This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Generic21.BPDJ and disappearing drives.

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm starting to get a bit worried about this. AVG has, on a few occasions, detected about 6-8 cases of this trojan. When I ask AVG to remove the infections, it can only remove the first instance. The trojan appears to be living in hidden folders to do with system restore points, not sure if that's relevant. Anyway, for some reason my E drive has disappeared from explorer, too. I can't access it at the moment. Here's the DDS log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 14:37:00.60 on Fri 04/08/2011 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2427 [GMT 9.5:30] ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\GIGABYTE\ET6\GUI.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\MediaMonkey\MediaMonkey.exe C:\Program Files\TechSmith\Snagit 9\SnagIt32.exe C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\AVG\AVG9\avgui.exe D:\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll mWinlogon: SfcDisable=-99 (0xffffff9d) BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [EasyTuneVI] c:\program files\gigabyte\et6\ETcall.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [GBTUpd] c:\program files\gigabyte\gbtupd\PreRun.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snagit~1.lnk - c:\program files\techsmith\snagit 9\Snagit32.exe uPolicies-explorer: NoSMMyDocs = 1 (0x1) uPolicies-explorer: NoSMMyPictures = 1 (0x1) uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1) mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) dPolicies-explorer: NoSMMyDocs = 1 (0x1) dPolicies-explorer: NoSMMyPictures = 1 (0x1) dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\bzti02sn.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.bom.gov.au/sa/forecasts/adelaide.shtml FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\microsoft silverlight\2.0.31005.0\npctrlui.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2011-4-4 216400] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2011-4-4 29584] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 243024] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2011-4-4 921952] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2011-4-4 308136] R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2011-4-1 68136] R3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2011-4-1 24944] S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-1 93184] =============== Created Last 30 ================ 2011-04-08 02:42 –d—– c:\docume~1\owner\applic~1\Malwarebytes 2011-04-08 02:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-08 02:42 20,952 a——- c:\windows\system32\drivers\mbam.sys 2011-04-08 02:42 –d—– c:\program files\Malwarebytes' Anti-Malware 2011-04-08 02:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2011-04-07 00:27 –d—– c:\program files\common files\Wise Installation Wizard 2011-04-06 23:01 376 a——- c:\windows\ODBC.INI 2011-04-06 23:01 –d—– c:\program files\Microsoft ActiveSync 2011-04-06 23:00 –d—– c:\windows\ShellNew 2011-04-06 21:31 –d—– c:\program files\ImageShack Uploader 2011-04-04 22:00 –d-h— c:\docume~1\alluse~1\applic~1\Common Files 2011-04-04 16:22 –d—– c:\docume~1\owner\applic~1\avidemux 2011-04-04 16:22 –d—– c:\program files\Avidemux 2.5 2011-04-04 15:40 12,536 a——- c:\windows\system32\avgrsstx.dll 2011-04-04 15:33 243,024 a——- c:\windows\system32\drivers\avgtdix.sys 2011-04-04 15:33 216,400 a——- c:\windows\system32\drivers\avgldx86.sys 2011-04-04 15:33 –d—– c:\windows\system32\drivers\Avg 2011-04-04 15:33 –d—– c:\program files\AVG 2011-04-04 15:33 –d—– c:\docume~1\alluse~1\applic~1\avg9 2011-04-04 15:28 –d—– c:\docume~1\alluse~1\applic~1\MFAData 2011-04-02 05:03 69 a——- c:\windows\NeroDigital.ini 2011-04-02 04:17 –d—– c:\program files\ExtractNow 2011-04-02 04:03 –d—– c:\program files\uTorrent 2011-04-02 04:03 –d—– c:\docume~1\owner\applic~1\uTorrent 2011-04-02 04:00 125,184 ——– c:\windows\system32\drivers\imagesrv.sys 2011-04-02 04:00 5,504 ——– c:\windows\system32\drivers\imagedrv.sys 2011-04-02 04:00 155,648 a——- c:\windows\system32\NeroCheck.exe 2011-04-02 04:00 106,496 a——- c:\windows\system32\TwnLib20.dll 2011-04-02 04:00 1,568,768 ——– c:\windows\system32\ImagX7.dll 2011-04-02 04:00 476,320 ——– c:\windows\system32\ImagXpr7.dll 2011-04-02 04:00 471,040 ——– c:\windows\system32\ImagXRA7.dll 2011-04-02 04:00 262,144 ——– c:\windows\system32\ImagXR7.dll 2011-04-02 01:57 –d—– c:\docume~1\alluse~1\applic~1\MediaMonkey 2011-04-02 01:30 –d—– c:\program files\MediaMonkey 2011-04-01 16:09 –d—– c:\program files\K-Lite Codec Pack 2011-04-01 15:23 4,444 a——- c:\windows\system32\pid.PNF 2011-04-01 14:54 3,072 a——- c:\windows\system32\drivers\audstub.sys 2011-04-01 14:53 21,504 a——- c:\windows\system32\hidserv.dll 2011-04-01 14:53 57,600 a——- c:\windows\system32\drivers\redbook.sys 2011-04-01 14:52 6,400 a——- c:\windows\system32\drivers\enum1394.sys 2011-04-01 14:51 –d—– c:\program files\common files\ODBC 2011-04-01 14:50 24,064 a——- c:\windows\system\OLESVR.DLL 2011-04-01 14:50 –d–r– c:\documents and settings\all users\Documents 2011-04-01 14:49 1,088,840 a—-r– c:\windows\SET4.tmp 2011-04-01 14:49 1,296,669 a—-r– c:\windows\SET3.tmp 2011-04-01 14:48 –d—– c:\windows\system32\CatRoot2 2011-04-01 14:48 –d—– c:\windows\system32\CatRoot 2011-04-01 14:48 –d—– C:\Documents and Settings 2011-04-01 14:47 869 a——- c:\windows\system32\$winnt$.inf 2011-04-01 06:23 –d—– c:\program files\Ulead Systems 2011-04-01 06:17 –d—– c:\program files\AMD 2011-04-01 06:17 –d—– c:\program files\Browser Configuration Utility 2011-04-01 06:16 –d—– c:\program files\Gigabyte 2011-04-01 06:13 –d—– c:\program files\common files\Logitech 2011-04-01 06:10 –d—– c:\program files\ANI 2011-04-01 06:10 –d—– c:\program files\D-Link 2011-04-01 06:08 –d—– c:\program files\common files\ATI Technologies 2011-04-01 06:05 –d—– c:\program files\ATI Technologies 2011-04-01 05:58 –dsh— c:\documents and settings\all users\DRM 2011-04-01 05:58 –d-h— c:\program files\WindowsUpdate 2011-04-01 05:58 –d—– c:\program files\Windows Media Connect 2 2011-04-01 05:57 –d—– c:\program files\common files\MSSoap 2011-04-01 05:27 –d—– c:\program files\VideoLAN 2011-04-01 05:18 –d—– c:\program files\Realtek ==================== Find3M ==================== 2011-04-05 08:14 24,944 a——- c:\windows\system32\drivers\GVTDrv.sys 2011-04-05 08:14 16,608 a——- c:\windows\gdrv.sys 2011-04-02 13:23 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2011-04-01 05:57 21,640 a——- c:\windows\system32\emptyregdb.dat ============= FINISH: 14:37:12.73 =============== I've attached the second file as requested by DDS (it's in text format, for some reason the forum wouldn't let me upload the RAR. Any help would be massively appreciated! I don't want to lose a drive full of… stuff.

Attachments:

Hello and welcome to What The Tech.

I am currently assessing your situation and will be back with a fix for your problem as soon as possible.

Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this, click Options, then click Track this topic. Please select Immediate Email Notification for the topic subscription, then click Proceed.

Please be patient with me during this time.

Meanwhile, please make a reply to this topic to acknowledge that you have read this and is still with me to tackle the problem until the end. If I do not get any response within 3 days, this topic will be closed.
Okay, got it! Thanks for helping out. :) I should add one thing: turns out the disappearing E drive may have been an unrelated problem. When I restarted my PC, Windows checked the file system, fixed a couple of things and I've had no problems since then. So it's just the Trojan that's still giving me sass.
Hello atomicblue :),

Welcome to What The Tech. I am Jack&Jill, and I will be helping you out.

Before we go further, there are a few things that I would like to make clear so that we are share the same understanding.
  • Please observe and follow these Terms of Use and the rules in Are you Infected? Getting Started: How To Get Help.
  • Any advice is for your computer only and is taken at your own risk. Fixes sometimes will cause unexpected results, but I will do my best to assist you.
  • Please read the instructions carefully and follow them closely, in the order they are presented to you.
  • If you have any doubts or problems during the fix, please stop and ask.
  • All the tools that I will ask you to download and use are safe. Please allow if prompted by any of your security softwares.
  • Do not use or run any malware cleaning tools without supervision as they may cause more harm if improperly used.
  • Refrain from installing any new programs except those that I request during the fix to prevent interference to my diagnosis of the problem.
  • Lack of malware symptoms does not mean your computer is clean. Stick to this topic until I give the All Clear.
  • If you do not reply within 3 days, this topic will be closed.
If you are agreeable to the above, then everything should go smoothly :) . We may begin.

——————–

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent

  • Our policy as pointed out in the Terms of Use:

    We will not support or allow the discussion of any peer to peer (P2P) applications, except for their removal.

  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.
Please run DDS again and back both the logs.

——————–

Is this a business computer? What do you use the computer for?

——————–

Check for additional security risks
  • Please download CKScanner© by askey127 and save to your desktop. Click here.
  • Double click on CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File. You will be prompted, click OK.
  • Post the contents of ckfiles.txt in your reply, it is located on your desktop.
——————–

Please post back:
1. fresh DDS logs
2. the answers to my questions about your computer
3. CKScanner log
Hello atomicblue :), I usually close the topic after 3 days without any reply, and it has already been 2 days since my last post. Do you still need help? Any problems following my instructions? Need more time? If I do not get any response within the next 24 hours, this topic will be closed.
Hey again! Sorry it's taking so long, I've had a lot of work over the last few days. I might need an extra day to do all this stuff, but I should have it all done within about 36 hours from now.
Okay, so I've run into a bit of a hitch. uTorrent is not uninstalling. When I went into Add/Remove programs, there were two uTorrent entries listed for some reason. One uninstalled. The other would let me go through the uninstall prompts but it would not disappear from the list of installed programs. Any tips?
Okay, here we go. The new DDS log: DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 5:28:06.26 on Thu 04/21/2011 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2266 [GMT 9.5:30] ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\GIGABYTE\ET6\GUI.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TechSmith\Snagit 9\Snagit32.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\MediaMonkey\MediaMonkey.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll mWinlogon: SfcDisable=-99 (0xffffff9d) BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [EasyTuneVI] c:\program files\gigabyte\et6\ETcall.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [GBTUpd] c:\program files\gigabyte\gbtupd\PreRun.exe mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snagit~1.lnk - c:\program files\techsmith\snagit 9\Snagit32.exe uPolicies-explorer: NoSMMyDocs = 1 (0x1) uPolicies-explorer: NoSMMyPictures = 1 (0x1) uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1) mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1) dPolicies-explorer: NoSMMyDocs = 1 (0x1) dPolicies-explorer: NoSMMyPictures = 1 (0x1) dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\bzti02sn.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.bom.gov.au/sa/forecasts/adelaide.shtml FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll FF - plugin: c:\program files\microsoft silverlight\2.0.31005.0\npctrlui.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2011-4-4 216400] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2011-4-4 29584] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 243024] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2011-4-4 921952] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2011-4-4 308136] R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2011-4-1 68136] R3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2011-4-1 24944] S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-1 93184] S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-4-21 27064] =============== Created Last 30 ================ 2011-04-21 05:21 27,064 a——- c:\windows\system32\drivers\revoflt.sys 2011-04-21 05:21 –d—– c:\program files\VS Revo Group 2011-04-18 15:51 –d—– c:\documents and settings\owner\dwhelper 2011-04-11 03:49 –d—– c:\documents and settings\owner\Tracing 2011-04-11 03:41 –d—– c:\windows\system32\DirectX 2011-04-11 03:40 –d—– c:\program files\Microsoft SQL Server Compact Edition 2011-04-11 03:37 –d—– c:\program files\Microsoft 2011-04-11 03:36 –d—– c:\program files\Windows Live SkyDrive 2011-04-11 03:25 –d—– c:\program files\common files\Windows Live 2011-04-08 02:42 –d—– c:\docume~1\owner\applic~1\Malwarebytes 2011-04-08 02:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2011-04-08 02:42 20,952 a——- c:\windows\system32\drivers\mbam.sys 2011-04-08 02:42 –d—– c:\program files\Malwarebytes' Anti-Malware 2011-04-08 02:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2011-04-07 00:27 –d—– c:\program files\common files\Wise Installation Wizard 2011-04-06 23:01 376 a——- c:\windows\ODBC.INI 2011-04-06 23:01 –d—– c:\program files\Microsoft ActiveSync 2011-04-06 23:00 –d—– c:\windows\ShellNew 2011-04-06 21:31 –d—– c:\program files\ImageShack Uploader 2011-04-04 22:00 –d-h— c:\docume~1\alluse~1\applic~1\Common Files 2011-04-04 16:22 –d—– c:\docume~1\owner\applic~1\avidemux 2011-04-04 16:22 –d—– c:\program files\Avidemux 2.5 2011-04-04 15:40 12,536 a——- c:\windows\system32\avgrsstx.dll 2011-04-04 15:33 243,024 a——- c:\windows\system32\drivers\avgtdix.sys 2011-04-04 15:33 216,400 a——- c:\windows\system32\drivers\avgldx86.sys 2011-04-04 15:33 –d—– c:\windows\system32\drivers\Avg 2011-04-04 15:33 –d—– c:\program files\AVG 2011-04-04 15:33 –d—– c:\docume~1\alluse~1\applic~1\avg9 2011-04-04 15:28 –d—– c:\docume~1\alluse~1\applic~1\MFAData 2011-04-02 05:03 69 a——- c:\windows\NeroDigital.ini 2011-04-02 04:17 –d—– c:\program files\ExtractNow 2011-04-02 04:03 –d—– c:\docume~1\owner\applic~1\uTorrent 2011-04-02 04:00 125,184 ——– c:\windows\system32\drivers\imagesrv.sys 2011-04-02 04:00 5,504 ——– c:\windows\system32\drivers\imagedrv.sys 2011-04-02 04:00 155,648 a——- c:\windows\system32\NeroCheck.exe 2011-04-02 04:00 106,496 a——- c:\windows\system32\TwnLib20.dll 2011-04-02 04:00 1,568,768 ——– c:\windows\system32\ImagX7.dll 2011-04-02 04:00 476,320 ——– c:\windows\system32\ImagXpr7.dll 2011-04-02 04:00 471,040 ——– c:\windows\system32\ImagXRA7.dll 2011-04-02 04:00 262,144 ——– c:\windows\system32\ImagXR7.dll 2011-04-02 01:57 –d—– c:\docume~1\alluse~1\applic~1\MediaMonkey 2011-04-02 01:30 –d—– c:\program files\MediaMonkey 2011-04-01 16:09 –d—– c:\program files\K-Lite Codec Pack 2011-04-01 15:23 4,444 a——- c:\windows\system32\pid.PNF 2011-04-01 14:54 3,072 a——- c:\windows\system32\drivers\audstub.sys 2011-04-01 14:53 21,504 a——- c:\windows\system32\hidserv.dll 2011-04-01 14:53 57,600 a——- c:\windows\system32\drivers\redbook.sys 2011-04-01 14:52 6,400 a——- c:\windows\system32\drivers\enum1394.sys 2011-04-01 14:51 –d—– c:\program files\common files\ODBC 2011-04-01 14:50 24,064 a——- c:\windows\system\OLESVR.DLL 2011-04-01 14:50 –d–r– c:\documents and settings\all users\Documents 2011-04-01 14:49 1,088,840 a—-r– c:\windows\SET4.tmp 2011-04-01 14:49 1,296,669 a—-r– c:\windows\SET3.tmp 2011-04-01 14:48 –d—– c:\windows\system32\CatRoot2 2011-04-01 14:48 –d—– c:\windows\system32\CatRoot 2011-04-01 14:48 –d—– C:\Documents and Settings 2011-04-01 14:47 869 a——- c:\windows\system32\$winnt$.inf 2011-04-01 06:23 –d—– c:\program files\Ulead Systems 2011-04-01 06:17 –d—– c:\program files\AMD 2011-04-01 06:17 –d—– c:\program files\Browser Configuration Utility 2011-04-01 06:16 –d—– c:\program files\Gigabyte 2011-04-01 06:13 –d—– c:\program files\common files\Logitech 2011-04-01 06:10 –d—– c:\program files\ANI 2011-04-01 06:10 –d—– c:\program files\D-Link 2011-04-01 06:08 –d—– c:\program files\common files\ATI Technologies 2011-04-01 06:05 –d—– c:\program files\ATI Technologies 2011-04-01 05:58 –dsh— c:\documents and settings\all users\DRM 2011-04-01 05:58 –d-h— c:\program files\WindowsUpdate 2011-04-01 05:58 –d—– c:\program files\Windows Media Connect 2 2011-04-01 05:57 –d—– c:\program files\common files\MSSoap 2011-04-01 05:27 –d—– c:\program files\VideoLAN 2011-04-01 05:18 –d—– c:\program files\Realtek ==================== Find3M ==================== 2011-04-17 01:25 24,944 a——- c:\windows\system32\drivers\GVTDrv.sys 2011-04-17 01:24 16,608 a——- c:\windows\gdrv.sys 2011-04-02 13:23 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat 2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf 2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf 2011-04-01 05:57 21,640 a——- c:\windows\system32\emptyregdb.dat ============= FINISH: 5:28:12.96 =============== UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-06-26.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/8/2005 12:54:05 AM System Uptime: 4/17/2011 1:42:01 AM (100 hours ago) Motherboard: Gigabyte Technology Co., Ltd. | | GA-MA770T-UD3P Processor: AMD Phenom™ II X4 810 Processor | Socket M2 | 2611/200mhz ==== Disk Partitions ========================= A: is Removable C: is FIXED (NTFS) - 75 GiB total, 67.849 GiB free. D: is FIXED (NTFS) - 75 GiB total, 44.137 GiB free. E: is FIXED (NTFS) - 932 GiB total, 465.595 GiB free. F: is FIXED (NTFS) - 932 GiB total, 620.428 GiB free. G: is Removable H: is Removable I: is Removable J: is Removable K: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP20: 4/4/2011 3:33:00 PM - Installed AVG Free 9.0 RP21: 4/4/2011 3:33:57 PM - Avg8 Update RP22: 4/4/2011 3:40:53 PM - Avg Update RP23: 4/4/2011 9:50:33 PM - Removed Logitech Desktop Messenger RP24: 4/4/2011 9:58:33 PM - Avg Update RP25: 4/4/2011 9:59:48 PM - Avg Update RP26: 4/5/2011 10:56:13 PM - System Checkpoint RP27: 4/6/2011 9:31:56 PM - Installed ImageShack Uploader 2.2.0 RP28: 4/6/2011 10:53:10 PM - Installed Adobe Reader 9. RP29: 4/6/2011 11:00:45 PM - Installed Microsoft Office XP Professional with FrontPage RP30: 4/7/2011 12:29:21 AM - Installed Snagit 9.1 RP31: 4/8/2011 3:25:39 AM - System Checkpoint RP32: 4/9/2011 4:06:39 AM - System Checkpoint RP33: 4/10/2011 4:11:09 AM - System Checkpoint RP34: 4/11/2011 3:41:22 AM - Installed DirectX RP35: 4/12/2011 4:22:57 AM - System Checkpoint RP36: 4/13/2011 4:28:50 AM - System Checkpoint RP37: 4/14/2011 6:19:43 AM - System Checkpoint RP38: 4/15/2011 6:50:15 AM - System Checkpoint RP39: 4/16/2011 7:05:54 AM - System Checkpoint RP40: 4/17/2011 7:29:27 AM - System Checkpoint RP41: 4/18/2011 7:35:20 AM - System Checkpoint RP42: 4/19/2011 8:46:11 AM - System Checkpoint RP43: 4/20/2011 9:47:06 AM - System Checkpoint ==== Installed Programs ====================== @BIOS Ver.2.05 µTorrent Acrobat.com Adobe AIR Adobe Flash Player 10 Plugin Adobe Reader 9 AMD Processor Driver ANIO Service ANIWZCS2 Service ATI - Software Uninstall Utility ATI AVIVO Codecs ATI Display Driver AVG Free 9.0 Avidemux 2.5 Browser Configuration Utility D-Link Wireless G DWA-510 DMIView B8.0717.01 Easy Tune 6 B09.0216.1 EasySaver B9.0205.1 ExtractNow Face_Wizard B08.0908.01 ImageShack Uploader 2.2.0 K-Lite Mega Codec Pack 5.5.1 Malwarebytes' Anti-Malware MediaMonkey 3.0 Microsoft .NET Framework 2.0 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Office XP Professional with FrontPage Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Mozilla Firefox 4.0 (x86 en-US) MSVCRT MSXML 4.0 SP2 (KB954430) Nero 6 Enterprise Edition REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Revo Uninstaller Pro 2.5.1 Segoe UI Snagit 9.1 Ulead GIF Animator 5 TBYB Update Manager B08.1027.1 VLC media player 0.9.4 WebFldrs XP Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Upload Tool Windows Rights Management Client Backwards Compatibility SP2 Windows Rights Management Client with Service Pack 2 WinRAR archiver ==== End Of File =========================== The CKFILES log: CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11 —– EOF —– As for the computer, I use it predominantly for Internet access and music. I'm an administrator of a forum so I spend a lot of time on that as well as a few other sites (Facebook, Tumblr, a handful of gaming sites like Eurogamer). In terms of music I have MediaMonkey. I also use it for study, so I've got Office installed. Finally, I use(d) uTorrent from time to time. I should also let you know that the trojan seems to have disappeared since I last posted. I know that doesn't mean it's gone, but AVG has stopped giving me alerts about it in the last few days.

Attachments:

Hello atomicblue :),

Did you uninstall µTorrent? Maybe you missed my post about it because I can still see it in the programs list.

——————–

Remove P2P software
  • IMPORTANT: I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent

  • Our policy as pointed out in the Terms of Use:

    We will not support or allow the discussion of any peer to peer (P2P) applications, except for their removal.

  • Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
  • Go to Control Panel > Add/Remove Programs and uninstall the P2P program(s) listed above (in red).
  • Please remove them before we continue with fixing your computer.
Please run DDS again and back Attach.txt by copy and pasting.

——————–

You have Malwarebytes' Anti-Malware (MBAM) on your machine. I wish to take a look at the most recent log file. Open MBAM and click on the Logs tab. Open the file at the bottom of the list and post the contents back here. If there is no log or you have yet to run MBAM, please let me know.

——————–

Please post back:
1. Attach.txt
2. previous MBAM result

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI