I was asked to help clear a virus off of a computer for a lady I met through work. I have the machine at my house at the moment, not connected to the internet so I can do proper scanning and such. I have only seen the issue once, but IE opens with a redirect to porn.com, and appears to disable any other internet activity other than another redirect to a bogus virus-removal tool. I have already scanned with malwarebytes and removed some of the infections, but I forgot to save that log to my flash drive.
I do, however, have the hijackthis log that was the latest scan of the machine:
McAfeeŽ Rootkit Detective 1.1 scan report
On 22-06-2010 at 19:20:22
OS-Version 5.1.2600
Service Pack 3.0
====================================
Object-Type: Process
Object-Name: services.exe
Pid: 712
Object-Path: C:\WINDOWS\system32\services.exe
Status: Visible
Object-Type: Process
Object-Name: smss.exe
Pid: 588
Object-Path: C:\WINDOWS\System32\smss.exe
Status: Visible
Object-Type: Process
Object-Name: System Idle Process
Pid: 0
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: avgwdsvc.exe
Pid: 1984
Object-Path: C:\Program Files\AVG\AVG9\avgwdsvc.exe
Status: Visible
Object-Type: Process
Object-Name: tdsskiller.exe
Pid: 3348
Object-Path: G:\tdsskiller.exe
Status: Visible
Object-Type: Process
Object-Name: Agentsvc.exe
Pid: 2016
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
Status: Visible
Object-Type: Process
Object-Name: BackupSvc.exe
Pid: 280
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
Status: Visible
Object-Type: Process
Object-Name: LSSrvc.exe
Pid: 188
Object-Path: C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Status: Visible
Object-Type: Process
Object-Name: agrsmsvc.exe
Pid: 1956
Object-Path: C:\WINDOWS\system32\agrsmsvc.exe
Status: Visible
Object-Type: Process
Object-Name: avgnsx.exe
Pid: 468
Object-Path: C:\Program Files\AVG\AVG9\avgnsx.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 872
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: System
Pid: 4
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: rundll32.exe
Pid: 2176
Object-Path: C:\WINDOWS\system32\RUNDLL32.EXE
Status: Visible
Object-Type: Process
Object-Name: avgtray.exe
Pid: 2208
Object-Path: C:\PROGRA~1\AVG\AVG9\avgtray.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1124
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: nvsvc32.exe
Pid: 1404
Object-Path: C:\WINDOWS\system32\nvsvc32.exe
Status: Visible
Object-Type: Process
Object-Name: cmd.exe
Pid: 196
Object-Path: C:\WINDOWS\system32\cmd.exe
Status: Visible
Object-Type: Process
Object-Name: lsass.exe
Pid: 724
Object-Path: C:\WINDOWS\system32\lsass.exe
Status: Visible
Object-Type: Process
Object-Name: avgcsrvx.exe
Pid: 2584
Object-Path: C:\Program Files\AVG\AVG9\avgcsrvx.exe
Status: Visible
Object-Type: Process
Object-Name: KK.exe
Pid: 1716
Object-Path: G:\New KK\ver7\KK.exe
Status: Visible
Object-Type: Process
Object-Name: Rootkit_Detecti
Pid: 3204
Object-Path: G:\Rootkit_Detective.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1004
Object-Path: C:\WINDOWS\System32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: BkupTray.exe
Pid: 1252
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
Status: Visible
Object-Type: Process
Object-Name: msmsgs.exe
Pid: 2244
Object-Path: C:\Program Files\Messenger\msmsgs.exe
Status: Visible
Object-Type: Process
Object-Name: avgam.exe
Pid: 416
Object-Path: C:\Program Files\AVG\AVG9\avgam.exe
Status: Visible
Object-Type: Process
Object-Name: winlogon.exe
Pid: 664
Object-Path: C:\WINDOWS\system32\winlogon.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1224
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: SchedulerSvc.ex
Pid: 1100
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
Status: Visible
Object-Type: Process
Object-Name: jusched.exe
Pid: 1472
Object-Path: C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
Status: Visible
Object-Type: Process
Object-Name: PDVDServ.exe
Pid: 1908
Object-Path: C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
Status: Visible
Object-Type: Process
Object-Name: avgchsvx.exe
Pid: 1136
Object-Path: C:\Program Files\AVG\AVG9\avgchsvx.exe
Status: Visible
Object-Type: Process
Object-Name: csrss.exe
Pid: 640
Object-Path: C:\WINDOWS\system32\csrss.exe
Status: Visible
Object-Type: Process
Object-Name: explorer.exe
Pid: 1540
Object-Path: C:\WINDOWS\Explorer.EXE
Status: Visible
Object-Type: Process
Object-Name: RichVideo.exe
Pid: 1788
Object-Path: C:\Program Files\CyberLink\Shared Files\RichVideo.exe
Status: Visible
Object-Type: Process
Object-Name: RTHDCPL.exe
Pid: 2160
Object-Path: C:\WINDOWS\RTHDCPL.EXE
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 952
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: spoolsv.exe
Pid: 1448
Object-Path: C:\WINDOWS\system32\spoolsv.exe
Status: Visible
Object-Type: Process
Object-Name: avgemc.exe
Pid: 2100
Object-Path: C:\Program Files\AVG\AVG9\avgemc.exe
Status: Visible
Object-Type: Process
Object-Name: alg.exe
Pid: 3712
Object-Path: C:\WINDOWS\System32\alg.exe
Status: Visible
Object-Type: Process
Object-Name: KK.exe
Pid: 2844
Object-Path: G:\New KK\ver13\KK.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1760
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: subinacl.exe
Pid: 2040
Object-Path: c:\subinacl.exe
Status: Visible
Object-Type: Process
Object-Name: ctfmon.exe
Pid: 2228
Object-Path: C:\WINDOWS\system32\ctfmon.exe
Status: Visible
Object-Type: Process
Object-Name: avgrsx.exe
Pid: 1144
Object-Path: C:\Program Files\AVG\AVG9\avgrsx.exe
Status: Visible
Object-Type: Process
Object-Name: avgcsrvx.exe
Pid: 1300
Object-Path: C:\Program Files\AVG\AVG9\avgcsrvx.exe
Status: Visible
Object-Type: Process
Object-Name: KK.exe
Pid: 3904
Object-Path: G:\New KK\ver11\KK.exe
Status: Visible
Scan complete. No hidden processes/files found.
Total files scanned: 99448
Not too sure where to proceed from here. Any help would be greatly appreciated.
Thanks,
Max
I do, however, have the hijackthis log that was the latest scan of the machine:
McAfeeŽ Rootkit Detective 1.1 scan report
On 22-06-2010 at 19:20:22
OS-Version 5.1.2600
Service Pack 3.0
====================================
Object-Type: Process
Object-Name: services.exe
Pid: 712
Object-Path: C:\WINDOWS\system32\services.exe
Status: Visible
Object-Type: Process
Object-Name: smss.exe
Pid: 588
Object-Path: C:\WINDOWS\System32\smss.exe
Status: Visible
Object-Type: Process
Object-Name: System Idle Process
Pid: 0
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: avgwdsvc.exe
Pid: 1984
Object-Path: C:\Program Files\AVG\AVG9\avgwdsvc.exe
Status: Visible
Object-Type: Process
Object-Name: tdsskiller.exe
Pid: 3348
Object-Path: G:\tdsskiller.exe
Status: Visible
Object-Type: Process
Object-Name: Agentsvc.exe
Pid: 2016
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
Status: Visible
Object-Type: Process
Object-Name: BackupSvc.exe
Pid: 280
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
Status: Visible
Object-Type: Process
Object-Name: LSSrvc.exe
Pid: 188
Object-Path: C:\Program Files\Common Files\LightScribe\LSSrvc.exe
Status: Visible
Object-Type: Process
Object-Name: agrsmsvc.exe
Pid: 1956
Object-Path: C:\WINDOWS\system32\agrsmsvc.exe
Status: Visible
Object-Type: Process
Object-Name: avgnsx.exe
Pid: 468
Object-Path: C:\Program Files\AVG\AVG9\avgnsx.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 872
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: System
Pid: 4
Object-Path:
Status: Visible
Object-Type: Process
Object-Name: rundll32.exe
Pid: 2176
Object-Path: C:\WINDOWS\system32\RUNDLL32.EXE
Status: Visible
Object-Type: Process
Object-Name: avgtray.exe
Pid: 2208
Object-Path: C:\PROGRA~1\AVG\AVG9\avgtray.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1124
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: nvsvc32.exe
Pid: 1404
Object-Path: C:\WINDOWS\system32\nvsvc32.exe
Status: Visible
Object-Type: Process
Object-Name: cmd.exe
Pid: 196
Object-Path: C:\WINDOWS\system32\cmd.exe
Status: Visible
Object-Type: Process
Object-Name: lsass.exe
Pid: 724
Object-Path: C:\WINDOWS\system32\lsass.exe
Status: Visible
Object-Type: Process
Object-Name: avgcsrvx.exe
Pid: 2584
Object-Path: C:\Program Files\AVG\AVG9\avgcsrvx.exe
Status: Visible
Object-Type: Process
Object-Name: KK.exe
Pid: 1716
Object-Path: G:\New KK\ver7\KK.exe
Status: Visible
Object-Type: Process
Object-Name: Rootkit_Detecti
Pid: 3204
Object-Path: G:\Rootkit_Detective.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1004
Object-Path: C:\WINDOWS\System32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: BkupTray.exe
Pid: 1252
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
Status: Visible
Object-Type: Process
Object-Name: msmsgs.exe
Pid: 2244
Object-Path: C:\Program Files\Messenger\msmsgs.exe
Status: Visible
Object-Type: Process
Object-Name: avgam.exe
Pid: 416
Object-Path: C:\Program Files\AVG\AVG9\avgam.exe
Status: Visible
Object-Type: Process
Object-Name: winlogon.exe
Pid: 664
Object-Path: C:\WINDOWS\system32\winlogon.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1224
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: SchedulerSvc.ex
Pid: 1100
Object-Path: C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
Status: Visible
Object-Type: Process
Object-Name: jusched.exe
Pid: 1472
Object-Path: C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
Status: Visible
Object-Type: Process
Object-Name: PDVDServ.exe
Pid: 1908
Object-Path: C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
Status: Visible
Object-Type: Process
Object-Name: avgchsvx.exe
Pid: 1136
Object-Path: C:\Program Files\AVG\AVG9\avgchsvx.exe
Status: Visible
Object-Type: Process
Object-Name: csrss.exe
Pid: 640
Object-Path: C:\WINDOWS\system32\csrss.exe
Status: Visible
Object-Type: Process
Object-Name: explorer.exe
Pid: 1540
Object-Path: C:\WINDOWS\Explorer.EXE
Status: Visible
Object-Type: Process
Object-Name: RichVideo.exe
Pid: 1788
Object-Path: C:\Program Files\CyberLink\Shared Files\RichVideo.exe
Status: Visible
Object-Type: Process
Object-Name: RTHDCPL.exe
Pid: 2160
Object-Path: C:\WINDOWS\RTHDCPL.EXE
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 952
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: spoolsv.exe
Pid: 1448
Object-Path: C:\WINDOWS\system32\spoolsv.exe
Status: Visible
Object-Type: Process
Object-Name: avgemc.exe
Pid: 2100
Object-Path: C:\Program Files\AVG\AVG9\avgemc.exe
Status: Visible
Object-Type: Process
Object-Name: alg.exe
Pid: 3712
Object-Path: C:\WINDOWS\System32\alg.exe
Status: Visible
Object-Type: Process
Object-Name: KK.exe
Pid: 2844
Object-Path: G:\New KK\ver13\KK.exe
Status: Visible
Object-Type: Process
Object-Name: svchost.exe
Pid: 1760
Object-Path: C:\WINDOWS\system32\svchost.exe
Status: Visible
Object-Type: Process
Object-Name: subinacl.exe
Pid: 2040
Object-Path: c:\subinacl.exe
Status: Visible
Object-Type: Process
Object-Name: ctfmon.exe
Pid: 2228
Object-Path: C:\WINDOWS\system32\ctfmon.exe
Status: Visible
Object-Type: Process
Object-Name: avgrsx.exe
Pid: 1144
Object-Path: C:\Program Files\AVG\AVG9\avgrsx.exe
Status: Visible
Object-Type: Process
Object-Name: avgcsrvx.exe
Pid: 1300
Object-Path: C:\Program Files\AVG\AVG9\avgcsrvx.exe
Status: Visible
Object-Type: Process
Object-Name: KK.exe
Pid: 3904
Object-Path: G:\New KK\ver11\KK.exe
Status: Visible
Scan complete. No hidden processes/files found.
Total files scanned: 99448
Not too sure where to proceed from here. Any help would be greatly appreciated.
Thanks,
Max
This post has been edited by Budapest: 22 June 2010 - 07:16 PM
Reason for edit: Moved from XP ~BP

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top









