Hi I made BAD CHOICE when downloading from a torrent site recently and installed an unknown number of viruses onto my computer they seem to be self replicating and every time i delete them or restart the computer the registry files come back within minutes and everything is being hacked including NORTON ANTIVIRUS. However the only reason i'm not completley taken over is because of norton antivirus. I have it notify me whenever something tries to connect using svchost.exe and also
something called alu_schedulersvc.exe keeps trying to connect. I have been working on this for 2 days now tried every anti virus program and method recomended on this site and still no luck. They seem to be undetectable because they pose as Google,Norton,Symantec,Sony software.
The closest i've come to finding out the problem is the startup list in hijack this utility comes up with MANY MANY MANY duplicate windows controls and norton controls i cant tell which is which.
Also there are several folders that seem to be empty that contain data and it tells me they are write protected. They are the following SONY EPSON MESSANGER XEROX all in the program files and also some folder in the common files folder are write protected or acces is denied its almost as if there is another administrator compromising my privilages.?!?
I have my logs available whenever you like and have made all the preperations listed in your starter guide.
Thanks for any help
here is the dds
DDS (Ver_09-01-19.01) - NTFSx86
Run by Taylore at 11:13:57.42 on Sat 01/31/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_11
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.thepiratebay.org/
uInternet Settings,ProxyOverride = <local>;*.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: CNisExtBho Class: {9ecb9560-04f9-4bbc-943d-298ddf1699e1} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
TB: Norton Internet Security: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} -
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
uRun: [DAEMON Tools Lite] "c:\program files\daemon tools lite\daemon.exe" -autorun
uRun: [RegistryMechanic] c:\program files\registry mechanic\RegMech.exe /H
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\john\applic~1\mozilla\firefox\profiles\13n4grcp.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.daemon-search.com/startpage
FF - component: c:\program files\daemon tools toolbar\firefoxdtt\components\DTToolbarFF.dll
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
=============== Created Last 30 ================
2009-01-31 08:48 <DIR> --d----- C:\VundoFix Backups
2009-01-31 07:46 161,792 a------- c:\windows\SWREG.exe
2009-01-31 07:46 98,816 a------- c:\windows\sed.exe
2009-01-30 10:52 73,728 a------- c:\windows\system32\javacpl.cpl
2009-01-30 10:52 410,984 a------- c:\windows\system32\deploytk.dll
2009-01-30 07:24 <DIR> -cd-h--- c:\docume~1\alluse~1\applic~1\{92E7A367-8E12-4830-AA70-29C32E331A81}
2009-01-29 19:54 <DIR> --d----- c:\program files\CCleaner
2009-01-29 19:08 <DIR> --d----- c:\docume~1\john\applic~1\Malwarebytes
2009-01-29 19:08 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-01-29 19:08 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-29 19:08 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-01-29 19:08 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-01-28 08:33 <DIR> --d----- c:\program files\Trend Micro
2009-01-28 08:16 <DIR> --d----- c:\program files\Wise Registry Cleaner 3
2009-01-28 06:34 <DIR> --d----- c:\program files\morrowind
2009-01-28 04:15 <DIR> --d----- c:\program files\DivX
2009-01-28 03:28 <DIR> --d----- c:\program files\uTorrent
2009-01-28 03:28 <DIR> --d----- c:\docume~1\john\applic~1\uTorrent
2009-01-27 13:11 43,520 a------- c:\windows\system32\CmdLineExt03.dll
2009-01-27 12:37 <DIR> --d----- c:\program files\directx
2009-01-27 06:32 <DIR> --d----- c:\docume~1\john\applic~1\Pharaohs Secret
2009-01-26 18:35 <DIR> --d----- c:\windows\system32\scripting
2009-01-26 18:35 <DIR> --d----- c:\windows\l2schemas
2009-01-26 18:35 <DIR> --d----- c:\windows\system32\en
2009-01-26 18:35 <DIR> --d----- c:\windows\system32\bits
2009-01-26 18:26 <DIR> --d----- c:\windows\ServicePackFiles
2009-01-26 18:19 <DIR> --d----- c:\windows\network diagnostic
2009-01-26 06:06 139,536 a------- c:\windows\system32\javaee.dll
2009-01-26 05:56 619,520 -c------ c:\windows\system32\dllcache\urlmon.dll
2009-01-26 05:56 1,499,136 -c------ c:\windows\system32\dllcache\shdocvw.dll
2009-01-26 05:56 1,846,400 -c------ c:\windows\system32\dllcache\win32k.sys
2009-01-26 05:56 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2009-01-26 05:56 2,189,184 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2009-01-26 05:56 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2009-01-26 05:56 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2009-01-26 05:55 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2009-01-26 05:55 333,952 -c------ c:\windows\system32\dllcache\srv.sys
2009-01-26 05:55 691,712 -c------ c:\windows\system32\dllcache\inetcomm.dll
2009-01-26 05:55 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
2009-01-26 04:35 <DIR> --d----- c:\program files\Bethesda Softworks
2009-01-25 22:07 <DIR> --d----- c:\program files\DAEMON Tools Lite
==================== Find3M ====================
2009-01-30 05:20 57,856 a------- c:\windows\system32\spoolsv.exe
2009-01-28 07:18 171,072 a------- c:\windows\pchealth\helpctr\config\cache\Professional_32_1033.dat
2009-01-26 18:43 86,327 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-01-26 06:06 2,678 a------- c:\windows\java\packages\data\CIB1V5V9.DAT
2009-01-26 06:06 2,678 a------- c:\windows\java\packages\data\LND3L7RD.DAT
2009-01-26 06:06 2,678 a------- c:\windows\java\packages\data\U3BJ9BLV.DAT
2009-01-26 06:06 2,678 a------- c:\windows\java\packages\data\57F537R9.DAT
2009-01-26 06:06 2,678 a------- c:\windows\java\packages\data\S226QLJT.DAT
2008-12-11 03:57 333,952 a------- c:\windows\system32\drivers\srv.sys
2008-12-10 17:33 200,704 a------- c:\windows\system32\dtu100.dll
2008-12-10 17:33 86,016 a------- c:\windows\system32\dpl100.dll
2008-12-08 19:28 593,920 a------- c:\windows\system32\dpuGUI11.dll
2008-12-08 19:28 344,064 a------- c:\windows\system32\dpus11.dll
2008-12-08 19:28 294,912 a------- c:\windows\system32\dpu11.dll
2008-12-08 19:28 57,344 a------- c:\windows\system32\dpv11.dll
2008-11-06 09:37 524,288 a------- c:\windows\system32\DivXsm.exe
2008-11-06 09:37 3,596,288 a------- c:\windows\system32\qt-dx331.dll
2008-11-06 09:37 129,784 -------- c:\windows\system32\pxafs.dll
2008-11-06 09:37 120,056 -------- c:\windows\system32\pxcpyi64.exe
2008-11-06 09:37 118,520 -------- c:\windows\system32\pxinsi64.exe
2008-11-06 09:35 1,044,480 a------- c:\windows\system32\libdivx.dll
2008-11-06 09:35 200,704 a------- c:\windows\system32\ssldivx.dll
2008-11-06 09:33 823,296 a------- c:\windows\system32\divx_xx0c.dll
2008-11-06 09:33 823,296 a------- c:\windows\system32\divx_xx07.dll
2008-11-06 09:33 815,104 a------- c:\windows\system32\divx_xx0a.dll
2008-11-06 09:33 802,816 a------- c:\windows\system32\divx_xx11.dll
2008-11-06 09:33 684,032 a------- c:\windows\system32\DivX.dll
2008-11-06 09:33 12,288 a------- c:\windows\system32\DivXWMPExtType.dll
============= FINISH: 11:14:53.14 ===============