Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help and Spyware Removal Computer Help Forums Windows Startup Programs Database Virus, Spyware, and Malware Removal Guides Computer Tutorials Uninstall Database File Database Computer Glossary Computer Resources
 

Welcome Guest ( Log In | Click here to Register a free account now! )



Register a free account to unlock additional features at BleepingComputer.com
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

> Forum Guidelines

Read this topic before posting a log.


DO NOT post a ComboFix log unless requested to.


Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.

> Rootkit, lsass worm, alureon win32, avenger, kungsfrqhfunmt.sys, how do i remove?
KRose
post Jun 5 2009, 10:46 AM
Post #1


Member
**

Group: Members
Posts: 22
Joined: 4-June 09
Member No.: 338,891



So I have a browser redirecting, and it blocks me from downloading exe files. Been using another computer and a USB key to run scans and antispyware things. MSN was also signing me out within ten seconds. I reinstalled both FF and MSN but still having the blocked exe's and root repeal, gmer, avast, superantispyware and the symantec that I have (school policy to have that and I had it before I put SAntispyware/avast on it. It's not the best AV at all.) Malwarebytes picked up some things and asked to reboot to delete and is showing nothing right now, but again, other programs are showing strange things still being there. I'd like them off.

here's from the DDS.txt. I've shortened my last name where it appears.
Thanks smile.gif


DDS (Ver_09-05-14.01) - NTFSx86
Run by Olivia M at 10:41:25.73 on 05/06/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1147 [GMT -4:00]

AV: avast! antivirus 4.8.1335 [VPS 090604-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
F:\Unlocker\UnlockerAssistant.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
svchost.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Documents and Settings\Olivia M\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://eeepc.asus.com/global
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe
mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe
mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [ETDWare] c:\program files\elantech\ETDCtrl.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [UnlockerAssistant] "f:\unlocker\UnlockerAssistant.exe"
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: igfxcui - igfxdev.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\olivia~1\applic~1\mozilla\firefox\profiles\8jn2jhhl.default\

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-4 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944]
R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-4 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-4 138680]
R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160]
R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-9-27 1813232]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2009-2-19 10752]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-4 254040]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-4 352920]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [2008-7-31 93696]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-11-4 38400]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090604.002\naveng.sys [2009-6-5 89104]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090604.002\navex15.sys [2009-6-5 876144]
R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2009-2-19 704384]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408]
R3 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-2-19 1684736]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-9-27 116464]

=============== Created Last 30 ================

2009-06-05 09:28 <DIR> --d----- C:\Avenger0
2009-06-05 03:00 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-06-04 23:29 268,648 a------- c:\windows\system32\mucltui.dll
2009-06-04 23:29 208,744 a------- c:\windows\system32\muweb.dll
2009-06-04 23:29 27,496 a------- c:\windows\system32\mucltui.dll.mui
2009-06-04 22:16 <DIR> --d----- c:\program files\Microsoft
2009-06-04 22:15 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-06-04 14:48 318 a------- c:\windows\system32\kungsflog.dat
2009-06-04 13:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-06-04 13:58 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-06-04 13:58 <DIR> --d----- c:\docume~1\olivia~1\applic~1\SUPERAntiSpyware.com
2009-06-04 13:57 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-06-04 13:07 0 a------- C:\LOG242.tmp
2009-06-04 13:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-06-04 09:46 <DIR> --d----- c:\windows\SxsCaPendDel
2009-06-03 17:35 <DIR> --d----- C:\Malwarebytes' Anti-Malware
2009-06-03 17:08 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-03 17:08 19,096 a------- c:\windows\system32\drivers\mbam.sys
2009-06-03 10:55 36,741 a------- c:\windows\system32\kungsfnrpnptoy.dat
2009-06-02 23:39 11,264 a------- c:\windows\system32\2368696Ptd.iso
2009-06-02 10:47 11,264 a------- c:\windows\system32\2139204HISP.rar
2009-06-01 17:49 17,408 a------- c:\windows\system32\5522976tlp-66.rar
2009-06-01 17:10 <DIR> --d----- c:\program files\EA GAMES
2009-06-01 17:10 442,368 a----r-- c:\windows\system32\vp6vfw.dll
2009-06-01 17:02 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite
2009-06-01 17:02 <DIR> --d----- c:\program files\DAEMON Tools Toolbar
2009-06-01 17:02 <DIR> --d----- c:\program files\DAEMON Tools Lite
2009-06-01 16:58 <DIR> --d----- c:\docume~1\olivia~1\applic~1\DAEMON Tools Lite
2009-06-01 13:51 253,992 a------- c:\windows\12065.exe
2009-06-01 13:47 303,144 a------- c:\windows\outputc.exe
2009-06-01 11:55 115,016 a------- c:\windows\system32\MSINET.OCX
2009-06-01 11:55 53,248 a------- c:\windows\system32\lsass64.exe
2009-06-01 11:55 24,576 a------- c:\windows\system32\micxp.exe
2009-06-01 11:55 721,904 a------- c:\windows\system32\drivers\sptd.sys
2009-06-01 11:54 7,220,168 a------- c:\windows\DTPro4100218Advanced.exe
2009-05-31 21:20 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat
2009-05-31 13:15 <DIR> --d----- c:\program files\MSXML 4.0
2009-05-30 14:23 <DIR> --d----- c:\docume~1\olivia~1\applic~1\Malwarebytes
2009-05-30 14:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-05-30 11:36 2,560 -------- c:\windows\system32\xpsp4res.dll
2009-05-30 04:12 <DIR> --d----- c:\windows\system32\PreInstall
2009-05-29 17:41 <DIR> --d----- c:\program files\Audacity
2009-05-29 10:21 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2009-05-29 05:16 <DIR> --d----- c:\documents and settings\olivia m\Bluetooth Software
2009-05-29 05:16 <DIR> --d----- c:\documents and settings\Olivia M
2009-05-29 04:34 <DIR> --d----- c:\program files\VideoLAN
2009-05-29 00:52 146 a------- c:\docume~1\olivia~1\applic~1\wklnhst.dat
2009-05-28 19:41 <DIR> --d----- c:\documents and settings\olivia m\Tracing
2009-05-28 19:06 <DIR> --d----- c:\docume~1\olivia~1\applic~1\foobar2000
2009-05-28 19:06 <DIR> --d----- c:\program files\foobar2000
2009-05-28 19:05 <DIR> --d----- c:\docume~1\olivia~1\applic~1\uTorrent
2009-05-28 17:16 0 a------- c:\windows\vpc32.INI
2009-05-28 16:52 109,744 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-05-28 16:52 48,816 a------- c:\windows\system32\S32EVNT1.DLL
2009-05-28 16:52 <DIR> --d----- c:\program files\Symantec
2009-05-28 16:52 <DIR> --d----- c:\program files\Symantec AntiVirus
2009-05-28 16:52 <DIR> --d----- c:\program files\common files\Symantec Shared
2009-05-28 16:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec

==================== Find3M ====================

2009-06-03 16:44 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-05-07 04:34 15,523,560 a------- c:\program files\U1 Setup.exe
2009-02-19 16:52 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat

============= FINISH: 10:42:25.29 ===============


EDIT: just editing to add the "Attach.txt" file. The actual files on my desktop aren't modified, just what I've written here (the last name shortened).

This post has been edited by KRose: Jun 5 2009, 10:55 AM

Attached File(s)
Attached File  Attach.txt ( 12.93k ) Number of downloads: 1
 
Go to the top of the page
 
+Quote Post

Posts in this topic


Closed TopicStart new topic
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

 



Lo-Fi Version Time is now: 21st November 2009 - 09:38 PM


Advertise   |   About Us   |   Terms of Use   |   Privacy Policy   |   Contact Us   |   Site Map   |   Chat   |   Tutorials   |   Uninstall List
Discussion Forums   |   The Computer Glossary   |   Resources   |   RSS Feeds   |   Startups   |   The File Database   |   Virus Removal Guides

© 2003-2009 All Rights Reserved Bleeping Computer LLC.