- I have a Sony Vaio VGN-FW139E Laptop that recently came across massive spyware and trojans. I tried all I could to get rid of the files through any Anti Virus/Malaware program I could find until none of the programs would even update (Malaware Bytes/Spyware Doctor/SuperAntiSpyware/Avast).....
- I do have Vaio Recovery Center so I Burned the Recovery CD's onto a DVD disk and then 'Restored C-Drive' through the Recovery Center (I didnt need to insert the Recovery Disks at all during this)
- The minute that got finished the computer was still infected with this trojan called "Troj/Rustok-N"...I downloaded and updated Avira but it didnt detect the Troj/Rustok-N, but certain website I tried surfing told me I had it and wouldnt let me view the websites.
- I called Sony and they told me to Insert my Recovery Disks and complete a 'Restore Complete System' and again-I still had the Malaware and Trojans on my computer.
- Everytime I scan with a non-updated Scanner, it never detects anything but when im surfing the internet, I get directed to numerous spyware pages ect.... So I know I have more than just Troj/Rustok-N....I beleive everything is in my Registry...
- I believe that when I recently burned my Recovery disdks, all the bad trojans and whatnot got transfered over to my recovery disk?
- Attached are my Logs and attachments. Please take a look at them and tell me what you think.
DDS (Ver_09-03-16.01) - NTFSx86
Run by Trenton at 13:35:53.66 on Mon 05/11/2009
Internet Explorer: 7.0.6001.18000
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3069.1986 [GMT -5:00]
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\RtkAudioService.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\PSIService.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Sony\ISB Utility\ISBMgr.exe
C:\Program Files\Java\jre1.6.0\bin\jusched.exe
C:\Program Files\Sony\VAIO Wireless Wizard\AutoLaunchWLASU.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\Apntex.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Trenton\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.sony.com/vaiopeople
uDefault_Page_URL = hxxp://www.sony.com/vaiopeople
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
uRun: [Steam] "c:\program files\steam\Steam.exe" -silent
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [Apoint] c:\program files\apoint\Apoint.exe
mRun: [ISBMgr.exe] "c:\program files\sony\isb utility\ISBMgr.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe"
mRun: [AML] c:\program files\sony\vaio launcher\AML.exe InitApp
mRun: [VAIOMyMemCenter] "c:\program files\sony\vaio my memory center\VAIO MyMemCenter.exe" 1
mRun: [VWLASU] "c:\program files\sony\vaio wireless wizard\AutoLaunchWLASU.exe"
mRun: [VAIO Help and Support Demo] "c:\program files\sony\vaio help and support demo\LaunchVHSD.exe"
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [OneCareUI] "c:\program files\microsoft windows onecare live\winssnotify.exe"
mRun: [TrojanScanner] c:\program files\trojan remover\Trjscan.exe /boot
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\npjpi160.dll
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
Handler: intu-help-qb1 - {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - c:\program files\intuit\quickbooks 2008\HelpAsyncPluggableProtocol.dll
Handler: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - c:\windows\system32\mscoree.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: VESWinlogon - VESWinlogon.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
================= FIREFOX ===================
FF - ProfilePath - c:\users\trenton\appdata\roaming\mozilla\firefox\profiles\y0ahswsz.default\
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\java\jre1.6.0\bin\npoji610.dll
============= SERVICES / DRIVERS ===============
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-4-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-4-28 72944]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-5-11 108289]
R2 RtkHDMIService;RtkHDMIService;c:\windows\RTKAUDIOSERVICE.EXE [2008-6-5 98304]
R2 VAIO Power Management;VAIO Power Management;c:\program files\sony\vaio power management\SPMService.exe [2008-6-5 411488]
R3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\drivers\btwl2cap.sys [2008-6-5 28464]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\drivers\SFEP.sys [2008-6-5 9344]
S2 OcHealthMon;Windows Live OneCare Health Monitor;c:\program files\microsoft windows onecare live\OcHealthMon.exe [2009-3-22 24936]
S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\sony\vaio media plus\SOHCImp.exe [2009-5-11 104288]
S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\sony\vaio media plus\SOHDms.exe [2009-5-11 350048]
S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\sony\vaio media plus\SOHDs.exe [2009-5-11 63328]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\sony\vcm intelligent analyzing manager\VcmIAlzMgr.exe [2008-6-5 333088]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\common files\sony shared\vcmxml\VcmXmlIfHelper.exe [2008-6-5 87328]
=============== Created Last 30 ================
2009-05-11 12:36 40 -------- c:\windows\system32\ivireg.ivr
2009-05-11 12:30 1,645,320 -------- c:\windows\system32\gdiplus.dll
2009-05-11 12:29 212,480 -------- c:\windows\system32\PCDLIB32.DLL
2009-05-11 12:29 55,808 -------- c:\windows\system32\ArcSoftKsUFilter.dll
2009-05-11 12:29 245,408 -------- c:\windows\system32\unicows.dll
2009-05-11 12:26 <DIR> --d----- c:\program files\ATI Technologies
2009-05-11 12:26 <DIR> --d----- c:\program files\ATI
2009-05-11 12:20 21,954,560 a------- c:\windows\ocsetup_install_OEMHelpCustomization.etl
2009-05-11 12:20 196,608 a------- c:\windows\ocsetup_cbs_install_OEMHelpCustomization.perf
2009-05-11 12:20 65,536 a------- c:\windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
2009-05-11 12:19 <DIR> --d----- c:\programdata\Uninstall
2009-05-11 12:19 <DIR> --d----- c:\progra~2\Uninstall
2009-05-11 12:19 <DIR> --d----- c:\programdata\Sonic
2009-05-11 12:18 0 -------- c:\windows\system32\104D_SONY_VGN-FW139E.mrk
2009-05-11 12:18 0 -------- c:\windows\system32\drivers\Sony_VGN-FW139E.mrk
2009-05-11 12:18 <DIR> --d----- c:\program files\OCA Marker
2009-05-11 12:17 <DIR> --d----- c:\programdata\Corel
2009-05-11 12:17 <DIR> --d----- c:\progra~2\Corel
2009-05-11 12:14 <DIR> --d----- c:\program files\Microsoft Windows OneCare Live Staging
2009-05-11 12:13 <DIR> --d----- c:\program files\Microsoft Windows OneCare Live
2009-05-11 12:12 <DIR> --d----- c:\program files\Microsoft Office Suite Activation Assistant
2009-05-11 12:11 32,592 -------- c:\windows\system32\msonpmon.dll
2009-05-11 12:09 <DIR> --d----- c:\programdata\Microsoft Help
2009-05-11 12:08 <DIR> --d----- c:\program files\common files\supportsoft
2009-05-11 12:08 3,518,464 -------- c:\windows\system32\cdintf300.dll
2009-05-11 12:08 1,843,200 -------- c:\windows\system32\acXMLParser.dll
2009-05-11 12:07 <DIR> --d----- c:\programdata\Intuit
2009-05-11 12:07 <DIR> --d----- c:\program files\Intuit
2009-05-11 12:07 <DIR> --d----- c:\program files\common files\Intuit
2009-05-11 12:07 <DIR> --d----- c:\progra~2\Intuit
2009-05-11 12:06 <DIR> --d----- c:\programdata\COMMON FILES
2009-05-11 12:06 <DIR> --d----- c:\progra~2\COMMON FILES
2009-05-11 12:06 <DIR> --d----- c:\program files\MSXML 4.0
2009-05-11 12:02 <DIR> --d----- c:\program files\Online Services
2009-05-11 12:02 <DIR> --d----- c:\programdata\SmartWi Connection Utility
2009-05-11 12:02 <DIR> --d----- c:\progra~2\SmartWi Connection Utility
2009-05-11 11:53 <DIR> --d----- c:\program files\common files\Steam
2009-05-11 11:53 <DIR> --d----- c:\program files\Steam
2009-05-11 11:45 <DIR> a-d----- c:\programdata\TEMP
2009-05-11 11:43 162,304 a------- c:\windows\system32\ztvunrar36.dll
2009-05-11 11:43 77,312 a------- c:\windows\system32\ztvunace26.dll
2009-05-11 11:43 69,632 a------- c:\windows\system32\ztvcabinet.dll
2009-05-11 11:43 153,088 a------- c:\windows\system32\UNRAR3.dll
2009-05-11 11:43 75,264 a------- c:\windows\system32\unacev2.dll
2009-05-11 11:43 <DIR> --d----- c:\users\trenton\appdata\roaming\Simply Super Software
2009-05-11 11:43 <DIR> --d----- c:\programdata\Simply Super Software
2009-05-11 11:43 <DIR> --d----- c:\program files\Trojan Remover
2009-05-11 11:43 <DIR> --d----- c:\progra~2\Simply Super Software
2009-05-11 11:33 37,440 a------- c:\windows\system32\drivers\msfwhlpr.sys
2009-05-11 11:33 91,200 a------- c:\windows\system32\drivers\msfwdrv.sys
2009-05-11 11:33 53,168 a------- c:\windows\system32\drivers\MpFilter.sys
2009-05-11 11:32 <DIR> --d----- c:\windows\PCHEALTH
2009-05-11 11:29 55,640 a------- c:\windows\system32\drivers\avgntflt.sys
2009-05-11 11:29 <DIR> --d----- c:\programdata\Avira
2009-05-11 11:29 <DIR> --d----- c:\program files\Avira
2009-05-11 11:29 <DIR> --d----- c:\progra~2\Avira
2009-05-11 11:24 <DIR> --d----- c:\programdata\SUPERAntiSpyware.com
2009-05-11 11:24 <DIR> --d----- c:\progra~2\SUPERAntiSpyware.com
2009-05-11 11:23 <DIR> --d----- c:\users\trenton\appdata\roaming\SUPERAntiSpyware.com
2009-05-11 11:23 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-05-11 11:23 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-05-11 11:21 <DIR> --d----- c:\users\trenton\appdata\roaming\Malwarebytes
2009-05-11 11:21 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-05-11 11:21 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-11 11:21 <DIR> --d----- c:\programdata\Malwarebytes
2009-05-11 11:21 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-05-11 11:21 <DIR> --d----- c:\progra~2\Malwarebytes
2009-05-11 11:04 146 a------- c:\windows\WININIT.INI
2009-05-11 10:46 <DIR> --d----- c:\users\trenton\Bluetooth Software
2009-05-11 10:46 <DIR> --d----- c:\programdata\ATI
2009-05-11 10:45 <DIR> --d----- c:\users\Trenton
==================== Find3M ====================
2009-05-11 12:08 86,016 a------- c:\windows\inf\infstrng.dat
2009-05-11 12:08 86,016 a------- c:\windows\inf\infstor.dat
2009-05-11 12:08 51,200 a------- c:\windows\inf\infpub.dat
2008-06-05 12:52 665,600 a------- c:\windows\inf\drvindex.dat
2008-01-20 21:43 174 a--sh--- c:\program files\desktop.ini
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 07:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 07:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 04:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 04:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 13:36:14.67 ===============
Attachments
-
2.7 KB Views: 32
-
504 bytes Views: 34