Avira found 12 problems. They are not false positives.
MBAM found 9
SAS found 2 Malware.Trace
HitMan Pro found Alureon Rootkit (possible variant of TDL3), Invalid security zone that is inhibiting active X controls on Microsoft Mgmt Console, and Master Boot Record Sector 0 Rootkit.
Chrome will not connect to the internet. Mozilla is stubborn and I am getting redirects. Opera was working but will not now. I am currently using Mozilla. When I plug in my USB stick the drive will not show up under My Computer. I tried 2 different sticks and the same result. You Tube will not work right.
I ran MBAM, Avira and SAS in safe mode. All that they detect has been removed, as far as those three scanners detect.
Here are the MBAM results:
Malwarebytes' Anti-Malware 1.50.1.1100
http://www.malwarebytes.org
Database version: 5522
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
1/15/2011 12:56:15 PM
mbam-log-2011-01-15 (12-56-15).txt
Scan type: Full scan (C:\|)
Objects scanned: 180162
Time elapsed: 19 minute(s), 29 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
c:\WINDOWS\system32\sshnas21.dll (Trojan.FraudPack.Gen) -> Delete on reboot.
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SSHNAS (Trojan.Renos) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\WINDOWS\system32\sshnas21.dll (Trojan.FraudPack.Gen) -> Delete on reboot.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008791.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008793.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008795.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008797.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008799.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008801.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{9f625216-922b-4b93-96d3-bf83d7ca5179}\RP142\A0008803.exe (Rootkit.TDSS) -> Quarantined and deleted successfully.
c:\WINDOWS\temp\Tmb.exe (Trojan.FraudPack.Gen) -> Quarantined and deleted successfully.
Here are Avira's results:
Avira AntiVir Personal
Report file date: Saturday, January 15, 2011 15:07
Scanning for 2370917 virus strains and unwanted programs.
The program is running as an unrestricted full version.
Online services are available:
Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Safe mode
Username : Scott
Computer name : SCOTT-981B04019
Version information:
BUILD.DAT : 10.0.0.609 31824 Bytes 12/13/2010 09:43:00
AVSCAN.EXE : 10.0.3.5 435368 Bytes 12/8/2010 15:31:15
AVSCAN.DLL : 10.0.3.0 46440 Bytes 4/19/2010 13:18:12
LUKE.DLL : 10.0.3.2 104296 Bytes 12/8/2010 15:31:19
LUKERES.DLL : 10.0.0.1 12648 Bytes 2/11/2010 03:40:49
VBASE000.VDF : 7.10.0.0 19875328 Bytes 11/6/2009 13:05:36
VBASE001.VDF : 7.11.0.0 13342208 Bytes 12/14/2010 16:01:51
VBASE002.VDF : 7.11.0.1 2048 Bytes 12/14/2010 16:01:51
VBASE003.VDF : 7.11.0.2 2048 Bytes 12/14/2010 16:01:51
VBASE004.VDF : 7.11.0.3 2048 Bytes 12/14/2010 16:01:51
VBASE005.VDF : 7.11.0.4 2048 Bytes 12/14/2010 16:01:51
VBASE006.VDF : 7.11.0.5 2048 Bytes 12/14/2010 16:01:51
VBASE007.VDF : 7.11.0.6 2048 Bytes 12/14/2010 16:01:51
VBASE008.VDF : 7.11.0.7 2048 Bytes 12/14/2010 16:01:52
VBASE009.VDF : 7.11.0.8 2048 Bytes 12/14/2010 16:01:52
VBASE010.VDF : 7.11.0.9 2048 Bytes 12/14/2010 16:01:52
VBASE011.VDF : 7.11.0.10 2048 Bytes 12/14/2010 16:01:52
VBASE012.VDF : 7.11.0.11 2048 Bytes 12/14/2010 16:01:52
VBASE013.VDF : 7.11.0.52 128000 Bytes 12/16/2010 10:04:30
VBASE014.VDF : 7.11.0.91 226816 Bytes 12/20/2010 02:18:04
VBASE015.VDF : 7.11.0.122 136192 Bytes 12/21/2010 01:13:19
VBASE016.VDF : 7.11.0.156 122880 Bytes 12/24/2010 10:06:09
VBASE017.VDF : 7.11.0.185 146944 Bytes 12/27/2010 13:46:42
VBASE018.VDF : 7.11.0.228 132608 Bytes 12/30/2010 20:32:03
VBASE019.VDF : 7.11.1.5 148480 Bytes 1/3/2011 20:32:00
VBASE020.VDF : 7.11.1.37 156672 Bytes 1/7/2011 20:31:58
VBASE021.VDF : 7.11.1.65 140800 Bytes 1/10/2011 20:32:02
VBASE022.VDF : 7.11.1.87 225280 Bytes 1/11/2011 20:32:04
VBASE023.VDF : 7.11.1.124 125440 Bytes 1/14/2011 20:31:23
VBASE024.VDF : 7.11.1.125 2048 Bytes 1/14/2011 20:31:24
VBASE025.VDF : 7.11.1.126 2048 Bytes 1/14/2011 20:31:24
VBASE026.VDF : 7.11.1.127 2048 Bytes 1/14/2011 20:31:24
VBASE027.VDF : 7.11.1.128 2048 Bytes 1/14/2011 20:31:24
VBASE028.VDF : 7.11.1.129 2048 Bytes 1/14/2011 20:31:24
VBASE029.VDF : 7.11.1.130 2048 Bytes 1/14/2011 20:31:24
VBASE030.VDF : 7.11.1.131 2048 Bytes 1/14/2011 20:31:24
VBASE031.VDF : 7.11.1.145 57344 Bytes 1/15/2011 19:17:34
Engineversion : 8.2.4.140
AEVDF.DLL : 8.1.2.1 106868 Bytes 7/29/2010 23:02:03
AESCRIPT.DLL : 8.1.3.52 1282426 Bytes 1/6/2011 20:32:37
AESCN.DLL : 8.1.7.2 127349 Bytes 11/23/2010 11:47:10
AESBX.DLL : 8.1.3.2 254324 Bytes 11/23/2010 11:47:21
AERDL.DLL : 8.1.9.2 635252 Bytes 9/21/2010 17:03:30
AEPACK.DLL : 8.2.4.7 512375 Bytes 12/30/2010 13:48:08
AEOFFICE.DLL : 8.1.1.10 201084 Bytes 11/23/2010 11:47:08
AEHEUR.DLL : 8.1.2.64 3154294 Bytes 1/6/2011 20:32:29
AEHELP.DLL : 8.1.16.0 246136 Bytes 12/3/2010 02:56:20
AEGEN.DLL : 8.1.5.1 397683 Bytes 1/6/2011 20:32:05
AEEMU.DLL : 8.1.3.0 393589 Bytes 11/23/2010 11:46:36
AECORE.DLL : 8.1.19.0 196984 Bytes 12/3/2010 02:56:16
AEBB.DLL : 8.1.1.0 53618 Bytes 4/25/2010 18:12:09
AVWINLL.DLL : 10.0.0.0 19304 Bytes 1/14/2010 16:03:38
AVPREF.DLL : 10.0.0.0 44904 Bytes 1/14/2010 16:03:35
AVREP.DLL : 10.0.0.8 62209 Bytes 2/18/2010 20:47:40
AVREG.DLL : 10.0.3.2 53096 Bytes 11/3/2010 09:01:47
AVSCPLR.DLL : 10.0.3.2 84328 Bytes 12/8/2010 15:31:16
AVARKT.DLL : 10.0.22.6 231784 Bytes 12/8/2010 15:30:45
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 1/26/2010 13:53:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 1/28/2010 16:57:58
AVSMTP.DLL : 10.0.0.17 63848 Bytes 3/16/2010 19:38:56
NETNT.DLL : 10.0.0.0 11624 Bytes 2/19/2010 18:41:00
RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 1/28/2010 17:10:20
RCTEXT.DLL : 10.0.58.0 97128 Bytes 11/3/2010 09:01:46
Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: C:\Program Files\Avira\AntiVir Desktop\sysscan.avp
Logging.............................: low
Primary action......................: delete
Secondary action....................: delete
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:,
Process scan........................: on
Extended process scan...............: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,
Start of the scan: Saturday, January 15, 2011 15:07
Starting search for hidden objects.
The driver could not be initialized.
The scan of running processes will be started
Scan process 'taskmgr.exe' - '34' Module(s) have been scanned
Scan process 'avscan.exe' - '69' Module(s) have been scanned
Scan process 'avcenter.exe' - '67' Module(s) have been scanned
Scan process 'Explorer.EXE' - '84' Module(s) have been scanned
Scan process 'svchost.exe' - '82' Module(s) have been scanned
Scan process 'svchost.exe' - '42' Module(s) have been scanned
Scan process 'svchost.exe' - '37' Module(s) have been scanned
Scan process 'lsass.exe' - '52' Module(s) have been scanned
Scan process 'services.exe' - '34' Module(s) have been scanned
Scan process 'winlogon.exe' - '63' Module(s) have been scanned
Scan process 'csrss.exe' - '12' Module(s) have been scanned
Scan process 'smss.exe' - '2' Module(s) have been scanned
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Starting to scan executable files (registry).
The registry was scanned ( '434' files ).
Starting the file scan:
Begin scan in 'C:\'
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\10\4c562fca-52c4f847
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/OpenConnecti.A Java virus
--> cpak/Crimepack$1.class
[DETECTION] Contains recognition pattern of the JAVA/OpenConnecti.A Java virus
--> cpak/KAVS.class
[DETECTION] Contains recognition pattern of the JAVA/OpenConnection.AH Java virus
--> cpak/Crimepack.class
[DETECTION] Contains recognition pattern of the JAVA/OpenStream.AB.1 Java virus
[NOTE] A backup was created as '4e0f7967.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\50\170b44f2-1b9abc3a
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0094.C exploit
--> Exploit$1$1.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0094.C exploit
--> Exploit$1.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0094.AF exploit
--> Exploit$2.class
[DETECTION] Contains recognition pattern of the EXP/CVE-2010-0094.D exploit
--> Exploit.class
[DETECTION] Contains recognition pattern of the JAVA/CV-2010-0094.A Java virus
--> PayloadCreater.class
[DETECTION] Contains recognition pattern of the JAVA/CV-2010-0094.C Java virus
--> PayloadClassLoader.class
[DETECTION] Contains recognition pattern of the JAVA/CV-2010-0094.B Java virus
--> Payloader.class
[DETECTION] Contains recognition pattern of the JAVA/CV-2010-0094.D Java virus
--> payload.ser
[DETECTION] Contains recognition pattern of the JAVA/CV-2010-0094.E Java virus
[NOTE] A backup was created as '569f572c.qua' ( QUARANTINE )
[NOTE] The file was deleted!
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\9\58413909-55f76746
[0] Archive type: ZIP
[DETECTION] Contains recognition pattern of the JAVA/Agent.AD.1 Java virus
--> goog/main.class
[DETECTION] Contains recognition pattern of the JAVA/Agent.AD.1 Java virus
[NOTE] A backup was created as '04c40dc5.qua' ( QUARANTINE )
[NOTE] The file was deleted!
End of the scan: Saturday, January 15, 2011 15:40
Used time: 32:33 Minute(s)
The scan has been done completely.
4648 Scanned directories
148430 Files were scanned
12 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
3 files were deleted
0 Viruses and unwanted programs were repaired
3 Files were moved to quarantine
0 Files were renamed
0 Files cannot be scanned
148418 Files not concerned
734 Archives were scanned
0 Warnings
3 Notes
