Forum Home |  MWR University |  New to the Board? |  IRC Chatroom |  Who Runs This Site? |  ASAP Members |  Microsoft MVP Members |  Downloads |  Good & Bad P2P Programs |  Our Rules

MalWare Removal Forum

Malware Removal University - Teaching people how to support those with infected computers - Teaching them to never give up untill your computer is clean and secure.

Tutorials (etc.) : Boot to Safe Mode - Safely - What to do if your Computer's running slowly
It is currently Thu 23 May, 2013 6:15 am

All times are UTC [ DST ]


Forum rules


Please read > >THIS ANNOUNCEMENT< < before posting your NEW topic about your problem.

Please do NOT reply to your topic until a staff member has responded as they are looking for topics that have ZERO replies.

Paste your logs into your post. DO NOT USE ATTACHMENTS! Logs posted as attachments will be ignored and the topic will be closed.

If no expert has replied after 3 days, and you still require assistance, please post in our 72 hour bump room > > CLICK HERE < < Please do NOT reply to your own topic in an attempt to "bump" it. Bumped topics will be closed, requiring you to start again from the beginning.

If you are being helped and you haven't replied to your helper within 3 days of their last post, your topic will be closed as inactive. If that happens, you will need to start a new topic when you have the time available to promptly complete all instructions.

If your topic has been closed due to inactivity, do NOT request that your topic be reopened - we do NOT reopen topics unless they have been closed in error - you will need to start a NEW topic with NEW DDS logs. Do NOT attempt to start a new topic with a post that is essentially a reply to your closed topic.



Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 56 posts ]  Go to page Previous  1, 2, 3, 4  Next
Author Message
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Thu 24 Mar, 2011 5:15 pm 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
lso it has not yet asked me if I want to continue scanning

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Thu 24 Mar, 2011 8:36 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
You should begin to see it count various tasks from 1 to 50 or so, then take a while to rollup the report.
Wait (let me know if it doesn't move for 30 min.)
_________________


Top
 Profile  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Thu 24 Mar, 2011 8:45 pm 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
It's still not moving, been about 4hrs

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Fri 25 Mar, 2011 2:23 pm 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
when I got home the window was gone a new file called catchme.log was on desktop

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 03/24/2011 at 9:36:40.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:

C:\WINDOWS\system32\verclsid.exe


Rkill completed on 03/24/2011 at 9:36:43.


File "C:\WINDOWS\system32\drivers\volsnap.sys" added successfully
File list cleared
_________________


Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Fri 25 Mar, 2011 4:07 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
When you can please post the contents of the catchme.log

Top
 Profile  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Fri 25 Mar, 2011 4:37 pm 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
File "C:\WINDOWS\system32\drivers\volsnap.sys" added successfully
File list cleared

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Fri 25 Mar, 2011 6:17 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
redbull,

I believe you have a rootkit infection and/or a severely damaged system.
If you have rebooted the machine since you last ran RKill, run it again, but don't bother with any logs it produces.
Then without rebooting, let's see if you can get this one to run:
-----------------------------------------------
Run RootRepeal
Download RootRepeal.zip from here & unzip it to your Desktop.
  • Double click RootRepeal.exe to start the program, or in Vista, right click and choose "Run as administrator"
  • Click the Report tab at the bottom of the program window
  • Click the Scan button
  • In the Select Scan dialog, check:
      Drivers
      Files
      Processes
      SSDT
      Stealth Objects
      Hidden Services
  • Click the OK button
  • In the next dialog, select every drive showing
  • Click OK to start the scan
Note: The scan can take some time. DO NOT run any other programs while the scan is running

[*]When the scan is complete, the Save Report button will become available
[*]Click this and save the report to your Desktop as RootRepeal.txt
[*]Go to File then Exit to close the program
[*] Post the contents of RootRepeal.txt in your next reply[/list]

askey127

Top
 Profile  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sat 26 Mar, 2011 4:49 am 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
ROOTREPEAL (c) AD, 2007-2009
==================================================
Scan Start Time: 2011/03/25 21:23
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP3
==================================================

Drivers
-------------------
Name: dump_iaStor.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_iaStor.sys
Address: 0x9DA97000 Size: 892928 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0x9CC9A000 Size: 49152 File Visible: No Signed: -
Status: -

Hidden/Locked Files
-------------------
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: c:\documents and settings\melissa\local settings\temp\~dfb082.tmp
Status: Allocation size mismatch (API: 65536, Raw: 16384)

Path: c:\documents and settings\melissa\local settings\temp\~dfb2d6.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\melissa\local settings\temp\~dfbed2.tmp
Status: Allocation size mismatch (API: 131072, Raw: 16384)

Path: C:\System Rollback Data\Restore\Archive\00000045\00000044\0\Target\Documents and Settings\All Users\Application Data\AVG10\Chjw\300648~1.DAT:d10ba13b-56b1-4a0f-9116-b417a99cbd3d
Status: Visible to the Windows API, but not on disk.

Processes
-------------------
Path: C:\WINDOWS\system32\MPK\MPK.exe
PID: 1788 Status: Hidden from the Windows API!

SSDT
-------------------
#: 041 Function Name: NtCreateKey
Status: Hooked by "<unknown>" at address 0xa3c985c6

#: 053 Function Name: NtCreateThread
Status: Hooked by "<unknown>" at address 0xa3c985bc

#: 063 Function Name: NtDeleteKey
Status: Hooked by "<unknown>" at address 0xa3c985cb

#: 065 Function Name: NtDeleteValueKey
Status: Hooked by "<unknown>" at address 0xa3c985d5

#: 098 Function Name: NtLoadKey
Status: Hooked by "<unknown>" at address 0xa3c985da

#: 122 Function Name: NtOpenProcess
Status: Hooked by "<unknown>" at address 0xa3c985a8

#: 128 Function Name: NtOpenThread
Status: Hooked by "<unknown>" at address 0xa3c985ad

#: 193 Function Name: NtReplaceKey
Status: Hooked by "<unknown>" at address 0xa3c985e4

#: 204 Function Name: NtRestoreKey
Status: Hooked by "<unknown>" at address 0xa3c985df

#: 247 Function Name: NtSetValueKey
Status: Hooked by "<unknown>" at address 0xa3c985d0

==EOF==

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sat 26 Mar, 2011 1:57 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
redbull,
This may be a very recent infection involving the Hard Disk Master Boot Record. We will see.
-----------------------------------------------
Run aswMBR
Download aswMBR.exe to your desktop.
Double click on aswMBR.exe to run it

Image
Click the "Scan" button to start scan

Image
On completion of the scan click save log, save it to your desktop and post in your next reply

askey127

Top
 Profile  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sat 26 Mar, 2011 3:56 pm 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
aswMBR version 0.9.4 Copyright(c) 2011 AVAST Software
Run date: 2011-03-26 08:54:26
-----------------------------
08:54:26.265 OS Version: Windows 5.1.2600 Service Pack 3
08:54:26.265 Number of processors: 2 586 0x1C02
08:54:26.265 ComputerName: PC135561314894 UserName: Melissa
08:54:27.437 Initialize success
08:55:00.468 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
08:55:00.484 Disk 0 Vendor: FUJITSU_ 8919 Size: 152627MB BusType: 3
08:55:00.500 Disk 0 MBR read successfully
08:55:00.500 Disk 0 MBR scan
08:55:00.515 Disk 0 scanning sectors +312560640
08:55:00.562 Disk 0 scanning C:\WINDOWS\system32\drivers
08:55:10.234 Service scanning
08:55:11.656 Disk 0 trace - called modules:
08:55:11.656
08:55:11.656 Scan finished successfully

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sat 26 Mar, 2011 9:27 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
redbull,

-------------------------------------------------
Please download RogueKiller.exe and save it to your desktop.

Run RogueKiller
  • Now quit all running programs.
  • Double click RogueKiller.exe to run it.
  • When prompted, type 1 and hit Enter.
  • A RKreport.txt should appear on your desktop.
  • Note: If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe .
  • Please post the contents of the RKreport.txt in your next Reply.

askey127

Top
 Profile  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sun 27 Mar, 2011 6:09 am 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
most of the categories said access denied, run as administrator, I only have XP and no option to run as administrator



RogueKiller V4.3.4 by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Melissa [Restricted rights]
Mode: Scan -- Date : 03/26/2011 23:02:17

Bad processes: 0

Registry Entries: 2
[APPDT/TMP/DESKTOP] BackOnTrack Instant Restore Idle.job : rstidle.exe -> FOUND
[APPDT/TMP/DESKTOP] AppleSoftwareUpdate.job : softwareupdate.exe -> FOUND

HOSTS File:
127.0.0.1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt

RogueKiller V4.3.4 by Tigzy
contact at http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.sur-la-toile.com/discussion- ... ntees.html

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Melissa [Restricted rights]
Mode: Scan -- Date : 03/26/2011 23:02:17

Bad processes: 0

Registry Entries: 2
[APPDT/TMP/DESKTOP] BackOnTrack Instant Restore Idle.job : rstidle.exe -> FOUND
[APPDT/TMP/DESKTOP] AppleSoftwareUpdate.job : softwareupdate.exe -> FOUND

HOSTS File:
127.0.0.1 localhost


Finished : << RKreport[1].txt >>
RKreport[1].txt

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sun 27 Mar, 2011 12:39 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
Go to Start, Control Panel, and double click on User Accounts.
When you see your account, does it say "Computer Administrator", or does it say "Limited Account"?
Are there any other accounts on the machine that are Administrator accounts, and do you know the passwords?

Top
 Profile  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sun 27 Mar, 2011 3:35 pm 
Offline
Regular Member

Joined: Sat 19 Mar, 2011 4:25 am
Posts: 31
my account says computer administrator, there is a guest account that is off, the only time I had an option for which account was in safe mode, I could choose mine or administrator

Top
 Profile E-mail  
 
 Post subject: Re: windows diagnostic virus, hijackthis log
New postPosted: Sun 27 Mar, 2011 6:24 pm 
Offline
Admin/Teacher
Admin/Teacher
User avatar

Joined: Sun 17 Apr, 2005 8:25 pm
Posts: 13439
Location: New Hampshire USA
---------------------------------------------
Run a Scan with OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed to let it run uninterrupted.
  • When the window appears, In the Standard Registry box, click All.
  • In Extra registry click Use Safe List
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location
      as OTL (should be on your desktop).
    • Make sure Notepad's Format, Wordwrap is unchecked.
Please copy the contents of OTL.txt , and post it in your next reply.

Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic This topic is locked, you cannot edit posts or make further replies.  [ 56 posts ]  Go to page Previous  1, 2, 3, 4  Next

All times are UTC [ DST ]


Who is online

Users browsing this forum: doby108, wannabeageek and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.

Member site: Alliance of Security Analysis Professionals | UNITE Against Malware

Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group