I believe my computer has contracted a trojan that is creating atlsystem{random number}.exe. I believe this creatation is due to either win32.delf.atk or consa32.sys, but I really do not know. I lose connection with my sound card after a random time after startup, and several atlsystem{random number}.exe try to access the internet. Norton could not detect any problems. MalwareBytes said the atlsystem files were trojan.agents, but even after cleanup by MalwareBytes, the altsystem files and sound problem comes back after restart. My DDS Log is below and the attach file is attached. Since I turned off my script blocker to run DDS, I terminated the 4 running atlsystem{random number}.exe programs that were running before running DDS. Thank you very much for your assistance.
DDS (Ver_09-02-01.01) - NTFSx86
Run by Eric at 18:27:01.64 on Mon 02/23/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.167 [GMT -10:00]
AV: Norton Internet Security *On-access scanning disabled* (Outdated)
FW: Norton Internet Security *enabled*
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\NORTON~1\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Symantec Shared\Nmain.exe
C:\Documents and Settings\Eric\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uInternet Settings,ProxyOverride = 127.0.0.1
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
BHO: CNisExtBho Class: {9ecb9560-04f9-4bbc-943d-298ddf1699e1} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: CNavExtBho Class: {bdf3e430-b101-42ad-a544-fadc6b084872} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
TB: Norton Internet Security: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\program files\common files\symantec shared\adblocking\NISShExt.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\program files\norton internet security\norton antivirus\NavShExt.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [LogitechSoftwareUpdate] "c:\program files\logitech\video\ManifestEngine.exe" boot
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_1_0
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [UpdReg] c:\windows\UpdReg.EXE
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe
mRun: [LogitechVideoTray] c:\program files\logitech\video\LogiTray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Symantec NetDriver Monitor] c:\progra~1\symnet~1\SNDMon.exe /Consumer
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
dRun: [Symantec NetDriver Warning] c:\progra~1\symantec\liveup~1\SNDWarn.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Trusted Zone: hotmail.com
Trusted Zone: live.com
Trusted Zone: msn.com
Trusted Zone: passport.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
============= SERVICES / DRIVERS ===============
R1 GhPciScan;GhostPciScanner;c:\program files\norton systemworks\norton ghost\GhPciScan.sys [2002-8-14 5632]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080312.003\NAVENG.Sys [2008-3-13 82256]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080312.003\NavEx15.Sys [2008-3-13 895408]
S3 gpibclsb;GPIB Board Class Driver;c:\windows\system32\drivers\gpibclsb.sys --> c:\windows\system32\drivers\gpibclsb.sys [?]
S3 gpibclsd;GPIB Device Class Driver;c:\windows\system32\drivers\gpibclsd.sys --> c:\windows\system32\drivers\gpibclsd.sys [?]
S3 iMSPQMn;iMSPQMn;\??\c:\docume~1\eric\locals~1\temp\imspqmn.sys --> c:\docume~1\eric\locals~1\temp\iMSPQMn.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2004-5-14 32896]
=============== Created Last 30 ================
2009-02-23 18:18 86,016 a------- c:\windows\system32\u1823330.dll
2009-02-23 18:18 77,824 a------- c:\windows\system32\u182399329.dll
2009-02-23 18:18 90,112 a------- c:\windows\system32\200921825.dll
2009-02-23 18:18 59,904 a------- c:\windows\system32\atlsystem30754.exe
2009-02-23 18:18 59,904 a------- c:\windows\system32\atlsystem683746.exe
2009-02-23 18:18 59,904 a------- c:\windows\system32\atlsystem452110.exe
2009-02-23 18:18 59,904 a------- c:\windows\system32\atlsystem412316.exe
2009-02-22 20:46 90,112 a------- c:\windows\system32\200924642.dll
2009-02-22 20:46 77,824 a------- c:\windows\system32\u202278246.dll
2009-02-22 20:46 86,016 a------- c:\windows\system32\u202273743.dll
2009-02-22 20:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-02-22 20:00 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-02-22 20:00 <DIR> --d----- c:\docume~1\eric\applic~1\SUPERAntiSpyware.com
2009-02-22 19:46 86,016 a------- c:\windows\system32\u19229325.dll
2009-02-22 19:46 90,112 a------- c:\windows\system32\200924559.dll
2009-02-22 19:46 77,824 a------- c:\windows\system32\u19229304.dll
2009-02-22 19:06 90,112 a------- c:\windows\system32\20092645.dll
2009-02-22 19:06 77,824 a------- c:\windows\system32\u192219149.dll
2009-02-22 19:06 86,016 a------- c:\windows\system32\u192278746.dll
2009-02-22 18:40 86,016 a------- c:\windows\system32\u182240829.dll
2009-02-22 18:40 77,824 a------- c:\windows\system32\u182236728.dll
2009-02-22 18:40 90,112 a------- c:\windows\system32\200924023.dll
2009-02-22 18:12 90,112 a------- c:\windows\system32\200921230.dll
2009-02-22 18:12 77,824 a------- c:\windows\system32\u182228733.dll
2009-02-22 18:12 86,016 a------- c:\windows\system32\u182232733.dll
2009-02-22 16:17 77,824 a------- c:\windows\system32\u162252324.dll
2009-02-22 16:17 90,112 a------- c:\windows\system32\20092177.dll
2009-02-22 15:23 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-02-22 15:23 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-02-22 14:58 <DIR> --d----- c:\program files\Trend Micro
2009-02-22 14:53 86,016 a------- c:\windows\system32\u142258711.dll
2009-02-22 14:53 77,824 a------- c:\windows\system32\u142287610.dll
2009-02-22 14:53 90,112 a------- c:\windows\system32\20092535.dll
2009-02-22 09:51 86,016 a------- c:\windows\system32\u92228817.dll
2009-02-22 09:51 77,824 a------- c:\windows\system32\u9229817.dll
2009-02-22 09:51 90,112 a------- c:\windows\system32\200925111.dll
2009-02-22 09:35 <DIR> --d----- c:\docume~1\eric\applic~1\Malwarebytes
2009-02-22 09:35 15,504 a------- c:\windows\system32\drivers\mbam.sys
2009-02-22 09:35 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-22 09:35 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-02-22 09:35 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-02-22 07:32 86,016 a------- c:\windows\system32\u72288326.dll
2009-02-22 07:32 77,824 a------- c:\windows\system32\u72289225.dll
2009-02-22 07:32 90,112 a------- c:\windows\system32\200923221.dll
2009-02-22 07:19 <DIR> --d----- c:\program files\common files\Wise Installation Wizard
2009-02-22 06:49 77,824 a------- c:\windows\system32\u62257853.dll
2009-02-22 06:49 86,016 a------- c:\windows\system32\u62263853.dll
2009-02-22 06:49 90,112 a------- c:\windows\system32\200924949.dll
2009-02-21 12:13 <DIR> --d----- c:\windows\Options
2009-02-21 11:37 86,016 a------- c:\windows\system32\u112147057.dll
2009-02-21 11:36 77,824 a------- c:\windows\system32\u112156856.dll
2009-02-21 11:36 90,112 a------- c:\windows\system32\200923651.dll
2009-02-21 11:32 86,016 a------- c:\windows\system32\u112126528.dll
2009-02-21 11:32 77,824 a------- c:\windows\system32\u112176427.dll
2009-02-21 11:32 90,112 a------- c:\windows\system32\200923223.dll
2009-02-21 11:21 86,016 a------- c:\windows\system32\u112151720.dll
2009-02-21 11:21 77,824 a------- c:\windows\system32\u112148720.dll
2009-02-21 11:21 90,112 a------- c:\windows\system32\200922115.dll
2009-02-21 10:05 77,824 a------- c:\windows\system32\u102195043.dll
2009-02-21 10:05 90,112 a------- c:\windows\system32\20092538.dll
2009-02-21 10:05 86,016 a------- c:\windows\system32\u102122540.dll
2009-02-21 09:25 86,016 a------- c:\windows\system32\u92197747.dll
2009-02-21 09:25 90,112 a------- c:\windows\system32\200922542.dll
2009-02-21 09:25 77,824 a------- c:\windows\system32\u92198646.dll
2009-02-21 08:47 90,112 a------- c:\windows\system32\200924736.dll
2009-02-21 08:47 86,016 a------- c:\windows\system32\u8214641.dll
2009-02-21 08:47 77,824 a------- c:\windows\system32\u82123540.dll
2009-02-21 08:22 86,016 a------- c:\windows\system32\u82149556.dll
2009-02-21 08:22 77,824 a------- c:\windows\system32\u82131355.dll
2009-02-21 08:22 90,112 a------- c:\windows\system32\200922254.dll
2009-02-21 06:46 90,112 a------- c:\windows\system32\20092461.dll
2009-02-21 06:46 86,016 a------- c:\windows\system32\u6219834.dll
2009-02-21 06:46 77,824 a------- c:\windows\system32\u6219634.dll
2009-02-20 22:03 86,016 a------- c:\windows\system32\u222013217.dll
2009-02-20 22:03 77,824 a------- c:\windows\system32\u222012217.dll
2009-02-20 22:03 90,112 a------- c:\windows\system32\20092312.dll
2009-02-20 21:09 86,016 a------- c:\windows\system32\u21202866.dll
2009-02-20 21:09 77,824 a------- c:\windows\system32\u21202434.dll
2009-02-20 21:09 90,112 a------- c:\windows\system32\2009290.dll
2009-02-20 18:05 86,016 a------- c:\windows\system32\u182097938.dll
2009-02-20 18:05 90,112 a------- c:\windows\system32\20092533.dll
2009-02-20 18:05 77,824 a------- c:\windows\system32\u182016838.dll
2009-02-20 16:27 86,016 a------- c:\windows\system32\u16206179.dll
2009-02-20 16:27 77,824 a------- c:\windows\system32\u16205858.dll
2009-02-20 16:27 90,112 a------- c:\windows\system32\20092273.dll
2009-02-20 10:52 86,016 a------- c:\windows\system32\u102051547.dll
2009-02-20 10:52 77,824 a------- c:\windows\system32\u102011346.dll
2009-02-20 10:52 90,112 a------- c:\windows\system32\200925240.dll
2009-02-20 10:39 410,984 a------- c:\windows\system32\deploytk.dll
2009-02-20 10:19 86,016 a------- c:\windows\system32\u102076646.dll
2009-02-20 10:19 90,112 a------- c:\windows\system32\200921940.dll
2009-02-20 10:19 77,824 a------- c:\windows\system32\u102089143.dll
2009-02-20 09:55 86,016 a------- c:\windows\system32\u92047910.dll
2009-02-20 09:55 90,112 a------- c:\windows\system32\20092555.dll
2009-02-20 09:55 77,824 a------- c:\windows\system32\u92079.dll
2009-02-20 06:23 77,824 a------- c:\windows\system32\u62049748.dll
2009-02-20 06:23 90,112 a------- c:\windows\system32\200922344.dll
2009-02-20 06:23 86,016 a------- c:\windows\system32\u62041245.dll
2009-02-19 13:49 77,824 a------- c:\windows\system32\u131927912.dll
2009-02-19 13:49 90,112 a------- c:\windows\system32\200924911.dll
2009-02-19 13:49 65,536 a------- c:\windows\system32\der971915.dll
2009-02-13 14:41 <DIR> --d----- c:\documents and settings\eric\Contacts
2009-02-13 14:37 <DIR> -cdsh--- c:\program files\common files\WindowsLiveInstaller
==================== Find3M ====================
2005-07-02 21:36 32 a--sh--- c:\windows\{13BA7CDB-5F15-477F-9454-0B75019D5BCD}.dat
2005-07-02 21:35 32 a--sh--- c:\windows\{496673E8-A388-4DB9-9386-63EB489B8C58}.dat
2005-07-02 21:35 32 a--sh--- c:\windows\{524675C4-6545-464A-B055-36BC9ECD7022}.dat
2005-07-02 21:37 32 a--sh--- c:\windows\{CC425BA1-2FB8-439A-B9EF-7DE64B749C36}.dat
2005-07-02 21:37 32 a--sh--- c:\windows\{E2B7E953-532F-4F37-8237-7BFFD6584056}.dat
2005-07-02 21:35 32 a--sh--- c:\windows\{E90AFDE7-389B-421D-8585-FD6A5BD1CCEE}.dat
2005-07-02 21:35 32 a--sh--- c:\windows\system32\{62F96A82-BE06-4B49-9B6B-99F1923757FB}.dat
2005-07-02 21:35 32 a--sh--- c:\windows\system32\{6791FBFC-032F-4111-9426-DD6A07278907}.dat
2005-07-02 21:35 32 a--sh--- c:\windows\system32\{86E01E9D-6CEA-4F79-99E4-F6A9204F201C}.dat
2005-07-02 21:37 32 a--sh--- c:\windows\system32\{9E0AE085-D6A9-4D7E-AFF3-40CE3DCC5F69}.dat
2005-07-02 21:37 32 a--sh--- c:\windows\system32\{A0E7E265-05E2-42DF-AFA5-95A3F0F8C795}.dat
2005-07-02 21:36 32 a--sh--- c:\windows\system32\{F6B7F89E-EBF8-4CE7-9902-8C4C161E9026}.dat
============= FINISH: 18:27:54.26 ===============
Attached Files
Edited by mauiej, 23 February 2009 - 11:38 PM.