cantic
2010-08-11, 16:58
Been having this problem for a few days now. I've run Avast, Windows Defender and Spybot. They cleared out some things but say my system is clean now even though I'm still having issues. What usually happens is a full screen pop up appears, I get a message saying windows has to shut down a program and the memory usage of svc host skyrockets. I can't use any programs unless I manually kill the svc process that's eating all the memory. I recently found out that I couldn't post to this forum from the infected pc. I'm guessing that's a compnent of the infection. Thanks in advance for any help.
DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 9:47:49.32 on Wed 08/11/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.722 [GMT -4:00]
AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast5\setup\avast.setup
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}\SOFTWARE
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}\SOFTWARE\Classes
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}\SOFTWARE\Classes\CLSID
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\SOFTWARE
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\SOFTWARE\Classes
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\SOFTWARE\Classes\CLSID
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ProgID
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE\Classes
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE\Classes\CLSID
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\ProgID
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\SOFTWARE
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\SOFTWARE\Classes
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\SOFTWARE\Classes\CLSID
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\ProgID
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247934756609
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-3 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-3 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-3 40384]
S1 kxwpmjva;kxwpmjva;\??\c:\windows\system32\drivers\kxwpmjva.sys --> c:\windows\system32\drivers\kxwpmjva.sys [?]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-3 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-3 40384]
S4 ahlnhcql;ahlnhcql;c:\windows\system32\drivers\cmbbrkh.sys [2010-5-12 54016]
S4 klmdb;klmdb;c:\windows\system32\drivers\klmdb.sys [2010-5-12 36488]
S4 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
2010-08-04 15:10:51 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-08-04 15:10:51 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-03 15:29:58 38848 ----a-w- c:\windows\avastSS.scr
2010-08-03 15:29:52 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-08-03 14:06:43 0 d-----w- c:\program files\F-Group
2010-08-03 13:44:15 0 d-----w- c:\program files\Trend Micro
2010-07-30 15:27:33 0 d-----w- c:\windows\system32\MpEngineStore
==================== Find3M ====================
2010-07-30 16:20:18 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-01-11 21:57:18 16384 --sha-w- c:\windows\system32\config\systemprofile\cookies\index.dat
2010-01-11 21:57:18 245760 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
2010-01-11 21:57:18 16384 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2010-01-11 21:57:18 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 9:49:24.71 ===============
DDS (Ver_10-03-17.01) - NTFSx86
Run by Owner at 9:47:49.32 on Wed 08/11/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.991.722 [GMT -4:00]
AV: Malware Defense *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast5\setup\avast.setup
C:\Documents and Settings\Owner\Desktop\dds.scr
============== Pseudo HJT Report ===============
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}\SOFTWARE
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}\SOFTWARE\Classes
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}\SOFTWARE\Classes\CLSID
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\SOFTWARE
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\SOFTWARE\Classes
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\SOFTWARE\Classes\CLSID
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2}\ProgID
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE\Classes
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\SOFTWARE\Classes\CLSID
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583}\ProgID
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\SOFTWARE
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\SOFTWARE\Classes
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\SOFTWARE\Classes\CLSID
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}\ProgID
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1247934756609
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} - hxxp://office.microsoft.com/officeupdate/content/opuc4.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
Hosts: 127.0.0.1 www.spywareinfo.com
============= SERVICES / DRIVERS ===============
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-8-3 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-8-3 17744]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-3 40384]
S1 kxwpmjva;kxwpmjva;\??\c:\windows\system32\drivers\kxwpmjva.sys --> c:\windows\system32\drivers\kxwpmjva.sys [?]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-3 40384]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-8-3 40384]
S4 ahlnhcql;ahlnhcql;c:\windows\system32\drivers\cmbbrkh.sys [2010-5-12 54016]
S4 klmdb;klmdb;c:\windows\system32\drivers\klmdb.sys [2010-5-12 36488]
S4 SBRE;SBRE;\??\c:\windows\system32\drivers\sbredrv.sys --> c:\windows\system32\drivers\SBREdrv.sys [?]
S4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
=============== Created Last 30 ================
2010-08-04 15:10:51 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-08-04 15:10:51 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-08-03 15:29:58 38848 ----a-w- c:\windows\avastSS.scr
2010-08-03 15:29:52 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-08-03 14:06:43 0 d-----w- c:\program files\F-Group
2010-08-03 13:44:15 0 d-----w- c:\program files\Trend Micro
2010-07-30 15:27:33 0 d-----w- c:\windows\system32\MpEngineStore
==================== Find3M ====================
2010-07-30 16:20:18 96512 ----a-w- c:\windows\system32\drivers\atapi.sys
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2010-01-11 21:57:18 16384 --sha-w- c:\windows\system32\config\systemprofile\cookies\index.dat
2010-01-11 21:57:18 245760 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
2010-01-11 21:57:18 16384 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\index.dat
2010-01-11 21:57:18 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\temporary internet files\content.ie5\index.dat
============= FINISH: 9:49:24.71 ===============