Virus infection with jmp code

I have been infected with a virus for a few weeks or in one or two cases possibly since May.
That is based on 3 trojans identified by AVZ which is part of Kaspersky's suite of tools. There is another utility called GMER that has circumvented the attacking and disabling of anti-malware packages which has been a symptom of this trojan - likely the GameThief.Win32.Onlinegame.TGNK identified by AVZ.
The out put from GMER may be of interest and I wonder if you have any means of blocking it or can block it in an emergency patch. I've had to truncate some of the other bits which were similar apartments due to character limits
I hope this information is of use and if you recognise the malware please let me know or confirm which it is of Mailfinder, Gamethief or Downloader and more especially a package that can tackle it.
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-08-26 16:23:07
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 WDC_WD1600JB-00GVA0 rev.08.02D08 149.05GB
Running: 8xkqoifm.exe; Driver: C:\DOCUME~1\Mark\LOCALS~1\Temp\awloapod.sys
---- User code sections - GMER 2.1 ----
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 018D3D20 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtFlushBuffersFile 7C90D32E 5 Bytes JMP 018BC661 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtQueryFullAttributesFile 7C90D7AE 5 Bytes JMP 018D3820 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtReadFile 7C90D9CE 5 Bytes JMP 018BC750 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtReadFileScatter 7C90D9DE 5 Bytes JMP 0215E1FF C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtWriteFile 7C90DF7E 5 Bytes JMP 018D43D0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!NtWriteFileGather 7C90DF8E 5 Bytes JMP 0215E1AE C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001F4C C:\Program Files\Mozilla Firefox\mozglue.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 020FF582 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 020FF55F C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] kernel32.dll!ValidateLocale + B648 7C844EE0 7 Bytes JMP 018D06F3 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 020FF4E0 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\firefox.exe[708] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 0200E5A9 C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1184] USER32.dll!GetWindowInfo 7E42C49C 5 Bytes JMP 1052825D C:\Program Files\Mozilla Firefox\xul.dll
.text C:\Program Files\Mozilla Firefox\plugin-container.exe[1184] USER32.dll!GetMenuContextHelpId + 1A 7E465319 7 Bytes JMP 10521BFA C:\Program Files\Mozilla Firefox\xul.dll
---- Devices - GMER 2.1 ----
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 snapman.sys
---- Registry - GMER 2.1 ----
Reg HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\ContentTypeSniffers\VideoFilesContentSniffer@RelPattern *.asf?*.avi?*.divx?*.mov?*.mpeg?*.mpg?*.ogm?*.qt?*.rm?*.wmv?*.mkv?*.vob?*.m1v?*.m2v?*.swf?*.fli?*.flc?*.flic?*.dat?*.mp4?*.mpe?*.3gp?*.3g2?*.ts?*.tp?*.trp?*.k3g?*.flv?*.m4v?*.mpg?VIDEO\*.mpg?*.
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xE2 0x63 0x26 0xF1 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x46 0x47 0x15 0xB0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0x7A 0x45 0x05 0xFD ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x3E 0x1E 0x9E 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xCD 0x44 0xCD 0xB9 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\System32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
---- EOF - GMER 2.1 ----

No because it was hijacked as has happened to every anti-malware package I've installed. The sign of this is icons on the desktop get greyed out but just those associated with malware scanning/killing tools.
The anonymization of filenames has worked a bit with GMER but I'm now concerned that if I visit the site again I'll get a false file.
The latest scan with a previous GMER file is now suggesting some tcpip parameters are affected including Lease Obtained, T1, T2 and Lease terminates.
Even in safe mode I'm now getting problems like almost 100%CPU usage for refreshing Firefox.

Similar Messages

  • Is it possible for a CD to be infected with a virus and can it infect my computer.

    My cousin burned me a Cd of her music and she told me it took her a minute to burn it because her computer was infected with a virus and she believes that was the reason why. My question is if I import this Cd in my ITunes will it give my Macbook system a virus? Or am I just worrying for nothing?

    can a CD pack a virus, certainly, seen it a million times.  Will it infect you Mac? NO.  I assume she has a PC and not a Mac.   Before you drag over the MP3 music ,
    download the free program CLAMXaV
    https://itunes.apple.com/us/app/clamxav/id430207028?mt=12
    That way you can scan the CD if anything is on the CD besides music, and also help her determine what is/isnt on her computer.
    What is scareware?
    Another type of hoax is referred to as scareware. It's a bogus virus warning that pops up when visiting some websites, and looks something like this. If you take a close look, you'll see the popup refers to a Windows system, which obviously doesn't relate to Mac OS X. It can't harm your Mac at all. Just close the site, clear your browser's cache and cookies, and you'll be fine. Sometimes these scareware sites will generate a never-ending loop of popups, to the point that you must Force Quit your browser. Such scareware sites are usually intended to lure a Windows user into clicking the links to install bogus "antivirus" software, which is typically a trojan. Even if you click the links on a Mac system, it can't install anything, because Windows executable files can't run on Mac OS X.
    There are NO viruses in the wild that affect Mac OS X at this time.
    If this changes, this post will be updated. According to noted computer virus expert Paul Ducklin, in order for a virus to be considered in the wild, "it must be spreading as a result of normal day-to-day operations on and between the computers of unsuspecting users." This definition excludes "proof of concept" code that is used in a testing situation under strictly controlled conditions, and which poses zero threat to average computer users.
    In the past, there have been a few viruses that ran on older versions of the Mac operating system (Mac OS 9 and earlier), but they do not run on any version of Mac OS X. Like every other OS, Mac OS X is not immune to malware threats, this situation could change at any time, but if a new virus is discovered, the news media, forums, blogs, etc. will be instantly buzzing with the news.
    There are trojans that can affect Mac OS X
    These must be downloaded and installed by the user, which usually involves entering the user's administrator password. Also, Mac OS X will give you a warning when you first launch an app you downloaded from the web. Trojans can easily be avoided by the user exercising common sense and caution when installing applications. A common source of trojans is pirated software, typically downloaded from bit torrent sites.

  • I have always heard that Macs are less likely to get infected with a virus.  My computer has been running much slower since I installed Maverick.  Just not sure what the problem might be.  Is there a way for me to run a diagnosis?

    I have always heard that Macs are less likely to get infected with a virus.  My computer has been running much slower since I installed Maverick.  Just not sure what the problem might be.  Is there a way for me to run a diagnosis?

    Some have found relief just by reinstalling, but it is more than likely incompatible third-party applications that slow it down.
    You will have to investigate to see what it is.
    Open Activity Monitor and see if anything is using a lot of CPU% or Memory. If they are, check to see if there is an update for them.
    Another place to look is the Console. See if anything is logging repeating messages with throttling and/or respawn in the All Messages list.
    Sometimes it is not that easy to root out the problems, but if you have anything that purported to clean, protect, optimize, maintain, or flush your system, then that is likely the cause.

  • How do I know if my Mac has been infected with the virus

    I recently was asked to download an Adobe Acrobat reader update but before I was made aware that the current virus was contained in a similar request, I downloaded what I assumed to be a legit update.  I currently do not use my mail program on my Mac so am unaware of any spam being distributed from the computer.  How can I identify if my computer has been infected with this Trojan Horse virus?

    Two Helpful Links Regarding Flashback Trojan
    A link to a great User Tip about the trojan: Flashback Trojan User Tip
    A related link in the tip to a checker: Malware Checker Dowload Link
    A Google search can reveal a variety of alternatives on how the remove the trojan should your computer get infected. This can get you started.
    For now I recommend the User Tip from etressoft to detect and remove:
    Checking for and removing the "Flashback" trojan

  • Can you get a virus on an ipad.I have had this message-Your computer appears to be infected We believe that your computer is infected with malicious software. If you don't take action, you might not be able to connect to the Internet in the future. Learn

    Your computer appears to be infected
    We believe that your computer is infected with malicious software. If you don't take action, you might not be able to connect to the Internet in the future.
    Learn how to remove this software.

    No you do not have a virus. That is a standard web popup usually, that tres to get up to download a "removal program". The removal program is the virus or similar.

  • My Mac Book Pro says it has been infected with viruses. How do I clean them up?

    My Macbook Pro says it has been infected with viruses. How do I clean it up?

    There are different variants of names for this malware but the steps of removal should be the same unless it has advanced.
    http://www.securemac.com/MAC-Defender-Rouge-Anti-Virus-Analysis-Removal.php
    https://discussions.apple.com/thread/3032201?start=0&tstart=0
    https://discussions.apple.com/thread/3042885?start=0&tstart=0
    http://www.reedcorner.net/news.php/news.php?s=macdefender

  • How can you find out if your mac is infected with the flash back virus

    how can you find out if your mac is infected with the flash back virus?

    F-Secure's Flashback removal tool - http://www.f-secure.com/v-descs/trojan-downloader_osx_flashback_k.shtml - supposedly also works on OSX 10.5 and earlier.
    05 Apr 2012 How to Detect and Protect Against Updated Flashback Malware - http://tidbits.com/article/12918 - detection methods for multiple browsers and general information
    Leopard and earlier users see recommendations at: https://discussions.apple.com/thread/3872491

  • My 6630 got infected with commwarrior virus!

    Thus anyone here can help me with my problem, my other phone which is Nokia 6630 got infected with commwarrior virus, now it it automatically restart every 2 minutes and
    has a green color with CommWarrior right next to the signal bar, please help.

    hi duanekier
    i had experienced this commwarrior with my 6680, had a friend with nokia care and flashed the phone for me, told him that was infected by virus. As soon as i put back the memory card the virus came back.. I was informed that this type of virus is very strong and sometimes that even fomatting it wont help i end up buying new memory card.

  • Is this a genuine error message 'ipad has been infected with potential virus'

    II was just about to watch a film through my iPad and a new screen opened 'phone updating.com' and the message read 'Virus warning, ipad has been infected with potential virus.  Click the ok button to scan your iPhone now.'
    I didn't press ok and it wouldn't let me cross out so I checked and updated to the latest version (8.2) and when my ipad restarted, safari opened it on the same error page.  I then went to settings and cleared my Safari history which thankfully clearly the page.
    My concern now is what if I have something bad (virus?) on my iPad? Or im hoping that because I didn't click okay that all is okay again.
    can anyone advise if they have come across anything similar or if I need to do something else?
    MAny Thanks

    Thanks, that's what I thought.  Do you know if there was any other way that I could have cleared the message other than by clearing my safari history, and more importantly, as I didn't click okay, would this have stopped anything else happening to my ipad?

  • Hi my computer is infected with 733,exec.bat malware..even though I had eth elitist virus barrier,HELP what do I do??

    Hi my mac book pro ( 1yr old)  is infected with 733,exec.bat malware..even though I had installed virus barrierX6
    HELP what do I do??

    Hi
    Message  comes up when using the net.... the Virusbarrierx 6 program tells me  with a pop up ..... asking me to repair  quarantine etc.... I hit  repair  and it says  virus eradicated... but then will come again at a new page..... some will say something like histplist....as file and others will be   something to do with cookies etc. Could  I delete all cookies/history and reset  safari? ps  I am on Lion operating system
    thanks CHM

  • Firefox was infected with a virus or spywar and now tries to pop up a certain site every time I load a new page or refresh.

    A few days ago my computer was infected with a virus from my antivirus license running out without me knowing it. Ever since then every time I load a page in firefox or refresh it a pop up window to a site that my ESET antivirus blocks comes up. This will not stop and I can't figure out how to fix it. I've deleted all temporary files on my comp and tried reinstalling firefox from scratch and still won't go away. I'm running out of things to try and not sure what to do. Any help would be greatly apreciated.

    Do a malware check with a few malware scan programs.<br />
    You need to use all programs because each detects different malware.<br />
    Make sure that you update each program to get the latest version of the database before doing a scan.
    * http://www.malwarebytes.org/mbam.php - Malwarebytes' Anti-Malware
    * http://www.superantispyware.com/ - SuperAntispyware
    * http://www.safer-networking.org/en/index.html - Spybot Search & Destroy
    * http://www.lavasoft.com/products/ad_aware_free.php - Ad-Aware Free
    * http://www.microsoft.com/windows/products/winfamily/defender/default.mspx - Windows Defender: Home Page
    See also "Spyware on Windows": http://kb.mozillazine.org/Popups_not_blocked and [[Searches are redirected to another site]]
    If you can't fix it with the above listed scanners then you need to ask advise on one of the forums that specialize in malware removal mentioned in the <i>Popups_not_blocked</i> article.

  • HT201184 My computer is infected with the DNS changer virus. I installed the Macscan DNS Changer Removal Tool but after restarting the virus is still there!

    My computer is infected with the DNS changer Virus. I installed the Macscan DNS Changer Removal tool but after running it and restarting the laptop, the virus is still there .

    "Hinweis: Für die korrekte Durchführung dieses Tests dürfen keine Proxy-Server in den Einstellungen Ihres Webbrowsers aktiviert sein. Diese werden häufig bei Firmenrechnern verwendet. Sie sollten daher im Zweifel Ihren IT-Support kontaktieren, der Ihnen mitteilen kann, ob dieser Test in ihrer Umgebung genutzt werden kann."
    Google Translate:
    Note: For proper implementation of this test may not be a proxy server enabled in your browser settings. These are often used in corporate machines. You should contact your IT support in doubt, you can tell whether this test can be used in their environment.
    and
    fane_j wrote:
    Does the US site use a different script, which works even when proxies are used?
    No idea.

  • Do you have any exp. guys that your ipad3 infected with malware virus?

    Do you have any exp. guys that your ipad3 infected with malware virus?

    There is no malware for the iPad, unless you have jailbroken it. If you have not jailbroken it, whatever problem you are having that prompts you to ask about viruses is not caused by malware, guaranteed.

  • I think I've been infected with a virus and my other anti-virus program isn't catching it; how do I turn on Firefox's virus protection?

    For the past few months, I've had this very weird problem. Any time I'm online, what looks like a big cursor (as if I'm in a writing program or typing in a text field) will appear in random places on any webpage. The cursor flashes, can be different sizes, and comes and goes randomly. Sometimes it's almost three-quarters the height of the webpage; sometimes it's small. I mentioned it to a computer-savvy friend who suggested that the computer might be infected with a virus. I have Avira, but apparently it's not catching this virus, if that's what it is. How do I know whether Firefox's anti-virus program is enabled, and do you think it can solve my "cursor" issue?? Help!

    You may have switched on [http://kb.mozillazine.org/accessibility.browsewithcaret caret browsing]: press F7 to toggle
    See http://kb.mozillazine.org/Scrolling_with_arrow_keys_no_longer_works
    Tools > Options > Advanced : General: Accessibility: [ ] "Always use the cursor keys to navigate within pages"
    See also http://kb.mozillazine.org/Accessibility_features_of_Firefox

  • I have an IMac and opened an email that may have been infected with a virus. How do I check my IMac for a possible virus?

    I have an IMac and opened an email that may have been infected with a virus. How do I check my IMac for a possible virus? What does PPC mean?

    You would be better posting this in the Lion forum.
    https://discussions.apple.com/community/mac_os/mac_os_x_v10.7_lion?view=discussi ons
    It's possible you email contained a virus, but unlikely.  There haven't been any reports of email viruses effecting the mac. 
    My understanding is the Apple provides security updates for all malware including viruses.
    There have been reports of a --
    -- Phoney virus checking program
    -- flash malware.
    ppc -- Power PC.   An older computer processor used by Apple.  Last Mac shipped with PPC was in 2006.
    I've read about two virus checking programs for the mac. One is clamav.  The rest are either junk or malware.
    http://www.clamav.net/lang/en/
    Security update.
    http://support.apple.com/kb/HT1222

Maybe you are looking for

  • Change member names in batch without the need to reload data

    Hi,I have several cubes on which the member names of one of the dimensions need to be changed. There are over 6000 members for that dimension. I used a rules file to change the member names and the previous data has to be reloaded (previous 13 months

  • Message to be make error for specific user id

    Hi Experts, I have converted message 06 28 to error to not allow to create PO in back date. Now i want to allow some User ID's to create PO in back date. Is it possible ?? Regards, Manish Jain

  • Unable to generate thumnail

    Hey. Every time I try to paste an HTML code in to my Adobe Muse site the text: "Unable to generate thumbnail" comes up. It does not matter if I use a twitter, facebook or youtube code/widget. This problem always shows up. Please help. Best Jacob

  • CD/DVD drive of Satellite A30 does not work properly

    I have a satellite A30 - 921, but for some reason the cd/dvd has stopped working. In Drivers folder it says "driver corrupt/missing. (Error code 39). It will not roll-back or update either. Do i need to download the driver ( it is Toshiba dvd-rom SD-

  • Import released transports to the qa system

    Hi Experts, I have released transports of couple of programs from dev system to QA system, I need to imports these transports in the QA system. So Can anyone suggest me how to do it, as i know tcode SCC1 and STMS these are involved in it. Any help wi