This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser hack/Virus issue

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have had my IE browser hacked after receipt of a bogus e-mail from a Facebook friend. I now get random pop-ups from a porn site and from a security site advising that I have been infected and trying to get me to run a scan which will start on it's own if I don't X out of the screen. I have McAfee Security AV/Anti-spyware program that is current but cannot find or remove the problem.

*Edit* Forgot to add, tried an on-line scan at both TrendMicro and Kaspersky (sp), both indicated errors and ultimately failed to launch.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:15:22 AM, on 6/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\SafeBoot\SbClientManager.exe
C:\Program Files\Network ICE\BlackICE\blackd.exe
C:\WINDOWS\System32\bmwebcfg.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
c:\Program Files\2173_Fiberlink\Fgrd.exe
C:\Program Files\Java\jre6\bin\jqs.exe
c:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\Pistolstar\Password Power Client\psservice.exe
c:\swd\pkgsvc.exe
C:\WINDOWS\System32\hpzipm12.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\Program Files\Network ICE\BlackICE\RapApp.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network ICE\BlackICE\vpatch.exe
c:\Program Files\Orchestria\Active Policy Management\system\wgninfra.exe
C:\WINDOWS\System32\acs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\Common Framework\udaterui.exe
C:\WINDOWS\system32\TpShocks.exe
C:\tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe
C:\WINDOWS\system32\SKDAEMON.EXE
C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\Orchestria\Active Policy Management\client\wgncm.exe
C:\Program Files\Network Associates\Common Framework\McTray.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINDOWS\system32\WhatsIn\wiAgent.exe
C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe
C:\windows\pp10.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/def…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://inside.here.travp.net/intraHome/index.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://inside.here.travp.net/intraHome/index.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/def…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by The Travelers Companies, Inc.
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Class Description 1 - {521FDCA1-D5C5-11D4-B613-000102027BBB} - C:\Program Files\Orchestria\Active Policy Management\client\WgnBrie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: IE_Bridge Class - {802358C8-A984-4CC2-B900-92BDF4EA1686} - c:\winnt\iebridge.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [lcfep] "c:\tivoli\lcf\bin\w32-ix86\mrt\lcfep.exe"
O4 - HKLM\..\Run: [Hot Key Kbd Daemon] SKDAEMON.EXE
O4 - HKLM\..\Run: [QCWLIcon] C:\PROGRA~1\ThinkPad\CONNEC~1\QCWLIcon.exe
O4 - HKLM\..\Run: [ShStatEXE] "c:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Orchestria APM Client] C:\Program Files\Orchestria\Active Policy Management\client\wgncm.exe
O4 - HKLM\..\Run: [SwdisUsrPCN.lp3cx101-642638] "c:\Tivoli\lcf\dat\1\cache\lib\w32-ix86\wdusrpcn.exe" "c:\Tivoli\swdis\2\wdusrpcn.envlp3cx101-642638"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [dg] C:\WINDOWS\system32\WhatsIn\whatsinagent.exe
O4 - HKLM\..\Run: [dga] C:\WINDOWS\system32\WhatsIn\wiAgent.exe
O4 - HKLM\..\Run: [SafeBootTrayManager] "C:\Program Files\SafeBoot Tray Manager\SbTrayManager.exe"
O4 - HKLM\..\Run: [sysldtray] C:\windows\ld08.exe
O4 - HKLM\..\Run: [pp] C:\windows\pp10.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [EntInv] wscript //nologo "c:\utils\logonscripts\nethood_claim.vbs" \\gporeports.prod.travp.net\gporpts$\inventory\ISSInven
O4 - HKCU\..\Policies\Explorer\Run: [1] c:\temp\logoncmds_applimp.cmd
O4 - Startup: layout3host.elf
O4 - User Startup: layout3host.elf
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: EditHosts_SS.lnk = ?
O4 - Global Startup: RunClmupdate.cmd
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\jp2iexp.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O10 - Unknown file in Winsock LSP: bmnet.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://inside.here.travp.net/intraHome/index.aspx
O15 - Trusted Zone: http://glassmateqa.emitchell.com
O15 - Trusted Zone: *.ftico.com
O15 - Trusted Zone: *.ftico.local
O15 - Trusted Zone: http://*.travelers.com
O16 - DPF: WebConnect Pro 6.5.8 - http://hostaccess.prod.travp.net:2041/WebConnectDU.cab
O16 - DPF: WebConnect Pro 7.0.1 - http://hostaccess.prod.travp.net:2041/WebConnectDU.cab
O16 - DPF: {03A89EFD-E023-8600-A22D-45F77558EB4C} (ILINCInstall86 Class) - http://learnlinc.prodlb.travp.net/download/ilinci86.dll
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - http://pkx1.prodlb.travp.net/qp2.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = prod.travp.net
O17 - HKLM\Software\..\Telephony: DomainName = prod.travp.net
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = prod.travp.net
O18 - Filter: application/x-vs-authtoken - {1F17617E-C296-4C16-89E3-E22C6C454645} - c:\Program Files\Common Files\Voltage Security\VSTokenHandler.dll
O23 - Service: ACU Configuration Service (ACS) - Unknown owner - C:\WINDOWS\System32\acs.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\blackd.exe
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\System32\bmwebcfg.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: FGR Service - Fiberlink Communications Corporation - c:\Program Files\2173_Fiberlink\Fgrd.exe
O23 - Service: hdlSrv - Unknown owner - C:\WINDOWS\system32\hdlsrv.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - c:\Tivoli\lcf\bin\w32-ix86\mrt\lcfd.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pistolstar SSO - Unknown owner - C:\Program Files\Pistolstar\Password Power Client\psservice.exe
O23 - Service: TivPkgInstaller (pkgsvc) - Unknown owner - c:\swd\pkgsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\hpzipm12.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\RapApp.exe
O23 - Service: SafeBoot Client Manager (SafeBootClientManager) - McAfee, Inc. - C:\Program Files\SafeBoot\SbClientManager.exe
O23 - Service: ISS Buffer Overflow Exploit Prevention (VPatch) - Internet Security Systems, Inc. - C:\Program Files\Network ICE\BlackICE\vpatch.exe
O23 - Service: Orchestria APM Infrastructure (WGNINFRA) - Orchestria - c:\Program Files\Orchestria\Active Policy Management\system\wgninfra.exe
O23 - Service: ControlGuard Agent (WhatsInAgentManager) - - C:\WINDOWS\system32\WhatsIn\WhatsInAgentManagerService.exe

–
End of file - 11114 bytes

Thanks very much in advance.
Hi,

  • One or more of the files infecting your computer have the ability to steal passwords and log keystrokes
  • Call all of your banks, credit card companies, financial institutions and inform them that your personal information may have been compromised and to take the necessary precautions.
    FROM AN UNINFECTED MACHINE
  • Change ALL your on-line passwords for email, banks, financial accounts, PayPal, eBay, on-line companies, any on-line forums, groups or games or any other organizations you belong to.
DO NOT change your passwords from this computer as the attacker will be able to get all the new passwords and transaction records.
If you wish to have me attempt to clean this machine I will be happy to do so but I cannot guarantee that even after cleaning, your machine will be completely trustworthy again.
The only way to be certain is to do a complete reformat and reinstall of your operating system.

Please advise of your wishes - in the meantime I will proceed with the cleaning.


Please do the following:

Download ComboFix from one of these locations:
Link 1
Link 2
Link 3

VERY IMPORTANT !!!
Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
Thanks for the quick response CatByte. I installed ComboFix to the desktop and ran it as instructed. It went thru the 50 or so stages and deleted several files along the way. It then indicated that it was rebooting the computer which it did. But, that was as far as it got, the computer now is dead and just keeps looping thru the reboot process culminating in a blue screen with a message that is too fast to read but eludes something about a virus on the hard drive. So, any suggestions on how to get the dang thing to boot back to the desktop?
We Need to Diagnose Your BlueScreen
  • When you boot your machine, press F8 to list the startup options, exactly as you would if you were trying to enter Safe Mode
  • Select "Disable Automatic Restart on System Failure", as shown here:
    [external image: Posted Image]
  • When your system BSODs, write down the STOP error code, as well as any written out error message back here. The STOP error will always appear, but the message may not. You are looking for this:
    [external image: Posted Image]

Please post the error message you see
The only options from the Windows Advanced options menu are the 3 Safe mode choices, Last Known Good Config or Start Windows Normally, none of which get me anywhere other that Last Known Good Config. It takes me to a screen that says the following file could not be located: System 32\Drivers\Safeboot.sys and indicates a repair may be possible from the original install CD which of course I do not have. I recall ComboFix deleted this file. On a second attempt I was able to catch the reboot sequence and switch from Windows XP to the Recovery Console which brought me to the bsod and just locked up but at least I could see what it said. The top error says: UNMOUNTABLE_BOOT_VOLUME The lower error code is: Stop: 0x000000ED Thanks
Safeboot.sys appears to be related to McAfee Endpoint Encryption. If so, it's a machine critical file. It's meant for encrypting the drive. Without it, no one can read data off it. when it encrypts a drive, the program should have created an emergency rescue disk for it. Do you have a McAfee rescue disk.
Yes, per the above, when I get to it……… if that is what you are calling the Recovery Console, I referred to it as the Windows Advanced options menu. Looks the same as the screen shot in your 4:51 post yesterday.

The only options from the Windows Advanced options menu are the 3 Safe mode choices, Last Known Good Config or Start Windows Normally, none of which get me anywhere other that Last Known Good Config. It takes me to a screen that says the following file could not be located: System 32\Drivers\Safeboot.sys and indicates a repair may be possible from the original install CD which of course I do not have. I recall ComboFix deleted this file.


I can't do anything from that console as far as I can tell. The only choice that does not go straight back to the reboot loop is the Last Known Good Config which simply advises of the missing System 32 Safeboot driver and suggesting I reinstall it from a repair disc.

Thanks
When Combofix is downloaded it installs the windows recovery console and erunt registry back-up.

For situations such as this it may be possible to boot into the recovery console and restore the registry back up to enable you to boot again

please try the following:


Boot into the Recovery Console by following these steps:


1. Restart your computer
2. Before Windows loads, you will be prompted to choose which Operating System to start (this is very fast - be ready to arrow to the recovery console)
3. Use the up and down arrow key to select Microsoft Windows Recovery Console
4. You must enter which Windows installation to log onto. Type 1 and press enter.
5. At the C:\Windows prompt, type the following bolded text, and press Enter:

cd erdnt\subs

6. At the next prompt, type the following bolded text, and press Enter:

batch erdnt.con

7. The erunt backups will begin copying.
8. At the next prompt, type the following bolded text, and press Enter:
exit

Windows should now begin loading.
OK, I'm on the same page now. Yes, I can chose the Recovery Console but after I do is when I get the bsod:

On a second attempt I was able to catch the reboot sequence and switch from Windows XP to the Recovery Console which brought me to the bsod and just locked up but at least I could see what it said. The top error says:
UNMOUNTABLE_BOOT_VOLUME The lower error code is: Stop: 0x000000ED


So the answer is No, I can not get to the Recovery Console. Heavy sigh :).

Any other suggestions? And again, thanks for the attempts to resolve this and the prompt responses.
Hi, You will need to get your hands on an installation disk for your operating system, then you should be able to boot into that recovery console and recovery the registry back-up…Ask around to see if anyone you know has one… It would need to be the same OS as yours Windows XP SP2. If you boot from a CD then you can bypass the problem. or if there is a rescue disk available for McAfee that would be preferable.
Thanks for all the efforts CatByte. Go ahead and mark this one as Closed. I will be re formatting the drive on Monday. It is overdue for that anyway and like you said in your very first response, even after cleaning there may still be issues. I assume whatever zapped me is a fairly serious virus. Thanks again. Havoc
Hi, Yes it was serious and it's probably for the best to reformat. Sorry I couldn't have been of more assistance, but at least now you will have a computer that is totally clean and trustworthy. Good luck CB

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI