|
WinAntivirus pro 2007
|
|
grfldd411
Newbie
|
1. November 2007 @ 03:39 |
Link to this message
|
I have a friends laptop that has a lot of virus, trogans and adware. I got rid of most of with a scan from Avast antivirus. Now I did see that it removed something from winantivirus but when I open explorer Avast found the virus again. I am posting the Avast log and the HJT log. Can someone tell me what I have to do. You guys helped a while ago with the virusburst viruses and got rid of them. Thanks
Logs:
Avast:
11/01/2007 02:28
Scan of all local drives
File C:\Documents and Settings\Marjorie\Application Data\winantiviruspro2007freeinstall[1].exe is infected by Win32:Downloader-KK [Trj], Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\!update.exe\[PECompact] is infected by Win32:Purityscan-Q [Trj], Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\is68131.exe is infected by Win32:Vundo-gen46 [Adw], Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\k11u72.exe is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\svhost.exe is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\WinAntiSpyware 2007 FreeInstall.exe is infected by Win32:Downloader-KK [Trj], Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\wr-1-0000077.exe\[UPX] is infected by Win32:Small-GWM [Trj], Deleted
File C:\Documents and Settings\Marjorie\Local Settings\Temp\yazzlesnet.exe is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\Program Files\Common Files\WinAntiVirus Pro 2007\wa7pinst.exe is infected by Win32:Downloader-KK [Trj], Deleted
File C:\Program Files\Common Files\Yazzle1281OinAdmin.exe\[PECompact] is infected by Win32:PurityScan-AF [Trj], Deleted
File C:\Program Files\func.exe is infected by Win32:Small-BSJ [Trj], Deleted
File C:\Program Files\MSN\qubaqib.dll is infected by Win32:Small-AHY [Trj], Deleted
File C:\Program Files\MSN\qubaqib668.dll is infected by Win32:Small-AHY [Trj], Deleted
File C:\Program Files\Online Services\mewemewyn22011.exe is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\Program Files\svhost\wr-1-0000077.exe is infected by Win32:Small-HRY [Trj], Deleted
File C:\Program Files\svhost\wr-1-77.exe\[UPX] is infected by Win32:Small-GWM [Trj], Deleted
File C:\Program Files\WinAntiVirus Pro 2007\fopn.sys is infected by Win32:Adware-gen. [Adw], Deleted
File C:\Program Files\WinAntiVirus Pro 2007\plugins\SCANKRNL.DLL\[UPX] is infected by PS/MPC-gen5, Deleted
File C:\WINDOWS\A?pPatch\ping.exe\[UPX] is infected by Win32:Purityscan-Q [Trj], Deleted
File C:\WINDOWS\Downloaded Program Files\DailyToolbar.dll is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\WINDOWS\Downloaded Program Files\vzbb.dll is infected by Win32:Adware-gen. [Adw], Deleted
File C:\WINDOWS\offun.exe is infected by Win32:Agent-CWW [Trj], Deleted
File C:\WINDOWS\rau001978.exe is infected by Win32:Adware-gen. [Adw], Deleted
File C:\WINDOWS\retadpu1000106.exe\[UPX] is infected by Win32:Agent-HKJ [Trj], Deleted
File C:\WINDOWS\retadpu77.exe.tmp\[UPX] is infected by Win32:Agent-HKJ [Trj], Deleted
File C:\WINDOWS\svhost.exe is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\WINDOWS\SYSTEM32\acmpnjoq.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\altkxgio.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\awtqnlk.dll is infected by Win32:Vundo-gen46 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\byxuvtr.dll is infected by Win32:Vundo-gen47 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\cdcclfdm.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\cfhgwwkv.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\djdcmlyx.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\DRIVERS\fopn.sys is infected by Win32:Adware-gen. [Adw], Deleted
File C:\WINDOWS\SYSTEM32\dwdsrngt.exe is infected by Win32:Adware-gen. [Adw], Deleted
File C:\WINDOWS\SYSTEM32\ebayhcqt.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\emqbladp.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\f02WtR\f02WtR1065.exe is infected by Win32:VB-ESB [Trj], Deleted
File C:\WINDOWS\SYSTEM32\f10WtR\f10WtR1099.exe is infected by Win32:VB-ESB [Trj], Deleted
File C:\WINDOWS\SYSTEM32\femlmyri.exe is infected by Win32:Agent-LML [Trj], Deleted
File C:\WINDOWS\SYSTEM32\fidpu.dll\[PECompact] is infected by Win32:Agent-RY [Trj], Deleted
File C:\WINDOWS\SYSTEM32\flvewwgj.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\fmbhdbrh.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\ftaqvhju.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\gmlfoaws.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\gnsmmmef.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\ijoysrve.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\iqlpxtaw.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\latarxyh.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\lhwvluaj.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\lpdsrngk.exe is infected by Win32:Adware-gen. [Adw], Deleted
File C:\WINDOWS\SYSTEM32\mljkjih.dll is infected by Win32:Vundo-gen46 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\nmnfbvxk.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\nvcdmqlf.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\oademmlx.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\plrsespu.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\qtbtudmk.exe is infected by Win32:Agent-LML [Trj], Deleted
File C:\WINDOWS\SYSTEM32\rebnvdjc.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\redftiua.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\rqrsstu.dll is infected by Win32:Vundo-gen46 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\sfynmibc.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\tjsqnpyn.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\tkivbsvf.exe is infected by Win32:Agent-LML [Trj], Deleted
File C:\WINDOWS\SYSTEM32\tunfoxle.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\tuvspqr.dll is infected by Win32:Vundo-gen47 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\tvcilmjj.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\twinqmdt.exe is infected by Win32:Downloader-IB [Trj], Deleted
File C:\WINDOWS\SYSTEM32\ukwnomnv.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\urqqq.dll is infected by Win32:Vundo-gen46 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\wbymdksd.exe is infected by Win32:Agent-LML [Trj], Deleted
File C:\WINDOWS\SYSTEM32\win\w71.exe\[UPX] is infected by Win32:Small-GWM [Trj], Deleted
File C:\WINDOWS\SYSTEM32\wsqguuuk.dll is infected by Win32:Vundo-gen49 [Adw], Deleted
File C:\WINDOWS\SYSTEM32\xoasejpq.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\SYSTEM32\Y2\x55.exe\[UPX] is infected by Win32:Agent-COV [Trj], Deleted
File C:\WINDOWS\SYSTEM32\ycbuncmu.exe is infected by Win32:Agent-LML [Trj], Deleted
File C:\WINDOWS\SYSTEM32\yorvojwm.exe is infected by Win32:Agent-LAP [Trj], Deleted
File C:\WINDOWS\TISKY009.exe is infected by Win32:Adware-gen. [Adw], Deleted
File C:\WINDOWS\tk58.exe is infected by Win32:Small-AHY [Trj], Deleted
File C:\WINDOWS\xyjeyua.exe is infected by Win32:Trojan-gen. {Other}, Deleted
File C:\WINDOWS\xyjeyuaA.exe is infected by Win32:VB-ESA [Trj], Deleted
File C:\WINDOWS\?icrosoft\t?skmgr.exe\[PECompact] is infected by Win32:PurityScan-AF [Trj], Deleted
Number of searched folders: 5197
Number of tested files: 47955
Number of infected files: 81
This was the warning I got when I opened IE:
11/1/2007 3:09:14 AM 1193900954 SYSTEM 1216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\WinAntiVirus Pro 2007\winpgi.dll" file.
11/1/2007 3:09:34 AM 1193900974 SYSTEM 1216 Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Program Files\WinAntiVirus Pro 2007\winpgi.dll" file.
HJT Log:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 3:18:15 AM, on 11/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\WINDOWS\retadpu77.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Marjorie\Desktop\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.portalsearching.com/search/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.portalsearching.com/search/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.portalsearching.com/search.php?phrase=%s
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.jasc.com/command.asp?app=dlp&...nt&lang=english
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {16E9067F-5746-4562-B6B6-4093CEF48A64} - C:\WINDOWS\system32\urqqq.dll (file missing)
O2 - BHO: (no name) - {2A4CD887-3262-3FB6-6556-4A71B17993B9} - C:\WINDOWS\system32\fidpu.dll (file missing)
O2 - BHO: (no name) - {2B4CD8F1-3214-4FC4-6521-4D71B27493CA} - C:\WINDOWS\system32\fidpu.dll (file missing)
O2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: 0 - {7D139317-54C1-4E62-F2B4-605043738FD5} - C:\Program Files\MSN\qubaqib.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\system32\uvvbkabf.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O2 - BHO: (no name) - {D6862A22-1DD6-11D3-BB7C-444553540000} - (no file)
O2 - BHO: (no name) - {E9BD0828-1FD9-410C-A50F-43EBE65D310F} - C:\WINDOWS\system32\mljkjih.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\retadpu77.exe 61A847B5BBF72815358B2B27128065E9C084320161C4661227A755E9C2933154389A28452DA545E9B1894E754BE54C29159A7DA197C7734672DE3F516CAC59B6
O4 - HKLM\..\Run: [xyjeyuaA] C:\WINDOWS\xyjeyuaA.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\APPATC~1\ping.exe" -vt yazb
O4 - HKCU\..\Run: [Arbwjgq] "C:\Documents and Settings\Marjorie\Application Data\??stem\r?gsvr32.exe"
O4 - HKCU\..\Run: [Tld] C:\WINDOWS\?icrosoft\t?skmgr.exe
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: IEToolbarCab - http://www.lesbiantoolbar.com/DailyToolbar.CAB
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {666E4D35-E955-11D0-A707-000000521958} - http://ads.dropspam.com/landing/aac/upgrade.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupd...b?1153417888490
O20 - Winlogon Notify: mljkjih - mljkjih.dll (file missing)
O20 - Winlogon Notify: urqqq - C:\WINDOWS\system32\urqqq.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\femlmyri.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\xyjeyua.exe (file missing)
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 8717 bytes
Garfield Da Kat!
|
bunny_c
Suspended permanently
|
3. November 2007 @ 11:59 |
Link to this message
|
|
|