Jump to content

Need Help in removing an infection


Recommended Posts

I got infected with "AV Security Suite" two days ago or so, I tried everything, malwarebytes, my antivirus and managed to remove most of the virus. But now some of the infection is still left on my computer and I keep getting this warning through my eset

virus.jpg

Before posting here I tried to do some research and came across a similar problem this guy was having in the following thread

http://forums.malwarebytes.org/index.php?showtopic=52554

I followed the each and every instruction, but somehow the infection is still there and whenever I'm browsing I'm getting that notification from ESET NOD.

--------------------------------------------------------

I decided to open a thread and follow the instructions to start a thread, but everytime i ran GMER Rootkit Scanner it scanned and when I tried saving the log it hung and would crash my windows, i tried several time but had no luck in finishing its scan successfully. I'm pasting my DDS and attaching the other log file.

Thanks.

DDS file.

DDS (Ver_10-03-17.01) - NTFSx86

Run by zee at 21:40:35.75 on Fri 07/09/2010

Internet Explorer: 6.0.2900.2180

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2047.1559 [GMT -5:00]

AV: ESET NOD32 Antivirus 4.0 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}

============== Running Processes ===============

D:\WINDOWS\system32\nvsvc32.exe

D:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

D:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

D:\WINDOWS\system32\spoolsv.exe

D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

D:\Program Files\Bonjour\mDNSResponder.exe

D:\WINDOWS\eHome\ehRecvr.exe

D:\WINDOWS\eHome\ehSched.exe

D:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

D:\WINDOWS\system32\HPZipm12.exe

D:\WINDOWS\system32\PnkBstrA.exe

D:\WINDOWS\system32\PnkBstrB.exe

svchost.exe

D:\WINDOWS\system32\svchost.exe -k imgsvc

D:\WINDOWS\system32\wuauclt.exe

D:\WINDOWS\Explorer.EXE

D:\WINDOWS\system32\dllhost.exe

D:\WINDOWS\ehome\ehtray.exe

D:\WINDOWS\RTHDCPL.EXE

D:\WINDOWS\system32\RUNDLL32.EXE

D:\Program Files\iTunes\iTunesHelper.exe

D:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

D:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

D:\Program Files\Razer\DeathAdder\razerhid.exe

D:\WINDOWS\system32\ctfmon.exe

D:\WINDOWS\eHome\ehmsas.exe

D:\WINDOWS\system32\wscntfy.exe

D:\Program Files\Razer\DeathAdder\razertra.exe

D:\Program Files\iPod\bin\iPodService.exe

D:\Program Files\Razer\DeathAdder\razerofa.exe

D:\Documents and Settings\zee\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uInternet Settings,ProxyOverride = ww.myantispyware.com;myantispyware.com;www.malwarebytes.org;go.trendmicro.com;<local>

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - d:\progra~1\micros~3\office12\GRA8E1~1.DLL

BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - d:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - d:\program files\java\jre6\bin\jp2ssv.dll

uRun: [Messenger (Yahoo!)] "d:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet

uRun: [msnmsgr] "d:\program files\windows live\messenger\msnmsgr.exe" /background

uRun: [beyluxeMessenger] d:\program files\beyluxe messenger\Beyluxe Messenger.exe

uRun: [ctfmon.exe] d:\windows\system32\ctfmon.exe

mRun: [ehTray] d:\windows\ehome\ehtray.exe

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [NvMediaCenter] RUNDLL32.EXE d:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [NvCplDaemon] RUNDLL32.EXE d:\windows\system32\NvCpl.dll,NvStartup

mRun: [QuickTime Task] "d:\program files\quicktime\QTTask.exe" -atboottime

mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"

mRun: [GrooveMonitor] "d:\program files\microsoft office\office12\GrooveMonitor.exe"

mRun: [LogitechQuickCamRibbon] "d:\program files\logitech\quickcam\Quickcam.exe" /hide

mRun: [egui] "d:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice

mRun: [DeathAdder] d:\program files\razer\deathadder\razerhid.exe

StartupFolder: d:\docume~1\zee\startm~1\programs\startup\onenot~1.lnk - d:\program files\microsoft office\office12\ONENOTEM.EXE

StartupFolder: d:\docume~1\zee\startm~1\programs\startup\xfire.lnk - d:\program files\xfire\Xfire.exe

StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\paltalk.lnk - d:\program files\paltalk messenger\paltalk.exe

IE: E&xport to Microsoft Excel - d:\progra~1\micros~3\office12\EXCEL.EXE/3000

IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - d:\program files\paltalk messenger\Paltalk.exe

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - d:\program files\messenger\msmsgs.exe

IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - d:\progra~1\micros~3\office12\ONBttnIE.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - d:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - d:\progra~1\micros~3\office12\REFIEBAR.DLL

DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - d:\progra~1\micros~3\office12\GR99D3~1.DLL

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - d:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - d:\progra~1\common~1\skype\SKYPE4~1.DLL

SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - d:\progra~1\micros~3\office12\GRA8E1~1.DLL

================= FIREFOX ===================

FF - ProfilePath - d:\docume~1\zee\applic~1\mozilla\firefox\profiles\rjb1gu30.default\

FF - prefs.js: browser.startup.homepage - hxxp://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official

FF - prefs.js: network.proxy.type - 0

---- FIREFOX POLICIES ----

FF - user.js: network.protocol-handler.warn-external.dnupdate - falsed:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

d:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);

d:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);

d:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);

d:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

d:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);

d:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);

d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr

ef", true);

d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");

d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);

d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);

d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 ehdrv;ehdrv;d:\windows\system32\drivers\ehdrv.sys [2009-5-14 107256]

R1 epfwtdir;epfwtdir;d:\windows\system32\drivers\epfwtdir.sys [2009-5-14 94360]

R2 ekrn;ESET Service;d:\program files\eset\eset nod32 antivirus\ekrn.exe [2009-5-14 731840]

R2 McrdSvc;Media Center Extender Service;d:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]

R3 cmudaxu;C-Media USB Sound Interface;d:\windows\system32\drivers\cmudaxu.sys [2010-3-14 1391296]

R3 DAdderFltr;DeathAdder Mouse;d:\windows\system32\drivers\dadder.sys [2010-5-10 22784]

R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;d:\windows\system32\drivers\ManyCam.sys [2008-1-14 21632]

R3 vHidDev;Razer Gaming Device;d:\windows\system32\drivers\vHidDev.sys [2010-5-10 5760]

S3 Avgfwdx;Avgfwdx;d:\windows\system32\drivers\avgfwdx.sys [2010-7-8 30104]

S3 Avgfwfd;AVG network filter service;d:\windows\system32\drivers\avgfwdx.sys [2010-7-8 30104]

S3 pbfilter;pbfilter;d:\program files\peerblock\pbfilter.sys [2010-3-14 14424]

=============== Created Last 30 ================

2010-07-10 02:18:11 0 ----a-w- d:\documents and settings\zee\defogger_reenable

2010-07-10 01:39:20 0 d-s---w- D:\Combo-Fix

2010-07-09 02:16:19 50968 ----a-w- d:\windows\system32\avgfwdx.dll

2010-07-09 02:16:19 30104 ----a-w- d:\windows\system32\drivers\avgfwdx.sys

2010-07-09 02:15:17 0 d-----w- d:\program files\AVG

2010-07-09 02:14:41 0 d-----w- d:\windows\SxsCaPendDel

2010-07-09 01:14:32 0 d-----w- d:\program files\Spybot - Search & Destroy

2010-07-09 01:14:32 0 d-----w- d:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

2010-07-08 18:05:35 664 ----a-w- d:\windows\system32\d3d9caps.dat

2010-07-08 09:13:20 0 d-----w- d:\windows\system32\wbem\Repository

2010-07-08 08:50:25 120 ----a-w- d:\windows\Dkeqozoqocef.dat

2010-07-08 08:50:25 0 ----a-w- d:\windows\Nkugutun.bin

2010-07-05 06:09:04 0 d-----w- D:\Hotspot Shield

2010-07-05 06:08:47 0 d-----w- d:\program files\Hotspot Shield

2010-06-18 03:46:31 0 d-----w- d:\program files\CamStudio

2010-06-14 03:19:14 0 d-----w- d:\docume~1\zee\applic~1\Antares

2010-06-14 03:05:41 499712 ----a-w- d:\windows\system32\MSVCP71.DLL

2010-06-14 03:03:56 348160 ----a-w- d:\windows\system32\msvcr71.dll

2010-06-14 02:43:17 0 d-----w- d:\program files\common files\Digidesign

2010-06-14 02:43:09 0 d-----w- d:\program files\Antares Audio Technologies

2010-06-14 02:43:03 1777664 ----a-w- d:\windows\system32\gdiplus.dll

2010-06-14 02:41:35 0 d-----w- d:\program files\ASIO4ALL v2

2010-06-14 02:41:13 225280 ----a-w- d:\windows\system32\rewire.dll

2010-06-14 02:41:13 0 d-----w- d:\program files\VstPlugins

2010-06-14 02:40:57 1294336 ----a-w- d:\windows\system32\vorbis.acm

2010-06-14 02:40:45 0 d-----w- d:\program files\Outsim

2010-06-14 02:39:05 0 d-----w- d:\program files\Image-Line

==================== Find3M ====================

2010-07-08 02:22:29 0 ----a-w- d:\windows\system32\drivers\lvuvc.hs

2010-07-08 02:22:27 0 ----a-w- d:\windows\system32\drivers\logiflt.iad

2010-06-05 02:27:05 138592 ----a-w- d:\windows\system32\drivers\PnkBstrK.sys

2010-06-05 02:26:51 219128 ----a-w- d:\windows\system32\PnkBstrB.exe

2010-05-28 00:09:00 41872 ----a-w- d:\windows\system32\xfcodec.dll

2010-05-11 03:39:04 75064 ----a-w- d:\windows\system32\PnkBstrA.exe

2010-05-11 03:20:54 22328 ----a-w- d:\docume~1\zee\applic~1\PnkBstrK.sys

============= FINISH: 21:41:33.90 ===============

Attach.zip

Link to post
Share on other sites

  • 2 weeks later...
  • Staff

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.