Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works


  • Please log in to reply



    New Member

  • Member
  • Pip
  • 1 posts
Greetings Gentlemen,

I hope I am posting this in the correct forum.

A week or so ago I downloaded a program and obviously became infected by trojans and God only knows what else. All google searches redirect. This thing killed 4 different antivirus programs.

Lately it has been worse, my browsers (IE, Firefox, Opera) crash constantly and I am no longer able do searches at all. I purchased avast and while it appears to be severely compromised it did say it I am probably infected with the Win32-Alureon-CUrtk virus (perhaps more than that, not sure).

Anyway, I did a search and found another post on this forum that said download the program from gmr...which I did. It crashed after listing lots of files, i ran it again and it just listed this:

GMER - http://www.gmer.net
Rootkit quick scan 2009-09-23 19:29:56
Windows 6.0.6001 Service Pack 1
Running: 9xg4r691.exe; Driver: C:\Users\sonya\AppData\Local\Temp\ugldypow.sys

---- System - GMER 1.0.15 ----

Code 86BF68B6 ZwEnumerateKey
Code 86CBC2E6 ZwFlushInstructionCache
Code 86D1784E ZwSaveKey
Code 86C0D836 ZwSaveKeyEx
Code 86E3CCA5 IofCallDriver
Code 86C9C475 IofCompleteRequest

---- Devices - GMER 1.0.15 ----

AttachedDevice \Driver\tdx \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\tdx \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- Services - GMER 1.0.15 ----

Service C:\Windows\system32\drivers\kbiwkmrjmegnrs.sys (*** hidden *** ) [SYSTEM] kbiwkmhaofrtri <-- ROOTKIT !!!
Service C:\Windows\system32\drivers\kbiwkmxxlhsrvb.sys (*** hidden *** ) [SYSTEM] kbiwkmxrqowpvm <-- ROOTKIT !!!

---- EOF - GMER 1.0.15 ----

Please help, I do not have discs (would have to order them) and I destroyed the HD backup (via advice found on another site) and I would prefer to avoid going back to factory settings.

Thank you.

Edited by Sonya_, 23 September 2009 - 05:43 PM.

  • 0




    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts
Hello Sonya_,

Welcome to Geekstogo.

Download Combofix from either of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2

Posted Image

Posted Image

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for review.

  • 0

Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP