Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum
![]() ![]() |
Jun 28 2010, 06:59 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
I think my laptop got infected with the above a week ago. The wave slider on my volume settings mysteriously mutes, I've been getting loads of IE popups despite seldom using Internet Explorer. Iexplore.exe processes are continually running despite me not opening IE. I've occasionally had audio adverts play randomly (for Dettol if that makes any difference!) When starting up my laptop last Thursday I was asked for a password to get onto Windows despite never setting one. I had to reboot 4 times before it finally let me on. I've ran malwarebytes, which said it was unable to remove the virus, and superantispyware, which seemed to remove it but the rogue iexplore.exe processes were still running upon rebooting and my laptop has slowed down to a crawl. I've just ran a hijackthis scan and I'll copy the results below. Any help would be very gratefully received. Thanks, Tom Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 01:43:35, on 29/06/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\System Volume Information\Microsoft\services.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\Ati2evxx.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ICO.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Sony\HotKey Utility\HKserv.exe C:\Program Files\Sony\Jog Dial Navigator\JogServ2.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\USB Disk Win98 Driver\Res.EXE C:\WINDOWS\system32\ezSP_Px.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\PowerPanel\Program\PcfMgr.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\wuauclt.exe C:\System Volume Information\Microsoft\smss.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\Sony Vaio\My Documents\Downloads\HiJackThis(2).exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 0.0.0.0:80 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file) O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe O4 - HKLM\..\Run: [JOGSERV2.EXE] C:\Program Files\Sony\Jog Dial Navigator\JogServ2.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe O4 - HKLM\..\Run: [MSSE] "c:\Program Files\Microsoft Security Essentials\msseces.exe" -hide -runkey O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9d.exe (User 'Default user') O4 - Global Startup: PowerPanel.lnk = ? O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1166124042403 O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- End of file - 7272 bytes |
|
|
|
Jun 29 2010, 08:22 AM
Post
#2
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
Hi
Please do the following: Download Bootkit remover to your desktop This is a rar file if you do not have a programme to open it then download and install Peazip
|
|
|
|
Jun 29 2010, 01:34 PM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
Hi CatByte,
Thanks for the response. Bootkit Remover won't download properly for me - its coming up as CRC error, data damaged. I'm not sure if its a problem with the file or the virus that's to blame. |
|
|
|
Jun 29 2010, 01:45 PM
Post
#4
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
are you able to download and extract it to another computer and transfer over via USB stick?
If not, there may be additional infections interfering, You have a new bootkit infection, which is a little stubborn, bootkit remover gets rid of it nicely, if you can't run it, there are other ways we can try. but let's get a thorough diagnosis first. Please run the following scans: Please download DDS from either of these links LINK 1 LINK 2 and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. NEXT ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries |
|
|
|
Jun 29 2010, 04:26 PM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
Hi,
Files are attached. Thanks again!
Attached File(s)
Attach.txt ( 14.1K )
Number of downloads: 114
Gmer.txt ( 645bytes )
Number of downloads: 81
DDS.txt ( 14.33K )
Number of downloads: 82 |
|
|
|
Jun 29 2010, 04:35 PM
Post
#6
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
Hi,
Please do the following: Download ComboFix from either of these locations: Link 1 Link 2 VERY IMPORTANT !!! Save ComboFix.exe to your Desktop * IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now |
|
|
|
Jun 29 2010, 05:54 PM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
I've still got 2 rogue iexplore.exe processes running according to Windows Task Manager. Scan has only just finished so I'm not sure if I'm still going to get the IE popups. I've attached the combofix log. Thanks again for all your help.
Attached File(s)
|
|
|
|
Jun 29 2010, 07:16 PM
Post
#8
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
Hi,
Please do the following:
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so. NEXT Using Internet Explorer or Firefox, visit Kaspersky Online Scanner: 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
|
|
|
|
Jul 1 2010, 04:24 AM
Post
#9
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
Hi Catbyte. Files are attached.
Thanks, Tom
Attached File(s)
mbam_log_2010_06_30__23_37_19_.txt ( 1.18K )
Number of downloads: 98
kaspersky.txt ( 981bytes )
Number of downloads: 110 |
|
|
|
Jul 1 2010, 07:45 AM
Post
#10
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
Hi
Please retry the Bootkit remover tool now: Download Bootkit remover to your desktop This is a rar file if you do not have a program to open it then download and install Peazip
|
|
|
|
Jul 1 2010, 01:50 PM
Post
#11
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
Hi CatByte,
I'm still getting the CRC Error when I attempt to open Bootkit Remover (through EasyZip if that's significant?) EDIT: I could do as you suggested and try to download it onto a USB stick when I'm at work tomorrow? This post has been edited by Tom10: Jul 1 2010, 03:28 PM |
|
|
|
Jul 1 2010, 04:45 PM
Post
#12
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
try the Peazip program, you can always remove it after, I haven't encountered anyone else with this error - it might be the EasyZip program?
|
|
|
|
Jul 1 2010, 05:13 PM
Post
#13
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
It worked first time with Peazip! Here's the log.
Attached File(s)
|
|
|
|
Jul 1 2010, 06:47 PM
Post
#14
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 19,739 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: XP, Vista, Win7 |
Hi
Please do the following: (Note: this command presumes you extracted the program to your desktop, if you placed it elsewhere, please let me know) Press the WinKey + R to open a run box, then copy and paste the bolded text below into the Run box and click OK. "%userprofile%\Desktop\remover.exe" fix \\.\PhysicalDrive0 Reboot your computer and re-run Bootkit remover as we did initially Post the resultant log |
|
|
|
Jul 2 2010, 12:56 PM
Post
#15
|
|
|
New Member ![]() Group: Authentic Member Posts: 10 Joined: 28-June 10 Member No.: 93,323 Operating System: Windows XP |
Hi Catbyte,
Wasn't able to paste the log contents onto notepad - I had trouble doing it last time too. I think its just that my Ctrl button is very stiff. I copied the bootkit remover log manually onto notepad, and proof read it many times to ensure accuracy. Log is attached. Thanks again.
Attached File(s)
|
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
9 | airjet | 4,397 | 13th November 2003 - 06:26 PM Last post by: cnm |
|||
![]() |
4 | alluciano | 4,928 | 7th May 2005 - 02:57 PM Last post by: pskelley |
|||
![]() |
7 | Anonymous412 | 2,686 | 7th July 2005 - 08:10 AM Last post by: pskelley |
|||
![]() |
4 | tacman | 2,753 | 31st January 2004 - 02:31 PM Last post by: cnm |
|||
![]() |
11 | hahaha144 | 3,458 | 14th May 2004 - 11:54 AM Last post by: Daemon |
|||
|
Time is now: 18th May 2013 - 09:47 AM |