Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.
Read this topic before posting a log.
DO NOT post a ComboFix log unless requested to.
Only members of the HijackThis Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
Jun 5 2009, 10:46 AM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 22 Joined: 4-June 09 Member No.: 338,891 |
So I have a browser redirecting, and it blocks me from downloading exe files. Been using another computer and a USB key to run scans and antispyware things. MSN was also signing me out within ten seconds. I reinstalled both FF and MSN but still having the blocked exe's and root repeal, gmer, avast, superantispyware and the symantec that I have (school policy to have that and I had it before I put SAntispyware/avast on it. It's not the best AV at all.) Malwarebytes picked up some things and asked to reboot to delete and is showing nothing right now, but again, other programs are showing strange things still being there. I'd like them off.
here's from the DDS.txt. I've shortened my last name where it appears. Thanks DDS (Ver_09-05-14.01) - NTFSx86 Run by Olivia M at 10:41:25.73 on 05/06/2009 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1147 [GMT -4:00] AV: avast! antivirus 4.8.1335 [VPS 090604-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\EeePC\ACPI\AsTray.exe C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe C:\Program Files\EeePC\ACPI\AsEPCMon.exe C:\Program Files\Elantech\ETDCtrl.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\igfxext.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe F:\Unlocker\UnlockerAssistant.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\ASUS\EeePC\Super Hybrid Engine\SuperHybridEngine.exe svchost.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Live\Contacts\wlcomm.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\system32\SNDVOL32.EXE C:\Documents and Settings\Olivia M\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://eeepc.asus.com/global BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [AsusTray] c:\program files\eeepc\acpi\AsTray.exe mRun: [AsusACPIServer] c:\program files\eeepc\acpi\AsAcpiSvr.exe mRun: [AsusEPCMonitor] c:\program files\eeepc\acpi\AsEPCMon.exe mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName mRun: [ETDWare] c:\program files\elantech\ETDCtrl.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [UnlockerAssistant] "f:\unlocker\UnlockerAssistant.exe" mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send To Bluetooth - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll Notify: igfxcui - igfxdev.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\olivia~1\applic~1\mozilla\firefox\profiles\8jn2jhhl.default\ ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-6-4 114768] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-5-26 9968] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-5-26 72944] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-6-4 20560] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-6-4 138680] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2006-7-19 192160] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2006-7-19 169632] R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2006-9-27 1813232] R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2009-2-19 10752] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-6-4 254040] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-6-4 352920] R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [2008-7-31 93696] R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2008-11-4 38400] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20090604.002\naveng.sys [2009-6-5 89104] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20090604.002\navex15.sys [2009-6-5 876144] R3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [2009-2-19 704384] R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-5-26 7408] R3 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2009-2-19 1684736] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2006-9-27 116464] =============== Created Last 30 ================ 2009-06-05 09:28 <DIR> --d----- C:\Avenger0 2009-06-05 03:00 <DIR> --d----- c:\program files\Microsoft CAPICOM 2.1.0.2 2009-06-04 23:29 268,648 a------- c:\windows\system32\mucltui.dll 2009-06-04 23:29 208,744 a------- c:\windows\system32\muweb.dll 2009-06-04 23:29 27,496 a------- c:\windows\system32\mucltui.dll.mui 2009-06-04 22:16 <DIR> --d----- c:\program files\Microsoft 2009-06-04 22:15 <DIR> --d----- c:\program files\Windows Live SkyDrive 2009-06-04 14:48 318 a------- c:\windows\system32\kungsflog.dat 2009-06-04 13:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com 2009-06-04 13:58 <DIR> --d----- c:\program files\SUPERAntiSpyware 2009-06-04 13:58 <DIR> --d----- c:\docume~1\olivia~1\applic~1\SUPERAntiSpyware.com 2009-06-04 13:57 <DIR> --d----- c:\program files\common files\Wise Installation Wizard 2009-06-04 13:07 0 a------- C:\LOG242.tmp 2009-06-04 13:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller 2009-06-04 09:46 <DIR> --d----- c:\windows\SxsCaPendDel 2009-06-03 17:35 <DIR> --d----- C:\Malwarebytes' Anti-Malware 2009-06-03 17:08 40,160 a------- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-03 17:08 19,096 a------- c:\windows\system32\drivers\mbam.sys 2009-06-03 10:55 36,741 a------- c:\windows\system32\kungsfnrpnptoy.dat 2009-06-02 23:39 11,264 a------- c:\windows\system32\2368696Ptd.iso 2009-06-02 10:47 11,264 a------- c:\windows\system32\2139204HISP.rar 2009-06-01 17:49 17,408 a------- c:\windows\system32\5522976tlp-66.rar 2009-06-01 17:10 <DIR> --d----- c:\program files\EA GAMES 2009-06-01 17:10 442,368 a----r-- c:\windows\system32\vp6vfw.dll 2009-06-01 17:02 <DIR> --d----- c:\docume~1\alluse~1\applic~1\DAEMON Tools Lite 2009-06-01 17:02 <DIR> --d----- c:\program files\DAEMON Tools Toolbar 2009-06-01 17:02 <DIR> --d----- c:\program files\DAEMON Tools Lite 2009-06-01 16:58 <DIR> --d----- c:\docume~1\olivia~1\applic~1\DAEMON Tools Lite 2009-06-01 13:51 253,992 a------- c:\windows\12065.exe 2009-06-01 13:47 303,144 a------- c:\windows\outputc.exe 2009-06-01 11:55 115,016 a------- c:\windows\system32\MSINET.OCX 2009-06-01 11:55 53,248 a------- c:\windows\system32\lsass64.exe 2009-06-01 11:55 24,576 a------- c:\windows\system32\micxp.exe 2009-06-01 11:55 721,904 a------- c:\windows\system32\drivers\sptd.sys 2009-06-01 11:54 7,220,168 a------- c:\windows\DTPro4100218Advanced.exe 2009-05-31 21:20 32 a------- c:\docume~1\alluse~1\applic~1\ezsid.dat 2009-05-31 13:15 <DIR> --d----- c:\program files\MSXML 4.0 2009-05-30 14:23 <DIR> --d----- c:\docume~1\olivia~1\applic~1\Malwarebytes 2009-05-30 14:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-05-30 11:36 2,560 -------- c:\windows\system32\xpsp4res.dll 2009-05-30 04:12 <DIR> --d----- c:\windows\system32\PreInstall 2009-05-29 17:41 <DIR> --d----- c:\program files\Audacity 2009-05-29 10:21 <DIR> --d----- c:\windows\system32\SoftwareDistribution 2009-05-29 05:16 <DIR> --d----- c:\documents and settings\olivia m\Bluetooth Software 2009-05-29 05:16 <DIR> --d----- c:\documents and settings\Olivia M 2009-05-29 04:34 <DIR> --d----- c:\program files\VideoLAN 2009-05-29 00:52 146 a------- c:\docume~1\olivia~1\applic~1\wklnhst.dat 2009-05-28 19:41 <DIR> --d----- c:\documents and settings\olivia m\Tracing 2009-05-28 19:06 <DIR> --d----- c:\docume~1\olivia~1\applic~1\foobar2000 2009-05-28 19:06 <DIR> --d----- c:\program files\foobar2000 2009-05-28 19:05 <DIR> --d----- c:\docume~1\olivia~1\applic~1\uTorrent 2009-05-28 17:16 0 a------- c:\windows\vpc32.INI 2009-05-28 16:52 109,744 a------- c:\windows\system32\drivers\SYMEVENT.SYS 2009-05-28 16:52 48,816 a------- c:\windows\system32\S32EVNT1.DLL 2009-05-28 16:52 <DIR> --d----- c:\program files\Symantec 2009-05-28 16:52 <DIR> --d----- c:\program files\Symantec AntiVirus 2009-05-28 16:52 <DIR> --d----- c:\program files\common files\Symantec Shared 2009-05-28 16:52 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Symantec ==================== Find3M ==================== 2009-06-03 16:44 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat 2008-05-07 04:34 15,523,560 a------- c:\program files\U1 Setup.exe 2009-02-19 16:52 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat ============= FINISH: 10:42:25.29 =============== EDIT: just editing to add the "Attach.txt" file. The actual files on my desktop aren't modified, just what I've written here (the last name shortened). This post has been edited by KRose: Jun 5 2009, 10:55 AM
Attached File(s)
|
|
|
|
KRose Rootkit, lsass worm, alureon win32, avenger, kungsfrqhfunmt.sys Jun 5 2009, 10:46 AM
_temp_ Hello and welcome to Bleeping Computer
We apologi... Jun 15 2009, 04:04 PM
KRose I've done a reformat. Things seemed to be gett... Jun 15 2009, 04:37 PM
m0le Hi KRose,
Welcome to [size=3]Bleeping Computer. M... Jun 16 2009, 01:40 PM
KRose Hi m0le!
Okay...I've run everything and sa... Jun 16 2009, 04:14 PM
m0le Hi KRose,
The best way to do this is to break up ... Jun 16 2009, 04:25 PM
KRose Ok...I've zipped them! Hopefully this work... Jun 16 2009, 04:32 PM
m0le Hi KRose,
The reinstall/reformat has cleaned the ... Jun 16 2009, 06:34 PM
KRose Thank you very much, m0le! Long days and pleas... Jun 16 2009, 06:47 PM
m0le Since this issue appears to be resolved ... this t... Jun 22 2009, 02:06 PM![]() ![]() |
| Lo-Fi Version | Time is now: 21st November 2009 - 09:38 PM |