Trojan.win32.agent.azsy

Here’s the mbam log file…scan is done, mbam is giving me the option of remove or ignore… UACpappanybig.dll…saw that found by Avast…mbam didn’t see it what about that???
Database version: 2736
Windows 5.1.2600 Service Pack 2

9/3/2009 1:09:03 PM
mbam-log-2009-09-03 (13-08-06).txt

Scan type: Full Scan (C:|)
Objects scanned: 216329
Time elapsed: 49 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) → No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) → No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) → No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.

Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.

Files Infected:
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) → No action taken.
C:\Documents and Settings\family\Local Settings\Temp\drv4865240.exe (Trojan.Dropper) → No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) → No action taken.
C:\WINDOWS\system32\UACwdbxmplvpe.dat (Rootkit.TDSS) → No action taken.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) → No action taken.

Malwarebytes’ Anti-Malware 1.40
Database version: 2736
Windows 5.1.2600 Service Pack 2

9/3/2009 1:09:03 PM
mbam-log-2009-09-03 (13-08-06).txt

Scan type: Full Scan (C:|)
Objects scanned: 216329
Time elapsed: 49 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) → No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) → No action taken.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) → No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.

Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) → No action taken.

Files Infected:
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) → No action taken.
C:\Documents and Settings\family\Local Settings\Temp\drv4865240.exe (Trojan.Dropper) → No action taken.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) → No action taken.
C:\WINDOWS\system32\UACwdbxmplvpe.dat (Rootkit.TDSS) → No action taken.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) → No action taken.

Ok fast Eddie, wish you had been faster, off to bed now ;D. Any how, first with MBAM you took no action.Run again, this time have MBAM fix the threats. REBOOT

Its possible Avast has removed rootkit Alureon. Just to be sure, download Rootrepeal,unzip, and open. click REPORT at the bottom, then SCAN, then tick all boxes,OK, then tick C drive,OK, when the scans done, save report. Copy/paste log http://rootrepeal.googlepages.com/

http://www.malwarebytes.org/forums/index.php?showtopic=12709

I don’t see any option to FIX, only remove or ignore I left the scan page open so the previous scan is still active should I remove or ignore??? No FIX option available…

Remove.

Done and done…here’s the log…

Malwarebytes’ Anti-Malware 1.40
Database version: 2736
Windows 5.1.2600 Service Pack 2

9/3/2009 2:10:23 PM
mbam-log-2009-09-03 (14-10-23).txt

Scan type: Full Scan (C:|)
Objects scanned: 216329
Time elapsed: 49 minute(s), 47 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 3
Folders Infected: 2
Files Infected: 5

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\UAC (Malware.Trace) → Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) → Quarantined and deleted successfully.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\personalav (Rogue.PersonalAntiVirus) → Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) → Quarantined and deleted successfully.
C:\Program Files\PersonalAV (Rogue.PersonalAntiVirus) → Quarantined and deleted successfully.

Files Infected:
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) → Quarantined and deleted successfully.
C:\Documents and Settings\family\Local Settings\Temp\drv4865240.exe (Trojan.Dropper) → Quarantined and deleted successfully.
C:\Program Files\Common Files\Uninstall\PersonalAV\Uninstall.lnk (Rogue.PersonalAntiVirus) → Quarantined and deleted successfully.
C:\WINDOWS\system32\UACwdbxmplvpe.dat (Rootkit.TDSS) → Quarantined and deleted successfully.
C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) → Quarantined and deleted successfully.

Not sure what to do in response to Mickeys 6:22 post…

I hope this does the trick…you guys are a big help…thx, Ed

To clean System Restore:

Create a clean restore point then delete all previous infected restore points

I see you are still running Windows Service Pack 2 so you should install Windows Service Pack 3 that has been available for over a year and contains several Critical Security updates plus performance improvements.

You need to start Internet Explorer then go to Tools then Windows Update and download all of the available updates.

Also you should enable Automatic Updates or at least be notified that Updates are available.

Go to Control Panel then Automatic Updates then select Automatic (recommended) or at least Notify me but don’t automatically download or install them.

Go to Secunia Online Software Inspector then run it to see what other applications are vulnerable:
http://secunia.com/vulnerability_scanning/online

Basically the files beginning with UAC (uacinit.dll ,UACwdbxmplvpe.dat) are protected by the rootkit, which also begins with UAC but ends in sys
Now Avast has already, in all probability removed the rootkit.
C:\System Volume Information_restore{8C1815BE-BDC6-45FA-B6EE-367DF9495606}\RP647\A0154781.sys is infected by Win32:Alureon-CV [Rtk]

If not these files will keep returning. Rootrepeal will show this. so see this post, and run rootrepeal http://forum.avast.com/index.php?topic=47639.msg402995#msg402995
Another option would be to reboot, re run MBAM, if it comes up clean, I would assume the rootkit has already gone.