Confuzzed Posted May 17, 2010 ID:251546 Share Posted May 17, 2010 I think I did it, almost. I had a few virus' and at one time a backdoor.bot, went throught the self help section to work it out. I think I got it. The computer is scanning clean (although it too a number of days). Both the disk.sys and atapi.sys were infected. About the only problem I still seem to have is the computer does not want to close outlook completely and is having problems shutting down from the Start Menu.Any thoughts would be appreciated.DDS (Ver_10-03-17.01) - NTFSx86 Run by Lawson at 11:31:56.64 on Mon 05/17/2010Internet Explorer: 8.0.6001.18702Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3582.2794 [GMT -7:00]AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}============== Running Processes ===============C:\WINDOWS\system32\svchost -k DcomLaunchsvchost.exec:\Program Files\Microsoft Security Essentials\MsMpEng.exeC:\WINDOWS\System32\svchost.exe -k netsvcsC:\Program Files\WTouch\WTouchService.exesvchost.exesvchost.exeC:\WINDOWS\System32\iscsiexe.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\WTouch\WTouchUser.exesvchost.exeC:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exeC:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Drobo\Drobo Dashboard\Support\DDService.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\Program Files\NDAS\System\ndassvc.exeC:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exeC:\WINDOWS\system32\svchost.exe -k imgsvcC:\WINDOWS\system32\Pen_Tablet.exeC:\Program Files\Live Mesh\Remote Desktop\wlcrasvc.exeC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXEC:\WINDOWS\system32\wuauclt.exeC:\WINDOWS\system32\WTablet\Pen_TabletUser.exeC:\WINDOWS\system32\Pen_Tablet.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exeC:\WINDOWS\system32\taskswitch.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Microsoft Security Essentials\msseces.exeC:\Program Files\Microsoft ActiveSync\wcescomm.exeC:\Program Files\Internet Download Manager\IDMan.exeC:\Documents and Settings\Lawson\Local Settings\Application Data\Microsoft\Live Mesh\Bin\Servicing\0.9.4014.7\MoeMonitor.exeC:\Program Files\Skype\Phone\Skype.exeC:\WINDOWS\system32\ctfmon.exeC:\PROGRA~1\MICROS~3\rapimgr.exeC:\Program Files\Drobo\Drobo Dashboard\DroboDashboard.exeC:\Program Files\Google\Google Calendar Sync\GoogleCalendarSync.exeC:\Program Files\Logitech\SetPoint\SetPoint.exeC:\Program Files\NDAS\System\ndasmgmt.exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeC:\Documents and Settings\Lawson\Local Settings\Application Data\Microsoft\Live Mesh\GacBase\Moe.exeC:\Program Files\PFU\ScanSnap\Driver\PfuSsMon.exeC:\Program Files\Southwest Airlines\Ding\Ding.exeC:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exeC:\Program Files\Internet Download Manager\IEMonitor.exeC:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXEC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Skype\Plugin Manager\skypePM.exeC:\Documents and Settings\Lawson\Desktop\Temp1\dds.EXE============== Pseudo HJT Report ===============uStart Page = about:blankuInternet Settings,ProxyOverride = *.localBHO: IDMIEHlprObj Class: {0055c089-8582-441b-a0bf-17b458c2a3a8} - c:\program files\internet download manager\IDMIECC.dllBHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dllBHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dllBHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dllBHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dllBHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dllBHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dllBHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllTB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dlluRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe"uRun: [iDMan] c:\program files\internet download manager\IDMan.exe /onbootuRun: [MoeMonitor.exe] "c:\documents and settings\lawson\local settings\application data\microsoft\live mesh\bin\servicing\0.9.4014.7\MoeMonitor.exe"uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimizeduRun: [ctfmon.exe] c:\windows\system32\ctfmon.exemRun: [RTHDCPL] RTHDCPL.EXEmRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"mRun: [CoolSwitch] c:\windows\system32\taskswitch.exemRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXEmRun: [sunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottimemRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkeyStartupFolder: c:\docume~1\lawson\startm~1\programs\startup\ding!.lnk - c:\program files\southwest airlines\ding\Ding.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\conver~1.lnk - c:\program files\pfu\scansnap\organizer\PfuSsOrgOcrChk.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\drobod~1.lnk - c:\program files\drobo\drobo dashboard\DroboDashboard.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\google~1.lnk - c:\program files\google\google calendar sync\GoogleCalendarSync.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ndasde~1.lnk - c:\program files\ndas\system\ndasmgmt.exeStartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\scansn~1.lnk - c:\program files\pfu\scansnap\driver\PfuSsMon.exeIE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.htmlIE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlIE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlIE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.htmlIE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlIE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.htmlIE: Download all links with IDM - c:\program files\internet download manager\IEGetAll.htmIE: Download FLV video content with IDM - c:\program files\internet download manager\IEGetVL.htmIE: Download with IDM - c:\program files\internet download manager\IEExt.htmIE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exeIE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exeIE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dllIE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~3\INetRepl.dllIE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLLDPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1238108135196DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1238176636093DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cabDPF: {A3E21079-7F41-4125-9EBB-FD44CFCC0AC1} - hxxps://www.mesh.com/0.9.4014.28/TSWeb.cabDPF: {AEF76437-F960-4EBC-97EA-7BBB4230CF38} - hxxps://oca.microsoft.com/en/secure/ocarpt.CABDPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cabDPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabDPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://linksyssupport.webex.com/client/T26L10NSP49EP32-linksyssupport/support/ieatgpc.cabHandler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dllHandler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLLNotify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dllNotify: wlcrdplauncher - c:\program files\live mesh\remote desktop\wlcrdplauncher.dllSSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll============= SERVICES / DRIVERS ===============R0 lfsfilt;NDAS Lean File Sharing Service;c:\windows\system32\drivers\lfsfilt.sys [2009-2-7 274920]R0 lpx;LPX Protocol;c:\windows\system32\drivers\lpx.sys [2009-2-7 100840]R0 ndasfs;ndasfs;c:\windows\system32\drivers\ndasfs.sys [2009-2-7 285160]R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040]R1 ndasfat;NDAS FAT File System Service;c:\windows\system32\drivers\ndasfat.sys [2009-2-7 416232]R1 ndasrofs;NDAS ROFS File System Service;c:\windows\system32\drivers\ndasrofs.sys [2009-2-7 783848]R2 DDService;Drobo Dashboard Service;c:\program files\drobo\drobo dashboard\support\DDService.exe [2010-3-19 704512]R2 MSiSCSI;Microsoft iSCSI Initiator Service;c:\windows\system32\iscsiexe.exe [2008-11-13 103480]R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2010-2-18 4408616]R2 wlcrasvc;Live Mesh Remote Desktop;c:\program files\live mesh\remote desktop\wlcrasvc.exe [2010-2-17 44880]R2 WTouchService;WTouch Service;c:\program files\wtouch\WTouchService.exe [2010-2-18 112936]R3 iScsiPrt;iScsiPort Driver;c:\windows\system32\drivers\msiscsi.sys [2008-11-13 158264]R3 ndasbus;NDAS Bus Driver;c:\windows\system32\drivers\ndasbus.sys [2009-2-7 121320]R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2009-3-26 39456]R3 RDPDISPM;RDPDISPM;c:\windows\system32\drivers\rdpdispm.sys [2010-2-17 9040]R3 RDPVDD;RDPVDD;c:\windows\system32\drivers\rdpvmp.sys [2010-2-17 19408]R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\drivers\wacmoumonitor.sys [2010-2-18 15656]S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-16 133104]S3 ndasscsi;NDAS SCSI Miniport Driver;c:\windows\system32\drivers\ndasscsi.sys [2009-2-7 276968]S3 TVService;TVService;c:\program files\team mediaportal\mediaportal tv server\TvService.exe [2009-5-8 192512]============== File Associations ===============.scr=DWGTrueViewScriptFile=============== Created Last 30 ================2010-05-15 00:23:13 0 ----a-w- c:\documents and settings\lawson\defogger_reenable2010-05-14 23:22:41 0 d-----w- c:\program files\Runtime Software2010-05-14 21:58:49 36352 -c--a-w- c:\windows\system32\dllcache\disk.sys2010-05-14 21:58:49 36352 ----a-w- c:\windows\system32\drivers\disk.sys2010-05-14 21:55:46 98816 ----a-w- c:\windows\sed.exe2010-05-14 21:55:46 77312 ----a-w- c:\windows\MBR.exe2010-05-14 21:55:46 256512 ----a-w- c:\windows\PEV.exe2010-05-14 21:55:46 161792 ----a-w- c:\windows\SWREG.exe2010-05-14 21:15:48 0 d-sha-r- C:\cmdcons2010-05-14 21:15:46 0 d-----w- c:\windows\setup.pss2010-05-14 21:15:36 0 d-----w- c:\windows\setupupd2010-05-14 16:25:21 3245 ----a-w- c:\windows\system32\wbem\Outlook_01caf3820c855766.mof2010-05-14 02:49:39 0 d-----w- c:\windows\system32\wbem\Repository2010-05-14 01:16:18 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys2010-05-14 01:16:18 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys2010-05-14 01:15:52 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys2010-05-14 01:15:52 8192 ----a-w- c:\windows\system32\drivers\changer.sys2010-05-13 16:36:47 221568 ------w- c:\windows\system32\MpSigStub.exe2010-05-13 16:33:15 0 d-----w- c:\program files\Microsoft Security Essentials2010-05-13 16:27:50 0 d-----w- C:\60d349ba54d46634af2010-05-13 00:50:07 0 d-----w- c:\docume~1\lawson\applic~1\Malwarebytes2010-05-13 00:49:59 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2010-05-13 00:49:58 20952 ----a-w- c:\windows\system32\drivers\mbam.sys2010-05-13 00:49:58 0 d-----w- c:\program files\Malwarebytes' Anti-Malware2010-05-13 00:49:58 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes2010-05-12 00:16:02 0 d-----w- c:\program files\Remove Empty Directories2010-05-11 20:06:51 0 d-----w- c:\program files\Microsoft LifeCam2010-05-11 20:06:40 0 d-----w- c:\windows\Logs2010-04-30 16:29:05 0 d-----w- c:\program files\iPod2010-04-30 16:29:01 0 d-----w- c:\program files\iTunes2010-04-30 16:25:48 0 d-----w- c:\program files\Bonjour2010-04-27 13:30:30 210352 ----a-w- c:\windows\system32\idmmbc.dll==================== Find3M ====================2010-05-14 21:45:46 96512 ----a-w- c:\windows\system32\drivers\atapi.sys2010-04-08 20:20:02 91424 ----a-w- c:\windows\system32\dnssd.dll2010-04-08 20:20:02 107808 ----a-w- c:\windows\system32\dns-sd.exe2010-03-25 22:19:28 74756 ---ha-w- c:\windows\system32\mlfcache.dat2010-03-15 23:02:39 137195 ----a-w- c:\windows\fonts\AdobeFnt08.lst2010-03-10 06:15:52 420352 ----a-w- c:\windows\system32\vbscript.dll2010-02-25 06:24:37 916480 ----a-w- c:\windows\system32\wininet.dll2010-02-17 23:34:07 15696 ----a-w- c:\windows\system32\rdpvdd.dll2010-02-17 23:34:07 118736 ----a-w- c:\windows\system32\rdpdispd.dll2009-10-21 01:21:18 245760 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat============= FINISH: 11:32:13.71 ===============Attach.zip Link to post Share on other sites More sharing options...
Staff screen317 Posted May 18, 2010 Staff ID:252181 Share Posted May 18, 2010 Hi and welcome to Malwarebytes.Please update MBAM, run a Quick Scan, and post its log.Next, please visit this webpage for instructions for running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofixWhen the tool is finished, it will produce a report for you.Please post the C:\ComboFix.txt along with a new DDS log so we may continue cleaning the system.-screen317 Link to post Share on other sites More sharing options...
Confuzzed Posted May 19, 2010 Author ID:252582 Share Posted May 19, 2010 The MBAM comes up clean and I have previously run the Combofix. Also the MS Security Essentials comes up clean. About the only thing left to turn on the CDROM emulation software using Defogger.The computer now seems to be shutting down ok, it just does not want to boot with a USB drive installed.Thoughts? Link to post Share on other sites More sharing options...
Staff screen317 Posted May 21, 2010 Staff ID:253417 Share Posted May 21, 2010 Thoughts?It would be worth scanning again with a fresh copy of ComboFix so that I can see its log. Link to post Share on other sites More sharing options...
Staff screen317 Posted June 2, 2010 Staff ID:260428 Share Posted June 2, 2010 Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts