I need assistance please. It is tough to type while closing all the opening browser windows from “Internet Speed Monitor” navigating to various adds. This malware began a few days ago on my daughter’s machine. She claimed to have gone to a page to view a preview of the movie “fireproof” and then the avast alarm went off. She used system restore the next day. I have been scanning this machine with various tools and always get different/varying results. The browser hijacking makes it impossible to use. I also note that automatic microsoft updates is now disabled and I can not get it enabled even running services.msc. Last night, I disabled system restore, and did a boot scan with avast and here is the log:
10/29/2008 11:05
Scan of all local drives
File C:\Program Files\support.com\providerComcast\htmlagent\inc\chtr_dectree.js is infected by JS:Feebs-A1, Deleted
Number of searched folders: 17296
Number of tested files: 161331
Number of infected files: 1
11/23/2008 23:42
Scan of all local drives
File C:\Program Files\Online Services\NetscapeOnline\NSsetup.exe is infected by Win32:Trojan-gen {Other}, Deleted
File C:\Program Files\Updates from HP\9972322\Program\Interop.SHDocVw.dll is infected by Win32:Adware-gen [Adw], Deleted
File C:\WINDOWS\system32\byXPHayy.dll is infected by Win32:Trojan-gen {Other}, Repair: Error 42060 {The file was not repaired.}, Move to chest: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Repair: Error 42060 {The file was not repaired.}, Repair: Error 42060 {The file was not repaired.}, Move to chest: Error 0xC0000034 {Object Name not found.}, Move to chest: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}, Delete: Error 0xC0000034 {Object Name not found.}
Scanning aborted
Number of searched folders: 16457
Number of tested files: 148404
Number of infected files: 3
11/24/2008 08:56
Scan of all local drives
File C:\WINDOWS\system32\drivers\TDSSpqlt.sys is infected by Win32:Tidserv [trj], Moved to chest
File C:\WINDOWS\system32\khfDvsTl.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\opnmNfCS.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\TDSShrxx.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\TDSSoiqt.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\TDSSvkql.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\wvUlmNdb.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
Number of searched folders: 17229
Number of tested files: 160313
Number of infected files: 7
11/25/2008 08:25
Scan of all local drives
File C:\Program Files\Alwil Software\Avast4\DATA\moved\A0049344.sys.vir is infected by Win32:Tidserv [trj], Moved to chest
File C:\Program Files\Alwil Software\Avast4\DATA\moved\eTIIB90.exe.vir is infected by Win32:Trojan-gen {Other}, Moved to chest
Number of searched folders: 17220
Number of tested files: 158407
Number of infected files: 2
11/25/2008 22:44
Scan of all local drives
File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\mwnsxrweox.tmp is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\nomearoasx.tmp is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\prun.tmp is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\System Volume Information_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP401\A0047323.dll is infected by Win32:Adware-gen [Adw], Deleted
File C:\System Volume Information_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP402\A0049557.dll is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\System Volume Information_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP403\A0049586.dll is infected by Win32:Rootkit-gen [Rtk], Deleted
File C:\System Volume Information_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP403\A0049597.exe is infected by Win32:Rootkit-gen [Rtk], Deleted
Number of searched folders: 17249
Number of tested files: 1206448
Number of infected files: 7
11/29/2008 23:44
Scan of all local drives
File C:\Documents and Settings\HP_Administrator\Local Settings\Temp\79.exe$PLUGINSDIR\f1 is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\Program Files\Alwil Software\Avast4\DATA\moved\OFCZXR.DLL.vir is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\aaptsbyf.dll is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\WINDOWS\system32\bdfngfys.dll is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\WINDOWS\system32\clwxwe.dll is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\WINDOWS\system32\evffleop.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\kvdliebg.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\nbwgqfdc.dll is infected by Win32:Trojan-gen {Other}, Moved to chest
File C:\WINDOWS\system32\trz3.tmp is infected by Win32:Rootkit-gen [Rtk], Moved to chest
File C:\WINDOWS\system32\trz4.tmp is infected by Win32:Rootkit-gen [Rtk], Moved to chest
Number of searched folders: 17062
Number of tested files: 1176847
Number of infected files: 10
I will post a hjt log next.
Thank you very very much for any help.