Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Virus/Trojan/Spyware Help Get Rid Of Malware With Help From Our Analysts. Follow the "First Steps" link at the top right of each page before posting for help.

Reply
 
LinkBack Thread Tools
Old 08-10-2009, 09:18 PM   #1 (permalink)
Registered User
 
Join Date: Aug 2009
Posts: 2
OS: windows XP SP3


malware infected all .exe (even system processes)

Previously I had AVG installed, it detected win32 heur and some tanatos.h, tanatos.j viruses. Recently I removed AVG and installed Avast home edition. It detected win32.sality, win32.junkpoly, win32.trojan-gen,
win32.klone-BMO, VBS-malware-gen.

Though I haven't figured out exact symptoms in my PC, I think all my .exe application are infected. I get error message when trying to execute some utility programs, registry cleaners after few uses. Also I can't boot my PC in safemode.It says due to recent hardware software conflict. But I guess a malware caused it.

DDS (Ver_09-07-30.01) - NTFSx86
Run by Manoj at 8:39:26.82 on Tue 08/11/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_03
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2724 [GMT 5.75:45]

AV: avast! antivirus 4.8.1335 [VPS 090810-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Manoj\LOCALS~1\Temp\winlicfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Manoj\My Documents\Techsupport\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank
uWindow Title = LRI Internet Explorer
BHO: Octh Class: {000123b4-9b42-4900-b3f7-f4b073efc214} - c:\program files\orbitdownloader\orbitcth.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
dRunOnce: [nltide_2] regsvr32 /s /n /i:U shell32
uPolicies-system: DisbleRegistryTools = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
IE: &Download by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/201
IE: &Grab video by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/204
IE: Do&wnload selected by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\orbitdownloader\orbitmxt.dll/202
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - c:\program files\yahoo!\messenger\YahooMessenger.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683}
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_03\bin\ssv.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\wpdshserviceobj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-10 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 72944]
R2 {95808DC4-FA4A-4c74-92FE-5B863F82066B};{95808DC4-FA4A-4c74-92FE-5B863F82066B};c:\program files\cyberlink\powerdvd\000.fcl [2006-11-2 13560]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-10 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-10 138680]
S3 aic32p;aic32p; [x]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\g:\ntglm7x.sys --> g:\NTGLM7X.sys [?]

=============== Created Last 30 ================

2009-08-11 00:19 <DIR> --d----- c:\program files\Trend Micro
2009-08-11 00:07 69,632 a------- c:\windows\system32\javacpl.cpl
2009-08-10 23:37 <DIR> --d----- c:\docume~1\manoj\applic~1\Malwarebytes
2009-08-10 23:37 38,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-10 23:37 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-08-10 23:37 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-08-10 23:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-10 23:11 344,064 a------- c:\windows\system32\rmsality.nt
2009-08-10 17:13 1,060,864 a------- c:\windows\system32\MFC71.dll
2009-08-09 21:54 <DIR> --d----- c:\program files\MSN Messenger
2009-08-06 22:19 1,846,632 a------- c:\windows\system32\D3DCompiler_41.dll
2009-08-06 22:19 453,456 a------- c:\windows\system32\d3dx10_41.dll
2009-08-06 22:19 4,178,264 a------- c:\windows\system32\D3DX9_41.dll
2009-08-06 22:19 517,448 a------- c:\windows\system32\XAudio2_4.dll
2009-08-06 22:19 235,352 a------- c:\windows\system32\xactengine3_4.dll
2009-08-06 22:19 69,448 a------- c:\windows\system32\XAPOFX1_3.dll
2009-08-06 22:19 3,786,760 a------- c:\windows\system32\D3DX9_37.dll
2009-08-06 22:19 1,420,824 a------- c:\windows\system32\D3DCompiler_37.dll
2009-08-06 22:19 462,864 a------- c:\windows\system32\d3dx10_37.dll
2009-08-06 22:19 81,768 a------- c:\windows\system32\xinput1_3.dll
2009-08-04 16:37 <DIR> --d----- c:\docume~1\manoj\applic~1\TuneUp Software
2009-08-03 17:11 <DIR> --d----- c:\program files\Guitar Pro 4
2009-08-03 17:11 <DIR> --d----- c:\windows\Downloaded Installations
2009-07-25 23:37 754 a------- c:\windows\WORDPAD.INI
2009-07-25 18:03 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-07-25 18:03 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-07-25 18:03 <DIR> --d----- c:\docume~1\manoj\applic~1\SUPERAntiSpyware.com
2009-07-22 12:21 <DIR> --d----- c:\program files\common files\ACD Systems
2009-07-21 00:11 <DIR> --d----- c:\program files\RegistryFix7
2009-07-20 22:03 56 a---h--- c:\windows\system32\ezsidmv.dat
2009-07-20 22:02 <DIR> --d----- c:\program files\Skype
2009-07-20 20:45 <DIR> --d----- c:\documents and settings\manoj\Contacts
2009-07-19 20:59 <DIR> --d----- c:\program files\Orbitdownloader
2009-07-18 15:36 26,368 ac------ c:\windows\system32\dllcache\usbstor.sys
2009-07-18 12:38 <DIR> --d----- c:\program files\VideoLAN
2009-07-18 12:04 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-07-18 09:14 <DIR> --d----- c:\docume~1\manoj\applic~1\MSNInstaller
2009-07-17 08:23 <DIR> --d----- c:\program files\Yahoo!
2009-07-17 08:19 <DIR> --d----- c:\windows\SxsCaPendDel
2009-07-17 03:38 3,072 a------- c:\windows\system32\drivers\audstub.sys
2009-07-17 03:38 57,600 a------- c:\windows\system32\drivers\redbook.sys
2009-07-17 03:37 74,240 ac------ c:\windows\system32\dllcache\usbui.dll
2009-07-17 03:37 74,240 a------- c:\windows\system32\usbui.dll
2009-07-17 03:36 <DIR> --d----- c:\program files\common files\ODBC
2009-07-17 03:36 <DIR> --d----- c:\program files\common files\SpeechEngines
2009-07-17 03:36 <DIR> --d--r-- c:\documents and settings\all users\Documents
2009-07-17 03:35 1,296,669 ac------ c:\windows\system32\dllcache\SP3.CAT
2009-07-17 03:34 <DIR> --d----- c:\windows\system32\CatRoot2
2009-07-17 03:34 <DIR> --d----- c:\windows\system32\CatRoot
2009-07-17 03:34 <DIR> --d----- C:\Documents and Settings
2009-07-17 03:33 717 a------- c:\windows\system32\$winnt$.inf
2009-07-16 23:37 <DIR> --d----- c:\program files\USB Vibration Joystick
2009-07-16 22:47 <DIR> --d----- c:\docume~1\manoj\applic~1\COWON
2009-07-16 22:47 <DIR> --d----- c:\program files\JetAudio
2009-07-16 22:47 <DIR> --d----- c:\program files\common files\COWON
2009-07-16 22:28 <DIR> --d----- c:\program files\Realtek
2009-07-16 22:22 <DIR> --d----- c:\docume~1\manoj\applic~1\URSoft
2009-07-16 22:22 <DIR> --d----- c:\program files\Your Uninstaller 2008
2009-07-16 21:59 <DIR> --dsh--- c:\documents and settings\all users\DRM
2009-07-16 21:58 <DIR> --d----- c:\program files\common files\MSSoap
2009-07-16 21:57 <DIR> --d----- c:\program files\Online Services
2009-07-16 21:57 <DIR> --d----- c:\program files\Windows Media Connect 2
2009-07-16 21:57 <DIR> --d----- c:\program files\Messenger
2009-07-16 21:57 <DIR> --d----- c:\program files\MSN Gaming Zone
2009-07-16 21:56 <DIR> --d----- c:\program files\Windows NT

==================== Find3M ====================

2009-08-04 16:33 505,392 a------- c:\windows\system32\msvcp71.dll
2009-07-20 18:12 1,650,688 a------- c:\windows\system32\nwiz.exe
2009-07-17 17:13 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-07-16 22:56 353,840 a------- c:\windows\system32\msvcr71.dll
2009-07-16 22:28 315,392 a------- c:\windows\HideWin.exe
2009-07-16 21:57 21,640 a------- c:\windows\system32\emptyregdb.dat

============= FINISH: 8:39:34.35 ===============
Attached Files
File Type: rar Attach&Ark.rar (2.4 KB, 2 views)
Spywarevictim is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 08-13-2009, 07:19 PM   #2 (permalink)
Registered User
 
Join Date: Aug 2009
Posts: 2
OS: windows XP SP3


Re: malware infected all .exe (even system processes)

Bump please
Spywarevictim is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 02:30 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85