This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unknown Infection

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O33 - MountPoints2\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\Shell - "" = AutoRun
    O33 - MountPoints2\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    O33 - MountPoints2\{70c635f0-b861-11de-a477-00a0cc3f1eca}\Shell - "" = AutoRun
    O33 - MountPoints2\{70c635f0-b861-11de-a477-00a0cc3f1eca}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{70c635f0-b861-11de-a477-00a0cc3f1eca}\Shell\AutoRun\command - "" = F:\LaunchU3.exe – File not found
    O33 - MountPoints2\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\Shell - "" = AutoRun
    O33 - MountPoints2\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\Shell\AutoRun - "" = Auto&Play
    O33 - MountPoints2\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\Shell\AutoRun\command - "" = E:\LaunchU3.exe – File not found
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
===================================================

Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :dir
    C:\Documents and Settings\Owner\Local Settings\Application Data\hgqlrggjs /s
    C:\Documents and Settings\Owner\Local Settings\Application Data\kngmupcgq /s
    C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} /s
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt

===================================================

Re-run Malwarebytes' Anti-Malware
  • Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
    • Go to Update tab to update Malwarebytes' Anti-Malware
  • Then click Check for Updates.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform Quick Scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
OTL log
SystemLook log
MBAM log

Good Day!
Thank you, Conspire.

OTL log

All processes killed
========== OTL ==========
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41013150-b6bd-11dd-aa22-00a0cc3f1eca}\ not found.
File E:\LaunchU3.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70c635f0-b861-11de-a477-00a0cc3f1eca}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70c635f0-b861-11de-a477-00a0cc3f1eca}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70c635f0-b861-11de-a477-00a0cc3f1eca}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70c635f0-b861-11de-a477-00a0cc3f1eca}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{70c635f0-b861-11de-a477-00a0cc3f1eca}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{70c635f0-b861-11de-a477-00a0cc3f1eca}\ not found.
File F:\LaunchU3.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a1bf12d0-808a-11de-a40b-00a0cc3f1eca}\ not found.
File E:\LaunchU3.exe not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 346096 bytes
->Flash cache emptied: 1899 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 37910058 bytes
->Flash cache emptied: 17612 bytes

User: Owner
->Temp folder emptied: 861228088 bytes
->Temporary Internet Files folder emptied: 293706584 bytes
->Java cache emptied: 81158477 bytes
->Google Chrome cache emptied: 6456803 bytes
->Flash cache emptied: 586184 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1119359 bytes
%systemroot%\System32 .tmp files removed: 3594257 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 85532720 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 2316 bytes

Total Files Cleaned = 1,308.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Default User

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 405 bytes

User: Owner
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.9.1 log created on 08102010_211003

Files\Folders moved on Reboot…
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XTR8CD5A\signup2_mb[1].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\APWLE7LL\jump1[2].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8IQLVFHY\general[1].css not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8IQLVFHY\onus1[1].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1KOV8BCV\flexcrollstyles[1].css not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1KOV8BCV\flexcroll[1].js moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\JETC44D.tmp not found!
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\HKY388RE\indexCAIWQH8R.htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\HKY388RE\like[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\88MGJ7JI\iframe[1].htm moved successfully.
File\Folder C:\WINDOWS\temp\07b02e78-bd31-4773-87df-8c163557640e.tmp not found!
File\Folder C:\WINDOWS\temp\0a2dbed0-3855-4e87-bf7f-b0bea4ee8de7.tmp not found!
C:\WINDOWS\temp\3b7d3be2-f888-4dd0-8790-5907902be48a.tmp moved successfully.
File\Folder C:\WINDOWS\temp\3def6bec-79cf-4723-b4c3-c0f9b28a6943.tmp not found!
File\Folder C:\WINDOWS\temp\46bb4e6e-7559-45b9-98a7-23a1423e229d.tmp not found!
C:\WINDOWS\temp\5e26f0df-205f-4a84-9804-39dd1535ed30.tmp moved successfully.
C:\WINDOWS\temp\5fbe6887-8764-4213-b2ad-61cbb181be70.tmp moved successfully.
File\Folder C:\WINDOWS\temp\8481d721-d0c8-4650-94ca-11b7cb2c1f30.tmp not found!
File\Folder C:\WINDOWS\temp\8c932e78-b757-4f0c-95a6-219be0a68199.tmp not found!
File\Folder C:\WINDOWS\temp\96ac3a4d-4f46-4c5d-baef-9d1e70b03be4.tmp not found!
File\Folder C:\WINDOWS\temp\bec122b0-24df-4ffb-81cd-3e200ef7d07b.tmp not found!
File\Folder C:\WINDOWS\temp\c5c89a03-e0ef-4f8a-a840-927fb9f5b590.tmp not found!
File\Folder C:\WINDOWS\temp\cd4a4472-46a1-42b6-bf26-df9777afae2b.tmp not found!
File\Folder C:\WINDOWS\temp\ee2a3116-e6aa-43cb-98e3-9b9c8d881ef6.tmp not found!

Registry entries deleted on Reboot…

SystemLook log

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 21:32 on 10/08/2010 by Owner (Administrator - Elevation successful)

========== dir ==========

C:\Documents and Settings\Owner\Local Settings\Application Data\hgqlrggjs - Parameters: "/s"

—Files—
None found.

No folders found.

C:\Documents and Settings\Owner\Local Settings\Application Data\kngmupcgq - Parameters: "/s"

—Files—
None found.

No folders found.

C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} - Parameters: "/s"

—Files—
None found.

C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86 d—– [07:30 07/03/2010]
DIFxAPI.dll –a— 319456 bytes [15:21 02/11/2006] [15:21 02/11/2006]
DifXInstall32.exe –a— 75112 bytes [22:56 04/02/2009] [22:56 04/02/2009]
DIFxInstallLog.txt –a–c 3654 bytes [07:31 07/03/2010] [07:31 07/03/2010]
GEARAspiWDM.inf –a–c 2763 bytes [22:48 18/05/2009] [22:48 18/05/2009]
gearaspiwdmx86.cat –a–c 7994 bytes [18:32 03/06/2009] [18:32 03/06/2009]

C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}\x86\x86 d—– [07:30 07/03/2010]
GEARAspi.dll –a— 107368 bytes [21:12 17/04/2008] [21:12 17/04/2008]
GEARAspiWDM.sys –a— 26600 bytes [22:17 18/05/2009] [22:17 18/05/2009]

-=End Of File=-

MBAM log

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4417

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

8/10/2010 9:59:59 PM
mbam-log-2010-08-10 (21-59-59).txt

Scan type: Quick scan
Objects scanned: 135793
Time elapsed: 22 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
FYI~ My pc is still launching a new IE window that I am closing before full launch. So I cannot see the webpage it's trying to load.
Ok, will take note of that. I'm awaiting for approval for further instructions, so please bear with me. Thanks
Hi,

Please post a fresh OTL log in your next reply without copy/paste the custom command given earlier.

Then,

Kaspersky Online Scanner in IE

I recommend you to leave your computer on for the whole night as the scanning will take longer than you expected.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

Please go to Kaspersky website and click on Kaspersky Online Scanner to perform an online scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.

    [external image: Posted Image]
  • Please post this log in your next reply.

**Note

For clearer guidance, here's the animated tutorial :-

Click here

To optimize scanning time and produce a more sensible report for review:
  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan. Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.

===================================================

On your next reply please post :
OTL log
Kaspersky report

Good Day!
First try…pc froze during installation of Kaspersky scanner and virus definitions. Soft boot to restart. Got as far as 45 minutes into the Kaspersky scan and a virus came up, caught by AVG??? AVG Firewall, Resident Shield and antispy were turned off prior to scan, how could that happen? AVG strongly recommend to restart, I chose to ignore. This is when my pc froze up. Do you think if I update Windows, this may help?

Do you think if I update Windows, this may help?

Not yet as your PC is still not free from malware.

You deactivated AVG on the first boot or second boot? Please refer to the instructions provided in AVG FAQ 2429: How to temporarily disable AVG Free Edition 9.0.

Make sure each time you boot up the AVG real time protection is off, because the auto start may have activated it.

If not, give another scanner a try.

Eset online scannner

You can use either Internet Explorer or Mozilla FireFox for this scan.

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish.
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.
Thank you… ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=7.00.6000.17055 (vista_gdr.100414-0533) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=3627fee554b69a41ab94408b743d0e50 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2010-08-13 05:45:28 # local_time=2010-08-12 10:45:28 (-0800, Pacific Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1031 16777189 100 92 0 982767 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=49345 # found=1 # cleaned=0 # scan_time=5584 C:\Documents and Settings\Owner\Application Data\Sun\Java\Deployment\cache\6.0\47\6cce12f-4c69b2dc multiple threats 00000000000000000000000000000000 I

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI