Two Plus Two Publishing LLC Two Plus Two Publishing LLC
 

Go Back   Two Plus Two Poker Forums > >

Notices

Computer Technical Help Post your questions about computer hardware and software and configuring same here.

Reply
 
Thread Tools Display Modes
Old 01-01-2012, 01:55 PM   #26
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

  • Please run OTL.exe again
  • Under the Custom Scans/Fixes box at the bottom, copy and paste in the following:
Code:
:files
C:\32788R22FWJFW
C:\myapp
C:\ProgramData\{CC6525B7-42F2-42DB-BF33-445E26F52EC1}
C:\ProgramData\BDJ
C:\Users\Sumit\AppData\Local\cmkk080234g6b6e418wo3736s778sk14tmsf3rj
C:\ProgramData\cmkk080234g6b6e418wo3736s778sk14tmsf3rj
C:\ProgramData\rgtr.exe
C:\ProgramData\ppft.exe
C:\ProgramData\pltf.exe
C:\ProgramData\mher.exe

:otl
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.

:commands
[reboot]
  • Then click the Run Fix button at the top (Not the Run Scan!).
  • Allow it to run. It may take some time and you may see some things happen to your desktop - this is normal.
  • If it asks to reboot the computer, allow it to reboot.
  • If the program freezes, and the computer fails to reboot - let me know.
  • Finally, post the contents of the log. (Located at C:\_OTL\Moved Files)
====================

This will delete some malware files I found, but I donīt think it will solve your problem.

Do you have redirects only on chrome or also in Firefox / Internet explorer?
Are you able to lay your hand on a WIN7 64-bit setup disk?

====================
  • Please download MBRCheck by a_d_13 from either of the following mirrors and save it to your Desktop.
  • Double click MBRCheck.exe to run it (right click > Run as Administrator for Vista and WIN7)
  • It will show a black screen with a report of what has been found.
  • Exit from the program, also if an infection is found.
  • The report can be found on your desktop, named MBRCheckxxxx.txt
  • Please post the contents of that report in your next reply.

Last edited by Gabethebabe; 01-01-2012 at 02:13 PM.
Gabethebabe is offline   Reply With Quote
Old 01-01-2012, 04:15 PM   #27
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

The OTL Moved Files log:

========== FILES ==========
C:\32788R22FWJFW\N_ folder moved successfully.
C:\32788R22FWJFW\License folder moved successfully.
C:\32788R22FWJFW\EN-US folder moved successfully.
C:\32788R22FWJFW\en-CA folder moved successfully.
C:\32788R22FWJFW folder moved successfully.
C:\myapp folder moved successfully.
C:\ProgramData\{CC6525B7-42F2-42DB-BF33-445E26F52EC1}\{0131D7EF-65FF-478F-8ABD-5ABEE24EC8EF} folder moved successfully.
C:\ProgramData\{CC6525B7-42F2-42DB-BF33-445E26F52EC1} folder moved successfully.
C:\ProgramData\BDJ\BindingUnit\-886-45-31-103-10-38-3637-1-86-88169796-5714-106-11018\ffffd54d\1963b93f68564d638dadb74d0a293987 folder moved successfully.
C:\ProgramData\BDJ\BindingUnit\-886-45-31-103-10-38-3637-1-86-88169796-5714-106-11018\ffffd54d folder moved successfully.
C:\ProgramData\BDJ\BindingUnit\-886-45-31-103-10-38-3637-1-86-88169796-5714-106-11018 folder moved successfully.
C:\ProgramData\BDJ\BindingUnit folder moved successfully.
C:\ProgramData\BDJ\ApplicationData\lfm folder moved successfully.
C:\ProgramData\BDJ\ApplicationData\-886-45-31-103-10-38-3637-1-86-88169796-5714-106-11018\ffffd54d\5804 folder moved successfully.
C:\ProgramData\BDJ\ApplicationData\-886-45-31-103-10-38-3637-1-86-88169796-5714-106-11018\ffffd54d folder moved successfully.
C:\ProgramData\BDJ\ApplicationData\-886-45-31-103-10-38-3637-1-86-88169796-5714-106-11018 folder moved successfully.
C:\ProgramData\BDJ\ApplicationData folder moved successfully.
C:\ProgramData\BDJ folder moved successfully.
C:\Users\Sumit\AppData\Local\cmkk080234g6b6e418wo3 736s778sk14tmsf3rj moved successfully.
C:\ProgramData\cmkk080234g6b6e418wo3736s778sk14tms f3rj moved successfully.
C:\ProgramData\rgtr.exe moved successfully.
C:\ProgramData\ppft.exe moved successfully.
C:\ProgramData\pltf.exe moved successfully.
C:\ProgramData\mher.exe moved successfully.
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8 A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
========== COMMANDS ==========

OTL by OldTimer - Version 3.2.31.0 log created on 01012012_150735

=============================================

And the MRBCheck log:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Sony Corporation
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: Sony Corporation
System Product Name: VPCF2290S
Logical Drives Mask: 0x00000014

Kernel Drivers (total 204):
0x02E56000 \SystemRoot\system32\ntoskrnl.exe
0x02E0D000 \SystemRoot\system32\hal.dll
0x00BCE000 \SystemRoot\system32\kdcom.dll
0x00CCD000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D1C000 \SystemRoot\system32\PSHED.dll
0x00D30000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00E27000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00ECB000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00EDA000 \SystemRoot\system32\drivers\ACPI.sys
0x00F31000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00F3A000 \SystemRoot\system32\drivers\msisadrv.sys
0x00F44000 \SystemRoot\system32\drivers\pci.sys
0x00F77000 \SystemRoot\system32\drivers\vdrvroot.sys
0x00F84000 \SystemRoot\System32\drivers\partmgr.sys
0x00F99000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00FA2000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00FAE000 \SystemRoot\system32\drivers\volmgr.sys
0x00D8E000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FC3000 \SystemRoot\System32\drivers\mountmgr.sys
0x0107B000 \SystemRoot\system32\drivers\iaStor.sys
0x011CF000 \SystemRoot\system32\drivers\amdxata.sys
0x01000000 \SystemRoot\system32\drivers\fltmgr.sys
0x0104C000 \SystemRoot\system32\drivers\fileinfo.sys
0x01060000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x01246000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01428000 \SystemRoot\System32\Drivers\msrpc.sys
0x01486000 \SystemRoot\System32\Drivers\ksecdd.sys
0x014A1000 \SystemRoot\System32\Drivers\cng.sys
0x01513000 \SystemRoot\System32\drivers\pcw.sys
0x01524000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016EF000 \SystemRoot\system32\drivers\ndis.sys
0x01600000 \SystemRoot\system32\drivers\NETIO.SYS
0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x018B5000 \SystemRoot\System32\drivers\tcpip.sys
0x01AB9000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01B03000 \SystemRoot\system32\drivers\volsnap.sys
0x01B4F000 \SystemRoot\System32\Drivers\spldr.sys
0x01B57000 \SystemRoot\System32\drivers\rdyboost.sys
0x01B91000 \SystemRoot\System32\Drivers\mup.sys
0x01BA3000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01BAC000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01BE6000 \SystemRoot\system32\drivers\disk.sys
0x01800000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x02F7D000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0152E000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x02FA7000 \SystemRoot\System32\Drivers\Null.SYS
0x02FB0000 \SystemRoot\System32\Drivers\Beep.SYS
0x02FB7000 \SystemRoot\System32\drivers\vga.sys
0x02FC5000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02FEA000 \SystemRoot\System32\drivers\watchdog.sys
0x02E00000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x02E09000 \SystemRoot\system32\drivers\rdpencdd.sys
0x0183E000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01847000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01852000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01863000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01885000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x01892000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x044A7000 \SystemRoot\system32\drivers\afd.sys
0x04530000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x0453D000 \SystemRoot\System32\DRIVERS\netbt.sys
0x04582000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x0458B000 \SystemRoot\system32\DRIVERS\pacer.sys
0x045B1000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x045C7000 \SystemRoot\system32\DRIVERS\netbios.sys
0x045D6000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x04400000 \SystemRoot\system32\DRIVERS\termdd.sys
0x04414000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x04465000 \SystemRoot\system32\drivers\nsiproxy.sys
0x04471000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x0447C000 \SystemRoot\System32\drivers\discache.sys
0x0168B000 \SystemRoot\System32\Drivers\dfsc.sys
0x0448B000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x04A7E000 \SystemRoot\System32\Drivers\aswSP.SYS
0x04ACF000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0F218000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x0FE8E000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x0FE90000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x0FF84000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0FFCA000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0FFEE000 \SystemRoot\system32\DRIVERS\HECIx64.sys
0x0F200000 \SystemRoot\system32\drivers\usbehci.sys
0x04AF5000 \SystemRoot\system32\drivers\USBPORT.SYS
0x04CC5000 \SystemRoot\system32\DRIVERS\athrx.sys
0x04F6B000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x04F78000 \SystemRoot\system32\DRIVERS\risdsnxc64.sys
0x04F96000 \SystemRoot\system32\DRIVERS\rimssne64.sys
0x04FB8000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x04C00000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x04C31000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x04C33000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x04C9A000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x04B4B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x05289000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x053E6000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x053F5000 \SystemRoot\system32\DRIVERS\SFEP.sys
0x05200000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x05209000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x0521F000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x05224000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x05234000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x0524A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x0526E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04B5A000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04B89000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04BA4000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04BC5000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x0527A000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04A00000 \SystemRoot\system32\DRIVERS\ks.sys
0x04A43000 \SystemRoot\system32\DRIVERS\umbus.sys
0x0588E000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x058E8000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x05901000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x05916000 \SystemRoot\system32\drivers\nvhda64v.sys
0x05943000 \SystemRoot\system32\drivers\portcls.sys
0x05980000 \SystemRoot\system32\drivers\drmk.sys
0x059A2000 \SystemRoot\system32\drivers\ksthunk.sys
0x06A55000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x06CF1000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06D0E000 \SystemRoot\System32\Drivers\usbvideo.sys
0x06D3C000 \SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
0x06E82000 \SystemRoot\system32\DRIVERS\btwampfl.sys
0x07172000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x0717B000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x06D46000 \SystemRoot\System32\Drivers\bthport.sys
0x000E0000 \SystemRoot\System32\win32k.sys
0x07193000 \SystemRoot\System32\drivers\Dxapi.sys
0x0719F000 \SystemRoot\System32\Drivers\crashdmp.sys
0x02E12000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x071AD000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x071C0000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x071EC000 \SystemRoot\system32\drivers\BthEnum.sys
0x06E00000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x05800000 \SystemRoot\system32\DRIVERS\btwavdt.sys
0x02020000 \SystemRoot\system32\drivers\btwaudio.sys
0x020B5000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
0x020C3000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0x020C7000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x020E0000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00450000 \SystemRoot\System32\TSDDD.dll
0x006F0000 \SystemRoot\System32\cdd.dll
0x020EE000 \SystemRoot\system32\drivers\luafv.sys
0x02111000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x0214D000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x02156000 \SystemRoot\system32\drivers\WudfPf.sys
0x02177000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x0218C000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x021DF000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x02000000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0B879000 \SystemRoot\system32\drivers\HTTP.sys
0x0B942000 \SystemRoot\system32\DRIVERS\bowser.sys
0x0B960000 \SystemRoot\System32\drivers\mpsdrv.sys
0x0B978000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x0B9A5000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0B800000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x0B824000 \??\C:\Windows\system32\drivers\regi.sys
0x0BE25000 \SystemRoot\system32\drivers\peauth.sys
0x0BECB000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0BED6000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0BF07000 \SystemRoot\System32\drivers\tcpipreg.sys
0x0BF19000 \SystemRoot\System32\DRIVERS\srv2.sys
0x0C2A7000 \SystemRoot\System32\DRIVERS\srv.sys
0x0C33F000 \SystemRoot\system32\drivers\spsys.sys
0x77090000 \Windows\System32\ntdll.dll
0x47BA0000 \Windows\System32\smss.exe
0xFF3B0000 \Windows\System32\apisetschema.dll
0xFFAA0000 \Windows\System32\autochk.exe
0xFF390000 \Windows\System32\nsi.dll
0xFF370000 \Windows\System32\imagehlp.dll
0x76F40000 \Windows\System32\urlmon.dll
0xFF190000 \Windows\System32\setupapi.dll
0xFF080000 \Windows\System32\msctf.dll
0xFEFA0000 \Windows\System32\oleaut32.dll
0xFED90000 \Windows\System32\ole32.dll
0x76E20000 \Windows\System32\kernel32.dll
0xFED10000 \Windows\System32\difxapi.dll
0xFEBE0000 \Windows\System32\rpcrt4.dll
0xFEB80000 \Windows\System32\Wldap32.dll
0xFEAE0000 \Windows\System32\clbcatq.dll
0xFEAC0000 \Windows\System32\sechost.dll
0x77260000 \Windows\System32\normaliz.dll
0xFDD30000 \Windows\System32\shell32.dll
0xFDC50000 \Windows\System32\advapi32.dll
0xFDC20000 \Windows\System32\imm32.dll
0xFDBA0000 \Windows\System32\shlwapi.dll
0xFDB50000 \Windows\System32\ws2_32.dll
0xFDAB0000 \Windows\System32\comdlg32.dll
0x76CC0000 \Windows\System32\wininet.dll
0xFDA10000 \Windows\System32\msvcrt.dll
0x76AB0000 \Windows\System32\iertutil.dll
0xFD9A0000 \Windows\System32\gdi32.dll
0x77250000 \Windows\System32\psapi.dll
0xFD990000 \Windows\System32\lpk.dll
0x769B0000 \Windows\System32\user32.dll
0xFD8C0000 \Windows\System32\usp10.dll
0xFD750000 \Windows\System32\crypt32.dll
0xFD730000 \Windows\System32\devobj.dll
0xFD6F0000 \Windows\System32\wintrust.dll
0xFD6B0000 \Windows\System32\cfgmgr32.dll
0xFD640000 \Windows\System32\KernelBase.dll
0xFD5A0000 \Windows\System32\comctl32.dll
0xFD590000 \Windows\System32\msasn1.dll
0x75120000 \Windows\SysWOW64\normaliz.dll

Processes (total 90):
0 System Idle Process
4 System
392 C:\Windows\System32\smss.exe
572 csrss.exe
656 C:\Windows\System32\wininit.exe
676 csrss.exe
724 C:\Windows\System32\services.exe
732 C:\Windows\System32\lsass.exe
740 C:\Windows\System32\lsm.exe
848 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\nvvsvc.exe
984 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\winlogon.exe
504 C:\Windows\System32\svchost.exe
832 C:\Windows\System32\svchost.exe
1036 C:\Windows\System32\svchost.exe
1064 C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1140 C:\Windows\System32\audiodg.exe
1192 C:\Windows\System32\svchost.exe
1280 C:\Windows\System32\svchost.exe
1424 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1436 C:\Windows\System32\nvvsvc.exe
1548 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1556 C:\Windows\System32\wlanext.exe
1564 C:\Windows\System32\conhost.exe
1736 C:\Windows\System32\dwm.exe
1760 C:\Windows\explorer.exe
1940 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1948 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1212 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
1528 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
704 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
1752 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrobat_sl.exe
1808 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
1908 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
2284 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
2292 C:\Program Files\AVAST Software\Avast\AvastUI.exe
2432 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2440 C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
2588 dllhost.exe
2636 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
2992 C:\Windows\System32\spoolsv.exe
3008 taskeng.exe
1184 C:\Windows\System32\svchost.exe
2368 C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
1088 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
2692 C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
2836 C:\Windows\System32\svchost.exe
2736 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
3152 C:\Windows\System32\taskhost.exe
3196 C:\Windows\System32\taskeng.exe
3236 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
3296 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
3324 C:\Windows\System32\svchost.exe
3356 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
3496 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3504 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3576 dllhost.exe
3924 dllhost.exe
2896 C:\Windows\System32\svchost.exe
3016 C:\Windows\System32\SearchIndexer.exe
2912 WmiPrvSE.exe
4640 C:\Program Files\Windows Media Player\wmpnetwk.exe
4848 C:\Windows\System32\svchost.exe
4296 C:\Windows\SysWOW64\rundll32.exe
4720 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
4908 C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
4888 C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
4524 C:\Windows\System32\SearchProtocolHost.exe
5160 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
5628 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
6040 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
148 C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
4760 WmiPrvSE.exe
5996 C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
6080 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
4340 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
1412 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
892 C:\Program Files\Sony\VAIO Care\VCPerfService.exe
5400 C:\Program Files\Sony\VAIO Care\listener.exe
5220 C:\Windows\System32\sppsvc.exe
4584 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
3392 C:\Program Files\Sony\VAIO Power Management\SPMService.exe
1980 C:\Windows\System32\svchost.exe
5964 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
1164 taskhost.exe
1776 C:\Users\Sumit\Desktop\MBRCheck.exe
5512 C:\Windows\System32\SearchFilterHost.exe
5428 C:\Windows\System32\conhost.exe
5312 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000004`0bc00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS545050B9SA00, Rev: PB4OC60X

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!
=============================================

As for the re-directs, I mainly use Firefox. I do use Chrome every now and then, and the problem is on both browser. I will search high and low for a Windows 7 disk.
SGicz is offline   Reply With Quote
Old 01-02-2012, 08:53 AM   #28
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Lets see if mbrcheck can fix the problem.

Warning - the fix below will overwrite your infected Master Boot Record (MBR) with a clean standard MBR. If you had a non-standard MBR, e.g. some computer brands like Dell sometimes alter the MBR to enable a startup option to revert to factory settings or you have something like GRUB installed, you will lose this functionality when the standard MBR is written. Do not proceed if you had a non-standard MBR and wish to maintain that functionality. Also note that overwriting the MBR is usually problemless, but it doesnīt hurt to have good backups available in case things go wrong.
  • Doubleclick MBRCheck.exe to run it
  • Choose Y for more options, 2 for restoring the MBR and 0 for the physical disk number
  • From the list of MBRs, choose the one that corresponds with your operating system
  • Choose Y when asked for confirmation
  • The MBR will be written and the black window will show a report
  • Left click the title bar of the black window and choose Edit > Select All
  • Hit enter to copy the highlighted contents and paste it into your next reply.
Gabethebabe is offline   Reply With Quote
Old 01-02-2012, 11:37 AM   #29
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

The information in the black box is the same as a log it generated:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Sony Corporation
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: Sony Corporation
System Product Name: VPCF2290S
Logical Drives Mask: 0x00000014

Kernel Drivers (total 203):
0x02E65000 \SystemRoot\system32\ntoskrnl.exe
0x02E1C000 \SystemRoot\system32\hal.dll
0x00BBA000 \SystemRoot\system32\kdcom.dll
0x00C19000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00C68000 \SystemRoot\system32\PSHED.dll
0x00C7C000 \SystemRoot\system32\CLFS.SYS
0x00CDA000 \SystemRoot\system32\CI.dll
0x00EFB000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F9F000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00E00000 \SystemRoot\system32\drivers\ACPI.sys
0x00E57000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00E60000 \SystemRoot\system32\drivers\msisadrv.sys
0x00E6A000 \SystemRoot\system32\drivers\pci.sys
0x00E9D000 \SystemRoot\system32\drivers\vdrvroot.sys
0x00EAA000 \SystemRoot\System32\drivers\partmgr.sys
0x00EBF000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00EC8000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00ED4000 \SystemRoot\system32\drivers\volmgr.sys
0x00D9A000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FAE000 \SystemRoot\System32\drivers\mountmgr.sys
0x0101D000 \SystemRoot\system32\drivers\iaStor.sys
0x01171000 \SystemRoot\system32\drivers\amdxata.sys
0x0117C000 \SystemRoot\system32\drivers\fltmgr.sys
0x011C8000 \SystemRoot\system32\drivers\fileinfo.sys
0x011DC000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x0121B000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01427000 \SystemRoot\System32\Drivers\msrpc.sys
0x01485000 \SystemRoot\System32\Drivers\ksecdd.sys
0x014A0000 \SystemRoot\System32\Drivers\cng.sys
0x01512000 \SystemRoot\System32\drivers\pcw.sys
0x01523000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016D9000 \SystemRoot\system32\drivers\ndis.sys
0x01600000 \SystemRoot\system32\drivers\NETIO.SYS
0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x018AC000 \SystemRoot\System32\drivers\tcpip.sys
0x01AB0000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01AFA000 \SystemRoot\system32\drivers\volsnap.sys
0x01B46000 \SystemRoot\System32\Drivers\spldr.sys
0x01B4E000 \SystemRoot\System32\drivers\rdyboost.sys
0x01B88000 \SystemRoot\System32\Drivers\mup.sys
0x01B9A000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01BA3000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01BDD000 \SystemRoot\system32\drivers\disk.sys
0x01800000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x043BA000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0152D000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x043E4000 \SystemRoot\System32\Drivers\Null.SYS
0x043ED000 \SystemRoot\System32\Drivers\Beep.SYS
0x04200000 \SystemRoot\System32\drivers\vga.sys
0x0420E000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x04233000 \SystemRoot\System32\drivers\watchdog.sys
0x04243000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x043F4000 \SystemRoot\system32\drivers\rdpencdd.sys
0x0183E000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01847000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01852000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01863000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01885000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x01892000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x02EFA000 \SystemRoot\system32\drivers\afd.sys
0x02F83000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x02F90000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02FD5000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x02E00000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02E26000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x02E3C000 \SystemRoot\system32\DRIVERS\netbios.sys
0x02E4B000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x02E66000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02E7A000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02ECB000 \SystemRoot\system32\drivers\nsiproxy.sys
0x02ED7000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02EE2000 \SystemRoot\System32\drivers\discache.sys
0x02FDE000 \SystemRoot\System32\Drivers\dfsc.sys
0x0168B000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x04601000 \SystemRoot\System32\Drivers\aswSP.SYS
0x04652000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0F23B000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x0FEB1000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x0FEB3000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x0FFA7000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0F200000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0F224000 \SystemRoot\system32\DRIVERS\HECIx64.sys
0x0FFED000 \SystemRoot\system32\drivers\usbehci.sys
0x04678000 \SystemRoot\system32\drivers\USBPORT.SYS
0x04CEA000 \SystemRoot\system32\DRIVERS\athrx.sys
0x04F90000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x04F9D000 \SystemRoot\system32\DRIVERS\risdsnxc64.sys
0x04FBB000 \SystemRoot\system32\DRIVERS\rimssne64.sys
0x04C00000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x04C3E000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x04C6F000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x04C71000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x04FDD000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x04CD8000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x0548A000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x055E7000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x055F6000 \SystemRoot\system32\DRIVERS\SFEP.sys
0x05400000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x05409000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x0541F000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x05424000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x05434000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x0544A000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x0546E000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x046CE000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x046FD000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04718000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04739000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x0547A000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04753000 \SystemRoot\system32\DRIVERS\ks.sys
0x04796000 \SystemRoot\system32\DRIVERS\umbus.sys
0x058CD000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x05927000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x05940000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x05955000 \SystemRoot\system32\drivers\nvhda64v.sys
0x05982000 \SystemRoot\system32\drivers\portcls.sys
0x059BF000 \SystemRoot\system32\drivers\drmk.sys
0x059E1000 \SystemRoot\system32\drivers\ksthunk.sys
0x06A2E000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x00040000 \SystemRoot\System32\win32k.sys
0x06CCA000 \SystemRoot\System32\drivers\Dxapi.sys
0x06CD6000 \SystemRoot\System32\Drivers\crashdmp.sys
0x0424C000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x06CE4000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x06CF7000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00550000 \SystemRoot\System32\TSDDD.dll
0x00630000 \SystemRoot\System32\cdd.dll
0x06D05000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06D22000 \SystemRoot\System32\Drivers\usbvideo.sys
0x06D50000 \SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
0x06E5B000 \SystemRoot\system32\DRIVERS\btwampfl.sys
0x0714B000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x07154000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x0716C000 \SystemRoot\System32\Drivers\bthport.sys
0x06E00000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x06E2C000 \SystemRoot\system32\drivers\BthEnum.sys
0x06D5A000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x06D7A000 \SystemRoot\system32\DRIVERS\btwavdt.sys
0x05800000 \SystemRoot\system32\drivers\btwaudio.sys
0x06E3C000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
0x06E4A000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0x06A00000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x05895000 \SystemRoot\system32\drivers\luafv.sys
0x047A8000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x06E4E000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x0169C000 \SystemRoot\system32\drivers\WudfPf.sys
0x06A19000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x05641000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x05694000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x056A7000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x056BF000 \SystemRoot\system32\drivers\HTTP.sys
0x05788000 \SystemRoot\system32\DRIVERS\bowser.sys
0x057A6000 \SystemRoot\System32\drivers\mpsdrv.sys
0x057BE000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x0AE95000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0AEE3000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x0AF07000 \??\C:\Windows\system32\drivers\regi.sys
0x0AF0F000 \SystemRoot\system32\drivers\peauth.sys
0x0AFB5000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0AFC0000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0AE00000 \SystemRoot\System32\drivers\tcpipreg.sys
0x0AE12000 \SystemRoot\System32\DRIVERS\srv2.sys
0x0B6FE000 \SystemRoot\System32\DRIVERS\srv.sys
0x77180000 \Windows\System32\ntdll.dll
0x47D80000 \Windows\System32\smss.exe
0xFF4A0000 \Windows\System32\apisetschema.dll
0xFF520000 \Windows\System32\autochk.exe
0xFF380000 \Windows\System32\msctf.dll
0x77020000 \Windows\System32\wininet.dll
0xFF2B0000 \Windows\System32\usp10.dll
0xFF290000 \Windows\System32\sechost.dll
0xFF1B0000 \Windows\System32\advapi32.dll
0xFF140000 \Windows\System32\gdi32.dll
0x77350000 \Windows\System32\normaliz.dll
0xFF010000 \Windows\System32\rpcrt4.dll
0xFE280000 \Windows\System32\shell32.dll
0xFE070000 \Windows\System32\ole32.dll
0xFDFD0000 \Windows\System32\clbcatq.dll
0xFDDF0000 \Windows\System32\setupapi.dll
0xFDD70000 \Windows\System32\difxapi.dll
0xFDD10000 \Windows\System32\Wldap32.dll
0x76F00000 \Windows\System32\kernel32.dll
0xFDD00000 \Windows\System32\lpk.dll
0x76E00000 \Windows\System32\user32.dll
0x77340000 \Windows\System32\psapi.dll
0x76BF0000 \Windows\System32\iertutil.dll
0xFDC20000 \Windows\System32\oleaut32.dll
0xFDC00000 \Windows\System32\imagehlp.dll
0xFDB80000 \Windows\System32\shlwapi.dll
0xFDAE0000 \Windows\System32\comdlg32.dll
0xFDAB0000 \Windows\System32\imm32.dll
0xFDA10000 \Windows\System32\msvcrt.dll
0xFDA00000 \Windows\System32\nsi.dll
0xFD9B0000 \Windows\System32\ws2_32.dll
0x76AA0000 \Windows\System32\urlmon.dll
0xFD910000 \Windows\System32\comctl32.dll
0xFD8D0000 \Windows\System32\wintrust.dll
0xFD8B0000 \Windows\System32\devobj.dll
0xFD840000 \Windows\System32\KernelBase.dll
0xFD6D0000 \Windows\System32\crypt32.dll
0xFD690000 \Windows\System32\cfgmgr32.dll
0xFD680000 \Windows\System32\msasn1.dll
0x77330000 \Windows\SysWOW64\normaliz.dll

Processes (total 92):
0 System Idle Process
4 System
392 C:\Windows\System32\smss.exe
556 csrss.exe
632 C:\Windows\System32\wininit.exe
652 csrss.exe
700 C:\Windows\System32\services.exe
712 C:\Windows\System32\lsass.exe
724 C:\Windows\System32\lsm.exe
856 C:\Windows\System32\svchost.exe
912 C:\Windows\System32\winlogon.exe
968 C:\Windows\System32\nvvsvc.exe
1008 C:\Windows\System32\svchost.exe
708 C:\Windows\System32\svchost.exe
452 C:\Windows\System32\svchost.exe
1036 C:\Windows\System32\svchost.exe
1064 C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1208 C:\Windows\System32\svchost.exe
1292 C:\Windows\System32\svchost.exe
1396 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1408 C:\Windows\System32\nvvsvc.exe
1524 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1532 C:\Windows\System32\wlanext.exe
1540 C:\Windows\System32\conhost.exe
1736 C:\Windows\System32\dwm.exe
1764 C:\Windows\explorer.exe
1928 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1940 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1328 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2108 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
2116 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
2240 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
2272 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
2496 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
2504 C:\Program Files\AVAST Software\Avast\AvastUI.exe
2536 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2588 dllhost.exe
2620 C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
2728 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
1164 C:\Windows\System32\spoolsv.exe
2372 C:\Windows\System32\svchost.exe
2332 C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
2456 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
2896 C:\Windows\System32\taskhost.exe
2936 C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
2352 C:\Windows\System32\svchost.exe
3116 C:\Windows\System32\taskeng.exe
3204 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
3224 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
3260 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
3316 C:\Windows\System32\svchost.exe
3404 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
3504 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3512 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3844 dllhost.exe
3908 dllhost.exe
4056 WmiPrvSE.exe
1076 C:\Windows\System32\SearchIndexer.exe
4104 C:\Windows\System32\svchost.exe
4524 C:\Program Files\Windows Media Player\wmpnetwk.exe
4840 C:\Windows\System32\svchost.exe
3160 C:\Windows\SysWOW64\rundll32.exe
4456 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
5176 C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
5256 C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
5716 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
5408 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
4776 C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
4820 C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
4704 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
5064 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
4648 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
2884 C:\Program Files\Sony\VAIO Care\VCPerfService.exe
5920 C:\Program Files\Sony\VAIO Care\listener.exe
4612 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
5964 C:\Program Files\Sony\VAIO Power Management\SPMService.exe
2228 C:\Windows\System32\svchost.exe
5988 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
2012 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
828 C:\Windows\System32\wuauclt.exe
1484 C:\Windows\servicing\TrustedInstaller.exe
3172 C:\Program Files\Sony\VAIO Care\VCsystray.exe
3928 C:\Program Files\Sony\VAIO Care\VCService.exe
5432 C:\Program Files\Sony\VAIO Care\VCAgent.exe
4964 C:\Windows\System32\vds.exe
4932 C:\Windows\System32\audiodg.exe
1964 C:\Windows\System32\SearchProtocolHost.exe
3924 C:\Windows\System32\SearchFilterHost.exe
1836 C:\Users\Sumit\Desktop\MBRCheck.exe
5464 C:\Windows\System32\conhost.exe
5444 C:\Program Files (x86)\Real\RealPlayer\realplay.exe
5044 C:\Program Files (x86)\Real\RealPlayer\realplay.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000004`0bc00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS545050B9SA00, Rev: PB4OC60X

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Options:
[1] Dump the MBR of a physical disk to file.
[2] Restore the MBR of a physical disk with a standard boot code.
[3] Exit.

Enter your choice: Enter the physical disk number to fix (0-99, -1 to cancel): 0Available MBR codes:
[ 0] Default (Windows 7)
[ 1] Windows XP
[ 2] Windows Server 2003
[ 3] Windows Vista
[ 4] Windows 2008
[ 5] Windows 7
[-1] Cancel

Please select the MBR code to write to this drive: 5
Do you want to fix the MBR code? Type 'YES' and hit ENTER to continue: yes
Successfully wrote new MBR code!
Please reboot your computer to complete the fix.


Done!
SGicz is offline   Reply With Quote
Old 01-02-2012, 11:39 AM   #30
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

OK, can you now rerun mbrcheck (only the report, no fixing) to see if it still shows the same problem?
Gabethebabe is offline   Reply With Quote
Old 01-02-2012, 11:54 AM   #31
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

There is a relatively new tool from Bitdefender that is worth trying if the mbrcheck log shows this again:

Quote:
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Found non-standard or infected MBR.
BitDefender 64-bit TDL4 removal tool
Gabethebabe is offline   Reply With Quote
Old 01-02-2012, 11:58 AM   #32
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

I think it's still there:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Sony Corporation
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: Sony Corporation
System Product Name: VPCF2290S
Logical Drives Mask: 0x00000014

Kernel Drivers (total 169):
0x02E1E000 \SystemRoot\system32\ntoskrnl.exe
0x03407000 \SystemRoot\system32\hal.dll
0x00BA6000 \SystemRoot\system32\kdcom.dll
0x00C13000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00C62000 \SystemRoot\system32\PSHED.dll
0x00C76000 \SystemRoot\system32\CLFS.SYS
0x00CD4000 \SystemRoot\system32\CI.dll
0x00EB3000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F57000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00F66000 \SystemRoot\system32\drivers\ACPI.sys
0x00FBD000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00FC6000 \SystemRoot\system32\drivers\msisadrv.sys
0x00E00000 \SystemRoot\system32\drivers\pci.sys
0x00E33000 \SystemRoot\system32\drivers\vdrvroot.sys
0x00E40000 \SystemRoot\System32\drivers\partmgr.sys
0x00E55000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00E5E000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00E6A000 \SystemRoot\system32\drivers\volmgr.sys
0x00D94000 \SystemRoot\System32\drivers\volmgrx.sys
0x00E7F000 \SystemRoot\System32\drivers\mountmgr.sys
0x01020000 \SystemRoot\system32\drivers\iaStor.sys
0x01174000 \SystemRoot\system32\drivers\amdxata.sys
0x0117F000 \SystemRoot\system32\drivers\fltmgr.sys
0x011CB000 \SystemRoot\system32\drivers\fileinfo.sys
0x011DF000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x01212000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01418000 \SystemRoot\System32\Drivers\msrpc.sys
0x01476000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01491000 \SystemRoot\System32\Drivers\cng.sys
0x01503000 \SystemRoot\System32\drivers\pcw.sys
0x01514000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x0169F000 \SystemRoot\system32\drivers\ndis.sys
0x01792000 \SystemRoot\system32\drivers\NETIO.SYS
0x01600000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x018A6000 \SystemRoot\System32\drivers\tcpip.sys
0x01AAA000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01AF4000 \SystemRoot\system32\drivers\volsnap.sys
0x01B40000 \SystemRoot\System32\Drivers\spldr.sys
0x01B48000 \SystemRoot\System32\drivers\rdyboost.sys
0x01B82000 \SystemRoot\System32\Drivers\mup.sys
0x01B94000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01B9D000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01BD7000 \SystemRoot\system32\drivers\disk.sys
0x01800000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x03FA9000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0151E000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x03FD3000 \SystemRoot\System32\Drivers\Null.SYS
0x03FDC000 \SystemRoot\System32\Drivers\Beep.SYS
0x03FE3000 \SystemRoot\System32\drivers\vga.sys
0x03E00000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x03E25000 \SystemRoot\System32\drivers\watchdog.sys
0x03E35000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x03FF1000 \SystemRoot\system32\drivers\rdpencdd.sys
0x0183E000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01847000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01852000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01863000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01885000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x01892000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x02E33000 \SystemRoot\system32\drivers\afd.sys
0x02EBC000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x02EC9000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02F0E000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x02F17000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02F3D000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x02F53000 \SystemRoot\system32\DRIVERS\netbios.sys
0x02F62000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x02F7D000 \SystemRoot\system32\DRIVERS\termdd.sys
0x02F91000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02FE2000 \SystemRoot\system32\drivers\nsiproxy.sys
0x02FEE000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02E00000 \SystemRoot\System32\drivers\discache.sys
0x02E0F000 \SystemRoot\System32\Drivers\dfsc.sys
0x01BED000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x0162B000 \SystemRoot\System32\Drivers\aswSP.SYS
0x015B4000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0F2FA000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x0FF70000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x0F200000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x0FF72000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0FFB8000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0FFDC000 \SystemRoot\system32\DRIVERS\HECIx64.sys
0x0FFED000 \SystemRoot\system32\drivers\usbehci.sys
0x04010000 \SystemRoot\system32\drivers\USBPORT.SYS
0x04450000 \SystemRoot\system32\DRIVERS\athrx.sys
0x046F6000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x04703000 \SystemRoot\system32\DRIVERS\risdsnxc64.sys
0x04721000 \SystemRoot\system32\DRIVERS\rimssne64.sys
0x04743000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x04781000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x047B2000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x04066000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x047B4000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x047D2000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x05443000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x055A0000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x055AF000 \SystemRoot\system32\DRIVERS\SFEP.sys
0x055B2000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x055BB000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x055D1000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x055D6000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x055E6000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x05400000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x05424000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04400000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x0442F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x040CD000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x047E1000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x05430000 \SystemRoot\system32\DRIVERS\swenum.sys
0x040EE000 \SystemRoot\system32\DRIVERS\ks.sys
0x04131000 \SystemRoot\system32\DRIVERS\umbus.sys
0x04143000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x0419D000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x041B6000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x041CB000 \SystemRoot\system32\drivers\nvhda64v.sys
0x013B5000 \SystemRoot\system32\drivers\portcls.sys
0x0167C000 \SystemRoot\system32\drivers\drmk.sys
0x05432000 \SystemRoot\system32\drivers\ksthunk.sys
0x060D8000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x06374000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06391000 \SystemRoot\System32\Drivers\usbvideo.sys
0x063BF000 \SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
0x0662F000 \SystemRoot\system32\DRIVERS\btwampfl.sys
0x0691F000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x06928000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x06940000 \SystemRoot\System32\Drivers\bthport.sys
0x000D0000 \SystemRoot\System32\win32k.sys
0x069CC000 \SystemRoot\System32\drivers\Dxapi.sys
0x06600000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x069D8000 \SystemRoot\system32\drivers\BthEnum.sys
0x063C9000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x06000000 \SystemRoot\system32\DRIVERS\btwavdt.sys
0x03E3E000 \SystemRoot\system32\drivers\btwaudio.sys
0x069E8000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
0x069F6000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0x06084000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x0609D000 \SystemRoot\System32\Drivers\crashdmp.sys
0x0205E000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x021B2000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x021C5000 \SystemRoot\system32\DRIVERS\monitor.sys
0x004C0000 \SystemRoot\System32\TSDDD.dll
0x007C0000 \SystemRoot\System32\cdd.dll
0x021D3000 \SystemRoot\system32\drivers\luafv.sys
0x02000000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x0203C000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x060AB000 \SystemRoot\system32\drivers\WudfPf.sys
0x02045000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x03ED3000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x063E9000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x03F26000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x0CA0E000 \SystemRoot\system32\drivers\HTTP.sys
0x0CAD7000 \SystemRoot\system32\DRIVERS\bowser.sys
0x0CAF5000 \SystemRoot\System32\drivers\mpsdrv.sys
0x0CB0D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x0CB3A000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0CB88000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x0CBAC000 \??\C:\Windows\system32\drivers\regi.sys
0x0D094000 \SystemRoot\system32\drivers\peauth.sys
0x0D13A000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0D145000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0D176000 \SystemRoot\System32\drivers\tcpipreg.sys
0x0D188000 \SystemRoot\System32\DRIVERS\srv2.sys
0x0D4B1000 \SystemRoot\System32\DRIVERS\srv.sys
0x77C30000 \Windows\System32\ntdll.dll
0x47F50000 \Windows\System32\smss.exe
0xFFF50000 \Windows\System32\apisetschema.dll
0xFFB40000 \Windows\System32\autochk.exe
0xFFE10000 \Windows\System32\rpcrt4.dll
0x77AD0000 \Windows\System32\wininet.dll

Processes (total 93):
0 System Idle Process
4 System
392 C:\Windows\System32\smss.exe
564 csrss.exe
648 C:\Windows\System32\wininit.exe
668 csrss.exe
712 C:\Windows\System32\services.exe
728 C:\Windows\System32\lsass.exe
740 C:\Windows\System32\lsm.exe
860 C:\Windows\System32\svchost.exe
940 C:\Windows\System32\nvvsvc.exe
980 C:\Windows\System32\svchost.exe
1020 C:\Windows\System32\winlogon.exe
444 C:\Windows\System32\svchost.exe
456 C:\Windows\System32\svchost.exe
1028 C:\Windows\System32\svchost.exe
1064 C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1184 C:\Windows\System32\svchost.exe
1276 C:\Windows\System32\svchost.exe
1412 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1424 C:\Windows\System32\nvvsvc.exe
1532 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1540 C:\Windows\System32\wlanext.exe
1548 C:\Windows\System32\conhost.exe
1716 C:\Windows\System32\dwm.exe
1736 C:\Windows\explorer.exe
1116 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1236 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2052 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2124 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
2132 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
2252 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
2280 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
2416 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
2424 C:\Program Files\AVAST Software\Avast\AvastUI.exe
2532 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2560 C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
2628 dllhost.exe
2760 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
672 C:\Windows\System32\spoolsv.exe
2100 C:\Windows\System32\taskhost.exe
1696 C:\Windows\System32\svchost.exe
2344 C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
1452 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
2900 C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
2756 C:\Windows\System32\taskeng.exe
2676 C:\Windows\System32\svchost.exe
3156 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
3204 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
3264 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
3336 C:\Windows\System32\svchost.exe
3428 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
3864 C:\Windows\System32\SearchIndexer.exe
3896 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3920 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3976 C:\Windows\System32\svchost.exe
3020 dllhost.exe
3040 dllhost.exe
3556 WmiPrvSE.exe
4576 C:\Program Files\Windows Media Player\wmpnetwk.exe
4888 C:\Windows\System32\svchost.exe
4156 C:\Windows\SysWOW64\rundll32.exe
4372 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
4568 C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
4780 C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
948 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
5876 C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
5964 C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
6064 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
6128 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
5132 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
772 C:\Program Files\Sony\VAIO Care\VCPerfService.exe
5160 C:\Program Files\Sony\VAIO Care\listener.exe
3324 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
3008 C:\Program Files\Sony\VAIO Power Management\SPMService.exe
2948 C:\Windows\System32\svchost.exe
2968 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
5028 C:\Windows\System32\wuauclt.exe
5228 C:\Program Files\Sony\VAIO Care\VCsystray.exe
5904 C:\Program Files\Sony\VAIO Care\VCService.exe
4152 C:\Program Files\Sony\VAIO Care\VCAgent.exe
4292 C:\Windows\System32\vds.exe
5676 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
5568 C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
4076 C:\Windows\System32\SearchProtocolHost.exe
5520 C:\Windows\System32\SearchFilterHost.exe
1464 C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
5500 C:\Windows\System32\audiodg.exe
2744 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
1088 C:\Users\Sumit\Desktop\MBRCheck.exe
1228 C:\Windows\System32\conhost.exe
4248 C:\Program Files (x86)\Real\RealPlayer\realplay.exe
6076 C:\Program Files (x86)\Real\RealPlayer\realplay.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000004`0bc00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS545050B9SA00, Rev: PB4OC60X

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!


EDIT: I'm going to try that BitDefender tool, and I'll reply with results.

Last edited by SGicz; 01-02-2012 at 11:59 AM. Reason: Using BitDefender
SGicz is offline   Reply With Quote
Old 01-02-2012, 12:02 PM   #33
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

BitDefender won't open, just like TDSSKiller.
SGicz is offline   Reply With Quote
Old 01-02-2012, 12:02 PM   #34
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

If the BD tool finds something, Iīd like to see a screenshot. I have never seen it in action

EDIT: Aha it does not open? You donīt make it to the start scan button?
Gabethebabe is offline   Reply With Quote
Old 01-02-2012, 12:06 PM   #35
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Yep. Same with TDSSKiller, I double-click on it, shows Windows is working (rotating blue circle) and then nothing. Same thing if I right-click and "Run as Administrator".
SGicz is offline   Reply With Quote
Old 01-02-2012, 12:06 PM   #36
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

have you tried renaming the TDSSkiller of Bitdefender exe file into helloworld.exe

it probably does nto change things, but you never know.
This infection has a very strong grip on your computer.

A windows setup disk will solve it for sure, because any MBR infection rolls over and dies to boot disk tools.
Gabethebabe is offline   Reply With Quote
Old 01-02-2012, 12:15 PM   #37
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Just tried re-naming it and then opening, but that didn't work either. I have to find a setup disk.
SGicz is offline   Reply With Quote
Old 01-02-2012, 01:20 PM   #38
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

if you canīt find one, try burning Hiren Boot CD and let me know when you manage to boot your computer with it.

http://www.hiren.info/
Gabethebabe is offline   Reply With Quote
Old 01-14-2012, 11:41 AM   #39
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Sorry for the late reply.

I downloaded Hiren Boot CD, and was able to boot my computer with it. What's the next step? Which option do I choose?
SGicz is offline   Reply With Quote
Old 01-15-2012, 02:54 PM   #40
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

OK

So bear with me because I have never used Hirenīs Boot CD before.
We are going to use the utility MBRFix, version 1.3 is installed on Hiren Boot CD.
First I want to make a backup of your current MBR.

Here are the commands available for MBRFix:
Quote:
MbrFix /drive <num> driveinfo Display drive information
MbrFix /drive <num> drivesize Returns drive size in MB as return value
MbrFix /drive <num> listpartitions Display partition information
MbrFix /drive <num> savembr <file> Save MBR and partitions to file
MbrFix /drive <num> restorembr <file> Restore MBR and partitions from file
MbrFix /drive <num> fixmbr {/vista|/win7} Update MBR code to W2K/XP/2003, Vista or Win7
MbrFix /drive <num> clean Delete all partitions on the selected disk
MbrFix /drive <num> readsignature {/byte} Read disk signature from MBR
MbrFix /drive <num> writesignature <hex> Write disk signature to MBR
MbrFix /drive <num> generatesignature Generate disk signature in MBR
MbrFix /drive <num> readstate Read state from byte 0x1b2 in MBR
MbrFix /drive <num> writestate <state> Write state to byte 0x1b2 in MBR
MbrFix /drive <num> readdrive <startsector> <sectorcount> <file>
Save sectors from drive to file
MbrFix /drive <num> /partition <part> fixbootsector <os>
Update Boot code in boot sector
MbrFix /drive <num> /partition <part> getpartitiontype
Get partition type
MbrFix /drive <num> /partition <part> setpartitiontype <typenum>
Set partition type
MbrFix /drive <num> /partition <part> setactivepartition
Set active partition
MbrFix /drive <num> getactivepartition Get active partition
MbrFix volumeinformation driveletter Get volume information for partition
MbrFix flush {driveletter(s)} Flush files to disk for partition
MbrFix listpartitiontypes List partition types

The bold commands are the ones that interest us.

So what I want to run first is this command:

MbrFix /drive 0 savembr c:\mbr_backup.dat

This saves a backup of your current (probably infected) MBR, which we can restore if necessary.

if that goes well, I want to run this command:

MbrFix /drive 0 fixmbr /win7

Which overwrites your current MBR wit a standard clean Windows 7 MBR.

Iīm not sure how MBRFix is run on hiren boot cd, so youīre going to have to tell me if you choose the MBRFix utility, what kind of options you see.
Gabethebabe is offline   Reply With Quote
Old 01-15-2012, 06:29 PM   #41
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

I would run MBRFix if I could actually find it. It's strange -- almost all the other programs listed under "MBR (Master Boot Record) Tools" are there, but MBRFix 1.3 isn't listed when actually using the boot CD. Maybe I'm missing something. If you can give a step-by-step guide, that would help.
SGicz is offline   Reply With Quote
Old 01-16-2012, 03:59 AM   #42
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

WTF

Iīm now downloading it and burning it myself to have a look.

BBL
Gabethebabe is offline   Reply With Quote
Old 01-18-2012, 04:55 AM   #43
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

OK so I burned the MFer and could not find mbrfix, lol

But we donīt need it

Hereīs what weīre (well, you) gonna do.

Please download aswMBR by Alwil Software from here.

Please download MBRCheck by a_d_13 from either of the following mirrors:
Save both tools to the root of your disk (C:\) or any other place where you can easily find them.

Now reboot with Hiren Boot CD and choose mini XP mode. Hopefully this works, because OTLPE seemed to NOT work with your computer.

Browse to your c: and run mbrcheck. I wonder what it will say, because now you will get a clean look at your MBR without anything being able to interfere.

If the MBR is infected or not standard, you will get some extra option. Choose to make a backup of your MBR (or a dump or whatever mbrcheck will call it).
After that try and write a clean MBR with mbrcheck. It will ask for a disk number ==> 0.

Close MBRcheck and rerun it again. Does it show that the MBR is a standard MBR? In that case we are finished and we have cleaned up your MBR and kept a backup of your previous (probably infected) MBR.

Boot back normally and see if redirects are gone.

If MBRCheck fails to clean your MBR (which I remember happened to me), then try and run aswMBR and clean with that tool.

After that rerun MBRCheck to see if the MBR is now standard.

Report back all your observations please, the more detailed the better, because it highly interests me for future cases. These MBR infections get tougher by the day and I expect more to come.
Gabethebabe is offline   Reply With Quote
Old 01-18-2012, 07:17 PM   #44
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Ok, so I ran the Hiren Boot CD in Mini XP Mode. I ran MBRCheck, and it showed everything as being fine. So, I pressed enter to exit. I did it a few times, just to be sure. I rebooted and started Windows normally. I used MBRCheck again, but it shows as being faked again. This time, under Mini XP Mode, I used aswMBR and clicked FixMBR. Here is the log:

aswMBR version 0.9.9.1297 Copyright(c) 2011 AVAST Software
Run date: 2012-01-18 18:06:49
-----------------------------
18:06:49.906 OS Version: Windows 5.1.2600
18:06:49.906 Number of processors: 1 586 0x2A07
18:06:49.906 ComputerName: MiniXP UserName: SYSTEM
18:06:49.906 Initialze error 1 Incorrect function.
18:06:56.046 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
18:06:56.046 Disk 0 Vendor: Hitachi_ PB4O Size: 476940MB BusType: 3
18:06:56.046 Disk 0 MBR read successfully
18:06:56.046 Disk 0 MBR scan
18:06:56.046 Disk 0 Windows XP default MBR code
18:06:56.078 Disk 0 Partition 1 00 27 Hidden NTFS WinRE NTFS 16471 MB offset 2048
18:06:56.093 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 100 MB offset 33734656
18:06:56.109 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 460367 MB offset 33939456
18:06:56.140 Disk 0 Partition 4 80 (A) 17 Hidd HPFS/NTFS NTFS 0 MB offset 976771120
18:06:56.140 Disk 0 Partition 4 **SUSPICIOUS**
18:06:56.140 Disk 0 scanning sectors +976773152
18:06:56.437 Disk 0 scanning X:\i386\system32\drivers
18:06:56.437 Service scanning
18:06:56.953 Modules scanning
18:06:57.156 Disk 0 trace - called modules:
18:06:57.187 NTKRNLMP.EXE CLASSPNP.SYS disk.sys acpi.sys HALAACPI.DLL IASTOR9.SYS
18:06:57.187 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x889b6030]
18:06:57.203 3 CLASSPNP.SYS[f7647fd7] -> nt!IofCallDriver -> \Device\00000042[0x8ba4f888]
18:06:57.203 5 acpi.sys[f7524620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0x8abd4028]
18:06:57.203 Scan finished successfully
18:07:16.062 Verifying
18:07:26.062 Disk 0 Windows 501 MBR fixed successfully
18:07:36.859 Disk 0 MBR has been saved successfully to "D:\MBR.dat"
18:07:36.875 The log file has been saved successfully to "D:\aswMBR.txt"

Where is says "SUSPICIOUS"...well, that's suspicious. I still ran MBRCheck again after that, but it still shows as faked:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Sony Corporation
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: Sony Corporation
System Product Name: VPCF2290S
Logical Drives Mask: 0x00000014

Kernel Drivers (total 203):
0x02E1C000 \SystemRoot\system32\ntoskrnl.exe
0x03405000 \SystemRoot\system32\hal.dll
0x00BA9000 \SystemRoot\system32\kdcom.dll
0x00CD8000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00D27000 \SystemRoot\system32\PSHED.dll
0x00D3B000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00E2E000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00ED2000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00EE1000 \SystemRoot\system32\drivers\ACPI.sys
0x00F38000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00F41000 \SystemRoot\system32\drivers\msisadrv.sys
0x00F4B000 \SystemRoot\system32\drivers\pci.sys
0x00F7E000 \SystemRoot\system32\drivers\vdrvroot.sys
0x00F8B000 \SystemRoot\System32\drivers\partmgr.sys
0x00FA0000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00FA9000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00FB5000 \SystemRoot\system32\drivers\volmgr.sys
0x00D99000 \SystemRoot\System32\drivers\volmgrx.sys
0x00FCA000 \SystemRoot\System32\drivers\mountmgr.sys
0x010A1000 \SystemRoot\system32\drivers\iaStor.sys
0x011F5000 \SystemRoot\system32\drivers\amdxata.sys
0x01000000 \SystemRoot\system32\drivers\fltmgr.sys
0x0104C000 \SystemRoot\system32\drivers\fileinfo.sys
0x01060000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x01244000 \SystemRoot\System32\Drivers\Ntfs.sys
0x0144B000 \SystemRoot\System32\Drivers\msrpc.sys
0x014A9000 \SystemRoot\System32\Drivers\ksecdd.sys
0x014C4000 \SystemRoot\System32\Drivers\cng.sys
0x01536000 \SystemRoot\System32\drivers\pcw.sys
0x01547000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x01644000 \SystemRoot\system32\drivers\ndis.sys
0x01737000 \SystemRoot\system32\drivers\NETIO.SYS
0x01797000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x018AE000 \SystemRoot\System32\drivers\tcpip.sys
0x01AB2000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01AFC000 \SystemRoot\system32\drivers\volsnap.sys
0x01B48000 \SystemRoot\System32\Drivers\spldr.sys
0x01B50000 \SystemRoot\System32\drivers\rdyboost.sys
0x01B8A000 \SystemRoot\System32\Drivers\mup.sys
0x01B9C000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01BA5000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01BDF000 \SystemRoot\system32\drivers\disk.sys
0x01800000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x0438E000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x01551000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x043B8000 \SystemRoot\System32\Drivers\Null.SYS
0x043C1000 \SystemRoot\System32\Drivers\Beep.SYS
0x043C8000 \SystemRoot\System32\drivers\vga.sys
0x043D6000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x04200000 \SystemRoot\System32\drivers\watchdog.sys
0x04210000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x04219000 \SystemRoot\system32\drivers\rdpencdd.sys
0x0183E000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01847000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01852000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01863000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01885000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x01892000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x044A2000 \SystemRoot\system32\drivers\afd.sys
0x0452B000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x04538000 \SystemRoot\System32\DRIVERS\netbt.sys
0x0457D000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x04586000 \SystemRoot\system32\DRIVERS\pacer.sys
0x045AC000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x045C2000 \SystemRoot\system32\DRIVERS\netbios.sys
0x045D1000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x045EC000 \SystemRoot\system32\DRIVERS\termdd.sys
0x04400000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x04451000 \SystemRoot\system32\drivers\nsiproxy.sys
0x0445D000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x04468000 \SystemRoot\System32\drivers\discache.sys
0x04477000 \SystemRoot\System32\Drivers\dfsc.sys
0x017C2000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x046C3000 \SystemRoot\System32\Drivers\aswSP.SYS
0x04714000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0F23F000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x0FEB5000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x0FEB7000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x0FFAB000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0F200000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0F224000 \SystemRoot\system32\DRIVERS\HECIx64.sys
0x0473A000 \SystemRoot\system32\drivers\usbehci.sys
0x0474B000 \SystemRoot\system32\drivers\USBPORT.SYS
0x04CD9000 \SystemRoot\system32\DRIVERS\athrx.sys
0x04F7F000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x04F8C000 \SystemRoot\system32\DRIVERS\risdsnxc64.sys
0x04FAA000 \SystemRoot\system32\DRIVERS\rimssne64.sys
0x04C00000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x04C3E000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x04C6F000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x04C71000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x04FCC000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x04FEA000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x0521B000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x05378000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x05387000 \SystemRoot\system32\DRIVERS\SFEP.sys
0x0538A000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x05393000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x053A9000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x053AE000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x053BE000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x053D4000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x05200000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x047A1000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x047D0000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04600000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04621000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x0520C000 \SystemRoot\system32\DRIVERS\swenum.sys
0x0463B000 \SystemRoot\system32\DRIVERS\ks.sys
0x0467E000 \SystemRoot\system32\DRIVERS\umbus.sys
0x0549A000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x054F4000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x0550D000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x05522000 \SystemRoot\system32\drivers\nvhda64v.sys
0x0554F000 \SystemRoot\system32\drivers\portcls.sys
0x0558C000 \SystemRoot\system32\drivers\drmk.sys
0x055AE000 \SystemRoot\system32\drivers\ksthunk.sys
0x06A1C000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x000D0000 \SystemRoot\System32\win32k.sys
0x06CB8000 \SystemRoot\System32\drivers\Dxapi.sys
0x06CC4000 \SystemRoot\System32\Drivers\crashdmp.sys
0x04222000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x06CD2000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x06CE5000 \SystemRoot\system32\DRIVERS\monitor.sys
0x00570000 \SystemRoot\System32\TSDDD.dll
0x007C0000 \SystemRoot\System32\cdd.dll
0x06CF3000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06D10000 \SystemRoot\System32\Drivers\usbvideo.sys
0x06D3E000 \SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
0x06E18000 \SystemRoot\system32\DRIVERS\btwampfl.sys
0x07108000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x07111000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x07129000 \SystemRoot\System32\Drivers\bthport.sys
0x071B5000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x071E1000 \SystemRoot\system32\drivers\BthEnum.sys
0x06D48000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x06D68000 \SystemRoot\system32\DRIVERS\btwavdt.sys
0x05400000 \SystemRoot\system32\drivers\btwaudio.sys
0x071F1000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
0x06E00000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0x06A00000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x055B4000 \SystemRoot\system32\drivers\luafv.sys
0x01600000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x06E04000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x055D7000 \SystemRoot\system32\drivers\WudfPf.sys
0x04690000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x07A8D000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x07AE0000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x07AF3000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x07B0B000 \SystemRoot\system32\drivers\HTTP.sys
0x07BD4000 \SystemRoot\system32\DRIVERS\bowser.sys
0x07A00000 \SystemRoot\System32\drivers\mpsdrv.sys
0x07A18000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x0B23D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x0B28B000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x0B2AF000 \??\C:\Windows\system32\drivers\regi.sys
0x0B2B7000 \SystemRoot\system32\drivers\peauth.sys
0x0B35D000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0B368000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0B399000 \SystemRoot\System32\drivers\tcpipreg.sys
0x0B832000 \SystemRoot\System32\DRIVERS\srv2.sys
0x0B89B000 \SystemRoot\System32\DRIVERS\srv.sys
0x77950000 \Windows\System32\ntdll.dll
0x47FC0000 \Windows\System32\smss.exe
0xFFC70000 \Windows\System32\apisetschema.dll
0xFFD10000 \Windows\System32\autochk.exe
0xFFB50000 \Windows\System32\msctf.dll
0x77830000 \Windows\System32\kernel32.dll
0xFFB30000 \Windows\System32\imagehlp.dll
0xFFA00000 \Windows\System32\rpcrt4.dll
0xFF930000 \Windows\System32\usp10.dll
0xFF920000 \Windows\System32\nsi.dll
0x776E0000 \Windows\System32\urlmon.dll
0xFF880000 \Windows\System32\msvcrt.dll
0xFEAF0000 \Windows\System32\shell32.dll
0xFEAD0000 \Windows\System32\sechost.dll
0x77B20000 \Windows\System32\psapi.dll
0xFEA80000 \Windows\System32\ws2_32.dll
0xFEA00000 \Windows\System32\shlwapi.dll
0xFE9D0000 \Windows\System32\imm32.dll
0xFE960000 \Windows\System32\gdi32.dll
0xFE8E0000 \Windows\System32\difxapi.dll
0xFE800000 \Windows\System32\oleaut32.dll
0xFE7A0000 \Windows\System32\Wldap32.dll
0xFE700000 \Windows\System32\clbcatq.dll
0xFE620000 \Windows\System32\advapi32.dll
0xFE580000 \Windows\System32\comdlg32.dll
0x77B10000 \Windows\System32\normaliz.dll
0xFE370000 \Windows\System32\ole32.dll
0xFE360000 \Windows\System32\lpk.dll
0x77580000 \Windows\System32\wininet.dll
0x77370000 \Windows\System32\iertutil.dll
0x77270000 \Windows\System32\user32.dll
0xFE180000 \Windows\System32\setupapi.dll
0xFE140000 \Windows\System32\cfgmgr32.dll
0xFE0D0000 \Windows\System32\KernelBase.dll
0xFDF60000 \Windows\System32\crypt32.dll
0xFDEC0000 \Windows\System32\comctl32.dll
0xFDEA0000 \Windows\System32\devobj.dll
0xFDE60000 \Windows\System32\wintrust.dll
0xFDE50000 \Windows\System32\msasn1.dll
0x75430000 \Windows\SysWOW64\normaliz.dll

Processes (total 93):
0 System Idle Process
4 System
392 C:\Windows\System32\smss.exe
552 csrss.exe
628 C:\Windows\System32\wininit.exe
648 csrss.exe
696 C:\Windows\System32\services.exe
704 C:\Windows\System32\lsass.exe
712 C:\Windows\System32\lsm.exe
800 C:\Windows\System32\winlogon.exe
880 C:\Windows\System32\svchost.exe
964 C:\Windows\System32\nvvsvc.exe
1004 C:\Windows\System32\svchost.exe
568 C:\Windows\System32\svchost.exe
456 C:\Windows\System32\svchost.exe
1028 C:\Windows\System32\svchost.exe
1068 C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1196 C:\Windows\System32\svchost.exe
1268 C:\Windows\System32\svchost.exe
1352 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1364 C:\Windows\System32\nvvsvc.exe
1440 C:\Windows\System32\wlanext.exe
1448 C:\Windows\System32\conhost.exe
1464 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1708 C:\Windows\System32\dwm.exe
1724 C:\Windows\explorer.exe
1660 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1620 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2064 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2176 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
2204 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
2244 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
2360 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
2384 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
2392 C:\Program Files\AVAST Software\Avast\AvastUI.exe
2620 dllhost.exe
2652 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2660 C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
2748 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
3036 C:\Windows\System32\spoolsv.exe
1480 C:\Windows\System32\taskhost.exe
1748 C:\Windows\System32\svchost.exe
2548 C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
2736 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
2700 C:\Windows\System32\taskeng.exe
2944 C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
2492 C:\Windows\System32\svchost.exe
3200 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
3260 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
3312 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
3348 C:\Windows\System32\svchost.exe
3444 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
3868 C:\Windows\System32\SearchIndexer.exe
3876 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3892 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
4044 C:\Windows\System32\svchost.exe
2560 dllhost.exe
3612 dllhost.exe
4104 WmiPrvSE.exe
4492 C:\Windows\SysWOW64\rundll32.exe
4548 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
4680 C:\Program Files\Windows Media Player\wmpnetwk.exe
4780 C:\Windows\System32\svchost.exe
2668 C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
4964 C:\PROGRA~1\Sony\VAIOSM~1\VSNCLI~1.EXE
1896 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
5196 C:\Windows\System32\notepad.exe
5264 C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
3288 C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
3504 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
2640 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
2808 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
2780 C:\Program Files\Sony\VAIO Care\VCPerfService.exe
5308 C:\Program Files\Sony\VAIO Care\listener.exe
1536 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
3888 C:\Program Files\Sony\VAIO Power Management\SPMService.exe
5724 C:\Windows\System32\svchost.exe
1212 C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
2908 C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
3796 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
1144 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
2904 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
2684 C:\Windows\System32\wuauclt.exe
1260 C:\Program Files\Sony\VAIO Care\VCsystray.exe
5452 C:\Program Files\Sony\VAIO Care\VCService.exe
3188 C:\Program Files\Sony\VAIO Care\VCAgent.exe
6044 C:\Windows\System32\vds.exe
4372 WmiPrvSE.exe
2524 C:\MBRCheck.exe
4380 C:\Windows\System32\conhost.exe
5248 <unknown>
4524 <unknown>
5760 C:\Windows\System32\dllhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000004`0bc00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS545050B9SA00, Rev: PB4OC60X

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: C2CE024D9810BCAA73B2B0C32584C5072E780542


Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:

Done!
SGicz is offline   Reply With Quote
Old 01-19-2012, 05:28 AM   #45
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Do you have the mbrcheck log that was saved during the execution in mini xp mode?

You still suffer from the redirects?

It could be possible that some legitimate process is protecting your MBR and thatīs why mbrcheck shows it is "faked".

But I cannot say I have ever encountered a case like this. I am really in WTF mode right now

Maybe look into your router again and post that screenshots you mentioned earlier in this thread.

Iīm running out of ideas.
Gabethebabe is offline   Reply With Quote
Old 01-19-2012, 07:33 PM   #46
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

I tried something. See, when using Mini XP Mode, I was able to run aswMBR, which I wasn't able to do when running Windows normally. So, I thought I might as well give TDSSKiller a shot in Mini XP Mode. I was able to run it, it found a problem (I believe it was called Root Killer). I cured the problem, restarted Windows in normal mode, and so far, I don't have the re-direct problem.

I just did an MBRCheck, and it appears everything is fine:

MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows 7 Home Premium Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Sony Corporation
BIOS Manufacturer: American Megatrends Inc.
System Manufacturer: Sony Corporation
System Product Name: VPCF2290S
Logical Drives Mask: 0x00000014

Kernel Drivers (total 203):
0x02E0E000 \SystemRoot\system32\ntoskrnl.exe
0x033F7000 \SystemRoot\system32\hal.dll
0x00BCA000 \SystemRoot\system32\kdcom.dll
0x00CA8000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00CF7000 \SystemRoot\system32\PSHED.dll
0x00D0B000 \SystemRoot\system32\CLFS.SYS
0x00E2D000 \SystemRoot\system32\CI.dll
0x00EED000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00F91000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x00FA0000 \SystemRoot\system32\drivers\ACPI.sys
0x00FF7000 \SystemRoot\system32\drivers\WMILIB.SYS
0x00E00000 \SystemRoot\system32\drivers\msisadrv.sys
0x00D69000 \SystemRoot\system32\drivers\pci.sys
0x00E0A000 \SystemRoot\system32\drivers\vdrvroot.sys
0x00E17000 \SystemRoot\System32\drivers\partmgr.sys
0x00D9C000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00DA5000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00DB1000 \SystemRoot\system32\drivers\volmgr.sys
0x00C00000 \SystemRoot\System32\drivers\volmgrx.sys
0x00C5C000 \SystemRoot\System32\drivers\mountmgr.sys
0x0106A000 \SystemRoot\system32\drivers\iaStor.sys
0x011BE000 \SystemRoot\system32\drivers\amdxata.sys
0x01000000 \SystemRoot\system32\drivers\fltmgr.sys
0x0104C000 \SystemRoot\system32\drivers\fileinfo.sys
0x011C9000 \SystemRoot\System32\Drivers\PxHlpa64.sys
0x0124B000 \SystemRoot\System32\Drivers\Ntfs.sys
0x01426000 \SystemRoot\System32\Drivers\msrpc.sys
0x01484000 \SystemRoot\System32\Drivers\ksecdd.sys
0x0149F000 \SystemRoot\System32\Drivers\cng.sys
0x01511000 \SystemRoot\System32\drivers\pcw.sys
0x01522000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016F0000 \SystemRoot\system32\drivers\ndis.sys
0x01600000 \SystemRoot\system32\drivers\NETIO.SYS
0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x0184B000 \SystemRoot\System32\drivers\tcpip.sys
0x01A4F000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x01A99000 \SystemRoot\system32\drivers\volsnap.sys
0x01AE5000 \SystemRoot\System32\Drivers\spldr.sys
0x01AED000 \SystemRoot\System32\drivers\rdyboost.sys
0x01B27000 \SystemRoot\System32\Drivers\mup.sys
0x01B39000 \SystemRoot\System32\drivers\hwpolicy.sys
0x01B42000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01B7C000 \SystemRoot\system32\drivers\disk.sys
0x01B92000 \SystemRoot\system32\drivers\CLASSPNP.SYS
0x02E00000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x0152C000 \SystemRoot\System32\Drivers\aswSnx.SYS
0x02E2A000 \SystemRoot\System32\Drivers\Null.SYS
0x02E33000 \SystemRoot\System32\Drivers\Beep.SYS
0x02E3A000 \SystemRoot\System32\drivers\vga.sys
0x02E48000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x02FD9000 \SystemRoot\System32\drivers\watchdog.sys
0x02FE9000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x02FF2000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01BD0000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01BD9000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01BE4000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01800000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01822000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x0182F000 \SystemRoot\System32\Drivers\aswTdi.SYS
0x04422000 \SystemRoot\system32\drivers\afd.sys
0x044AB000 \SystemRoot\System32\Drivers\aswRdr.SYS
0x044B8000 \SystemRoot\System32\DRIVERS\netbt.sys
0x044FD000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x04506000 \SystemRoot\system32\DRIVERS\pacer.sys
0x0452C000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x04542000 \SystemRoot\system32\DRIVERS\netbios.sys
0x04551000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x0456C000 \SystemRoot\system32\DRIVERS\termdd.sys
0x04580000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x045D1000 \SystemRoot\system32\drivers\nsiproxy.sys
0x045DD000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x045E8000 \SystemRoot\System32\drivers\discache.sys
0x04400000 \SystemRoot\System32\Drivers\dfsc.sys
0x0168B000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x0169C000 \SystemRoot\System32\Drivers\aswSP.SYS
0x015C2000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x0F23A000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys
0x0FEB0000 \SystemRoot\System32\Drivers\nvBridge.kmd
0x0FEB2000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x0FFA6000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0F200000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x0F224000 \SystemRoot\system32\DRIVERS\HECIx64.sys
0x0FFEC000 \SystemRoot\system32\drivers\usbehci.sys
0x04ADA000 \SystemRoot\system32\drivers\USBPORT.SYS
0x04CF9000 \SystemRoot\system32\DRIVERS\athrx.sys
0x04F9F000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x04FAC000 \SystemRoot\system32\DRIVERS\risdsnxc64.sys
0x04FCA000 \SystemRoot\system32\DRIVERS\rimssne64.sys
0x04C00000 \SystemRoot\system32\DRIVERS\1394ohci.sys
0x04C3E000 \SystemRoot\system32\DRIVERS\nusb3xhc.sys
0x04C6F000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x04C71000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x04CD8000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x04FEC000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x05254000 \SystemRoot\system32\DRIVERS\SynTP.sys
0x053B1000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x053C0000 \SystemRoot\system32\DRIVERS\SFEP.sys
0x053C3000 \SystemRoot\system32\DRIVERS\wmiacpi.sys
0x053CC000 \SystemRoot\system32\DRIVERS\intelppm.sys
0x053E2000 \SystemRoot\system32\DRIVERS\CmBatt.sys
0x053E7000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x05200000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x05216000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x0523A000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x04B30000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04B5F000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x04B7A000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x04B9B000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x05246000 \SystemRoot\system32\DRIVERS\swenum.sys
0x04BB5000 \SystemRoot\system32\DRIVERS\ks.sys
0x04A00000 \SystemRoot\system32\DRIVERS\umbus.sys
0x04A12000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x04A6C000 \SystemRoot\system32\DRIVERS\nusb3hub.sys
0x04A85000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04A9A000 \SystemRoot\system32\drivers\nvhda64v.sys
0x01200000 \SystemRoot\system32\drivers\portcls.sys
0x01400000 \SystemRoot\system32\drivers\drmk.sys
0x05248000 \SystemRoot\system32\drivers\ksthunk.sys
0x068FE000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x06B9A000 \SystemRoot\System32\Drivers\crashdmp.sys
0x02E6D000 \SystemRoot\System32\Drivers\dump_iaStor.sys
0x06BA8000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x00050000 \SystemRoot\System32\win32k.sys
0x06BBB000 \SystemRoot\System32\drivers\Dxapi.sys
0x06BC7000 \SystemRoot\system32\DRIVERS\monitor.sys
0x06BD5000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x06800000 \SystemRoot\System32\Drivers\usbvideo.sys
0x0682E000 \SystemRoot\system32\DRIVERS\ArcSoftKsUFilter.sys
0x004C0000 \SystemRoot\System32\TSDDD.dll
0x00600000 \SystemRoot\System32\cdd.dll
0x06C0F000 \SystemRoot\system32\DRIVERS\btwampfl.sys
0x06EFF000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x06F08000 \SystemRoot\System32\Drivers\BTHUSB.sys
0x06F20000 \SystemRoot\System32\Drivers\bthport.sys
0x06FAC000 \SystemRoot\system32\DRIVERS\rfcomm.sys
0x06FD8000 \SystemRoot\system32\drivers\BthEnum.sys
0x06838000 \SystemRoot\system32\DRIVERS\bthpan.sys
0x06858000 \SystemRoot\system32\DRIVERS\btwavdt.sys
0x03E74000 \SystemRoot\system32\drivers\btwaudio.sys
0x03F09000 \SystemRoot\system32\DRIVERS\btwl2cap.sys
0x03F17000 \SystemRoot\system32\DRIVERS\btwrchid.sys
0x03F1B000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x03F34000 \SystemRoot\system32\drivers\luafv.sys
0x03F57000 \??\C:\Windows\system32\drivers\aswMonFlt.sys
0x03F93000 \SystemRoot\System32\Drivers\aswFsBlk.SYS
0x03F9C000 \SystemRoot\system32\drivers\WudfPf.sys
0x03FBD000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x03E00000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x03E53000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x03FD2000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x09269000 \SystemRoot\system32\drivers\HTTP.sys
0x09332000 \SystemRoot\system32\DRIVERS\bowser.sys
0x09350000 \SystemRoot\System32\drivers\mpsdrv.sys
0x09368000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x09395000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x09200000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x09224000 \??\C:\Windows\system32\drivers\regi.sys
0x0985F000 \SystemRoot\system32\drivers\peauth.sys
0x09905000 \SystemRoot\System32\Drivers\secdrv.SYS
0x09910000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x09941000 \SystemRoot\System32\drivers\tcpipreg.sys
0x09953000 \SystemRoot\System32\DRIVERS\srv2.sys
0x09CB4000 \SystemRoot\System32\DRIVERS\srv.sys
0x09D4C000 \SystemRoot\system32\drivers\spsys.sys
0x77070000 \Windows\System32\ntdll.dll
0x47C00000 \Windows\System32\smss.exe
0xFF390000 \Windows\System32\apisetschema.dll
0xFF0A0000 \Windows\System32\autochk.exe
0x76E60000 \Windows\System32\iertutil.dll
0xFF370000 \Windows\System32\lpk.dll
0xFE5E0000 \Windows\System32\shell32.dll
0xFE540000 \Windows\System32\comdlg32.dll
0xFE460000 \Windows\System32\advapi32.dll
0xFE400000 \Windows\System32\Wldap32.dll
0xFE2F0000 \Windows\System32\msctf.dll
0xFE270000 \Windows\System32\shlwapi.dll
0x76D10000 \Windows\System32\urlmon.dll
0xFE200000 \Windows\System32\gdi32.dll
0xFE1F0000 \Windows\System32\nsi.dll
0x76BB0000 \Windows\System32\wininet.dll
0xFE1C0000 \Windows\System32\imm32.dll
0x77240000 \Windows\System32\psapi.dll
0xFDFE0000 \Windows\System32\setupapi.dll
0xFDFC0000 \Windows\System32\sechost.dll
0x76AB0000 \Windows\System32\user32.dll
0xFDFA0000 \Windows\System32\imagehlp.dll
0x77230000 \Windows\System32\normaliz.dll
0xFDF50000 \Windows\System32\ws2_32.dll
0xFDEB0000 \Windows\System32\msvcrt.dll
0xFDDE0000 \Windows\System32\usp10.dll
0xFDCB0000 \Windows\System32\rpcrt4.dll
0xFDC30000 \Windows\System32\difxapi.dll
0x76990000 \Windows\System32\kernel32.dll
0xFDA20000 \Windows\System32\ole32.dll
0xFD940000 \Windows\System32\oleaut32.dll
0xFD8A0000 \Windows\System32\clbcatq.dll
0xFD880000 \Windows\System32\devobj.dll
0xFD7E0000 \Windows\System32\comctl32.dll
0xFD7A0000 \Windows\System32\wintrust.dll
0xFD760000 \Windows\System32\cfgmgr32.dll
0xFD5F0000 \Windows\System32\crypt32.dll
0xFD580000 \Windows\System32\KernelBase.dll
0xFD570000 \Windows\System32\msasn1.dll

Processes (total 91):
0 System Idle Process
4 System
384 C:\Windows\System32\smss.exe
540 csrss.exe
620 C:\Windows\System32\wininit.exe
644 csrss.exe
696 C:\Windows\System32\services.exe
712 C:\Windows\System32\lsass.exe
728 C:\Windows\System32\lsm.exe
788 C:\Windows\System32\winlogon.exe
864 C:\Windows\System32\svchost.exe
944 C:\Windows\System32\nvvsvc.exe
984 C:\Windows\System32\svchost.exe
320 C:\Windows\System32\svchost.exe
416 C:\Windows\System32\svchost.exe
852 C:\Windows\System32\svchost.exe
396 C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
1136 C:\Windows\System32\svchost.exe
1236 C:\Windows\System32\svchost.exe
1344 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
1356 C:\Windows\System32\nvvsvc.exe
1408 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
1416 C:\Windows\System32\wlanext.exe
1424 C:\Windows\System32\conhost.exe
1688 C:\Windows\System32\dwm.exe
1708 C:\Windows\explorer.exe
2020 C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
1228 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
2152 C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
2160 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
2168 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
2184 C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
2452 C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
2464 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
2484 C:\Program Files\AVAST Software\Avast\AvastUI.exe
2524 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
2532 C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
2788 C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
2940 C:\Windows\System32\spoolsv.exe
2972 C:\Windows\System32\svchost.exe
3016 C:\Windows\System32\taskhost.exe
2100 C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
424 C:\Windows\System32\taskeng.exe
2476 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
2392 C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
2764 C:\Windows\System32\svchost.exe
2680 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
2300 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
2876 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
3108 C:\Windows\System32\svchost.exe
3148 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
3352 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3380 C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
3452 dllhost.exe
3744 dllhost.exe
3984 WmiPrvSE.exe
4032 C:\Windows\System32\SearchIndexer.exe
4060 C:\Windows\System32\svchost.exe
4300 C:\Program Files\Windows Media Player\wmpnetwk.exe
4404 C:\Windows\System32\svchost.exe
4880 C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
4936 C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
4980 dllhost.exe
5112 C:\Windows\SysWOW64\rundll32.exe
4324 C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
3496 C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
2324 C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
4840 C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
2640 C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
4736 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
3008 C:\Program Files\Sony\VAIO Care\VCPerfService.exe
5224 C:\Program Files\Sony\VAIO Update Common\VUAgent.exe
5276 C:\Program Files\Sony\VAIO Care\listener.exe
5416 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
5952 C:\Windows\System32\sppsvc.exe
5980 C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
6008 C:\Program Files\Sony\VAIO Power Management\SPMService.exe
6044 C:\Windows\System32\svchost.exe
4200 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
1172 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
3440 C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
5388 C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
5040 C:\Windows\System32\wuauclt.exe
3048 C:\Program Files\Sony\VAIO Care\VCsystray.exe
2288 C:\Program Files\Sony\VAIO Care\VCService.exe
3140 C:\Program Files\Sony\VAIO Care\VCAgent.exe
1376 C:\Windows\System32\vds.exe
4088 WmiPrvSE.exe
2784 C:\Windows\System32\dllhost.exe
2056 C:\MBRCheck.exe
2416 C:\Windows\System32\conhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000004`0bc00000 (NTFS)

PhysicalDrive0 Model Number: HitachiHTS545050B9SA00, Rev: PB4OC60X

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79


Done!


Am I cured?
SGicz is offline   Reply With Quote
Old 01-20-2012, 03:19 AM   #47
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

zomg

I donīt get how aswmbr finds nothing and neither does mbrcheck and tdsskiller finds you a rootkit? They are all looking at the same thing. Anyway, if tdsskiller cured something, it was your redirect, because thatīs what it does.

Means next time I will tell the user directly to run tdsskiller from minixp mode

Now you can run aswmbr and tdsskiller also when you boot the computer normally?
Gabethebabe is offline   Reply With Quote
Old 01-20-2012, 06:35 AM   #48
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Yes, I'm able to run aswMBR and TDSSKiller normally now!
SGicz is offline   Reply With Quote
Old 01-20-2012, 08:32 AM   #49
Gabethebabe
Malware Jedi
 
Gabethebabe's Avatar
 
Join Date: Oct 2007
Location: In front of my monitor
Posts: 20,098
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

kewlllllllllllllllllllllllllllll

fun case

I think I saw that your Java was outdated. You should only use 64-bit java if you use a 64-bit browser. I think this is not yet the standard.

You need to install the latest version of Java. Having the latest version is important to take advantage of fixes that have eliminated security vulnerabilities.
  • Go to Start > Control Panel
  • Double-click on Add or Remove Programs
  • Look for entries that say Java, Java RunTime Environment or J2SE.
  • Uninstall all of them that are not named Java (TM) 6 Update 30
After doing this, you can go to java.com, click on Free Java Download and proceed from there to install the latest version of Java (currently Version 6 Update 30).

After installing Java, go to Start > Control Panel > Java to open the Java Control Panel.
Under the General tab, Temporary Internet Files click Settings, then click Delete Files.
Select both options and click OK to delete the Java cache.
Gabethebabe is offline   Reply With Quote
Old 01-20-2012, 06:38 PM   #50
SGicz
newbie
 
Join Date: Dec 2011
Posts: 27
Re: TDSSKiller won't run (Re-direct/System Fix Virus)

Java is now up to date. Any other suggestions? Anything else that looks out of sorts?
SGicz is offline   Reply With Quote

Reply
      

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off


Forum Jump


All times are GMT -4. The time now is 10:03 PM.


Powered by vBulletin®
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
Search Engine Optimisation provided by DragonByte SEO v2.0.33 (Pro) - vBulletin Mods & Addons Copyright © 2016 DragonByte Technologies Ltd.
Copyright Đ 2008-2010, Two Plus Two Interactive
 
 
Poker Players - Streaming Live Online