History: Vipre AV quarantined Exploit.PDF-JS.Gen a few minutes before the "hard drive failure" scare alerts started popping up, then it quarantined multiple instances of Trojan.Win32.Jorik.Fraud.un - all the same file. MBAM would not run ("Access Denied") so they tried fixing it with system restore. It restored the desktop and some other functionality, but did not fix MBAM or the redirects. I used the Windows Restore removal guide from this site, using RKill (didn't kill any processes) and a renamed copy of MBAM, which caught and removed Trojan.FakeAlert. Ran Unhide. Reran a Vipre scan and MBAM again, all came up clean. At that point there were still copies of the Jorik trojan file in all users\applicationdata, and Vipre would not catch them even if asked to scan them specifically, so I deleted them. They've also tried a couple of other scanners including one booting from a linux CD but all these found were infected restore points, cookies, and low-grade adware.
Status: Google searches still redirect, and iexplore.exe starts and runs on its own and starts racking up temp files. MBAM seems to run fine. The PC's Vipre can no longer be pinged or managed from the server's VIPRE enterprise console, and trying to open the Vipre UI on the infected machine gives a "Webpage unavailable while offline" error box that blocks the UI and cannot be closed.
I've run Defogger and the rest of the tools in the preparation guide, posted below. Any help you can offer is very much appreciated!
.
DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.18702
Run by Kathy Moore at 19:17:38 on 2011-07-06
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.894.556 [GMT -7:00]
.
AV: Sunbelt VIPRE *Enabled/Updated* {964FCE60-0B18-4D30-ADD6-EB178909041C}
.
============== Running Processes ===============
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
svchost.exe
C:\WINDOWS\system32\agrsmsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\Sunbelt Software\SBEAgent\SBAMSvc.exe
C:\Program Files\Sunbelt Software\SBEAgent\SBPIMSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\WINDOWS\system32\TODDSrv.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Atheros\ACU.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Sunbelt Software\SBEAgent\SBAMTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Page = hxxp://www.google.com
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [LtMoh] c:\program files\ltmoh\Ltmoh.exe
uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [TPSMain] TPSMain.exe
mRun: [NDSTray.exe] NDSTray.exe
mRun: [ACU] "c:\program files\atheros\ACU.exe" -nogui
mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe
mRun: [SynTPStart] c:\program files\synaptics\syntp\SynTPStart.exe
mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe
mRun: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
mRun: [MSWheel]
mRun: [SBAMTray] "c:\program files\sunbelt software\sbeagent\SBAMTray.exe"
mRun: [CFSServ.exe] CFSServ.exe -NoClient
mRun: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
.
============= SERVICES / DRIVERS ===============
.
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R1 sbaphd;sbaphd;c:\windows\system32\drivers\sbaphd.sys [2011-1-17 21464]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2010-5-13 98392]
R1 SbTis;SbTis;c:\windows\system32\drivers\sbtis.sys [2011-1-17 212568]
R2 SBAMSvc;VIPRE Enterprise Agent;c:\program files\sunbelt software\sbeagent\SBAMSvc.exe [2010-9-23 2763080]
R2 sbapifs;sbapifs;c:\windows\system32\drivers\sbapifs.sys [2011-1-17 69976]
R2 SBPIMSvc;SB Recovery Service;c:\program files\sunbelt software\sbeagent\SBPIMSvc.exe [2010-9-23 181584]
R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [2007-3-26 105856]
R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [2007-2-19 134016]
R3 FwLnk;FwLnk Driver;c:\windows\system32\drivers\FwLnk.sys [2007-10-5 5888]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-1-17 135664]
.
=============== Created Last 30 ================
.
2011-07-05 18:28:59 -------- d-----w- c:\windows\Standalone System Sweeper
2011-07-01 21:00:40 -------- d-----w- c:\windows\system32\wbem\repository\FS
2011-07-01 21:00:40 -------- d-----w- c:\windows\system32\wbem\Repository
2011-06-30 02:34:44 -------- d-----w- c:\windows\pss
2011-06-30 02:31:28 -------- d-----w- c:\program files\SpecialInstall
2011-06-29 21:30:05 105472 -c----w- c:\windows\system32\dllcache\mup.sys
2011-06-29 21:19:31 388096 ----a-r- c:\documents and settings\kathy moore\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-06-29 21:19:30 -------- d-----w- c:\program files\Trend Micro
2011-06-29 19:02:38 -------- d-----w- c:\documents and settings\kathy moore\application data\SUPERAntiSpyware.com
2011-06-29 19:02:38 -------- d-----w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com
2011-06-29 19:02:22 -------- d-----w- c:\program files\SUPERAntiSpyware
2011-06-08 15:50:59 98304 ----a-w- c:\windows\system32\redmonnt.dll
2011-06-08 15:50:36 -------- d-----w- c:\program files\FoxTabPDFConverter
.
==================== Find3M ====================
.
2011-07-06 20:10:13 7304 ----a-w- c:\windows\TMP0001.TMP
2011-05-29 16:11:30 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 16:11:20 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-02 15:31:52 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-04-29 17:25:27 151552 ----a-w- c:\windows\system32\schannel.dll
2011-04-29 16:19:43 456320 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-04-25 16:11:12 916480 ----a-w- c:\windows\system32\wininet.dll
2011-04-25 16:11:11 43520 ------w- c:\windows\system32\licmgr10.dll
2011-04-25 16:11:11 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-04-25 12:01:22 385024 ------w- c:\windows\system32\html.iec
2011-04-21 13:37:43 105472 ----a-w- c:\windows\system32\drivers\mup.sys
.
============= FINISH: 19:23:36.65 ===============
Attached File(s)
-
ark.txt (6.1K)
Number of downloads: 2 -
attach.txt (19.76K)
Number of downloads: 3

Help
This topic is locked

Back to top
















