busterdean
2009-08-20, 22:41
I appreciate any help on this one...........
Scanned with AGV and could not delete WIN 32/Cryptor
Downloaded Malwarebytes - can't delete
Downloaded Spybot - can't delete
Friend suggested I use Mozilla browser not IE anymore and had me disable add-ons in browser.
Downloaded Sophos anti-rootkit but have not heard back from tech dept as to how to get rid of the bad files as they were noted "not to delete"
Downloaded ATF Cleaner and Superantispyware and ran in SAFE mode hich didn't show any infected files.
Rebooted in normal mode and ran another Spybot scan and STILL have viruses.
Ran Kaspersky Scanner and it showed I have infections and called them trojan.win32.agent.crez but program does not delete infection.
Currently ran Malwarebytes and found 17 files infected with Trojan.TDSS but can't remove them.
UGH!!!!!!!! I feel like I am running in circles. Can anyone help?
Here is last report:
Malwarebytes' Anti-Malware 1.40
Database version: 2659
Windows 5.1.2600 Service Pack 3
8/20/2009 12:38:13 PM
mbam-log-2009-08-20 (12-38-13).txt
Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|)
Objects scanned: 94347
Time elapsed: 40 minute(s), 46 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 12
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
\\?\globalroot\systemroot\SYSTEM32\hjgruikftputso.dll (Trojan.TDSS) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb2865 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd3846 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga5401 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc9311 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb3567 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd858 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga8764 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc2933 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb8706 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd8002 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga5372 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc9704 (Trojan.TDSS) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
\\?\globalroot\systemroot\SYSTEM32\hjgruikftputso.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\hjgruiskapptxe.sys (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\SYSTEM32\hjgruikftputso.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\SYSTEM32\hjgruiwpkhlsjb.dll (Trojan.TDSS) -> Delete on reboot.
Scanned with AGV and could not delete WIN 32/Cryptor
Downloaded Malwarebytes - can't delete
Downloaded Spybot - can't delete
Friend suggested I use Mozilla browser not IE anymore and had me disable add-ons in browser.
Downloaded Sophos anti-rootkit but have not heard back from tech dept as to how to get rid of the bad files as they were noted "not to delete"
Downloaded ATF Cleaner and Superantispyware and ran in SAFE mode hich didn't show any infected files.
Rebooted in normal mode and ran another Spybot scan and STILL have viruses.
Ran Kaspersky Scanner and it showed I have infections and called them trojan.win32.agent.crez but program does not delete infection.
Currently ran Malwarebytes and found 17 files infected with Trojan.TDSS but can't remove them.
UGH!!!!!!!! I feel like I am running in circles. Can anyone help?
Here is last report:
Malwarebytes' Anti-Malware 1.40
Database version: 2659
Windows 5.1.2600 Service Pack 3
8/20/2009 12:38:13 PM
mbam-log-2009-08-20 (12-38-13).txt
Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|)
Objects scanned: 94347
Time elapsed: 40 minute(s), 46 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 0
Registry Values Infected: 12
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
\\?\globalroot\systemroot\SYSTEM32\hjgruikftputso.dll (Trojan.TDSS) -> Delete on reboot.
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb2865 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd3846 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga5401 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc9311 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb3567 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd858 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga8764 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc2933 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingb8706 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingd8002 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletinga5372 (Trojan.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\spybotdeletingc9704 (Trojan.TDSS) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
\\?\globalroot\systemroot\SYSTEM32\hjgruikftputso.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\hjgruiskapptxe.sys (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\SYSTEM32\hjgruikftputso.dll (Trojan.TDSS) -> Delete on reboot.
C:\WINDOWS\SYSTEM32\hjgruiwpkhlsjb.dll (Trojan.TDSS) -> Delete on reboot.