Hey Forum. I need some help from you guys, I seem to have hit a brick wall.
First off, let me give you some backround on the system I am running. It's a intel core duo 2.6 running windows xp pro service pack 3. For protection I run Spybot s&d, along with avast antivirus, and peerguardian 2. Up until recently I have been safely surfing for almost a year with this configuration. This all changed this morning.
When I logged in this morning, I was greeted by a wonderful fake antivirus program know as windows antivirus pro 2009. It told me that every app on my computer was a know virus and that I needed to give them money to make all the bad things go away. Knowing that something was seriously amis, I attempted to run a scan with spybot. when I tryed to run spybot however, nothing happend. It's still running in my minibar, but I can't run a scan or anything. The same thing with Avast! So I try reinstalling avast, and it gives me the option for a boot scan. I do this, and come back with 10 virus, which I delete all of them. The windows antivirus persists however and I end up having to go into safe mode, and remove all associated files and regedit all associated entries as well. After this was said and done I rebooted and noticed that while the fake AV software was gone, I still couldn't access the higher functions of both spybot or Avast. I then noticed something disturbing. When I try to regedit while logged in normally, it says I haven'y admin privlages. When I try to acess my user accounts in control panel, nothing happens. Same with most of my other control panel actions. Just nothing happens.
I've read a few other forum posts, and know that you guys need the hijack this results, but when I tryed to run it, it got to where the scan should start, and just dissappered!! Now when I click on it again NOTHING HAPPENS!! I'm going insane, please help me!!
... and when logged into safe mode, none of the control panel functions are working as well!
I've gotten Gmer to run. I'll post the results when finished.
Here's what I was able to get. It eventually quit the ap, and now I can't get it to run again.
GMER 1.0.15.15011 [ynnbqzmr.exe] - http://www.gmer.net
Rootkit scan 2009-08-07 05:20:56
Windows 5.1.2600 Service Pack 3
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xB57366B8]
SSDT 8A1FBEE0 ZwConnectPort
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xB5736574]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwCreatePagingFile [0xB9F82A20]
SSDT 89FDC220 ZwCreateThread
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xB5736A52]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xB573614C]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateKey [0xB9F832A8]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwEnumerateValueKey [0xB9F8E910]
SSDT 8A1B4F00 ZwLoadDriver
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xB573664E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xB573608C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xB57360F0]
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwQueryKey [0xB9F832C8]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xB573676E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xB573672E]
SSDT 8A036BC0 ZwResumeThread
SSDT d347bus.sys (PnP BIOS Extension/ ) ZwSetSystemPowerState [0xB9F8E0B0]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xB57368AE]
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!ZwCallbackReturn + 2CE8 80504584 4 Bytes JMP BCEEFF81
? SYMEFA.SYS The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\NAV\1005000.086\SYMTDI.SYS The system cannot find the path specified. !
? C:\WINDOWS\system32\Drivers\SYMEVENT.SYS The system cannot find the file specified. !
? C:\WINDOWS\system32\drivers\NAV\1005000.086\SYMNDIS.SYS The system cannot find the path specified. !
? C:\WINDOWS\system32\drivers\NAV\1005000.086\SYMFW.SYS The system cannot find the path specified. !
? C:\WINDOWS\system32\drivers\NAV\1005000.086\SYMIDS.SYS The system cannot find the path specified. !
? C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090206.001\IDSxpx86.sys The system cannot find the file specified. !
? win32k.sys:1 The system cannot find the file specified. !
? win32k.sys:2 The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\DOCUME~1\Tim\LOCALS~1\Temp\spoolsv.exe[304] GDI32.DLL!GetHFONT + 51 77F17EA7 7 Bytes CALL 35672DDC \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll
.text C:\DOCUME~1\Tim\LOCALS~1\Temp\spoolsv.exe[304] GDI32.DLL!GetTextExtentPoint32W + E4 77F18081 7 Bytes CALL 35672DF8 \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll
.text C:\DOCUME~1\Tim\LOCALS~1\Temp\spoolsv.exe[304] USER32.dll!CallNextHookEx + 4A 7E42B410 7 Bytes CALL 35672DB0 \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\DOCUME~1\Tim\LOCALS~1\Temp\spoolsv.exe[304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtWriteFile] [35672AAE] \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll
IAT C:\DOCUME~1\Tim\LOCALS~1\Temp\spoolsv.exe[304] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!LdrGetProcedureAddress] [35672A38] \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll
IAT C:\WINDOWS\system32\services.exe[1112] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[1112] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 8A5EC880
AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
Device \FileSystem\Udfs \UdfsCdRom 8A262C50
Device \FileSystem\Udfs \UdfsDisk 8A262C50
Device \Driver\USBSTOR \Device\0000008f sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS
Device \Driver\Cdrom \Device\CdRom0 8A0120C8
Device \FileSystem\Rdbss \Device\FsWrap 8A2D7578
Device \Driver\Cdrom \Device\CdRom1 8A0120C8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 89F42E68
Device \Driver\atapi \Device\Ide\IdePort0 89F42E68
Device \Driver\atapi \Device\Ide\IdePort1 89F42E68
Device \Driver\atapi \Device\Ide\IdePort2 89F42E68
Device \Driver\atapi \Device\Ide\IdePort3 89F42E68
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 89F42E68
Device \Driver\Cdrom \Device\CdRom2 8A0120C8
Device \Driver\USBSTOR \Device\00000090 sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Srv \Device\LanmanServer 89FE62A0
AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 8A2E1EE0
Device \FileSystem\MRxSmb \Device\LanmanRedirector 8A2E1EE0
Device \FileSystem\Npfs \Device\NamedPipe 8A154358
Device \FileSystem\Msfs \Device\Mailslot 8A00BFB0
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target1Lun0 8A04AC70
Device \Driver\d347prt \Device\Scsi\d347prt1Port4Path0Target0Lun0 8A04AC70
Device \Driver\d347prt \Device\Scsi\d347prt1 8A04AC70
Device \Driver\USBSTOR \Device\0000008d sfsync02.sys (StarForce Protection Synchronization Driver/Protection Technology)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer 8A07CE78
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer 8A07CE78
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer 8A07CE78
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer 8A07CE78
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer 8A07CE78
Device \FileSystem\Cdfs \Cdfs 889936A8
---- Modules - GMER 1.0.15 ----
Module _________ B9EE5000-B9EFD000 (98304 bytes)
---- Processes - GMER 1.0.15 ----
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\DOCUME~1\Tim\LOCALS~1\Temp\spoolsv.exe [304] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [372] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\Program Files\uTorrent\uTorrent.exe [916] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1376] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\svchost.exe [1500] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1600] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\Program Files\Java\jre6\bin\jqs.exe [1664] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1764] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\ashServ.exe [1956] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\PnkBstrA.exe [2052] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2352] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2392] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\System32\alg.exe [3040] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\WINDOWS\system32\PnkBstrB.exe [3364] 0x35670000
Library \\?\globalroot\Device\__max++>\ECE3EDCA.x86.dll (*** hidden *** ) @ C:\Program Files\DNA\btdna.exe [3788] 0x35670000
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\drivers\SKYNETaafvnklv.sys (*** hidden *** ) [SYSTEM] SKYNETvpmypdwy <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@PendingFileRenameOperations ?????a??? ?????????????a????(a? ?????????? ?????????????????????????????????????????? ???????a???????????a? ????????N??a???????????a?&????(??a???????e??avast! Mail Scanner??????a?????????????????????????????????s?????????a??????s???LegacyDriver??????N??a????????D?????{8ECC055D-047F-11D1-A537-0000F8753ED1}??????? (??a??????????????avast! Mail Scanner??????a?a?a?a?a?a????C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\*??S?????????????????????????????????????????9?9??C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\* /s????CurrentControlSet\Services\dmboot\??????????????? ???????e???a???a??HKEY_LOCAL_MACHINE\Software\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\SharedDefs\*???????????a???a??????????????CurrentControlSet\Services\NAVEX15\*?CurrentControlSet\Services\NAVENG\*???????????????????????????????a1\???????a???????????????a?????a???????????????????(?)?*?)?+?+?B?-?-?\?????????????(???*?+?,?*?
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z0 0x42 0xD1 0xC5 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z1 0xA6 0xD1 0xC5 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z2 0xA6 0xD1 0xC5 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z3 0xA6 0xD1 0xC5 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf40@hj34z4 0xA6 0xD1 0xC5 0x0F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf41
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf42
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf42@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf43
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf43@khjeh 0x20 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\d347prt\Cfg\0Jf43@hj34z0 0x16 0xA4 0x05 0xF3 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy@imagepath \systemroot\system32\drivers\SKYNETaafvnklv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main@aid 10020
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETaafvnklv.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\modules@SKYNETcmd.dll \systemroot\system32\SKYNETalnkpkpm.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\modules@SKYNETlog.dat \systemroot\system32\SKYNETbnreabeq.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\modules@SKYNETwsp.dll \systemroot\system32\SKYNEThwymdipu.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETvpmypdwy\modules@SKYNET.dat \systemroot\system32\SKYNETqlhmurwu.dat
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy@imagepath \systemroot\system32\drivers\SKYNETaafvnklv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main@aid 10020
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\modules@SKYNETrk.sys \systemroot\system32\drivers\SKYNETaafvnklv.sys
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\modules@SKYNETcmd.dll \systemroot\system32\SKYNETalnkpkpm.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\modules@SKYNETlog.dat \systemroot\system32\SKYNETbnreabeq.dat
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\modules@SKYNETwsp.dll \systemroot\system32\SKYNEThwymdipu.dll
Reg HKLM\SYSTEM\ControlSet002\Services\SKYNETvpmypdwy\modules@SKYNET.dat \systemroot\system32\SKYNETqlhmurwu.dat