Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Gmer scan not completing


  • Please log in to reply

#16
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hi Ron,

Some more information after the reboot....

I have run the sigverif and the list is quite big so some of the more recent entries include;
wmpdxm.dll
mxdwdrv.dll
mxdwdui.ini
logagent.exe
slextspk.dll
unregmp2.exe



Vino's Event Viewer v01c run on Windows XP in English
Report run at 24/10/2010 21:57:49

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

Advertisements


#17
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
for the application part of VEW here is the log;


Vino's Event Viewer v01c run on Windows XP in English
Report run at 24/10/2010 22:00:08

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#18
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,629 posts
  • MVP
The files from sigverif are from Windows Media Player and a modem. Nothing to worry about. The event logs came up clean too which is great. I think we are done except for some housekeeping.

We need to clean up System Restore. Follow Jim's procedure here:
http://forum.aumha.o...581099691bf108f


You can uninstall or delete any tools we had you download and their logs.
To uninstall combofix, copy the next line:

"%userprofile%\Desktop\george.exe" /Uninstall

Start, Run, cmd, OK then right click, Paste, then hit Enter.

To hide hidden files again:

XP

# Close all programs so that you are at your desktop.
# Double-click on the My Computer icon.
# Select the Tools menu and click Folder Options.
# After the new window appears select the View tab.
# Uncheck the checkbox labeled Display the contents of system folders.
# Under the Hidden files and folders section select the 'Hide protected operating system files (recommended)' option.
# Check the checkbox labeled Hide protected operating system files.
# Press the Apply button and then the OK button and shutdown My Computer.

You do not have the latest Java (Java™ 6 Update 22). Get the latest at:

http://javadl.sun.co...?BundleId=41723

Save it to your PC then close all browsers and install it.

Once you install it, go into Control Panel, Add/Remove Software and remove any old versions (which may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE)



Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat. Adobe is fond of foisting GetPlus on you. You can let them install it and then afterwards, go into Control Panel, Add/Remove Software and remove it. It probably doesn't hurt to leave it but I don't see the need for it and it has caused problems in the past.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program. There is an exploit out there now that can use it to get on your PC. For Adobe Reader: Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript. OK Close program. It's the same for Foxit reader except you uncheck Enable Javascript Actions.

I recommend you install the free WinPatrol 18.1 from http://www.winpatrol.com/download.html

It's a small program that will sit in your systray and warn you if something tries to make changes to your system.

If you use USB drives you might want to install Autorun Eater v2.5.
http://download.cnet...4-10752777.html
Another small program which will stay resident and prevent an infected USB drive from infecting your PC.

If you use Firefox then get the AdBlock Plus Add-on. WOT (Web of Trust) and No Script are two others you might want to try.

If Firefox is slow loading make sure it only has the current Java add-on. Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox. It seems to work best if you reboot right after running it. You can run it any time that Firefox seems slow.

Be warned: If you use Limewire, utorrent or any of the other P2P programs you will almost certain be coming back to the Malware Removal forum. If you must use P2P then submit any files you get to http://virustotal.com before you open them.

If you install the MVP Hosts file:
http://www.mvps.org/...p2002/hosts.htm
it will keep you from going to most bad sites. You do not need Spybot's Immunize which does the same thing.

If you have a router, log on to it today and change the default password!

Ron
  • 0

#19
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hi Ron

Thank you for the help so far.
I have tried to run the Gmer scan again and it is still stalling my computer.
I have run it now for many hours. I have tried to save but the Pc is not responding.
There are many entries that have come up.
The are all like this from sector 1 to sector 61;

Disk \Device\Harddisk0\DR0 sector46: copy of MBR
and

Disk \Device\Harddisk0\DR0 sector62: rootkit-like behavior; copy...

Disk \Device\Harddisk0\DR0 sector63: rootkit-like behavior; copy...

Please advise.
  • 0

#20
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,629 posts
  • MVP
What we usually do in this situation is either run mbr -f or boot into the recovery console and run fixmbr. Problem is that doing either can be dangerous. It may not boot afterward and if you have a hidden partition with the recovery to factory default on it you will lose it. With no other sign of a problem do you want to try it? Best to back up your data first. Do you have the Operating System disks in case you need to reinstall from scratch?

Let's try one more tool first.

Download ice sword from:

http://majorgeeks.co...word_d5199.html
using one of the links under DOWNLOADS.

SAVE it to your desktop, close all programs and then Rightclick on it and select Extract All. Let it extract to your desktop. It should create a folder icesword122en on your desktop. Doubleclick on the folder icesword122en to open it and then doubleclick on icesword.exe. (If it complains about something hooking when it first tries to open that's a sign of a possible rootkit.)

It should open a new window.

Step 1 : Close all windows and run IceSword. Click the Processes tab and watch for processes displayed in red color. A red colored process in this list indicates that it's hidden. Write down the PathName of any processes in red color. Then click on LOG at the top left. It will prompt you to save the log, call this Processes and save it to your desktop.

Step 2 : Click the Win32 Services tab and look out for red colored entries in the services list. Write down the Module name of any services in red color, you will need to expand out the Module tab to see the full name. Then click on LOG. It will prompt you to save the log, call this Services and save it to your desktop.

Step 3 : Click the Startup tab and look out for red colored entries in the startup list. Write down the Path of any startup entries in red color (Often the same path will show up over and over. Just give me the path once). Then click on LOG. It will prompt you to save the log, call this Startup and save it to your desktop.

Step 4 : Click the SSDT tab and check for red colored entries. If there are any, write down the KModule name.

Step 5 : Click the Message Hooks tab and check for any entries that are underneath Type and labelled WH_KEYBOARD. Write down the Process Path of these entries if present.

Now post all of the data collected under the headings for :

Processes
Win32 Services
Startup
SSDT
Message Hooks

Ron
  • 0

#21
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hi Ron,

Now I try to do the things that you have said on the Pc and for whatever reason all the internet connections have gone.
The Pc is connected by ethernet cable and I am working on my laptop wireless. Please advise on how I can get this back first before I can proceed.
  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,629 posts
  • MVP
Start, Run, devmgmt.msc, OK to bring up Device Manager. Find Network Adapters and click on the + in front of it. For each network Adapter, right click and uninstall then close device manager and

Start, Run, cmd, OK then type:


netsh  winsock  reset  catalog

netsh  int  ip  reset  reset.log

exit

Now restart. Any better?

Ron
  • 0

#23
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Ron,

I have restarted now but am still on my laptop. Now at lease the light is on at the back of the pc where the cable connects as before it was not.
I am now being asked to install Intel® PRO/100 VE Network Connection
However as I go to install automatically it tells me that 'the file e100b325.sys on Intel PRO adapter CD-Rom or Floppy disk is required'

Where to?!
  • 0

#24
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,629 posts
  • MVP
Very Strange. We didn't do anything so I don't know why it should have stopped working. Perhaps a hard drive glitch. Might need to run a disk check again.

Should be part of this download:

http://www.intel.com...b/cs-026658.htm
  • 0

#25
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hi Ron,

Now i'm a little lost!
Should I do a system check like before?
Or maybe should I try to uninstall the drivers as before and try again?
  • 0

Advertisements


#26
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,629 posts
  • MVP
1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, then reboot.

The file it is looking for used to be present

2010/10/24 18:51:12.0984 E100B (7d91dc6342248369f94d6eba0cf42e99) C:\WINDOWS\system32\DRIVERS\e100b325.sys

There might be another copy hanging around which would save downloading the big file:

Start, Run, cmd, OK then

cd \

dir /a /s e100b325.sys



Ron
  • 0

#27
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Ok Ron,
I have completed the system check and have done the command prompt which has given me the following;

Directory of c:\Applications\Driver\LAN\PRO100\WS03XP2
11/02/2004 1 File 154,112 bytes e100b325.sys


Directory of c:\WINDOWS\System32\dllcache
17/08/2001 1 File 117,760 bytes e100b325.sys


Directory of c:\WINDOWS\System32\drivers
17/08/2001 1 File 117,760 bytes e100b325.sys

How should I proceed now?
When I am asked to put in a CD or Floppy Disk should I instead specify one of these paths instead?
  • 0

#28
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,629 posts
  • MVP
Yes that should make it happy. You might give it the newer one:
11/02/2004 1 File 154,112 bytes e100b325.sys
  • 0

#29
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Hey Ron,

Great I'm back online!
Thanks for the help with that diversion!
I will go back now and complete your advice from earlier today starting with ice sword.
  • 0

#30
brodigan

brodigan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 73 posts
Ok Ron,
Here are the results of Icesword;

Process:

System Idle Process
System
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Digital Media Reader\shwiconEM.exe
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\alg.exe
C:\Documents and Settings\Maureen\Desktop\IceSword122en\IceSword.exe





Started Service:

Service Name:ALG Display Name:Application Layer Gateway Service
Service Name:AudioSrv Display Name:Windows Audio
Service Name:BITS Display Name:Background Intelligent Transfer Service
Service Name:CCALib8 Display Name:Canon Camera Access Library 8
Service Name:Creative Service for CDROM Access Display Name:Creative Service for CDROM Access
Service Name:CryptSvc Display Name:CryptSvc
Service Name:DcomLaunch Display Name:DCOM Server Process Launcher
Service Name:Dhcp Display Name:DHCP Client
Service Name:Dnscache Display Name:DNS Client
Service Name:ERSvc Display Name:Error Reporting Service
Service Name:Eventlog Display Name:Event Log
Service Name:EventSystem Display Name:COM+ Event System
Service Name:FastUserSwitchingCompatibility Display Name:Fast User Switching Compatibility
Service Name:helpsvc Display Name:Help and Support
Service Name:HidServ Display Name:HID Input Service
Service Name:iPod Service Display Name:iPod Service
Service Name:lanmanserver Display Name:Server
Service Name:lanmanworkstation Display Name:Workstation
Service Name:LexBceS Display Name:LexBce Server
Service Name:LmHosts Display Name:TCP/IP NetBIOS Helper
Service Name:MsMpSvc Display Name:Microsoft Antimalware Service
Service Name:Netman Display Name:Network Connections
Service Name:Nla Display Name:Network Location Awareness (NLA)
Service Name:PlugPlay Display Name:Plug and Play
Service Name:PolicyAgent Display Name:IPSEC Services
Service Name:ProtectedStorage Display Name:Protected Storage
Service Name:RasMan Display Name:Remote Access Connection Manager
Service Name:RpcSs Display Name:Remote Procedure Call (RPC)
Service Name:SamSs Display Name:Security Accounts Manager
Service Name:Schedule Display Name:Task Scheduler
Service Name:seclogon Display Name:Secondary Logon
Service Name:SENS Display Name:System Event Notification
Service Name:SharedAccess Display Name:Windows Firewall/Internet Connection Sharing (ICS)
Service Name:ShellHWDetection Display Name:Shell Hardware Detection
Service Name:SLService Display Name:SmartLinkService
Service Name:Spooler Display Name:Print Spooler
Service Name:srservice Display Name:System Restore Service
Service Name:SSDPSRV Display Name:SSDP Discovery Service
Service Name:stisvc Display Name:Windows Image Acquisition (WIA)
Service Name:TapiSrv Display Name:Telephony
Service Name:TermService Display Name:Terminal Services
Service Name:Themes Display Name:Themes
Service Name:TrkWks Display Name:Distributed Link Tracking Client
Service Name:W32Time Display Name:Windows Time
Service Name:WebClient Display Name:WebClient
Service Name:winmgmt Display Name:Windows Management Instrumentation
Service Name:wscsvc Display Name:Security Center
Service Name:wuauserv Display Name:Automatic Updates
Service Name:WudfSvc Display Name:Windows Driver Foundation - User-mode Driver Framework
Service Name:WZCSVC Display Name:Wireless Zero Configuration







Startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IgfxTray
C:\WINDOWS\system32\igfxtray.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
High Definition Audio Property Page Shortcut
HDAudPropShortcut.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
CHotkey
zHotkey.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ShowWnd
ShowWnd.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RemoteControl
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NeroFilterCheck
C:\WINDOWS\system32\NeroCheck.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SoundMan
SOUNDMAN.EXE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SunKistEM
C:\Program Files\Digital Media Reader\shwiconem.exe

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AlcWzrd
ALCWZRD.EXE

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Lexmark X1100 Series
"C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
QuickTime Task
"C:\Program Files\QuickTime\qttask.exe" -atboottime

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
iTunesHelper
"C:\Program Files\iTunes\iTunesHelper.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
GrooveMonitor
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Adobe Reader Speed Launcher
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SunJavaUpdateSched
"C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSSE
"c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MoneyAgent
"C:\Program Files\Microsoft Money\System\mnyexpr.exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
desktop.ini


C:\Documents and Settings\Maureen\Start Menu\Programs\Startup
Cyber-shot Viewer Media Check Tool.lnk
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe (Remark£ºCyber-shot Viewer Media Check Tool)

C:\Documents and Settings\Maureen\Start Menu\Programs\Startup
desktop.ini






SSDT-There were no red entries.





Message Hooks:

1. C:\WINDOWS\zHotkey.exe
2. C:\WINDOWS\system32\ctfmon.exe
3. C:\WINDOWS\explorer.exe
4. C:\Program Files\Sony\Sony Picture Utility\Volume Watcher\SPUVolumeWatcher.exe
5. C:\Program Files\Microsoft Security Essentials\msseces.exe
6. C:\WINDOWS\ALCWZRD.EXE
7. C:\Program Files\Microsoft Security Essentials\msseces.exe
8. C:\WINDOWS\explorer.exe
9. C:\WINDOWS\explorer.exe
10.C:\WINDOWS\zHotkey.exe
11.C:\WINDOWS\explorer.exe
12.C:\WINDOWS\explorer.exe


That's the lot.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP