This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help With Trojan

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Thank you for taking the time to help me. I have run Norton, Ad-Aware, Avast, and all have told me that a Trojan has been found and successfully quarantined. However, I am still having major issues with my computer. I am occasionally getting random webpages popping up. I usually use Mozilla, but even Internet Explorer pages pop up with garbage websites. Also, when I try to go a search either with Google or Yahoo, the list of results shows up, but than I get re-directed to another web-page. My comp is running quite slow as well. This has been going on for the past week or so since I downloaded a file from a P2P site and ran it (my mistake in the first place!!) I am hoping you can help, as I'm sure you can in reading all the other posts. I should also mention that nothing was produced when I ran the GMER (the one that was to be named ark.txt) Here is the info you need: Malwarebytes' Anti-Malware 1.44 Database version: 3670 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18882 31/01/2010 8:45:49 PM mbam-log-2010-01-31 (20-45-49).txt Scan type: Quick Scan Objects scanned: 97098 Time elapsed: 7 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 10 Registry Keys Infected: 1 Registry Values Infected: 1 Registry Data Items Infected: 21 Folders Infected: 3 Files Infected: 13 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\Windows\System32\cmutil32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\dbghelp32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\cnvfat32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\dbnetlib32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\comdlg3232.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\ddrawex32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\l4rui32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\e9uzkhl32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\epwdtbz332.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\whjwc932.dll (Trojan.Tracur) -> Delete on reboot. Registry Keys Infected: HKEY_CLASSES_ROOT\.fsharproj (Trojan.BHO) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rthdbpl (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\cmutil32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\cmutil32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\dbghelp32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\dbghelp32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\cnvfat32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\cnvfat32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\dbnetlib32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\dbnetlib32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\comdlg3232.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\comdlg3232.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\ddrawex32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\ddrawex32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\l4rui32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\l4rui32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\e9uzkhl32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\e9uzkhl32.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\epwdtbz332.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\epwdtbz332.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: c:\windows\system32\whjwc932.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Tracur) -> Data: system32\whjwc932.dll -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D} (Trojan.Swisyn) -> Quarantined and deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome (Trojan.Swisyn) -> Quarantined and deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content (Trojan.Swisyn) -> Quarantined and deleted successfully. Files Infected: C:\Windows\System32\cmutil32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\dbghelp32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\cnvfat32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\dbnetlib32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\comdlg3232.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\ddrawex32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\l4rui32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\e9uzkhl32.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\epwdtbz332.dll (Trojan.Tracur) -> Delete on reboot. C:\Windows\System32\whjwc932.dll (Trojan.Tracur) -> Delete on reboot. C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest (Trojan.Swisyn) -> Quarantined and deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf (Trojan.Swisyn) -> Quarantined and deleted successfully. C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}\chrome\content\timer.xul (Trojan.Swisyn) -> Quarantined and deleted successfully. DDS (Ver_09-12-01.01) - NTFSX64 Run by [removed] at 21:12:10.94 on 31/01/2010 Internet Explorer: 8.0.6001.18882 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.2.1033.18.8181.6142 [GMT -6:00] SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\LSI SoftModem\agr64svc.exe c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\WUDFHost.exe C:\Windows\System32\mobsync.exe C:\PROGRA~1\HEWLET~1\HPREMO~1\HPREMO~1.EXE C:\Program Files (x86)\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe C:\Windows\SysWOW64\DllHost.exe C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe C:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe C:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\Java\jre6\bin\jusched.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Windows\system32\conime.exe C:\Program Files (x86)\Mozilla Firefox\firefox.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe C:\Users\The Hyatt Family\AppData\Local\Temp\Temp1_gmer.zip\gmer.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\The Hyatt Family\Downloads\dds(2).scr C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.ca/ uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=93&bd=Pavilion&pf=cndt mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=93&bd=Pavilion&pf=cndt mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=93&bd=Pavilion&pf=cndt mLocal Page = c:\windows\syswow64\blank.htm BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files (x86)\norton internet security\engine\16.8.0.41\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files (x86)\norton internet security\engine\16.8.0.41\IPSBHO.DLL BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files (x86)\java\jre6\bin\jp2ssv.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files (x86)\norton internet security\engine\16.8.0.41\coIEPlg.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [msnmsgr] "c:\program files (x86)\windows live\messenger\msnmsgr.exe" /background mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe mRun: [HP Health Check Scheduler] c:\program files (x86)\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [UpdateP2GoShortCut] "c:\program files (x86)\cyberlink\power2go\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\power2go" updatewithcreateonce "software\cyberlink\power2go\6.0" mRun: [UpdateLBPShortCut] "c:\program files (x86)\cyberlink\labelprint\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\labelprint" updatewithcreateonce "software\cyberlink\labelprint\2.5" mRun: [UpdatePDIRShortCut] "c:\program files (x86)\cyberlink\powerdirector\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\powerdirector" updatewithcreateonce "software\cyberlink\powerdirector\7.0" mRun: [UpdatePSTShortCut] "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe\muitransfer\muistartmenu.exe" "c:\program files (x86)\cyberlink\cyberlink dvd suite deluxe" updatewithcreateonce "software\cyberlink\PowerStarter" mRun: [TSMAgent] "c:\program files (x86)\hewlett-packard\touchsmart\media\TSMAgent.exe" mRun: [CLMLServer for HP TouchSmart] "c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\CLMLSvc.exe" mRun: [DVDAgent] "c:\program files (x86)\hewlett-packard\media\dvd\DVDAgent.exe" mRun: [HP Software Update] c:\program files (x86)\hp\hp software update\HPWuSchd2.exe mRun: [SunJavaUpdateSched] "c:\program files (x86)\java\jre6\bin\jusched.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~2\micros~4\office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\micros~4\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files (x86)\norton internet security\engine\16.8.0.41\CoIEPlg.dll BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - c:\program files\windows live\family safety\fssbho.dll BHO-X64: Windows Live Family Safety Browser Helper - No File BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun-x64: [HP Remote Software] c:\program files\hewlett-packard\hp remote\HP REMOTE V1.0.5.exe mRun-x64: [IgfxTray] c:\windows\system32\igfxtray.exe mRun-x64: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun-x64: [Persistence] c:\windows\system32\igfxpers.exe mRun-x64: [SmartMenu] %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe mRun-x64: [IAAnotif] "c:\program files (x86)\intel\intel matrix storage manager\iaanotif.exe" ================= FIREFOX =================== FF - ProfilePath - c:\users\thehya~1\appdata\roaming\mozilla\firefox\profiles\b7ymurax.default\ FF - prefs.js: browser.startup.homepage - www.yahoo.ca FF - plugin: c:\program files (x86)\microsoft\office live\npOLW.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-1-30 69152] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nisx64\1008000.029\SymEFA64.sys [2010-1-27 402992] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-1-31 120912] R1 BHDrvx64;Symantec Heuristics Driver;c:\windows\system32\drivers\nisx64\1008000.029\BHDrvx64.sys [2010-1-27 334384] R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nisx64\1008000.029\cchpx64.sys [2010-1-27 583296] R1 IDSVia64;IDSVia64;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100128.002\IDSviA64.sys [2010-1-29 466992] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-1-31 22096] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-1-31 63568] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-31 40384] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files (x86)\lavasoft\ad-aware\AAWService.exe [2009-12-2 1181328] R2 Norton Internet Security;Norton Internet Security;c:\program files (x86)\norton internet security\engine\16.8.0.41\ccSvcHst.exe [2010-1-27 117640] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-1-30 132656] R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\system32\drivers\nisx64\1008000.029\symndisv.sys [2010-1-27 56880] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-31 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-1-31 40384] S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-12-3 89920] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2009-9-10 61280] S3 fsssvc;Windows Live Family Safety Service;c:\program files (x86)\windows live\family safety\fsssvc.exe [2009-8-5 704864] S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-2-2 23536] S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968] ============== File Associations =============== JSEFile=c:\windows\syswow64\WScript.exe "%1" %* =============== Created Last 30 ================ 2010-02-01 02:36:38 0 d—–w- c:\users\thehya~1\appdata\roaming\Malwarebytes 2010-02-01 02:36:28 0 d—–w- c:\programdata\Malwarebytes 2010-02-01 02:36:27 22104 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-02-01 02:36:25 0 d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2010-02-01 01:13:34 63568 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys 2010-02-01 01:13:34 0 —-a-w- c:\windows\syswow64\config.nt 2010-02-01 01:12:19 38848 —-a-w- c:\windows\syswow64\avastSS.scr 2010-02-01 01:12:19 152672 —-a-w- c:\windows\syswow64\aswBoot.exe 2010-02-01 01:11:54 0 d—–w- c:\programdata\Alwil Software 2010-02-01 01:11:54 0 d—–w- c:\program files\Alwil Software 2010-01-31 15:15:43 0 d—–w- c:\users\thehya~1\appdata\roaming\Uniblue 2010-01-31 04:28:42 15880 —-a-w- c:\windows\system32\lsdelete.exe 2010-01-31 01:49:01 69152 —-a-w- c:\windows\system32\drivers\Lbd.sys 2010-01-31 00:21:43 0 dc-h–w- c:\programdata\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9} 2010-01-31 00:17:44 0 d—–w- c:\programdata\Lavasoft 2010-01-31 00:17:44 0 d—–w- c:\program files (x86)\Lavasoft 2010-01-29 13:15:31 0 d-sh–w- C:\found.000 2010-01-28 00:19:12 0 d-sh–w- c:\users\thehya~1\appdata\roaming\SystemProc 2010-01-28 00:14:04 1372 —-a-w- c:\users\thehya~1\appdata\roaming\DAVh0.vbs 2010-01-28 00:07:58 0 d—–w- c:\programdata\Apple 2010-01-26 16:12:44 580096 —-a-w- c:\windows\system32\ac3filter64.acm 2010-01-26 16:12:44 497664 —-a-w- c:\windows\syswow64\ac3filter.acm 2010-01-26 16:12:43 0 d—–w- c:\program files (x86)\AC3Filter 2010-01-23 19:55:52 0 d—–w- c:\users\thehya~1\appdata\roaming\Friday's games 2010-01-23 14:54:25 0 d—–w- c:\program files (x86)\Vacation Mogul 2010-01-21 23:57:57 0 d—–w- c:\users\thehya~1\appdata\roaming\World-Loom 2010-01-20 13:00:59 0 d—–w- c:\program files (x86)\Fix-It-Up - World Tour 2010-01-20 12:59:51 0 d—–w- c:\program files (x86)\Sally's Spa 2010-01-19 00:44:01 0 d—–w- c:\program files (x86)\easyMule 2010-01-14 00:13:51 0 d—–w- c:\windows\Farm Frenzy 3 American Pie 2010-01-14 00:13:51 0 d—–w- c:\program files (x86)\Farm Frenzy 3 American Pie 2010-01-13 06:48:21 96256 —-a-w- c:\windows\system32\fontsub.dll 2010-01-13 06:48:21 72704 —-a-w- c:\windows\syswow64\fontsub.dll 2010-01-13 06:48:21 189440 —-a-w- c:\windows\system32\t2embed.dll 2010-01-13 06:48:21 156672 —-a-w- c:\windows\syswow64\t2embed.dll 2010-01-10 22:42:33 0 d—–w- c:\programdata\FarmFrenzy3_America 2010-01-07 12:57:46 0 d—–w- c:\program files (x86)\Princess Isabella - A Witch's Curse 2010-01-07 12:56:40 0 d—–w- c:\program files (x86)\Drawn - The Painted Tower ==================== Find3M ==================== 2010-01-31 22:08:59 6044 —-a-w- c:\users\thehya~1\appdata\roaming\wklnhst.dat 2010-01-02 07:08:29 1147904 —-a-w- c:\windows\system32\wininet.dll 2010-01-02 07:03:21 77312 —-a-w- c:\windows\system32\iesetup.dll 2010-01-02 07:03:21 132096 —-a-w- c:\windows\system32\iesysprep.dll 2010-01-02 06:38:20 916480 —-a-w- c:\windows\syswow64\wininet.dll 2010-01-02 06:38:04 1208832 —-a-w- c:\windows\syswow64\urlmon.dll 2010-01-02 06:36:10 206848 —-a-w- c:\windows\syswow64\occache.dll 2010-01-02 06:33:34 5942784 —-a-w- c:\windows\syswow64\mshtml.dll 2010-01-02 06:33:32 594432 —-a-w- c:\windows\syswow64\msfeeds.dll 2010-01-02 06:33:32 55296 —-a-w- c:\windows\syswow64\msfeedsbs.dll 2010-01-02 06:32:51 25600 —-a-w- c:\windows\syswow64\jsproxy.dll 2010-01-02 06:32:33 71680 —-a-w- c:\windows\syswow64\iesetup.dll 2010-01-02 06:32:33 1985536 —-a-w- c:\windows\syswow64\iertutil.dll 2010-01-02 06:32:33 164352 —-a-w- c:\windows\syswow64\ieui.dll 2010-01-02 06:32:33 109056 —-a-w- c:\windows\syswow64\iesysprep.dll 2010-01-02 06:32:32 55808 —-a-w- c:\windows\syswow64\iernonce.dll 2010-01-02 06:32:32 184320 —-a-w- c:\windows\syswow64\iepeers.dll 2010-01-02 06:32:32 11070464 —-a-w- c:\windows\syswow64\ieframe.dll 2010-01-02 06:32:26 387584 —-a-w- c:\windows\syswow64\iedkcs32.dll 2010-01-02 05:25:39 162816 —-a-w- c:\windows\system32\ieUnatt.exe 2010-01-02 04:57:00 133632 —-a-w- c:\windows\syswow64\ieUnatt.exe 2010-01-02 04:56:50 173056 —-a-w- c:\windows\syswow64\ie4uinit.exe 2010-01-02 04:56:14 13312 —-a-w- c:\windows\syswow64\msfeedssync.exe 2009-12-05 01:41:42 86016 —-a-w- c:\windows\inf\infstor.dat 2009-12-05 01:41:42 665600 —-a-w- c:\windows\inf\drvindex.dat 2009-12-05 01:41:42 51200 —-a-w- c:\windows\inf\infpub.dat 2009-12-05 01:41:42 143360 —-a-w- c:\windows\inf\infstrng.dat 2009-12-05 01:41:32 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2009-12-04 02:58:56 37665 —-a-w- c:\windows\fonts\GlobalUserInterface.CompositeFont 2009-11-09 13:01:54 32768 —-a-w- c:\windows\system32\nshhttp.dll 2009-11-09 12:59:52 33792 —-a-w- c:\windows\system32\httpapi.dll 2009-11-09 12:31:42 24064 —-a-w- c:\windows\syswow64\nshhttp.dll 2009-11-09 12:30:03 30720 —-a-w- c:\windows\syswow64\httpapi.dll 2008-01-21 03:21:59 174 –sha-w- c:\program files\desktop.ini 2008-01-21 03:21:59 174 –sha-w- c:\program files (x86)\desktop.ini 2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 15:14:56 30674 —-a-w- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 15:14:56 287440 —-a-w- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:52:12 287440 —-a-w- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:52:10 30674 —-a-w- c:\windows\inf\perflib\0000\perfc.dat 2009-07-06 19:00:05 8192 –sha-w- c:\windows\users\default\NTUSER.DAT ============= FINISH: 21:12:59.58 ===============
I just wanted to confirm that it was, in fact, GMER that did not produce any results, and therefore I did not include it in my first post - "GMER hasn't found any system modification" Just want to be clear so you have all the info you need. Thanks again, much appreciated!!!
Thanks for your reply. I am not getting the searches re-directed in Google or Yahoo anymore. However, the Yahoo webpage looks really messed up and can't display any pictures from the site. Some webpages load fine, while others have the same problem as the Yahoo webpage. Also, I am not able to access Hotmail through Mozilla, but am able to through Internet Explorer. Could the virus have affected Mozilla somehow? I have run Norton and all it finds is one tracking cookie, but no viruses. I ran Kaspersky online and it found a virus - Trojan.Win32.Chifrax.d Other than that, everything seems OK. What do you suggest?
To empty the cache in firefox 1. click on tools > options 2. click on the Privacy button on the left side of the window 3. click the "Clear All" button to clear all cached items or select individual items to clear by clicking on individual "Clear" buttons (History, Saved Information, Saved Passwords, Download Manager History, Cookies, Cache)
Thanks, Firefox and IE both work properly now. How I can get rid of that virus that gets detected by Kaspersky? Trojan.Win32.Chifrax.d Thanks again for all you do to help!!
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.


Also please describe how your computer behaves at the moment.
When I tried running Combofix, it loaded and all the icons blinked for a second. Then it told me that it is only compatible with Windows 2000 and XP. I have Vista. What should I do?
Vista and Windows 7 users: 1. These tools MUST be run from the executable. (.exe) every time you run them 2. With Admin Rights (Right click, choose "Run as Administrator")

I am running Windows Home Premium 64-bit.

That's why. 64 bit

Go to Kaspersky and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
  • Spyware, Adware, Dialers, and other potentially dangerous programs
    Archives
    Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to your desktop. Change the Files of type to TXT before clicking on the Save. Then post the results.
Here is the result of the scan: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, February 3, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 64-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, February 03, 2010 23:23:00 Records in database: 3405183 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ Scan statistics: Objects scanned: 166207 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 02:13:44 File name / Threat / Threats count C:\Users\The Hyatt Family\Documents\Azureus Downloads\BigFishGames.Be.Richer.v1.0.WinAll.Cracked.GAME\Setup.exe Infected: Trojan.Win32.Chifrax.d 1 Selected area has been scanned.
I think you can see where the infection came from. C:\Users\The Hyatt Family\Documents\Azureus Downloads\BigFishGames.Be.Richer.v1.0.WinAll.Cracked.GAME\Setup.exe I'd suggest you uninstall the cracked software.
Uninstalled software, ran Kaspersky again and no virus found. Everything seems OK. Thanks for all of your help!! You guys and gals are awesome!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI