1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Unable to Clean Win32 Olmarik Trojan

Discussion in 'Virus & Other Malware Removal' started by elsargente, Jan 27, 2011.

Thread Status:
Not open for further replies.
  1. elsargente

    elsargente Thread Starter

    Joined:
    Jan 27, 2011
    Messages:
    3
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 9:13:38 AM, on 1/27/2011
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16982)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User '?')
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
    O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    --
    End of file - 2129 bytes




    DDS (Ver_10-12-12.02) - NTFSx86
    Run by Phil at 9:14:04.16 on Thu 01/27/2011
    Internet Explorer: 7.0.6000.16982 BrowserJavaVersion: 1.6.0_07

    ============== Running Processes ===============


    ============== Pseudo HJT Report ===============

    uInternet Settings,ProxyOverride = <local>;*.local
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
    TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
    mPolicies-system: EnableLUA = 0 (0x0)
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab
    Notify: igfxcui - igfxdev.dll

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\phil\appdata\roaming\mozilla\firefox\profiles\evfnwmxy.default\
    FF - prefs.js: browser.startup.homepage - hxxp://google.com
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}

    ============= SERVICES / DRIVERS ===============


    =============== Created Last 30 ================

    2011-01-26 17:45:20 5890896 ----a-w- c:\progra~2\microsoft\windows defender\definition updates\{5a56e11c-a63a-47b0-a4ca-57e67b33bf27}\mpengine.dll
    2011-01-25 17:34:26 -------- d-----w- c:\users\phil\appdata\roaming\Malwarebytes
    2011-01-25 17:34:03 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2011-01-25 17:33:58 -------- d-----w- c:\progra~2\Malwarebytes
    2011-01-25 17:33:49 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2011-01-25 17:33:48 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2011-01-25 15:26:49 -------- d-----w- c:\users\phil\appdata\local\ESET
    2011-01-24 16:53:42 388096 ----a-r- c:\users\phil\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
    2011-01-24 16:53:39 -------- d-----w- c:\program files\Trend Micro
    2011-01-24 16:03:11 -------- d-----w- c:\program files\ESET
    2011-01-24 15:08:36 -------- d-----w- C:\4507a2973e65b29b582a8aa3953a
    2011-01-24 15:01:37 -------- d-----w- c:\program files\CONEXANT
    2011-01-24 15:00:18 -------- d-----w- c:\program files\VLC
    2011-01-24 14:54:14 311296 ----a-w- c:\windows\system32\unregmp2.exe
    2011-01-24 14:54:14 1418240 ----a-w- c:\program files\windows media player\setup_wm.exe
    2011-01-24 14:54:11 168960 ----a-w- c:\program files\windows media player\wmplayer.exe
    2011-01-24 14:54:10 7680 ----a-w- c:\windows\system32\spwmp.dll
    2011-01-24 14:54:09 4096 ----a-w- c:\windows\system32\msdxm.ocx
    2011-01-24 14:54:09 4096 ----a-w- c:\windows\system32\dxmasf.dll
    2011-01-24 14:54:09 107520 ----a-w- c:\program files\windows media player\wmpshare.exe
    2011-01-24 14:54:09 107520 ----a-w- c:\program files\windows media player\wmpconfig.exe
    2011-01-24 14:54:06 8147968 ----a-w- c:\windows\system32\wmploc.DLL
    2011-01-24 13:49:57 -------- d-----w- c:\windows\system32\MpEngineStore

    ==================== Find3M ====================

    2010-11-13 00:53:06 472808 ----a-w- c:\windows\system32\deployJava1.dll

    =================== ROOTKIT ====================

    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 6.0.6000 Disk: ST3120813AS rev.3.AAE -> Harddisk0\DR0 -> \Device\Ide\IdePort2 P2T0L0-3

    device: opened successfully
    user: MBR read successfully

    Disk trace:
    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll >>UNKNOWN [0x83ACBEE4]<<
    _asm { PUSH EBP; MOV EBP, ESP; SUB ESP, 0x50; PUSH EBX; PUSH ESI; MOV DWORD [EBP-0x4], 0xb0d52820; SUB DWORD [EBP-0x4], 0xb0d5212e; PUSH EDI; CALL 0xffffffffffffe10c; }
    1 nt!IofCallDriver[0x82067985] -> \Device\Harddisk0\DR0[0x834DB030]
    3 nt[0x820A80AF] -> nt!IofCallDriver[0x82067985] -> [0x833474A8]
    5 acpi[0x8047632A] -> nt!IofCallDriver[0x82067985] -> [0x83347BB0]
    [0x83BF4528] -> IRP_MJ_CREATE -> 0x83ACBEE4
    kernel: MBR read successfully
    _asm { XOR DI, DI; MOV SI, 0x200; MOV SS, DI; MOV SP, 0x7a00; MOV BX, 0x7a0; MOV CX, SI; MOV DS, BX; MOV ES, BX; REP MOVSB ; JMP FAR 0x7a0:0x5f; }
    detected disk devices:
    \Device\Ide\IdeDeviceP2T0L0-3 -> \??\IDE#DiskST3120813AS_____________________________3.AAE___#5&37fb79bb&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
    detected hooks:
    \Driver\atapi DriverStartIo -> 0x83ACBCE2
    user & kernel MBR OK
    sectors 234441646 (+225): user != kernel
    Warning: possible TDL3 rootkit infection !

    ============= FINISH: 9:15:23.59 ===============


    GMER 1.0.15.15530 - http://www.gmer.net
    Rootkit scan 2011-01-27 09:53:11
    Windows 6.0.6000 Harddisk0\DR0 -> \Device\Ide\IdePort2 ST3120813AS rev.3.AAE
    Running: unql9pys.exe; Driver: C:\Users\Phil\AppData\Local\Temp\pxrdipow.sys


    ---- System - GMER 1.0.15 ----

    SSDT 83A2DC90 ZwAssignProcessToJobObject
    SSDT 83A2E200 ZwDebugActiveProcess
    SSDT 83A2E2F0 ZwDuplicateObject
    SSDT 83A2D590 ZwOpenProcess
    SSDT 83A2DFD0 ZwProtectVirtualMemory
    SSDT 83A2E0E0 ZwQueueApcThread
    SSDT 83A2DEC0 ZwSetContextThread
    SSDT 83A2DD90 ZwSetInformationThread
    SSDT 83A2DB90 ZwSuspendProcess
    SSDT 83A2DA80 ZwSuspendThread
    SSDT 83A2D6E0 ZwTerminateProcess
    SSDT 83A2DA50 ZwTerminateThread
    SSDT 83A2E6D0 ZwWriteVirtualMemory

    ---- Kernel code sections - GMER 1.0.15 ----

    .text ntoskrnl.exe!_alloca_probe + D4 82055E44 4 Bytes [90, DC, A2, 83]
    .text ntoskrnl.exe!_alloca_probe + 1FC 82055F6C 4 Bytes [00, E2, A2, 83]
    .text ntoskrnl.exe!_alloca_probe + 230 82055FA0 4 Bytes [F0, E2, A2, 83]
    .text ntoskrnl.exe!_alloca_probe + 334 820560A4 4 Bytes [90, D5, A2, 83]
    .text ntoskrnl.exe!_alloca_probe + 374 820560E4 4 Bytes [D0, DF, A2, 83]
    .text ...
    .rsrc C:\Windows\System32\DRIVERS\RDPCDD.sys entry point in ".rsrc" section [0x85A8A014]
    ? C:\Users\Phil\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[784] kernel32.dll!SetUnhandledExceptionFilter 75DAD177 4 Bytes [C2, 04, 00, 00]
    .text C:\Program Files\Mozilla Firefox\firefox.exe[2312] ntdll.dll!LdrLoadDll 76E8EB00 5 Bytes JMP 000E13F0 C:\Program Files\Mozilla Firefox\firefox.exe (Firefox/Mozilla Corporation)
    .text C:\Program Files\Mozilla Firefox\plugin-container.exe[3048] USER32.dll!TrackPopupMenu 759FCFF8 5 Bytes JMP 6A702342 C:\Program Files\Mozilla Firefox\xul.dll (Mozilla Foundation)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
    AttachedDevice \Driver\tdx \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)

    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-0 83ACBCE2
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 83ACBCE2
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 83ACBCE2
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 83ACBCE2
    Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 83ACBCE2
    Device \Device\Ide\IdeDeviceP2T0L0-3 -> \??\IDE#DiskST3120813AS_____________________________3.AAE___#5&37fb79bb&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found

    ---- Disk sectors - GMER 1.0.15 ----

    Disk \Device\Harddisk0\DR0 sectors 234441421 (+225): rootkit-like behavior;

    ---- Files - GMER 1.0.15 ----

    File C:\Windows\System32\DRIVERS\RDPCDD.sys suspicious modification; TDL3 <-- ROOTKIT !!!

    ---- EOF - GMER 1.0.15 ----
     

    Attached Files:

  2. elsargente

    elsargente Thread Starter

    Joined:
    Jan 27, 2011
    Messages:
    3
  3. elsargente

    elsargente Thread Starter

    Joined:
    Jan 27, 2011
    Messages:
    3
    fixed problem with tdss killer... thanks for nothin :)
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/977314

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice