I could really use some help, I hope I am doing this right...My work computer has a virus on it, and to complicate matters further, my employer for some reason will not allow us to install any antivirus programs onto our computers (do not have admin rights).
I ran bit defender through firefox and the report is below. For some reason I was able to DL and use OTL to scan as well. (and can include any scan reports etc if it would be helpful)
Not sure how much can be done without being able to install any software or reformat, but after doing a search and reading some of the threads here I know if anyone can help me it's one of y'all. Any help would be greatly appreciated!
Thank you
QuickScan Beta 32-bit v0.9.9.41
-------------------------------
Scan date: Wed Oct 20 08:33:54 2010
Machine ID: 4831D48F
Found 3 infected files!
-----------------------
C:\Documents and Settings\myname\Local Settings\Application Data\csginbd.dll --> Trojan.TDSS.AGS
--> HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Mnutur"
--> Process explorer.exe (1684)
--> Process rundll32.exe (3832)
C:\Documents and Settings\myname\Local Settings\Application Data\olukaqojo.dll --> Gen:Variant.Hiloti.4
--> HKCU\Software\Microsoft\Windows\CurrentVersion\Run\"Jqajewomewomewom"
--> Process ctfmon.exe (3812)
--> Process explorer.exe (1684)
--> Process firefox.exe (2696)
--> Process msimn.exe (1924)
--> Process msmsgs.exe (3840)
--> Process rundll32.exe (3832)
--> Process soffice.bin (2312)
c:\windows\system\svchost.exe --> Trojan.Agent.AAEQ
--> HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit"
Processes
---------
Firefox 2696 C:\Documents and Settings\All Users\Application Data\Mozilla Firefox\firefox.exe
Messenger 3840 C:\Program Files\Messenger\msmsgs.exe
Microsoft® Windows® Operating System 1924 C:\Program Files\Outlook Express\msimn.exe
Microsoft® Windows® Operating System 1684 C:\WINDOWS\explorer.exe
Microsoft® Windows® Operating System 3812 C:\WINDOWS\system32\ctfmon.exe
Microsoft® Windows® Operating System 3832 C:\WINDOWS\system32\rundll32.exe
OpenOffice.org 2.4 2312 C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
OpenOffice.org 2.4 2984 C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
Network activity
----------------
Process firefox.exe (2696) connected on port 80 (HTTP) --> 74.125.227.49
Process firefox.exe (2696) connected on port 80 (HTTP) --> 74.125.227.49
Process firefox.exe (2696) connected on port 80 (HTTP) --> 74.125.227.49
Process firefox.exe (2696) connected on port 443 (HTTP over SSL) --> 74.125.227.49
Process firefox.exe (2696) connected on port 80 (HTTP) --> 74.125.227.49
Process firefox.exe (2696) connected on port 443 (HTTP over SSL) --> 74.125.227.55
Autoruns and critical files
---------------------------
Adobe Acrobat C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
FrameDbl C:\Documents and Settings\myname\Local Settings\Application Data\csginbd.dll
Messenger C:\Program Files\Messenger\msmsgs.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\browseui.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\crypt32.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\cryptnet.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\cscdll.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\ctfmon.exe
Microsoft® Windows® Operating System C:\WINDOWS\System32\dimsntfy.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\logonui.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\sclgntfy.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\shell32.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\stobject.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\userinit.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\wlnotify.dll
olukaqojo.dll C:\Documents and Settings\myname\Local Settings\Application Data\olukaqojo.dll
quickstart.exe C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
QuickTime C:\Program Files\QuickTime\qttask.exe
svchost.exe c:\windows\system\svchost.exe
Windows® Internet Explorer C:\WINDOWS\system32\webcheck.dll
Browser plugins
---------------
AcroIEHelperShim Library c:\program files\common files\adobe\acrobat\activex\acroiehelpershim.dll
Adobe Acrobat C:\Program Files\Internet Explorer\plugins\nppdf32.dll
Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
BitDefender QuickScan C:\Documents and Settings\myname\Application Data\Mozilla\Firefox\Profiles\dz3gik1t.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll
BitDefender QuickScan C:\Documents and Settings\myname\Application Data\Mozilla\Firefox\Profiles\dz3gik1t.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
Download PDF Files C:\Program Files\PlotSoft\PDFill\DownloadPDF.exe
getPlusPlus for Adobe 16263 C:\Documents and Settings\myname\Application Data\Mozilla\Firefox\Profiles\dz3gik1t.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.dll
InstallShield Update Service C:\WINDOWS\Downloaded Program Files\dwusplay.exe
InstallShield Update Service C:\WINDOWS\Downloaded Program Files\isusweb.dll
Java Platform SE 6 U11 c:\program files\java\jre6\bin\jp2ssv.dll
Java Platform SE 6 U11 c:\program files\java\jre6\bin\ssv.dll
Java Platform SE 6 U11 c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
Messenger C:\Program Files\Messenger\msmsgs.exe
Microsoft® Windows® Operating System C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
Microsoft® Windows® Operating System C:\WINDOWS\system32\mswsock.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\rsvpsp.dll
Microsoft® Windows® Operating System C:\WINDOWS\system32\winrnr.dll
Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll
NPSWF32.dll C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
QuickTime Plug-in 7.6.4 C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
Silverlight Plug-In c:\Program Files\Microsoft Silverlight\3.0.40818.0\npctrl.dll
Windows® Internet Explorer C:\WINDOWS\system32\ieframe.dll
Missing files
-------------
File not found: C:\WINDOWS\System32\appmgmts.dll
--> HKLM\System\ControlSet001\services\AppMgmt\Parameters\"ServiceDll"
File not found: C:\WINDOWS\System32\hidserv.dll
--> HKLM\System\ControlSet001\services\HidServ\Parameters\"ServiceDll"
Scan
----
The following file(s) must be uploaded for server-side scanning:
C:\Documents and Settings\myname\Local Settings\Application Data\olukaqojo.dll
Upload started - 1 file(s)
olukaqojo.dll (199168)
Upload speed - 13 KB/s
Upload finished - 1 uploaded, 0 failed
Scan finished - communication took 16 sec
Total traffic - 0.21 MB sent, 0.86 KB recvd
Scanned 610 files and modules - 53 seconds
==============================================================================
Edited by Budapest, 20 October 2010 - 06:24 PM.
Moved from Virus, Trojan, Spyware, and Malware Removal Logs ~BP