Results 1 to 3 of 3

Thread: win32.tdss.rtk PLEASE HELP!

  1. #1
    Junior Member
    Join Date
    Aug 2009
    Posts
    1

    Default win32.tdss.rtk PLEASE HELP!

    spybot picks it up every scan but doesnt remove it...it scans 23 entries...i need serious help from you guys...thank you...here are the results to clipboard

    Win32.TDSS.rtk: [SBI $4568377B] File (File, nothing done)
    C:\Windows\System32\drivers\kbiwkmbervssft.sys
    Properties.size=0
    Properties.md5=0678BC19F51CEEE13254B4F2B52A090E

    Win32.TDSS.rtk: [SBI $4568377B] File (File, nothing done)
    C:\Windows\System32\drivers\kbiwkmeoirhepc.sys
    Properties.size=0
    Properties.md5=0678BC19F51CEEE13254B4F2B52A090E

    Win32.TDSS.rtk: [SBI $4568377B] File (File, nothing done)
    C:\Windows\System32\drivers\kbiwkmjxpuqsvk.sys
    Properties.size=0
    Properties.md5=0678BC19F51CEEE13254B4F2B52A090E

    Win32.TDSS.rtk: [SBI $4568377B] File (File, nothing done)
    C:\Windows\System32\drivers\kbiwkmnnfbiiti.sys
    Properties.size=0
    Properties.md5=0678BC19F51CEEE13254B4F2B52A090E

    Win32.TDSS.rtk: [SBI $4568377B] File (File, nothing done)
    C:\Windows\System32\drivers\kbiwkmpwenmrvn.sys
    Properties.size=0
    Properties.md5=0678BC19F51CEEE13254B4F2B52A090E

    Win32.TDSS.rtk: [SBI $4568377B] File (File, nothing done)
    C:\Windows\System32\drivers\kbiwkmymqhptwr.sys
    Properties.size=0
    Properties.md5=0678BC19F51CEEE13254B4F2B52A090E

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmeocencox.dll
    Properties.size=0
    Properties.md5=686C6457694856BA8157A1E872D5E7E5

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmibfmumwp.dll
    Properties.size=0
    Properties.md5=782C1797DE394BC972D3585C0906A4C8

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmnqxmunhd.dll
    Properties.size=0
    Properties.md5=782C1797DE394BC972D3585C0906A4C8

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmqkodynwt.dll
    Properties.size=0
    Properties.md5=782C1797DE394BC972D3585C0906A4C8

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmucpbtvdw.dll
    Properties.size=0
    Properties.md5=782C1797DE394BC972D3585C0906A4C8

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmutbrdyxm.dll
    Properties.size=0
    Properties.md5=686C6457694856BA8157A1E872D5E7E5

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmveyqncwh.dll
    Properties.size=0
    Properties.md5=782C1797DE394BC972D3585C0906A4C8

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmvwpiixxt.dll
    Properties.size=0
    Properties.md5=686C6457694856BA8157A1E872D5E7E5

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmxpiwmpgs.dll
    Properties.size=0
    Properties.md5=686C6457694856BA8157A1E872D5E7E5

    Win32.TDSS.rtk: [SBI $6BF0B3E5] File (File, nothing done)
    C:\Windows\System32\kbiwkmyitcbhip.dll
    Properties.size=0
    Properties.md5=782C1797DE394BC972D3585C0906A4C8

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmbyhxvsrv.dat
    Properties.size=0
    Properties.md5=0522D1B01BEAFDB9B071D162446580B5

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmeewutpms.dat
    Properties.size=0
    Properties.md5=A0E33CBECC32FBBF66F8BE1EA6B0D163

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmihebxufy.dat
    Properties.size=0
    Properties.md5=1869FBC7E46EE632E38B7AB577A591C4

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmlsspkxti.dat
    Properties.size=0
    Properties.md5=A0E33CBECC32FBBF66F8BE1EA6B0D163

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmqeuxugcd.dat
    Properties.size=0
    Properties.md5=A0E33CBECC32FBBF66F8BE1EA6B0D163

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmsbjullfg.dat
    Properties.size=0
    Properties.md5=05A7DF7CC000FCEF5A926824C1C4DA53

    Win32.TDSS.rtk: [SBI $D8151B64] File (File, nothing done)
    C:\Windows\System32\kbiwkmvjbsmqim.dat
    Properties.size=0
    Properties.md5=A98AC831745984400A15F28F2E4E0E94


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SDWinSec.exe (1.0.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2009-02-04 unins000.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-07-28 advcheck.dll (1.6.3.17)
    2007-04-02 aports.dll (2.1.0.0)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2009-05-19 Includes\Adware.sbi (*)
    2009-08-25 Includes\AdwareC.sbi (*)
    2009-01-22 Includes\Cookies.sbi (*)
    2009-05-19 Includes\Dialer.sbi (*)
    2009-08-25 Includes\DialerC.sbi (*)
    2009-01-22 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2009-08-04 Includes\HijackersC.sbi (*)
    2009-06-23 Includes\Keyloggers.sbi (*)
    2009-07-30 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2009-08-19 Includes\Malware.sbi (*)
    2009-08-25 Includes\MalwareC.sbi (*)
    2009-03-25 Includes\PUPS.sbi (*)
    2009-08-25 Includes\PUPSC.sbi (*)
    2009-01-22 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2009-07-30 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2009-04-07 Includes\Spyware.sbi (*)
    2009-08-11 Includes\SpywareC.sbi (*)
    2009-06-08 Includes\Tracks.uti
    2009-08-25 Includes\Trojans.sbi (*)
    2009-08-26 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:17:41 PM, on 8/29/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\hp\KBD\kbd.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Windows\system32\igfxsrvc.exe
    C:\Program Files\AVG\AVG8\avgtray.exe
    C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Users\jonny\AppData\Local\Google\Update\GoogleUpdate.exe
    C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...ion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O1 - Hosts: 91.212.127.221 viruskill2009.microsoft.com
    O1 - Hosts: 91.212.127.221 viruskill2009.com
    O1 - Hosts: 91.212.127.221 www.viruskill2009.com
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll
    O2 - BHO: (no name) - {b410a47a-2513-4df4-b223-ebda03cec52b} - (no file)
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
    O4 - HKCU\..\Run: [Google Update] "C:\Users\jonny\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB487] command.com /c del "C:\Windows\System32\drivers\kbiwkmbervssft.sys" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB1689] command.com /c del "C:\Windows\System32\drivers\kbiwkmpwenmrvn.sys" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD5873] cmd.exe /c del "C:\Windows\System32\drivers\kbiwkmpwenmrvn.sys" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB9214] command.com /c del "C:\Windows\System32\drivers\kbiwkmymqhptwr.sys" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD3400] cmd.exe /c del "C:\Windows\System32\drivers\kbiwkmymqhptwr.sys" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB743] command.com /c del "C:\Windows\System32\kbiwkmibfmumwp.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD384] cmd.exe /c del "C:\Windows\System32\kbiwkmibfmumwp.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB3341] command.com /c del "C:\Windows\System32\kbiwkmqkodynwt.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD1517] cmd.exe /c del "C:\Windows\System32\kbiwkmqkodynwt.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB2756] command.com /c del "C:\Windows\System32\kbiwkmucpbtvdw.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD2010] cmd.exe /c del "C:\Windows\System32\kbiwkmucpbtvdw.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB9920] command.com /c del "C:\Windows\System32\kbiwkmutbrdyxm.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD6478] cmd.exe /c del "C:\Windows\System32\kbiwkmutbrdyxm.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB2429] command.com /c del "C:\Windows\System32\kbiwkmvwpiixxt.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD5101] cmd.exe /c del "C:\Windows\System32\kbiwkmvwpiixxt.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB6648] command.com /c del "C:\Windows\System32\kbiwkmxpiwmpgs.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD7558] cmd.exe /c del "C:\Windows\System32\kbiwkmxpiwmpgs.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB393] command.com /c del "C:\Windows\System32\kbiwkmyitcbhip.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD6508] cmd.exe /c del "C:\Windows\System32\kbiwkmyitcbhip.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB3984] command.com /c del "C:\Windows\System32\kbiwkmbyhxvsrv.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD8743] cmd.exe /c del "C:\Windows\System32\kbiwkmbyhxvsrv.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB2227] command.com /c del "C:\Windows\System32\kbiwkmihebxufy.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD8500] cmd.exe /c del "C:\Windows\System32\kbiwkmihebxufy.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB6175] command.com /c del "C:\Windows\System32\kbiwkmlsspkxti.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD3283] cmd.exe /c del "C:\Windows\System32\kbiwkmlsspkxti.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB8523] command.com /c del "C:\Windows\System32\kbiwkmqeuxugcd.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD6009] cmd.exe /c del "C:\Windows\System32\kbiwkmqeuxugcd.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB983] command.com /c del "C:\Windows\System32\kbiwkmsbjullfg.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD2615] cmd.exe /c del "C:\Windows\System32\kbiwkmsbjullfg.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingB7171] command.com /c del "C:\Windows\System32\kbiwkmvjbsmqim.dat" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [SpybotDeletingD8070] cmd.exe /c del "C:\Windows\System32\kbiwkmvjbsmqim.dat" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [SpybotDeletingB487] command.com /c del "C:\Windows\System32\drivers\kbiwkmbervssft.sys" (User 'Default user')
    O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Download All Files by HiDownload - C:\Program Files\HiDownload\HDGetAll.htm
    O8 - Extra context menu item: Download by HiDownload - C:\Program Files\HiDownload\HDGet.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: HiDownload - {F4FBA929-A891-492C-A0F6-5C79CC4F1742} - C:\Program Files\HiDownload\hidownload.exe (HKCU)
    O13 - Gopher Prefix:
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/wind...?1233847043215
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1233847124678
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
    O18 - Protocol: intu-help-qb2 - {84D77A00-41B5-4B8B-8ADF-86486D72E749} - C:\Program Files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
    O18 - Protocol: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (file missing)
    O20 - AppInit_DLLs: C:\Windows\System32\avgrsstx.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Application Experience AeLookupSvcALG (AeLookupSvcALG) - Unknown owner - C:\Windows\system32\f.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
    O23 - Service: QBCFMonitorService - Intuit - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
    O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: TVersityMediaServer - Unknown owner - C:\Program Files\TVersity\Media Server\MediaServer.exe
    O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 15307 bytes
    Last edited by tashi; 2009-08-30 at 07:35. Reason: Merged 2 posts as per forum FAQ

  2. #2
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Hello footixy

    Welcome to Safer Networking.

    Please read Before You Post
    That said, All advice given by anyone volunteering here, is taken at your own risk.
    While best efforts are made to assist in removing infections safely, unexpected stuff can happen.


    Your infected with a variant of the TDSS Rootkit, you need to follow these instructions to rename Combofix or this Rootkit will prevent it from running.

    Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

    Link 1
    Link 2
    Link 3






    * IMPORTANT !!! Save ComboFix.exe to your Desktop


    • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
    • See this Link for programs that need to be disabled and instruction on how to disable them.
    • Remember to re-enable them when we're done.

    • Double click on ComboFix.exe & follow the prompts.

    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.


    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.




    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    Click on Yes, to continue scanning for malware.

    When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

    *If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

  3. #3
    Emeritus-Security Expert
    Join Date
    Nov 2005
    Location
    Florida's SpaceCoast
    Posts
    15,208

    Default

    Due to inactivity, this thread will now be closed.

    If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a new HijackThis log with a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.
    Microsoft MVP Consumer Security 2007-2008-2009-2010-2011-2012-2013-2014

    ERROR MESSAGE 386
    No KeyBoard Detected
    Press F1 To Continue

    Just a reminder that threads will be closed if no reply in 3 days.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •