Page 5 of 8 FirstFirst 12345678 LastLast
Results 41 to 50 of 71

Thread: DDS Will not complete, No task Manager, etc...

  1. #41
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    After that warning screen, I selected ok to close it out and GMER comes up but it does not look like the example you show... lots of the pick boxes are greyed out.

  2. #42
    Malware Team-Emeritus
    Join Date
    May 2010
    Posts
    212

    Default

    Let's postpone any use of GMER and take a closer look at the MBR:


    aswMBR

    Please download aswMBR and save it to your Desktop.

    • Double click aswMBR.exe to run it.
    • When asked if you want to download Avast's virus definitions please select Yes. Continue even if the definition download fails.
    • Click the Scan button.
    • After a short while when the scan reports "Scan finished successfully", click Save log & save the log to your desktop.
    • Click OK > Exit.
    • Note: Do not attempt to fix anything at this stage!
    • Two files will be created, aswMBR.txt & a file named MBR.dat.
    • MBR.dat is a backup of the MBR(master boot record), do not delete it.
    • Copy & Paste the contents of aswMBR.txt into your next reply.



    Upload File for testing

    Please go to Virustotal.

    Click Choose file and upload the following file on your desktop:
    MBR.dat
    Click Scan it! to upload the file for testing.
    Click Reanalyse if asked.
    Please wait for all the scanners to finish then copy and paste the web address in your next response.
    Example of web address:



    MBRCheck

    • Please download MBRCheck.exe and save it to your desktop.
    • Double click on MBRCheck.exe to run it.
    • A window similar to this should open on your desktop:




    • If you are prompted with options, enter N at the prompt and press Enter
    • Press Enter again.
    • A log will open on your Desktop ...... MBRCheck_mm.dd.yy_hh.mm.ss.txt (where mm.dd.yy_hh.mm.ss are the date and time the scan was run)
    • Please post the contents of the log in your next reply.



    OTL

    Please download OTL by Old Timer and save it to your Desktop.
    • Double click on OTL.exe to run it.
    • Under Output, ensure that Standard Output is selected.
    • Under Extra Registry section, select Use SafeList.
    • Click the Scan All Users checkbox.
    • Please save all work and close all open program windows.
    • Click on Run Scan at the top left hand corner.
    • When done, two Notepad files will open.
      • OTL.txt <-- Will be opened
      • Extra.txt <-- Will be minimized
    • Please post the contents of these 2 Notepad files in your next replies. Please use a separate reply for each log.



    Remember to post:
    • aswMBR log.
    • Link to the Virustotal scan.
    • MBRCheck log.
    • OTL logs.


    How is the computer performing now?
    Are you able to start Task Manager and download antivirus updates?
    Does google still redirect?
    Are the files on your desktop and c: drive visible?
    Is the Start menu normal?

  3. #43

  4. #44
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    aswMBR version 0.9.9.1532 Copyright(c) 2011 AVAST Software
    Run date: 2012-01-26 19:30:21
    -----------------------------
    19:30:21.103 OS Version: Windows 5.1.2600 Service Pack 3
    19:30:21.113 Number of processors: 1 586 0xD06
    19:30:21.113 ComputerName: MOBILE UserName: adnott
    19:30:21.804 Initialize success
    19:34:13.276 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
    19:34:13.276 Disk 0 Vendor: HTS726060M9AT00 MH4OA6EA Size: 57231MB BusType: 3
    19:34:13.296 Disk 0 MBR read successfully
    19:34:13.296 Disk 0 MBR scan
    19:34:13.296 Disk 0 unknown MBR code
    19:34:13.306 Disk 0 MBR hidden
    19:34:13.306 Disk 0 Partition 1 00 DE Dell Utility Dell 4.1 47 MB offset 63
    19:34:13.316 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 53976 MB offset 96390
    19:34:13.336 Disk 0 Partition 3 00 DB CP/M / CTOS MSWIN4.1 3200 MB offset 110639655
    19:34:13.357 Disk 0 Partition 4 80 (A) 17 Hidd HPFS/NTFS NTFS 7 MB offset 117194175
    19:34:13.357 Disk 0 Partition 4 **SUSPICIOUS**
    19:34:13.367 Disk 0 scanning sectors +117210224
    19:34:13.527 Disk 0 scanning C:\WINDOWS\system32\drivers
    19:34:22.560 Service scanning
    19:34:24.222 Modules scanning
    19:34:32.364 Disk 0 trace - called modules:
    19:34:32.384 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8a93afa9]<<
    19:34:32.394 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8aa07ab8]
    19:34:32.394 3 CLASSPNP.SYS[f76b7fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aa0cb00]
    19:34:32.394 \Driver\atapi[0x8aa0fc28] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x8a93afa9
    19:34:32.394 Scan finished successfully
    19:53:48.857 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\adnott\Desktop\MBR.dat"
    19:53:48.877 The log file has been saved successfully to "C:\Documents and Settings\adnott\Desktop\aswMBR.txt"

  5. #45
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    MBRCheck, version 1.2.3
    (c) 2010, AD

    Command-line:
    Windows Version: Windows XP Professional
    Windows Information: Service Pack 3 (build 2600)
    Logical Drives Mask: 0x0000000c

    Kernel Drivers (total 196):
    0x804D7000 \WINDOWS\system32\ntoskrnl.exe
    0x806EF000 \WINDOWS\system32\hal.dll
    0xF7987000 \WINDOWS\system32\KDCOM.DLL
    0xF7897000 \WINDOWS\system32\BOOTVID.dll
    0xF75A8000 ACPI.sys
    0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
    0xF7597000 pci.sys
    0xF75F7000 isapnp.sys
    0xF789B000 compbatt.sys
    0xF789F000 \WINDOWS\system32\DRIVERS\BATTC.SYS
    0xF7A4F000 pciide.sys
    0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
    0xF798B000 cmdide.sys
    0xF798D000 intelide.sys
    0xF798F000 toside.sys
    0xF7991000 viaide.sys
    0xF7993000 aliide.sys
    0xF74D9000 pcmcia.sys
    0xF7607000 MountMgr.sys
    0xF74BA000 ftdisk.sys
    0xF7494000 dmio.sys
    0xF770F000 PartMgr.sys
    0xF7617000 VolSnap.sys
    0xF78A3000 cpqarray.sys
    0xF747C000 \WINDOWS\system32\DRIVERS\SCSIPORT.SYS
    0xF7464000 atapi.sys
    0xF78A7000 aha154x.sys
    0xF7717000 sparrow.sys
    0xF78AB000 symc810.sys
    0xF7627000 aic78xx.sys
    0xF78AF000 dac960nt.sys
    0xF7637000 ql10wnt.sys
    0xF78B3000 amsint.sys
    0xF771F000 asc.sys
    0xF78B7000 asc3550.sys
    0xF7727000 mraid35x.sys
    0xF772F000 i2omp.sys
    0xF78BB000 ini910u.sys
    0xF7647000 ql1240.sys
    0xF7657000 aic78u2.sys
    0xF7737000 symc8xx.sys
    0xF773F000 sym_hi.sys
    0xF7747000 sym_u3.sys
    0xF774F000 ABP480N5.SYS
    0xF7757000 asc3350p.sys
    0xF7995000 cd20xrnt.sys
    0xF7667000 ultra.sys
    0xF786E000 adpu160m.sys
    0xF775F000 dpti2o.sys
    0xF7677000 ql1080.sys
    0xF7687000 ql1280.sys
    0xF7697000 ql12160.sys
    0xF7767000 perc2.sys
    0xF7997000 perc2hib.sys
    0xF776F000 hpn.sys
    0xF78BF000 cbidf2k.sys
    0xF7842000 dac2w2k.sys
    0xF76A7000 disk.sys
    0xF76B7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
    0xF7967000 fltmgr.sys
    0xF7830000 sr.sys
    0xF76C7000 PxHelp20.sys
    0xF7952000 drvmcdb.sys
    0xF7A38000 KSecDD.sys
    0xF7A25000 WudfPf.sys
    0xF7B52000 Ntfs.sys
    0xF7B25000 NDIS.sys
    0xF76D7000 sisagp.sys
    0xF76E7000 viaagp.sys
    0xF76F7000 ohci1394.sys
    0xF7587000 \WINDOWS\system32\DRIVERS\1394BUS.SYS
    0xBA746000 Mup.sys
    0xF7577000 agp440.sys
    0xF7567000 alim1541.sys
    0xF7557000 amdagp.sys
    0xF7547000 agpCPQ.sys
    0xBA6EA000 \SystemRoot\system32\DRIVERS\tunmp.sys
    0xF7414000 \SystemRoot\system32\DRIVERS\intelppm.sys
    0xBA6E6000 \SystemRoot\system32\DRIVERS\CmBatt.sys
    0xB98CE000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
    0xB98BA000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
    0xF77D7000 \SystemRoot\system32\DRIVERS\usbuhci.sys
    0xB9896000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
    0xF77DF000 \SystemRoot\system32\DRIVERS\usbehci.sys
    0xF7404000 \SystemRoot\system32\DRIVERS\bcm4sbxp.sys
    0xB9678000 \SystemRoot\system32\DRIVERS\w29n51.sys
    0xF7887000 \SystemRoot\system32\DRIVERS\i8042prt.sys
    0xB965F000 \SystemRoot\system32\DRIVERS\Apfiltr.sys
    0xF77E7000 \SystemRoot\system32\DRIVERS\mouclass.sys
    0xF77EF000 \SystemRoot\system32\DRIVERS\kbdclass.sys
    0xBA7F0000 \SystemRoot\system32\DRIVERS\imapi.sys
    0xF79C1000 \SystemRoot\system32\drivers\sscdbhk5.sys
    0xBA7E0000 \SystemRoot\system32\DRIVERS\cdrom.sys
    0xBA7D0000 \SystemRoot\system32\DRIVERS\redbook.sys
    0xB963C000 \SystemRoot\system32\DRIVERS\ks.sys
    0xF77F7000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys
    0xB95FB000 \SystemRoot\system32\drivers\stac97.sys
    0xB95D7000 \SystemRoot\system32\drivers\portcls.sys
    0xBA7C0000 \SystemRoot\system32\drivers\drmk.sys
    0xB95A6000 \SystemRoot\system32\DRIVERS\HSFHWICH.sys
    0xB94A7000 \SystemRoot\system32\DRIVERS\HSF_DP.sys
    0xB9401000 \SystemRoot\system32\DRIVERS\HSF_CNXT.sys
    0xF77FF000 \SystemRoot\System32\Drivers\Modem.SYS
    0xB93E5000 \SystemRoot\system32\DRIVERS\dne2000.sys
    0xB93D3000 \SystemRoot\System32\Drivers\KUSBusByTCPMasterBus.sys
    0xF7807000 \SystemRoot\System32\Drivers\TDI.SYS
    0xF780F000 \SystemRoot\system32\drivers\tbhsd.sys
    0xF7AAE000 \SystemRoot\system32\DRIVERS\audstub.sys
    0xBA7B0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
    0xBA6B5000 \SystemRoot\system32\DRIVERS\ndistapi.sys
    0xB93BC000 \SystemRoot\system32\DRIVERS\ndiswan.sys
    0xBA7A0000 \SystemRoot\system32\DRIVERS\raspppoe.sys
    0xBA790000 \SystemRoot\system32\DRIVERS\raspptp.sys
    0xB93AB000 \SystemRoot\system32\DRIVERS\psched.sys
    0xBA780000 \SystemRoot\system32\DRIVERS\msgpc.sys
    0xF7817000 \SystemRoot\system32\DRIVERS\ptilink.sys
    0xF781F000 \SystemRoot\system32\DRIVERS\raspti.sys
    0xBA695000 \SystemRoot\System32\Drivers\Pcouffin.sys
    0xB932B000 \SystemRoot\system32\DRIVERS\rdpdr.sys
    0xBA760000 \SystemRoot\system32\DRIVERS\termdd.sys
    0xF79C5000 \SystemRoot\system32\DRIVERS\swenum.sys
    0xB92A5000 \SystemRoot\system32\DRIVERS\update.sys
    0xBA69D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
    0xBA68D000 \SystemRoot\system32\DRIVERS\omci.sys
    0xBA685000 \SystemRoot\system32\DRIVERS\NkVBus.sys
    0xF7527000 \SystemRoot\System32\Drivers\NDProxy.SYS
    0xBA5F3000 \SystemRoot\system32\DRIVERS\usbhub.sys
    0xF79CB000 \SystemRoot\system32\DRIVERS\USBD.SYS
    0xBA712000 \SystemRoot\System32\Drivers\i2omgmt.SYS
    0xB8256000 \SystemRoot\system32\DRIVERS\MpFilter.sys
    0xF79ED000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
    0xF7A9F000 \SystemRoot\System32\Drivers\Null.SYS
    0xF79EF000 \SystemRoot\System32\Drivers\Beep.SYS
    0xBA655000 \SystemRoot\system32\drivers\ssrtln.sys
    0xBA64D000 \SystemRoot\System32\drivers\vga.sys
    0xF79F1000 \SystemRoot\System32\Drivers\mnmdd.SYS
    0xF79F3000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
    0xF778F000 \SystemRoot\System32\Drivers\Msfs.SYS
    0xF7797000 \SystemRoot\System32\Drivers\Npfs.SYS
    0xBA6E2000 \SystemRoot\system32\DRIVERS\rasacd.sys
    0xB8223000 \SystemRoot\system32\DRIVERS\ipsec.sys
    0xB8208000 \??\C:\WINDOWS\system32\Drivers\RCFOX.sys
    0xB81AF000 \SystemRoot\system32\DRIVERS\tcpip.sys
    0xB8187000 \SystemRoot\system32\DRIVERS\netbt.sys
    0xB814F000 \SystemRoot\system32\DRIVERS\tcpip6.sys
    0xBA6DE000 \SystemRoot\System32\drivers\ws2ifsl.sys
    0xB8105000 \SystemRoot\System32\drivers\afd.sys
    0xBA5D3000 \SystemRoot\system32\DRIVERS\netbios.sys
    0xB80DA000 \SystemRoot\system32\DRIVERS\rdbss.sys
    0xB806A000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
    0xBA5B3000 \SystemRoot\System32\Drivers\Fips.SYS
    0xB8044000 \SystemRoot\system32\DRIVERS\ipnat.sys
    0xBA5A3000 \SystemRoot\system32\drivers\ip6fw.sys
    0xB8299000 \SystemRoot\SYSTEM32\DRIVERS\APPDRV.SYS
    0xBA091000 \SystemRoot\system32\DRIVERS\wanarp.sys
    0xBA071000 \SystemRoot\System32\Drivers\Cdfs.SYS
    0xB8004000 \SystemRoot\System32\Drivers\dump_atapi.sys
    0xB9D42000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
    0xBF800000 \SystemRoot\System32\win32k.sys
    0xBA6FE000 \SystemRoot\System32\drivers\Dxapi.sys
    0xF77BF000 \SystemRoot\System32\watchdog.sys
    0xBF000000 \SystemRoot\System32\drivers\dxg.sys
    0xF7A98000 \SystemRoot\System32\drivers\dxgthk.sys
    0xBF012000 \SystemRoot\System32\nv4_disp.dll
    0xBF3A4000 \SystemRoot\System32\ATMFD.DLL
    0xBA061000 \SystemRoot\system32\drivers\drvnddm.sys
    0xB9DC4000 \SystemRoot\system32\dla\tfsndres.sys
    0xB5A26000 \SystemRoot\system32\dla\tfsnifs.sys
    0xB633D000 \SystemRoot\system32\dla\tfsnopio.sys
    0xF79A7000 \SystemRoot\system32\dla\tfsnpool.sys
    0xF77CF000 \SystemRoot\system32\dla\tfsnboio.sys
    0xBA041000 \SystemRoot\system32\dla\tfsncofs.sys
    0xB9DC5000 \SystemRoot\system32\dla\tfsndrct.sys
    0xB5A0D000 \SystemRoot\system32\dla\tfsnudf.sys
    0xB59F4000 \SystemRoot\system32\dla\tfsnudfa.sys
    0xB5AF4000 \SystemRoot\system32\DRIVERS\fssfltr_tdi.sys
    0xB584E000 \SystemRoot\system32\DRIVERS\nwlnkipx.sys
    0xB5AE4000 \SystemRoot\system32\DRIVERS\nwlnknb.sys
    0xB5964000 \SystemRoot\system32\DRIVERS\ndisuio.sys
    0xB5954000 \SystemRoot\system32\DRIVERS\s24trans.sys
    0xB4EED000 \SystemRoot\system32\DRIVERS\nwrdr.sys
    0xB4EC0000 \SystemRoot\system32\DRIVERS\mrxdav.sys
    0xB9D3A000 \??\C:\Program Files\321Studios\Shared\CDRPDACC.SYS
    0xB9D38000 \SystemRoot\system32\DRIVERS\dsunidrv.sys
    0xB4D14000 \SystemRoot\system32\DRIVERS\srv.sys
    0xB4DC8000 \SystemRoot\System32\Drivers\MCSTRM.SYS
    0xB4C44000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys
    0xB4F65000 \SystemRoot\system32\DRIVERS\nwlnkspx.sys
    0xB4B1F000 \SystemRoot\system32\drivers\wdmaud.sys
    0xB4E38000 \SystemRoot\system32\drivers\sysaudio.sys
    0xB3B87000 \SystemRoot\System32\Drivers\HTTP.sys
    0xB1912000 \??\C:\DOCUME~1\adnott\LOCALS~1\Temp\pwtdypod.sys
    0xB9D40000 \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys
    0xB22BA000 \??\C:\DOCUME~1\adnott\LOCALS~1\Temp\aswMBR.sys
    0xB0E07000 \SystemRoot\system32\drivers\kmixer.sys
    0x7C900000 \WINDOWS\SYSTEM32\ntdll.dll

    Processes (total 74):
    0 System Idle Process
    4 System
    880 C:\WINDOWS\SYSTEM32\smss.exe
    1656 csrss.exe
    1680 C:\WINDOWS\SYSTEM32\winlogon.exe
    1724 C:\WINDOWS\SYSTEM32\services.exe
    1736 C:\WINDOWS\SYSTEM32\lsass.exe
    1920 C:\WINDOWS\SYSTEM32\svchost.exe
    2008 svchost.exe
    156 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
    236 C:\WINDOWS\SYSTEM32\svchost.exe
    332 C:\WINDOWS\SYSTEM32\svchost.exe
    568 C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
    724 svchost.exe
    984 C:\WINDOWS\SYSTEM32\spoolsv.exe
    1076 svchost.exe
    1116 C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
    1140 C:\Program Files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
    1160 C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    1176 C:\Program Files\Bonjour\mDNSResponder.exe
    1212 C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    1260 C:\Program Files\Java\jre6\bin\jqs.exe
    1312 C:\Program Files\Common Files\Motive\McciCMService.exe
    1544 C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    1584 C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
    1636 C:\Program Files\Nikon\Wireless Camera Setup Utility\NkPtpEnum.exe
    1844 C:\WINDOWS\SYSTEM32\nvsvc32.exe
    408 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    1384 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    1532 C:\WINDOWS\SYSTEM32\TCPSVCS.EXE
    1660 C:\WINDOWS\SYSTEM32\snmp.exe
    148 C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    2176 C:\WINDOWS\SYSTEM32\svchost.exe
    2204 C:\Program Files\Viewpoint\Common\ViewpointService.exe
    2296 C:\Program Files\Windows Home Server\WHSConnector.exe
    3152 C:\WINDOWS\SYSTEM32\wscntfy.exe
    3176 alg.exe
    3188 C:\Program Files\Apoint\Apoint.exe
    3204 C:\WINDOWS\SYSTEM32\BacsTray.exe
    3212 C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    3220 wmiprvse.exe
    3228 C:\Program Files\Dell\Media Experience\DMXLauncher.exe
    3244 C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
    3276 C:\WINDOWS\SYSTEM32\dla\tfswctrl.exe
    3304 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    3344 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    3368 C:\Program Files\Verizon\McciTrayApp.exe
    3396 C:\Program Files\Dell\QuickSet\quickset.exe
    3452 C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    3480 C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
    3532 C:\Program Files\Apoint\ApntEx.exe
    3548 C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
    3564 C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    3612 C:\Program Files\TRENDnet\MFP Server\Control Center.exe
    3620 C:\WINDOWS\SYSTEM32\umonit.exe
    3628 C:\Program Files\iTunes\iTunesHelper.exe
    3660 C:\Program Files\Common Files\Java\Java Update\jusched.exe
    3684 C:\Program Files\Microsoft Security Client\msseces.exe
    3848 C:\Program Files\AWS\WeatherBug\Weather.exe
    3884 C:\Program Files\DellSupport\DSAgnt.exe
    4040 C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    2596 C:\Program Files\Digital Line Detect\DLG.exe
    2708 C:\Program Files\ArcSoft\Media Card Companion\MCC Monitor.exe
    464 C:\WINDOWS\SYSTEM32\WBEM\UNSECAPP.EXE
    556 wmiprvse.exe
    1388 C:\Program Files\Windows Home Server\WHSTrayApp.exe
    1456 C:\WINDOWS\SYSTEM32\ctfmon.exe
    396 C:\Program Files\iPod\bin\iPodService.exe
    3288 C:\WINDOWS\explorer.exe
    1204 C:\Program Files\Common Files\Java\Java Update\jucheck.exe
    2284 C:\Program Files\Mozilla Firefox\firefox.exe
    636 C:\WINDOWS\SYSTEM32\wuauclt.exe
    3000 C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    3292 C:\Documents and Settings\adnott\Desktop\MBRCheck.exe

    \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`02f10c00 (NTFS)

    PhysicalDrive0 Model Number: HTS726060M9AT00, Rev: MH4OA6EA

    Size Device Name MBR Status
    --------------------------------------------
    55 GB \\.\PhysicalDrive0 MBR Code Faked!
    SHA1: 84B95CE8A54B7C5C3AAF149934FC46FB70FF8365


    Found non-standard or infected MBR.
    Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    Done!

  6. #46
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    Just as i was about to run otl.exe, an internet security 2012 popup came up along with a warning message saying 'tfswctrl.exe cannot start' file tfswctrl is infected by w32/blaster.worm as well as another popup saying Warning! INTERNET SECURITY 2012 HAS found 68 useless and unwanted files on your computer!

  7. #47
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    Beyond the new popups. I see a new internet security 2012 on the desktop that i did not download.

    Taskmanager launches
    I have programs and files back
    internet connection is really flaky again and having trouble downloading even these small tool files

    Rkill.exe will not run since this new set of popups

  8. #48
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    Newest development. 61 microsoft updates ready to install. No programs at all will run- taskmgr comes up but hides itself, security essentials or web browsers won't even do that.

  9. #49
    Member
    Join Date
    Jan 2012
    Posts
    46

    Default

    In watching the Microsoft Security Updates install... seems like every 2nd or 3rd one fails. Still unable to open any program.

    Strange this happens after running aswMBR & MBRcheck. Never got to OTL.exe before this started.

  10. #50
    Malware Team-Emeritus
    Join Date
    May 2010
    Posts
    212

    Default

    Your computer seems to be infected with a variant of the TDSS Rootkit, also known as W32/Alureon, which installs itself on a hidden partition.

    This particular version might not be fixable and in over 90% of cases so far, the only guaranteed cure has been a reformat of the hard drive and reinstall of Windows.

    A rootkit is a set of software tools intended for concealing running processes, files or system data from the operating system.

    Due to its rootkit functionality, it's impossible to tell what may have been done when the system was compromised.

    You should:
    • Call all your banks, financial institutions, credit card companies and inform them that you may be a victim of identity theft and put a watch on your accounts.
    • Change all your passwords (ISP login password, your email address(es) passwords, financial accounts, PayPal, eBay, Amazon, online groups and forums and any other online activities you carry out which require a username and password)


    Here are two links to further information if you would like more information:
    What are rootkits from Wikipedia
    How do I respond to a possible identity theft and how do I prevent it


    Internet Security 2012 is a fake anti virus often bundled with the other infections we so far have identified on this computer.


    Please follow the instructions below:


    Safe mode

    • Restart your computer
    • During startup, but before the Windows logo appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode with Networking, then press Enter.
    • Choose your usual account.
    • When asked to proceed to safe mode, click Yes.



    Try to run rkill, you can alternatively download an alternate rkill from one of the following links and run it:
    One Two Three

    Re-run exehelper again by double clicking the file.

    Disable Microsoft Security Essentials.
    • Open MSE and go to Settings > Real Time Protection.
    • Then uncheck "Turn on real time protection".
    • Exit MSE when done.


    Re-run Combofix:
    Click Start -> Run..., copy and paste the following line into the run box, then click OK:
    combofix /nombr
    Let combofix update itself if prompted.
    Post the Combofix log in your next reply.

    If combofix sucessfully ran and gave you a new log, then:
    Start your computer in Safe Mode again (required if Combofix restarted the computer).
    Rerun rkill and wait for it to finish.
    Click Start -> Run..., copy and paste the following line into the run box, then click OK:
    aswMBR.exe -ap 2

    When aswMBR finishes running, it should give you a log. Please post it.
    Last edited by vict0r; 2012-01-27 at 21:34.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •