PDA

View Full Version : Alfacleaner- With a twist :(



rpace
2006-03-02, 11:04
The twist is my machine won't boot into safe mode anymore.

I was downloading that 'Still Seeing Breen' Machinama video(from the authors website no less) when all the sudden all this crap pops up on my screen. My first instict was Alt-Ctrl-Dlt, and shut the unfamiliar programs down. I think I killed the program before it finished installing(There was a taskbar icon flashing all the files it was installing). I imediately went to program files, deleted the folder it installed in, went into C:/windows and deleted the HTML file it had placed there for use on my desktop(And deleted the entry in my display settings), and deleted ntzl.exe, lich.exe, and intell321.exe.

Then I ran Hijackthis, got rid of the following entries, which were the only ones different from a normal hijackthis scan.
O4 - HKLM\..\Run: [lich] lich.exe
O4 - HKLM\..\Run: [intell321.exe] C:\WINDOWS\System32\intell321.exe
O4 - HKLM\..\Run: [AlfaCleaner] C:\Program Files\AlfaCleaner\AlfaCleaner.exe
O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://udpates.lifesceinc.com/installers/pinstall/pinstall.cab
O23 - Service: AlfaCleanerService - AlfaCleaner.com - C:\Program Files\AlfaCleaner\ACServer.exe

Next step was google, I searched these fine forums, downloaded smitRem, shut my comp down and tried to boot in safe mode. It starts loading the files, and then prompts me to 'Press esc to skip loading vax347b.sys' It restarts whether I press esc or let it load. Comp still boots into normal windows fine, but if I try to boot to safe mode it hangs.

Booting into windows, everything seems fine, the desktop is back to normal, there are no unfamiliar programs running, so I run smitREM. It finds one infected file, and repairs it. I run hijackthis again, then spybot, then ewido anti-malware just for good measure :). None of them found any problems, and windows seems to be operating normally. Still, this leaves me somewhat concerned, without scanning from safe mode I'm feeling a little less than confident. What do you guys think? Am I in the clear? any ideas as to what's keeping me out of safe mode?

rpace
2006-03-02, 11:52
PPS- Hijack log for those interested

Logfile of HijackThis v1.99.1
Scan saved at 4:59:09 PM, on 3/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Ryan Pace\Desktop\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1141244409000
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe


I suppose this is what I get for forgetting to update java :banghead:

LonnyRJones
2006-03-07, 08:22
Hi, still having problems ?
Why dont we see signs of an antivirus program running ?

Post a startup list from hijackthis, Start Hijackthis click config misc tools >
place a check in [X] list also minor sections
and [X] list empty sections, then click gernerate startuplist log.

tashi
2006-03-12, 20:06
This topic will now be archived to prevent others with similar issues posting in it.
If you need it re-opened please send me a pm and provide a link to the thread.