This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Fake Alert Virus Removal Problem

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I'm having a problem fully removing a Trojan virus. I ran a scan with Malwarebytes and deleted the virus. Several scans have come back clean, including scans in safe mode. However, I am sometimes still directed to a random website when clicking on links in a search engine results page. Any help would be greatly appreciated. Thanks.
Hello there, ADJ

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
Hello,

Can you please post Malwarebytes' log in your next reply?
To retrieve the log
  • Open MBAM and click on the Logs tab
  • Click on the most recent log
  • Click Open
Copy and paste the contents of the log into your next reply.

===================================================

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.

===================================================

On your next reply please post :
Malwarebytes' log
DDS log
GMER log

Good Day!
Hi Conspire,

Okay, I completed your directions and posted and attached the information in this response. However, before I initially posted my problem on the forum I did something dumb. I ran the ComboFix program which found a rootkit and quarantined quite a few files. I did a system restore but there are still several files I can't access. Is there a way to un-quarantine/restore these files in the Qoobox folder? Sorry for the headache. I should have listened to the warnings.

The Malwarebytes log was erased however the virus path was: C:\WINN\system32\spool\prtprocs\w32x86\00006201.tmp


DDS (Ver_09-12-01.01) - NTFSx86
Run by [removed] at 13:00:50.50 on Mon 01/25/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.669 [GMT -5:00]


============== Running Processes ===============

C:\WINNT\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\spoolsv.exe
svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINNT\System32\svchost.exe -k imgsvc
C:\WINNT\wanmpsvc.exe
C:\WINNT\system32\PROMon.exe
C:\WINNT\system32\igfxtray.exe
C:\WINNT\system32\SK9910DM.EXE
C:\WINNT\GWMDMMSG.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://flashline.kent.edu/cp/home/loginf
uInternet Settings,ProxyOverride = *.local
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\winnt\system32\ctfmon.exe
uRun: [Microsoft Works Update Detection] c:\program files\microsoft works\WkDetect.exe
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
mRun: [PROMon.exe] PROMon.exe
mRun: [IgfxTray] c:\winnt\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\winnt\system32\hkcmd.exe
mRun: [Hot Key Kbd 9910 Daemon] SK9910DM.EXE
mRun: [GWMDMMSG] GWMDMMSG.exe
mRun: [REGSHAVE] c:\program files\regshave\REGSHAVE.EXE /AUTORUN
mRun: [YBrowser] c:\progra~1\yahoo!\browser\ybrwicon.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Microsoft Works Update Detection] c:\program files\common files\microsoft shared\works shared\WkUFind.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\logite~1.lnk - c:\program files\common files\logishrd\ereg\setpoint\eReg.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\SetPoint.exe
mPolicies-system: EnableLUA = 0 (0x0)
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
DPF: {2EDF75C0-5ABD-49f9-BAB6-220476A32034} - hxxp://intel-drv-cdn.systemrequirementslab.com/multi/bin/sysreqlab_srlx.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {41F17733-B041-4099-A042-B518BB6A408C} - hxxp://a1540.g.akamai.net/7/1540/52/20030530/qtinstall.info.apple.com/bonnie/us/win/QuickTimeInstaller.exe
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} - hxxp://simcity.ea.com/update/EARTPX.cab
DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1196452767401
DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} - hcp://system/RunExeActiveX.CAB
DPF: {7CF052DE-C74F-421B-B04A-3B3037EF5887} - hxxp://64.124.45.181/chaincast/proxy/CCMP.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} - hcp://system/StartFirstControl.CAB
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37849.503912037
DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - hxxp://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} - hxxp://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} - hxxp://chat.yahoo.com/cab/yvwrctl.cab
Notify: igfxcui - igfxsrvc.dll
Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\winnt\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

============= SERVICES / DRIVERS ===============

R2 LBeepKE;LBeepKE;c:\winnt\system32\drivers\LBeepKE.sys [2010-1-14 10384]
R2 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
R3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\winnt\system32\drivers\HCWBT8XX.sys [2007-1-11 472644]
S2 gupdate1c9cea0ad676636;Google Update Service (gupdate1c9cea0ad676636);c:\program files\google\update\GoogleUpdate.exe [2009-5-6 133104]
S3 EVOLUSB;%EVOL_USB_SvcDesc%;c:\winnt\system32\drivers\evolusb.sys –> c:\winnt\system32\drivers\evolusb.sys [?]
S3 iscFlash;iscFlash;\??\c:\winnt\system32\drivers\iscflash.sys –> c:\winnt\system32\drivers\iscflash.sys [?]
S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\qctest\pcdoc\pcdrdrv.sys –> c:\atf\qctest\pcdoc\PCDRDRV.sys [?]
S3 vsdatant;vsdatant;\??\c:\winnt\system32\vsdatant.sys –> c:\winnt\system32\vsdatant.sys [?]

=============== Created Last 30 ================

2010-01-24 21:28:15 0 d—–w- c:\winnt\system32\wbem\Repository
2010-01-24 21:26:12 0 d—–w- c:\docume~1\alluse~1\applic~1\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2010-01-24 21:26:11 0 d—–w- c:\docume~1\alluse~1\applic~1\CA
2010-01-24 21:26:11 0 d—–w- c:\docume~1\alluse~1\applic~1\Broderbund LLC
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\SSScanWizard
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\SSScanAppDataDir
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\SBSI
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\Musicnotes
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\McAfee.com
2010-01-24 21:26:01 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-01-24 21:26:00 0 d—–w- c:\docume~1\alluse~1\applic~1\Trend Micro
2010-01-24 21:26:00 0 d—–w- c:\docume~1\alluse~1\applic~1\Symantec
2010-01-24 21:25:57 0 d—–w- c:\documents and settings\owner\.realobjects
2010-01-24 21:25:56 0 d—–w- c:\docume~1\owner\applic~1\iShell
2010-01-24 21:25:56 0 d—–w- c:\docume~1\owner\applic~1\ChessBase
2010-01-24 21:25:55 0 d—–w- c:\docume~1\owner\applic~1\Symantec
2010-01-24 21:25:55 0 d—–w- c:\docume~1\owner\applic~1\McAfee
2010-01-24 21:25:55 0 d—–w- c:\docume~1\owner\applic~1\Malwarebytes
2010-01-24 21:25:53 0 d-sh–w- c:\documents and settings\owner\IETldCache
2010-01-24 21:25:53 0 d-sh–w- c:\documents and settings\owner\IECompatCache
2010-01-24 21:25:49 0 d-sh–w- c:\documents and settings\owner\UserData
2010-01-24 21:25:49 0 d-sh–w- c:\documents and settings\owner\PrivacIE
2010-01-24 21:25:49 0 d—–w- c:\documents and settings\owner\WINDOWS
2010-01-24 21:06:06 0 d—–w- c:\documents and settings\owner\PrivacIE(2)
2010-01-24 21:06:01 0 d—–w- c:\documents and settings\owner\IECompatCache(2)
2010-01-24 21:04:43 0 d-sh–w- C:\RECYCLER(2)
2010-01-24 20:52:13 0 d—–w- c:\documents and settings\owner\IETldCache(2)
2010-01-24 20:52:09 0 d—–w- c:\docume~1\alluse~1\applic~1\Windows Genuine Advantage(2)
2010-01-24 19:44:41 0 d—–w- c:\winnt\ERUNT
2010-01-24 19:44:31 0 d—–w- C:\!FixIEDef
2010-01-15 02:59:43 0 d—–w- c:\program files\NES Emulator
2010-01-14 22:23:46 10384 —-a-w- c:\winnt\system32\drivers\LBeepKE.sys
2010-01-14 22:23:37 0 —ha-w- c:\winnt\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-01-14 22:23:24 0 —ha-w- c:\winnt\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2010-01-14 22:23:21 0 —ha-w- c:\winnt\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-14 22:21:40 301656 —-a-w- c:\winnt\system32\BtCoreIf.dll
2010-01-14 22:21:34 84496 —-a-w- c:\winnt\system32\KemXML.dll
2010-01-14 22:21:34 170512 —-a-w- c:\winnt\system32\kemutb.dll
2010-01-14 22:21:34 145936 —-a-w- c:\winnt\system32\KemUtil.dll
2010-01-14 22:21:34 117264 —-a-w- c:\winnt\system32\KemWnd.dll
2010-01-10 18:50:59 21504 —-a-w- c:\winnt\system32\hidserv.dll
2010-01-10 18:50:59 21504 —-a-w- c:\winnt\system32\dllcache\hidserv.dll
2010-01-08 20:30:28 0 d—–w- c:\program files\SystemRequirementsLab
2010-01-08 19:54:30 471552 ——w- c:\winnt\system32\dllcache\aclayers.dll
2009-12-30 23:47:09 0 d—–w- c:\program files\Firaxis Games

==================== Find3M ====================

2010-01-14 16:12:06 181120 ——w- c:\winnt\system32\MpSigStub.exe
2010-01-07 21:07:14 38224 —-a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07:04 19160 —-a-w- c:\winnt\system32\drivers\mbam.sys
2009-12-21 13:19:18 173056 —-a-w- c:\winnt\system32\dllcache\ie4uinit.exe
2009-12-18 16:39:07 66952 —-a-w- c:\docume~1\owner\applic~1\GDIPFONTCACHEV1.DAT
2004-11-04 23:49:52 16706160 —-a-w- c:\program files\AdbeRdr60_enu_full.exe
2008-05-20 02:50:31 32768 –sha-w- c:\winnt\system32\config\systemprofile\local settings\history\history.ie5\mshist012008051920080520\index.dat

============= FINISH: 13:01:53.39 ===============

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-25 21:59:11
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\fxtdypow.sys


—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINNT\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF7496780]

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\Explorer.EXE [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)
IAT C:\WINNT\Explorer.EXE[1172] @ C:\WINNT\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [5CB77774] C:\WINNT\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F7489B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7489B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort0 [F7489B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort1 [F7489B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F7489B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}

—- Files - GMER 1.0.15 —-

File C:\WINNT\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-
Hello,

Not to worry about that, we will see what we can do. :)

I need you to post the ComboFix log generated on your last run, please post it in your next reply. It can be found at C:\ComboFix.txt



I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto-updating for the Viewpoint Manager – the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad".
This may change, read Viewpoint to Plunge Into Adware.

Please uninstall the following Programs using the Add/Remove Programs utility if you choose to do so.
Viewpoint Media Player

Detailed steps below :-
On the Windows XP taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Add or Remove Programs.

===================================================

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    *atapi*
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===================================================

On your next reply please post :
ComboFix log
SystemLook log


Good Day!
Hi, thanks for the info about viewpoint. I went ahead and removed it. I also attached the SystemLook and ComboFix logs. The ComboFix log was too large to post all at once. So, I broke this up into a couple posts. Thanks. SystemLook v1.0 by jpshortstuff (11.01.10) Log created at 20:57 on 26/01/2010 by Owner (Administrator - Elevation successful) ========== filefind ========== Searching for "*atapi*" C:\cmdcons\ATAPI.SY_ –a— 49558 bytes [02:59 04/08/2004] [02:59 04/08/2004] 28541D14647BB58502D09D1CEAEE6684 C:\I386\ATAPI.SY_ –a— 47118 bytes [17:00 18/08/2001] [17:00 18/08/2001] A88F2B56DA29BAD0C8ED9760A2D4C705 C:\Qoobox\Quarantine\C\WINNT\system32\drivers\atapi.sys.vir –a— 96512 bytes [19:58 24/01/2010] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674 C:\Qoobox\Quarantine\C\WINNT\system32\drivers\atapi.sys.vir_ –a— 96512 bytes [02:11 30/08/2002] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674 C:\WINNT\$NtServicePackUninstall$\atapi.sys —–c 95360 bytes [02:11 20/05/2008] [05:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51 C:\WINNT\ServicePackFiles\i386\atapi.sys —— 96512 bytes [21:13 05/11/2003] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674 C:\WINNT\system32\drivers\atapi.sys –a— 96512 bytes [02:11 30/08/2002] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674 C:\WINNT\system32\ReinstallBackups\0008\DriverFiles\i386\atapi.sys –a— 86656 bytes [02:11 30/08/2002] [18:51 17/08/2001] A64013E98426E1877CB653685C5C0009 -=End Of File=-
Hi, I had some problems posting the text. The file was too large. I attached the log as three attachments. I hope that is okay. Thanks.
Hello there,

***Read through this entire procedure and if you have any questions, please ask them before you begin. Then either print out, or copy this page to Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.


Please download and run by clicking this link : http://download.bleepingcomputer.com/sUBs/CFDQ-UsrPrf.exe

Once you finished running it, DO NOT reboot your computer but delete your existing copy of ComboFix and download a fresh copy and run it. Then, post back a new log in here.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
ComboFix 10-01-27.03 - Owner 01/27/2010 20:18:41.3.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1022.774 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Start Menu\Programs\Startup\Logitech . Product Registration.lnk
c:\winnt\AUTOLNCH.REG
c:\winnt\jestertb.dll
c:\winnt\system32\lsprst7.dll
c:\winnt\system32\SIntf16.dll
c:\winnt\system32\ssprs.dll
c:\winnt\system32\twain_32.dll
F:\autorun.inf

Infected copy of c:\winnt\system32\DRIVERS\atapi.sys was found and disinfected
Restored copy from - c:\system volume information\_restore{0193FC1C-0A70-478B-8107-B531B8E70CAB}\RP314\A0020189.sys
.
((((((((((((((((((((((((( Files Created from 2009-12-28 to 2010-01-28 )))))))))))))))))))))))))))))))
.

2010-01-28 00:41 . 2010-01-28 00:41 ——– d—–w- c:\documents and settings\All Users\DRM
2010-01-24 21:28 . 2010-01-24 21:28 ——– d—–w- c:\winnt\system32\wbem\Repository
2010-01-24 21:25 . 2010-01-28 00:41 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-01-24 21:11 . 2010-01-14 17:59 66952 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-01-24 21:06 . 2010-01-24 21:06 ——– d—–w- c:\documents and settings\Owner\PrivacIE(2)
2010-01-24 21:06 . 2010-01-24 21:06 ——– d—–w- c:\documents and settings\Owner\IECompatCache(2)
2010-01-24 21:04 . 2010-01-24 21:25 ——– d—–w- C:\RECYCLER(2)
2010-01-24 20:52 . 2010-01-24 20:52 ——– d—–w- c:\documents and settings\Owner\IETldCache(2)
2010-01-24 20:52 . 2010-01-24 21:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Windows Genuine Advantage(2)
2010-01-24 19:44 . 2010-01-24 21:27 ——– d—–w- c:\winnt\ERUNT
2010-01-24 19:44 . 2010-01-24 19:44 ——– d—–w- C:\!FixIEDef
2010-01-15 02:59 . 2010-01-15 03:51 ——– d—–w- c:\program files\NES Emulator
2010-01-14 22:23 . 2009-06-17 16:55 10384 —-a-w- c:\winnt\system32\drivers\LBeepKE.sys
2010-01-14 22:21 . 2009-07-20 17:25 301656 —-a-w- c:\winnt\system32\BtCoreIf.dll
2010-01-14 22:21 . 2009-07-20 17:26 84496 —-a-w- c:\winnt\system32\KemXML.dll
2010-01-14 22:21 . 2009-07-20 17:26 117264 —-a-w- c:\winnt\system32\KemWnd.dll
2010-01-14 22:21 . 2009-07-20 17:26 145936 —-a-w- c:\winnt\system32\KemUtil.dll
2010-01-14 22:21 . 2009-07-20 17:26 170512 —-a-w- c:\winnt\system32\kemutb.dll
2010-01-14 22:20 . 2010-01-14 22:24 ——– d—–w- c:\program files\Common Files\Logishrd
2010-01-14 22:20 . 2010-01-14 22:20 ——– d—–w- c:\program files\Logitech
2010-01-10 18:50 . 2008-04-14 01:11 21504 —-a-w- c:\winnt\system32\hidserv.dll
2010-01-10 18:50 . 2008-04-14 01:11 21504 —-a-w- c:\winnt\system32\dllcache\hidserv.dll
2010-01-08 20:30 . 2010-01-08 20:30 ——– d—–w- c:\program files\SystemRequirementsLab
2010-01-08 19:54 . 2009-11-21 15:51 471552 ——w- c:\winnt\system32\dllcache\aclayers.dll
2009-12-30 23:47 . 2009-12-30 23:47 ——– d—–w- c:\program files\Firaxis Games

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-28 01:08 . 2010-01-24 21:26 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-01-28 00:44 . 2010-01-24 21:25 ——– d—–w- c:\documents and settings\Owner\Application Data\MSN6
2010-01-28 00:43 . 2010-01-24 21:25 ——– d—–w- c:\documents and settings\Owner\Application Data\Move Networks
2010-01-28 00:43 . 2010-01-24 21:25 ——– d—–w- c:\documents and settings\Owner\Application Data\Canon
2010-01-28 00:42 . 2010-01-24 21:25 ——– d—–w- c:\documents and settings\Owner\Application Data\Audacity
2010-01-28 00:41 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo!
2010-01-28 00:41 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\SSScanAppDataDir
2010-01-28 00:39 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\MSN6
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\InterTrust
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Symantec
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\McAfee
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\CA
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\SSScanWizard
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\ScanSoft
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Motive
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-24 21:26 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Yahoo
2010-01-24 20:19 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Trend Micro
2010-01-24 20:18 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-01-24 20:18 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\SBSI
2010-01-24 20:18 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\muvee Technologies
2010-01-24 20:18 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Musicnotes
2010-01-24 20:18 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2010-01-24 20:18 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-24 20:11 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Logitech
2010-01-24 20:11 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-01-24 20:11 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\InstallShield
2010-01-24 20:11 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Broderbund LLC
2010-01-24 20:11 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2010-01-24 20:11 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2010-01-24 20:10 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-01-24 20:10 . 2010-01-24 21:26 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2010-01-24 19:38 . 2005-01-16 22:02 178 —-a-w- c:\documents and settings\Administrator\ntuser.ini.vir
2010-01-24 19:38 . 2005-01-16 22:02 594832 —-a-w- c:\documents and settings\Administrator\Local Settings\Application Data\IconCache.db.vir
2010-01-24 00:42 . 2009-04-29 17:47 ——– d—–w- c:\program files\SpywareBlaster
2010-01-21 12:07 . 2008-02-19 00:48 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-14 22:23 . 2010-01-14 22:23 0 —ha-w- c:\winnt\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2010-01-14 22:23 . 2010-01-14 22:23 0 —ha-w- c:\winnt\system32\drivers\Msft_Kernel_LHidFilt_01005.Wdf
2010-01-14 22:23 . 2010-01-14 22:23 0 —ha-w- c:\winnt\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-01-14 22:21 . 2002-08-30 02:12 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-01-14 22:14 . 2002-09-07 14:50 ——– d—–w- c:\program files\ChainCast
2010-01-14 16:12 . 2009-10-03 13:08 181120 ——w- c:\winnt\system32\MpSigStub.exe
2010-01-11 16:35 . 2009-03-07 00:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-01-11 16:35 . 2009-04-23 17:08 5115824 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2010-01-08 20:39 . 2005-08-26 17:03 ——– d—–w- c:\program files\Java
2010-01-08 20:38 . 2010-01-08 20:38 152576 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-01-08 20:38 . 2009-11-08 16:24 79488 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-01-07 21:07 . 2009-03-07 00:04 38224 —-a-w- c:\winnt\system32\drivers\mbamswissarmy.sys
2010-01-07 21:07 . 2009-03-07 00:04 19160 —-a-w- c:\winnt\system32\drivers\mbam.sys
2009-12-29 15:22 . 2003-10-08 23:58 ——– d—–w- c:\program files\SPSS
2009-12-21 19:14 . 2004-02-06 22:05 916480 —-a-w- c:\winnt\system32\wininet.dll
2009-12-01 17:06 . 2004-05-29 18:33 ——– d—–w- c:\program files\Canon
2009-12-01 17:05 . 2009-12-01 17:05 ——– d—–w- c:\program files\ArcSoft
2009-12-01 17:03 . 2002-08-30 02:14 ——– d—–w- c:\program files\Microsoft Picture It! 2002
2009-11-21 15:51 . 2003-11-05 21:10 471552 —-a-w- c:\winnt\AppPatch\aclayers.dll
2004-11-04 23:49 . 2004-11-04 21:03 16706160 —-a-w- c:\program files\AdbeRdr60_enu_full.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft Works Update Detection"="c:\program files\Microsoft Works\WkDetect.exe" [BU]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-06-30 133104]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PROMon.exe"="PROMon.exe" [2002-04-18 73728]
"IgfxTray"="c:\winnt\system32\igfxtray.exe" [2005-06-21 155648]
"HotKeysCmds"="c:\winnt\system32\hkcmd.exe" [2005-06-21 126976]
"Hot Key Kbd 9910 Daemon"="SK9910DM.EXE" [2001-01-03 66048]
"GWMDMMSG"="GWMDMMSG.exe" [2002-05-07 65536]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-05 53248]
"YBrowser"="c:\progra~1\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 55824]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2003-07-15 34880]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
desktop.ini.vir [2001-10-9 84]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-1-14 813584]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2009-07-20 17:28 72208 —-a-w- c:\program files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\winnt\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AutoStart IR.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\AutoStart IR.lnk
backup=c:\winnt\pss\AutoStart IR.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CapFax]
2001-11-07 18:25 20480 ——w- c:\program files\PhoneTools\capFax.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-07-13 18:03 292128 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Portfolio]
2001-08-23 21:52 331830 —-a-w- c:\program files\Microsoft Works\wkssb.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Microsoft Works Update Detection]
2001-08-17 04:41 28738 —-a-w- c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 —-a-w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Omnipage]
2002-06-03 15:38 49152 —-a-w- c:\program files\ScanSoft\OmniPageSE\opware32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-05-26 21:18 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WorksFUD]
2001-10-06 00:34 24576 —-a-w- c:\program files\Microsoft Works\wkfud.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINNT\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\WINNT\\system32\\dplaysvr.exe"=
"c:\\WINNT\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R2 LBeepKE;LBeepKE;c:\winnt\system32\drivers\LBeepKE.sys [1/14/2010 5:23 PM 10384]
R3 HCWBT8xx;Hauppauge WinTV 848/9 WDM Video Driver;c:\winnt\system32\drivers\HCWBT8XX.sys [1/11/2007 6:28 PM 472644]
S2 gupdate1c9cea0ad676636;Google Update Service (gupdate1c9cea0ad676636);c:\program files\Google\Update\GoogleUpdate.exe [5/6/2009 6:16 PM 133104]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 6:19 PM 13592]
S3 EVOLUSB;%EVOL_USB_SvcDesc%;c:\winnt\system32\drivers\evolusb.sys –> c:\winnt\system32\drivers\evolusb.sys [?]
S3 iscFlash;iscFlash;\??\c:\winnt\SYSTEM32\DRIVERS\iscflash.sys –> c:\winnt\SYSTEM32\DRIVERS\iscflash.sys [?]
S3 PCDRDRV;Pcdr Helper Driver;\??\c:\atf\Qctest\PCDoc\PCDRDRV.sys –> c:\atf\Qctest\PCDoc\PCDRDRV.sys [?]
.
Contents of the 'Scheduled Tasks' folder

2010-01-26 c:\winnt\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]

2010-01-28 c:\winnt\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 23:16]

2010-01-28 c:\winnt\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-05-06 23:16]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://flashline.kent.edu/cp/home/loginf
uInternet Settings,ProxyOverride = *.local
DPF: Microsoft XML Parser for Java - file://c:\winnt\Java\classes\xmldso.cab
DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} - hxxp://lads.myspace.com/upload/MySpaceUploader2.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-27 20:28
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(428)
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
c:\program files\common files\logishrd\bluetooth\LBTServ.dll

- - - - - - - > 'explorer.exe'(2328)
c:\winnt\system32\WININET.dll
c:\program files\Logitech\SetPoint\GameHook.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\winnt\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
c:\winnt\system32\ieframe.dll
c:\winnt\system32\webcheck.dll
c:\winnt\system32\WPDShServiceObj.dll
c:\winnt\system32\PortableDeviceTypes.dll
c:\winnt\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\winnt\wanmpsvc.exe
c:\winnt\system32\PROMon.exe
c:\winnt\system32\NMSSvc.exe
c:\winnt\system32\SK9910DM.EXE
c:\winnt\GWMDMMSG.exe
c:\progra~1\Yahoo!\browser\ycommon.exe
c:\program files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
.
**************************************************************************
.
Completion time: 2010-01-27 20:37:18 - machine was rebooted
ComboFix-quarantined-files.txt 2010-01-28 01:37
ComboFix2.txt 2010-01-24 21:00

Pre-Run: 26,899,423,232 bytes free
Post-Run: 26,865,803,264 bytes free

- - End Of File - - 73918648AD298CCFF4E908D1FC6C5517

Hi, what do you mean by new Hijack this log? Did you have me run this before? Thanks.

Sorry, a typo there. Will be back soon for instructions. :)

Thanks
Hi,

I need you to make a batch file.

Open a new Notepad session

  • Click the Start button, click Run
  • In the run box type notepad
  • Click OK
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
@echo off
ren "c:\documents and settings\Administrator\ntuser.ini.vir" ntuser.ini
ren "c:\documents and settings\Administrator\Local Settings\Application Data\IconCache.db.vir" IconCache.db
ren "c:\documents and settings\Administrator\Start Menu\Programs\Startup\desktop.ini.vir" desktop.ini
del /Q %0

In the notepad

Click File, Save as…, and set the Save in to your Desktop
In the filename box, type (including quotation marks) as the filename: "fix.bat"
Click Save


You should now have a file on your desktop with an icon like this [external image: Posted Image]

Double click on fix.bat & allow it to run. A small black screen may briefly flash on and off, that normal.

===================================================

Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

===================================================

On your next reply please post :
How is your computer behaving? Are you still being redirected?
ESET log

Good Day!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI