Hello,
I hope you can help. A week ago I began having redirects and ran Spybot only to discover this hijacker/trojan in my registry which it removed - only to return on the next boot. The symptoms include:
1. IE 8 redirects.
2. An ever increasing svchost process in task manager which becomes huge and takes over cpu usage, causing the system to slow to an unacceptable level.
3. An inability to reach the microsoft windows update site getting a "cannot connect" IE error message.
I tried running malwarebytes, avg, ccleaner and any other programs available but they neither find problem or fix it. I tried Microsoft Security Enhancement program but it too did nothing to solve the problem. I tried to update the virus database but couldn't connect to their site. Then I called them and
worked with tech support via remote access and they ran all kinds or programs with no success, finally telling me to format my drive and reinstall windows (my last and most undesireable recourse).
And here's the latest-when I try to send this post to you, I receive the same IE can't connect message so I'm using my laptop to get this message to you, with attach and dds from my infected desktop, for which I've run the backup program as stated in the instructions for posting.
Thanks in advance for your help.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Morris at 18:12:56.03 on Sat 04/30/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.586 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
F:\Nero 7\InCD\InCDsrv.exe
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
svchost.exe
C:\WINDOWS\regedit.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Morris\Desktop\Virus Problems\spybot support\dds.pif
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboForm.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
BHO: ieCom Class: {c6ceac32-d45c-11d4-94af-0050babd5fd6} - c:\program files\url organizer\UrlOrgIE.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboForm.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
dRunOnce: [RunNarrator] Narrator.exe
IE: &4 Edit Passcards
IE: &7 Fill Forms
IE: &8 Save Forms
IE: &Copy Location
IE: &Highlight
IE: &Links List
IE: Add to Google Photos Screensa&ver
IE: Customize Menu &4
IE: Fill Forms &]
IE: I&mages List
IE: Open Frame in &New Window
IE: Save Forms &[
IE: Zoom &In
IE: Zoom O&ut
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - {C651A691-CCD9-11D2-92D3-0000F87A4A55} - c:\windows\system32\webzone.dll
IE: {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - {C651A693-CCD9-11D2-92D3-0000F87A4A55} - c:\windows\system32\webzone.dll
IE: {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - {A58D06D4-CA90-11D2-92D2-0000F87A4A55} - c:\windows\system32\oline.dll
Trusted Zone: aol.com\my.screenname
Trusted Zone: aol.com\webmail
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: microsoft.com\www.update
Trusted Zone: windowsupdate.com\download
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B}
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF}
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C}
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8}
DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxps://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1303957118671
DPF: {65FDEDF3-8ED9-4F5B-825E-18C2D44191A7}
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1281675242218
DPF: {6F750200-1362-4815-A476-88533DE61D0C}
DPF: {6F750202-1362-4815-A476-88533DE61D0C}
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D}
DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7}
DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68}
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A}
DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} - hxxp://moneycentral.msn.com/cabs/pmupdate2.exe
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
DPF: {AECD14A8-F662-11D1-A395-00805F535788}
DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747}
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003}
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5}
TCP: {894A79C5-4324-4432-A90F-654335FBE272} = 4.2.2.1,4.2.2.2
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} -
Name-Space Handler: http\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} -
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-4-7 13496]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 HPFECP15;HPFECP15;c:\windows\system32\drivers\HPFecp15.sys [1999-2-16 52800]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-3-7 1373480]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-5 135664]
S3 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-18 14336]
S3 lgatbus;LG USB Composite Device driver (WDM);c:\windows\system32\drivers\lgatbus.sys [2007-4-17 43024]
S3 lgatmdm;LG CDMA USB Modem Drivers;c:\windows\system32\drivers\lgatmdm.sys [2007-4-17 77104]
S3 lgatserd;LG CDMA USB Modem Diagnostic Serial Port Drivers (WDM);c:\windows\system32\drivers\lgatserd.sys [2007-4-17 60816]
.
=============== Created Last 30 ================
.
2011-04-30 14:35:56 7071056 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-30 14:35:34 7071056 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{64b81509-fdf8-4fe9-8bfc-714292c3896c}\mpengine.dll
2011-04-30 04:48:33 -------- d-sha-r- C:\cmdcons
2011-04-29 04:14:08 2476 ----a-w- C:\regbak.reg
2011-04-28 04:17:33 -------- d-----w- c:\program files\ESET
2011-04-28 02:43:36 98816 ----a-w- c:\windows\sed.exe
2011-04-28 02:43:36 89088 ----a-w- c:\windows\MBR.exe
2011-04-28 02:43:36 256512 ----a-w- c:\windows\PEV.exe
2011-04-28 02:43:36 161792 ----a-w- c:\windows\SWREG.exe
2011-04-27 01:23:56 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-04-27 01:23:56 -------- d-----w- c:\windows\system32\wbem\Repository
2011-04-27 01:22:04 -------- d-----w- c:\docume~1\morris\locals~1\applic~1\{7CBA73E9-288D-47ED-8FD7-A2540E3C5FAC}
2011-04-27 01:22:04 -------- d-----w- c:\docume~1\morris\applic~1\Huuziz
2011-04-27 01:22:04 -------- d-----w- c:\docume~1\morris\applic~1\2874392D513E59CB58D1165949F560A5
2011-04-27 01:19:18 -------- d--h--w- c:\windows\ie8
2011-04-26 23:39:44 -------- dc----w- c:\windows\ie8(2)
2011-04-26 06:47:41 -------- d-----w- c:\windows\system32\CatRoot2
2011-04-25 15:09:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-25 14:54:09 106496 --sha-r- c:\windows\system32\winmineq.dll
2011-04-25 14:49:24 -------- d-----w- c:\docume~1\morris\applic~1\TeamViewer
2011-04-25 05:34:47 -------- d-----w- c:\windows\ERDNT -registry backup 04252011
2011-04-24 02:58:10 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-24 02:11:05 -------- d-----w- c:\program files\Microsoft Easy Assist
2011-04-24 02:09:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\Applications
2011-04-23 06:04:59 -------- d-----w- c:\program files\AVG
2011-04-22 06:29:33 -------- d-----w- c:\program files\common files\ParetoLogic
2011-04-22 06:29:33 -------- d-----w- c:\docume~1\morris\applic~1\ParetoLogic
2011-04-22 06:29:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2011-04-22 06:28:46 -------- d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2011-04-22 06:15:57 -------- d-----w- c:\docume~1\morris\applic~1\DriverCure
2011-04-22 05:51:27 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-21 08:06:13 -------- d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2011-04-17 06:20:35 -------- d-----w- c:\docume~1\morris\locals~1\applic~1\PackageAware
2011-04-15 22:52:58 -------- d-----w- c:\docume~1\morris\applic~1\Umxye
2011-04-07 04:40:15 -------- d-----w- c:\docume~1\morris\applic~1\IObit
2011-04-07 04:40:02 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-04-07 04:40:02 13496 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-04-07 04:39:57 -------- d-----w- c:\program files\IObit
2011-04-04 02:32:31 -------- d-----w- c:\program files\NirSoft
.
==================== Find3M ====================
.
2011-04-24 04:14:23 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2011-04-10 04:11:26 256 ----a-w- c:\windows\system32\pool.bin
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD400BB-75CAA0 rev.16.06V16 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys iomdisk.sys hal.dll >>UNKNOWN [0x8ACE54E7]<<
c:\windows\system32\drivers\iomdisk.sys Iomega Corporation Microsoft(R) Windows NT(R) Operating System
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8aceb7d0]; MOV EAX, [0x8aceb84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8AD89AB8]
3 CLASSPNP[0xF7647FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x8AD8CB08]
5 iomdisk[0xF7717BC3] -> nt!IofCallDriver[0x804E37D5] -> [0x8AD6AD98]
\Driver\atapi[0x8AD9DB08] -> IRP_MJ_CREATE -> 0x8ACE54E7
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8ACE5332
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 18:14:17.25 ===============
Here's the DDS file:
I hope you can help. A week ago I began having redirects and ran Spybot only to discover this hijacker/trojan in my registry which it removed - only to return on the next boot. The symptoms include:
1. IE 8 redirects.
2. An ever increasing svchost process in task manager which becomes huge and takes over cpu usage, causing the system to slow to an unacceptable level.
3. An inability to reach the microsoft windows update site getting a "cannot connect" IE error message.
I tried running malwarebytes, avg, ccleaner and any other programs available but they neither find problem or fix it. I tried Microsoft Security Enhancement program but it too did nothing to solve the problem. I tried to update the virus database but couldn't connect to their site. Then I called them and
worked with tech support via remote access and they ran all kinds or programs with no success, finally telling me to format my drive and reinstall windows (my last and most undesireable recourse).
And here's the latest-when I try to send this post to you, I receive the same IE can't connect message so I'm using my laptop to get this message to you, with attach and dds from my infected desktop, for which I've run the backup program as stated in the instructions for posting.
Thanks in advance for your help.
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Morris at 18:12:56.03 on Sat 04/30/2011
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1279.586 [GMT -4:00]
.
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
F:\Nero 7\InCD\InCDsrv.exe
C:\Program Files\AT&T Global Network Client\netcfgsvr.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Microsoft Security Client\msseces.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\wscntfy.exe
svchost.exe
C:\WINDOWS\regedit.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\internet explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\Morris\Desktop\Virus Problems\spybot support\dds.pif
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: H - No File
mWinlogon: Userinit=userinit.exe
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File
BHO: {53707962-6F74-2D53-2644-206D7942484F} - No File
BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboForm.dll
BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
BHO: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.6209.1142\swg.dll
BHO: ieCom Class: {c6ceac32-d45c-11d4-94af-0050babd5fd6} - c:\program files\url organizer\UrlOrgIE.dll
BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboForm.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [RoboForm] "c:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe"
dRunOnce: [RunNarrator] Narrator.exe
IE: &4 Edit Passcards
IE: &7 Fill Forms
IE: &8 Save Forms
IE: &Copy Location
IE: &Highlight
IE: &Links List
IE: Add to Google Photos Screensa&ver
IE: Customize Menu &4
IE: Fill Forms &]
IE: I&mages List
IE: Open Frame in &New Window
IE: Save Forms &[
IE: Zoom &In
IE: Zoom O&ut
IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - c:\program files\siber systems\ai roboform\RoboFormComFillForms.html
IE: {724d43aa-0d85-11d4-9908-00400523e39a} - c:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {B06300D0-CCDE-11d2-92D3-0000F87A4A55} - {C651A691-CCD9-11D2-92D3-0000F87A4A55} - c:\windows\system32\webzone.dll
IE: {BF80219A-CCDD-11d2-92D3-0000F87A4A55} - {C651A693-CCD9-11D2-92D3-0000F87A4A55} - c:\windows\system32\webzone.dll
IE: {FC09D8A3-C85A-11d2-92D0-0000F87A4A55} - {A58D06D4-CA90-11D2-92D2-0000F87A4A55} - c:\windows\system32\oline.dll
Trusted Zone: aol.com\my.screenname
Trusted Zone: aol.com\webmail
Trusted Zone: microsoft.com\*.update
Trusted Zone: microsoft.com\update
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: microsoft.com\www.update
Trusted Zone: windowsupdate.com\download
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
DPF: Microsoft XML Parser for Java
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B}
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
DPF: {11260943-421B-11D0-8EAC-0000C07D88CF}
DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
DPF: {17492023-C23A-453E-A040-C7C580BBF700}
DPF: {26FCCDF9-A7E1-452A-A73D-7BF7B4D0BA6C}
DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE}
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0}
DPF: {43B70AAD-23F4-4FD8-ADD9-441D8592EEB8}
DPF: {5763F8E8-0DD7-4A0F-ADB0-9F64C8F2C349}
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxps://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1303957118671
DPF: {65FDEDF3-8ED9-4F5B-825E-18C2D44191A7}
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1281675242218
DPF: {6F750200-1362-4815-A476-88533DE61D0C}
DPF: {6F750202-1362-4815-A476-88533DE61D0C}
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D}
DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7}
DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68}
DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A}
DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} - hxxp://moneycentral.msn.com/cabs/pmupdate2.exe
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
DPF: {AECD14A8-F662-11D1-A395-00805F535788}
DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C}
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - hxxp://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
DPF: {D670D0B3-05AB-4115-9F87-D983EF1AC747}
DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7}
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B}
DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003}
DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5}
TCP: {894A79C5-4324-4432-A90F-654335FBE272} = 4.2.2.1,4.2.2.2
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - c:\program files\belarc\advisor\system\BAVoilaX.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Name-Space Handler: ftp\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} -
Name-Space Handler: http\GetRightIEClickCatcher - {73BA8F12-723E-11D1-A9E2-00403320FCF2} -
Notify: AtiExtEvent - Ati2evxx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;c:\windows\system32\drivers\SmartDefragDriver.sys [2011-4-7 13496]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2010-10-24 165264]
R2 HPFECP15;HPFECP15;c:\windows\system32\drivers\HPFecp15.sys [1999-2-16 52800]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2008-3-7 1373480]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-5 135664]
S3 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-18 14336]
S3 lgatbus;LG USB Composite Device driver (WDM);c:\windows\system32\drivers\lgatbus.sys [2007-4-17 43024]
S3 lgatmdm;LG CDMA USB Modem Drivers;c:\windows\system32\drivers\lgatmdm.sys [2007-4-17 77104]
S3 lgatserd;LG CDMA USB Modem Diagnostic Serial Port Drivers (WDM);c:\windows\system32\drivers\lgatserd.sys [2007-4-17 60816]
.
=============== Created Last 30 ================
.
2011-04-30 14:35:56 7071056 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2011-04-30 14:35:34 7071056 ----a-w- c:\docume~1\alluse~1\applic~1\microsoft\microsoft antimalware\definition updates\{64b81509-fdf8-4fe9-8bfc-714292c3896c}\mpengine.dll
2011-04-30 04:48:33 -------- d-sha-r- C:\cmdcons
2011-04-29 04:14:08 2476 ----a-w- C:\regbak.reg
2011-04-28 04:17:33 -------- d-----w- c:\program files\ESET
2011-04-28 02:43:36 98816 ----a-w- c:\windows\sed.exe
2011-04-28 02:43:36 89088 ----a-w- c:\windows\MBR.exe
2011-04-28 02:43:36 256512 ----a-w- c:\windows\PEV.exe
2011-04-28 02:43:36 161792 ----a-w- c:\windows\SWREG.exe
2011-04-27 01:23:56 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-04-27 01:23:56 -------- d-----w- c:\windows\system32\wbem\Repository
2011-04-27 01:22:04 -------- d-----w- c:\docume~1\morris\locals~1\applic~1\{7CBA73E9-288D-47ED-8FD7-A2540E3C5FAC}
2011-04-27 01:22:04 -------- d-----w- c:\docume~1\morris\applic~1\Huuziz
2011-04-27 01:22:04 -------- d-----w- c:\docume~1\morris\applic~1\2874392D513E59CB58D1165949F560A5
2011-04-27 01:19:18 -------- d--h--w- c:\windows\ie8
2011-04-26 23:39:44 -------- dc----w- c:\windows\ie8(2)
2011-04-26 06:47:41 -------- d-----w- c:\windows\system32\CatRoot2
2011-04-25 15:09:55 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-25 14:54:09 106496 --sha-r- c:\windows\system32\winmineq.dll
2011-04-25 14:49:24 -------- d-----w- c:\docume~1\morris\applic~1\TeamViewer
2011-04-25 05:34:47 -------- d-----w- c:\windows\ERDNT -registry backup 04252011
2011-04-24 02:58:10 -------- d-----w- c:\program files\Microsoft Security Client
2011-04-24 02:11:05 -------- d-----w- c:\program files\Microsoft Easy Assist
2011-04-24 02:09:59 -------- d-----w- c:\docume~1\alluse~1\applic~1\Applications
2011-04-23 06:04:59 -------- d-----w- c:\program files\AVG
2011-04-22 06:29:33 -------- d-----w- c:\program files\common files\ParetoLogic
2011-04-22 06:29:33 -------- d-----w- c:\docume~1\morris\applic~1\ParetoLogic
2011-04-22 06:29:33 -------- d-----w- c:\docume~1\alluse~1\applic~1\ParetoLogic
2011-04-22 06:28:46 -------- d-----w- c:\docume~1\alluse~1\applic~1\PC Tools
2011-04-22 06:15:57 -------- d-----w- c:\docume~1\morris\applic~1\DriverCure
2011-04-22 05:51:27 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-21 08:06:13 -------- d-----w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2011-04-17 06:20:35 -------- d-----w- c:\docume~1\morris\locals~1\applic~1\PackageAware
2011-04-15 22:52:58 -------- d-----w- c:\docume~1\morris\applic~1\Umxye
2011-04-07 04:40:15 -------- d-----w- c:\docume~1\morris\applic~1\IObit
2011-04-07 04:40:02 29520 ----a-w- c:\windows\system32\SmartDefragBootTime.exe
2011-04-07 04:40:02 13496 ----a-w- c:\windows\system32\drivers\SmartDefragDriver.sys
2011-04-07 04:39:57 -------- d-----w- c:\program files\IObit
2011-04-04 02:32:31 -------- d-----w- c:\program files\NirSoft
.
==================== Find3M ====================
.
2011-04-24 04:14:23 2828 --sha-w- c:\windows\system32\KGyGaAvL.sys
2011-04-10 04:11:26 256 ----a-w- c:\windows\system32\pool.bin
2011-03-07 05:33:50 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-03-04 06:37:06 420864 ----a-w- c:\windows\system32\vbscript.dll
2011-03-03 13:21:11 1857920 ----a-w- c:\windows\system32\win32k.sys
2011-02-22 23:06:29 916480 ----a-w- c:\windows\system32\wininet.dll
2011-02-22 23:06:29 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-02-22 23:06:29 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-02-17 12:32:12 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2011-02-15 12:56:39 290432 ----a-w- c:\windows\system32\atmfd.dll
2011-02-11 13:25:52 229888 ----a-w- c:\windows\system32\fxscover.exe
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-08 13:33:55 978944 ----a-w- c:\windows\system32\mfc42.dll
2011-02-08 13:33:55 974848 ----a-w- c:\windows\system32\mfc42u.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD400BB-75CAA0 rev.16.06V16 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys iomdisk.sys hal.dll >>UNKNOWN [0x8ACE54E7]<<
c:\windows\system32\drivers\iomdisk.sys Iomega Corporation Microsoft(R) Windows NT(R) Operating System
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8aceb7d0]; MOV EAX, [0x8aceb84c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8AD89AB8]
3 CLASSPNP[0xF7647FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x8AD8CB08]
5 iomdisk[0xF7717BC3] -> nt!IofCallDriver[0x804E37D5] -> [0x8AD6AD98]
\Driver\atapi[0x8AD9DB08] -> IRP_MJ_CREATE -> 0x8ACE54E7
error: Read A device attached to the system is not functioning.
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
detected hooks:
\Driver\atapi DriverStartIo -> 0x8ACE5332
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 18:14:17.25 ===============
Here's the DDS file: