This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Very wierd never seen this before

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have a college students laptop here trying to fix it for her. Had trend on it and still got a virus. I loaded Kaspersky on it and had to do a manual update since the comuter will not connect to the interenet. I can connect to my wireless router via wifi and a cable but I do not get an IP address. If I try and use cmd or regedit it locks exlplorer up for a minute and then it comes back. At random times there is a loud system bee and the whole system locks up. Have to reboot to use the computer again. IE 8 (only browser installed) will not show any page at all but wants to run a tool to fix the problem. It always wants to fix the winsock files. I did this but still no go. I have deleted all the files in IE, and the local temp files on the computer exept a few that are locked and will not allow me to delete them (ie: DF7FE.tmp), plus all the refetch files. Below I am listing my HT log and the log from kaspersky showing what was on the pc. Thanks for the any help. She has a major week long seminar after this coming weekend and I am sure she would love to have her computer working if possible. (all restore disks for this dell are in NC and we are currently in NB)

THANKS!


HT Log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:31:12 AM, on 4/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Safe mode

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\Iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3061211
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DLCFCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCFtime.dll,RunDLLEntry
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Banner Ad Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {6F714D46-E4EF-11D4-93EF-00D0D7032099} (Active DJ Studio ActiveX Control) - http://www.christianrock2.net/amp3dj.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://www.walmartphotocentre.ca/upload/ac…upv2.0.0.11.cab?
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~2\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
O23 - Service: dlcf_device - - C:\WINDOWS\system32\dlcfcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Unknown owner - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe (file missing)
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 8340 bytes


XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX


Kaspersky Log:
Full Scan: completed 4/21/2009 10:02:53 PM (events: 40, objects: 350036, time: 01:23:14)
4/21/2009 8:39:39 PM Task started
4/21/2009 8:40:19 PM Detected: http://www.viruslist.com/en/advisories/27361 C:\Program Files\Real\RealPlayer\RealPlay.exe
4/21/2009 8:42:48 PM Detected: http://www.viruslist.com/en/advisories/32991 C:\Program Files\java\jre1.5.0_06\bin\javaws.exe
4/21/2009 8:42:58 PM Detected: http://www.viruslist.com/en/advisories/27361 C:\Program Files\Real\RealPlayer\RealPlay.exe
4/21/2009 8:43:50 PM Detected: http://www.viruslist.com/en/advisories/33632 C:\Program Files\quicktime\quicktimeplayer.exe
4/21/2009 8:43:52 PM Detected: http://www.viruslist.com/en/advisories/34451 C:\windows\system32\java.exe
4/21/2009 8:50:21 PM Detected: Rootkit.Win32.Agent.fub C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP245\A0088282.sys
4/21/2009 8:50:21 PM Untreated: Rootkit.Win32.Agent.fub C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP245\A0088282.sys Postponed
4/21/2009 8:50:22 PM Detected: Rootkit.Win32.Agent.fwt C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP245\A0088281.sys
4/21/2009 8:50:22 PM Untreated: Rootkit.Win32.Agent.fwt C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP245\A0088281.sys Postponed
4/21/2009 9:18:29 PM Detected: Packed.Win32.Tdss.f C:\Documents and Settings\Heather Kivett\Local Settings\Temporary Internet Files\Content.IE5\VYK2MNH2\tomi[1].htm
4/21/2009 9:18:30 PM Untreated: Packed.Win32.Tdss.f C:\Documents and Settings\Heather Kivett\Local Settings\Temporary Internet Files\Content.IE5\VYK2MNH2\tomi[1].htm Postponed
4/21/2009 9:24:52 PM Detected: http://www.viruslist.com/en/advisories/32270 C:\i386\Flash.ocx
4/21/2009 9:25:23 PM Detected: http://www.viruslist.com/en/advisories/34451 C:\i386\java.exe
4/21/2009 9:25:23 PM Detected: http://www.viruslist.com/en/advisories/32991 C:\i386\javaws.exe
4/21/2009 9:31:35 PM Detected: http://www.viruslist.com/en/advisories/33901 C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.dll
4/21/2009 9:34:43 PM Detected: http://www.viruslist.com/en/advisories/26027 C:\Program Files\Common Files\AOL\Flasha.ocx
4/21/2009 9:40:20 PM Detected: http://www.viruslist.com/en/advisories/32991 C:\Program Files\java\jre1.5.0_06\bin\javaws.exe
4/21/2009 9:40:20 PM Detected: http://www.viruslist.com/en/advisories/34451 C:\Program Files\java\jre1.5.0_06\bin\java.exe
4/21/2009 9:44:41 PM Detected: http://www.viruslist.com/en/advisories/33632 C:\Program Files\quicktime\quicktimeplayer.exe
4/21/2009 9:44:42 PM Detected: http://www.viruslist.com/en/advisories/27361 C:\Program Files\Real\RealPlayer\RealPlay.exe
4/21/2009 9:45:35 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\devicemgrplugin.dll
4/21/2009 9:45:35 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\cdplayer.dll
4/21/2009 9:45:36 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\mmatch.dll
4/21/2009 9:45:36 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\lcradio.dll
4/21/2009 9:45:37 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\mylibrary.dll
4/21/2009 9:45:38 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\musicnet.dll
4/21/2009 9:45:38 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\playlist.dll
4/21/2009 9:45:39 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe
4/21/2009 9:45:40 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\upnpnetwork.dll
4/21/2009 9:45:40 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Plugins\ympmsgr.dll
4/21/2009 9:45:49 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Support\ratectrl.dll
4/21/2009 9:45:49 PM Detected: http://www.viruslist.com/en/advisories/28757 C:\Program Files\Yahoo!\Yahoo! Music Jukebox\Support\datagrid.dll
4/21/2009 10:00:05 PM Detected: http://www.viruslist.com/en/advisories/34451 C:\windows\system32\java.exe
4/21/2009 10:00:05 PM Detected: http://www.viruslist.com/en/advisories/32991 C:\windows\system32\javaws.exe
4/21/2009 10:01:33 PM Detected: http://www.viruslist.com/en/advisories/34012 C:\windows\system32\Macromed\Flash\Flash10a.ocx
4/21/2009 10:01:58 PM Detected: http://www.viruslist.com/en/advisories/23655 C:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9841.0_x-ww_18171213\msxml4.dll
4/21/2009 10:01:58 PM Detected: http://www.viruslist.com/en/advisories/23655 C:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.1.0.0_x-ww_b319d8da\msxml4.dll
4/21/2009 10:01:59 PM Detected: http://www.viruslist.com/en/advisories/23655 C:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9848.0_x-ww_1b897e9a\msxml4.dll
4/21/2009 10:02:55 PM Task completed
Hi Spurge13,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Scroll down to where it says "JRE 6 Update 13.
  • Click the "Download" button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u13-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are two options in the window to clear the cache - Leave both Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI