Hello Bobbye,
First of all I would like to say thank you for your response. Secondly, I wasn't aware that you have change your reply. I already did (not all, I haven't perform the last one which is DDS) what you have said earlier last night. So I will paste the logs here I have.
Things you may wanna know:
After doing so what is instructed in "
UPDATED 5-step Viruses/Spyware/Malware Preliminary Removal Instructions", my PC got
SLOWER like 3-4 times (ex may PC boot start-up is 20secs, now it takes me 1min or more to go into my windows and when I browse the internet or open an application, its really slow.) This slow-thing happened after the GMER scan, I guess. (Note: when I ran the GMER it performed like a real quick scan. I'm not sure if that was really a scan because there was no log after. So I did
click scan. I thought the scan will end up very soon. But after like an hour it's still scanning. I was thinking that I did this wrong, so I had just to stop it.)
Please help. Would you recommend to system restore? Thanks for you response.
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8025
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
10/27/2011 7:00:58 AM
mbam-log-2011-10-27 (07-00-58).txt
Scan type: Quick scan
Objects scanned: 158683
Time elapsed: 10 minute(s), 45 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 14
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Btdsdt (Trojan.Agent) -> Value: Btdsdt -> Delete on reboot.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\documents and settings\jun\application data\btdsdt.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\153D.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\237.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\74.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\76.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\C.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\E64.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\1C.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\46.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\18.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\application data\3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\local settings\Temp;\acd\tasker.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\local settings\Temp;\acd\taskr.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
c:\documents and settings\Jun\local settings\Temp;\acd\tasks.exe (Trojan.BCMiner) -> Quarantined and deleted successfully.
**GMER LOG**
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2011-10-27 08:40:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-e ST340014A rev.3.04
Running: 1o89xn4h.exe; Driver: C:\DOCUME~1\Jun\LOCALS~1\TEMP_~1\pgliipoc.sys
---- Kernel code sections - GMER 1.0.15 ----
? xvcelyl.sys The system cannot find the file specified. !
---- User code sections - GMER 1.0.15 ----
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 00, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtMapViewOfSection + 6 7C90D524 1 Byte [28]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 03, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 00, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 01, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B90EC1A
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 02, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 01, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 02, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B90EC8B
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 00, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B90EDB9
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 01, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 02, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 1 Byte [68]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 03, 16, 00]
.text C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[916] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002C0010
IAT C:\Documents and Settings\Jun\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1360] @ C:\WINDOWS\system32\RPCRT4.dll [KERNEL32.dll!CreateNamedPipeW] 002C0010
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272c2098d
Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\000272c2098d@6c9b026c9c00 0x42 0xB1 0x21 0x24 ...
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272c2098d (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\000272c2098d@6c9b026c9c00 0x42 0xB1 0x21 0x24 ...
---- EOF - GMER 1.0.15 ----
P.S:
Microsoft Essentials Security does not detecting those viruses anymore, for now. I guess it was completely removed after scanning with Malwarebytes.