C:\Program Files\Common Files\ MySoftware
[07/05/2007|06:00] C:\Program Files\Common Files\ ODBC
[05/08/2008|02:01] C:\Program Files\Common Files\ Real
[10/18/2008|01:53] C:\Program Files\Common Files\ Research In Motion
[09/15/2008|11:34] C:\Program Files\Common Files\ Roxio Shared
[07/05/2007|10:13] C:\Program Files\Common Files\ Services
[09/15/2008|11:33] C:\Program Files\Common Files\ Sonic Shared
[07/05/2007|06:00] C:\Program Files\Common Files\ SpeechEngines
[09/03/2008|11:04] C:\Program Files\Common Files\ supportsoft
[11/23/2007|03:01] C:\Program Files\Common Files\ Symantec Shared
[09/03/2008|12:53] C:\Program Files\Common Files\ System
[11/14/2007|05:37] C:\Program Files\Common Files\ WindowsLiveInstaller
[05/08/2008|02:01] C:\Program Files\Common Files\ xing shared

——————–\\ Process

( 34 Processes )

… OK !

——————–\\ Searching with S_Lop

No Lop folder found !

——————–\\ Searching for Lop Files - Folders

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\msgpl_a20b.tmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ns083.torrent

——————–\\ Searching within the Registry

….. OK !

——————–\\ Checking the Hosts file

Hosts file CLEAN


——————–\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-16 09:04:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden files …
disk error: C:\WINDOWS\System32\
please note that you need administrator rights to perform deep scan

——————–\\ Searching for other infections

C:\WINDOWS\system32\DLnXEfhk.ini
C:\WINDOWS\system32\DLnXEfhk.ini2
C:\WINDOWS\system32\mopYIkkj.ini
C:\WINDOWS\system32\mopYIkkj.ini2
C:\WINDOWS\system32\NpsBaccf.ini
C:\WINDOWS\system32\NpsBaccf.ini2
C:\WINDOWS\system32\PrtssBeg.ini
C:\WINDOWS\system32\PrtssBeg.ini2
C:\WINDOWS\system32\SBbadccf.ini
C:\WINDOWS\system32\SBbadccf.ini2
==> VUNDO <==

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters]
DhcpNameServer REG_SZ [removed] [removed] [removed]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters]
DhcpNameServer REG_SZ [removed] [removed] [removed]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{C886E8A1-6FE1-4755-B2A7-A4C037CBDC28}]
DhcpNameServer REG_SZ [removed] [removed] [removed]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{C886E8A1-6FE1-4755-B2A7-A4C037CBDC28}]
DhcpNameServer REG_SZ [removed] [removed] [removed]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{C886E8A1-6FE1-4755-B2A7-A4C037CBDC28}]
DhcpNameServer REG_SZ [removed] [removed] [removed]
==> WAREOUT <==

——————–\\ ROOTKIT !!

Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_TDSSSERV.SYS]
Rootkit Tibs ! .. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_TDSSSERV.SYS]

——————–\\ Cracks & Keygens ..

C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\GTA San Andreas (pc games) with crack (Decrypt) [mininova].torrent
C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\Prince Of Persia 3 The Two Thrones [PC][Incl Crack]_KaYz 2008 [mininova].torrent
C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\prince_of_persia_sands_of_time_pc_iso_with_crack_www_pirateuropa_com_.torre
nt
C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\[isoHunt] STOPzilla__v3[1].1.0.7___Crack_(pop_up_blocker_and_the_code_works__.3581060.TPB [mininova].torrent
C:\DOCUME~1\ADMINI~1\My Documents\My Music\Music\Kayne West - Late Registration\08 - Crack Music (Feat. The Game).mp3
C:\DOCUME~1\ADMINI~1\Recent\Prince Of Persia 3 The Two Thrones Incl Crack (2).lnk


[F:4][D:0]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp
[F:2][D:0]-> C:\DOCUME~1\ADMINI~1\Cookies
[F:1][D:0]-> C:\DOCUME~1\ADMINI~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Sun 11/16/2008| 9:05 - Option : [1]

——————–\\ Scan completed at 9:05:20
You got infected because you downloaded cracks

Please download the OTMoveIt3 by OldTimer or from here.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    
    :Files
    C:\WINDOWS\system32\DLnXEfhk.ini
    C:\WINDOWS\system32\DLnXEfhk.ini2
    C:\WINDOWS\system32\mopYIkkj.ini
    C:\WINDOWS\system32\mopYIkkj.ini2
    C:\WINDOWS\system32\NpsBaccf.ini
    C:\WINDOWS\system32\NpsBaccf.ini2
    C:\WINDOWS\system32\PrtssBeg.ini
    C:\WINDOWS\system32\PrtssBeg.ini2
    C:\WINDOWS\system32\SBbadccf.ini
    C:\WINDOWS\system32\SBbadccf.ini2
    C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\GTA San Andreas (pc games) with crack (Decrypt) [mininova].torrent
    C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\Prince Of Persia 3 The Two Thrones [PC][Incl Crack]_KaYz 2008 [mininova].torrent
    C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\prince_of_persia_sands_of_time_pc_iso_with_crack_www_pirateuropa_com_.torre
    nt
    C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\[isoHunt] STOPzilla__v3[1].1.0.7___Crack_(pop_up_blocker_and_the_code_works__.3581060.TPB [mininova].torrent
    C:\DOCUME~1\ADMINI~1\Recent\Prince Of Persia 3 The Two Thrones Incl Crack (2).lnk
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.




Download ComboFix from one of these locations:

Link 1
Link 2
Link 3


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
It seems i'm in a bit of a twist, After i ran the OTMovieIt3 and it produced the log, it asked me to reboot which i did, and it did succesfully but when i tried to open Combofix.exe it didn't do anything, i waited like 5 mins and still nothiing so i went into task manager and end tasked it and tried to run it again, again it didn't start so i thought i would have better luck rebooting the computer and then trying again. But now everytime i try to turn on the computer it doesn't goto the windows login screen anymore it just freezes on the blue screen. I've restarted countless times but with no luck of it getting past that blue screen.
I can't seem to get Combofix to work, i double click it and nothing happens. Could you please let me know what the requirements are maybe i missed something. But i did get the OTMoveit3 log: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\system32\DLnXEfhk.ini moved successfully. C:\WINDOWS\system32\DLnXEfhk.ini2 moved successfully. C:\WINDOWS\system32\mopYIkkj.ini moved successfully. C:\WINDOWS\system32\mopYIkkj.ini2 moved successfully. C:\WINDOWS\system32\NpsBaccf.ini moved successfully. C:\WINDOWS\system32\NpsBaccf.ini2 moved successfully. C:\WINDOWS\system32\PrtssBeg.ini moved successfully. C:\WINDOWS\system32\PrtssBeg.ini2 moved successfully. C:\WINDOWS\system32\SBbadccf.ini moved successfully. C:\WINDOWS\system32\SBbadccf.ini2 moved successfully. C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\GTA San Andreas (pc games) with crack (Decrypt) [mininova].torrent moved successfully. C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\Prince Of Persia 3 The Two Thrones [PC][Incl Crack]_KaYz 2008 [mininova].torrent moved successfully. File/Folder C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\prince_of_persia_sands_of_time_pc_iso_with_crack_www_pirateuropa_com_.torre not found. File/Folder nt not found. C:\DOCUME~1\ADMINI~1\Application Data\Azureus\torrents\[isoHunt] STOPzilla__v3[1].1.0.7___Crack_(pop_up_blocker_and_the_code_works__.3581060.TPB [mininova].torrent moved successfully. C:\DOCUME~1\ADMINI~1\Recent\Prince Of Persia 3 The Two Thrones Incl Crack (2).lnk moved successfully. ========== COMMANDS ========== User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. Windows Temp folder emptied. Java cache emptied. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11162008_093706 Files moved on Reboot… File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
The Combofix works now, i don't know if this is normal but after i clicked yes to installing windows recovery console it told me to agree on the following message of the end-user liscense agreement, after i clicked ok the blinker started going all over the prompt screen and its been like that for about 20 mins now.
It shouldn't

Give it a little more time, then try this


Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.
Its been two hours since i started Combofix and its still doing the same thing as before. Should i still continue waiting or just skip to the next step that you posted?
Alright, It took awhile, but its finally done.




SDFix: Version 1.240
Run by [removed] on Sun 11/16/2008 at 03:02 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :

Rootkit Found :
C:\WINDOWS\system32\drivers\TDSSijso.sys - Rootkit.Win32.Agent.cku

Name :
TDSSserv.sys

Path :
\systemroot\system32\drivers\TDSSijso.sys

TDSSserv.sys - Deleted



Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Infected beep.sys Found!

beep.sys File Locations:

"C:\WINDOWS\system32\dllcache\beep.sys" 23040 11/10/2008 11:33 AM

Infected File Listed Below:

C:\WINDOWS\system32\dllcache\beep.sys

File copied to Backups Folder
Attempting to replace beep.sys with original version


Original beep.sys Restored

"C:\WINDOWS\system32\dllcache\beep.sys" 4224 2008-08-07 15:27
"C:\WINDOWS\system32\drivers\beep.sys" 4224 2008-08-07 15:27



Checking Files :

Trojan Files Found:

C:\resycled\boot.com - Deleted
C:\WINDOWS\system32\wini108023.exe - Deleted
C:\WINDOWS\system32\av.dat - Deleted
C:\WINDOWS\system32\delself.bat - Deleted
C:\WINDOWS\system32\drivers\TDSSijso.sys - Deleted
C:\WINDOWS\SYSTEM32\DRIVERS\TDSSIJSO.sys - Deleted
C:\WINDOWS\system32\TDSSesan.dll - Deleted
C:\WINDOWS\system32\TDSSurta.dll - Deleted
C:\WINDOWS\system32\TDSSckvy.dll - Deleted
C:\WINDOWS\system32\TDSSeuvq.dll - Deleted
C:\WINDOWS\system32\TDSSnhvw.dll - Deleted
C:\WINDOWS\SYSTEM32\TDSSURTA.dll - Deleted
C:\WINDOWS\SYSTEM32\TDSSCKVY.dll - Deleted
C:\WINDOWS\system32\TDSSierd.dat - Deleted
C:\WINDOWS\SYSTEM32\TDSSIERD.dat - Deleted
C:\WINDOWS\system32\TDSSuikm.log - Deleted
C:\WINDOWS\SYSTEM32\TDSSUIKM.log - Deleted



Folder C:\resycled - Removed


Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-16 15:29:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden services & system hive …

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:54,bc,d2,47,73,9d,08,6e,74,65,ea,dd,1c,a5,94,38,a6,f0,c8,ba,5f,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,e1,af,8d,cf,0e,96,a9,da,41,26,7a,be,ff,c1,ed,de,67,..
"khjeh"=hex:f4,9f,7e,ae,93,b8,76,6f,a5,b8,ce,cf,53,0e,d4,e0,5b,49,76,45,27,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:55,fa,5e,26,71,5f,be,0e,5b,70,94,47,00,fe,74,af,37,6f,91,d8,59,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:2e,25,4d,be,b9,39,37,30,c6,92,7a,26,90,81,10,b3,b7,04,06,d7,95,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:15,eb,db,54,6a,bb,59,be,2e,6d,9b,2d,d6,c2,e8,1b,93,7c,da,2a,ab,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:54,bc,d2,47,73,9d,08,6e,74,65,ea,dd,1c,a5,94,38,a6,f0,c8,ba,5f,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,e1,af,8d,cf,0e,96,a9,da,41,26,7a,be,ff,c1,ed,de,67,..
"khjeh"=hex:f4,9f,7e,ae,93,b8,76,6f,a5,b8,ce,cf,53,0e,d4,e0,5b,49,76,45,27,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:55,fa,5e,26,71,5f,be,0e,5b,70,94,47,00,fe,74,af,37,6f,91,d8,59,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:2e,25,4d,be,b9,39,37,30,c6,92,7a,26,90,81,10,b3,b7,04,06,d7,95,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:15,eb,db,54,6a,bb,59,be,2e,6d,9b,2d,d6,c2,e8,1b,93,7c,da,2a,ab,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:54,bc,d2,47,73,9d,08,6e,74,65,ea,dd,1c,a5,94,38,a6,f0,c8,ba,5f,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,e1,af,8d,cf,0e,96,a9,da,41,26,7a,be,ff,c1,ed,de,67,..
"khjeh"=hex:f4,9f,7e,ae,93,b8,76,6f,a5,b8,ce,cf,53,0e,d4,e0,5b,49,76,45,27,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:55,fa,5e,26,71,5f,be,0e,5b,70,94,47,00,fe,74,af,37,6f,91,d8,59,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:2e,25,4d,be,b9,39,37,30,c6,92,7a,26,90,81,10,b3,b7,04,06,d7,95,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:15,eb,db,54,6a,bb,59,be,2e,6d,9b,2d,d6,c2,e8,1b,93,7c,da,2a,ab,..

scanning hidden registry entries …

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="vmfcub.dll pnzjen.dll ekzdfu.dll zdawfg.dll rpqlep.dll ihmfqh.dll"
"DeviceNotSelectedTimeout"="15"
"GDIProcessHandleQuota"=dword:00002710
"Spooler"="yes"
"swapdisk"=""
"TransmissionRetryTimeout"="90"
"USERProcessHandleQuota"=dword:00002710
"LoadAppInit_DLLs"=dword:00000001

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Disabled:Azureus"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\AOE 2\\empires2.exe"="C:\\AOE 2\\empires2.exe:*:Disabled:Age of Empires II"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE"="C:\\Program Files\\Symantec\\pcAnywhere\\WINAW32.EXE:*:Enabled:pcAnywhere Main Program"
"C:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE"="C:\\Program Files\\Symantec\\pcAnywhere\\AWHOST32.EXE:*:Enabled:pcAnywhere Host Service"
"C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe"="C:\\Program Files\\Symantec\\pcAnywhere\\awrem32.exe:*:Enabled:pcAnywhere Remote Service"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
"C:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe"="C:\\Program Files\\Intuit\\QuickBooks 2008\\QBDBMgrN.exe:*:Enabled:QuickBooks 2008 Data Manager"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\AOE 2\\empires2.exe"="C:\\AOE 2\\empires2.exe:*:Enabled:Age of Empires II"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Disabled:Ares p2p for windows"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Disabled:RealPlayer"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"

Remaining Files :


File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sun 15 Jun 2008 4 ..SHR — "C:\WINOS.SYS"
Sat 12 Apr 2008 6,104,632 A..H. — "C:\Program Files\Picasa2\setup.exe"
Tue 6 May 2008 4,348 A.SH. — "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 6 Sep 2008 0 A.SH. — "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 7 Dec 2006 3,096,576 A..H. — "C:\Documents and Settings\administrator\Application Data\U3\temp\Launchpad Removal.exe"

Finished!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI