A couple days ago she dropped off the pc for me to fix saying the redirects were back, along with a new rogue AV called Security Protection. Tried running mbam, tdsskiller,gmer etc in normal mode and Security Protection blocked them and most other programs. was able to run gmer in safe mode, reported as having found TDL4@MBR code in \Device\Harddisk0\DR0. Then ran TDSSKiller, found rootkit.win32.zaccess.e in C:\system32\drivers\netbt.sys and win32.tdss.tdl4 in \device\harddisk0\dro selected cure and restarted. once it had restarted(in normal mode) Security Protection was still there and blocking everything so rebooted into safe mode ran TDSSkiller again and found nothing then ran mbam, found and cured 8 infections, restarted in normal mode and Security Protection is gone but the redirects remained.
Then I ran avast free bootscan reported 3 files, win32\adrotator-B in C:\users\dna\appdata\local\temp\nsm9c17.tmp, win32\hupigon-onx[trj] in C:\system32\data\enUS\interface\cinematics\wow_fotlk_1024.avi,and win32\fakeav-ano[trj] in c:\windows\system32\data\enUS\wow-update-enUS-14333.mpq and removed them. Ran ESET online scanner found and removed 10 files several in temp folders saying they were win32\kryptik.rst trojan, win32\kryptik.cb trojan, win32\adware.yontoo.a application, and win32\adware.antimalwaredoctor.ae.gen application. Reran mbam and reported 2 files in temp as spyware.passwords.xgen and removed them.
Scanned drivers,stealth, and ssdt(forgot to uncheck it) using RKU. In the ssdt section it reported possible rootkit activity all related to aswsp.sys and aswsnx.sys which is avast if i'm not mistaken so i'm fairly sure its a false positive, was nothing mentioned in stealth, and in drivers they all seem to be Microsoft related except augehdm.sys, and msahci.sys which I can't really find any info about so idk if they are legit or not.
Also an item I found in startup in msconfig that I can't find any info on so don't know if it is legit called cfgaclapp.exe also showed up in Hijack this log but the registy key HKLM\software\microsoft \windows\currentversion\run where it is supposed to be doesn't exist, but there are keys at HKLM\software\microsoft\shared tools\msconfig\startupreg\cfgaclapp.exe, HKLM\software\microsoft\tracing\cfgaclapp_rasapi32, and HKLM\software\microsoft\tracing\cfgaclapp_rasmancs. Can't find anything on the hard drive named cfgaclapp even with hidden and system files/folders shown.
At this point eset online scanner,mbam,tdsskiller,avast boot scan all come up clean, I don't see anything that screams infected in the gmer log either. Still getting redirects
like just now i typed bleepingcomputer into google hit search and got redirected to microsoft.com saying "Were you searching for something else and arrived at this page in error? If so, we suspect that your computer might be infected with malware" but type in bleeping and bleepingcomputer is the top result and clicking on the link bring you here fine. Doesn't seem to be happening in IE, just firefox, and randomly at that.
.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Run by DNA at 0:55:52 on 2011-09-05
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3070.2179 [GMT -4:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\rundll32.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Digidesign\Drivers\MMERefresh.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\ctfmon.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.ask.com/?l=dis&o=1587&gct=hp
uInternet Settings,ProxyOverride = *.local
uURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuz0.dll
mURLSearchHooks: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuz0.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngin0.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuz0.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Vuze Remote Toolbar: {ba14329e-9550-4989-b3f2-9732e92d17cc} - c:\program files\vuze_remote\prxtbVuz0.dll
TB: Conduit Engine : {30f9b915-b755-4826-820b-08fba6bd249d} - c:\program files\conduitengine\prxConduitEngin0.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [Aim] "c:\program files\aim\aim.exe" /d locale=en-US
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
mRun: [XboxStat] "c:\program files\microsoft xbox 360 accessories\XboxStat.exe" silentrun
mRun: [DigidesignMMERefresh] c:\program files\digidesign\drivers\MMERefresh.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 10.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\users\dna\appdata\roaming\micros~1\windows\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
dPolicies-explorer: HideSCAHealth = 1 (0x1)
dPolicies-system: DisableTaskMgr = 1 (0x1)
IE: {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\pokerstars.net\PokerStarsUpdate.exe
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{A06EB91F-6976-4B04-A135-62D9A07C1518} : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{CB695F5B-E881-40EF-866F-9EC95DA376AB} : NameServer = 4.2.2.3,4.2.2.4
TCP: Interfaces\{CB695F5B-E881-40EF-866F-9EC95DA376AB} : DhcpNameServer = 192.168.0.1
TCP: Interfaces\{CB695F5B-E881-40EF-866F-9EC95DA376AB}\2375942554137343 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{CB695F5B-E881-40EF-866F-9EC95DA376AB}\3557D6D69647F575966496 : DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
TCP: Interfaces\{CB695F5B-E881-40EF-866F-9EC95DA376AB}\35F657E646771667563547574696F6 : DhcpNameServer = 192.168.0.146 10.1.10.1
TCP: Interfaces\{CB695F5B-E881-40EF-866F-9EC95DA376AB}\35F657E646771667563547574696F6D27657563747 : DhcpNameServer = 192.168.33.1 10.1.10.1
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\dna\appdata\roaming\mozilla\firefox\profiles\ngjltam9.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/|http://www.google.com/search?q=eset&ie=utf-8&oe=utf-8&aq=t&rls=org.mozilla:en-US:official&client=firefox-a|http://www.bleepingcomputer.com/forums/topic416200.html/page__p__2394825__hl__online+scanner__fromsearch__1#entry2394825|http://go.eset.com/us/online-scanner#
FF - prefs.js: network.proxy.type - 0
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnu.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdnupdater2.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
.
============= SERVICES / DRIVERS ===============
.
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-9-4 441176]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-9-4 309848]
R1 SAVRKBootTasks;Boot Tasks Driver;c:\windows\system32\SAVRKBootTasks.sys [2011-9-4 18816]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-9-4 19544]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-9-4 54104]
R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-9-4 42184]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [2010-7-28 16400]
R3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\drivers\yk62x86.sys [2009-9-28 315392]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 28337204;28337204;c:\windows\system32\drivers\15522702.sys [2011-9-3 94768]
S3 42395104;42395104;c:\windows\system32\drivers\65716441.sys [2011-9-3 94768]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 dalwdmservice;dal service;c:\windows\system32\drivers\Dalwdm.sys [2010-7-28 85008]
S3 iLokDrvr;Usb Driver;c:\windows\system32\drivers\iLokDrvr.sys [2009-12-23 54328]
S3 MBX2DFU;MBX2DFU;c:\windows\system32\drivers\mbx2dfu.sys [2010-7-28 21648]
S3 MBX2MIDK;Digidesign Mbox 2 Midi Driver;c:\windows\system32\drivers\mbx2midk.sys [2010-7-28 21904]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-13 1343400]
.
=============== Created Last 30 ================
.
2011-09-04 18:21:21 -------- d-----w- c:\windows\pss
2011-09-04 14:14:26 -------- d-----w- c:\windows\system32\CodeIntegrity
2011-09-04 10:00:40 441176 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-09-04 10:00:39 54104 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-09-04 10:00:19 40112 ----a-w- c:\windows\avastSS.scr
2011-09-04 10:00:14 -------- d-----w- c:\programdata\AVAST Software
2011-09-04 10:00:14 -------- d-----w- c:\program files\AVAST Software
2011-09-04 09:40:37 18816 ------w- c:\windows\system32\SAVRKBootTasks.sys
2011-09-04 08:46:15 -------- d-----w- c:\program files\Sophos
2011-09-04 00:57:58 -------- d-----w- c:\program files\ESET
2011-09-04 00:48:13 388096 ----a-r- c:\users\dna\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-09-04 00:48:13 -------- d-----w- c:\program files\Trend Micro
2011-09-03 23:14:24 94768 ----a-w- c:\windows\system32\drivers\65716441.sys
2011-09-03 23:14:09 94768 ----a-w- c:\windows\system32\drivers\15522702.sys
2011-09-03 19:23:15 4194304 ----a-w- c:\windows\system32\xadqgnnk.dll
2011-08-18 02:51:28 218624 ----a-w- c:\windows\system32\toldsw32.dll
2011-08-12 00:11:44 65536 --sha-r- c:\windows\system32\ReWirel.dll
2011-08-11 23:50:53 -------- d-----w- c:\users\dna\appdata\roaming\Malwarebytes
2011-08-11 23:50:21 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-11 23:50:20 -------- d-----w- c:\programdata\Malwarebytes
2011-08-11 23:50:17 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-11 23:50:17 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-11 01:48:52 -------- d-----w- c:\programdata\Tarma Installer
2011-08-10 03:44:05 6881616 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{903dcef0-384b-44b6-9bd6-0a609c48e618}\mpengine.dll
.
==================== Find3M ====================
.
2011-09-03 23:13:29 187904 ----a-w- c:\windows\system32\drivers\netbt.sys
2011-07-22 04:56:17 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-16 04:37:32 169984 ----a-w- c:\windows\system32\winsrv.dll
2011-07-16 04:34:28 290816 ----a-w- c:\windows\system32\KernelBase.dll
2011-07-16 04:31:12 271360 ----a-w- c:\windows\system32\conhost.exe
2011-07-16 02:21:47 6144 ---ha-w- c:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2011-07-16 02:21:47 4608 ---ha-w- c:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2011-07-16 02:21:47 3584 ---ha-w- c:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2011-07-16 02:21:47 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2011-07-15 08:07:04 0 ----a-w- c:\windows\system32\ConduitEngine.tmp
2011-07-13 14:25:49 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-09 02:26:10 222720 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-23 04:38:05 3957120 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-06-23 04:38:04 3902336 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-06-21 05:39:53 1286016 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-06-21 05:36:36 981504 ----a-w- c:\windows\system32\wininet.dll
2011-06-21 05:35:05 44544 ----a-w- c:\windows\system32\licmgr10.dll
2011-06-21 04:26:02 386048 ----a-w- c:\windows\system32\html.iec
2011-06-15 09:04:46 86016 ----a-w- c:\windows\system32\odbccu32.dll
2011-06-15 09:04:46 81920 ----a-w- c:\windows\system32\odbccr32.dll
2011-06-15 09:04:46 319488 ----a-w- c:\windows\system32\odbcjt32.dll
2011-06-15 09:04:46 163840 ----a-w- c:\windows\system32\odbctrac.dll
2011-06-15 09:04:46 122880 ----a-w- c:\windows\system32\odbccp32.dll
2011-06-11 02:37:19 2332672 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 0:57:48.23 ===============
Attached File(s)
-
ark.txt.log (72.34K)
Number of downloads: 1 -
Attach.txt (16.64K)
Number of downloads: 1
This post has been edited by Johnny613: 05 September 2011 - 05:32 PM

Help
This topic is locked

Back to top











