How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

View previous topic View next topic Go down

How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 24th December 2009, 6:05 pm

Dear Sir/Madam,

Got this annoying virus/trojan ( contains recognition pattern of the DR/Delphi.Gen - Dropper located at c:\WINDOWS\Temp\xxxx.tmp\svchost.exe. on my computer.

Cant seem to get rid of it. My Avira antivirus keeps popping a window reminder.
Using WINDOWS XP SP2.

Can anyone help me please ?

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 24th December 2009, 6:43 pm

Please download the current version of HijackThis from [You must be registered and logged in to see this link.]

  • Double click and run the installer.
  • It will install to C:\Program Files\Trend Micro\HijackThis\hijackthis.exe
  • After installing, you should get the user agreement, press accept and Hijack This will run.
  • Select Do a system scan and save a log file. This will open a notepad file of everything Hijack This found, copy and paste it back here.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 24th December 2009, 6:52 pm

Below I've pasted the log file report :

Logfile of Trend Micro HijackThis v2.0.3 (BETA)
Scan saved at 12:20:57 AM, on 12/25/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [MPlayerForWindows_UpdateReminder] "C:\Program Files\MPlayer for Windows\AutoUpdate.exe" /L=1033 /TASK
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - [You must be registered and logged in to see this link.]
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Bluetooth Service (btwdins) - WIDCOMM, Inc. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 6462 bytes

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 24th December 2009, 6:54 pm

Please download and run this tool.

Download Malwarebytes' Anti-Malware from [You must be registered and logged in to see this link.]

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 24th December 2009, 7:48 pm

I ran the quick scan of MBAM (updated)... It says 'no malicious items were detected' while even when the scan was running my avira kept popping the reminder window No way! ...hope i dint have to exit my antivirus (antivir) before running the scan... neways i've pasted the scan log below...

Malwarebytes' Anti-Malware 1.42
Database version: 3425
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

12/25/2009 1:12:57 AM
mbam-log-2009-12-25 (01-12-57).txt

Scan type: Quick Scan
Objects scanned: 108087
Time elapsed: 8 minute(s), 17 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 24th December 2009, 8:16 pm

Hello.
Before we try a temp file cleaner, I wanna check these two logs.

  • Please download DDS by sUBs to your Desktop (Important!!) from one of these locations:
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]
  • Double click DDS.scr to run.
  • When complete, two logs will open. Save both of the report to your Desktop.
  • Copy and paste BOTH LOGS back here, use more than one post if needed.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 24th December 2009, 8:50 pm

here r the log posts...
DDS log:


DDS (Ver_09-12-01.01) - NTFSx86
Run by Sam at 2:15:32.58 on Fri 12/25/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.140 [GMT 5.5:30]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Program Files\Java\jre6\bin\jucheck.exe
C:\DOCUME~1\Sam\LOCALS~1\Temp\jre-6u17-windows-i586-iftw-rv.exe
C:\Documents and Settings\Sam\Desktop\dds.scr

============== Pseudo HJT Report ===============

mWinlogon: Taskman=c:\documents and settings\sam\application data\kohboq.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [MPlayerForWindows_UpdateReminder] "c:\program files\mplayer for windows\AutoUpdate.exe" /L=1033 /TASK
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - [You must be registered and logged in to see this link.]
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-12-14 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-12-14 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-12-14 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-14 56816]

=============== Created Last 30 ================

2009-12-24 19:53:25 3255 ----a-w- c:\windows\system32\wbem\Outlook_01ca84d2c1126fd0.mof
2009-12-24 19:30:21 0 d-----w- c:\docume~1\sam\applic~1\Malwarebytes
2009-12-24 19:30:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 19:30:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-24 19:30:09 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 19:30:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 18:49:47 0 d-----w- c:\program files\TrendMicro
2009-12-21 18:27:52 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-12-21 18:27:52 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-12-21 18:27:40 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-21 18:27:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-21 18:27:28 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-12-21 18:05:40 0 d-----w- c:\program files\common files\PCSuite
2009-12-21 18:05:32 0 d-----w- c:\program files\common files\Nokia
2009-12-21 18:05:18 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-12-21 18:05:08 0 d-----w- c:\program files\PC Connectivity Solution
2009-12-21 18:05:01 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-12-21 18:05:01 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-12-21 18:05:00 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-12-21 18:04:57 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-12-21 18:04:57 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-12-21 18:04:57 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-12-21 18:04:55 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-12-21 18:04:54 0 d-----w- c:\program files\Nokia
2009-12-17 07:08:08 0 d-----w- c:\documents and settings\sam\fontconfig
2009-12-17 07:05:00 0 d-----w- c:\program files\MPlayer for Windows
2009-12-16 15:23:33 151 ----a-w- c:\windows\PhotoSnapViewer.INI
2009-12-14 09:04:47 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-14 09:04:42 0 d-----w- c:\program files\Avira
2009-12-14 09:04:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2009-12-05 11:44:55 174 ----a-w- c:\documents and settings\sam\default.pls
2009-12-05 09:44:48 69 ----a-w- c:\windows\NeroDigital.ini
2009-12-03 02:56:54 0 d-----w- c:\program files\Nero
2009-12-03 02:56:54 0 d-----w- c:\docume~1\alluse~1\applic~1\Nero
2009-12-03 02:56:00 0 d-----w- c:\windows\RegisteredPackages
2009-11-30 21:37:00 0 d-----w- c:\windows\system32\KB905474
2009-11-30 21:32:16 0 d-----w- c:\windows\ServicePackFiles
2009-11-30 00:07:15 0 d-----w- c:\windows\system32\CatRoot_bak
2009-11-29 23:08:37 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-29 23:08:36 2180352 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-11-29 23:08:35 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-29 23:08:34 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-29 22:41:50 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-29 21:30:25 0 d-----w- c:\windows\system32\PreInstall
2009-11-29 21:30:24 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-11-29 21:30:22 0 d--h--w- c:\windows\$hf_mig$
2009-11-29 19:16:55 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-11-29 19:16:55 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-11-29 18:45:05 73728 ----a-w- c:\windows\system32\javacpl.cpl
2009-11-29 18:45:05 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-11-29 18:35:34 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-11-29 18:26:53 0 d-----w- c:\windows\system32\appmgmt
2009-11-29 18:26:45 0 d-----w- c:\windows\SxsCaPendDel
2009-11-28 13:07:13 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-11-28 13:07:13 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-28 13:07:09 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-11-28 13:07:09 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys
2009-11-27 18:36:03 0 d-----w- c:\program files\uTorrent
2009-11-27 18:35:35 0 d-----w- c:\docume~1\sam\applic~1\uTorrent
2009-11-26 23:47:16 0 d-----w- c:\program files\common files\ODBC
2009-11-26 23:47:12 0 d-----w- c:\program files\common files\SpeechEngines
2009-11-26 23:46:38 0 d-----r- c:\documents and settings\all users\Documents
2009-11-26 21:15:45 0 d-----w- c:\program files\VideoLAN
2009-11-26 21:02:07 0 d-----w- c:\program files\K-Lite Codec Pack
2009-11-26 20:35:10 0 d-----w- c:\program files\Synaptics
2009-11-26 20:30:57 0 d-----w- c:\program files\GCC4243N_fw
2009-11-26 20:24:53 0 d-----w- c:\program files\WIDCOMM
2009-11-26 18:27:14 0 d-sh--w- c:\documents and settings\all users\DRM
2009-11-26 18:26:52 0 d--h--w- c:\program files\WindowsUpdate
2009-11-26 18:25:41 0 d-----w- c:\program files\common files\MSSoap
2009-11-26 18:23:51 0 d-----w- c:\program files\Online Services
2009-11-26 18:23:44 0 d-----w- c:\program files\Messenger
2009-11-26 18:23:38 0 d-----w- c:\program files\MSN Gaming Zone
2009-11-26 18:22:48 0 d-----w- c:\program files\Windows NT

==================== Find3M ====================

2009-11-26 18:24:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat

============= FINISH: 2:16:16.86 ===============

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 24th December 2009, 8:52 pm

n here's the 'Attach log':

UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-12-01.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 11/27/2009 12:01:51 AM
System Uptime: 12/25/2009 2:07:55 AM (0 hours ago)

Motherboard: Quanta | | 308F
Processor: Intel(R) Pentium(R) M processor 1.70GHz | U1 | 1695/400mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 20 GiB total, 1.542 GiB free.
D: is FIXED (FAT32) - 29 GiB total, 0.86 GiB free.
E: is FIXED (FAT32) - 26 GiB total, 1.768 GiB free.
F: is CDROM ()

==== Disabled Device Manager Items =============

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Mass Storage Controller
Device ID: PCI\VEN_104C&DEV_8033&SUBSYS_3080103C&REV_00\4&AD1B67F&0&4BF0
Manufacturer:
Name: Mass Storage Controller
PNP Device ID: PCI\VEN_104C&DEV_8033&SUBSYS_3080103C&REV_00\4&AD1B67F&0&4BF0
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: PCI Modem
Device ID: PCI\VEN_8086&DEV_266D&SUBSYS_3080103C&REV_03\3&B1BFB68&0&F3
Manufacturer:
Name: PCI Modem
PNP Device ID: PCI\VEN_8086&DEV_266D&SUBSYS_3080103C&REV_03\3&B1BFB68&0&F3
Service:

==== System Restore Points ===================

RP16: 12/2/2009 12:00:10 AM - System Checkpoint
RP17: 12/3/2009 12:16:59 AM - System Checkpoint
RP18: 12/3/2009 8:25:01 AM - Installed DirectX
RP19: 12/3/2009 8:26:49 AM - Installed Nero 7 Premium
RP20: 12/4/2009 9:15:07 AM - System Checkpoint
RP21: 12/5/2009 9:38:29 AM - System Checkpoint
RP22: 12/6/2009 12:11:17 PM - System Checkpoint
RP23: 12/8/2009 2:31:30 AM - System Checkpoint
RP24: 12/9/2009 2:41:15 AM - System Checkpoint
RP25: 12/10/2009 3:02:17 AM - System Checkpoint
RP26: 12/11/2009 3:37:49 AM - System Checkpoint
RP27: 12/12/2009 4:19:32 AM - System Checkpoint
RP28: 12/13/2009 5:11:21 AM - System Checkpoint
RP29: 12/14/2009 2:30:59 PM - Avira AntiVir Personal - 12/14/2009 14:30
RP30: 12/14/2009 2:34:14 PM - Avira AntiVir Personal - 12/14/2009 14:34
RP31: 12/15/2009 3:28:14 PM - System Checkpoint
RP32: 12/16/2009 4:16:17 PM - System Checkpoint
RP33: 12/17/2009 4:31:43 PM - System Checkpoint
RP34: 12/18/2009 9:37:43 PM - System Checkpoint
RP35: 12/19/2009 9:47:03 PM - System Checkpoint
RP36: 12/21/2009 1:02:50 AM - System Checkpoint
RP37: 12/21/2009 7:39:02 AM - Removed Adobe Reader 9.1.
RP38: 12/21/2009 11:57:28 PM - Installed Windows XP Wdf01007.
RP39: 12/23/2009 2:56:10 AM - System Checkpoint
RP40: 12/24/2009 4:23:07 AM - System Checkpoint
RP41: 12/25/2009 12:19:45 AM - Installed HiJackThis

==== Installed Programs ======================

µTorrent
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
Avira AntiVir Personal - Free Antivirus
Bluetooth by hp
Conexant AC-Link Audio
Google Chrome
Google Talk (remove only)
HiJackThis
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB976098-v2)
Intel(R) Graphics Media Accelerator Driver for Mobile
Java(TM) 6 Update 11
K-Lite Codec Pack 3.4.5 Full
Malwarebytes' Anti-Malware
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Software Update for Web Folders (English) 12
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
MPlayer for Windows (Full Package)
MSVC80_x86
Nero 7 Premium
neroxml
Nokia Connectivity Cable Driver
Nokia PC Suite
PC Connectivity Solution
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971032)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Synaptics Pointing Device Driver
Update for Windows XP (KB898461)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VLC media player 0.9.9
WebFldrs XP
Windows Driver Package - Nokia Modem (06/01/2009 4.1)
Windows Driver Package - Nokia Modem (06/01/2009 7.01.0.3)
Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
WinRAR archiver

==== Event Viewer Messages From Past Week ========

12/21/2009 12:17:38 AM, error: Dhcp [1002] - The IP address lease 192.168.1.3 for the Network Card with network address 00150050C859 has

been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
12/21/2009 10:39:09 AM, error: ipnathlp [32003] - The Network Address Translator (NAT) was unable to request an operation of the kernel-mode

translation module. This may indicate misconfiguration, insufficient resources, or an internal error. The data is the error code.
12/21/2009 10:39:09 AM, error: Dhcp [1002] - The IP address lease 192.168.1.4 for the Network Card with network address 00150050C859 has

been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
12/21/2009 10:21:43 AM, error: Dhcp [1002] - The IP address lease 192.168.1.2 for the Network Card with network address 00150050C859 has

been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message).
12/18/2009 8:43:29 PM, error: Ftdisk [49] - Configuring the Page file for crash dump failed. Make sure there is a page file on the boot partition and that

is large enough to contain all physical memory.
12/18/2009 8:43:29 PM, error: Ftdisk [45] - The system could not sucessfully load the crash dump driver.

==== End Of File ===========================

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 24th December 2009, 9:49 pm

Hello.

Go to Start > Control Panel > Add/Remove Programs and remove the following programs.

    µTorrent
    Java(TM) 6 Update 11

Please download the [You must be registered and logged in to see this link.].

  • Save it to your desktop.
  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :files
    c:\documents and settings\sam\application data\kohboq.exe
    c:\program files\uTorrent
    c:\docume~1\sam\applic~1\uTorrent

    :reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman]

    :commands
    [emptytemp]
    [reboot]


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 26th December 2009, 4:08 am

Hey! Sorry for not being able to get back to u earlier... freed about 760 MBs :smile2:
but still havn't got rid of the dropper! Here's the OTMoveIt log:

All processes killed
========== FILES ==========
File/Folder c:\documents and settings\sam\application data\kohboq.exe not found.
File/Folder c:\program files\uTorrent not found.
c:\docume~1\sam\applic~1\uTorrent folder moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\taskman\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Sam
->Temp folder emptied: 697916250 bytes
->Temporary Internet Files folder emptied: 56592585 bytes
->Java cache emptied: 13702010 bytes
->FireFox cache emptied: 16603219 bytes
->Google Chrome cache emptied: 9715096 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2142714 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
Windows Temp folder emptied: 226475 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 760.00 mb


OTM by OldTimer - Version 3.1.4.0 log created on 12262009_092900

Files moved on Reboot...
File C:\Documents and Settings\Sam\Local Settings\Temp\Perflib_Perfdata_8f0.dat not found!

Registry entries deleted on Reboot...

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 26th December 2009, 8:57 pm

I know, made a slight error in my script there.

Please re-run DDS and post the new DDS.txt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 27th December 2009, 5:00 am

okay... herez the DDS n ATTACH scripts again:


DDS (Ver_09-12-01.01) - NTFSx86
Run by Sam at 10:17:49.21 on Sun 12/27/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.158 [GMT 5.5:30]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Desktop\dds.scr

============== Pseudo HJT Report ===============

mWinlogon: Taskman=c:\documents and settings\sam\application data\kohboq.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [MPlayerForWindows_UpdateReminder] "c:\program files\mplayer for windows\AutoUpdate.exe" /L=1033 /TASK
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-12-14 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-12-14 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-12-14 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-14 56816]

=============== Created Last 30 ================

2009-12-26 03:59:00 0 d-----w- C:\_OTM
2009-12-24 19:53:25 3255 ----a-w- c:\windows\system32\wbem\Outlook_01ca84d2c1126fd0.mof
2009-12-24 19:30:21 0 d-----w- c:\docume~1\sam\applic~1\Malwarebytes
2009-12-24 19:30:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 19:30:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-24 19:30:09 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 19:30:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 18:49:47 0 d-----w- c:\program files\TrendMicro
2009-12-21 18:27:52 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-12-21 18:27:52 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-12-21 18:27:40 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-21 18:27:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-21 18:27:28 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-12-21 18:05:40 0 d-----w- c:\program files\common files\PCSuite
2009-12-21 18:05:32 0 d-----w- c:\program files\common files\Nokia
2009-12-21 18:05:18 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-12-21 18:05:08 0 d-----w- c:\program files\PC Connectivity Solution
2009-12-21 18:05:01 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-12-21 18:05:01 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-12-21 18:05:00 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-12-21 18:04:57 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-12-21 18:04:57 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-12-21 18:04:57 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-12-21 18:04:55 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-12-21 18:04:54 0 d-----w- c:\program files\Nokia
2009-12-17 07:08:08 0 d-----w- c:\documents and settings\sam\fontconfig
2009-12-17 07:05:00 0 d-----w- c:\program files\MPlayer for Windows
2009-12-16 15:23:33 151 ----a-w- c:\windows\PhotoSnapViewer.INI
2009-12-14 09:04:47 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-14 09:04:42 0 d-----w- c:\program files\Avira
2009-12-14 09:04:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2009-12-05 11:44:55 174 ----a-w- c:\documents and settings\sam\default.pls
2009-12-05 09:44:48 69 ----a-w- c:\windows\NeroDigital.ini
2009-12-03 02:56:54 0 d-----w- c:\program files\Nero
2009-12-03 02:56:54 0 d-----w- c:\docume~1\alluse~1\applic~1\Nero
2009-12-03 02:56:00 0 d-----w- c:\windows\RegisteredPackages
2009-11-30 21:37:00 0 d-----w- c:\windows\system32\KB905474
2009-11-30 21:32:16 0 d-----w- c:\windows\ServicePackFiles
2009-11-30 00:07:15 0 d-----w- c:\windows\system32\CatRoot_bak
2009-11-29 23:08:37 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-29 23:08:36 2180352 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-11-29 23:08:35 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-29 23:08:34 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-29 22:41:50 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-29 21:30:25 0 d-----w- c:\windows\system32\PreInstall
2009-11-29 21:30:24 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-11-29 21:30:22 0 d--h--w- c:\windows\$hf_mig$
2009-11-29 19:16:55 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-11-29 19:16:55 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-11-29 18:45:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-29 18:35:34 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-11-29 18:26:53 0 d-----w- c:\windows\system32\appmgmt
2009-11-29 18:26:45 0 d-----w- c:\windows\SxsCaPendDel
2009-11-28 13:07:13 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-11-28 13:07:13 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-28 13:07:09 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-11-28 13:07:09 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys

==================== Find3M ====================

2009-11-26 18:24:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat

============= FINISH: 10:18:41.23 ===============



Attach log:


DDS (Ver_09-12-01.01) - NTFSx86
Run by Sam at 10:17:49.21 on Sun 12/27/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.158 [GMT 5.5:30]

AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Program Files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sam\Desktop\dds.scr

============== Pseudo HJT Report ===============

mWinlogon: Taskman=c:\documents and settings\sam\application data\kohboq.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe"
uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [NeroFilterCheck] c:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [MPlayerForWindows_UpdateReminder] "c:\program files\mplayer for windows\AutoUpdate.exe" /L=1033 /TASK
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\bttray.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\micros~2\office12\GR99D3~1.DLL
Handler: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - c:\windows\system32\BTXPPanel.dll
Notify: igfxcui - igfxdev.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\micros~2\office12\GRA8E1~1.DLL

============= SERVICES / DRIVERS ===============

R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2009-12-14 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2009-12-14 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2009-12-14 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-14 56816]

=============== Created Last 30 ================

2009-12-26 03:59:00 0 d-----w- C:\_OTM
2009-12-24 19:53:25 3255 ----a-w- c:\windows\system32\wbem\Outlook_01ca84d2c1126fd0.mof
2009-12-24 19:30:21 0 d-----w- c:\docume~1\sam\applic~1\Malwarebytes
2009-12-24 19:30:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 19:30:10 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-24 19:30:09 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 19:30:09 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 18:49:47 0 d-----w- c:\program files\TrendMicro
2009-12-21 18:27:52 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-12-21 18:27:52 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-12-21 18:27:40 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-21 18:27:38 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-21 18:27:28 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-12-21 18:05:40 0 d-----w- c:\program files\common files\PCSuite
2009-12-21 18:05:32 0 d-----w- c:\program files\common files\Nokia
2009-12-21 18:05:18 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2009-12-21 18:05:08 0 d-----w- c:\program files\PC Connectivity Solution
2009-12-21 18:05:01 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerfltj.sys
2009-12-21 18:05:01 7808 ----a-w- c:\windows\system32\drivers\usbser_lowerflt.sys
2009-12-21 18:05:00 22016 ----a-w- c:\windows\system32\drivers\ccdcmbo.sys
2009-12-21 18:04:57 659968 ----a-w- c:\windows\system32\nmwcdcocls.dll
2009-12-21 18:04:57 17664 ----a-w- c:\windows\system32\drivers\ccdcmb.sys
2009-12-21 18:04:57 1112288 ----a-w- c:\windows\system32\wdfcoinstaller01007.dll
2009-12-21 18:04:55 91136 ----a-w- c:\windows\system32\nmwcdcls.dll
2009-12-21 18:04:54 0 d-----w- c:\program files\Nokia
2009-12-17 07:08:08 0 d-----w- c:\documents and settings\sam\fontconfig
2009-12-17 07:05:00 0 d-----w- c:\program files\MPlayer for Windows
2009-12-16 15:23:33 151 ----a-w- c:\windows\PhotoSnapViewer.INI
2009-12-14 09:04:47 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-14 09:04:42 0 d-----w- c:\program files\Avira
2009-12-14 09:04:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Avira
2009-12-05 11:44:55 174 ----a-w- c:\documents and settings\sam\default.pls
2009-12-05 09:44:48 69 ----a-w- c:\windows\NeroDigital.ini
2009-12-03 02:56:54 0 d-----w- c:\program files\Nero
2009-12-03 02:56:54 0 d-----w- c:\docume~1\alluse~1\applic~1\Nero
2009-12-03 02:56:00 0 d-----w- c:\windows\RegisteredPackages
2009-11-30 21:37:00 0 d-----w- c:\windows\system32\KB905474
2009-11-30 21:32:16 0 d-----w- c:\windows\ServicePackFiles
2009-11-30 00:07:15 0 d-----w- c:\windows\system32\CatRoot_bak
2009-11-29 23:08:37 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-29 23:08:36 2180352 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-11-29 23:08:35 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-29 23:08:34 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-29 22:41:50 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-29 21:30:25 0 d-----w- c:\windows\system32\PreInstall
2009-11-29 21:30:24 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-11-29 21:30:22 0 d--h--w- c:\windows\$hf_mig$
2009-11-29 19:16:55 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-11-29 19:16:55 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-11-29 18:45:05 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-29 18:35:34 0 d-----w- c:\windows\system32\SoftwareDistribution
2009-11-29 18:26:53 0 d-----w- c:\windows\system32\appmgmt
2009-11-29 18:26:45 0 d-----w- c:\windows\SxsCaPendDel
2009-11-28 13:07:13 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-11-28 13:07:13 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-28 13:07:09 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-11-28 13:07:09 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys

==================== Find3M ====================

2009-11-26 18:24:19 21640 ----a-w- c:\windows\system32\emptyregdb.dat

============= FINISH: 10:18:41.23 ===============

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 27th December 2009, 5:02 am

Hope u had a lovely christmas bro... Cheers Mate

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 27th December 2009, 3:41 pm

Hello.

  • Please double-click OTM.exe to run it.
  • Copy the bolded text below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose CopyCrying


    :reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "taskman"=-


  • Return to OTMoveIt, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 27th December 2009, 4:15 pm

dear sir,
here's the log file for OTM..

========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\taskman deleted successfully.

OTM by OldTimer - Version 3.1.4.0 log created on 12272009_213913

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 27th December 2009, 4:17 pm

Got it right that time. LMBO or ROFL

Still having problems now?


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 27th December 2009, 4:40 pm

yup! no more irritating pop-ups nemore. Seems like we've finally got rid of it...

That's a welcome relief, all thanx to u belahzur.
Thank You!
for all your help!!!
Right On!

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 27th December 2009, 4:54 pm

Hey! guess i got too excited too soon... The problem persists, the Delphi.Gen-Dropper started popping up again ,after a brief break of about an hr... :sad:

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 27th December 2009, 5:32 pm

Hello.

  • Download combofix from here
    [You must be registered and logged in to see this link.]
    [You must be registered and logged in to see this link.]

    1. If you are using Firefox, make sure that your download settings are as follows:

    * Tools->Options->Main tab
    * Set to "Always ask me where to Save the files".

    2. During the download, rename Combofix to Combo-Fix as follows:





    3. It is important you rename Combofix during the download, but not after.
    4. Please do not rename Combofix to other names, but only to the one indicated.
    5. Close any open browsers.
    6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • We need to disable your local AV (Anti-virus) before running Combofix.
  • See [You must be registered and logged in to see this link.] for how to disable your AV.
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.



  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will then get this next prompt that asks if you want to continue the malware scan, select yes



  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by kshitij mathur on 27th December 2009, 7:37 pm

Hello.
Here's the combofix log :

ComboFix 09-12-26.05 - Sam 12/28/2009 0:55.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.502.269 [GMT 5.5:30]
Running from: c:\documents and settings\Sam\Desktop\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

Infected copy of c:\windows\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - Kitty ate it :p
.
((((((((((((((((((((((((( Files Created from 2009-11-27 to 2009-12-27 )))))))))))))))))))))))))))))))
.

2009-12-27 16:43 . 2009-12-27 16:43 -------- d-----w- c:\documents and settings\Sam\Application Data\gnupg
2009-12-26 09:03 . 2009-12-27 16:42 -------- d-----w- c:\program files\uTorrent
2009-12-26 09:03 . 2009-12-27 19:01 -------- d-----w- c:\documents and settings\Sam\Application Data\uTorrent
2009-12-26 03:59 . 2009-12-26 03:59 -------- d-----w- C:\_OTM
2009-12-24 20:47 . 2009-12-24 20:47 152576 ----a-w- c:\documents and settings\Sam\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-24 20:44 . 2009-12-24 20:47 79488 ----a-w- c:\documents and settings\Sam\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-24 19:30 . 2009-12-24 19:30 -------- d-----w- c:\documents and settings\Sam\Application Data\Malwarebytes
2009-12-24 19:30 . 2009-12-03 10:44 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-24 19:30 . 2009-12-24 19:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-24 19:30 . 2009-12-24 19:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-24 19:30 . 2009-12-03 10:43 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-24 18:49 . 2009-12-24 18:49 -------- d-----w- c:\program files\TrendMicro
2009-12-21 18:27 . 2004-08-03 17:38 25600 -c--a-w- c:\windows\system32\dllcache\usbser.sys
2009-12-21 18:27 . 2004-08-03 17:38 25600 ----a-w- c:\windows\system32\drivers\usbser.sys
2009-12-21 18:27 . 2008-03-21 08:27 14640 ------w- c:\windows\system32\spmsgXP_2k3.dll
2009-12-21 18:06 . 2009-12-21 18:07 -------- d-----w- c:\documents and settings\Sam\Application Data\Nokia
2009-12-21 18:06 . 2009-12-21 18:07 -------- d-----w- c:\documents and settings\Sam\Application Data\PC Suite
2009-12-21 18:06 . 2009-12-21 18:06 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Suite
2009-12-21 18:05 . 2009-12-21 18:05 -------- d-----w- c:\program files\Common Files\PCSuite
2009-12-21 18:04 . 2009-09-27 17:41 33773208 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Nokia_PC_Suite_7_1_30_9_eng_web.exe
2009-12-21 18:04 . 2009-12-21 18:04 95232 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\pcswpcsi.exe
2009-12-21 18:04 . 2009-12-21 18:04 8192 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstCCD.exe
2009-12-21 18:04 . 2009-12-21 18:04 61440 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2009-12-21 18:04 . 2009-12-21 18:04 10240 ----a-w- c:\documents and settings\All Users\Application Data\Installations\{3D39E775-DDDA-4327-B747-0BDC5F191331}\Installer\CommonCustomActions\UninstPCS.exe
2009-12-21 18:03 . 2009-12-21 18:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Installations
2009-12-21 15:46 . 2009-12-21 15:46 -------- d-----w- c:\windows\Sun
2009-12-17 07:08 . 2009-12-17 07:08 -------- d-----w- c:\documents and settings\Sam\fontconfig
2009-12-17 07:05 . 2009-12-27 11:12 -------- d-----w- c:\program files\MPlayer for Windows
2009-12-14 09:04 . 2009-12-15 09:08 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-12-14 09:04 . 2009-03-30 04:03 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-12-14 09:04 . 2009-02-13 05:59 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-12-14 09:04 . 2009-02-13 05:47 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-12-14 09:04 . 2009-12-14 09:04 -------- d-----w- c:\program files\Avira
2009-12-14 09:04 . 2009-12-14 09:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-12-03 03:01 . 2009-12-03 03:02 -------- d-----w- c:\documents and settings\Sam\Local Settings\Application Data\Ahead
2009-12-03 02:59 . 2009-12-05 09:46 -------- d-----w- c:\documents and settings\Sam\Application Data\Ahead
2009-12-03 02:59 . 2009-12-03 02:59 -------- d-----w- c:\documents and settings\All Users\Application Data\Ahead
2009-12-03 02:56 . 2009-12-03 02:58 -------- d-----w- c:\program files\Common Files\Ahead
2009-12-03 02:56 . 2009-12-03 02:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-12-03 02:56 . 2009-12-03 02:56 -------- d-----w- c:\program files\Nero
2009-12-02 17:51 . 2009-12-02 18:03 -------- d-----w- c:\documents and settings\Sam\Application Data\dvdcss
2009-11-30 21:37 . 2009-11-30 21:37 -------- d-----w- c:\windows\system32\KB905474
2009-11-30 21:37 . 2009-03-10 16:56 1403264 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-11-30 21:37 . 2009-03-10 16:48 453512 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2009-11-30 21:34 . 2004-08-03 19:26 221184 ----a-w- c:\windows\system32\wmpns.dll
2009-11-30 21:32 . 2009-11-30 21:32 -------- d-----w- c:\windows\ServicePackFiles
2009-11-30 00:07 . 2009-11-30 01:32 -------- d-----w- c:\windows\system32\CatRoot_bak
2009-11-29 23:08 . 2009-08-04 13:58 2136064 -c----w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-11-29 23:08 . 2009-08-04 14:00 2180352 -c----w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-11-29 23:08 . 2009-08-04 13:13 2015744 -c----w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-11-29 23:08 . 2009-08-04 13:13 2057728 -c----w- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-11-29 22:41 . 2008-10-24 11:10 453632 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-11-29 21:30 . 2008-07-09 07:38 26488 ----a-w- c:\windows\system32\spupdsvc.exe
2009-11-29 21:30 . 2009-11-30 21:38 -------- d--h--w- c:\windows\$hf_mig$
2009-11-29 19:16 . 2008-06-13 13:10 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-11-29 19:16 . 2008-06-13 13:10 272128 ------w- c:\windows\system32\drivers\bthport.sys
2009-11-29 18:45 . 2009-10-10 22:47 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-11-29 18:26 . 2009-11-29 18:32 -------- d-----w- c:\windows\SxsCaPendDel
2009-11-28 13:07 . 2001-08-17 08:18 12160 -c--a-w- c:\windows\system32\dllcache\mouhid.sys
2009-11-28 13:07 . 2001-08-17 08:18 12160 ----a-w- c:\windows\system32\drivers\mouhid.sys
2009-11-28 13:07 . 2001-08-17 08:32 9600 -c--a-w- c:\windows\system32\dllcache\hidusb.sys
2009-11-28 13:07 . 2001-08-17 08:32 9600 ----a-w- c:\windows\system32\drivers\hidusb.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-21 18:27 . 2009-12-21 18:27 0 ---ha-w- c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2009-12-21 18:27 . 2009-12-21 18:27 0 ---ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2009-12-21 18:06 . 2009-12-21 18:05 -------- d-----w- c:\program files\DIFX
2009-12-21 18:05 . 2009-12-21 18:05 -------- d-----w- c:\program files\Common Files\Nokia
2009-12-21 18:05 . 2009-12-21 18:04 -------- d-----w- c:\program files\Nokia
2009-12-21 18:05 . 2009-12-21 18:05 -------- d-----w- c:\program files\PC Connectivity Solution
2009-12-21 02:09 . 2009-11-26 20:58 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-30 16:00 . 2009-11-27 12:24 -------- d-----w- c:\documents and settings\Sam\Application Data\vlc
2009-11-29 18:33 . 2009-11-26 20:38 68456 ----a-w- c:\documents and settings\Sam\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-27 18:26 . 2009-11-27 18:26 -------- d-----w- c:\program files\Google
2009-11-27 11:52 . 2009-11-27 11:52 0 ----a-w- c:\windows\nsreg.dat
2009-11-26 21:15 . 2009-11-26 21:15 -------- d-----w- c:\program files\VideoLAN
2009-11-26 21:14 . 2009-11-26 21:14 -------- d-----w- c:\documents and settings\Sam\Application Data\Media Player Classic
2009-11-26 21:02 . 2009-11-26 21:02 -------- d-----w- c:\program files\K-Lite Codec Pack
2009-11-26 20:55 . 2009-11-26 20:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-11-26 20:54 . 2009-11-26 20:54 -------- d-----w- c:\program files\Microsoft Works
2009-11-26 20:53 . 2009-11-26 20:53 -------- d-----w- c:\program files\MSBuild
2009-11-26 20:35 . 2009-11-26 20:35 -------- d-----w- c:\program files\Intel
2009-11-26 20:35 . 2009-11-26 20:35 -------- d-----w- c:\program files\Synaptics
2009-11-26 20:35 . 2009-11-26 20:35 -------- d-----w- c:\program files\Common Files\InstallShield
2009-11-26 20:30 . 2009-11-26 20:30 -------- d-----w- c:\program files\GCC4243N_fw
2009-11-26 20:24 . 2009-11-26 20:24 -------- d-----w- c:\program files\WIDCOMM
2009-11-26 18:54 . 2009-11-26 18:27 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-26 18:28 . 2009-11-26 18:28 -------- d-----w- c:\program files\microsoft frontpage
2009-11-26 18:24 . 2009-11-26 18:24 21640 ----a-w- c:\windows\system32\emptyregdb.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2009-06-25 1414144]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-04 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-04 688218]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"MPlayerForWindows_UpdateReminder"="c:\program files\MPlayer for Windows\AutoUpdate.exe" [2009-12-06 254329]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-02 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2004-6-2 565309]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"d:\\Games\\CS\\COUNTER STRIKE\\COUNTER STRIKE\\Condition Zero\\czero.exe"=
"d:\\Games\\AOE\\age2_x1.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [12/14/2009 2:34 PM 108289]
.
------- Supplementary Scan -------
.
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send To &Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, [You must be registered and logged in to see this link.]
Rootkit scan 2009-12-28 01:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hȋdden processes ...

scanning hȋdden autostart entries ...

scanning hȋdden files ...

scan completed successfully
hȋdden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(764)
c:\windows\system32\msi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
c:\windows\system32\wscntfy.exe
c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclBCBTSrv.exe
c:\\?\c:\windows\system32\WBEM\WMIADAP.EXE
.
**************************************************************************
.
Completion time: 2009-12-28 01:03:14 - machine was rebooted
ComboFix-quarantined-files.txt 2009-12-27 19:33

Pre-Run: 898,711,552 bytes free
Post-Run: 871,034,880 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - F868D7911C66B80040031608D4EA7BD7

kshitij mathur
Novice
Novice

Posts Posts : 12
Joined Joined : 2009-12-21
OS OS : Windows XP Service Pack 2
Points Points : 25628
# Likes # Likes : 0

View user profile

Back to top Go down

Re: How to remove this virus/trojan DR/Delphi.Gen - Dropper ?

Post by Belahzur on 27th December 2009, 9:07 pm

Okay, run OTM one more time using this script.

:files
c:\documents and settings\Sam\Application Data\gnupg
c:\program files\uTorrent
c:\documents and settings\Sam\Application Data\uTorrent


[You must be registered and logged in to see this link.] - [You must be registered and logged in to see this link.] - Please PM me if I fail to respond within 24hrs.


Belahzur
Administrator
Administrator

Posts Posts : 34918
Joined Joined : 2008-08-03
Gender Gender : Male
OS OS : 7 Home Premium x64
Points Points : 245111
# Likes # Likes : 1

View user profile

Back to top Go down

View previous topic View next topic Back to top

- Similar topics

 
Permissions in this forum:
You cannot reply to topics in this forum