OS: Win XP Home SP3 32 bit
Avast 5.0.545 (Auto update)
A couple of days ago avast prevented an “attack” on my computer with the real-time shield by JS:Jaderun-A [Expl] then VBS:Malware-Gen then Win32:Malware-gen (in 2 minute space). I have multiple files in my chest including drivers which I need especially the USB storage driver. Currently my computer is freezing once it gets to the desktop, I can open AVAST and that still works but explorer/taskbar/start menu etc do not work for a while due to the disrupted startup processes but eventually everything works fine.
Here is the extract from avast real-time scanner log:
Started on: Tuesday, June 15, 2010 5:59:25 PM
15/06/2010 8:07:57 PM C:\Documents and Settings\Dariusz\Local Settings\Temporary Internet Files\Content.IE5\IVUVU1YF\Applet1[1].htm [L] JS:Jaderun-A [Expl] (0)
File was successfully moved to chest…
15/06/2010 8:08:41 PM C:\Program Files\Mozilla Firefox\fjhdyfhsn.bat [L] VBS:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:35 PM C:\WINDOWS\system32\drivers\aec.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:36 PM C:\WINDOWS\system32\drivers\arp1394.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:36 PM C:\WINDOWS\system32\drivers\asyncmac.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:42 PM C:\WINDOWS\system32\drivers\atmarpc.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:43 PM C:\WINDOWS\system32\drivers\Cdaudio.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:43 PM C:\WINDOWS\system32\drivers\Changer.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:43 PM C:\WINDOWS\system32\drivers\dmusic.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:43 PM C:\WINDOWS\system32\drivers\drmkaud.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:43 PM C:\WINDOWS\system32\drivers\i2omgmt.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:43 PM C:\WINDOWS\system32\drivers\ip6fw.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:47 PM C:\WINDOWS\system32\drivers\ipfltdrv.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:47 PM C:\WINDOWS\system32\drivers\ipinip.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:49 PM C:\WINDOWS\system32\drivers\irenum.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:49 PM C:\WINDOWS\system32\drivers\lbrtfdc.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:49 PM C:\WINDOWS\system32\drivers\lusbfilt.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:49 PM C:\WINDOWS\system32\drivers\ma_cmidi.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:49 PM C:\WINDOWS\system32\drivers\Modem.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:50 PM C:\WINDOWS\system32\drivers\mskssrv.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:50 PM C:\WINDOWS\system32\drivers\mspclock.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:53 PM C:\WINDOWS\system32\drivers\mspqm.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:54 PM C:\WINDOWS\system32\drivers\nic1394.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:55 PM C:\WINDOWS\system32\drivers\nwlnkflt.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\nwlnkfwd.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\palmusbd.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\PCIDump.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\PDCOMP.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\PDFRAME.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\PDRELI.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\PDRFRAME.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:56 PM C:\WINDOWS\system32\drivers\RDPWD.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:57 PM C:\WINDOWS\system32\drivers\rtenicxp.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:57 PM C:\program files\superantispyware\sasenum.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:57 PM C:\WINDOWS\system32\drivers\secdrv.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:09:59 PM C:\WINDOWS\system32\drivers\Sfloppy.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:00 PM C:\WINDOWS\system32\drivers\splitter.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:00 PM C:\WINDOWS\system32\drivers\swmidi.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:02 PM C:\WINDOWS\system32\drivers\TDPIPE.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:02 PM C:\WINDOWS\system32\drivers\TDTCP.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:02 PM C:\WINDOWS\system32\drivers\usbaapl.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:03 PM C:\WINDOWS\system32\drivers\usbaudio.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:03 PM C:\WINDOWS\system32\drivers\usbscan.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:03 PM C:\WINDOWS\system32\drivers\usbstor.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:03 PM C:\WINDOWS\system32\drivers\WDICA.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:06 PM C:\WINDOWS\system32\drivers\wpdusb.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:06 PM C:\WINDOWS\system32\drivers\wudfrd.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
15/06/2010 8:10:06 PM C:\WINDOWS\system32\drivers\2590449099.sys [L] Win32:Malware-gen (0)
File was successfully moved to chest…
A subsequent thorough full system scan with Avast found:
in Local Settings\Temp\svchost.exe Win32:Malware-Gen (in chest)
in Local Settings\Temporary internet files\content.ie5\JVUVU1YF\Notes1[1].pdf JS:Pdfka-AHK [Expl] (in Chest)
Other Scans done: Mailwarebytes Anti-Mailware (nothing) and Superantispyware (just tracking cookies).
I have CClean but am yet to use it.
I am not sure what is the next step to restore my system functionality?
Hello,
I suspect that all the files are same inside but with different filenames. Send us (virus@avast.com) that files with link to this forum to anlalyze them.
I can’t seem to get them to email because they are supposedly .exe files and it wont send them. I have tried a .zip file and .rar file, anybody know how I could send them?
I thought it would be interesting to note that the virus had moved from various Drivers to Temp files in C:windows… it keeps creating .tmp files in the same folder. Every time it finds a files in the avast5 folder and removes it a new one is generated straight away.
Todays avast log:
Started on: Saturday, June 19, 2010 10:33:00 AM
19/06/2010 1:29:38 PM C:\WINDOWS\ckbcdp.dll [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 1:30:06 PM C:\WINDOWS\trz4F.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 1:35:07 PM C:\WINDOWS\trz50.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 1:40:11 PM C:\WINDOWS\trz55.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 1:45:12 PM C:\WINDOWS\trz5B.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 1:53:40 PM C:\WINDOWS\trz5D.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 1:58:40 PM C:\WINDOWS\trz5F.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:03:42 PM C:\WINDOWS\trz60.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:08:41 PM C:\WINDOWS\trz61.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:13:41 PM C:\WINDOWS\trz62.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:18:44 PM C:\WINDOWS\trz63.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:23:55 PM C:\WINDOWS\Temp_avast5_\unp258465847.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:29:02 PM C:\WINDOWS\Temp_avast5_\unp133538749.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:34:05 PM C:\WINDOWS\Temp_avast5_\unp213109777.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:39:19 PM C:\WINDOWS\Temp_avast5_\unp102098617.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:45:03 PM C:\WINDOWS\Temp_avast5_\unp226431120.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:50:04 PM C:\WINDOWS\Temp_avast5_\trz71.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 2:55:04 PM C:\WINDOWS\Temp_avast5_\unp234372650.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 3:00:06 PM C:\WINDOWS\Temp_avast5_\trz73.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 3:05:12 PM C:\WINDOWS\Temp_avast5_\trz74.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 3:10:13 PM C:\WINDOWS\Temp_avast5_\trz7F.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 3:15:26 PM C:\WINDOWS\Temp_avast5_\trz80.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 3:20:38 PM C:\WINDOWS\Temp_avast5_\trz81.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
19/06/2010 3:25:38 PM C:\WINDOWS\Temp_avast5_\trz82.tmp [L] Win32:Malware-gen (0)
File was successfully moved to chest…
A scan on usbscan.sys at VirusTotal which is one of the original driver files infected that I need resulted in: