rootkit, happili, cridex, alurion

#1 e-z-d


Posted 13 August 2012 - 08:07 PM

Getting search redirects so I have been trying to remove. I've had success removing things, but it's definitely not solved. I guess it's time to ask for help. :angry:

Windows XPSP3 auto updates enabled
Microsoft Security Essentials

TDSSkiller removed several things
mbam removed 2-happili and cridex
Microsoft caught a bunch of Alureon trojans

At first it was only Firefox, and chrome, but after uninstalling and trying IE that was also redirecting search results.

#2 e-z-d

Posted 13 August 2012 - 08:17 PM

DDS log

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.5.1
Run by EZD at 20:13:10 on 2012-08-13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2279 [GMT -5:00]
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\svchost.exe -k HPService
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\TightVNC\tvnserver.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\ASUS\GPU NOS\Gpu.exe
C:\Program Files\KMaestro\KMaestro.exe
C:\Program Files\TightVNC\tvnserver.exe
C:\Program Files\HTC\ModeSelection\VMMModeSelection.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Plex\Plex Media Server\Plex Media Server.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\EZD\Application Data\Dropbox\bin\Dropbox.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Plex\Plex Media Server\PlexScriptHost.exe
C:\Program Files\Plex\Plex Media Server\PlexDlnaServer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.exe
C:\Documents and Settings\EZD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\EZD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\EZD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\EZD\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
============== Pseudo HJT Report ===============
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Bing Bar Helper: {1dad3af3-ef2f-4f64-ac4b-11789189fcb6} - c:\program files\microsoft\bingbar\7.1.361.0\BingExt.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\oracle\javafx 2.1 runtime\bin\ssv.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\oracle\javafx 2.1 runtime\bin\jp2ssv.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
EB: HP Smart Web Printing: {555d4d79-4bd2-4094-a395-cfc534424a05} - c:\program files\hp\digital imaging\smart web printing\hpswp_bho.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\nero\lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
uRun: [Plex Media Server] "c:\program files\plex\plex media server\Plex Media Server.exe"
uRun: [foobar2000] RUNDLL32.EXE "c:\documents and settings\ezd\local settings\application data\foobar2000\bteyagjv.dll",EditHhCtrlScript
uRun: [Google Update] "c:\documents and settings\ezd\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [HDAudDeck] c:\program files\via\viaudioi\hdadeck\HDeck.exe 1
mRun: [GPU NOS] "c:\program files\asus\gpu nos\Gpu.exe" -b
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe
mRun: [BtcMaestro] "c:\program files\kmaestro\KMaestro.exe"
mRun: [tvncontrol] "c:\program files\tightvnc\tvnserver.exe" -controlservice -slave
mRun: [VMM Mode Selection] c:\program files\htc\modeselection\VMMModeSelection.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey
mRun: [DeltaIITaskbarApp] c:\windows\system32\DeltaIITray.exe
mRun: [M-Audio Taskbar Icon] c:\windows\system32\DeltaIITray.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\ezd\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\ezd\application data\dropbox\bin\Dropbox.exe
StartupFolder: c:\docume~1\ezd\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} - hxxp://support.asus.com/select/asusTek_sys_ctrl3.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://windowsupdate.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1326011794609
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer =
TCP: Interfaces\{AE757562-A429-41A5-9247-A98A014B1531} : DhcpNameServer =
Notify: AtiExtEvent - Ati2evxx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\documents and settings\ezd\application data\mozilla\firefox\profiles\cja38n9w.default\
FF - plugin: c:\documents and settings\ezd\local settings\application data\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\\npGoogleUpdate3.dll
FF - plugin: c:\program files\microsoft silverlight\5.1.10411.0\npctrlui.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dll
FF - plugin: c:\program files\oracle\javafx 2.1 runtime\bin\plugin2\npjp2.dll
FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_3_300_270.dll
FF - plugin: c:\windows\system32\npDeployJava1.dll
FF - plugin: c:\windows\system32\npptools.dll
============= SERVICES / DRIVERS ===============
R0 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 171064]
R1 MpKslb6591f20;MpKslb6591f20;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ce25dfcb-27ee-4f81-b881-909a85aeb531}\MpKslb6591f20.sys [2012-8-13 29904]
R2 MotoHelper;MotoHelper Service;c:\program files\motorola\motohelper\MotoHelperService.exe [2011-12-6 214896]
R2 tvnserver;TightVNC Server;c:\program files\tightvnc\tvnserver.exe [2011-8-3 828944]
R3 AODDriver;AODDriver;c:\program files\asus\gpu nos\i386\aoddriver.sys [2012-1-8 36864]
R3 BBUpdate;BBUpdate;c:\program files\microsoft\bingbar\7.1.361.0\SeaPort.EXE [2012-2-10 240408]
R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\drivers\deltaII.sys [2012-5-14 302728]
S2 BBSvc;BingBar Service;c:\program files\microsoft\bingbar\7.1.361.0\BBSvc.EXE [2012-2-10 193816]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2012-5-14 116648]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2012-5-14 116648]
S3 motandroidusb;Mot ADB Interface Driver;c:\windows\system32\drivers\motoandroid.sys [2012-2-24 25856]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\mozilla maintenance service\maintenanceservice.exe [2012-8-13 113120]
S3 PSMounter;Macrium Reflect Image Explorer Service;c:\docume~1\ezd\locals~1\temp\hbcd\psmounter.sys [2012-1-28 44512]
S3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2012-1-8 2106880]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
=============== Created Last 30 ================
2012-08-14 00:50:21 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ce25dfcb-27ee-4f81-b881-909a85aeb531}\offreg.dll
2012-08-14 00:48:57 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ce25dfcb-27ee-4f81-b881-909a85aeb531}\MpKslb6591f20.sys
2012-08-14 00:35:56 -------- d-----w- c:\program files\CCleaner
2012-08-14 00:34:04 6891424 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{ce25dfcb-27ee-4f81-b881-909a85aeb531}\mpengine.dll
2012-08-14 00:13:51 388096 ----a-r- c:\documents and settings\ezd\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2012-08-14 00:13:50 -------- d-----w- c:\program files\Trend Micro
2012-08-14 00:12:14 6891424 ------w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll
2012-08-13 01:19:09 -------- d-----w- c:\documents and settings\ezd\application data\Malwarebytes
2012-08-13 01:18:55 -------- d-----w- c:\documents and settings\all users\application data\Malwarebytes
2012-08-13 01:18:54 22344 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-13 01:18:54 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2012-08-13 01:17:20 98992 ----a-w- c:\windows\system32\drivers\27467272.sys
2012-08-12 17:53:44 -------- d-----w- c:\program files\ESET
2012-08-12 17:42:07 -------- d-----w- c:\documents and settings\ezd\local settings\application data\Sun
2012-08-12 17:35:06 -------- d-----w- C:\TDSSKiller_Quarantine
2012-08-11 16:25:41 -------- d-----w- c:\documents and settings\ezd\local settings\application data\RTGreene_&_MJS_Gadgets
2012-08-11 16:25:23 136008 ----a-w- c:\windows\system32\msinet.ocx
2012-08-11 16:25:14 203976 ----a-w- c:\windows\system32\RICHTX32.OCX
2012-08-11 16:25:14 152848 ----a-w- c:\windows\system32\COMDLG32.OCX
2012-08-11 16:25:14 150528 ----a-w- c:\windows\system32\TLBINF32.DLL
2012-08-11 16:25:14 124688 ----a-w- c:\windows\system32\MSWINSCK.OCX
2012-08-11 16:25:09 -------- d-----w- c:\program files\RideRunner
2012-08-11 05:12:19 -------- d-----w- c:\program files\Oracle
2012-08-11 05:12:09 772544 ----a-w- c:\windows\system32\npDeployJava1.dll
2012-08-11 05:12:09 143872 ----a-w- c:\windows\system32\javacpl.cpl
2012-08-10 01:13:36 -------- d-----w- c:\windows\system32\NtmsData
2012-08-10 01:04:36 -------- d-----w- c:\documents and settings\ezd\local settings\application data\foobar2000
2012-08-01 01:04:23 -------- d-----w- c:\program files\Aixcoustic
2012-08-01 01:04:22 -------- d-----w- c:\program files\VstPlugins
2012-07-31 02:17:49 -------- d-----w- c:\documents and settings\ezd\application data\foobar2000
==================== Find3M ====================
2012-08-05 13:53:56 70344 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-08-05 13:53:56 426184 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-06 03:06:20 687544 ----a-w- c:\windows\system32\deployJava1.dll
2012-06-23 20:35:04 9815752 ----a-w- c:\windows\system32\FlashPlayerInstaller.exe
2012-06-13 13:19:59 1866112 ----a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50:25 1372672 ----a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50:25 1172480 ----a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32:08 152576 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 20:19:44 22040 ----a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 20:19:38 219160 ----a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 20:19:38 15384 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 20:19:34 15384 ----a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 20:19:30 17944 ----a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 20:18:58 275696 ----a-w- c:\windows\system32\mucltui.dll
2012-06-02 20:18:58 214256 ----a-w- c:\windows\system32\muweb.dll
2012-06-02 20:18:58 17136 ----a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22:09 599040 ----a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08:26 916992 ----a-w- c:\windows\system32\wininet.dll
============= FINISH: 20:13:29.76 ===============

#3 e-z-d

Posted 14 August 2012 - 09:59 PM

Had a recent re-image backup decided to do that in 10 minutes instead of fight off an STD over several hours. Consider this closed.

