indyjack,
You've got a poker game program installed that is known to bring malware onto your system:
Full Tilt Poker -
http://www.bleepingcomputer.com/uninstall/…Tilt-Poker.html
Please uninstall it using add or remove programs in your control panel
JavaRa …by: Paul McLain and Fred de Vries
Please download
JavaRa (Copyright © 2008 RaProducts.org) and
unzip it to your desktop .
***Please close any instances of Internet Explorer before continuing!***
Print these instructions…you won't have Internet access during this particular phase!
Double-click on JavaRa.exe to start the program. From the drop-down menu, choose English or the appropriate language…and click on Select . JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer. Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK . A logfile will pop up. Please save it to a convenient location. Copy and paste the contents of the JavaRa log, in your next reply.
Tom,
I use the Full Tilt poker program all the time on all my computers.
I will install JAVARA and post a log.
indyjack,
Then you are going to continue to have malware on your system. But it is your system and your choice.
When I run JavaRa it does not save a log file, but it did change my boot home page.
indyjack,
Well that is very strange. It won't give you a log if it doesn't find any old java. However, it has nothing to do with your homepage.
Please run DDS and post the logs again.
DDS text file
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 1:56:29.33 on Sat 07/11/2009
Internet Explorer: 8.0.6001.18783
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1013.244 [GMT -4:00]
AV: avast! antivirus 4.8.1229 [VPS 081117-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: avast! antivirus 4.8.1229 [VPS 081117-0] *enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\agrsmsvc.exe
C:\Acer\ALaunch\ALaunchSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
C:\Windows\system32\taskeng.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\Acer\Empowering Technology\eNet\eNet Service.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Windows\system32\igfxext.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Mouse Driver\StartAutorun.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\igfxsrvc.exe
C:\Users\JACKCL~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Mouse Driver\KMConfig.exe
C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Mouse Driver\KMProcess.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Program Files\Apoint2K\Apntex.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Jack Clouse\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://en.us.acer.yahoo.com/
mStart Page = hxxp://en.us.acer.yahoo.com
TB: Acer eDataSecurity Management: {5cbe3b7c-1e47-477e-a7dd-396db0476e29} - c:\acer\empowering technology\edatasecurity\x86\eDStoolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [eDataSecurity Loader] c:\acer\empowering technology\edatasecurity\x86\eDSloader.exe
mRun: [PCMService] "c:\program files\acer\acer arcade\PCMService.exe"
mRun: [PLFSetL] c:\windows\PLFSetL.exe
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [Skytel] Skytel.exe
mRun: [Apoint] c:\program files\apoint2k\Apoint.exe
mRun: [Acer Product Registration] "c:\program files\acer\acer registration\ACE1.exe" /startup
mRun: [Acer Assist Launcher] c:\program files\acer\acer assist\launcher.exe
mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [KMCONFIG] c:\program files\mouse driver\StartAutorun.exe KMConfig.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\empowe~1.lnk - c:\acer\empowering technology\eAPLauncher.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {6218F7B5-0D3A-48BA-AE4C-49DCFA63D400} - hxxp://www.myheritage.com/Genoogle/Components/ActiveX/SearchEngineQuery.dll
DPF: {71D413D7-38C5-4035-8548-976522CF11D5} - hxxp://www.crucial.com/controls/cpcVistaBeta.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_10-windows-i586.cab
Notify: igfxcui - igfxdev.dll
================= FIREFOX ===================
FF - ProfilePath - c:\users\jackcl~1\appdata\roaming\mozilla\firefox\profiles\iwipglfv.default\
—- FIREFOX POLICIES —-
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - fales
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
============= SERVICES / DRIVERS ===============
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-8-30 114768]
R2 ALaunchService;ALaunch Service;c:\acer\alaunch\ALaunchSvc.exe [2008-3-21 51200]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-8-30 20560]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2008-8-30 51792]
R3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2008-3-21 180736]
=============== Created Last 30 ================
2009-07-10 09:07 –dsh— C:\$RECYCLE.BIN
2009-07-10 08:53 161,792 a——- c:\windows\SWREG.exe
2009-07-10 08:53 155,136 a——- c:\windows\PEV.exe
2009-07-10 08:53 98,816 a——- c:\windows\sed.exe
2009-07-09 13:43 –d—– c:\users\jackcl~1\appdata\roaming\Malwarebytes
2009-07-09 13:43 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-09 13:43 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-09 13:43 –d—– c:\programdata\Malwarebytes
2009-07-09 13:43 –d—– c:\progra~2\Malwarebytes
2009-07-09 13:43 –d—– c:\program files\Malwarebytes' Anti-Malware
==================== Find3M ====================
2009-06-10 09:56 86,016 a——- c:\windows\inf\infstor.dat
2009-06-10 09:56 51,200 a——- c:\windows\inf\infpub.dat
2009-06-10 09:56 143,360 a——- c:\windows\inf\infstrng.dat
2009-06-10 09:49 665,600 a——- c:\windows\inf\drvindex.dat
2009-05-09 01:50 915,456 a——- c:\windows\system32\wininet.dll
2009-05-09 01:34 71,680 a——- c:\windows\system32\iesetup.dll
2009-04-23 08:15 784,896 a——- c:\windows\system32\rpcrt4.dll
2009-04-23 08:14 623,616 a——- c:\windows\system32\localspl.dll
2009-04-21 07:39 2,034,688 a——- c:\windows\system32\win32k.sys
2008-10-27 18:39 0 a——- c:\users\jackcl~1\appdata\roaming\wklnhst.dat
2008-01-20 22:57 174 a–sh— c:\program files\desktop.ini
2006-11-02 08:39 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:39 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:39 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:39 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat
============= FINISH: 1:57:54.32 ===============
indyjack,
What was your homepage and what is it now?
It had 3 tabs, yahoo, acer, and windows live. Now it is just yahoo.
indyjack,
Will it allow you to add the other tabs?
Tom,
Sorry. I don't know how. I'm not quite used to Vista yet.
indyjack,
The tabs should be a function of the browser rather than the operating system.
Which browser are you adding them in. Internet Explorer or FireFox.
IE. and I figured it out. thanks.
Does everything else look OK?
indyjack,
I'm not seeing any malware remaining, however, your java is still out of date.
Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop. Scroll down to where it says "JRE 6 Update 14 . Click the "Download " button to the right. Select your Platform: "Windows ". Select your Language: "Multi-language ". Read the License Agreement, and then check the box that says: "Accept License Agreement ". Click Continue and the page will refresh. Click on the link to download Windows Offline Installation and save the file to your desktop. Close any programs you may have running - especially your web browser. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java. Check (highlight ) any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller. Repeat as many times as necessary to remove each Java versions. Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
Now to
Clean out the Java cache:
Go into the Control Panel and double-click the Java Icon.
[external image: Posted Image]
Under Temporary Internet Files, click the Settings… button click the Delete Files button. There are two options in the window to clear the cache - Leave both Checked
Applications and Applets
Trace and Log Files Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. Click OK to leave the Temporary Files Settings Click OK to leave the Java Control Panel.
Tom,
Thanks for all of your help. I will work on JAVA tomorrow and reply then.
Jack