cmd at / delete:
oh, I already had pressed 'Y' in my last attempt
and then a new line of C:\Documents and Settings\Administrator>
had appeared, so I guess the deleting of scheduled tasks went through then, or at least now
vvvvvvvvvvvv
it was in the first run of TDSSKiller that on default it was set to 'skip' for the
2011/02/01 02:54:59.0359 Forged file(mefbxzgm) - User select action: Skip
for the next run I had changed it to 'delete' so it should be gone now
now also I tried again the cdm:
sc config mefbxzgm start= disabled
it leads to the info: 'The specified service does not exist as an installed service
however doing the sc config xpkihsl start= disabled
which I thought we also had successfully removed, now says: 'access is denied'
vvvvvvvvvvvvvv
when running Combofix, before starting it's proper scan, a message box comes saying:
'This machine does not have the 'Microsoft Windows Recovery console' installed. Alternatively, an existing installation of the recovery console may be present but requires updating.
Without it, Combofix shall not attempt to fixing of some of serious infections.
Click 'Yes' to have Combofix download/install it.
NOTE: this requires an active internet connection'
I had pressed 'YES' also for, in the meantime, two prior runs of Combofix.
It had said it downloaded and installed the 'Microsoft Windows Recovery console' during the fist run of Combofix, ending in:
'Congratulations!!! Microsoft Recovery Console was successfully installed.
On each restart of the machine, a black screen will offer you the option to boot into recovery console mode.
For normal use, just ignore theblack screen. windows shall boot normally in 2 seconds
Click 'Yes' to continue scaning for malware'
but: the same message that the 'Microsoft Windows Recovery console' is missing and needs to be installed again popped up in the second, and now again on starting the third run of Combofix!?
doing this third run of Combofix:
after some 10 minutes the screen went black ( I guess just something like an automatic 'screen saver mode' but it had not been working lately )
left it there another 15 minutes
then clicked left on the mouse to make the screen come back,
the Combofix still seemed running ( and the watch of the computer, like during the two earlier scans stopped running )
left it running abother 45 minutes but there was no further change inside the message box of Combofix so I turned off the computer then
so again no Combofix log..
should I have left it scanning even longer?
vvvvvvvvvvvvv
log of the new run of GMER:
GMER 1.0.15.15530 - http://www.gmer.net
Rootkit scan 2011-02-02 15:57:33
Windows 5.1.2600 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600BEVS-22RST0 rev.04.01G04
Running: l2901tnx.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\uwldrpog.sys
---- Kernel code sections - GMER 1.0.15 ----
pnidata C:\WINDOWS\system32\DRIVERS\secdrv.sys unknown last section [0xAC772F00, 0x24000, 0x48000000]
---- User code sections - GMER 1.0.15 ----
.text C:\WINDOWS\Explorer.EXE[268] ntdll.dll!DbgBreakPoint 7C901230 1 Byte [C3]
.text C:\WINDOWS\Explorer.EXE[268] ntdll.dll!DbgUiRemoteBreakin 7C95077B 5 Bytes JMP 7C923DEF C:\WINDOWS\system32\ntdll.dll (NT Layer DLL/Microsoft Corporation)
.text C:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!DbgBreakPoint 7C901230 1 Byte [C3]
.text C:\WINDOWS\System32\svchost.exe[1440] ntdll.dll!DbgUiRemoteBreakin 7C95077B 5 Bytes JMP 7C923DEF C:\WINDOWS\system32\ntdll.dll (NT Layer DLL/Microsoft Corporation)
---- User IAT/EAT - GMER 1.0.15 ----
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExA] [6144AE29] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenu] [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!TrackPopupMenuEx] [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!GetStockObject] [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA] [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW] [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW] [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExA] [6144AE29] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!AnimateWindow] [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx] [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcA] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColor] [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DefWindowProcW] [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetSysColorBrush] [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
IAT C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[3728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!TrackPopupMenu] [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\system32\svchost.exe (*** hidden *** ) [DISABLED] xpkihsl <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@DisplayName Manager Driver
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@Type 32
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@Start 4
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl\Parameters
Reg HKLM\SYSTEM\CurrentControlSet\Services\xpkihsl\Parameters@Se rviceDll C:\WINDOWS\system32\tiusetr.dll
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@DisplayName Manager Driver
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@Type 32
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@Start 4
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@ImagePath %SystemRoot%\system32\svchost.exe -k netsvcs
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl@Description Allows error reporting for services and applictions running in non-standard environments.
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl\Parameters (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\xpkihsl\Parameters@Servic eDll C:\WINDOWS\system32\tiusetr.dll
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@DeviceNotSelectedTimeout 15
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@GDIProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@Spooler yes
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@swapdisk
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@TransmissionRetryTimeout 90
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@USERProcessHandleQuota 10000
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows@LoadAppInit_DLLs 1
---- EOF - GMER 1.0.15 ----
I tried as you instructed, opened GMER again.
however on opening the scan always immediately starts,
therefore I failed to do the right click to choose to scan only MS files
( once the scan is running the right click does not do anything and there is no 'pause' button neither )
..so sorry, no second GMER log
the computer already is much more responsive and pleasant to use
best greetings,
anderle



Zitieren