This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] infected with trojan-downloader.js.Multi.ca and a bunch of ot

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi! I'm freaking out. I'm getting Security Center Alert pop-up every minute telling me that I'm infected with trojan-downloader.js.Multi.ca; backdoor.win32.kbot.al; trojan.win32.ageat.dcc; Net-Worm.Win32.Mytob.t and a bunch of lovely things that I didn't bother recording the names of. Besides these pop-ups my computer isn't acting peculiar in anyway thus far, except for maybe being a bit slow. Below are the reports for my computer. Thanks for helping!!! I'm so frustrated right now… DDS Log: DDS (Ver_09-11-29.01) - NTFSx86 Run by [removed] at 22:32:18.98 on Mon 11/30/2009 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2037.508 [GMT -5:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Fingerprint Reader Suite\upeksvr.exe C:\Windows\System32\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\System32\bcmwltry.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\McAfee\MSK\MskSrver.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\System32\rpcnet.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\OEM02Mon.exe C:\Windows\System32\igfxpers.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Windows\system32\wbem\unsecapp.exe C:\Users\shalalalala\Program Files\DNA\btdna.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Stickies\stickies.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Fingerprint Reader Suite\psqltray.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Windows\system32\taskeng.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe C:\Windows\system32\wuauclt.exe C:\Users\SHALAL~1\AppData\Local\Temp\Low\wscsvc32.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Program Files\Maxtor\Sync\MaxSync.exe C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe C:\Program Files\Maxtor\ManagerApp\MaxUtilities.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\shalalalala\Desktop\dds.scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uWindow Title = Internet Explorer provided by Dell uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6080828 uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [BitTorrent DNA] "c:\users\shalalalala\program files\dna\btdna.exe" uRun: [Google Update] "c:\users\shalalalala\appdata\local\google\update\GoogleUpdate.exe" /c uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe" mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" StartupFolder: c:\users\shalal~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\stickies.lnk - c:\program files\stickies\stickies.exe mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: DisableCAD = 1 (0x1) IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL Trusted Zone: internet Trusted Zone: mcafee.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll Notify: psfus - c:\windows\system32\psqlpwd.dll LSA: Notification Packages = scecli psqlpwd ================= FIREFOX =================== FF - ProfilePath - c:\users\shalal~1\appdata\roaming\mozilla\firefox\profiles\bflkzgfi.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig FF - plugin: c:\program files\google\picasa3\npPicasa3.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\users\shalalalala\appdata\local\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\users\shalalalala\appdata\roaming\move networks\plugins\npqmp071503000010.dll FF - plugin: c:\users\shalalalala\appdata\roaming\mozilla\plugins\npgoogletalk.dll FF - plugin: c:\users\shalalalala\program files\dna\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ ============= SERVICES / DRIVERS =============== =============== Created Last 30 ================ 2009-11-25 08:03:23 2048 —-a-w- c:\windows\system32\tzres.dll 2009-11-25 02:58:26 1399296 —-a-w- c:\windows\system32\msxml6.dll 2009-11-25 02:58:26 1257472 —-a-w- c:\windows\system32\msxml3.dll 2009-11-25 02:58:22 714240 —-a-w- c:\windows\system32\timedate.cpl 2009-11-18 01:52:21 0 d—–w- c:\programdata\Real 2009-11-11 03:41:08 351232 —-a-w- c:\windows\system32\WSDApi.dll 2009-11-11 03:35:39 2035712 —-a-w- c:\windows\system32\win32k.sys 2009-11-09 08:01:25 0 d—–w- c:\program files\MSXML 4.0 2009-11-08 07:47:54 0 d—–w- c:\programdata\Maxtor 2009-11-08 07:47:54 0 d—–w- c:\program files\Maxtor 2009-11-08 07:46:22 0 d—–w- c:\windows\Downloaded Installations ==================== Find3M ==================== 2009-11-30 22:24:10 17408 —-a-w- c:\windows\system32\rpcnetp.exe 2009-11-29 06:43:56 56680 —-a-w- c:\windows\system32\rpcnet.dll 2009-11-29 06:43:56 17408 —-a-w- c:\windows\system32\rpcnetp.dll 2009-11-08 07:49:14 51200 —-a-w- c:\windows\inf\infpub.dat 2009-11-08 07:49:14 143360 —-a-w- c:\windows\inf\infstrng.dat 2009-11-08 07:49:12 86016 —-a-w- c:\windows\inf\infstor.dat 2009-11-03 01:42:06 195456 ——w- c:\windows\system32\MpSigStub.exe 2009-09-10 17:30:12 213504 —-a-w- c:\windows\system32\msv1_0.dll 2009-09-10 15:21:53 8147456 —-a-w- c:\windows\system32\wmploc.DLL 2009-09-10 15:21:07 310784 —-a-w- c:\windows\system32\unregmp2.exe 2009-09-10 04:10:10 48 —ha-w- c:\programdata\ezsidmv.dat 2009-09-09 23:34:08 49152 —-a-w- c:\windows\system32\instw32.exe 2009-09-04 12:24:34 61440 —-a-w- c:\windows\system32\msasn1.dll 2008-08-28 13:28:29 665600 —-a-w- c:\windows\inf\drvindex.dat 2008-01-21 02:43:21 174 –sha-w- c:\program files\desktop.ini 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 12:42:02 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 12:42:02 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 09:20:21 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 09:20:19 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-05-24 22:40:49 16384 –sha-w- c:\windows\temp\cookies\index.dat 2009-05-24 22:40:49 16384 –sha-w- c:\windows\temp\history\history.ie5\index.dat 2009-05-24 22:40:49 32768 –sha-w- c:\windows\temp\temporary internet files\content.ie5\index.dat 2008-08-28 13:25:08 8192 –sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 22:36:00.25 =============== RootRepeal Log: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/11/30 22:43 Program Version: Version 1.3.5.0 Windows Version: Windows Vista SP1 ================================================== Drivers ——————- Name: dump_iaStor.sys Image Path: C:\Windows\System32\Drivers\dump_iaStor.sys Address: 0x8B409000 Size: 778240 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\Windows\system32\drivers\rootrepeal.sys Address: 0xCB62E000 Size: 49152 File Visible: No Signed: - Status: - Processes ——————- Path: System PID: 4 Status: Locked to the Windows API! Path: C:\Windows\System32\audiodg.exe PID: 1236 Status: Locked to the Windows API! ==EOF==

Attachments:

Hi gah,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI