PDA

View Full Version : Packed.Win32.TDSS.z From Razer-Driver download



kraiford
2009-09-24, 07:21
As stated on Razer's website their site was compromised and the drivers I downloaded were infected with all sorts of fun stuff. This is especially frustrating as this has happened on my brand new Gaming Machine I've just finished assembling.

_____________________________________________________
-------------------------------------------------------------
Highjackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:12:31 AM, on 9/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [SpybotDeletingA8910] command.com /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3898] cmd.exe /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA9892] command.com /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4038] cmd.exe /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys"
O4 - HKLM\..\RunOnce: [SpybotDeletingA125] command.com /c del "C:\WINDOWS\system32\gasfkyftivalki.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8631] cmd.exe /c del "C:\WINDOWS\system32\gasfkyftivalki.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA4113] command.com /c del "C:\WINDOWS\system32\gasfkyftivalki.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6569] cmd.exe /c del "C:\WINDOWS\system32\gasfkyftivalki.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3783] command.com /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5539] cmd.exe /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA862] command.com /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC865] cmd.exe /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5328] command.com /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC51] cmd.exe /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3371] command.com /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4006] cmd.exe /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2921] command.com /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC362] cmd.exe /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1214] command.com /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC60] cmd.exe /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingA1940] command.com /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC5437] cmd.exe /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA5844] command.com /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4794] cmd.exe /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingB7101] command.com /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1105] cmd.exe /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1683] command.com /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7227] cmd.exe /c del "C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3810] command.com /c del "C:\WINDOWS\system32\gasfkyftivalki.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5834] cmd.exe /c del "C:\WINDOWS\system32\gasfkyftivalki.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1775] command.com /c del "C:\WINDOWS\system32\gasfkyftivalki.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3416] cmd.exe /c del "C:\WINDOWS\system32\gasfkyftivalki.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7374] command.com /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6766] cmd.exe /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8628] command.com /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5100] cmd.exe /c del "C:\WINDOWS\system32\gasfkysphkhxwm.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4385] command.com /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6791] cmd.exe /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB368] command.com /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD376] cmd.exe /c del "C:\WINDOWS\system32\gasfkyxkoqjxgb.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6357] command.com /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2693] cmd.exe /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5304] command.com /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1331] cmd.exe /c del "C:\WINDOWS\system32\gasfkyqsuwuyno.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2944] command.com /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4717] cmd.exe /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9921] command.com /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7281] cmd.exe /c del "C:\WINDOWS\system32\gasfkytikerrpu.dat"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1252987274937
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15108/CTPID.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

--
End of file - 9530 bytes

_________________________________________________________
-----------------------------------------------------------------

Here is a copy of a recent Spybot log:

Win32.TDSS.rtk: [SBI $CC549FA0] File (File, nothing done)
C:\WINDOWS\system32\drivers\gasfkysqrxplab.sys
Properties.size=0
Properties.md5=B126770AEA45A3B498BEFECE18C9365D

Win32.TDSS.rtk: [SBI $44B45F45] File (File, nothing done)
C:\WINDOWS\system32\gasfkyftivalki.dll
Properties.size=0
Properties.md5=6E3594510104590B1D8E45F23D18583A

Win32.TDSS.rtk: [SBI $44B45F45] File (File, nothing done)
C:\WINDOWS\system32\gasfkysphkhxwm.dll
Properties.size=0
Properties.md5=6F2256B6790032961FF64AA3AE1B8EA9

Win32.TDSS.rtk: [SBI $44B45F45] File (File, nothing done)
C:\WINDOWS\system32\gasfkyxkoqjxgb.dll
Properties.size=0
Properties.md5=8966EB3F8A03C014426DEF4449312EA2

Win32.TDSS.rtk: [SBI $4430B36D] File (File, nothing done)
C:\WINDOWS\system32\gasfkyqsuwuyno.dat
Properties.size=0
Properties.md5=E0F68A7DDCB974D63F45DA427DD439A9

Win32.TDSS.rtk: [SBI $4430B36D] File (File, nothing done)
C:\WINDOWS\system32\gasfkytikerrpu.dat
Properties.size=0
Properties.md5=3D9D9BD06D1A0B02E0372D0165A892AB


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-09-17 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-09-07 advcheck.dll (1.6.4.18)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-05-19 Includes\Adware.sbi (*)
2009-09-22 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-08-10 Includes\Dialer.sbi (*)
2009-09-22 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-05-26 Includes\Hijackers.sbi (*)
2009-09-22 Includes\HijackersC.sbi (*)
2009-09-22 Includes\Keyloggers.sbi (*)
2009-09-22 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-08-19 Includes\Malware.sbi (*)
2009-09-22 Includes\MalwareC.sbi (*)
2009-03-25 Includes\PUPS.sbi (*)
2009-09-22 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-09-22 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-04-07 Includes\Spyware.sbi (*)
2009-09-22 Includes\SpywareC.sbi (*)
2009-06-08 Includes\Tracks.uti
2009-09-15 Includes\Trojans.sbi (*)
2009-09-22 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll
_________________________________________________________
-----------------------------------------------------------------
Here are 2 scans of Kaspersky Online Scanner
(2nd one was result after the 1st scan and an AVG scan/clean in safe mode)

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, September 23, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 24, 2009 03:16:06
Records in database: 2884008
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 42011
Threats found: 4
Infected objects found: 7
Suspicious objects found: 0
Scan duration: 00:41:51


File name / Threat / Threats count
globalroot\systemroot\system32\gasfkyxkoqjxgb.dll/globalroot\systemroot\system32\gasfkyxkoqjxgb.dll Infected: Packed.Win32.TDSS.z 2
C:\WINDOWS\system32\usbctl.exe/C:\WINDOWS\system32\usbctl.exe Infected: Net-Worm.Win32.Aspxor.fp 1
C:\Documents and Settings\l33t pwn4ge\My Documents\Downloads\LachesisEnglish.zip Infected: Trojan-Dropper.Win32.Joiner.jm 1
C:\Documents and Settings\l33t pwn4ge\My Documents\Downloads\LachesisFirmwareUpdaterv1.91.zip Infected: Trojan-Dropper.Win32.Joiner.jm 1
C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\pb\htm\wa001407.htm Infected: Trojan-Downloader.JS.Gumblar.a 1
C:\WINDOWS\system32\usbctl.exe Infected: Net-Worm.Win32.Aspxor.fp 1

Selected area has been scanned.
_____________________________________________________
-------------------------------------------------------------

--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Thursday, September 24, 2009
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Thursday, September 24, 2009 05:56:53
Records in database: 2894451
--------------------------------------------------------------------------------

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 35585
Threats found: 1
Infected objects found: 2
Suspicious objects found: 0
Scan duration: 00:24:30


File name / Threat / Threats count
globalroot\systemroot\system32\gasfkyxkoqjxgb.dll/globalroot\systemroot\system32\gasfkyxkoqjxgb.dll Infected: Packed.Win32.TDSS.z 2

Selected area has been scanned.

____________________________________________________________
---------------------------------------------------------------------

It was obvious in the first scan that "usbctl.exe" was an issue and that has been deleted. AVG scan shows firefox.exe AND explorer.exe infected with Hidden.________ (I've since forgotten what the blank is).


Help, my new gaming machine needs help :sad:

The virus AVG shows is titled "Packed.Hidden" It shows up under explorer.exe(540) firefox.exe(1988)
====================
"BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

shelf life
2009-09-28, 23:29
hi kraiford,

Legitimate compromised websites, you can expect more of those. Your log is several days old, if you still need help with the surprises reply to the post.