OTL and Extra - pasted and attached

Page 3 of 3 Previous  1, 2, 3

View previous topic View next topic Go down

Roguekiller/avg questions

Post by etrdave on Mon 03 Sep 2012, 2:29 am

First topic message reminder :

After running roguekiller, i have 6 SSDT's:
111 Nt notify change key
112 Nt notify change multiple keys
122 Nt open process
257 Nt terminate process
257 Nt terminate thread
258 Nt write virtual memory

I also have 4 S_SSDT's listed as unknown:
383, 414, 416, and 549

Is this a normal finding? What about the MBR finding?

RK 1 report is pasted below, followed by RK 9 report.
I have AVG, Spybot, and Malwarebytes:
RogueKiller V8.0.2 [08/31/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: [You must be registered and logged in to see this link.]
Blog: [You must be registered and logged in to see this link.]

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : David [Admin rights]
Mode : Scan -- Date : 09/01/2012 12:09:25

Bad processes : 0

Registry Entries : 2
[HJ SMENU] HKLM\[...]\Advanced : Start_ShowRecentDocs (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

Particular Files / Folders:

Driver : [LOADED]

Infection :

HOSTS File:
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 008k.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 032439.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 1001namen.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 100888290cs.com
127.0.0.1 [You must be registered and logged in to see this link.]
127.0.0.1 [You must be registered and logged in to see this link.]
[...]


MBR Check:

+++++ PhysicalDrive0: Hitachi HTS543216L9A300 +++++
--- User ---
[MBR] 7cb3943294ecd87e39cd94dc8f24b530
[BSP] 0639599f9f10526a8845373803eb7b9b : Acer tatooed MBR Code
Partition table:
0 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 63 | Size: 4996 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 10233405 | Size: 147628 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt

RogueKiller V8.0.2 [08/31/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: [You must be registered and logged in to see this link.]
Blog: [You must be registered and logged in to see this link.]

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : David [Admin rights]
Mode : Scan -- Date : 09/02/2012 08:02:08

Bad processes : 0

Registry Entries : 0

Particular Files / Folders:

Driver : [LOADED]

Infection :

HOSTS File:
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


MBR Check:

+++++ PhysicalDrive0: Hitachi HTS543216L9A300 +++++
--- User ---
[MBR] 7cb3943294ecd87e39cd94dc8f24b530
[BSP] 0639599f9f10526a8845373803eb7b9b : Acer tatooed MBR Code
Partition table:
0 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 63 | Size: 4996 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 10233405 | Size: 147628 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: SanDisk U3 Cruzer Micro USB Device +++++
--- User ---
[MBR] 36f0ad908b28843bd8a944b854b09a62
[BSP] 096ca65415799301792a33c93b5e78da : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT16 (0x06) [VISIBLE] Offset (sectors): 63 | Size: 971 Mo
User = LL1 ... OK!
Error reading LL2 MBR!

Finished : << RKreport[9].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt ; RKreport[4].txt ; RKreport[5].txt ;
RKreport[6].txt ; RKreport[7].txt ; RKreport[8].txt ; RKreport[9].txt








etrdave

Newbie Surfer
Newbie Surfer

Posts : 40
Joined : 2012-09-02
Operating System : xp home edition 2002 sp3

View user profile

Back to top Go down


Re: OTL and Extra - pasted and attached

Post by etrdave on Sun 16 Sep 2012, 12:49 am

At CMD /K SC QC WSCSVC, OpenService FAILED 1060 appears. The specified service does not exist as an installed service.

etrdave

Newbie Surfer
Newbie Surfer

Posts : 40
Joined : 2012-09-02
Operating System : xp home edition 2002 sp3

View user profile

Back to top Go down

Re: OTL and Extra - pasted and attached

Post by DragonMaster Jay on Sun 16 Sep 2012, 5:30 am

It is usual for us to only allow one topic per person at a time. Otherwise, it gets seriously confusing.

ComboFix

Please download ComboFix by sUBs
From BleepingComputer.com

Please save the file to your Desktop, but rename it first to svchost.exe

Important information about ComboFix

Before the download:

  • Please copy and paste these instructions to Notepad and save to your Desktop, or print them - for easier access.
  • It is important to rename ComboFix before the download.
  • Please do not rename ComboFix to other names, but only the one indicated.

After the download:

  • Close any open browsers.
  • Very Important: Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results". Please visit here if you don't know how.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until ComboFix has completely finished.
  • If there is no Internet connection after running ComboFix, then restart your computer to restore back your connection.

Running ComboFix:

  • Double click on svchost.exe & follow the prompts.
  • It will attempt to install the Recovery Console:


  • When ComboFix finishes, it will produce a report for you.
  • Please post the "C:\Combo-Fix.txt" in your next reply.

Troubleshooting ComboFix

Safe Mode:

If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there.

(To boot into Safe Mode, tap F8 after BIOS, and just before the Windows
logo appears. A list of options will appear, select "Safe Mode.")

Re-downloading:

If this doesn't work either, try the same method (above method), but try to download it again, except name
ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe.

Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe.


NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: OTL and Extra - pasted and attached

Post by etrdave on Sun 16 Sep 2012, 12:52 pm

Thanks for your help, but as it's been 2 weeks since my pc got infected I couldn't keep working at it at that pace, so I took it to the shop that built it today.

etrdave

Newbie Surfer
Newbie Surfer

Posts : 40
Joined : 2012-09-02
Operating System : xp home edition 2002 sp3

View user profile

Back to top Go down

Re: OTL and Extra - pasted and attached

Post by etrdave on Sun 16 Sep 2012, 12:56 pm

By the way...if someone posts asking whether or not they should be connected to the internet or should reconnect if they've disconnected, you really need to let them know. Just mho.

etrdave

Newbie Surfer
Newbie Surfer

Posts : 40
Joined : 2012-09-02
Operating System : xp home edition 2002 sp3

View user profile

Back to top Go down

Re: OTL and Extra - pasted and attached

Post by DragonMaster Jay on Sun 16 Sep 2012, 9:00 pm

Most of the time, when you have originally detected the malware issue, it means the computer is infected by malware of some sort. Antivirus scanners may not show a sign of the malware still being there, which could be a sign of a rootkit.

Whenever rootkit scanners, and antivirus software scan for the rootkit, it gets as close to the system kernel as possible. If the rootkit is beyond that point, it will not be detected.

So, the idea is, is when you post to a forum that you need help removing malware, it is best to stay with the helper, to ensure your computer is clean.

However, we all face issues helping our victims out. Because of being volunteers, we have to succumb to the demand of many victims of malware, not just one of two at a time.

For myself, I have a workrate of 30-40 victims per day that I assist. In that case, it is only best to keep things less confusing. Maintaining a level of professionalism is important on both sides of the spectrum, and we do our best to try to seek out the best answers.

All of the info posted is to help reveal malware entry points so we can find and target the malware. Sometimes logs cannot properly help diagnose the issue. Eventually, malware finds ways to get around our scanners.

If we did not use our scanners, and instead used third party products, we could not get enough info to make sure we can help to defeat the issue. So, these scanners are engineered by our staff, and corresponding staff to help bypass malware, and fully detect it.

Our wish would be that if you'd like help in the future, you would keep some of these principles in mind.

Since you have requested no more help, this topic is now closed.


[You must be registered and logged in to see this link.] - Get $30 off Kaspersky products.

~DMJ
GeekPolice Academy Manager


Donations/Contributions

DragonMaster Jay

Manager | Tech Officer
Manager | Tech Officer

Posts : 13451
Joined : 2009-09-07
Operating System : Windows 7 Ultimate

View user profile http://www.twitter.com/jaypfoutz

Back to top Go down

Re: OTL and Extra - pasted and attached

Post by Sponsored content Today at 7:46 am


Sponsored content


Back to top Go down

Page 3 of 3 Previous  1, 2, 3

View previous topic View next topic Back to top


 
Permissions in this forum:
You cannot reply to topics in this forum