Results 1 to 3 of 3

Thread: Unusual behavior led me here

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Junior Member
    Join Date
    May 2010
    Virgina, USA

    Default Unusual behavior led me here

    I am not on "so called" corrupted computer as it does not recognize the visual recognition from the registration page. Last Thursday my computer began locking up after my AVG discovered threat JS/Dropper.
    I had to uninstall Firefox due to the freezes.

    I was told to run a number of things, malwarebytes, adaware, obvously my virus scan. MB did result in the discovery of a number of threats PSW.Sinowal.AW

    ANyway, friend said install and run spybot. After it locked up on virtumonde I discovered that I should have disabled tea timer. I have not rescanned with tea timer disabled.

    The following DDS report is where I stand.

    DDS (Ver_10-03-17.01) - NTFSx86
    Run by Nick Lukowsky at 16:20:24.23 on Mon 05/03/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_19
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3070.2413 [GMT -4:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
    C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
    C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\Hewlett-Packard\AiO\hp officejet k series\Bin\hpoorn07.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
    C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
    C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
    C:\Documents and Settings\Nick Lukowsky\Desktop\

    ============== Pseudo HJT Report ===============

    uStart Page = hxxp://
    uSearch Page = hxxp://
    uSearch Bar = hxxp://
    uDefault_Page_URL =
    uInternet Connection Wizard,ShellNext = hxxp://
    mSearchAssistant = hxxp://
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
    EB: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
    uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [SigmatelSysTrayApp] stsystra.exe
    mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\Iaanotif.exe
    mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe
    mRun: [RealTray] c:\program files\real\realplayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
    mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE
    mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [D-Link RangeBooster G WDA-2320] c:\program files\d-link\rangebooster g wda-2320\AirPlusCFG.exe
    mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
    mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
    mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
    mRun: [nwiz] nwiz.exe /installquiet
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [Share-to-Web Namespace Daemon] c:\program files\hewlett-packard\hp share-to-web\hpgs2wnd.exe
    mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpaiod~1.lnk - c:\program files\hewlett-packard\aio\hp officejet k series\bin\hpoorn07.exe
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
    IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://
    DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://
    DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://
    DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://
    DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll

    ============= SERVICES / DRIVERS ===============

    R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-5-3 64288]
    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-10-23 216200]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-10-23 29512]
    R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-4-24 242896]
    R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-3-18 308064]
    R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1285864]
    R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [2005-8-25 466880]
    S2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
    S4 Symantec Core LC;Symantec Core LC;"c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe" --> c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [?]

    =============== Created Last 30 ================

    2010-05-03 18:49:12 15880 ----a-w- c:\windows\system32\lsdelete.exe
    2010-05-03 17:07:58 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
    2010-05-03 17:07:55 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
    2010-05-03 17:06:11 0 dc-h--w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
    2010-05-03 17:05:58 0 d-----w- c:\program files\Lavasoft
    2010-05-03 15:05:54 0 d-----w- c:\docume~1\nicklu~1\applic~1\Malwarebytes
    2010-05-03 15:05:47 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-05-03 15:05:47 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-05-03 15:05:46 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-05-03 15:05:46 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-04-30 20:27:58 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-04-30 20:27:58 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2010-04-30 18:21:41 181632 ------w- c:\windows\system32\MpSigStub.exe
    2010-04-15 13:21:19 54156 ---ha-w- c:\windows\QTFont.qfn
    2010-04-15 13:21:19 1409 ----a-w- c:\windows\QTFont.for
    2010-04-14 14:44:28 0 d-----w- c:\program files\Ventrilo
    2010-04-14 14:44:25 262 ----a-w- c:\windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
    2010-04-14 14:44:13 0 d-----w- c:\program files\common files\Wise Installation Wizard
    2010-04-05 13:26:32 0 d-----w- c:\documents and settings\nick lukowsky\.worldoflogs

    ==================== Find3M ====================

    2010-04-21 12:58:21 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-03-18 11:33:33 12464 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-03-18 11:33:25 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-03-16 07:37:50 278120 ----a-w- c:\windows\system32\nvmccs.dll
    2010-03-16 07:37:50 154216 ----a-w- c:\windows\system32\nvsvc32.exe
    2010-03-16 07:37:50 145000 ----a-w- c:\windows\system32\nvcolor.exe
    2010-03-16 07:37:50 13670504 ----a-w- c:\windows\system32\nvcpl.dll
    2010-03-16 07:37:50 110696 ----a-w- c:\windows\system32\nvmctray.dll
    2010-03-16 07:37:44 81920 ----a-w- c:\windows\system32\nvwddi.dll
    2010-03-12 15:26:36 600680 ----a-w- c:\windows\system32\NVUNINST.EXE
    2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\vbscript.dll
    2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\dllcache\vbscript.dll
    2010-03-09 08:28:20 411368 ----a-w- c:\windows\system32\deploytk.dll
    2010-02-25 15:54:36 11070976 ------w- c:\windows\system32\dllcache\ieframe.dll
    2010-02-24 13:11:07 455680 ------w- c:\windows\system32\dllcache\mrxsmb.sys
    2010-02-24 09:54:25 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
    2010-02-17 13:10:28 2189952 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
    2010-02-16 14:08:49 2146304 ----a-w- c:\windows\system32\ntoskrnl.exe
    2010-02-16 14:08:49 2146304 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
    2010-02-16 13:25:04 2066816 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
    2010-02-16 13:25:04 2024448 ----a-w- c:\windows\system32\ntkrnlpa.exe
    2010-02-16 13:25:04 2024448 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
    2010-02-12 04:33:11 100864 ----a-w- c:\windows\system32\6to4svc.dll
    2010-02-12 04:33:11 100864 ------w- c:\windows\system32\dllcache\6to4svc.dll
    2010-02-11 12:02:15 226880 ------w- c:\windows\system32\dllcache\tcpip6.sys
    2004-08-04 09:00:00 94784 --sh--w- c:\windows\twain.dll
    2008-04-14 00:12:07 50688 --sh--w- c:\windows\twain_32.dll
    2008-04-14 00:11:56 1028096 --sh--w- c:\windows\system32\mfc42.dll
    2008-04-14 00:12:01 57344 --sh--w- c:\windows\system32\msvcirt.dll
    2008-04-14 00:12:01 413696 --sh--w- c:\windows\system32\msvcp60.dll
    2008-04-14 00:12:01 343040 --sh--w- c:\windows\system32\msvcrt.dll
    2008-04-14 00:12:02 551936 --sh--w- c:\windows\system32\oleaut32.dll
    2008-04-14 00:12:02 84992 --sh--w- c:\windows\system32\olepro32.dll
    2008-04-14 00:12:32 11776 --sh--w- c:\windows\system32\regsvr32.exe
    2008-09-29 12:46:26 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092920080930\index.dat

    ============= FINISH: 16:20:54.73 ===============

    Sorry I did not come here first. Let me know what you think.

    Thank you.

    Ok, I tried to run spybot with tea timer disabled and it still locked up.

    I took the hint and started to back up all my data onto disc and the system locked up before I could get it started. I expect I can do a system restore, via Dell/Symantec software. I will move data via a thumb drive instead of disc.
    Last edited by tashi; 2010-05-04 at 16:36. Reason: Merged 2 posts as per forum FAQ

  2. #2
    Emeritus Blade81's Avatar
    Join Date
    Oct 2006



    Please rerun DDS and post back attach.txt part this time too.

    Download GMER here by clicking download exe -button and then saving it your desktop:
    • Double-click .exe that you downloaded
    • Click rootkit-tab, uncheck files option and then click scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log (if the log is long, archive it into a zip file and attach instead of posting) in your reply.
    Microsoft Windows Insider MVP 2016-2019
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  3. #3
    Emeritus Blade81's Avatar
    Join Date
    Oct 2006


    Due to inactivity, this thread will now be closed.

    Note:If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh DDS log and a link to your previous thread. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.

    If it has been less than three days since your last response and you need the thread re-opened, please send me or other MOD a private message (pm). A valid, working link to the closed topic is required.
    Microsoft Windows Insider MVP 2016-2019
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts