Jump to content

Help with system error


shaxta

Recommended Posts

Hi, i need help with this issue im having im having.

I have installed Malaware bytes and ran a scan, once it finished it deleted a bunch of files that were infected.

Now iam having a pop up system error saying that a miner.dll program is missing and i must install it now to fix the problem. It pops up every 5 minutes.

 

I went through a few different other topics with the same problem and downloaded DDS and ran it, saved the two notepads to my desktop and ill post the DDS.txt in this topic and ill attach the Attach.txt to this as well.

DDS.txt contents:

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 10.0.9200.16660  BrowserJavaVersion: 10.25.2
Run by Calum at 18:06:51 on 2013-08-17
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.16375.13889 [GMT 9.5:30]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Windows\system32\taskhost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\SysWOW64\PnkBstrA.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\sppsvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Users\Calum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Usbsupply.exe
C:\Users\Calum\AppData\Local\Temp\RarSFX1\Cloudll.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
 
 
 
 
mWinlogon: Userinit = userinit.exe,
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
TB: <No Name>: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - <no file>
uRun: [GameTracker] C:\Program Files (x86)\GameTracker\GTLite.exe
uRun: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
uRun: [steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
uRun: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
uRun: [skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [EADM] "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
mRun: [VirtualCloneDrive] "C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [sunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
StartupFolder: C:\Users\Calum\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Adobe.lnk - C:\Users\Calum\AppData\Roaming\data\Adobe.vbs
StartupFolder: C:\Users\Calum\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\CLOUDL~1.LNK - C:\Users\Calum\AppData\Local\Temp\RarSFX1\Cloudll.exe
StartupFolder: C:\Users\Calum\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\OPENOF~1.LNK - C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
StartupFolder: C:\Users\Calum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Usbsupply.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\UPDATE~1.LNK - C:\Program Files (x86)\ESET\MiNODLogin\launcher.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:0
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableLUA = dword:0
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: NameServer = 10.0.0.138
TCP: Interfaces\{B8A342E0-651B-4194-BDA9-3F12AF7F73CF} : DHCPNameServer = 10.0.0.138
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype add-on for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
x64-TB: <No Name>: {ae07101b-46d4-4a98-af68-0333ea26e113} - LocalServer32 - <no file>
x64-Run: [CL2 Launcher] C:\Program Files (x86)\City Life RPG\CL2 Launcher\CL2Launcher.exe
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-17 418376]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-17 701512]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2013-7-12 3289472]
R2 StarWindServiceAE;StarWind AE Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [2009-12-24 370688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2013-3-14 383264]
R2 TeamViewer8;TeamViewer 8;C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe [2013-8-11 4308320]
R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2013-8-17 25928]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2009-6-11 187392]
R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\System32\drivers\ScreamingBAudio64.sys [2010-7-1 38992]
S2 AxAutoMntSrv;Alcohol Virtual Drive Auto-mount Service;C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [2012-1-6 75624]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-6-21 162408]
S3 BEService;BattlEye Service;C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2013-5-11 49152]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2013-8-10 57840]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2013-2-5 1512448]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2013-5-16 19456]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2013-5-16 57856]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2013-5-16 30208]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 VaneFltr;Lachesis Mouse Driver;C:\Windows\System32\drivers\Lachesis.sys [2007-8-17 30336]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2013-5-9 1255736]
S3 WinRing0_1_2_0;WinRing0_1_2_0;C:\Program Files (x86)\Razer\Razer Game Booster\Driver\WinRing0x64.sys [2013-8-16 14544]
.
=============== Created Last 30 ================
.
2013-08-17 07:41:42 -------- d-----w- C:\Users\Calum\AppData\Roaming\data
2013-08-17 06:12:36 -------- d-----w- C:\Users\Calum\AppData\Roaming\Malwarebytes
2013-08-17 06:12:32 25928 ----a-w- C:\Windows\System32\drivers\mbam.sys
2013-08-17 06:12:32 -------- d-----w- C:\ProgramData\Malwarebytes
2013-08-17 06:12:32 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-16 16:54:49 -------- d-----w- C:\Program Files (x86)\ESET
2013-08-16 16:51:37 -------- d-----w- C:\Users\Calum\AppData\Local\ESET
2013-08-16 16:35:35 -------- d-sh--r- C:\Users\Calum\AppData\Roaming\-467460987
2013-08-16 13:44:25 -------- d-----w- C:\Program Files (x86)\RAR Password Unlocker
2013-08-16 11:50:15 -------- d-----w- C:\Users\Calum\AppData\Local\Origin
2013-08-16 11:34:31 -------- d-----w- C:\ProgramData\Electronic Arts
2013-08-16 11:34:30 -------- d-----w- C:\Program Files (x86)\Origin
2013-08-16 11:19:59 -------- d-----w- C:\Users\Calum\AppData\Local\Razer
2013-08-14 03:25:32 1472512 ----a-w- C:\Windows\System32\crypt32.dll
2013-08-11 10:21:09 -------- d-----w- C:\Program Files (x86)\TeamViewer
2013-08-11 09:38:03 9460976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{AA71D0FD-1225-4649-A713-5ABD9E7F267B}\mpengine.dll
2013-08-10 13:59:38 737072 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\SportsV2\SportsTemplateCore\Microsoft.MediaCenter.Sports.UI.dll
2013-08-10 13:54:57 -------- d-----w- C:\Users\Calum\Tracing
2013-08-10 13:53:31 -------- d-----w- C:\Windows\en
2013-08-10 13:52:55 -------- d-----w- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2013-08-10 13:52:04 57840 ----a-w- C:\Windows\System32\drivers\fssfltr.sys
2013-08-10 13:51:36 -------- d-----w- C:\Windows\PCHEALTH
2013-08-10 13:49:06 2876528 ----a-w- C:\ProgramData\Microsoft\eHome\Packages\MCEClientUX\UpdateableMarkup\markup.dll
2013-08-10 13:47:58 -------- d-----w- C:\Users\Calum\AppData\Local\Windows Live
2013-08-10 13:47:53 -------- d-----w- C:\Program Files (x86)\Common Files\Windows Live
2013-08-09 15:41:10 298584 ----a-w- C:\Windows\SysWow64\PnkBstrB.xtr
2013-08-09 15:41:05 -------- d-----w- C:\Users\Calum\AppData\Local\PunkBuster
2013-08-09 15:39:46 298584 ----a-w- C:\Windows\SysWow64\PnkBstrB.exe
2013-08-09 15:39:46 298584 ----a-w- C:\Windows\SysWow64\PnkBstrB.ex0
2013-08-09 15:39:42 76888 ----a-w- C:\Windows\SysWow64\PnkBstrA.exe
2013-08-09 15:04:40 1837683 ----a-w- C:\Users\Calum\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Usbsupply.exe
2013-08-09 14:52:32 -------- d-----w- C:\Ubisoft
2013-08-09 05:01:56 804384 ----a-w- C:\Windows\SysWow64\fmodex.dll
2013-08-09 05:01:56 312864 ----a-w- C:\Windows\SysWow64\fmod_event.dll
2013-08-08 14:19:08 -------- d-----w- C:\Users\Calum\AppData\Local\WarThunder
2013-08-08 14:19:08 -------- d-----w- C:\ProgramData\WarThunder
2013-08-08 14:18:59 -------- d-----w- C:\Program Files (x86)\WarThunder
2013-08-05 13:02:09 -------- d-----w- C:\Users\Calum\AppData\Local\PAYDAY 2
2013-08-04 03:55:25 -------- d-----w- C:\Program Files\Ventrilo
2013-08-04 03:54:53 -------- d-----w- C:\Program Files (x86)\Common Files\Wise Installation Wizard
2013-08-03 14:32:38 -------- d-----w- C:\Users\Calum\AppData\Local\ArmaAddonSync2009
2013-08-03 14:32:37 -------- d-----w- C:\Users\Calum\AppData\Local\Yoma_Tools
2013-08-03 11:12:56 -------- d-----w- C:\Fraps
2013-08-01 16:52:58 -------- d-----w- C:\Users\Calum\AppData\Roaming\SpinTires
2013-07-31 07:26:19 -------- d-----w- C:\Users\Calum\AppData\Roaming\.minecraft
2013-07-29 08:55:13 -------- d-----w- C:\Program Files (x86)\Call of Juarez Gunslinger
2013-07-28 08:29:41 -------- d-----w- C:\Users\Calum\AppData\Roaming\Origin
2013-07-28 08:29:15 -------- d-----w- C:\ProgramData\Origin
2013-07-25 09:03:30 -------- d-----w- C:\Windows\System32\MRT
2013-07-25 07:37:12 -------- d-----w- C:\Program Files\Common Files\EasyInfo
2013-07-25 07:31:41 75472 ----a-w- C:\Windows\DSETUP.dll
2013-07-25 07:31:41 2245840 ----a-w- C:\Windows\dsetup32.dll
2013-07-19 05:47:53 -------- d-----w- C:\Users\Calum\AppData\Local\4A Games
2013-07-19 05:29:55 -------- d-----w- C:\Program Files (x86)\Metro Last Light
2013-07-18 12:23:49 -------- d-----w- C:\Users\Calum\jagexcache
2013-07-18 12:22:50 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
.
==================== Find3M  ====================
.
2013-07-26 05:13:37 2241024 ----a-w- C:\Windows\System32\wininet.dll
2013-07-26 05:12:08 3958784 ----a-w- C:\Windows\System32\jscript9.dll
2013-07-26 05:12:04 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2013-07-26 05:12:03 67072 ----a-w- C:\Windows\System32\iesetup.dll
2013-07-26 03:35:08 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2013-07-26 03:13:24 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2013-07-26 03:12:04 2877440 ----a-w- C:\Windows\SysWow64\jscript9.dll
2013-07-26 03:12:00 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2013-07-26 03:12:00 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2013-07-26 02:49:14 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2013-07-26 02:39:38 89600 ----a-w- C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-26 01:59:38 71680 ----a-w- C:\Windows\SysWow64\RegisterIEPKEYs.exe
2013-07-25 09:25:54 1888768 ----a-w- C:\Windows\System32\WMVDECOD.DLL
2013-07-25 08:57:27 1620992 ----a-w- C:\Windows\SysWow64\WMVDECOD.DLL
2013-07-19 01:58:42 2048 ----a-w- C:\Windows\System32\tzres.dll
2013-07-19 01:41:01 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2013-07-18 12:22:47 867240 ----a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-07-18 12:22:47 789416 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2013-07-09 06:03:30 5550528 ----a-w- C:\Windows\System32\ntoskrnl.exe
2013-07-09 05:54:22 1732032 ----a-w- C:\Windows\System32\ntdll.dll
2013-07-09 05:53:12 243712 ----a-w- C:\Windows\System32\wow64.dll
2013-07-09 05:52:52 224256 ----a-w- C:\Windows\System32\wintrust.dll
2013-07-09 05:51:16 1217024 ----a-w- C:\Windows\System32\rpcrt4.dll
2013-07-09 05:46:20 184320 ----a-w- C:\Windows\System32\cryptsvc.dll
2013-07-09 05:46:20 139776 ----a-w- C:\Windows\System32\cryptnet.dll
2013-07-09 05:03:34 3968960 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-07-09 05:03:34 3913664 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-07-09 04:53:47 1292192 ----a-w- C:\Windows\SysWow64\ntdll.dll
2013-07-09 04:52:33 663552 ----a-w- C:\Windows\SysWow64\rpcrt4.dll
2013-07-09 04:52:33 5120 ----a-w- C:\Windows\SysWow64\wow32.dll
2013-07-09 04:52:10 175104 ----a-w- C:\Windows\SysWow64\wintrust.dll
2013-07-09 04:46:31 140288 ----a-w- C:\Windows\SysWow64\cryptsvc.dll
2013-07-09 04:46:31 1166848 ----a-w- C:\Windows\SysWow64\crypt32.dll
2013-07-09 04:46:31 103936 ----a-w- C:\Windows\SysWow64\cryptnet.dll
2013-07-09 04:45:07 44032 ----a-w- C:\Windows\apppatch\acwow64.dll
2013-07-09 02:49:42 25600 ----a-w- C:\Windows\SysWow64\setup16.exe
2013-07-09 02:49:41 7680 ----a-w- C:\Windows\SysWow64\instnm.exe
2013-07-09 02:49:39 14336 ----a-w- C:\Windows\SysWow64\ntvdm64.dll
2013-07-09 02:49:38 2048 ----a-w- C:\Windows\SysWow64\user.exe
2013-07-06 06:03:53 1910208 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2013-06-15 04:32:16 39936 ----a-w- C:\Windows\System32\drivers\tssecsrv.sys
2013-06-08 18:36:01 108448 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2013-06-08 18:36:00 971680 ----a-w- C:\Windows\System32\deployJava1.dll
2013-06-08 18:36:00 1092512 ----a-w- C:\Windows\System32\npDeployJava1.dll
2013-06-05 03:34:27 3153920 ----a-w- C:\Windows\System32\win32k.sys
2013-06-04 17:32:36 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-06-04 06:00:13 624128 ----a-w- C:\Windows\System32\qedit.dll
2013-06-04 04:53:07 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2013-05-31 00:45:08 43680 ----a-w- C:\Windows\System32\drivers\lirsgt.sys
2013-05-31 00:45:08 314016 ----a-w- C:\Windows\System32\drivers\atksgt.sys
2013-05-19 15:34:18 564824 ----a-w- C:\Windows\System32\drivers\sptd.sys
.
============= FINISH: 18:07:13.03 ===============
 

 

 

 

 

In addition i downloaded the gmer program, scanned and saved the ark.txt file which i will include the contents of that under this:

 

Ark.txt contents:

 

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-08-17 18:20:31
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 ST3500413AS rev.JC45 465.76GB
Running: yedzfvjx.exe; Driver: C:\Users\Calum\AppData\Local\Temp\agloqpog.sys
 
 
---- Devices - GMER 2.1 ----
 
Device  \Driver\atapi \Device\Ide\IdePort4                                                                                                           fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdePort0                                                                                                           fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdePort5                                                                                                           fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdePort1                                                                                                           fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdeDeviceP3T0L0-4                                                                                                  fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdePort2                                                                                                           fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-3                                                                                                  fffffa800ca4f2c0
Device  \Driver\atapi \Device\Ide\IdePort3                                                                                                           fffffa800ca4f2c0
Device  \Driver\akslu0n3 \Device\Scsi\akslu0n31                                                                                                      fffffa800e3c22c0
Device  \Driver\akslu0n3 \Device\Scsi\akslu0n31Port7Path0Target0Lun0                                                                                 fffffa800e3c22c0
Device  \Driver\VClone \Device\Scsi\VClone1                                                                                                          fffffa800e4442c0
Device  \Driver\VClone \Device\Scsi\VClone1Port6Path0Target0Lun0                                                                                     fffffa800e4442c0
Device  \FileSystem\Ntfs \Ntfs                                                                                                                       fffffa800d3872c0
Device  \Driver\NetBT \Device\NetBT_Tcpip_{B8A342E0-651B-4194-BDA9-3F12AF7F73CF}                                                                     fffffa800e0882c0
Device  \Driver\USBSTOR \Device\0000007e                                                                                                             fffffa800ebe32c0
Device  \Driver\akslu0n3 \Device\ScsiPort7                                                                                                           fffffa800e3c22c0
Device  \Driver\usbehci \Device\USBPDO-1                                                                                                             fffffa800e3532c0
Device  \Driver\cdrom \Device\CdRom0                                                                                                                 fffffa800e05b2c0
Device  \Driver\cdrom \Device\CdRom1                                                                                                                 fffffa800e05b2c0
Device  \Driver\cdrom \Device\CdRom2                                                                                                                 fffffa800e05b2c0
Device  \Driver\usbehci \Device\USBFDO-0                                                                                                             fffffa800e3532c0
Device  \Driver\USBSTOR \Device\0000007c                                                                                                             fffffa800ebe32c0
Device  \Driver\usbehci \Device\USBFDO-1                                                                                                             fffffa800e3532c0
Device  \Driver\NetBT \Device\NetBt_Wins_Export                                                                                                      fffffa800e0882c0
Device  \Driver\atapi \Device\ScsiPort0                                                                                                              fffffa800ca4f2c0
Device  \Driver\usbehci \Device\USBPDO-0                                                                                                             fffffa800e3532c0
Device  \Driver\atapi \Device\ScsiPort1                                                                                                              fffffa800ca4f2c0
Device  \Driver\atapi \Device\ScsiPort2                                                                                                              fffffa800ca4f2c0
Device  \Driver\atapi \Device\ScsiPort3                                                                                                              fffffa800ca4f2c0
Device  \Driver\atapi \Device\ScsiPort4                                                                                                              fffffa800ca4f2c0
Device  \Driver\atapi \Device\ScsiPort5                                                                                                              fffffa800ca4f2c0
Device  \Driver\VClone \Device\ScsiPort6                                                                                                             fffffa800e4442c0
 
---- Trace I/O - GMER 2.1 ----
 
Trace   ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys >>UNKNOWN [0xfffffa800ca4f2c0]<< sptd.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys   fffffa800ca4f2c0
Trace   1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800dbee060]                                                                              fffffa800dbee060
Trace   3 CLASSPNP.SYS[fffff8800120143f] -> nt!IofCallDriver -> [0xfffffa800d867580]                                                                 fffffa800d867580
Trace   5 ACPI.sys[fffff8800100b7a1] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0xfffffa800d868060]                                        fffffa800d868060
Trace   \Driver\atapi[0xfffffa800d82dcb0] -> IRP_MJ_CREATE -> 0xfffffa800ca4f2c0                                                                     fffffa800ca4f2c0
 
---- Modules - GMER 2.1 ----
 
Module  \SystemRoot\System32\Drivers\akslu0n3.SYS                                                                                                    fffff8800539c000-fffff880053e8000 (311296 bytes)
 
---- Threads - GMER 2.1 ----
 
Thread  C:\Program Files\Windows Media Player\wmpnetwk.exe [4772:4388]                                                                               000007fefbc72a7c
Thread  C:\Windows\System32\svchost.exe [4016:3816]                                                                                                  000007feed399688
 
---- Registry - GMER 2.1 ----
 
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                                             
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                          C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                          0
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                       0x28 0xB8 0x7C 0xF1 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                                                    
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                 0xA0 0x02 0x00 0x00 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                              0x6B 0xC1 0x39 0x98 ...
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                                             
Reg     HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                       0x35 0x35 0xEA 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                                         
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                                              C:\Program Files (x86)\Alcohol Soft\Alcohol 120\
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                                              0
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                                           0x28 0xB8 0x7C 0xF1 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)                                
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                                                     0xA0 0x02 0x00 0x00 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                                                  0x6B 0xC1 0x39 0x98 ...
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)                         
Reg     HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                                           0x35 0x35 0xEA 0x00 ...
 
---- EOF - GMER 2.1 ----
 

attach.txt

Link to post
Share on other sites

Hi, Shaxta: :)

 

Welcome!

 

OOPS!

 

It appears that you already have created 2 additional, identical topics in the malware removal section?

http://forums.malwarebytes.org/index.php?showtopic=131229

http://forums.malwarebytes.org/index.php?showtopic=131230

 

Please do not create any more duplicate topics, especially in multiple sections of the forum, for the same issue.

(That is considered "cross-posting" and is a forum etiquette "no-no". :( Doing so wastes precious forum resources and creates confusion. )

 

The mod team will soon remove 1 of the 2 duplicates in the malware removal section.

Please be patient and stay with the one, original topic there until a malware helper picks it up to help you.

 

Thanks very much for your patience and understanding,

 

daledoc1

Link to post
Share on other sites

Indeed.

That does happen from time to time. :)

 

However, there is no need to "cross-post" in multiple sections of the forum (e.g. malware removal and PC Help) for the same problem.

 

In any event, it appears that Maniac has just replied to you in this post: http://forums.malwarebytes.org/index.php?showtopic=131230

So, please stay with him there until he gives you the "all clear".

 

The mods will take care of deleting the duplicate and closing this one (to prevent others from posting in them). ;)

 

Thanks!

 

daledoc1

Link to post
Share on other sites

the OP is more than welcome to "hang out" with the rest of us crazies ... err ... ummm ... *ahem* members in this section .

:lol:

 

Yes, of course.

And Maniac may -- indeed -- refer shaxta back here for NON-MALWARE issues, after he is cleaned up.

 

I was only pointing out that the OP had created 3 identical posts for the same issue in 2 different sections of the forum.

 

Cheers!

 

daledoc1

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.