This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Homepage Hijacked to http:/// (continued)

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry I was unable to reply to the previous thread before it was closed. It's been really busy at work. Basically, I've been doing all kinds of stuff to try to regain control over my Internet Explorer 8 home page. Here's everything I've done so far:

  • installed & ran ATF Cleaner
  • installed & ran Malwarebyte's Anti-Malware and removed selected items
  • ran HijackThis and clicked "fix checked" to the seleted items
  • downloaded & ran Rooter.exe
  • performed Kaspersky online virus scan
  • downloaded & ran ComboFix

If you need to see the logs from those, except ComboFix, see my previous threads at the following link:http://forums.whatthetech.com/Homepage_Hij…tp_t101138.html

Here is the ComboFix log:


ComboFix 09-03-26.03 - Lewis 2009-03-27 14:49:17.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.218 [GMT -3:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.
ADS - WINDOWS: deleted 24 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Lewis\Application Data\inst.exe

.
((((((((((((((((((((((((( Files Created from 2009-02-27 to 2009-03-27 )))))))))))))))))))))))))))))))
.

2009-03-20 12:41 . 2009-03-20 12:41 d–hs—- c:\documents and settings\LocalService\IETldCache
2009-03-20 12:05 . 2009-03-20 12:20 d–h-c— c:\windows\ie8
2009-03-16 11:51 . 2009-03-16 11:51 d——– c:\program files\iPod
2009-03-16 11:49 . 2009-03-16 11:53 d——– c:\documents and settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
2009-03-16 11:40 . 2009-03-16 11:43 d——– c:\program files\QuickTime
2009-03-14 18:47 . 2009-03-14 18:47 d——– c:\program files\TagScanner
2009-03-12 04:40 . 2009-03-12 04:44 d——– C:\Rooter$
2009-03-11 10:31 . 2009-03-11 10:31 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-09 23:46 . 2009-03-25 23:28 d——– c:\documents and settings\Lewis\YPOPs
2009-03-09 21:38 . 2007-04-09 14:23 28,040 –a—— c:\windows\system32\mdimon.dll
2009-03-09 21:38 . 2009-03-09 21:38 376 –a—— c:\windows\ODBC.INI
2009-03-09 21:23 . 2009-03-09 21:23 d——– c:\program files\Microsoft ActiveSync
2009-03-09 21:08 . 2009-03-09 21:24 d——– c:\windows\SHELLNEW
2009-03-09 21:07 . 2009-03-09 21:07 d——– c:\program files\Microsoft.NET
2009-03-08 20:19 . 2009-03-12 15:49 d——– c:\program files\YPOPs
2009-03-08 14:22 . 2009-03-08 14:22 49,152 ——— c:\windows\system32\msrating.dll.mui
2009-03-08 14:22 . 2009-03-08 14:22 2,560 ——— c:\windows\system32\mshta.exe.mui
2009-03-08 14:21 . 2009-03-08 14:21 4,096 ——— c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:20 . 2009-03-08 14:20 81,920 ——— c:\windows\system32\iedkcs32.dll.mui
2009-03-08 12:02 . 2009-03-08 12:02 d——– c:\program files\PicLensIE
2009-03-08 04:33 . 2009-03-08 04:33 18,944 —–c— c:\windows\system32\dllcache\corpol.dll
2009-03-07 16:29 . 2009-03-07 16:29 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-07 16:29 . 2009-03-07 16:29 d——– c:\documents and settings\Lewis\Application Data\Malwarebytes
2009-03-07 16:29 . 2009-03-07 16:29 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-07 16:29 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-07 16:29 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-03-07 16:24 . 2009-03-07 16:24 d–hs—- c:\documents and settings\Lewis\PrivacIE
2009-03-07 16:24 . 2009-03-07 16:24 d–hs—- c:\documents and settings\Lewis\IECompatCache
2009-03-07 16:22 . 2009-03-07 16:22 d–hs—- c:\documents and settings\Lewis\IETldCache
2009-03-07 16:00 . 2009-03-20 12:33 d——– c:\windows\ie8updates
2009-03-07 15:57 . 2009-03-20 12:20 1,374 –a—— c:\windows\imsins.BAK
2009-03-07 15:51 . 2009-02-28 01:55 105,984 —–c— c:\windows\system32\dllcache\iecompat.dll
2009-03-07 15:36 . 2009-03-07 15:36 d——– c:\program files\Trend Micro
2009-03-06 20:08 . 2009-03-06 20:08 d——– c:\documents and settings\Lewis\Application Data\AccurateRip
2009-03-06 20:07 . 2009-03-06 21:31 d——– c:\program files\Exact Audio Copy
2009-03-06 20:07 . 2009-03-06 20:08 d——– c:\documents and settings\Lewis\Application Data\AD ON Multimedia
2009-03-06 18:37 . 2009-03-06 18:41 d——– c:\program files\OpenVPN
2009-03-04 16:44 . 2009-03-04 16:50 d——– c:\program files\GMATPrep
2009-03-02 19:04 . 2009-03-02 19:04 d——– c:\program files\Audacity

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-27 17:17 ——— d—–w c:\documents and settings\Lewis\Application Data\uTorrent
2009-03-27 11:57 ——— d—–w c:\program files\LogMeIn
2009-03-26 02:22 ——— d—–w c:\program files\Google
2009-03-17 13:49 ——— d—–w c:\documents and settings\Lewis\Application Data\foobar2000
2009-03-16 14:53 ——— d—–w c:\program files\iTunes
2009-03-16 14:51 ——— d—–w c:\program files\Common Files\Apple
2009-03-11 13:31 410,984 —-a-w c:\windows\system32\deploytk.dll
2009-03-11 13:30 ——— d—–w c:\program files\Java
2009-03-09 23:32 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-08 07:34 914,944 —-a-w c:\windows\system32\wininet.dll
2009-03-08 07:34 43,008 —-a-w c:\windows\system32\licmgr10.dll
2009-03-08 07:33 420,352 —-a-w c:\windows\system32\vbscript.dll
2009-03-08 07:33 18,944 —-a-w c:\windows\system32\corpol.dll
2009-03-08 07:32 72,704 —-a-w c:\windows\system32\admparse.dll
2009-03-08 07:32 71,680 —-a-w c:\windows\system32\iesetup.dll
2009-03-08 07:31 48,128 —-a-w c:\windows\system32\mshtmler.dll
2009-03-08 07:31 45,568 —-a-w c:\windows\system32\mshta.exe
2009-03-08 07:31 34,816 —-a-w c:\windows\system32\imgutil.dll
2009-03-08 07:22 156,160 —-a-w c:\windows\system32\msls31.dll
2009-03-05 19:44 ——— d—–w c:\documents and settings\Lewis\Application Data\Vso
2009-03-04 19:44 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-26 09:29 ——— d—–w c:\program files\Microsoft Silverlight
2009-02-25 19:03 ——— d—–w c:\program files\Windows Live
2009-02-25 19:02 ——— d—–w c:\program files\Windows Live SkyDrive
2009-02-25 04:34 ——— d—–w c:\program files\ATI Technologies
2009-02-25 04:22 ——— d—–w c:\program files\Microsoft Office Outlook Connector
2009-02-25 04:22 ——— d—–w c:\program files\Microsoft
2009-02-18 23:40 ——— d—–w c:\program files\uTorrent
2009-02-17 01:19 ——— d—–w c:\documents and settings\Lewis\Application Data\EmailNotifier
2009-02-17 01:19 ——— d—–w c:\documents and settings\All Users\Application Data\Megaupload
2009-02-17 01:19 ——— d—–w c:\documents and settings\All Users\Application Data\EmailNotifier
2009-02-17 01:17 ——— d—–w c:\program files\Megaupload
2009-02-17 01:14 ——— d—–w c:\documents and settings\Lewis\Application Data\InstallShield
2009-02-15 20:54 ——— d—–w c:\program files\iTunes Genre Art Manager
2009-02-12 18:38 ——— d—–w c:\documents and settings\All Users\Application Data\vsosdk
2009-02-12 13:08 ——— d—–w c:\documents and settings\Lewis\Application Data\U3
2009-02-11 17:01 ——— d—–w c:\documents and settings\Lewis\Application Data\Digsby
2009-02-11 17:01 ——— d—–w c:\documents and settings\All Users\Application Data\Digsby
2009-02-10 01:15 ——— d—–w c:\program files\VSO
2009-02-10 01:07 47,360 —-a-w c:\windows\system32\drivers\pcouffin.sys
2009-02-10 01:07 47,360 —-a-w c:\documents and settings\Lewis\Application Data\pcouffin.sys
2009-02-09 11:13 1,846,784 —-a-w c:\windows\system32\win32k.sys
2009-02-08 22:03 ——— d—–w c:\program files\QuickMediaConverter
2009-02-06 21:52 49,504 —-a-w c:\windows\system32\sirenacm.dll
2009-02-05 12:48 ——— d—–w c:\program files\Common Files\InstallShield
2009-02-05 12:45 ——— d—–w c:\program files\Sonic
2009-02-05 12:44 ——— d—–w c:\program files\Common Files\Sonic Shared
2009-02-05 12:31 ——— d—–w c:\program files\Samsung
2009-02-05 12:28 ——— d—–w c:\documents and settings\Lewis\Application Data\Sonic
2009-02-05 12:28 ——— d—–w c:\documents and settings\Lewis\Application Data\Leadertech
2009-01-28 01:11 ——— d—–w c:\documents and settings\Lewis\Application Data\DivX
2009-01-27 21:46 ——— d—–w c:\program files\Bonjour
2009-01-27 13:30 ——— d—–w c:\program files\DivX
2009-01-07 21:21 26,144 —-a-w c:\windows\system32\spupdsvc.exe
2009-01-07 21:20 265,720 —-a-w c:\windows\system32\msdbg2.dll
2009-01-07 21:20 26,112 —-a-w c:\windows\system32\idndl.dll
2009-01-07 21:20 24,576 —-a-w c:\windows\system32\nlsdl.dll
2009-01-07 21:20 23,552 —-a-w c:\windows\system32\normaliz.dll
2008-12-28 22:48 2,330,643 —-a-w c:\windows\system32\x264vfw.dll
2008-07-19 15:50 7,486 –sha-r c:\windows\system32\killVBS.vbs
2008-05-24 23:58 32,768 –sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052420080525\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232]
"Google Update"="c:\documents and settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-08 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-07-24 63048]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-11 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
"iLike"="c:\program files\iLike\1.2.10\ilikesidebar.exe" [2008-09-10 63024]

c:\documents and settings\Lewis\Start Menu\Programs\Startup\
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2008-04-15 157008]
Yahoo! Widgets.lnk - c:\program files\Yahoo!\Widgets\YahooWidgets.exe [2007-12-11 3746856]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Google Calendar Sync.lnk - c:\program files\Google\Google Calendar Sync\GoogleCalendarSync.exe [2008-10-02 546288]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2008-10-16 19:35 87352 c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"= DrvTrNTm.dll
"wave"= DrvTrNTm.dll
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\ZPoC\\ZPoc.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\Lewis\\Local Settings\\Application Data\\Google\\Google Talk, Labs Edition\\GoogleTalkLabsEdition.exe"=
"c:\\Documents and Settings\\Lewis\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Lewis\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"52530:TCP"= 52530:TCP:uTorrent

R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [2008-07-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-09-17 47640]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2008-04-14 200192]
R3 TotRec7;Total Recorder WDM audio driver;c:\windows\system32\drivers\TotRec7.sys [2008-07-12 120472]
S2 gupdate1c8ef3c3f7440de;Google Update Service (gupdate1c8ef3c3f7440de);c:\program files\Google\Update\GoogleUpdate.exe [2008-07-26 133104]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-06 31592]
S3 tap0801;TAP-Win32 Adapter V8;c:\windows\system32\drivers\tap0801.sys [2006-10-01 26624]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]

— Other Services/Drivers In Memory —

*Deregistered* - Viewpoint Manager Service
*Deregistered* - W32Time
*Deregistered* - WebClient
*Deregistered* - WinDefend
*Deregistered* - winmgmt
*Deregistered* - wscsvc
*Deregistered* - WSearch
*Deregistered* - wuauserv
*Deregistered* - WudfSvc
*Deregistered* - WZCSVC

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ff0912d-1075-11dd-a062-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ff09149-1075-11dd-a062-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c6a20c-4018-11dd-a0ab-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c6a20d-4018-11dd-a0ab-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69d69b7a-60a1-11dd-a0e0-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7673fc2-55aa-11dd-a0cf-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c064000c-3fc1-11dd-a0a9-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f55566f0-f38c-11dd-a178-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa1b7f50-1896-11dd-a06a-0014a52449d7}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe killVBS.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder

2009-03-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-03-27 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2008-08-29 11:47]

2009-03-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1659004503-1972579041-682003330-1004.job
- c:\documents and settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-08 14:24]

2009-03-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]

2009-03-12 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-04-16 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2008-04-16 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe []

2009-03-27 c:\windows\Tasks\User_Feed_Synchronization-{DD417806-D794-49CF-B554-A3DB5EC47752}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{C9D0879E-F33F-4CA8-9137-6F2A0AEDCFB9} - (no file)
WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe


.
——- Supplementary Scan ——-
.
uStart Page =
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: plaxo.com\www
DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} - hxxp://www.christianrock2.net/amp3dj.cab
FF - ProfilePath - c:\documents and settings\Lewis\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\
FF - prefs.js: browser.search.selectedEngine - Google US
FF - prefs.js: browser.startup.homepage - hxxp://my.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://br.search.yahoo.com/search?ei=ISO-8859-1&fr;=megaup&p;=
FF - component: c:\documents and settings\Lewis\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll
FF - plugin: c:\documents and settings\Lewis\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\Lewis\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Lewis\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-27 14:51:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2009-03-27 14:54:40
ComboFix-quarantined-files.txt 2009-03-27 17:54:01

Pre-Run: 4,279,439,360 bytes free
Post-Run: 4,358,119,424 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

290 — E O F — 2009-03-13 15:25:25

Please let me know what I should do next. Is it time to try to set my homepage yet? :)
Hi sorrycharlie,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

You have an autorun infection. We'll have to get that under control first then deal with the rest.

I need to know how many USB devices such as flash drives, hard drives, phones, ipod, etc you have.

Some additional instructions for using Flash_Disinfector.

-Hold the Shift Key down when attaching the usb device to the computer. Then run Flash Drive disinfector.
-Do this with each usb device you have.
-Reboot after all drives have been done

Download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder…it will help protect your drives from future infection.




Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    Do Not copy the word CODE note the fix starts with the :
    :Processes
    explorer.exe
    
    :Services
    
    :Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ff0912d-1075-11dd-a062-0014a52449d7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c6a20c-4018-11dd-a0ab-0014a52449d7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69d69b7a-60a1-11dd-a0e0-0014a52449d7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7673fc2-55aa-11dd-a0cf-0014a52449d7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c064000c-3fc1-11dd-a0a9-0014a52449d7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f55566f0-f38c-11dd-a178-0014a52449d7}]
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa1b7f50-1896-11dd-a06a-0014a52449d7}]
    
    :Files
    c:\windows\system32\killVBS.vbs
    
    :Commands
    [Purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Please post back with
  • number of usb devices
  • OTMOVEIT3 log
  • new HJT log

Thanks
Actually, I thought I'd go ahead and try to set my home page again and now it's working fine. It's all fixed. No offense, but I'm tired of installing and running all of these programs just to fix a simple home page issue. Now it's fixed and I'm happy. So that's all I needed. Thanks for all the suggestions. :)

Hi sorrycharlie,

No offence taken, but your home page was the least of your worries. This computer is still infected.


Alright, then. I guess I'll give it a try. Please don't close this thread until I've done so. I promise I'll get to it soon, probably this weekend. It's quite a pain in the tassk trying to re-explain and post links to previously closed threads.
These are the follwing USB devices I use:


I also use a Microsoft LifeCam NX-6000 USB webcam and I use a SanDisk microSD/TransFlash Adapter for my cell phone's SanDisk 1 GB microSD card.

So I ran the Flash Disinfector program for all of my USB drives and then I ran OTMoveIt3. Here is the log from OTMoveIt3:


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0ff0912d-1075-11dd-a062-0014a52449d7}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{52c6a20c-4018-11dd-a0ab-0014a52449d7}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69d69b7a-60a1-11dd-a0e0-0014a52449d7}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b7673fc2-55aa-11dd-a0cf-0014a52449d7}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c064000c-3fc1-11dd-a0a9-0014a52449d7}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f55566f0-f38c-11dd-a178-0014a52449d7}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fa1b7f50-1896-11dd-a06a-0014a52449d7}\\ deleted successfully.
========== FILES ==========
c:\windows\system32\killVBS.vbs moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Lewis\LOCALS~1\Temp\etilqs_21Gn3a2HnNzSfYvwI7dV scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6d4.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Google Gears for Firefox\localserver.db scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Google Gears for Firefox\permissions.db scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04042009_184227

Files moved on Reboot…
File C:\DOCUME~1\Lewis\LOCALS~1\Temp\etilqs_21Gn3a2HnNzSfYvwI7dV not found!
File C:\WINDOWS\temp\Perflib_Perfdata_6d4.dat not found!
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Google Gears for Firefox\localserver.db moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Google Gears for Firefox\permissions.db moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Lewis\Local Settings\Application Data\Mozilla\Firefox\Profiles\op4g881c.default\XUL.mfl moved successfully.


Now, here is the new HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:17 PM, on 4/4/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.2.10\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1208220874359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1208221931375
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} (Active DJ Studio ActiveX Control) - http://www.christianrock2.net/amp3dj.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c8ef3c3f7440de) (gupdate1c8ef3c3f7440de) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

–
End of file - 8389 bytes


I don't know if this affected anything, but when I was trying to do the instructions for the Flash Disinfector, I ran into an unexpected situation. While holding down the shift key and inserting the USB device, I got a pop-up message from Windows saying that holding down the Shift key for eight seconds turns on "FilterKeys." I just clicked "Cancel" and didn't release the Shift key until after I heard the usual "bleep BLEEP" sound when I insert anything into the USB or SD ports. Also, I should note that I didn't insert the USB device until after I ran Flash Disinfector and saw the message asking me to insert the device - not before running Flash Disinfector. Please let me know if I did something wrong or if there's anything else I need to do. Thanks!
Hi sorrycharlie,

Flash Drive Disinfector will work in a couple of ways. 1. if a Usb storage device is attached it will run and add the good autorun.inf to the drive. 2. If none are detected, it will ask, then run.

What you did should be fine.

Have a look in the root of these drives for a file called killvbs.vbs, delete it if found and empty your recycle bin.

SanDisk Cruzer Micro 2 GB
SanDisk Cruzer Mini 128 MB
Western Digital Combo (USB/Firewire) External Drive 300 GB
cell phone's SanDisk 1 GB microSD



Is your homepage still ok?


Something to consider…

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.



Viewpoint Manager is considered as foistware instead of malware since it is often installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware
It is STRONGLY recommended that you remove the Viewpoint products; however, decide for yourself. To uninstall the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):

  1. Click Start, then Settings, then click Control Panel.
  2. In Control Panel, double-click Add or Remove Programs.
  3. In Add or Remove Programs, Remove the Viewpoint component
  4. Do the same for each Viewpoint component.




  5. Let me know how you made out and we'll clean up the tools.

    Thansk
oldman, Thanks for the tips. I uninstalled the Viewpoint Media Player. It was the only Viewpoint product listed in the Add/Remove Programs list. I also searched all of the USB drives and the one microSD card for the killvbs.vbs file, but I didn't find it on any of them. Something's not right about the Flash_Disinfector, though. I just did a search on all of the drives that I ran Flash_Disinfector for, to see if it actually installed the autorun.inf, but I didn't find it on any of the drives. What do you think could have happend? It seemed like it worked because my screen went "blank" like it said (except for the wallpaper) and then it said it was "Done." But if it worked, then they should all have autorun.inf on them, right? Also, my home page is still good. :)
Hi sorrycharlie,

the autorun.inf is a hidden file.

At the top of windows explorer, click tools, folder options, click the
view tab
  • check Display the contents of system folders
  • check Show hidden files and folders
  • uncheck "Hide extensions for known file types" box
  • uncheck "Hide protecting operating system files" box
Click apply, click ok


After you have finished,
  • check Display the contents of system folders
  • uncheck Show hidden files and folders
  • check "Hide extensions for known file types" box
  • check "Hide protecting operating system files" box
Click apply, click ok


A bit more to do

Go to add remove programs and uninstall this program if present

TS Webclient


Use OTMOVEIT3 again with this fix

:Processes
explorer.exe

:Services

:Reg

:Files
c:\program files\Viewpoint
C:\Program Files\TS Webclient

:Commands
[start explorer]
[Reboot]


I don't see an active antivirus program installed. Windows Defender is not an antivirus program.

Download and install one of these free antivirus programs. Do a full system scan afterwards.


Avast
Help and support can be found here Avast Forum
AVG
Help and support can be found here AVG Forum
Antivir PersonalEditionClassic
Help and support can be found hereAvira Personal Support Forum


Post back with
  • OTMOVEIT3 log
  • new HJT log

I will be off line untill tomorrow night.

Thanks
I knew that autorun.inf was a hidden file, so I did what you suggested the first time I searched for it, but it's not there. I am going to install AVG 8.0 free edition as soon as we get the rest of this taken care of. I'll go check on the TS Webclient now and report back with those logs you asked for once I'm done. Thanks again for the help. :)
Hi sorrycharlie, Don't know why the autorun.inf isn't there. You can try FDD again. The system appears to be clean, so go ahead with AVG8. We'll clean up after you reply back.
Here's the new OTMoveIt log:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File/Folder c:\program files\Viewpoint not found.
C:\Program Files\TS Webclient moved successfully.
========== COMMANDS ==========
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04052009_154535


And here's the new HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:57 PM, on 4/5/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\Webshots\Webshots.scr
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Cooliris Plug-In for Internet Explorer - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files\PicLensIE\cooliris.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Lewis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [iLike] C:\Program Files\iLike\1.2.10\ilikesidebar.exe /checkforupdate (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Startup: Yahoo! Widgets.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.4.2\gears.dll
O9 - Extra button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files\PicLensIE\cooliris.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1208220874359
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1208221931375
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} (Active DJ Studio ActiveX Control) - http://www.christianrock2.net/amp3dj.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c8ef3c3f7440de) (gupdate1c8ef3c3f7440de) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe

–
End of file - 8262 bytes

Hi sorrycharlie,

Looks good. Any problems? If not we can clean up the tools we used including the ones you may have from your other threads.

From your desktop, please delete
  • any notepads/logs that we created
  • Rooter.exe

FDD, your choice. You may find it useful to keep. If you do not want it, it can be deleted.



In windows explorer, please delete this folder

c:\\Rooter$



Next
Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u



Open OTMOVEIT3 then click the Clean Up button. You may get prompted by your firewall that OTMOVEIT3 wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep ATF and MBAM. Keep MBAM updated and use both regularly.



Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update



***Install your antivirus progeam ASAP and do a full scan. The longer you wait, the greater the risk of getting infected.***



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. With the addition of MBAM and installing a firewall you would have the basics covered.

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for tips, reviews and links to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879



We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI