Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Antivirus Live Infection


  • This topic is locked This topic is locked
2 replies to this topic

#1 pandabar

pandabar

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:08:48 PM

Posted 09 December 2009 - 08:54 PM

Antivirus Live infected my computer and pop-ups started appearing. Also, it disabled many programs such as Word, Internet Explorer, Google Chrome, iTunes, etc.

DDS (Ver_09-12-01.01) - NTFSx86
Run by Masayuki at 17:40:10.48 on Wed 12/09/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1791.1246 [GMT -8:00]

AV: avast! antivirus 4.8.1351 [VPS 091209-1] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Masayuki\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.google.com
uRun: [Google Update] "c:\documents and settings\masayuki\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe"
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [RemoteControl] "c:\program files\asustek\asusdvd\PDVDServ.exe"
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd.exe"
mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
Notify: AtiExtEvent - Ati2evxx.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\masayuki\applic~1\mozilla\firefox\profiles\r1xrnifb.default\
FF - plugin: c:\documents and settings\masayuki\application data\mozilla\firefox\profiles\r1xrnifb.default\extensions\{e2883e8f-472f-4fb0-9522-ac9bf37916a7}\plugins\np_gp.dll
FF - plugin: c:\documents and settings\masayuki\local settings\application data\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

============= SERVICES / DRIVERS ===============

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-8-20 114768]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-6-23 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-6-23 74480]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-8-20 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-8-20 138680]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-8-20 352920]
S2 srrjdh;srrjdh;\??\c:\windows\system32\drivers\gxatkyg.sys --> c:\windows\system32\drivers\gxatkyg.sys [?]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-8-20 254040]
S3 OEMFVNETusb(505_2958)®;OEM FVNETusb(505_2958)® Service for 802.11b Pen Size Wireless USB Adapter;c:\windows\system32\drivers\vnet558x.sys [2009-8-20 102144]
S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-6-23 7408]

=============== Created Last 30 ================

2009-12-10 01:08:17 0 d-sha-r- C:\cmdcons
2009-12-10 01:06:32 98816 ----a-w- c:\windows\sed.exe
2009-12-10 01:06:32 77312 ----a-w- c:\windows\MBR.exe
2009-12-10 01:06:32 261632 ----a-w- c:\windows\PEV.exe
2009-12-10 01:06:32 161792 ----a-w- c:\windows\SWREG.exe
2009-12-06 02:54:31 157184 ----a-w- C:\waees.exe
2009-12-06 02:54:25 30206 ----a-w- C:\siuhb.exe

==================== Find3M ====================

2009-12-07 03:48:58 96512 ------w- c:\windows\system32\drivers\atapi.sys
2009-09-29 23:02:00 19942 ----a-w- c:\program files\common files\lezy.exe
2009-09-27 23:14:34 36540 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-27 00:52:54 16204 ----a-w- c:\docume~1\masayuki\applic~1\ados.scr
2009-09-20 17:24:48 13593 ----a-w- c:\windows\lysasoby.bin
2009-09-15 05:03:57 19588 ----a-w- c:\program files\common files\jytolezek.lib
2009-09-15 05:03:57 15823 ----a-w- c:\docume~1\alluse~1\applic~1\agelu.pif
2009-09-15 05:03:57 15612 ----a-w- c:\windows\uquvuq.bin
2009-09-15 05:03:57 10556 ----a-w- c:\docume~1\masayuki\applic~1\ofunuj.com
2009-09-15 05:03:56 15436 ----a-w- c:\program files\common files\lurocuq.db
2009-09-15 05:03:56 13680 ----a-w- c:\docume~1\alluse~1\applic~1\ukyzakemez.sys
2009-09-15 05:03:56 12622 ----a-w- c:\windows\romy.pif
2009-09-15 05:03:56 11528 ----a-w- c:\windows\fipowegyh.pif
2009-09-15 05:03:56 11143 ----a-w- c:\windows\system32\ferylomu.bin
2009-09-15 04:38:43 19358 ----a-w- c:\program files\common files\ysoh.com
2009-09-15 04:38:43 16641 ----a-w- c:\program files\common files\osumewo.com
2009-09-15 04:38:43 15211 ----a-w- c:\docume~1\masayuki\applic~1\pikes.dll
2009-09-15 04:38:43 14107 ----a-w- c:\program files\common files\oxenen.ban
2009-09-15 04:38:43 13175 ----a-w- c:\docume~1\alluse~1\applic~1\owacucim.bin
2009-09-15 04:38:43 10699 ----a-w- c:\program files\common files\sifa.dat
2009-09-15 04:38:43 10240 ----a-w- c:\windows\system32\ifuhaveb.dll
2009-09-11 14:18:39 136192 ----a-w- c:\windows\system32\msv1_0.dll

============= FINISH: 17:40:25.04 ===============

Attached Files



BC AdBot (Login to Remove)

 


#2 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:48 AM

Posted 21 December 2009 - 10:46 PM

Hi,

My name is Extremeboy (or EB for short), and I will be helping you with your log.

We apologize for the delay of response.

If you still require assistance we would like to see the current condition of your system so please post a new set of DDS Logs as well as a RootRepeal log and a description of any remaining problems or symptoms you may still have please.

If for any reason you did not post a DDS log or RootRepeal log please refer to this page and in step #6 and Step #7 for further instructions on downloading and running DDS & RootRepeal. If you have any problems just let me know in your next reply or simply post a Hijackthis log.


For your next reply I would like to see:
-The DDS logs
---DDS.txt and Attach logs
-RootRepeal logs
-Description of any remaining problems you may still have.


Thanks again and we apologize for the delay.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.

#3 extremeboy

extremeboy

  • Malware Response Team
  • 12,975 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:48 AM

Posted 26 December 2009 - 09:37 AM

Hello.

Due to Lack of feedback, this topic is now Closed

If you need this topic reopened, please Send Me a Message. In your message please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,
Extremeboy
Note: Please do not PM me asking for help, instead please post it in the correct forum requesting for help. Help requests via the PM system will be ignored.

If I'm helping you and I don't reply within 48 hours please feel free to send me a PM.

The help you receive here is always free but if you wish to show your appreciation, you may wish to Posted Image.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users