atomicblue
Topic Starter
I'm starting to get a bit worried about this. AVG has, on a few occasions, detected about 6-8 cases of this trojan. When I ask AVG to remove the infections, it can only remove the first instance. The trojan appears to be living in hidden folders to do with system restore points, not sure if that's relevant.
Anyway, for some reason my E drive has disappeared from explorer, too. I can't access it at the moment.
Here's the DDS log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 14:37:00.60 on Fri 04/08/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2427 [GMT 9.5:30]
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\GIGABYTE\ET6\GUI.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\MediaMonkey\MediaMonkey.exe
C:\Program Files\TechSmith\Snagit 9\SnagIt32.exe
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\AVG\AVG9\avgui.exe
D:\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [EasyTuneVI] c:\program files\gigabyte\et6\ETcall.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [GBTUpd] c:\program files\gigabyte\gbtupd\PreRun.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snagit~1.lnk - c:\program files\techsmith\snagit 9\Snagit32.exe
uPolicies-explorer: NoSMMyDocs = 1 (0x1)
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoSMMyDocs = 1 (0x1)
dPolicies-explorer: NoSMMyPictures = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\bzti02sn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bom.gov.au/sa/forecasts/adelaide.shtml
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\microsoft silverlight\2.0.31005.0\npctrlui.dll
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2011-4-4 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2011-4-4 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 243024]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2011-4-4 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2011-4-4 308136]
R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2011-4-1 68136]
R3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2011-4-1 24944]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-1 93184]
=============== Created Last 30 ================
2011-04-08 02:42 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2011-04-08 02:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-08 02:42 20,952 a——- c:\windows\system32\drivers\mbam.sys
2011-04-08 02:42 –d—– c:\program files\Malwarebytes' Anti-Malware
2011-04-08 02:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-07 00:27 –d—– c:\program files\common files\Wise Installation Wizard
2011-04-06 23:01 376 a——- c:\windows\ODBC.INI
2011-04-06 23:01 –d—– c:\program files\Microsoft ActiveSync
2011-04-06 23:00 –d—– c:\windows\ShellNew
2011-04-06 21:31 –d—– c:\program files\ImageShack Uploader
2011-04-04 22:00 –d-h— c:\docume~1\alluse~1\applic~1\Common Files
2011-04-04 16:22 –d—– c:\docume~1\owner\applic~1\avidemux
2011-04-04 16:22 –d—– c:\program files\Avidemux 2.5
2011-04-04 15:40 12,536 a——- c:\windows\system32\avgrsstx.dll
2011-04-04 15:33 243,024 a——- c:\windows\system32\drivers\avgtdix.sys
2011-04-04 15:33 216,400 a——- c:\windows\system32\drivers\avgldx86.sys
2011-04-04 15:33 –d—– c:\windows\system32\drivers\Avg
2011-04-04 15:33 –d—– c:\program files\AVG
2011-04-04 15:33 –d—– c:\docume~1\alluse~1\applic~1\avg9
2011-04-04 15:28 –d—– c:\docume~1\alluse~1\applic~1\MFAData
2011-04-02 05:03 69 a——- c:\windows\NeroDigital.ini
2011-04-02 04:17 –d—– c:\program files\ExtractNow
2011-04-02 04:03 –d—– c:\program files\uTorrent
2011-04-02 04:03 –d—– c:\docume~1\owner\applic~1\uTorrent
2011-04-02 04:00 125,184 ——– c:\windows\system32\drivers\imagesrv.sys
2011-04-02 04:00 5,504 ——– c:\windows\system32\drivers\imagedrv.sys
2011-04-02 04:00 155,648 a——- c:\windows\system32\NeroCheck.exe
2011-04-02 04:00 106,496 a——- c:\windows\system32\TwnLib20.dll
2011-04-02 04:00 1,568,768 ——– c:\windows\system32\ImagX7.dll
2011-04-02 04:00 476,320 ——– c:\windows\system32\ImagXpr7.dll
2011-04-02 04:00 471,040 ——– c:\windows\system32\ImagXRA7.dll
2011-04-02 04:00 262,144 ——– c:\windows\system32\ImagXR7.dll
2011-04-02 01:57 –d—– c:\docume~1\alluse~1\applic~1\MediaMonkey
2011-04-02 01:30 –d—– c:\program files\MediaMonkey
2011-04-01 16:09 –d—– c:\program files\K-Lite Codec Pack
2011-04-01 15:23 4,444 a——- c:\windows\system32\pid.PNF
2011-04-01 14:54 3,072 a——- c:\windows\system32\drivers\audstub.sys
2011-04-01 14:53 21,504 a——- c:\windows\system32\hidserv.dll
2011-04-01 14:53 57,600 a——- c:\windows\system32\drivers\redbook.sys
2011-04-01 14:52 6,400 a——- c:\windows\system32\drivers\enum1394.sys
2011-04-01 14:51 –d—– c:\program files\common files\ODBC
2011-04-01 14:50 24,064 a——- c:\windows\system\OLESVR.DLL
2011-04-01 14:50 –d–r– c:\documents and settings\all users\Documents
2011-04-01 14:49 1,088,840 a—-r– c:\windows\SET4.tmp
2011-04-01 14:49 1,296,669 a—-r– c:\windows\SET3.tmp
2011-04-01 14:48 –d—– c:\windows\system32\CatRoot2
2011-04-01 14:48 –d—– c:\windows\system32\CatRoot
2011-04-01 14:48 –d—– C:\Documents and Settings
2011-04-01 14:47 869 a——- c:\windows\system32\$winnt$.inf
2011-04-01 06:23 –d—– c:\program files\Ulead Systems
2011-04-01 06:17 –d—– c:\program files\AMD
2011-04-01 06:17 –d—– c:\program files\Browser Configuration Utility
2011-04-01 06:16 –d—– c:\program files\Gigabyte
2011-04-01 06:13 –d—– c:\program files\common files\Logitech
2011-04-01 06:10 –d—– c:\program files\ANI
2011-04-01 06:10 –d—– c:\program files\D-Link
2011-04-01 06:08 –d—– c:\program files\common files\ATI Technologies
2011-04-01 06:05 –d—– c:\program files\ATI Technologies
2011-04-01 05:58 –dsh— c:\documents and settings\all users\DRM
2011-04-01 05:58 –d-h— c:\program files\WindowsUpdate
2011-04-01 05:58 –d—– c:\program files\Windows Media Connect 2
2011-04-01 05:57 –d—– c:\program files\common files\MSSoap
2011-04-01 05:27 –d—– c:\program files\VideoLAN
2011-04-01 05:18 –d—– c:\program files\Realtek
==================== Find3M ====================
2011-04-05 08:14 24,944 a——- c:\windows\system32\drivers\GVTDrv.sys
2011-04-05 08:14 16,608 a——- c:\windows\gdrv.sys
2011-04-02 13:23 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2011-04-01 05:57 21,640 a——- c:\windows\system32\emptyregdb.dat
============= FINISH: 14:37:12.73 ===============
I've attached the second file as requested by DDS (it's in text format, for some reason the forum wouldn't let me upload the RAR. Any help would be massively appreciated! I don't want to lose a drive full of… stuff.