Hello! Long time member, first time request for help... :normal:
My brother's PC has picked up Antivirus 2009, apparently through a Flash Player update ruse. Before he came to me he deleted the folder labeled "Antivirus 2009" in his program files.
This malware apparently tries hard to avoid its removal. I installed Malwarebytes' AntiMalware and HijackThis on advice from elsewhere. (I had to rename the installers before they would install; the same was true with GMER). I cannot get Malwarebytes' AntiMalware or Spybot S&D to run; the malware appears to block them somehow. I am also unable to update AVG Free. I have run HijackThis and produced a log if it is needed.
In accordance with your instructions, here are my GMER, DDS, and ATTACH files...
Any help would be most appreciated. Thank you for your kind assistance.
DDS (Version 1.0) - NTFSx86
Run by Chris at 13:26:15.42 on Wed 11/19/2008
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.248 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\explorer32.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Chris\Desktop\sillybill.exe
C:\Documents and Settings\Chris\Desktop\dds.scr
============== Psuedo HJT Report ===============
uStart Page = hxxp://www.hotmail.com/
BHO: {037C7B8A-151A-49E6-BAED-CC05FCB50328} - c:\windows\system32\winsrc.dll
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg8\avgssie.dll
BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [85211389743856697855676872738774] c:\program files\antivirus 2009\av2009.exe
uRun: [ieupdate] "c:\windows\system32\explorer32.exe"
mRun: [VTTimer] VTTimer.exe
mRun: [VTTrayp] VTtrayp.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys
R1 BIOS;BIOS;\??\c:\windows\system32\drivers\BIOS.sys
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys
R2 KodakSvc;Kodak AiO Device Service;"c:\program files\kodak\printer\center\KodakSvc.exe"
R3 ati2mtaa;ati2mtaa;c:\windows\system32\drivers\ati2mtaa.sys
=============== Created Last 30 ================
2008-11-19 12:32 <DIR> --d----- c:\program files\Trend Micro
2008-11-19 12:24 0 a------- c:\windows\system32\winsrc.dll.tmp
2008-11-19 10:19 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-11-19 10:19 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-19 10:19 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2008-11-19 10:19 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2008-11-17 14:37 76,040 a------- c:\windows\system32\drivers\avgtdix.sys
2008-11-17 14:37 10,520 a------- c:\windows\system32\avgrsstx.dll
2008-11-17 14:37 97,928 a------- c:\windows\system32\drivers\avgldx86.sys
2008-11-17 14:37 <DIR> --d----- c:\windows\system32\drivers\Avg
2008-11-17 14:37 <DIR> --d----- c:\program files\AVG
2008-11-17 14:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2008-11-14 11:55 364,032 a------- c:\windows\system32\winsrc.BAK
2008-11-14 11:53 119,296 a------- c:\windows\system32\explorer32.exe
2008-11-14 11:53 119,296 a------- c:\windows\system32\ieupdates.exe
2008-11-12 15:49 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 15:49 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2008-10-24 08:25 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
==================== Find3M ====================
2008-11-19 11:01 <DIR> --d----- c:\program files\SpywareBlaster
2008-10-19 15:04 4,212 ----h--- c:\windows\system32\zllictbl.dat
2008-10-12 08:30 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
2008-09-15 07:12 1,846,400 a------- c:\windows\system32\win32k.sys
2008-09-13 09:30 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-09-09 20:14 1,307,648 -------- c:\windows\system32\msxml6.dll
2008-09-04 12:15 1,106,944 a------- c:\windows\system32\msxml3.dll
2008-07-15 20:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2008-06-03 17:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Eastman Kodak Company
2008-04-12 06:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\kds_kodak
2008-01-09 19:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kodak
2008-01-07 19:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SBT
============= FINISH: 13:26:56.07 ===============
My brother's PC has picked up Antivirus 2009, apparently through a Flash Player update ruse. Before he came to me he deleted the folder labeled "Antivirus 2009" in his program files.
This malware apparently tries hard to avoid its removal. I installed Malwarebytes' AntiMalware and HijackThis on advice from elsewhere. (I had to rename the installers before they would install; the same was true with GMER). I cannot get Malwarebytes' AntiMalware or Spybot S&D to run; the malware appears to block them somehow. I am also unable to update AVG Free. I have run HijackThis and produced a log if it is needed.
In accordance with your instructions, here are my GMER, DDS, and ATTACH files...
Any help would be most appreciated. Thank you for your kind assistance.
DDS (Version 1.0) - NTFSx86
Run by Chris at 13:26:15.42 on Wed 11/19/2008
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.248 [GMT -5:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Kodak\printer\center\KodakSvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\VTTimer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EKIJ5000MUI.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\explorer32.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Chris\Desktop\sillybill.exe
C:\Documents and Settings\Chris\Desktop\dds.scr
============== Psuedo HJT Report ===============
uStart Page = hxxp://www.hotmail.com/
BHO: {037C7B8A-151A-49E6-BAED-CC05FCB50328} - c:\windows\system32\winsrc.dll
BHO: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - c:\program files\avg\avg8\avgssie.dll
BHO: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [85211389743856697855676872738774] c:\program files\antivirus 2009\av2009.exe
uRun: [ieupdate] "c:\windows\system32\explorer32.exe"
mRun: [VTTimer] VTTimer.exe
mRun: [VTTrayp] VTtrayp.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [NeroCheck] c:\windows\system32\NeroCheck.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [EKIJ5000StatusMonitor] c:\windows\system32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office\OSA9.EXE
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
AppInit_DLLs: avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys
R1 BIOS;BIOS;\??\c:\windows\system32\drivers\BIOS.sys
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys
R2 KodakSvc;Kodak AiO Device Service;"c:\program files\kodak\printer\center\KodakSvc.exe"
R3 ati2mtaa;ati2mtaa;c:\windows\system32\drivers\ati2mtaa.sys
=============== Created Last 30 ================
2008-11-19 12:32 <DIR> --d----- c:\program files\Trend Micro
2008-11-19 12:24 0 a------- c:\windows\system32\winsrc.dll.tmp
2008-11-19 10:19 15,504 a------- c:\windows\system32\drivers\mbam.sys
2008-11-19 10:19 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-19 10:19 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2008-11-19 10:19 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2008-11-17 14:37 76,040 a------- c:\windows\system32\drivers\avgtdix.sys
2008-11-17 14:37 10,520 a------- c:\windows\system32\avgrsstx.dll
2008-11-17 14:37 97,928 a------- c:\windows\system32\drivers\avgldx86.sys
2008-11-17 14:37 <DIR> --d----- c:\windows\system32\drivers\Avg
2008-11-17 14:37 <DIR> --d----- c:\program files\AVG
2008-11-17 14:37 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8
2008-11-14 11:55 364,032 a------- c:\windows\system32\winsrc.BAK
2008-11-14 11:53 119,296 a------- c:\windows\system32\explorer32.exe
2008-11-14 11:53 119,296 a------- c:\windows\system32\ieupdates.exe
2008-11-12 15:49 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 15:49 1,106,944 -c------ c:\windows\system32\dllcache\msxml3.dll
2008-10-24 08:25 337,408 -c------ c:\windows\system32\dllcache\netapi32.dll
==================== Find3M ====================
2008-11-19 11:01 <DIR> --d----- c:\program files\SpywareBlaster
2008-10-19 15:04 4,212 ----h--- c:\windows\system32\zllictbl.dat
2008-10-12 08:30 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll
2008-09-15 07:12 1,846,400 a------- c:\windows\system32\win32k.sys
2008-09-13 09:30 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-09-09 20:14 1,307,648 -------- c:\windows\system32\msxml6.dll
2008-09-04 12:15 1,106,944 a------- c:\windows\system32\msxml3.dll
2008-07-15 20:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2008-06-03 17:59 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Eastman Kodak Company
2008-04-12 06:47 <DIR> --d----- c:\docume~1\alluse~1\applic~1\kds_kodak
2008-01-09 19:58 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Kodak
2008-01-07 19:31 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SBT
============= FINISH: 13:26:56.07 ===============
Attachments
-
2.8 KB Views: 102
-
20.3 KB Views: 79