larryri42
Topic Starter
hey i notice one of those fake anti virus things on my computer telling me i was infected. right away i ran malwarebytes and tried to remove it. i was not able to update malwarebytes kept getting an error:
An error occurred. Please report the following error code to the Malwarebyte's Anti-Malware support team.
Error code: 732 (0,0)
i was able to run it with the Sept updates and it found 4 files infected. i removed and restarted computer. when computer came back up i notice that IE does not work right and show like if my internet is off line. Mozilla Firefox works just fine. when i try to type an address in the address box i will get something like invalid address or page cannot be found but others will pull up just fine. with Firefox everything seems to work fine. the only problem is some web pages that i have to go to for work only work in IE so i need this resolve soon. i was finally able to update Malwarebytes and it found two more infected files. after those two infected files i tried IE7 and everything was working fine. after a reboot of my computer now IE7 is doing the same thing as before. it will not even pull up www.msn.com. i ran through the steps that say here i was able to get the log file for DDS and i used ATF as the cleaner. i was not able to run RootRepeal from any other the three links provided. i am able to install it but when i try running it the application will not open. i open task manager and it says Not Responding and i check and the CPU process is at 99. here are the two log files that i was able to get.
DDS.txt
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 19:57:51.04 on Wed 12/02/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2046.1252 [GMT -5:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
I:\WINDOWS\System32\svchost.exe -k netsvcs
I:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
I:\Program Files\AVG\AVG9\avgchsvx.exe
I:\Program Files\AVG\AVG9\avgrsx.exe
I:\Program Files\AVG\AVG9\avgcsrvx.exe
svchost.exe
svchost.exe
I:\WINDOWS\system32\spoolsv.exe
I:\WINDOWS\system32\Ati2evxx.exe
I:\WINDOWS\Explorer.EXE
svchost.exe
I:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
I:\Program Files\AVG\AVG9\avgwdsvc.exe
I:\Program Files\Bonjour\mDNSResponder.exe
I:\Program Files\Juniper Networks\Common Files\dsNcService.exe
I:\Program Files\Java\jre6\bin\jqs.exe
I:\Program Files\AVG\AVG9\avgnsx.exe
I:\Program Files\LogMeIn\x86\RaMaint.exe
I:\Program Files\LogMeIn\x86\LogMeIn.exe
I:\Program Files\LogMeIn\x86\LMIGuardian.exe
I:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
I:\Program Files\mobile PhoneTools\WatchDog.exe
i:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
I:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
I:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
I:\WINDOWS\System32\svchost.exe -k imgsvc
I:\Program Files\Viewpoint\Common\ViewpointService.exe
I:\WINDOWS\System32\MsPMSPSv.exe
I:\Program Files\LogMeIn\x86\LogMeInSystray.exe
I:\WINDOWS\system32\SearchIndexer.exe
I:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
I:\Program Files\iTunes\iTunesHelper.exe
I:\PROGRA~1\AVG\AVG9\avgtray.exe
I:\Program Files\LogMeIn\x86\LMIGuardian.exe
I:\WINDOWS\system32\svchost.exe -k netsvcs
I:\WINDOWS\system32\ctfmon.exe
I:\PROGRA~1\MI3AA1~1\wcescomm.exe
I:\PROGRA~1\MI3AA1~1\rapimgr.exe
I:\Program Files\Brother\Brmfcmon\BrMfimon.exe
I:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
I:\Program Files\Windows Media Player\WMPNSCFG.exe
I:\WINDOWS\System32\svchost.exe -k HTTPFilter
I:\Program Files\iPod\bin\iPodService.exe
I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
I:\Program Files\ATI Technologies\ATI.ACE\cli.exe
I:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
I:\Program Files\AVG\AVG9\avgcsrvx.exe
I:\Program Files\Mozilla Firefox\firefox.exe
I:\Program Files\AVG\AVG9\avgui.exe
I:\WINDOWS\system32\wscntfy.exe
I:\WINDOWS\system32\SearchProtocolHost.exe
I:\Documents and Settings\Larry\Desktop\dds(2).scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride =
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - i:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - i:\program files\avg\avg9\avgssie.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - i:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - i:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - i:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - i:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - i:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - i:\program files\google\google toolbar\GoogleToolbar_32.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
uRun: [ctfmon.exe] i:\windows\system32\ctfmon.exe
uRun: [H/PC Connection Agent] "i:\progra~1\mi3aa1~1\wcescomm.exe"
uRun: [NBJ] "i:\program files\ahead\nero backitup\NBJ.exe"
uRun: [swg] "i:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Aim6]
uRun: [WMPNSCFG] i:\program files\windows media player\WMPNSCFG.exe
mRun: [NvCplDaemon] RUNDLL32.EXE i:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [RoxioEngineUtility] "i:\program files\common files\roxio shared\system\EngUtil.exe"
mRun: [WatchDog] i:\program files\mobile phonetools\WatchDog.exe
mRun: [NeroFilterCheck] i:\program files\common files\ahead\lib\NeroCheck.exe
mRun: [NvMediaCenter] RUNDLL32.EXE i:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [ATICCC] "i:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay
mRun: [CloneCDTray] "i:\program files\slysoft\clonecd\CloneCDTray.exe" /s
mRun: [GrooveMonitor] "i:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [SSBkgdUpdate] "i:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [PaperPort PTD] "i:\program files\scansoft\paperport\pptd40nt.exe"
mRun: [IndexSearch] "i:\program files\scansoft\paperport\IndexSearch.exe"
mRun: [PPort11reminder] "i:\program files\scansoft\paperport\ereg\ereg.exe" -r "i:\documents and settings\all users\application data\scansoft\paperport\11\config\ereg\Ereg.ini
mRun: [BrMfcWnd] i:\program files\brother\brmfcmon\BrMfcWnd.exe /AUTORUN
mRun: [ControlCenter3] i:\program files\brother\controlcenter3\brctrcen.exe /autorun
mRun: [LogMeIn GUI] "i:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [iTunesHelper] "i:\program files\itunes\iTunesHelper.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "i:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [AVG9_TRAY] i:\progra~1\avg\avg9\avgtray.exe
mRun: [QuickTime Task] "i:\program files\quicktime\QTTask.exe" -atboottime
dRun: [DWQueuedReporting] "i:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: i:\docume~1\larry\startm~1\programs\startup\adobeg~1.lnk - i:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: i:\docume~1\larry\startm~1\programs\startup\erunta~1.lnk - i:\program files\erunt\AUTOBACK.EXE
StartupFolder: i:\docume~1\larry\startm~1\programs\startup\onenot~1.lnk - i:\program files\microsoft office\office12\ONENOTEM.EXE
IE: Google Sidewiki… - i:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - i:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - i:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - i:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - i:\progra~1\mi3aa1~1\INetRepl.dll
IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - i:\progra~1\mi3aa1~1\INetRepl.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - i:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: arise.com
Trusted Zone: intuit.com
Trusted Zone: turbotax.com
Trusted Zone: willowcsn.com\cybercentral
DPF: Microsoft XML Parser for Java - file:///I:/WINDOWS/Java/classes/xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
DPF: {036F8A56-0BC8-4607-8F98-D3231E6FF5ED} - hxxp://asp23.centra.com/SiteRoots/main/Install/win32/CentraUpdaterAx.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/e/7/3/e7345c16-80aa-4488-ae10-9ac6be844f99/OGAControl.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/5/b/0/5b0d4654-aa20-495c-b89f-c1c34c691085/LegitCheckControl.cab
DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85} - hxxp://download.microsoft.com/download/7/4/9/749b0dc5-2175-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab
DPF: {32564D57-9980-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmv8dmo.cab
DPF: {33564D57-9980-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/D/0/D/D0DD87DA-994F-4334-8B55-AF2E4D98ED0C/wmv9dmo.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182530425484
DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - hxxp://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {95D88B35-A521-472B-A182-BB1A98356421} - hxxp://asp.mathxl.com/books/_Players/PearsonInstallAsst2.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38066.5709953704
DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09}
DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://ns.arise.com/dana-cached/setup/JuniperSetupSP1.cab
DPF: {E6D23284-0E9B-417D-A782-03E4487FC947} - hxxp://asp.mathxl.com/books/_Players/MathPlayer.cab
DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} - hxxps://secure.logmein.com/activex/ractrl.cab?lmi=100
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - i:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - i:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: LMIinit - LMIinit.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - i:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - i:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - i:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - i:\docume~1\larry\applic~1\mozilla\firefox\profiles\uz0fyw53.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxps://admintools.ariasystems.net/dashboard-idp/auth/login-aria.php?RelayState=https%3A%2F%2Fadmintools.ariasystems.net%3A443%2Fdashboard-idp%2Fsaml2%2Fidp%2FSSOService.php%3FRequestID%3D_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&spentityid=admintools.ariasystems.net&AuthId=_c0cf1c5c7235cdb9fc55eaf2649f117105d7d0cb1e&protocol=saml2&timeout=0
FF - component: i:\program files\avg\avg9\firefox\components\avgssff.dll
FF - plugin: i:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: i:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: i:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: i:\program files\mozilla firefox\plugins\npican.dll
FF - plugin: i:\program files\mozilla firefox\plugins\npunagi2.dll
FF - plugin: i:\program files\mozilla firefox\plugins\npViewpoint.dll
FF - plugin: i:\program files\viewpoint\viewpoint media player\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - i:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - i:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
============= SERVICES / DRIVERS ===============
R1 AvgLdx86;AVG Free AVI Loader Driver x86;i:\windows\system32\drivers\avgldx86.sys [2009-4-8 333192]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;i:\windows\system32\drivers\avgmfx86.sys [2009-4-8 28424]
R1 AvgTdiX;AVG Free8 Network Redirector;i:\windows\system32\drivers\avgtdix.sys [2009-4-8 360584]
R1 NEOFLTR_550_12129;Juniper Networks TDI Filter Driver (NEOFLTR_550_12129);i:\windows\system32\drivers\NEOFLTR_550_12129.sys [2007-10-3 63008]
R2 avg9wd;AVG Free WatchDog;i:\program files\avg\avg9\avgwdsvc.exe [2009-11-9 285392]
R2 LMIInfo;LogMeIn Kernel Information Provider;i:\program files\logmein\x86\rainfo.sys [2008-7-24 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;i:\windows\system32\drivers\LMIRfsDriver.sys [2009-2-12 47640]
R2 Viewpoint Manager Service;Viewpoint Manager Service;i:\program files\viewpoint\common\ViewpointService.exe [2009-7-3 24652]
R3 portio32;portio32;i:\windows\system32\drivers\portio32.sys [2009-9-7 2048]
S2 gupdate1c9d3431ddff9c6;Google Update Service (gupdate1c9d3431ddff9c6);i:\program files\google\update\GoogleUpdate.exe [2009-5-12 133104]
S3 NPF;Netgroup Packet Filter;i:\windows\system32\drivers\npf.sys –> i:\windows\system32\drivers\npf.sys [?]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
=============== Created Last 30 ================
2009-12-02 19:54 -cd—– i:\windows\BACKUPERDNT
2009-12-02 10:28 -cd—– i:\program files\common files\AnswerWorks 4.0
2009-12-02 09:43 -cd—– i:\program files\Arise
2009-12-02 09:24 38,224 ac—— i:\windows\system32\drivers\mbamswissarmy.sys
2009-12-02 09:24 19,160 ac—— i:\windows\system32\drivers\mbam.sys
2009-12-02 09:24 -cd—– i:\program files\Malwarebytes' Anti-Malware
2009-11-21 11:15 411,368 ac—— i:\windows\system32\deploytk.dll
2009-11-21 11:15 73,728 ac—— i:\windows\system32\javacpl.cpl
2009-11-10 23:08 94,208 ac—— i:\windows\system32\QuickTimeVR.qtx
2009-11-10 23:08 69,632 ac—— i:\windows\system32\QuickTime.qts
2009-11-09 10:22 -cd-h— I:\$AVG
2009-11-09 10:21 -cd—– i:\docume~1\alluse~1\applic~1\avg9
2009-11-07 11:30 -cd—– i:\documents and settings\larry\taw
2009-11-05 16:03 -cd—– i:\program files\iPod
2009-11-05 16:03 -cd—– i:\program files\iTunes
2009-11-02 23:17 244 ac–h— I:\sqmnoopt07.sqm
2009-11-02 23:17 232 ac–h— I:\sqmdata07.sqm
==================== Find3M ====================
2009-11-10 09:12 360,584 ac—— i:\windows\system32\drivers\avgtdix.sys
2009-11-09 10:22 333,192 ac—— i:\windows\system32\drivers\avgldx86.sys
2009-11-09 10:22 12,464 ac—— i:\windows\system32\avgrsstx.dll
2009-10-27 02:27 96,256 a——- i:\windows\system32\drivers\sptd4045.sys
2009-10-01 10:36 83,288 a——- i:\windows\system32\LMIRfsClientNP.dll
2009-10-01 10:36 28,984 ac—— i:\windows\system32\LMIport.dll
2009-10-01 10:36 87,352 a——- i:\windows\system32\LMIinit.dll
2009-09-30 13:56 73,880 ac–h— i:\windows\system32\mlfcache.dat
2009-09-11 09:33 133,632 a——- i:\windows\system32\msv1_0.dll
2009-09-08 10:35 25,248 ac—— i:\windows\system32\lmimirr.dll
2009-09-08 10:35 11,552 ac—— i:\windows\system32\lmimirr2.dll
2009-09-04 15:45 58,880 a——- i:\windows\system32\msasn1.dll
2005-07-14 13:31 27,648 ac-sh— i:\windows\system32\AVSredirect.dll
============= FINISH: 19:57:59.70 ===============
Attach.txt
has been attached.