AeroMonk
Topic Starter
I tried to get rid of the infections, but I don't know if it's all gone. I booted into safemode and ran:
Norton Internet Security 2009
Ad-Aware
Spybot S&D
CCleaner
Here's some info:
Under System Configuration (msconfig), I noticed these strange Startup Items:
Startup Item:
PowerReg
Manufacturer:
Leader Technologies
Command:
rundll32.exe "C:\Users\Dan\AppData\Local\alerf32.dll",Startup
Location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Startup Item:
uishf9wuifwuh387fh3wufinhjfdwefe
Command:
C:\Users\Dan\AppData\Local\Temp\jxegb4cps.exe
Location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Startup Item:
asg984jgkfmgasiBug98jgkfgfb
Command:
C:\Users\Dan\AppData\Local\Temp\win32.exe
Location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Then in Registry Editor I found these also:
Same section–> HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
1) Value name: Dbixidarexow
Value data: rundll32.exe "C:\Users\Dan\AppData\Local\alerf32.dll",Startup
2) Value name: asg984jgkfmgasiBug98jgkfgfb
Value data: C:\Users\Dan\AppData\Local\Temp\win32.exe
3) Value name: uishf9wuifwuh387fh3wufinhjfdwefe
Value data: C:\Users\Dan\AppData\Local\Temp\jxegb4cps.exe
Ad-Aware found these 2 infections:
FamilyName–> Trojan.Win32.Sasfis.a (v)
Full Path–> C:\Windows\SysWOW64\xlyf.ppo
FamilyName–> VirTool.Win32.Obfuscator.hg!a (v)
Full Path–> C:\Windows\SysWow64\by7es.dll
Malwarebytes' Anti-Malware 1.44 found these:
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dbixidarexow (Trojan.Hiloti) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\AppCertDlls\appsecdll (Spyware.Passwords) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\winid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xlomemuguxavig (Trojan.Agent.U) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe rundll32.exe xlyf.ppo ebneby) Good: (Explorer.exe) -> Quarantined and deleted successfully.
Files Infected:
C:\Users\Dan\AppData\Local\alerf32.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Users\Dan\AppData\Local\elacafojufanero.dll (Trojan.Agent.U) -> Quarantined and deleted successfully.
C:\Windows\System32\mshlps.dll (Backdoor.Bot) -> Quarantined and deleted successfully.
So am I safe now, how can I make sure it's all gone?