Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I Got the Alureon Trojan


  • This topic is locked This topic is locked
60 replies to this topic

#1 Rusty F

Rusty F

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 06 December 2009 - 07:12 PM

New here, hope ya can help me get rid of it. Like other posters I get rid of it and it comes back to haunt me. As a matter of fact it just came back. So, here are my logs for ya peruse and get rid of this dang thing. Thank ya so much for your help in advance.

DDS (Ver_09-12-01.01) - NTFSx86
Run by Rusty at 17:44:13.29 on Sun 12/06/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_10
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.466 [GMT -6:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
e:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICLA.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIEGA.EXE
C:\Documents and Settings\Rusty\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig?hl=en#home
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
uDefault_Page_URL = hxxp://www.msn.com
uSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q=
mSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q=
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
uRun: [SpybotSD TeaTimer] e:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus CX6400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2L1.EXE /P28 "EPSON Stylus CX6400 (Copy 1)" /M "Stylus CX6400" /EF "HKCU"
uRun: [Google Update] "c:\documents and settings\rusty\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [EPSON Stylus Photo RX595 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticla.exe /fu "c:\docume~1\rusty\locals~1\temp\E_S1C.tmp" /EF "HKCU"
uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\docume~1\rusty\locals~1\temp\E_S21.tmp" /EF "HKCU"
mRun: [ABIT uGuru] c:\program files\abit\abit uguru\uGuru.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime
mRun: [EPSON Stylus CX6400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2L1.EXE /P28 "EPSON Stylus CX6400 (Copy 1)" /O6 "USB003" /M "Stylus CX6400"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Malwarebytes Anti-Malware (reboot)] "e:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [winupdate86.exe] c:\windows\system32\winupdate86.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
dRun: [AntiVirus Plus] "c:\windows\system32\rundll32.exe" "c:\documents and settings\rusty\application data\antivirus plus\AntiVirus Plus.70367201.dll", start 70367201
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Add to AMV Convert Tool... - c:\program files\mp3 player utilities 4.00\amvconverter\grab.html
IE: Add to Media Manager... - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2E5E800E-6AC0-411E-940A-369530A35E43} - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: download.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15015/CTSUEng.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?LinkID=39204
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15023/CTPID.cab
Notify: !SASWinLogon - e:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: pulowule.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - e:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli zewobihu.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rusty\applic~1\mozilla\firefox\profiles\gp06i8r4.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\rusty\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\rusty\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: e:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: e:\program files\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: e:\program files\divx\divx web player\npdivx32.dll
FF - plugin: e:\program files\netscape6\nppl3260.dll
FF - plugin: e:\program files\netscape6\nprjplug.dll
FF - plugin: e:\program files\netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2} - c:\documents and settings\rusty\local settings\application data\{B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2}
FF - HiddenExtension: XULRunner: {DDE14058-4105-401E-9823-2851736FF5D5} - c:\documents and settings\rusty\local settings\application data\{dde14058-4105-401e-9823-2851736ff5d5}\

============= SERVICES / DRIVERS ===============

R0 AC2003;AC2003;c:\windows\system32\drivers\AC2003.sys [2005-8-29 4224]
R0 uGuru;uGuru;c:\windows\system32\drivers\uGuru.SYS [2005-8-29 10752]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R1 SASDIFSV;SASDIFSV;e:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;e:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [2005-8-29 44928]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [2005-8-29 55936]
R3 PTDLBus;PANTECH UM175AL Composite Device Driver;c:\windows\system32\drivers\PTDLBus.sys [2009-2-21 32256]
R3 PTDLMdm;PANTECH UM175AL Drivers;c:\windows\system32\drivers\PTDLMdm.sys [2009-2-21 41344]
R3 PTDLVsp;PANTECH UM175AL Diagnostic Port;c:\windows\system32\drivers\PTDLVsp.sys [2009-2-21 39936]
S1 flmvzlti;flmvzlti;\??\c:\windows\system32\drivers\flmvzlti.sys --> c:\windows\system32\drivers\flmvzlti.sys [?]
S1 kvpxodfy;kvpxodfy;\??\c:\windows\system32\drivers\kvpxodfy.sys --> c:\windows\system32\drivers\kvpxodfy.sys [?]
S1 ngkrqdgz;ngkrqdgz;\??\c:\windows\system32\drivers\ngkrqdgz.sys --> c:\windows\system32\drivers\ngkrqdgz.sys [?]
S2 dmycvbjrfcbsfww;dmycvbjrfcbsfww;\??\c:\windows\system32\drivers\ghvwhkcofp.sys --> c:\windows\system32\drivers\ghvwhkcofp.sys [?]
S2 jwtldzmafkfnn;jwtldzmafkfnn;\??\c:\windows\system32\drivers\thyqeafogo.sys --> c:\windows\system32\drivers\thyqeafogo.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-11-9 23680]
S3 PTDLWWAN;PANTECH UM175AL WWAN Driver;c:\windows\system32\drivers\PTDLWWAN.sys [2009-2-21 59776]
S3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\ptdmmdm.sys --> c:\windows\system32\drivers\PTDMMdm.sys [?]
S3 SASENUM;SASENUM;e:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [2009-2-9 14848]
UnknownUnknown zfupvhvn;zfupvhvn; [x]

============== File Associations ===============

regfile=regedit.exe "%1" %*
scrfile="%1" %*

=============== Created Last 30 ================

2010-09-10 19:53:44 0 d-----w- c:\program files\Elaborate Bytes
2009-12-03 22:10:29 237600 ----a-w- c:\windows\system32\drivers\str.sys
2009-12-03 22:03:53 0 d-----w- c:\program files\Microsoft Security Essentials
2009-12-01 06:19:30 0 d-----w- c:\docume~1\rusty\applic~1\IrfanView
2009-11-30 08:21:37 0 ----a-w- c:\windows\system32\6334.exe
2009-11-30 08:01:37 0 ----a-w- c:\windows\system32\18467.exe
2009-11-30 07:29:07 0 ----a-w- c:\windows\system32\AVR10.exe
2009-11-30 07:20:27 0 ----a-w- c:\windows\system32\41.exe
2009-11-30 07:18:31 0 ----a-w- c:\windows\system32\winhelper86.dll
2009-11-30 07:18:15 0 d-----w- c:\documents and settings\all users\Microsoft PData
2009-11-26 17:17:43 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-11-26 16:40:40 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-11-26 16:40:38 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-11-23 23:50:02 95 ----a-w- c:\windows\wininit.ini
2009-11-23 17:19:10 0 d-----w- c:\docume~1\rusty\applic~1\AntiVirus Plus
2009-11-22 10:15:22 0 d-----w- c:\program files\WinPcap
2009-11-11 11:22:02 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys

==================== Find3M ====================

2009-11-03 02:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-09-28 18:20:43 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll
2008-01-14 01:51:24 1600 ----a-w- c:\program files\ALLTEL Internet Accelerator Client setup.log
2007-08-30 03:30:16 920 ----a-w- c:\program files\INSTALL.LOG
2009-04-23 21:59:51 65536 --sha-w- c:\windows\temp\history\history.ie5\mshist012009042320090424\index.dat

============= FINISH: 17:47:19.00 ===============
Now I've tried the Root Repeal twice and my computer froze up both times. I had to reset to get my computer going again. I hope this won't be too much of a problem. Thanks again.

Attached Files



BC AdBot (Login to Remove)

 


#2 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 14 December 2009 - 03:34 PM

Hello again, I know the topic is not suppose to be bumped up. I am in desperate need of help. I cannot log on net without having to re-boot because of Alureon trojan. I'm doing this several times a day. I'm afraid to do any kind of personal business on line because of this. Today I got hit with something that caused my desktop to disappear, I could not run Malware anti-bytes, and could not boot into safe mode. It was one of those fake virus alerts I believe. I think I may have gotten rid of it. It also turned my automatic updates off. So, I've updated my DDS log and I still cannot run rootrepeal without locking up my computer. I tried to also run it in safe mode and no luck. Thanks again.


DDS (Ver_09-12-01.01) - NTFSx86
Run by Rusty at 14:20:17.81 on Mon 12/14/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_10
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.340 [GMT -6:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
e:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Documents and Settings\Rusty\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig?hl=en#home
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
uDefault_Page_URL = hxxp://www.msn.com
uSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q=
mSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q=
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
uRun: [SpybotSD TeaTimer] e:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus CX6400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2L1.EXE /P28 "EPSON Stylus CX6400 (Copy 1)" /M "Stylus CX6400" /EF "HKCU"
uRun: [Google Update] "c:\documents and settings\rusty\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [EPSON Stylus Photo RX595 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticla.exe /fu "c:\docume~1\rusty\locals~1\temp\E_S1C.tmp" /EF "HKCU"
uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\docume~1\rusty\locals~1\temp\E_S21.tmp" /EF "HKCU"
uRun: [notepad] rundll32.exe c:\docume~1\networ~1\ntload.dll,_IWMPEvents@0
mRun: [ABIT uGuru] c:\program files\abit\abit uguru\uGuru.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime
mRun: [EPSON Stylus CX6400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2L1.EXE /P28 "EPSON Stylus CX6400 (Copy 1)" /O6 "USB003" /M "Stylus CX6400"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Malwarebytes Anti-Malware (reboot)] "e:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [winupdate86.exe] c:\windows\system32\winupdate86.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
dRun: [AntiVirus Plus] "c:\windows\system32\rundll32.exe" "c:\documents and settings\rusty\application data\antivirus plus\AntiVirus Plus.70367201.dll", start 70367201
dRun: [notepad] rundll32.exe c:\docume~1\locals~1\ntload.dll,_IWMPEvents@0
StartupFolder: c:\docume~1\rusty\startm~1\programs\startup\scandisk.lnk - c:\windows\system32\rundll32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: EnableLUA = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: Add to AMV Convert Tool... - c:\program files\mp3 player utilities 4.00\amvconverter\grab.html
IE: Add to Media Manager... - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2E5E800E-6AC0-411E-940A-369530A35E43} - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: download.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15015/CTSUEng.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?LinkID=39204
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15023/CTPID.cab
Notify: !SASWinLogon - e:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: pulowule.dll ,yazeriza.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - e:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli zewobihu.dll gunowini.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rusty\applic~1\mozilla\firefox\profiles\gp06i8r4.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\rusty\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\rusty\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: e:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: e:\program files\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: e:\program files\divx\divx web player\npdivx32.dll
FF - plugin: e:\program files\netscape6\nppl3260.dll
FF - plugin: e:\program files\netscape6\nprjplug.dll
FF - plugin: e:\program files\netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2} - c:\documents and settings\rusty\local settings\application data\{B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2}
FF - HiddenExtension: XULRunner: {DDE14058-4105-401E-9823-2851736FF5D5} - c:\documents and settings\rusty\local settings\application data\{dde14058-4105-401e-9823-2851736ff5d5}\

============= SERVICES / DRIVERS ===============

R0 AC2003;AC2003;c:\windows\system32\drivers\AC2003.sys [2005-8-29 4224]
R0 uGuru;uGuru;c:\windows\system32\drivers\uGuru.SYS [2005-8-29 10752]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R1 SASDIFSV;SASDIFSV;e:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;e:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [2005-8-29 44928]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [2005-8-29 55936]
R3 PTDLBus;PANTECH UM175AL Composite Device Driver;c:\windows\system32\drivers\PTDLBus.sys [2009-2-21 32256]
R3 PTDLMdm;PANTECH UM175AL Drivers;c:\windows\system32\drivers\PTDLMdm.sys [2009-2-21 41344]
R3 PTDLVsp;PANTECH UM175AL Diagnostic Port;c:\windows\system32\drivers\PTDLVsp.sys [2009-2-21 39936]
S1 ewbccxfl;ewbccxfl;\??\c:\windows\system32\drivers\ewbccxfl.sys --> c:\windows\system32\drivers\ewbccxfl.sys [?]
S1 flmvzlti;flmvzlti;\??\c:\windows\system32\drivers\flmvzlti.sys --> c:\windows\system32\drivers\flmvzlti.sys [?]
S1 kvpxodfy;kvpxodfy;\??\c:\windows\system32\drivers\kvpxodfy.sys --> c:\windows\system32\drivers\kvpxodfy.sys [?]
S1 ngkrqdgz;ngkrqdgz;\??\c:\windows\system32\drivers\ngkrqdgz.sys --> c:\windows\system32\drivers\ngkrqdgz.sys [?]
S2 dmycvbjrfcbsfww;dmycvbjrfcbsfww;\??\c:\windows\system32\drivers\ghvwhkcofp.sys --> c:\windows\system32\drivers\ghvwhkcofp.sys [?]
S2 jwtldzmafkfnn;jwtldzmafkfnn;\??\c:\windows\system32\drivers\thyqeafogo.sys --> c:\windows\system32\drivers\thyqeafogo.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-11-9 23680]
S3 PTDLWWAN;PANTECH UM175AL WWAN Driver;c:\windows\system32\drivers\PTDLWWAN.sys [2009-2-21 59776]
S3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\ptdmmdm.sys --> c:\windows\system32\drivers\PTDMMdm.sys [?]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 SASENUM;SASENUM;e:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [2009-2-9 14848]

============== File Associations ===============

regfile=regedit.exe "%1" %*
scrfile="%1" %*

=============== Created Last 30 ================

2010-09-10 19:53:44 0 d-----w- c:\program files\Elaborate Bytes
2009-12-14 20:01:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-14 20:01:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-14 16:25:28 19968 ----a-w- c:\windows\system32\winlogon86.exe
2009-12-14 16:25:16 8704 ----a-w- C:\acad.exe
2009-12-14 16:25:16 19968 ----a-w- C:\dens.exe
2009-12-09 18:59:49 0 d-----w- c:\windows\Performance
2009-12-09 18:59:19 0 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-12-03 22:03:53 0 d-----w- c:\program files\Microsoft Security Essentials
2009-12-01 06:19:30 0 d-----w- c:\docume~1\rusty\applic~1\IrfanView
2009-11-30 08:21:37 0 ----a-w- c:\windows\system32\6334.exe
2009-11-30 08:01:37 0 ----a-w- c:\windows\system32\18467.exe
2009-11-30 07:29:07 0 ----a-w- c:\windows\system32\AVR10.exe
2009-11-30 07:20:27 0 ----a-w- c:\windows\system32\41.exe
2009-11-30 07:18:31 0 ----a-w- c:\windows\system32\winhelper86.dll
2009-11-30 07:18:15 0 d-----w- c:\documents and settings\all users\Microsoft PData
2009-11-26 17:17:43 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-11-23 23:50:02 95 ----a-w- c:\windows\wininit.ini
2009-11-23 17:19:10 0 d-----w- c:\docume~1\rusty\applic~1\AntiVirus Plus
2009-11-22 10:15:22 0 d-----w- c:\program files\WinPcap

==================== Find3M ====================

2009-11-11 11:22:02 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-11-03 02:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20:16 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-28 18:20:43 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2008-01-14 01:51:24 1600 ----a-w- c:\program files\ALLTEL Internet Accelerator Client setup.log
2007-08-30 03:30:16 920 ----a-w- c:\program files\INSTALL.LOG
2009-04-23 21:59:51 65536 --sha-w- c:\windows\temp\history\history.ie5\mshist012009042320090424\index.dat

============= FINISH: 14:22:19.29 ===============

Attached Files



#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:17 AM

Posted 19 December 2009 - 08:52 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems just let me know in your next reply or simply post a Hijackthis log.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#4 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 19 December 2009 - 09:44 PM

Hello EB,
Thanks for answering my call I was on the verge of re-formatting. My problem is the Trojan Win32\Alureon.CT. My scanner picks it up cleans it and it keeps coming back. If seems that each time I log on to the net is when it hits. If stay connected too long I lose my connection and have to re-boot to get it back. I had some search re-directs and some false virus warnings. I get a couple of error messages on a re-start about RunDLL bad image, but I click OK and it continues on. As I stated before I never could get root repeal to work my computer locks up. I tried it in safe mode also and it still locks up. Here are my DDS logs.

DDS (Ver_09-12-01.01) - NTFSx86
Run by Rusty at 20:32:01.35 on Sat 12/19/2009
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_10
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1023.351 [GMT -6:00]

AV: Microsoft Security Essentials *On-access scanning enabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Microsoft Security Essentials\MsMpEng.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
e:\Program Files\Executive Software\DiskeeperLite\DKService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ABIT\ABIT uGuru\uGuru.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft Security Essentials\msseces.exe
C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Rusty\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/ig?hl=en#home
uSearch Page = hxxp://www.google.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}
uDefault_Page_URL = hxxp://www.msn.com
uSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q=
mSearch Bar = hxxp://www.starbarsearch.com/?useie5=1&q=
mSearchAssistant = hxxp://www.google.com/ie
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - e:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: EpsonToolBandKicker Class: {e99421fb-68dd-40f0-b4ac-b7027cae2f1a} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: EPSON Web-To-Page: {ee5d279f-081b-4404-994d-c6b60aaeba6d} - c:\program files\epson\epson web-to-page\EPSON Web-To-Page.dll
TB: The Weather Channel Toolbar: {2e5e800e-6ac0-411e-940a-369530a35e43} - c:\windows\system32\TwcToolbarIe7.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [AnyDVD] c:\program files\slysoft\anydvd\AnyDVDtray.exe
uRun: [SpybotSD TeaTimer] e:\program files\spybot - search & destroy\TeaTimer.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [EPSON Stylus CX6400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2L1.EXE /P28 "EPSON Stylus CX6400 (Copy 1)" /M "Stylus CX6400" /EF "HKCU"
uRun: [Google Update] "c:\documents and settings\rusty\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [EPSON Stylus Photo RX595 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticla.exe /fu "c:\docume~1\rusty\locals~1\temp\E_S1C.tmp" /EF "HKCU"
uRun: [EPSON Stylus NX400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatiega.exe /fu "c:\docume~1\rusty\locals~1\temp\E_S21.tmp" /EF "HKCU"
uRun: [notepad] rundll32.exe c:\docume~1\networ~1\ntload.dll,_IWMPEvents@0
mRun: [ABIT uGuru] c:\program files\abit\abit uguru\uGuru.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime
mRun: [EPSON Stylus CX6400 (Copy 1)] c:\windows\system32\spool\drivers\w32x86\3\E_S4I2L1.EXE /P28 "EPSON Stylus CX6400 (Copy 1)" /O6 "USB003" /M "Stylus CX6400"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [Malwarebytes Anti-Malware (reboot)] "e:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [winupdate86.exe] c:\windows\system32\winupdate86.exe
mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
dRun: [swg] c:\program files\google\googletoolbarnotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
dRun: [AntiVirus Plus] "c:\windows\system32\rundll32.exe" "c:\documents and settings\rusty\application data\antivirus plus\AntiVirus Plus.70367201.dll", start 70367201
dRun: [notepad] rundll32.exe c:\docume~1\locals~1\ntload.dll,_IWMPEvents@0
StartupFolder: c:\docume~1\rusty\startm~1\programs\startup\scandisk.lnk - c:\windows\system32\rundll32.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
mPolicies-system: EnableLUA = 0 (0x0)
dPolicies-explorer: NoSetActiveDesktop = 1 (0x1)
IE: Add to AMV Convert Tool... - c:\program files\mp3 player utilities 4.00\amvconverter\grab.html
IE: Add to Media Manager... - c:\program files\mp3 player utilities 4.00\mediamanager\grab.html
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2E5E800E-6AC0-411E-940A-369530A35E43} - {A6790AA5-C6C7-4BCF-A46D-0FDAC4EA90EB}
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - e:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: download.com
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15015/CTSUEng.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?LinkID=39204
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://by109fd.bay109.hotmail.msn.com/resources/MsnPUpld.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - hxxp://www.superadblocker.com/activex/sabspx.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15023/CTPID.cab
Notify: !SASWinLogon - e:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
AppInit_DLLs: pulowule.dll ,yazeriza.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - e:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli zewobihu.dll gunowini.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\rusty\applic~1\mozilla\firefox\profiles\gp06i8r4.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\rusty\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\rusty\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: e:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: e:\program files\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: e:\program files\divx\divx web player\npdivx32.dll
FF - plugin: e:\program files\netscape6\nppl3260.dll
FF - plugin: e:\program files\netscape6\nprjplug.dll
FF - plugin: e:\program files\netscape6\nprpjplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2} - c:\documents and settings\rusty\local settings\application data\{B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2}
FF - HiddenExtension: XULRunner: {DDE14058-4105-401E-9823-2851736FF5D5} - c:\documents and settings\rusty\local settings\application data\{dde14058-4105-401e-9823-2851736ff5d5}\

============= SERVICES / DRIVERS ===============

R0 AC2003;AC2003;c:\windows\system32\drivers\AC2003.sys [2005-8-29 4224]
R0 uGuru;uGuru;c:\windows\system32\drivers\uGuru.SYS [2005-8-29 10752]
R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-6-18 142832]
R1 SASDIFSV;SASDIFSV;e:\program files\superantispyware\sasdifsv.sys [2009-11-23 9968]
R1 SASKUTIL;SASKUTIL;e:\program files\superantispyware\SASKUTIL.SYS [2009-11-23 74480]
R2 npf;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-15 34064]
R2 ousbehci;OrangeWare USB Enhanced Host Controller Service;c:\windows\system32\drivers\ousbehci.sys [2005-8-29 44928]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 ousb2hub;OrangeWare USB 2.0 Root Hub Support;c:\windows\system32\drivers\ousb2hub.sys [2005-8-29 55936]
R3 PTDLBus;PANTECH UM175AL Composite Device Driver;c:\windows\system32\drivers\PTDLBus.sys [2009-2-21 32256]
R3 PTDLMdm;PANTECH UM175AL Drivers;c:\windows\system32\drivers\PTDLMdm.sys [2009-2-21 41344]
R3 PTDLVsp;PANTECH UM175AL Diagnostic Port;c:\windows\system32\drivers\PTDLVsp.sys [2009-2-21 39936]
S1 ewbccxfl;ewbccxfl;\??\c:\windows\system32\drivers\ewbccxfl.sys --> c:\windows\system32\drivers\ewbccxfl.sys [?]
S1 flmvzlti;flmvzlti;\??\c:\windows\system32\drivers\flmvzlti.sys --> c:\windows\system32\drivers\flmvzlti.sys [?]
S1 kvpxodfy;kvpxodfy;\??\c:\windows\system32\drivers\kvpxodfy.sys --> c:\windows\system32\drivers\kvpxodfy.sys [?]
S1 ngkrqdgz;ngkrqdgz;\??\c:\windows\system32\drivers\ngkrqdgz.sys --> c:\windows\system32\drivers\ngkrqdgz.sys [?]
S2 dmycvbjrfcbsfww;dmycvbjrfcbsfww;\??\c:\windows\system32\drivers\ghvwhkcofp.sys --> c:\windows\system32\drivers\ghvwhkcofp.sys [?]
S2 jwtldzmafkfnn;jwtldzmafkfnn;\??\c:\windows\system32\drivers\thyqeafogo.sys --> c:\windows\system32\drivers\thyqeafogo.sys [?]
S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys --> c:\windows\system32\drivers\motccgp.sys [?]
S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys --> c:\windows\system32\drivers\motccgpfl.sys [?]
S3 MotDev;Motorola Inc. USB Device;c:\windows\system32\drivers\motodrv.sys --> c:\windows\system32\drivers\motodrv.sys [?]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [2007-11-9 23680]
S3 PTDLWWAN;PANTECH UM175AL WWAN Driver;c:\windows\system32\drivers\PTDLWWAN.sys [2009-2-21 59776]
S3 PTDMMdm;PANTECH USB Modem Drivers ;c:\windows\system32\drivers\ptdmmdm.sys --> c:\windows\system32\drivers\PTDMMdm.sys [?]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys --> c:\windows\system32\drivers\rootrepeal.sys [?]
S3 SASENUM;SASENUM;e:\program files\superantispyware\SASENUM.SYS [2009-11-23 7408]
S3 SIUSBXP;SIUSBXP;c:\windows\system32\drivers\SiUSBXp.sys [2009-2-9 14848]
UnknownUnknown nylowqoh;nylowqoh; [x]

============== File Associations ===============

regfile=regedit.exe "%1" %*
scrfile="%1" %*

=============== Created Last 30 ================

2010-09-10 19:53:44 0 d-----w- c:\program files\Elaborate Bytes
2009-12-17 02:58:05 54156 ---ha-w- c:\windows\QTFont.qfn
2009-12-17 02:58:05 1409 ----a-w- c:\windows\QTFont.for
2009-12-14 20:01:21 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-14 20:01:20 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-09 18:59:49 0 d-----w- c:\windows\Performance
2009-12-09 18:59:19 0 d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2009-12-08 15:06:09 104512 ----a-w- c:\windows\system32\drivers\AnyDVD.sys
2009-12-03 22:03:53 0 d-----w- c:\program files\Microsoft Security Essentials
2009-12-01 06:19:30 0 d-----w- c:\docume~1\rusty\applic~1\IrfanView
2009-11-30 08:21:37 0 ----a-w- c:\windows\system32\6334.exe
2009-11-30 08:01:37 0 ----a-w- c:\windows\system32\18467.exe
2009-11-30 07:29:07 0 ----a-w- c:\windows\system32\AVR10.exe
2009-11-30 07:20:27 0 ----a-w- c:\windows\system32\41.exe
2009-11-30 07:18:31 0 ----a-w- c:\windows\system32\winhelper86.dll
2009-11-30 07:18:15 0 d-----w- c:\documents and settings\all users\Microsoft PData
2009-11-26 17:17:43 0 d-----w- c:\program files\common files\Wise Installation Wizard
2009-11-23 23:50:02 95 ----a-w- c:\windows\wininit.ini
2009-11-23 17:19:10 0 d-----w- c:\docume~1\rusty\applic~1\AntiVirus Plus
2009-11-22 10:15:22 0 d-----w- c:\program files\WinPcap

==================== Find3M ====================

2009-11-03 02:42:06 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-10-29 07:45:38 916480 ----a-w- c:\windows\system32\wininet.dll
2009-10-21 05:38:36 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38:36 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-13 10:30:16 270336 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38:19 149504 ----a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38:18 79872 ----a-w- c:\windows\system32\raschap.dll
2009-09-28 18:20:43 89256 ----a-w- c:\windows\system32\ElbyCDIO.dll
2008-01-14 01:51:24 1600 ----a-w- c:\program files\ALLTEL Internet Accelerator Client setup.log
2007-08-30 03:30:16 920 ----a-w- c:\program files\INSTALL.LOG
2009-04-23 21:59:51 65536 --sha-w- c:\windows\temp\history\history.ie5\mshist012009042320090424\index.dat

============= FINISH: 20:33:51.50 ===============
Once again thank you so much.

Attached Files



#5 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:17 AM

Posted 19 December 2009 - 09:46 PM

Hello again.

You seem to heavily infected.

--

Let's get a GMER scan and see if that works.

Download and Run GMER

We will use GMER to scan for rootkits.This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop. Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.

  • Close any and all open programs, as this process may crash your computer.
  • Double click Posted Image or Posted Image on your desktop.
  • When you have done this, close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program. Right-click and select Run As Administrator... if you are using Vista
  • Allow the gmer.sys driver to load if asked.

    If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system... Click NO.
  • In the right panel, you will see several boxes that have been checked. Please UNCHECK the following:
    • Sections
    • IAT/EAT
    • Registry
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show all (Don't miss this one!)
  • Click on Posted Image and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push Posted Image and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running
*Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<--- ROOKIT" entries
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#6 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 19 December 2009 - 11:48 PM

Sorry for the long delay, but that was a long scan here is the log.
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2009-12-19 22:41:15
Windows 5.1.2600 Service Pack 3
Running: n32kh867.exe; Driver: C:\DOCUME~1\Rusty\LOCALS~1\Temp\uwtdypob.sys


---- Devices - GMER 1.0.15 ----

Device \Driver\nvatabus \Device\000000a4 AnyDVD.sys (AnyDVD Filter Driver/SlySoft, Inc.)
Device \Driver\nvatabus \Device\000000a5 AnyDVD.sys (AnyDVD Filter Driver/SlySoft, Inc.)
Device \Driver\nvatabus \Device\000000a6 AnyDVD.sys (AnyDVD Filter Driver/SlySoft, Inc.)
Device \Driver\nvatabus \Device\000000a7 AnyDVD.sys (AnyDVD Filter Driver/SlySoft, Inc.)
Device \Driver\nvatabus \Device\NvAta0 AnyDVD.sys (AnyDVD Filter Driver/SlySoft, Inc.)

AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

---- EOF - GMER 1.0.15 ----

#7 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:17 AM

Posted 20 December 2009 - 11:40 AM

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page on instructions on doing so.

Please include the C:\ComboFix.txt in your next reply for further review.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#8 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 20 December 2009 - 01:54 PM

OK, EB, ComboFix scan ran and here is the log.

Attached Files



#9 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 20 December 2009 - 02:21 PM

EB,
Wanted to let you know that Windows Security is still picking up Alureon.CT.
Thanks

#10 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:17 AM

Posted 20 December 2009 - 02:47 PM

Hello.

Wanted to let you know that Windows Security is still picking up Alureon.CT.

What file is it that your Windows Security detect that is in question.

In the mean time I'm going to review the CF log and provide the next set of instructions.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#11 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 20 December 2009 - 02:59 PM

EB,
It picked up: Trojan:Win32/Alureon.CT. After it cleaned and re-booted Windows Security picked up: Trojan Downloader:Win32/Fakeinit, Trojan Downloader: Win32/Harnig.gen!L, and Trojan:Win32/Opachki.A

#12 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:17 AM

Posted 20 December 2009 - 03:00 PM

Okay, but what is the filename that it's detecting this.
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#13 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 20 December 2009 - 03:02 PM

It's "Microsoft Security Essential" that is detecting this.

#14 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:09:17 AM

Posted 20 December 2009 - 03:04 PM

Hello.

Answer my previous question please.

It's "Microsoft Security Essential" that is detecting this.

Yes... but what is the file that it's detecting?



Let's continue here, however regarding one of the infections.

Posted ImageBackdoor Threat

IMPORTANT NOTE: Unfortunatly One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.

If you wish to continue, please follow the instructions below please...

---
Run ComboFix with CFScript

We will run ComboFix again. This time, the instructions are slightly different.
  • Close any open browsers.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are unsure how.
  • Open notepad (Start>Run>"notepad") and copy/paste the text in the quotebox below into it:
    File::
    c:\windows\system32\drivers\ewbccxfl.sys
    c:\windows\system32\drivers\flmvzlti.sys
    c:\windows\system32\drivers\kvpxodfy.sys
    c:\windows\system32\drivers\ngkrqdgz.sys
    c:\windows\system32\drivers\ghvwhkcofp.sys
    c:\windows\system32\drivers\thyqeafogo.sys
    c:\windows\S56185B5A.tmp
    c:\windows\system32\28.tmp
    c:\windows\system32\23.tmp
    Driver::
    ewbccxfl
    flmvzlti
    kvpxodfy
    ngkrqdgz
    dmycvbjrfcbsfww
    jwtldzmafkfnn
    Registry::
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7c94cc9-0035-11de-b179-f181650591d0}]
    DDS::
    FF - HiddenExtension: XULRunner: {B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2} - c:\documents and settings\Rusty\Local Settings\Application Data\{B54BDBA0-E0F5-4FEB-831F-DDD4C1F2F2A2}
    FF - HiddenExtension: XULRunner: {DDE14058-4105-401E-9823-2851736FF5D5} - c:\documents and settings\Rusty\Local Settings\Application Data\{DDE14058-4105-401E-9823-2851736FF5D5}\
    Save this as CFScript.txt, in the same location as ComboFix.exe. (This should be your desktop.)
    Posted Image
    Refering to the picture above, drag CFScript into ComboFix.exe.
When finished, it shall produce a log for you at "C:\ComboFix.txt". Post back with that log.

Do not mouseclick ComboFix's window while it's running. That may cause it to stall

Download and Run GooredFix

Please download GooredFix and save it to your Desktop if you lost your copy.
Alternative Download Mirror #1

Please make sure all instances of Firefox are closed at this point before proceeding.
  • Ensure all Firefox windows are closed at this time.
  • Please double-click GooredFix.exe on your Desktop to run it. If you are using Vista, please right-click and select run as administartor
  • When prompted to run the scan, click Yes.
  • The removal process will begin, please be paitent until it finishes.
  • A log will open with the file after completion, please post the contents of that log in your next reply
*Note: The log can also be found on your desktop called GooredFix.txt

Download and run MalwareBytes Anti-Malware

Please download Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 1
  • Make sure you are connected to the Internet.
  • Double-click on Download_mbam-setup.exe to install the application.
  • When the installation begins, follow the prompts and do not make any changes to default settings.
  • When installation has finished, make sure you leave both of these checked:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue. If you encounter any problems while downloading the updates, manually download them from here and just double-click on mbam-rules.exe to install.
  • On the Scanner tab:
    • Make sure the "Perform Quick Scan" option is selected.
    • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
  • Back at the main Scanner screen, click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply and exit MBAM.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.

For complete or visual instructions on installing and running Malwarebytes Anti-Malware please read this link

Please then run GMER again in Normal Mode and post the GMER log in your next reply as well.

With Regards,
Extremeboy

Edited by extremeboy, 20 December 2009 - 03:04 PM.

Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#15 Rusty F

Rusty F
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:07:17 AM

Posted 20 December 2009 - 03:23 PM

Sorry EB, misunderstood the question here are the files that are infected
container file:C:\Windows\System32\config\Systemprofile\local settings\Temporary Internet Files\Content.IE5\UD2V8V2Z\hnkppz[1].htm
file:C:Windows\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UD2V8V2Z\hnkppz[1].htm-(VFS:ntload.DLL)
file:C:Windows\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UD2V8V2Z\hohhveswgc[1].htm
file:C:Windows\System32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\I1Q96BON\zgzzjjwli[1].htm
file:C:Windows\System32\tdlcmd.dll

These are the files that are showing infected should I go ahead and following your previous instructions.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users