ALSO I'm using another computer to type this.
It found the following which i deleted!
2bti.exe - win32:rootkit-gen
DLLNC.dll - win32:Trojan-gen
KoPb.exe - Win32:trojan-gen
mshtml2.exe [UPX] - Win32-Agent-YTZ (TRJ)
msiexec.exe - Win32: Agent-VDE [TRJ]
c3w3clab/in[1].html - JS:Obfuscated-cv [trj]
C:/programfiles/pc_antispyware2010/wscui.cpl - win32
Found a couple files in my system restore folder which i moved to the chest or deleted
Found the following which i moved to chest(quarantine)
C:/windows/sytem32/000020.exe - win32:Trojan-gen
C:/Windows/system32/000090.exe - win32:crypt-CIL (TRJ)
C:Windows/system32/dllcache/beep.sys is infelected by Win32:FakeAV-No[Rtk]
C:Windows/system32/dllcache/figaro.sys is infelected by Win32:FakeAV-No[Rtk]
C:/windows/sytem32/imeshere.dIl is infected by win32:Trojan-gen
UPDATE: scan was complete, got back onto windows only for it to find another virus. Again Avast is making me run a bootTime Scan.There are two user privalages on the computer ( 1 being my account which is given full rights, and my fathers which is limited(thats where he got he virus using his account). Seems like both are infected though. Can someone please help. thank you.
————————————–
DDS RESULTS::: - had to run this under my account because it wouldn't let me do it under my fathers.
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 15:27:31.10 on Wed 08/26/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.446.75 [GMT -4:00]
AV: avast! antivirus 4.8.1351 [VPS 090826-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner.YOUR-642EF43EAF\My Documents\Computer Fix\dds.scr
============== Pseudo HJT Report ===============
uSearch Bar = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=MX6433
uStart Page = hxxp://www.yahoo.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=PTB&M;=MX6433
BHO: FDMIECookiesBHO Class: {cc59e0f9-7e43-44fa-9faa-8377850bf205} - c:\program files\free download manager\iefdm2.dll
TB: {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - No File
TB: {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [updateMgr] c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe AcRdB7_0_9
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; Media Center PC 2.8; FDM)" -"http://games2.gamesxl.com/03a3616a71e4ef8deed49732d104fce9/game.php?file=687474703a2f2f67616d6573322e67616d6573786c2e636f6d2f30336133363136613731653
465663864656564343937333264313034666365392f3332392e646372&width;=100%&height;=100%&gamesxl;=1&cr;=1&ovrprldr;=1&nobtn;=1"
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Reminder] %WINDIR%\Creator\Remind_XP.exe
mRun: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
mRun: [ATIPTA] c:\program files\ati technologies\ati control panel\atiptaxx.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY
mRun: [AdaptecDirectCD] c:\program files\adaptec\easy cd creator 5\directcd\DirectCD.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ActiveSMART] c:\program files\active smart\\ActiveSMART.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
StartupFolder: c:\docume~1\savan\startm~1\programs\startup\hddlife.lnk - c:\program files\binarysense\hddlife 3\HDDlifeNB.exe
IE: Download all with Free Download Manager - file://c:\program files\free download manager\dlall.htm
IE: Download selected with Free Download Manager - file://c:\program files\free download manager\dlselected.htm
IE: Download video with Free Download Manager - file://c:\program files\free download manager\dlfvideo.htm
IE: Download with Free Download Manager - file://c:\program files\free download manager\dllink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1176519432375
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\savan\applic~1\mozilla\firefox\profiles\5dlbpgce.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?ei=utf-8&fr;=megaup&p;=
FF - component: c:\documents and settings\savan\application data\mozilla\firefox\profiles\5dlbpgce.default\extensions\{0b457caa-602d-484a-8fe7-c1d894a011ba}\platform\winnt_x86-msvc\components\SSSLauncher.dll
FF - component: c:\program files\free download manager\firefox\extension\components\vmsfdmff.dll
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-4-5 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-4-5 20560]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2007-9-29 138680]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2006-11-7 200576]
S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2007-9-29 254040]
S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2007-9-29 352920]
=============== Created Last 30 ================
2009-08-26 14:08 34,816 a——- c:\windows\system32\drivers\.sys
2009-08-26 10:29 17,130 a——- c:\windows\sygumetap.vbs
2009-08-26 10:29 16,666 a——- c:\docume~1\alluse~1\applic~1\yxokem.reg
2009-08-26 10:29 15,653 a——- c:\windows\foxifumes.inf
2009-08-26 10:29 14,566 a——- c:\windows\system32\uxyjagiwu.inf
2009-08-26 10:29 10,791 a——- c:\windows\system32\yjojymygy.dll
2009-08-26 10:29 10,631 a——- c:\windows\uxewi.dat
2009-08-26 10:29 10,015 a——- c:\windows\system32\ykegij.exe
2009-08-26 10:29 16,897 a——- c:\docume~1\alluse~1\applic~1\wuburowaf.com
2009-08-26 07:20 19,462 a——- c:\windows\ejuxyb.reg
2009-08-26 07:20 16,277 a——- c:\windows\system32\uhaketizub.sys
2009-08-26 07:20 13,258 a——- c:\docume~1\alluse~1\applic~1\vobacyl.vbs
2009-08-26 07:20 11,504 a——- c:\program files\common files\ukiku.vbs
2009-08-26 07:20 10,088 a——- c:\windows\yvalytuz.ban
2009-08-26 07:20 18,962 a——- c:\windows\system32\oraked.dl
2009-08-26 07:20 18,677 a——- c:\program files\common files\kecyg.vbs
2009-08-26 07:20 18,438 a——- c:\windows\ogahygosyr.sys
2009-08-26 07:20 18,171 a——- c:\windows\system32\uxohejisy.pif
2009-08-26 07:20 18,031 a——- c:\docume~1\alluse~1\applic~1\hujat.sys
2009-08-26 07:20 14,289 a——- c:\docume~1\alluse~1\applic~1\tyryxiheqa.bat
2009-08-26 07:20 10,845 a——- c:\program files\common files\dilomu.bat
2009-08-26 07:20 –d—– c:\program files\PC_Antispyware2010
2009-08-26 07:13 190,697 a——- c:\windows\system32\wisdstr.exe
==================== Find3M ====================
2009-08-26 10:29 12,993 a——- c:\program files\common files\noxytafo.ban
2009-08-26 07:20 14,530 a——- c:\program files\common files\ewicizo.lib
2009-06-17 12:43 34,688 a——- c:\docume~1\savan\applic~1\GDIPFONTCACHEV1.DAT
2009-06-16 10:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 10:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 15:09 1,291,264 a——- c:\windows\system32\quartz.dll
2008-06-13 16:12 187,904 —sh— c:\program files\common files\Yazzle1552OinAdmin.exe
============= FINISH: 15:28:22.75 ===============