Not working
Dear Roni:
Thanks very much for your help. Unfortunately it did not work. After running exehelper I tried to open the DDS file and it came back to the screen where it asks to choose a program to open the file.
I'm attaching all of the logs I have got since I began with the 8 steps. I hope you can help me as I'm getting a little anxious about this.
Thanks in advance.
Alejandro.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4052
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
23/08/2010 10:50:09 p.m.
mbam-log-2010-08-23 (22-50-09).txt
Scan type: Quick scan
Objects scanned: 123027
Time elapsed: 40 minute(s), 40 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
__________________________________________________________________________________
GMER 1.0.15.15281 -
http://www.gmer.net
Rootkit scan 2010-08-24 00:35:55
Windows 5.1.2600 Service Pack 3
Running: 3o27pp0g.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\pwdoqkow.sys
---- System - GMER 1.0.15 ----
SSDT 858EB168 ZwAlertResumeThread
SSDT 857C4B00 ZwAlertThread
SSDT 85844CD0 ZwAllocateVirtualMemory
SSDT 859E84D8 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xEEBF6020]
SSDT 857CE908 ZwCreateMutant
SSDT 8593A308 ZwCreateThread
SSDT 85A7EF00 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xEEBF62A0]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xEEBF6800]
SSDT 857591D8 ZwFreeVirtualMemory
SSDT 85AAFEB0 ZwImpersonateAnonymousToken
SSDT 85AA5570 ZwImpersonateThread
SSDT 859189F8 ZwMapViewOfSection
SSDT 85B021B0 ZwOpenEvent
SSDT 857FD180 ZwOpenProcessToken
SSDT 85A77438 ZwOpenSection
SSDT 8585C4E8 ZwOpenThreadToken
SSDT 858D3C28 ZwResumeThread
SSDT 857381B8 ZwSetContextThread
SSDT 85A88108 ZwSetInformationProcess
SSDT 8585DE08 ZwSetInformationThread
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xEEBF6A50]
SSDT 85AB1AF0 ZwSuspendProcess
SSDT 8585E828 ZwSuspendThread
SSDT 858D3438 ZwTerminateProcess
SSDT 8584B158 ZwTerminateThread
SSDT 858BB220 ZwUnmapViewOfSection
SSDT 85814208 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.15 ----
.text ntoskrnl.exe!_abnormal_termination + F8 804E2754 4 Bytes JMP BF99ACD5 \SystemRoot\System32\win32k.sys (Multi-User Win32 Driver/Microsoft Corporation)
.text ntoskrnl.exe!_abnormal_termination + 250 804E28AC 4 Bytes CALL 83D3AE75
? kiilxea.sys The system cannot find the file specified. !
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp fssfltr_tdi.sys (Family Safety Filter Driver (TDI)/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update@OfflineDetectionPending 1
---- EOF - GMER 1.0.15 ----
_________________________________________________________________________________________
This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.
Ran as Owner on 24/08/2010 at 20:07:16.
Processes terminated by Rkill or while it was running:
C:\Documents and Settings\Owner\Desktop\8 steps\rkill.com
Rkill completed on 24/08/2010 at 20:07:26.
_______________________________________________________________________________________
exeHelper by Raktor
Build 20100414
Run at 20:09:05 on 08/24/10
Now searching...
Checking for numerical processes...
Checking for sysguard processes...
Checking for bad processes...
Checking for bad files...
Checking for bad registry entries...
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values...
Resetting policies...
--Finished--