Dave1022
Topic Starter
First, thank you in advance for any help you can provide!!
I am helping a friend who's machine was infested with viruses. McAfee had been disabled, and would only boot in safe mode. Having some experience, I set out to aid another buddy. Using Malwarebyes (free, regular and safemode scans) and Hitman Pro 3 (free) cleaned close to 200 items. These primarily included adware for my-search with several other trojans (I have all the logs). Machine came back to life with some coaching and is running seemingly well overall.
Next step was to ensure his Windows was up-to-date as part of my friendly and free buddy service. This is where the issue surfaced. The windows update page gives me a "cannot be displayed" message in both IE8 and Firefox (installed after cleanup when IE would not connect). I have seen messages that the connection had been reset. Search engines have also been hijacked that have "windows update" in the address. Google, Bing and Yahoo all have the same behavior. Click on a link that has any combination of windows update in the address and you are taken to an obscure web search engine page or some other unrelated site. If I paste the address directly into the address bar it DOES go to the correct address. Except the windows update page which will show "page cannot be displayed".
Hitman Pro and Malware bytes show clean, have checked IE DNS and proxy settings (unchecked), have disabled all add in's. Attached below is the requested DDS log taken just now. I will refrain from messing with anything else to maintain this baseline until you have a chance to respond.
Again, thank you for your assistance,
Dave
**********************************************
DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 12:14:40.53 on Sun 06/20/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1704 [GMT -5:00]
AV: Defense Center *On-access scanning enabled* (Outdated) {28e00e3b-806e-4533-925c-f4c3d79514b9}
AV: Webroot Internet Security Essentials *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: Webroot Internet Security Essentials *enabled* {63671000-11A2-46DD-BADD-A084CABCDEAE}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Smart PDF Creator\sspdfagentd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\System32\svchost.exe -k HPZ12
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Documents and Settings\Beth\Desktop\dds.scr
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uDefault_Page_URL = hxxp://www.msn.com
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\swg.dll
BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.1203.0\msneshellx.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
TB: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ArcSoft Connection Service] "c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe"
mRun: [SmartSoft PDF Printer (demo) Agent] "c:\program files\smart pdf creator\sspdfagentd.exe"
mRun: [SmartSoft PDF Printer (demo) virtual printer agent] "c:\program files\smart pdf creator\sspdfagentd.exe"
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [HitmanPro35] "c:\program files\hitman pro 3.5\HitmanPro35.exe" /scan:boot
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
IE: &Search
IE: Append Link Target to Existing PDF - c:\program files\common files\adobe\acrobat\activex\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: microsoft.com\update
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\beth\applic~1\mozilla\firefox\profiles\d0m3a7ib.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/
FF - plugin: c:\documents and settings\beth\application data\facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-4-14 385536]
S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-6-14 79816]
S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-6-14 35272]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2010-6-14 34248]
S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2010-6-14 40552]
S4 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2010-6-14 203280]
S4 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2010-6-14 359952]
S4 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2010-6-14 144704]
S4 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2010-6-14 606736]
=============== Created Last 30 ================
2010-06-19 20:12:45 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-06-19 20:08:52 0 d—–w- c:\program files\Hitman Pro 3.5
2010-06-19 19:34:28 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-19 19:24:07 0 d-sh–w- c:\documents and settings\beth\IECompatCache
2010-06-19 16:43:26 159744 —-a-w- c:\windows\system32\nvuenet.exe
2010-06-19 16:43:26 1556 —-a-w- c:\windows\system32\nvenet.nvu
2010-06-19 16:43:24 789 —-a-w- c:\windows\system32\nvsmb.nvu
2010-06-19 16:43:24 172032 —-a-w- c:\windows\system32\nvusmb.exe
2010-06-19 16:43:24 172032 —-a-w- c:\windows\system32\NVUNINST.EXE
2010-06-19 16:42:02 0 d—–w- C:\NVIDIA
2010-06-19 15:20:15 0 d—–w- c:\docume~1\beth\applic~1\Malwarebytes
2010-06-19 15:20:06 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-19 15:20:05 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-06-19 15:20:04 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-19 15:20:04 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-16 19:34:21 3059184 —-a-w- c:\program files\DMSetup-Serial.exe
2010-06-16 19:33:37 95568 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-06-15 03:00:26 1360 —-a-w- c:\windows\system32\Config.MPF
2010-06-15 02:35:51 23040 —-a-w- c:\windows\system32\psapi.dll
2010-06-15 02:32:58 79816 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2010-06-15 02:32:58 40552 —-a-w- c:\windows\system32\drivers\mfesmfk.sys
2010-06-15 02:32:58 35272 —-a-w- c:\windows\system32\drivers\mfebopk.sys
2010-06-15 02:32:52 120136 —-a-w- c:\windows\system32\drivers\Mpfp.sys
2010-06-15 02:32:27 0 d—–w- c:\program files\common files\McAfee
2010-06-15 02:32:26 0 d—–w- c:\program files\McAfee.com
2010-06-15 02:27:31 34248 —-a-w- c:\windows\system32\drivers\mferkdk.sys
2010-06-14 19:51:08 0 d–h–w- c:\windows\system32\GroupPolicy
2010-06-10 23:23:18 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-06-10 23:22:44 0 d—–w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-06-10 20:26:15 0 d—–w- c:\windows\McAfee.com
2010-06-10 05:07:19 0 d—–w- c:\docume~1\beth\applic~1\McAfee
2010-06-07 23:44:39 0 d—–w- c:\docume~1\beth\applic~1\W Photo Studio Viewer
2010-06-02 18:52:44 0 d—–w- c:\docume~1\beth\applic~1\KodakCredentialStore
2010-05-31 17:48:10 32656 —-a-w- c:\windows\system32\msonpmon.dll
2010-05-31 17:36:15 0 d—–w- c:\program files\Microsoft Visual Studio 8
2010-05-31 17:34:56 0 d—–w- c:\windows\SHELLNEW
2010-05-30 19:47:01 33280 -c–a-w- c:\windows\system32\dllcache\rundll32.exe
2010-05-30 19:47:01 33280 —-a-w- c:\windows\system32\rundll32.exe
2010-05-30 06:59:24 165376 —-a-w- c:\windows\system32\unrar.dll
2010-05-24 17:33:55 38 —-a-w- c:\windows\AviSplitter.INI
==================== Find3M ====================
2010-05-30 21:36:11 87608 —-a-w- c:\docume~1\beth\applic~1\inst.exe
2010-05-30 21:36:11 47360 —-a-w- c:\docume~1\beth\applic~1\pcouffin.sys
2010-05-01 17:46:48 54469632 —-a-w- c:\program files\AVSVideoConverter.exe
2009-09-17 04:02:48 111616 —-a-w- c:\program files\BlankProfile_97_03_final.doc
2009-09-17 03:52:34 111616 —-a-w- c:\program files\Blank Profile_97_2003_2.doc
2009-01-07 22:52:38 12340814 —-a-w- c:\program files\ta08stdw.exe
2009-10-16 15:46:31 245760 –sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
2009-09-01 18:11:06 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082420090831\index.dat
2009-09-01 18:11:06 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009090120090902\index.dat
============= FINISH: 12:16:03.26 ===============
********************************