Hi all. I would like to thank everyone who helped fix the rootkit virus on my computer last week and a special mention to crunchie from Mandurah, WA for some extraordinary support.
Sadly, this time a friend's PC is sick and needs some help. He got me a list of files that he thinks are trojans/worms on his PC, possibly appeared in an Norton AV or AVG scan. I have tried to have a look at his PC, and it is simply struggling. Windows takes forever to load unless started up in safe mode. Below is the list that he provided me with:
Hi Train. Sorry for the late post. Been running around a little bit to get things done.
The Malwarebytes scan appeared with 22 infections like Rootkits, Trojans and Worms. Cleaned all of these. The GMER scan didn't work too well and rebooted the PC automatically, so ran the Gooredfix scan instead. Also ran the DDS scan. Logs in the next post.
DDS (Ver_10-03-17.01) - NTFSx86 NETWORK
Run by Admin at 16:05:35.17 on Sun 12/09/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1398 [GMT 10:00]
Attach.txt:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 1/01/2007 10:21:44 PM
System Uptime: 9/12/2010 3:54:40 PM (-2111 hours ago)
C: is FIXED (NTFS) - 298 GiB total, 251.964 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP657: 31/05/2010 6:00:10 PM - System Checkpoint
RP658: 1/06/2010 7:42:52 PM - System Checkpoint
RP659: 3/06/2010 11:57:32 PM - System Checkpoint
RP660: 5/06/2010 12:52:32 PM - Software Distribution Service 3.0
RP661: 6/06/2010 2:02:55 PM - System Checkpoint
RP662: 7/06/2010 4:17:38 PM - System Checkpoint
RP663: 8/06/2010 4:46:28 PM - System Checkpoint
RP664: 9/06/2010 5:14:15 PM - System Checkpoint
RP665: 9/06/2010 7:55:47 PM - Installed Windows XP -- Software Updates KB952011.
RP666: 9/06/2010 8:01:18 PM - Software Distribution Service 3.0
RP667: 10/06/2010 9:32:51 PM - System Checkpoint
RP668: 11/06/2010 10:33:18 PM - System Checkpoint
RP669: 13/06/2010 11:35:05 AM - System Checkpoint
RP670: 14/06/2010 2:30:08 PM - System Checkpoint
RP671: 15/06/2010 5:47:11 PM - System Checkpoint
RP672: 17/06/2010 1:28:15 PM - System Checkpoint
RP673: 18/06/2010 6:49:58 PM - System Checkpoint
RP674: 20/06/2010 7:23:32 PM - System Checkpoint
RP675: 21/06/2010 8:09:24 PM - System Checkpoint
RP676: 22/06/2010 8:29:42 PM - System Checkpoint
RP677: 23/06/2010 1:08:47 PM - Avg8 Update
RP678: 24/06/2010 10:24:20 PM - Software Distribution Service 3.0
RP679: 28/06/2010 5:46:14 PM - System Checkpoint
RP680: 29/06/2010 7:09:37 PM - System Checkpoint
RP681: 30/06/2010 9:38:12 PM - System Checkpoint
RP682: 3/07/2010 6:01:51 PM - System Checkpoint
RP683: 5/07/2010 6:00:12 PM - System Checkpoint
RP684: 6/07/2010 9:14:30 PM - System Checkpoint
RP685: 8/07/2010 11:27:34 AM - System Checkpoint
RP686: 9/07/2010 11:30:33 AM - Avg8 Update
RP687: 10/07/2010 3:45:34 PM - Avg8 Update
RP688: 11/07/2010 4:40:08 PM - System Checkpoint
RP689: 12/07/2010 5:59:11 PM - System Checkpoint
RP690: 13/07/2010 8:29:11 PM - System Checkpoint
RP691: 15/07/2010 5:28:08 PM - Software Distribution Service 3.0
RP692: 16/07/2010 8:52:53 PM - System Checkpoint
RP693: 18/07/2010 11:52:31 AM - System Checkpoint
RP694: 19/07/2010 6:09:57 PM - System Checkpoint
RP695: 20/07/2010 7:38:16 PM - System Checkpoint
RP696: 23/07/2010 9:02:27 PM - System Checkpoint
RP697: 25/07/2010 5:38:32 PM - System Checkpoint
RP698: 26/07/2010 6:07:19 PM - System Checkpoint
RP699: 27/07/2010 6:56:02 PM - System Checkpoint
RP700: 30/07/2010 8:14:29 PM - System Checkpoint
RP701: 1/08/2010 2:52:09 PM - System Checkpoint
RP702: 2/08/2010 6:01:02 PM - System Checkpoint
RP703: 3/08/2010 7:43:12 PM - System Checkpoint
RP704: 4/08/2010 3:41:13 PM - Software Distribution Service 3.0
RP705: 7/08/2010 7:53:26 PM - System Checkpoint
RP706: 9/08/2010 6:12:52 PM - System Checkpoint
RP707: 10/08/2010 6:34:47 PM - System Checkpoint
RP708: 13/08/2010 2:48:21 PM - Software Distribution Service 3.0
RP709: 14/08/2010 6:12:37 PM - System Checkpoint
RP710: 15/08/2010 6:49:16 PM - System Checkpoint
RP711: 17/08/2010 4:24:59 PM - System Checkpoint
RP712: 18/08/2010 7:41:11 PM - System Checkpoint
RP713: 20/08/2010 5:38:53 PM - System Checkpoint
RP714: 21/08/2010 6:39:28 PM - System Checkpoint
RP715: 22/08/2010 7:42:35 PM - System Checkpoint
RP716: 24/08/2010 6:58:59 PM - System Checkpoint
RP717: 26/08/2010 8:27:41 PM - Installed Java(TM) 6 Update 21
RP718: 26/08/2010 11:02:43 PM - avast! Free Antivirus Setup
RP719: 31/08/2010 10:39:34 AM - System Checkpoint
RP720: 3/09/2010 2:36:19 PM - System Checkpoint
==== Installed Programs ======================
µTorrent
Adobe Acrobat 5.0
Adobe Bridge 1.0
Adobe Common File Installer
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 8.1.3
Adobe Shockwave Player 11.5
Adobe Stock Photos 1.0
AFL Premiership 2005
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ArcSoft PhotoBase 3
ArcSoft PhotoStudio 5
avast! Free Antivirus
AVG Free 8.5
AviSynth 2.5
Bonjour
Canon CanoScan Toolbox 4.1
Click'N Design 3D (V5)
Compatibility Pack for the 2007 Office system
Critical Update for Windows Media Player 11 (KB959772)
DigitImg
DVD Shrink 3.2
DVD Suite
Google Chrome
Google Earth
Google Toolbar for Internet Explorer
Google Update Helper
Greeting Card Maker
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB954708)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Memories Disc
HP Software Update
Intel(R) Graphics Media Accelerator Driver
iTunes
Java Auto Updater
Java(TM) 6 Update 21
Java(TM) 6 Update 3
Java(TM) 6 Update 5
Java(TM) 6 Update 7
Java(TM) SE Runtime Environment 6
Junk Mail filter update
LimeWire PRO 4.12.6
Malwarebytes' Anti-Malware
Manual CanoScan LiDE 50
Messenger Plus! Live
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft ActiveSync
Microsoft Application Error Reporting
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Live Add-in 1.3
Microsoft Office Outlook Connector
Microsoft Office Professional Edition 2003
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
MixMeister Express 6 Demo
Mozilla Firefox (2.0.0.20)
MSN Toolbar
MSVCRT
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Nero 7 Essentials
ninemsn Internet Software
Norton PC Checkup
Norton Security Scan
OGA Notifier 1.7.0105.35.0
OmniPage SE
OpenOffice.org 2.2
Panasonic VS3_VS2_MX6_SA6 USB-Handset Manager
PC Wizard 2007.1.73
PCFriendly
Photosmart 140,240,7200,7600,7700,7900 Series
Picasa 3
PowerDVD
PowerProducer
Presto! PageManager 6
PS7700
PSP Video 9 5.03
PSShortcuts
PSUsage
QFolder
QuickTime
REALTEK GbE & FE Ethernet PCI-E NIC Driver
Realtek High Definition Audio Driver
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB972260)
Security Update for Windows Internet Explorer 8 (KB974455)
Security Update for Windows Internet Explorer 8 (KB976325)
Security Update for Windows Internet Explorer 8 (KB978207)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Segoe UI
SmartSound Quicktracks Plugin
Spybot - Search & Destroy
TrojanHunter 5.3
Ulead VideoStudio 10
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB976749)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB961503)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC 9.0 Runtime
VLC media player 0.9.9
WebFldrs XP
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Player 11
Windows XP Service Pack 3
WinRAR archiver
Yahoo! Install Manager
Yahoo! Search Protection
Yahoo! Software Update
Yahoo!7 Toolbar
YouTube Downloader App 2.03
ZoneAlarm Security Suite
ZoneAlarm Spy Blocker Toolbar
ZoneAlarm Toolbar
==== Event Viewer Messages From Past Week ========
8/09/2010 8:49:24 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
8/09/2010 8:48:53 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 AFD aswSP aswTdi AvgLdx86 AvgMfx86 AvgTdiX Fips intelppm IPSec kl1 KLIF MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip vsdatant
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The TrueVector Internet Monitor service depends on the vsdatant service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the AFD service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The IPSEC Services service depends on the IPSEC driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The DNS Client service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The DHCP Client service depends on the NetBios over Tcpip service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The avast! Web Scanner service depends on the avast! Antivirus service which failed to start because of the following error: The dependency service or group failed to start.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The avast! Mail Scanner service depends on the avast! Antivirus service which failed to start because of the following error: The dependency service or group failed to start.
8/09/2010 8:48:53 AM, error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/09/2010 8:48:52 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}
8/09/2010 8:48:19 AM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service netman with arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
8/09/2010 5:46:53 PM, error: Ntfs [55] - The file system structure on the disk is corrupt and unusable. Please run the chkdsk utility on the volume C:.
6/09/2010 5:54:44 PM, error: Service Control Manager [7022] - The UStorage Server Service service hung on starting.
6/09/2010 5:54:44 PM, error: Service Control Manager [7022] - The AVG8 E-mail Scanner service hung on starting.
6/09/2010 5:54:44 PM, error: Service Control Manager [7022] - The Apple Mobile Device service hung on starting.
6/09/2010 5:53:18 PM, error: Service Control Manager [7022] - The avast! Mail Scanner service hung on starting.
10/09/2010 7:17:24 PM, error: DCOM [10005] - DCOM got error "%1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
10/09/2010 7:13:55 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Aavmker4 aswSP aswTdi AvgLdx86 AvgMfx86 Fips intelppm kl1 KLIF
I know this isn't in the manual, but I've also tried the following scans: TDSSKiller, stinger, spybot search and destroy, unhackme, trojanhunter, securitycheck, stinger and combofix. Each of these scans had to be run in safe mode since when loading up Windows XP in normal mode, the desktop background is displayed but none of the icons appear, nor does the taskbar appear. The PC just freezes at this stage until it is rebooted via the CPU.
The trojanhunter scan popped up a message which I have attached here. Don't worry, the virus is on my friend's PC, not mine. And I've scanned the USB stick twice on my PC to check if any viruses got copied and none did. Have also attached the scan logs of some of the scans.