60GB Hard Drive Space Gone in Two Minutes - Malware or Virus? |
![]() ![]() |
60GB Hard Drive Space Gone in Two Minutes - Malware or Virus? |
Sep 13 2009, 10:20 AM
Post
#1
|
|
|
New Member ![]() Posts: 8 OS: Vista |
Hello,
This morning I was downloading ringtones on a website and all was well until one that I downloaded throw up 50 pop-ups and starting making Horse sounds really loudly. I opened up task manager straight away and deleated a bunch of stuff I didn't recognise. Strangly AVG disappeared from my computer at the same time. Loads of 'XXXXX Program Didn't Install Correctly' promts came up and then instantly a warning that my computer was running low on memory. I checked it straight away and it was down to 875MB!! from the 62GB it was earlier today. I have ran Malwarebytes which found loads of stuff and also ran AVG again from a fresh Install. I am still however getting popups aswell as the Disk Space still only being back up to 3.7GB Windows Security is also infected in someway as I am unable to switch it on: ![]() Any help would be great. Thanks in advance, Declan This post has been edited by decbohan22: Sep 13 2009, 10:41 AM |
|
|
Sep 13 2009, 10:36 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
Hello decbohan22
Welcome to G2Go. =====================
=========== Download This file. Note its name and save it to your root folder, such as C:\.
|
|
|
Sep 13 2009, 11:21 AM
Post
#3
|
|
|
New Member ![]() Posts: 8 OS: Vista |
Hello decbohan22 Welcome to G2Go. Thanks .. Copy)[/b] the contents of these files, one at a time, and post it with your next reply. Okay, did that ..
OTL_TXT_and_Extras.Txt ( 218.96K )
Number of downloads: 139Situation now worse. Windows Security switched off and unaccesible and Desktop is locked and can only access programmes and files through the start menu This post has been edited by decbohan22: Sep 13 2009, 11:22 AM |
|
|
Sep 13 2009, 11:33 AM
Post
#4
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
Do you have the other log?
This appears to be the source of infection: C:\users\declan\documents\downloads\programs\keygen.vidcrop.pro.1.0.0.11.exe Keygens are used to make expensive free and they are illegal and most if not all of them come with a malware surprise. Stay away from cracks\keygens of any kind or this will continue to happen. See if you can get me the other log and we will continue from there. |
|
|
Sep 13 2009, 11:42 AM
Post
#5
|
|
|
New Member ![]() Posts: 8 OS: Vista |
Do you have the other log? This appears to be the source of infection: C:\users\declan\documents\downloads\programs\keygen.vidcrop.pro.1.0.0.11.exe Keygens are used to make expensive free and they are illegal and most if not all of them come with a malware surprise. Stay away from cracks\keygens of any kind or this will continue to happen. See if you can get me the other log and we will continue from there. Not sure what a keygen is but I did downloaded Vidcrop from a website earlier - so that's what it was. It was from a video on Youtube and in the description area on the right was that link. It didn't download so thought no more of it .. The other file that you need is just below that one in the TXT file .. I cut & pasted both in the one document. Thanks for your help. Really appreciate ie .. This post has been edited by decbohan22: Sep 13 2009, 11:43 AM |
|
|
Sep 13 2009, 12:30 PM
Post
#6
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
Hi no I meant the rootkit scan log it is not in with the rest it is only 2 OTL files.
See if you can get that for me please. |
|
|
Sep 13 2009, 03:01 PM
Post
#7
|
|
|
New Member ![]() Posts: 8 OS: Vista |
Hi no I meant the rootkit scan log it is not in with the rest it is only 2 OTL files. See if you can get that for me please. Hi, Okay .. took a while as the program kept crashing. Four times in all - so I just kept rebooting. At the end it said: "GMER HAS FOUND SYSTEM MOD CAUSED BY ROOTKIT ACTIVITY" and also the following part was RED: "Library C:\Program (*** hidden *** ) @ C:\Program [3268] 0x00400000" If there is anything else you need just let me know. Thanks again ..
GMERResults.txt ( 8.86K )
Number of downloads: 2GMER 1.0.15.15077 [RootLogThing.exe] - http://www.gmer.net Rootkit scan 2009-09-13 21:53:22 Windows 6.0.6002 Service Pack 2 ---- System - GMER 1.0.15 ---- INT 0x61 ? 9C118CD0 INT 0x71 ? 9C0FA050 INT 0xB3 ? 9C0FACD0 ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [749D7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [74A2A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [749DBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [749CF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [749D75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [749CE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74A08395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [749DDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [749CFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [749CFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [749C71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [74A5CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [749FC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [749CD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [749C6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [749C687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\Explorer.EXE[2256] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [749D2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) AttachedDevice \Driver\tdx \Device\Tcp tdifw_drv.sys AttachedDevice \Driver\tdx \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\tdx \Device\Udp tdifw_drv.sys AttachedDevice \Driver\tdx \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) AttachedDevice \Driver\tdx \Device\RawIp tdifw_drv.sys AttachedDevice \Driver\tdx \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.) ---- Processes - GMER 1.0.15 ---- Library C:\Program (*** hidden *** ) @ C:\Program [3268] 0x00400000 ---- Registry - GMER 1.0.15 ---- Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6E652B76-8D91-FE0C-7086-1312CF84256D} Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6E652B76-8D91-FE0C-7086-1312CF84256D}@oagakhclcljedjbbdcbdpchgndbdfp 0x64 0x61 0x67 0x63 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6E652B76-8D91-FE0C-7086-1312CF84256D}@oacbcpbgcacclehljhmmefopcpalap 0x6A 0x61 0x6A 0x61 ... Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{6E652B76-8D91-FE0C-7086-1312CF84256D}@namaihcdlihoflleafbdkgapjmnk 0x6A 0x61 0x6A 0x61 ... ---- EOF - GMER 1.0.15 ---- This post has been edited by decbohan22: Sep 13 2009, 03:03 PM |
|
|
Sep 13 2009, 03:06 PM
Post
#8
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
Download ComboFix from one of these locations:
Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. |
|
|
Sep 13 2009, 03:51 PM
Post
#9
|
|
|
New Member ![]() Posts: 8 OS: Vista |
Please include the C:\ComboFix.txt in your next reply. Hi, here you go ..
Combo_Fix_Log.txt ( 35.62K )
Number of downloads: 10 |
|
|
Sep 13 2009, 07:37 PM
Post
#10
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
First: Update Run Malwarebytes
Please update\run Malwarebytes' Anti-Malware. Double Click the Malwarebytes Anti-Malware icon to run the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley. ===== Second: Online Scanner Please do a scan with Kaspersky Online Scanner Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. Click on the Accept button and install any components it needs.
|
|
|
Sep 14 2009, 06:34 AM
Post
#11
|
|
|
New Member ![]() Posts: 8 OS: Vista |
First: Update Run Malwarebytes Please update\run Malwarebytes' Anti-Malware. [*]Copy&Paste the entire report in your next reply. Second: Online Scanner [*]Copy and paste that information in your next post. Thanks, here are those reports .. Malwarebytes __________________________________________________________________________________________ Malwarebytes' Anti-Malware 1.41 Database version: 2794 Windows 6.0.6002 Service Pack 2 14/09/2009 03:02:40 mbam-log-2009-09-14 (03-02-40).txt Scan type: Quick Scan Objects scanned: 90829 Time elapsed: 9 minute(s), 29 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syntpenh (Trojan.Downloader) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Program Files\Synaptics\SynTP\syntpenh.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\System32\rthdvcpl.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Windows\System32\hkcmd.exe113 (Trojan.Downloader) -> Quarantined and deleted successfully. _____________________________________________________________________________________ KASPERSKY -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Monday, September 14, 2009 Operating system: Microsoft Windows Vista Business Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, September 14, 2009 05:39:06 Records in database: 2803095 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Objects scanned: 122281 Threats found: 1 Infected objects found: 8 Suspicious objects found: 0 Scan duration: 06:09:33 File name / Threat / Threats count C:\Program Files\Adobe\acrotray .exe Infected: Backdoor.Win32.Small.yb 1 C:\Program Files\AVG\AVG8\avgtray.exe183 Infected: Backdoor.Win32.Small.yb 1 C:\Program Files\Synaptics\SynTP\syntpenh.exe104 Infected: Backdoor.Win32.Small.yb 1 C:\Program Files\Synaptics\SynTP\syntpenh.exe156 Infected: Backdoor.Win32.Small.yb 1 C:\Program Files\Synaptics\SynTP\syntpenh.exe180 Infected: Backdoor.Win32.Small.yb 1 C:\Program Files\Windows Defender\msascui.exe -hide Infected: Backdoor.Win32.Small.yb 1 C:\Qoobox\Quarantine\C\Windows\System32\rthdvcpl .exe.vir Infected: Backdoor.Win32.Small.yb 1 C:\Users\Declan\AppData\Roaming\IDM\rthdvcpl.exe Infected: Backdoor.Win32.Small.yb 1 Selected area has been scanned. ---------------------------------------------------------------------------------- |
|
|
Sep 14 2009, 12:03 PM
Post
#12
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
1. Open notepad and copy/paste the text in the codebox below into it:
CODE http://www.geekstogo.com/forum/60GB-Hard-Drive-Space-Gone-Two-Minutes-Malware-Virus-t252629.html#entry1640704 Collect:: C:\Program Files\Adobe\acrotray .exe C:\Program Files\AVG\AVG8\avgtray.exe183 C:\Program Files\Synaptics\SynTP\syntpenh.exe104 C:\Program Files\Synaptics\SynTP\syntpenh.exe156 C:\Program Files\Synaptics\SynTP\syntpenh.exe180 C:\Program Files\Windows Defender\msascui.exe -hide C:\Users\Declan\AppData\Roaming\IDM\rthdvcpl.exe ![]() Refering to the picture above, drag CFScript.txt into ComboFix.exe When finished, it shall produce a log for you. Post that log in your next reply. **Note** When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
=========== Note:: If Combofix fails to upload anything please do the following: Go to Start > My Computer > C:\ Then Navigate to C:\Qoobox\Quarantine\[4]-Submit_Date_Time.zip Click Here to upload the submit.zip please. |
|
|
Sep 15 2009, 07:33 PM
Post
#13
|
|
|
New Member ![]() Posts: 8 OS: Vista |
|
|
|
Sep 15 2009, 07:41 PM
Post
#14
|
|
![]() GeekU Teacher Posts: 13,543 From: Florida OS: Windows xp,Vista business |
Please read my previous post.
You have to create a text file called cfscript. Then the contents would be the text inside of the code box in my above post. |
|
|
Sep 15 2009, 08:38 PM
Post
#15
|
|
|
New Member ![]() Posts: 8 OS: Vista |
Please read my previous post. You have to create a text file called cfscript. I did read it but you never said I had to call the txt file CFScript. Anyway, I have uploaded it. Thanks again for your time ..
Attached File(s)
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
19 / 1,489 | 17th September 2008 - 01:31 PM pulchritude08 started - last by Essexboy |
|||||
![]() |
11 / 784 | 20th March 2009 - 10:46 AM mintchip started - last by MickDublin |
|||||
![]() |
1 / 541 | 19th December 2008 - 02:46 PM BlackCat13 started - last by wannabe1 |
|||||
![]() |
13 / 419 | 13th April 2009 - 05:54 PM MattCharles started - last by MattCharles |
|||||
|
Time is now: 20th November 2009 - 09:52 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising