Hi.
My computer has been infected by the Antivirus Pro 2010 Virus.
So far, I've ran a Malwarebytes system scan and it has removed the virus initially.
However, it has come back as an icon in the sidetray and has now infected my computer.
When I tried to access my account, a BSOD appears and my computer just crashes.
Here are the logs in respective order: Rootrepeal/DDS/Attached Attach file.
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/10/09 23:34
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================
Drivers
——————-
Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xF7D54000 Size: 98304 File Visible: No Signed: -
Status: -
Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8A56000 Size: 8192 File Visible: No Signed: -
Status: -
Name: rootrepeal[1].sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal[1].sys
Address: 0xF6BFC000 Size: 49152 File Visible: No Signed: -
Status: -
==EOF==
—–
DDS (Ver_09-06-26.01) - NTFSx86 NETWORK
Run by [removed] at 23:29:59.37 on Fri 10/09/2009
Internet Explorer: 6.0.2900.2180
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.511.283 [GMT -7:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
svchost.exe C:\WINDOWS\TEMP\VRT1.tmp
C:\WINDOWS\System32\reader_s.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Christopher Ow\Local Settings\Temporary Internet Files\Content.IE5\HQB15M06\dds[1].scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com.sg/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101761&gct=&gc=1&q=%s
mSearchAssistant = hxxp://www.crawler.com/search/ie.aspx?tb_id=60347
mCustomizeSearch = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60347
uURLSearchHooks: N/A: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\toolbar\ctbr.dll
mURLSearchHooks: H - No File
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\digital imaging\smart web printing\hpswp_printenhancer.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\toolbar\ctbr.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\toolbar\ctbr.dll
TB: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [SpywareTerminatorUpdate] "c:\program files\spyware terminator\SpywareTerminatorUpdate.exe"
uRun: [restorer64_a] c:\documents and settings\christopher ow\restorer64_a.exe
uRun: [mserv] c:\documents and settings\christopher ow\application data\seres.exe
uRun: [svchost] c:\documents and settings\christopher ow\application data\svcst.exe
mRun: [SpywareTerminator] "c:\program files\spyware terminator\SpywareTerminatorShield.exe"
mRun: [Regedit32] c:\windows\system32\regedit.exe
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [restorer64_a] c:\windows\system32\restorer64_a.exe
mRun: [reader_s] c:\windows\system32\reader_s.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [ter8m] RUNDLL32.EXE c:\windows\system32\msxm192z.dll,w
dRun: [restorer32_a] .\9.tmp
dRun: [servises] c:\windows\system32\servises.exe
dRun: [reader_s] c:\documents and settings\christopher ow\reader_s.exe
mExplorerRun: [exec] c:\windows\fonts\services.exe
dExplorerRun: [servises] c:\windows\system32\servises.exe
StartupFolder: c:\docume~1\christ~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: Save YouTube Video as MP3 - c:\program files\common files\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dll
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {31435657-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/e/2/f/e2fcec4b-6c8b-48b7-adab-ab9c403a978f/wvc1dmo.cab
DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} - hxxp://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1234251265663
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://www.sibelius.com/download/software/win/ActiveXPlugin.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\toolbar\ctbr.dll
Notify: Sebring - c:\windows\system32\LgNotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
============= SERVICES / DRIVERS ===============
R3 WBSD;Winbond Secure Digital Storage (SD/MMC) Device Driver;c:\windows\system32\drivers\wbsd.sys [2009-2-10 26240]
S1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2009-7-30 142592]
S1 synsend;synsend;\??\c:\windows\system32\drivers\synsenddrv.sys –> c:\windows\system32\drivers\synsenddrv.sys [?]
S2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-2-20 55152]
S2 geijgzabni;geijgzabni;c:\windows\system32\drivers\scuffhmxbzvssnz.sys [2009-10-8 80000]
S2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
S3 fsssvc;Windows Live Family Safety;c:\program files\windows live\family safety\fsssvc.exe [2009-2-6 533360]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-3-27 33176]
S3 NtApm;NT Apm/Legacy Interface Driver;c:\windows\system32\drivers\ntapm.sys [2001-8-17 9344]
S3 tcpsr;tcpsr;c:\windows\system32\drivers\tcpsr.sys [2009-10-9 6016]
S3 XDva273;XDva273;\??\c:\windows\system32\xdva273.sys –> c:\windows\system32\XDva273.sys [?]
=============== Created Last 30 ================
2009-10-09 23:17 92 a——- c:\windows\system32\8.tmp
2009-10-09 23:17 6,016 a——- c:\windows\system32\drivers\tcpsr.sys
2009-10-09 23:12 92 a——- c:\windows\system32\7.tmp
2009-10-09 23:08 61,440 a——- c:\windows\system32\msxm192z.dll
2009-10-09 23:08 62,496 a——- c:\windows\system32\MSWINSCK.OCX
2009-10-09 23:08 258,048 a——- C:\5297444.exe
2009-10-09 23:07 804 a——- C:\7505915.exe
2009-10-09 23:07 92 a——- c:\windows\system32\5.tmp
2009-10-09 00:39 26,935 a——- c:\windows\system32\9.tmp
2009-10-09 00:39 38,912 a——- c:\documents and settings\christopher ow\reader_s.exe
2009-10-09 00:39 136 a——- c:\windows\system32\4.tmp
2009-10-09 00:31 26,935 a——- c:\windows\system32\6.tmp
2009-10-09 00:31 56,320 a——- c:\windows\system32\reader_s.exe
2009-10-09 00:31 136 a——- c:\windows\system32\3.tmp
2009-10-09 00:27 0 a——- c:\windows\system32\drivers\str.sys
2009-10-08 23:32 37,888 a——- c:\docume~1\christ~1\applic~1\svcst.exe
2009-10-08 23:32 37,888 a——- c:\docume~1\christ~1\applic~1\seres.exe
2009-10-08 23:32 68,096 a——- c:\windows\system32\restorer64_a.exe
2009-10-08 23:32 68,096 a——- c:\documents and settings\christopher ow\restorer64_a.exe
2009-10-08 23:32 44,087 a——- c:\windows\system32\restorer32_a.exe
2009-10-08 23:32 26,935 a——- c:\documents and settings\christopher ow\restorer32_a.exe
2009-10-08 23:31 136 a——- c:\windows\system32\2.tmp
2009-10-08 23:06 –d—– c:\docume~1\christ~1\applic~1\Malwarebytes
2009-10-08 23:06 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-08 23:06 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-10-08 23:06 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-10-08 23:06 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-10-08 18:43 19,147 a——- c:\windows\system32\wurocok.exe
2009-10-08 18:43 18,603 a——- c:\windows\system32\dykobowu.dll
2009-10-08 18:43 18,405 a——- c:\docume~1\alluse~1\applic~1\mewe.bat
2009-10-08 18:43 18,325 a——- c:\windows\kofirap._dl
2009-10-08 18:43 17,886 a——- c:\docume~1\alluse~1\applic~1\oqibow.bin
2009-10-08 18:43 17,306 a——- c:\windows\alorataly.lib
2009-10-08 18:43 16,226 a——- c:\windows\system32\ujetyjud.dll
2009-10-08 18:43 15,598 a——- c:\program files\common files\hyzybutas.scr
2009-10-08 18:43 14,116 a——- c:\windows\vivaca.bin
2009-10-08 18:43 13,805 a——- c:\windows\system32\opiresakeb._sy
2009-10-08 18:43 13,385 a——- c:\docume~1\christ~1\applic~1\iwesipi.dll
2009-10-08 18:43 12,641 a——- c:\docume~1\alluse~1\applic~1\ryqeser.vbs
2009-10-08 18:43 13,027 a——- c:\windows\system32\venesuc.reg
2009-10-08 18:42 –d—– c:\windows\LastGood.Tmp
2009-10-08 18:39 80,000 a——- c:\windows\system32\drivers\scuffhmxbzvssnz.sys
2009-10-08 18:32 80,000 a——- c:\windows\system32\drivers\dahbjhotgjhm.sys
2009-10-08 18:32 0 a——- c:\windows\system32\10.tmp
2009-10-07 20:13 –d—– c:\program files\AhnLab
2009-10-07 19:50 740 a——- C:\717724.exe
2009-10-07 19:50 57,344 a——- c:\windows\system32\44.tmp
2009-10-07 19:50 60,416 a——- c:\windows\system32\43.tmp
2009-10-07 19:50 42,496 a——- c:\windows\system32\41.tmp
2009-10-07 19:50 264 a——- c:\windows\system32\38.tmp
2009-10-07 19:45 25,600 a——- c:\windows\system32\sfsp.cfo
2009-10-07 19:45 57,344 a——- c:\windows\system32\1A.tmp
2009-10-07 19:44 60,416 a——- c:\windows\system32\16.tmp
2009-10-07 19:44 42,496 a——- c:\windows\system32\11.tmp
2009-10-07 19:16 –d—– c:\program files\WIZET
2009-10-07 18:32 740 a——- C:\9893457.exe
2009-10-07 09:32 –d—– c:\windows\system32\SoftwareDistribution
2009-10-07 09:32 18,944 a——- c:\windows\system32\83.tmp
2009-10-07 09:31 136 a——- c:\windows\system32\7D.tmp
2009-10-07 00:45 18,944 a——- c:\windows\system32\A1.tmp
2009-10-07 00:45 136 a——- c:\windows\system32\9E.tmp
2009-10-06 23:42 182,912 ac—— c:\windows\system32\dllcache\ndis.sys
2009-10-06 23:37 94,432 ac—— c:\windows\system32\dllcache\agp440.sys
2009-10-06 23:37 0 a——- c:\windows\system32\55.tmp
2009-10-06 23:37 18,944 a——- c:\windows\system32\54.tmp
2009-10-06 23:37 136 a——- c:\windows\system32\51.tmp
2009-10-06 23:37 740 a——- C:\8998835.exe
2009-10-06 23:36 360,320 a——- c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2009-10-06 23:28 2,297,552 a——- c:\windows\system32\d3dx9_26.dll
2009-10-06 23:20 –d—– c:\docume~1\christ~1\applic~1\GetRightToGo
2009-09-16 11:46 202 a——- c:\windows\system32\BIN_STRSBW.SPT
2009-09-10 22:38 153,088 -c—— c:\windows\system32\dllcache\triedit.dll
==================== Find3M ====================
2009-10-09 23:18 94,432 a——- c:\windows\system32\drivers\agp440.sys
2009-10-09 23:08 1,032 —-h— c:\windows\fonts\mlog
2009-10-06 23:42 182,912 a——- c:\windows\system32\drivers\ndis.sys
2009-09-10 22:42 43,856 a——- c:\docume~1\christ~1\applic~1\GDIPFONTCACHEV1.DAT
2009-08-06 19:23 274,288 a——- c:\windows\system32\mucltui.dll
2009-08-06 19:23 215,920 a——- c:\windows\system32\muweb.dll
2009-08-05 02:11 204,800 a——- c:\windows\system32\mswebdvd.dll
2009-07-24 18:30 1,409 a——- c:\windows\fonts\RPRSSPEC.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\RPRSSCRP.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\RPRSCHOR.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\RPRS____.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\OPUSPC__.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\OPUSFS__.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\OPUSCSC_.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\OPUSCS__.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\OPUSC___.FOT
2009-07-24 18:30 1,409 a——- c:\windows\fonts\INK2CHOR.FOT
2009-07-17 11:55 58,880 a——- c:\windows\system32\atl.dll
============= FINISH: 23:30:33.21 ===============
—