This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] hijacked browser (vista) cant open anti-malware softwa

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think my laptop has a virus b/c when I click my browser (Firefox) results, I am redirected to another website/ad. The back button only takes me to yet another unrelated website/ad. To fix it, I have done the following so far: (since my laptop browser started saying it "could not find the host server for provided address" of the following two downloads, I downloaded them to a jumpdrive using my Desktop PC, then i downloaded them to my laptop from the jumpdrive… i hope this makes sense!) 1. Downloaded - ATF Cleaner and run from the executable, with Admin Rights as directed 2. Downloaded Malwarebytes' Anti-Malware to my desktop ran it as administrator, followed the prompts to install the program, and made sure Update Malwarebytes' Anti- Malware and Launch Malwarebytes' Anti-Malware were checked before clicking Finish. Now when I clicked Finish, the program did not auto launch… I tried double clicking the icon, i tried right clicking the icon and both times I got a window informing me that "Malwarebytes' Anti-Malware has stopped working correctly. Windows will close the program and notify you if a solution is available." When I click the only button available (Close program) the window goes away and nothing happens…
Thanks for the bombard of help responses (sigh). Not that anyone cares, but I was able to open the anti-malware software by re-naming the exe files.
Hello.

My name is Extremeboy and I will help you with your problem.

We will start off with Combofix. Please read instructions on transferring it from another computer to the infected one.

Download and Run ComboFix Through A CD's/Flash-Drive

Download the tools needed to a flash drive or other removable media, and transfer them to the infected computer. It would be better if you can use some spare CD's and a CD burner to avoid infection going onto your clean machine. If you are going to use a removable drive, please run the following tool on your clean machine first.

Download and Run FlashDisinfector

  • Please download Flash_Disinfector.exe by sUBs and save it to your desktop.
  • Double-click Flash_Disinfector.exe to run it and follow any prompts that may appear.
  • The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
  • Wait until it has finished scanning and then exit the program.
  • Reboot your computer when done.
Note: Flash_Disinfector will create a hidden file named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.

***************************************************

Download Combofix

Download Combofix from any of the links below, and save it to your desktop.

Link 1
Link 2
Link 3

**Note: It is important that it is saved directly to your desktop**

Transfer the programs via CD/Removable Drive

Transfer all files you just downloaded, to the desktop of the infected computer.

A complete guide on using and running Combofix can be found over here. I suggest you read it since you are using a Vista Machine.
——————————————————————–

Run Combofix

  • Disable your AntiVirus and AntiSpyware applications before running Combofix!. This can be usually done via a right click on the System Tray icon. If not disabled they may otherwise interfere with our tools. Refer to this page if you are not sure how.
  • Close any open windows, including this one.
  • Double click on ComboFix.exe & follow the prompts.
  • Follow the prompts to start and run ComboFix.

    [external image: Posted Image]
  • At the next prompt, click 'Yes' to run the full ComboFix scan.
  • When the tool is finished, it will produce a report for you.
Please post the C:\ComboFix.txt in your next reply.

Note: Please Do NOT mouseclick combofix's window while its running because it may call it to stall.

Let me know how it goes and post the Combofix log in your next reply.

With Regards,
Extremeboy
Thanks for the help Extremeboy!
I did as you said, but when I double clicked the ComboFix.exe icon, I didnt have to follow any prompts, it just ran, and then produced the C:\ComboFix.txt report…. I was expecting to see the following window, but it never popped up.

http://img.photobucket.com/albums/v706/ried7/whatnext.png

I hope I did everything okay… I disabled Windows Defender as the link you provided suggested…. Anyway, here is my C:\ComboFix.txt report/log (I also attached it in case i didnt paste it correctly ie. remove wrap text etc.):


ComboFix 09-04-27.02 - Us 04/27/2009 15:50.5 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1013.317 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-4-27 )))))))))))))))))))))))))))))))
.

2009-04-27 05:17 . 2009-04-27 05:17 ——– d—–w c:\users\Us\AppData\Local\Adobe
2009-04-26 21:14 . 2009-04-06 22:32 15504 —-a-w c:\windows\system32\drivers\mbam.sys
2009-04-26 21:14 . 2009-04-06 22:32 38496 —-a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-26 21:14 . 2009-04-26 23:33 ——– d—–w c:\program files\Malwarebytes' Anti-Malware
2009-04-24 04:51 . 2009-04-24 04:51 ——– d—–w c:\program files\Common Files\Adobe AIR
2009-04-24 04:48 . 2009-04-24 04:48 ——– d—–w c:\users\Us\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-04-15 21:51 . 2008-12-06 04:42 376832 —-a-w c:\windows\system32\winhttp.dll
2009-04-15 21:51 . 2008-06-06 03:27 562176 —-a-w c:\windows\system32\msdtcprx.dll
2009-04-15 21:51 . 2008-06-06 03:27 38912 —-a-w c:\windows\system32\xolehlp.dll
2009-04-14 02:26 . 2009-04-14 02:26 ——– d—–w c:\users\Us\AppData\Roaming\SanDisk
2009-03-30 02:44 . 2008-06-20 01:14 97800 —-a-w c:\windows\system32\infocardapi.dll
2009-03-30 02:44 . 2008-06-20 01:14 105016 —-a-w c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-03-30 02:44 . 2008-06-20 01:14 622080 —-a-w c:\windows\system32\icardagt.exe
2009-03-30 02:44 . 2008-06-20 01:14 11264 —-a-w c:\windows\system32\icardres.dll
2009-03-30 02:44 . 2008-06-20 01:14 43544 —-a-w c:\windows\system32\PresentationHostProxy.dll
2009-03-30 02:44 . 2008-06-20 01:14 781344 —-a-w c:\windows\system32\PresentationNative_v0300.dll
2009-03-30 02:44 . 2008-06-20 01:14 326160 —-a-w c:\windows\system32\PresentationHost.exe
2009-03-30 02:37 . 2008-07-27 18:03 96760 —-a-w c:\windows\system32\dfshim.dll
2009-03-30 02:37 . 2008-07-27 18:03 282112 —-a-w c:\windows\system32\mscoree.dll
2009-03-30 02:37 . 2008-07-27 18:03 41984 —-a-w c:\windows\system32\netfxperf.dll
2009-03-30 02:37 . 2008-07-27 18:03 158720 —-a-w c:\windows\system32\mscorier.dll
2009-03-30 02:37 . 2008-07-27 18:03 83968 —-a-w c:\windows\system32\mscories.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-27 21:09 . 2006-12-07 03:15 12 —-a-w c:\windows\bthservsdp.dat
2009-04-26 19:47 . 2007-02-04 22:30 ——– d—–w c:\program files\Trend Micro
2009-04-25 06:43 . 2007-09-07 01:41 1356 —-a-w c:\users\Us\AppData\Local\d3d9caps.dat
2009-04-25 05:45 . 2006-12-07 04:35 ——– d—–w c:\program files\Java
2009-04-16 10:07 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-08 04:42 . 2007-02-06 19:11 4468 —-a-w c:\users\Us\AppData\Roaming\wklnhst.dat
2009-04-04 16:01 . 2007-02-06 23:44 ——– d—–w c:\program files\LimeWire
2009-03-17 03:38 . 2009-04-15 21:50 40960 —-a-w c:\windows\AppPatch\apihex86.dll
2009-03-17 03:38 . 2009-04-15 21:50 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 21:50 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-03 04:46 . 2009-04-15 21:50 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 21:50 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:39 . 2009-04-15 21:50 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 21:50 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 21:50 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 21:50 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 21:50 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 21:50 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 21:50 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 21:50 17408 —-a-w c:\windows\system32\iashost.exe
2009-02-16 18:43 . 2009-02-16 18:44 410984 —-a-w c:\windows\system32\deploytk.dll
2009-02-13 08:49 . 2009-04-15 21:50 72704 —-a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-15 21:50 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-02-10 03:42 . 2007-02-05 12:48 123304 —-a-w c:\users\Us\AppData\Local\GDIPFONTCACHEV1.DAT
2009-02-09 05:52 . 2006-11-02 12:50 174 –sha-w c:\program files\desktop.ini
2009-02-09 05:49 . 2006-11-02 10:25 86016 —-a-w c:\windows\inf\infstor.dat
2009-02-09 05:49 . 2006-11-02 10:25 51200 —-a-w c:\windows\inf\infpub.dat
2009-02-09 05:49 . 2006-11-02 10:25 143360 —-a-w c:\windows\inf\infstrng.dat
2009-02-09 05:41 . 2006-11-02 10:25 665600 —-a-w c:\windows\inf\drvindex.dat
2009-02-09 03:10 . 2009-03-11 05:24 2033152 —-a-w c:\windows\system32\win32k.sys
2009-02-08 05:43 . 2006-11-02 10:32 101888 —-a-w c:\windows\system32\ifxcardm.dll
2009-02-08 05:43 . 2006-11-02 10:32 82432 —-a-w c:\windows\system32\axaltocm.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-04-27_21.17.42 )))))))))))))))))))))))))))))))))))))))))
.
+ 2006-11-02 13:05 . 2009-04-27 21:30 63982 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-02-05 12:44 . 2009-04-27 21:30 8396 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2408971179-2623291522-433246010-1000_UserData.bin
- 2009-04-27 21:10 . 2009-04-27 21:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-04-27 21:10 . 2009-04-27 21:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-04-27 21:10 . 2009-04-27 21:10 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-04-27 21:10 . 2009-04-27 21:29 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2006-11-02 10:33 . 2009-04-27 21:16 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-04-27 21:57 595684 c:\windows\System32\perfh009.dat
+ 2006-11-02 10:33 . 2009-04-27 21:57 101350 c:\windows\System32\perfc009.dat
- 2006-11-02 10:33 . 2009-04-27 21:16 101350 c:\windows\System32\perfc009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
"SansaDispatch"="c:\users\Us\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe" [2009-04-14 79872]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-11-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-11-06 106496]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-11-06 81920]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2006-11-28 46704]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"pccguide.exe"="c:\program files\Trend Micro\Antivirus\pccguide.exe" [2004-02-17 950337]
"PCClient.exe"="c:\program files\Trend Micro\Antivirus\PCClient.exe" [2004-02-17 634949]
"TM Outbreak Agent"="c:\program files\Trend Micro\Antivirus\TMOAgent.exe" [2004-02-17 290816]
"TheRecordNavigatorDetector"="c:\program files\FTR\ForTheRecord\TheRecordNavigatorDetector.exe" [2008-05-22 56448]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2006-12-07 77824]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Connections.lnk - c:\program files\HP Connections\6811507\Program\HP Connections.exe [2006-12-6 34520]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.exe

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C13CFDF4-CBF6-4003-98CB-D85726E3BAF7}"= UDP:c:\program files\HP\QuickPlay\QP.exe:QP
"{5818DBE5-366B-489D-A300-E585B9C7BDE9}"= TCP:c:\program files\HP\QuickPlay\QP.exe:QP
"{AB81B409-7B9F-408D-9B33-E96B91D8CB21}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{12023DF5-9536-466B-875C-D304A8E43358}"= c:\program files\HP Connections\6811507\Program\HP Connections:HP Connections
"{D46F40E2-4C1B-40A9-A14E-05A062C7B768}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{A0EAA65B-0587-4688-B2E6-1D6BABC56EEB}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{B42D76BF-F458-4F8D-9A3F-30C70AC87D25}"= UDP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{17838E49-6A14-4578-AF49-3BF1DF102A21}"= TCP:c:\program files\HP Connections\6811507\Program\HP Connections.exe:HP Connections
"{7CAE62A9-C5EB-409E-B8A5-4BF75325F57D}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{FC38138A-F5F0-4A80-99C5-E52E6B2A22EF}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{BAB02D40-EBE2-4DC7-A088-26646FB71A42}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{C2612C67-E1C2-4BB9-B87C-CA49121425D1}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{63738A1A-B8B7-46D7-A818-11184BE082CF}"= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{185679C1-42EC-44AA-9F90-BEFE26CD1532}"= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
"TCP Query User{565D91DD-35D8-4D9F-891B-DCBBBF79F721}c:\\stubinstaller.exe"= UDP:C:\stubinstaller.exe:LimeWire swarmed installer
"UDP Query User{2F493D53-5A4A-4275-BB92-986C0D191612}c:\\stubinstaller.exe"= TCP:C:\stubinstaller.exe:LimeWire swarmed installer
"{F72816A6-795A-4835-BB61-6AC3C5C0F101}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{DD0C72A1-ED73-4D20-AEE9-779F3D4B9766}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{A10722D7-A0E7-4DBB-A5A1-08073AE1AF1E}c:\\program files\\world of warcraft\\wow-2.0.3-enus-downloader.exe"= UDP:c:\program files\world of warcraft\wow-2.0.3-enus-downloader.exe:Blizzard Downloader
"UDP Query User{0E225EB0-224C-445A-9426-4E1C08621AA2}c:\\program files\\world of warcraft\\wow-2.0.3-enus-downloader.exe"= TCP:c:\program files\world of warcraft\wow-2.0.3-enus-downloader.exe:Blizzard Downloader
"TCP Query User{B8D6AE71-925A-44FE-9A95-7AD526868D07}c:\\program files\\world of warcraft\\wow-2.0.3.6299-to-2.0.12.6546-enus-downloader.exe"= UDP:c:\program files\world of warcraft\wow-2.0.3.6299-to-2.0.12.6546-enus-downloader.exe:Blizzard Downloader
"UDP Query User{18B0FEF8-8244-4530-BF17-C3E7AC432359}c:\\program files\\world of warcraft\\wow-2.0.3.6299-to-2.0.12.6546-enus-downloader.exe"= TCP:c:\program files\world of warcraft\wow-2.0.3.6299-to-2.0.12.6546-enus-downloader.exe:Blizzard Downloader
"TCP Query User{11567300-CFFA-4561-B5A1-7063B1E3B34F}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{843E3C96-519E-4897-93AF-56400B33572C}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{0504A697-A420-4A56-BF1F-DD09669BBA4B}c:\\users\\us\\desktop\\wow-burningcrusade-enus-installer-downloader.exe"= UDP:c:\users\us\desktop\wow-burningcrusade-enus-installer-downloader.exe:wow-burningcrusade-enus-installer-downloader.exe
"UDP Query User{7A19155F-CC41-4952-B9BC-FAF2D4E4AEDB}c:\\users\\us\\desktop\\wow-burningcrusade-enus-installer-downloader.exe"= TCP:c:\users\us\desktop\wow-burningcrusade-enus-installer-downloader.exe:wow-burningcrusade-enus-installer-downloader.exe
"TCP Query User{91978037-9DFB-48D6-9058-681D2BA80F09}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{F8FC7120-C873-4546-A18F-4791CC4DF440}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"{860E3446-E24C-4C57-9358-C369575C3633}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{9DA2888B-BE93-4917-AE53-3A9B6B034766}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B92CA60E-FFF4-45FD-B164-F2B3F8001226}"= c:\program files\MySpace\IM\MySpaceIM.exe:MySpaceIM

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe"= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

R2 Tmntsrv;Trend NT Realtime Service;c:\program files\Trend Micro\Antivirus\Tmntsrv.exe [2004-02-17 241737]
S2 Tmfilter;Tmfilter;c:\windows\system32\drivers\TmXPFlt.sys [2007-06-29 203024]
S2 Tmpreflt;Tmpreflt;c:\windows\system32\drivers\Tmpreflt.sys [2007-06-29 36112]
S2 tmproxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Antivirus\tmproxy.exe [2004-02-17 204873]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2009-04-18 c:\windows\Tasks\HPCeeScheduleForUs.job
- c:\program files\hewlett-packard\sdp\ceement\HPCEE.exe [2006-12-07 00:08]

2009-04-27 c:\windows\Tasks\User_Feed_Synchronization-{E55847F3-5AB0-4E21-BE4A-0DB7DBD410BA}.job
- c:\windows\system32\msfeedssync.exe [2008-10-20 10:05]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=laptop
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\Corel\WordPerfect Office X4\Programs\WPLauncher.hta
Trusted Zone: az.gov\secure
Trusted Zone: azui.com
DPF: {B030900C-746A-47BF-8B1D-EA3FB3395563} - hxxps://fastconnect.cox.net/cd20/CoxFastConnect20.ocx
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-27 15:52
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
SansaDispatch = c:\users\Us\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe?on%2fSansaDispatch_1_009.txt&certificate-url=https%3a%2f%2ff?3ftype%

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10a.exe,-101"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\Elevation]
"Enabled"=dword:00000001

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10a.exe"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{0BE09CC1-42E0-11DD-AE16-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}]
@Denied: (A 2) (Everyone)
@SACL=
@="FlashProp Class"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\InprocServer32]
@SACL=
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash9b.ocx"
"ThreadingModel"="Apartment"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{1171A62F-05D2-11D1-83FC-00A0C9089C5A}\Programmable]
@SACL=

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10a.ocx"
"ThreadingModel"="Apartment"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10a.ocx, 1"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10a.ocx"
"ThreadingModel"="Apartment"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\system32\\Macromed\\Flash\\Flash10a.ocx, 1"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}]
@Denied: (A 2) (Everyone)
@SACL=
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9b.exe,-101"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\Elevation]
@SACL=
"Enabled"=dword:00000001

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\LocalServer32]
@SACL=
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil9b.exe"

[HKEY_USERS\SOFTWARE\Classes\CLSID\{D4304BCF-B8E9-4B35-BEA0-DC5B522670C2}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_USERS\SOFTWARE\Classes\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}]
@Denied: (A 2) (Everyone)
@SACL=
@="IFlashBroker"

[HKEY_USERS\SOFTWARE\Classes\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\ProxyStubClsid32]
@SACL=
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_USERS\SOFTWARE\Classes\Interface\{2E4BB6BE-A75F-4DC0-9500-68203655A2C4}\TypeLib]
@SACL=
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_USERS\SOFTWARE\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}]
@Denied: (A 2) (Everyone)
@="IFlashBroker2"

[HKEY_USERS\SOFTWARE\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_USERS\SOFTWARE\Classes\Interface\{DDF4CE26-4BDA-42BC-B0F0-0E75243AD285}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@SACL=

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
@SACL=
@="Shockwave Flash"

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
@Denied: (A 2) (Everyone)
@SACL=
@=""

[HKEY_USERS\SOFTWARE\Classes\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
@SACL=
@="FlashBroker"

[HKEY_USERS\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_USERS\SYSTEM\ControlSet003\Services\gxvxcserv.sys]
@DACL=(02 0000)
"start"=dword:00000001
"type"=dword:00000001
"group"="file system"
"imagepath"=expand:"\\systemroot\\system32\\drivers\\gxvxcyxxjrbibwncfgwpfawddirdhtrhqoutq.sys"
.
Completion time: 2009-04-27 15:53
ComboFix-quarantined-files.txt 2009-04-27 22:53
ComboFix2.txt 2009-04-27 21:46
ComboFix3.txt 2009-04-27 21:38
ComboFix4.txt 2009-04-27 21:19

Pre-Run: 76,261,105,664 bytes free
Post-Run: 76,236,300,288 bytes free

321 — E O F — 2009-04-27 14:19

Attachments:

Hello.

…. I was expecting to see the following window, but it never popped up.

Yeah, it's not suppose to since you are using a Vista OS. I remember me removing that picture before posting… Strange, must of slipped then..

I see that Combofix was ran 5 times!! I told you only to run it once. Not more than that… Next time, only run it once. If you have any problems. ASK.

I see an indication of a rootkit. Please note on rootkits.

[external image: Posted Image]Backdoor Threat

IMPORTANT NOTE: Unfortunatly One or more of the identified infections is a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do.

I would like to see the FIRST Combofix log. Please navigate to C:\Qoobox and find the text file called ComboFix4.txt.

Post that log in your next reply, unless you want to format.

With Regards,
Extremeboy
Hello.

Good decision. Below are some prevention tips. Good luck next time!

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users.

Disable Autorun on Flash-Drive/Removable Drives

When is AUTORUN.INF really an AUTORUN.INF?

USB worms work by creating a file called AUTORUN.INF on the root of USB drives. These INF files then use Autorun or Autoplay (not the same thing!) to execute themselves either when the stick is inserted, or more commonly, when the user double-clicks on the USB drive icon from My Computer (Windows Explorer)…


Keeping Autorun enabled on USB and other removable drives has become a significant security risk due to the increasing number of malware variants that can infect them and transfer the infection to your computer. Read USB-Based Malware Attacks and Please disable Autorun asap!.

If using Windows Vista, please refer to:
"Disable AutoPlay in Windows Vista"
"Preventing AutoPlay with Local Group Policy Editor or AutoPlay options panel"

Note: When Autorun is disabled, double-clicking a drive which has autorun.inf in its root directory may still activate Autorun so be careful.

Vist the WindowsUpdate Site Regularly

I recommend you regularly visit the Windows Update Site!
  • Lots of Hacking/Trojans use the methods found (plugged by the updates) that have not been stopped by people not updating.
  • Update ALL Critical updates and any other Windows updates for services/programs that you use.
  • If you wish to turn on automatic updates then you will find here is a nice little article about turning on automatic updates.
  • Note that it will download them for you, but you still have to actually click install.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.

Update all programs regularly - Make sure you update all the programs you have installed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Follow this list and your potential for being infected again will reduce dramatically.
Finally, and definitely the MOST IMPORTANT step, click on the following tutorial and follow each step listed there:

Simple and easy ways to keep your computer safe and secure on the Internet


With Regards,
Extremeboy
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI