[RESOLVED] several trojans found
brothers computer doing bsod after 40min use.
i used bit defenderonline scan, it found variant kazy10178
with stopzilla and cureit [drwebhk],... removed enuf to cure the bsod.
but still get instant bsod when i try to remove google chrome.
here is mbam log...
Malwarebytes Anti-Malware (Trial) 1.65.1.1000
www.malwarebytes.org
Database version: v2012.11.21.03
Windows 7 x64 NTFS
Internet Explorer 9.0.8112.16421
Gary :: GARY-PC [administrator]
Protection: Enabled
11/21/2012 1:11:59 AM
mbam-log-2012-11-21 (01-11-59).txt
Scan type: Full scan (C:\|)
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 454374
Time elapsed: 1 hour(s), 10 minute(s), 44 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
(end)
here is MBR log
aswMBR version 0.9.9.1707 Copyright(c) 2011 AVAST Software
Run date: 2012-11-21 03:37:59
-----------------------------
03:37:59.345 OS Version: Windows x64 6.1.7600
03:37:59.345 Number of processors: 2 586 0x170A
03:37:59.345 ComputerName: GARY-PC UserName: Gary
03:38:00.218 Initialize success
03:44:30.059 AVAST engine defs: 12112100
03:45:20.338 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
03:45:20.338 Disk 0 Vendor: ST932032 D005 Size: 305245MB BusType: 3
03:45:20.338 Device \Driver\iaStor -> MajorFunction fffffa80054985e8
03:45:20.338 Disk 0 MBR read successfully
03:45:20.353 Disk 0 MBR scan
03:45:20.369 Disk 0 Windows 7 default MBR code
03:45:20.385 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 100 MB offset 2048
03:45:20.400 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15000 MB offset 206848
03:45:20.478 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 290143 MB offset 30926848
03:45:20.572 Disk 0 scanning C:\Windows\system32\drivers
03:45:34.877 Service scanning
03:46:08.043 Modules scanning
03:46:08.043 Disk 0 trace - called modules:
03:46:08.573 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0xfffffa80054985e8]<<
03:46:08.573 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80031c5060]
03:46:08.589 3 CLASSPNP.SYS[fffff88001b3543f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8002e64050]
03:46:08.589 \Driver\iaStor[0xfffffa800547a250] -> IRP_MJ_CREATE -> 0xfffffa80054985e8
03:46:09.805 AVAST engine scan C:\Windows
03:46:15.390 AVAST engine scan C:\Windows\system32
03:52:01.789 AVAST engine scan C:\Windows\system32\drivers
03:52:16.749 AVAST engine scan C:\Users\Gary
03:55:31.594 AVAST engine scan C:\ProgramData
03:59:43.097 Scan finished successfully
04:15:10.878 Disk 0 MBR has been saved successfully to "C:\Users\Gary\Desktop\MBR.dat"
04:15:10.893 The log file has been saved successfully to "C:\Users\Gary\Desktop\aswMBR.txt"