This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

exe on c:\windows\temp come back after deleting them

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 5:34:07 PM, on 8/20/2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\CTHELPER.EXE D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe D:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe C:\WINDOWS\system32\szetyj67vx.exe C:\WINDOWS\fonts\services.exe C:\Program Files\Symantec\Backup Exec System Recovery\Shared\Drivers\SymSnapService.exe C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe C:\Program Files\Password Safe\pwsafe.exe C:\DOCUME~1\Fede\LOCALS~1\Temp\alr5m1.exe D:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE C:\WINDOWS\system32\scvhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\TEMP\VRT5.tmp D:\Program Files\Microsoft Office\Office10\WINWORD.EXE D:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe D:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Documents and Settings\Fede\Desktop\HiJackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,,C:\WINDOWS\system32\ini.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" O4 - HKLM\..\Run: [Symantec Backup Exec System Recovery 2010] "C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [Adobe Photo Downloader] "D:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe" O4 - HKLM\..\Run: [wuaucldt] c:\windows\system32\wuaucldt.exe O4 - HKLM\..\Run: [cftmon] C:\WINDOWS\system32\cftmon.exe O4 - HKLM\..\Run: [szetyj67v] C:\WINDOWS\system32\szetyj67v.exe O4 - HKLM\..\Run: [szetyj67vx] C:\WINDOWS\system32\szetyj67vx.exe O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe O4 - HKLM\..\Policies\Explorer\Run: [ipmu4a] C:\WINDOWS\TEMP\alr5m1.exe O4 - HKLM\..\Policies\Explorer\Run: [apps] C:\WINDOWS\fonts\services.exe O4 - HKUS\S-1-5-18\..\Run: [wuaucldt] c:\windows\system32\config\systemprofile\wuaucldt.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\Run: [NetLog2] C:\WINDOWS\svc2.exe (User 'SYSTEM') O4 - HKUS\S-1-5-18\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [wuaucldt] c:\windows\system32\config\systemprofile\wuaucldt.exe (User 'Default user') O4 - HKUS\.DEFAULT\..\RunOnce: [SetDefaultMidi] MIDIDEF.EXE (User 'Default user') O4 - Startup: Password Safe.lnk = C:\Program Files\Password Safe\pwsafe.exe O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: McAfee Security Scan Plus.lnk = ? O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: C:\WINDOWS\system32\0053.DLL O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - D:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Backup Exec System Recovery - Symantec Corporation - C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe O23 - Service: Bonjour Service - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing) O23 - Service: GenericMount Helper Service - Symantec - C:\Program Files\Symantec\Backup Exec System Recovery\Shared\Drivers\GenericMountHelper.exe O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: SymSnapService - Symantec - C:\Program Files\Symantec\Backup Exec System Recovery\Shared\Drivers\SymSnapService.exe O23 - Service: Windows Media Optimizer (WMOptimizer) - Unknown owner - C:\WINDOWS\system32\scvhost.exe – End of file - 8148 bytes
Hello Fede and welcome to WhatTheTech. Please follow these guidelines while we work on your PC:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
🖼Click to load external image (Posted Image) Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.scr
DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
🖼Click to load external image (Posted Image) Download GMER Rootkit Scanner from here to your desktop.
  • Double click the exe file. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.


    [external image: Posted Image]
    Click the image to enlarge it


  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have trouble running GEMR:
  • Make sure that your security software is disabled
  • Uncheck the box next to "Files" this time also
  • If you still can't run it, try in the Safe Mode
Please include the following in your next post:
  • DDS and Attach.txt logs
  • GMER log
DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 18:09:06.35 on Sat 08/21/2010 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.254 [GMT -6:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProSvc.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\CTHELPER.EXE D:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\Symantec\Backup Exec System Recovery\Agent\VProTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe D:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe C:\Program Files\Symantec\Backup Exec System Recovery\Shared\Drivers\SymSnapService.exe C:\Program Files\Password Safe\pwsafe.exe C:\WINDOWS\system32\scvhost.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter D:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe D:\Program Files\Microsoft Office\Office10\WINWORD.EXE D:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE C:\WINDOWS\system32\taskmgr.exe D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcrobatInfo.exe J:\dds.scr ============== Pseudo HJT Report =============== uStart Page = about:blank mWinlogon: Userinit=c:\windows\system32\userinit.exe,,c:\windows\system32\ini.exe BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - d:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll mRun: [CTHelper] CTHELPER.EXE mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [nwiz] nwiz.exe /installquiet mRun: [Acrobat Assistant 7.0] "d:\program files\adobe\acrobat 7.0\distillr\Acrotray.exe" mRun: [] mRun: [Symantec Backup Exec System Recovery 2010] "c:\program files\symantec\backup exec system recovery\agent\VProTray.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup mRun: [Adobe Photo Downloader] "d:\program files\adobe\photoshop elements 4.0\apdproxy.exe" mRun: [wuaucldt] c:\windows\system32\wuaucldt.exe mRun: [cftmon] c:\windows\system32\cftmon.exe mRun: [Regedit32] c:\windows\system32\regedit.exe dRun: [wuaucldt] c:\windows\system32\config\systemprofile\wuaucldt.exe dRun: [NetLog2] c:\windows\svc2.exe dRunOnce: [SetDefaultMidi] MIDIDEF.EXE mExplorerRun: [apps] c:\windows\fonts\services.exe StartupFolder: c:\docume~1\fede\startm~1\programs\startup\passwo~1.lnk - c:\program files\password safe\pwsafe.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobea~1.lnk - c:\windows\installer\{ac76ba86-1033-0000-7760-100000000002}\SC_Acrobat.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\2.0.181\SSScheduler.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - d:\program files\microsoft office\office10\OSA.EXE IE: Convert link target to Adobe PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - d:\program files\adobe\acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - d:\progra~1\micros~1\office10\EXCEL.EXE/3000 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL AppInit_DLLs: c:\windows\system32\0053.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\fede\applic~1\mozilla\firefox\profiles\z79oo48o.default\ FF - component: d:\program files\mozilla firefox\extensions\{ab2ce124-6272-4b12-94a9-7303c7397bd1}\components\SkypeFfComponent.dll FF - plugin: d:\program files\adobe\acrobat 7.0\acrobat\browser\nppdf32.dll FF - plugin: d:\program files\mozilla firefox\plugins\npatgpc.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); d:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); d:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); d:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); d:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); d:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); d:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24); d:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096); d:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); d:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); d:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); d:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); d:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); d:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); d:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); d:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); d:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R2 Backup Exec System Recovery;Backup Exec System Recovery;c:\program files\symantec\backup exec system recovery\agent\VProSvc.exe [2009-10-1 4585312] R2 WMOptimizer;Windows Media Optimizer;c:\windows\system32\scvhost.exe service –> c:\windows\system32\scvhost.exe service [?] R3 GenericMount;Generic Mount Driver;c:\windows\system32\drivers\GenericMount.sys [2009-9-21 46192] R3 SymSnapService;SymSnapService;c:\program files\symantec\backup exec system recovery\shared\drivers\SymSnapService.exe [2009-9-21 1964528] S3 GenericMount Helper Service;GenericMount Helper Service;c:\program files\symantec\backup exec system recovery\shared\drivers\GenericMountHelper.exe [2009-9-21 1571336] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-3-4 30192] S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232] S3 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-8-4 32256] =============== Created Last 30 ================ 2010-08-20 23:22:03 0 —ha-w- c:\windows\system32\wupd.dat 2010-08-19 09:27:18 72192 —-a-w- c:\windows\system32\ini.exe 2010-08-19 09:27:18 38400 —-a-w- c:\windows\system32\0053.DLL 2010-08-19 09:10:09 206 —-a-w- c:\windows\system32\MRT.INI 2010-08-18 20:43:27 0 d—–w- c:\windows\system32\LogFiles 2010-08-18 20:32:08 4 —-a-w- c:\documents and settings\fede\proxy_port 2010-08-18 20:30:40 62496 —-a-w- c:\windows\system32\MSWINSCK.OCX 2010-08-18 20:30:32 58 –sh–w- c:\windows\system32\User.ini 2010-08-18 20:30:30 269824 —-a-w- c:\windows\svc3.exe 2010-08-18 20:30:21 46080 —-a-w- c:\windows\system32\updata.exe 2010-08-18 20:29:50 40 —-a-w- c:\windows\system32\service.sys 2010-08-18 20:29:49 163328 —-a-w- c:\windows\system32\szetyj67v.exe 2010-08-18 20:29:38 180224 —-a-w- c:\windows\system32\szetyj67vx.exe 2010-08-18 20:29:32 106496 –sh–r- c:\windows\system32\cftmon.exe 2010-08-18 20:29:31 106496 –sh–r- c:\windows\system32\scvhost.exe 2010-08-18 20:29:17 269824 —-a-w- c:\windows\svc2.exe 2010-08-18 20:28:17 60672 —-a-w- c:\documents and settings\fede\wuaucldt.exe 2010-08-18 20:28:17 59392 —-a-w- c:\windows\system32\wuaucldt.exe ==================== Find3M ==================== 2010-08-22 00:08:16 84800 -c–a-w- c:\windows\system32\drivers\cdrom.sys 2010-08-21 00:45:16 4870 —h–w- c:\windows\fonts\mlog ============= FINISH: 18:09:53.06 =============== Unable to run gmer.exe. It reboots computer 20 seconds into it. Even after I uncheck those options (IAT, drives, etc and in safe mode)

Attachments:

Fede:

🖼Click to load external image (Posted Image) Please download Rootkit Unhooker and save it on your desktop.
  • Disable your security programs
  • Double click RKUnhookerLE.exe to run it
  • Click the Report tab, then click Scan
  • Check Drivers, Stealth Code, Files, and Code Hooks
  • Uncheck the rest, then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished then go File > Save Report
  • Save the report somewhere you can find it. Click Close
  • Copy the entire contents of the report and paste it in your next reply.
Note - You may get this warning it is ok, just ignore it:

"Rootkit Unhooker has detected a parasite inside itself!
It is recommended to remove parasite, okay?"

Please include the following in your next post:
  • Rootkit Unhooker log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI