Hello all,
a few weeks ago I noticed my computer was running slow, I used anti malaware bytes to scan and found 50 infected items, which I deleted.
My computer seemed to be doing fine until one day it was incredibly slow. I checked windows task manager, and my computer was at 100% cpu usage, never dropping, just staying constant.
I checked the processes and one was "Apple mobile devices services" or something similar. I do not have an Ipod, Iphone, nor do I itunes installed, so I was very suspicious. I tried ending it as a process but it kept coming back. I even tried to lower its priority, and I got an "Access is denied" error message, when I am the Administrator of my computer.
I searched my computer for apple and found three files with the name "apple mobile device services". At least one of them was locked with a password, but I used password breaker to unlock it.
Now, my computer is randomly going from 100% cpu usage to somewhere around 12 % cpu usage, and it will not connect to wireless internet. (Wired works fine, this might be a different problem but I wasn't sure)
I really do believe I have a virus, thank you for your time and hopefully your help.
Here are the logs, I was not able to get the DDS logs, it would never finish a scan on my computer and whenever I ran it I had to reboot. Also, I tried to remove any peer to peer programs, but if there are any left I apologize.
GMER ONE:
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit quick scan 2011-05-07 13:25:50
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST9408114A rev.8.03
Running: 6fkxeje6.exe; Driver: C:\DOCUME~1\Chance\LOCALS~1\Temp\uxldqaog.sys
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- System - GMER 1.0.15 ----
SSDT spnp.sys ZwEnumerateKey [0xB9ECDDA4]
SSDT spnp.sys ZwEnumerateValueKey [0xB9ECE132]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi \Device\Ide\IdePort0 [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\aj984yqm \Device\Scsi\aj984yqm1Port2Path0Target0Lun0 89600500
Device \Driver\aj984yqm \Device\Scsi\aj984yqm1 89600500
Device \FileSystem\Ntfs \Ntfs 89ACC1F8
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
---- EOF - GMER 1.0.15 ----
GMER TWO:
GMER 1.0.15.15627 - http://www.gmer.net
Rootkit scan 2011-05-07 13:28:17
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort0 ST9408114A rev.8.03
Running: 6fkxeje6.exe; Driver: C:\DOCUME~1\Chance\LOCALS~1\Temp\uxldqaog.sys
---- System - GMER 1.0.15 ----
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0xA940C610]
SSDT spnp.sys ZwCreateKey [0xB9EB50E0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0xA940CC10]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0xA940C730]
SSDT spnp.sys ZwEnumerateKey [0xB9ECDDA4]
SSDT spnp.sys ZwEnumerateValueKey [0xB9ECE132]
SSDT spnp.sys ZwOpenKey [0xB9EB50C0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0xA940C4B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0xA940C570]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0xA940C6D0]
SSDT spnp.sys ZwQueryKey [0xB9ECE20A]
SSDT spnp.sys ZwQueryValueKey [0xB9ECE08A]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0xA940C690]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0xA940C650]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0xA940C7D0]
SSDT spnp.sys ZwSetValueKey [0xB9ECE29C]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0xA940C510]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0xA940C590]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0xA940C4D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0xA940C5D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0xA940C750]
INT 0x62 ? 89ACDBF8
INT 0x63 ? 895F5F00
INT 0x63 ? 895F5F00
INT 0x82 ? 89ACDBF8
INT 0x83 ? 895F5F00
INT 0xB4 ? 895F5F00
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 89ACC1F8
AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
Device \Driver\usbuhci \Device\USBPDO-0 895DD500
Device \Driver\usbuhci \Device\USBPDO-1 895DD500
Device \Driver\usbuhci \Device\USBPDO-2 895DD500
Device \Driver\usbuhci \Device\USBPDO-3 895DD500
Device \Driver\usbehci \Device\USBPDO-4 8976D1F8
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
Device \Driver\Ftdisk \Device\HarddiskVolume1 89A5F1F8
Device \Driver\Cdrom \Device\CdRom0 895FC500
Device \Driver\Cdrom \Device\CdRom1 895FC500
Device \Driver\atapi \Device\Ide\IdePort0 [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdePort1 [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e [B9E11B40] atapi.sys[unknown section] {MOV EDX, [ESP+0x8]; LEA ECX, [ESP+0x4]; PUSH EAX; MOV EAX, ESP; PUSH EAX}
Device \Driver\NetBT \Device\NetBt_Wins_Export 8972E500
Device \Driver\NetBT \Device\NetbiosSmb 8972E500
Device \Driver\PCI_PNP5932 \Device\0000004c spnp.sys
Device \Driver\sptd \Device\2542950932 spnp.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{6863198E-FAAB-483C-9717-FABA7F3633E9} 8972E500
Device \Driver\usbuhci \Device\USBFDO-0 895DD500
Device \Driver\usbuhci \Device\USBFDO-1 895DD500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 89650500
Device \Driver\usbuhci \Device\USBFDO-2 895DD500
Device \Driver\NetBT \Device\NetBT_Tcpip_{C67F00D5-D713-49DD-8A2C-858157CA4792} 8972E500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 89650500
Device \Driver\usbuhci \Device\USBFDO-3 895DD500
Device \Driver\usbehci \Device\USBFDO-4 8976D1F8
Device \Driver\Ftdisk \Device\FtControl 89A5F1F8
Device \Driver\aj984yqm \Device\Scsi\aj984yqm1Port2Path0Target0Lun0 89600500
Device \Driver\aj984yqm \Device\Scsi\aj984yqm1 89600500
Device \FileSystem\Cdfs \Cdfs 897381F8
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x5C 0x7B 0xEB 0x65 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xD1 0x21 0x5C 0xF0 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xAA 0x68 0x0C 0xF8 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files\Alcohol Soft\Alcohol 120\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0x5C 0x7B 0xEB 0x65 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0xD1 0x21 0x5C 0xF0 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xAA 0x68 0x0C 0xF8 ...
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 MBR read error
Disk \Device\Harddisk0\DR0 MBR BIOS signature not found 0
---- EOF - GMER 1.0.15 ----
MBA scan:
Internet Explorer 8.0.6001.18702
5/7/2011 5:25:58 PM
mbam-log-2011-05-07 (17-25-58).txt
Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 189911
Time elapsed: 26 minute(s), 1 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)