This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Jacked Up

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Last Friday when I got to work my computer was jacked up. So I restoed it back to a previous restore point and run a variety of software removal tools to eliminate a bunch of stuff (i.e. SuperAntiSpyware, Symatic Antivirus, SpyBot, System Mechanic, etc.)

The problems I have noted so far are:

1) Directories and files have become hidden (i.e. Toad, Visual Studio, Internet Favorites, etc.)

2) While searching on the internet clicking one of the links goes to some random webpage.

3) When I am not on the internet I receive random script errors in a popup to some URL I've never heard of and asking if I want to continue running scripts on this page.

4) When I login to my Yahoo email after a minute or so it automatically logs me out.

Any help would be greatly appreciated.

Here is the hijackthis.log….
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:20:44 AM, on 05/02/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.17514)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\tim\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = alpine.local
O17 - HKLM\Software\..\Telephony: DomainName = alpine.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = alpine.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = alpine.local
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASPEN Information Service - Alpine Technology Group - C:\Program Files\ASPEN Information Service\ASPENInformationService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Broadcom Power monitoring service (BPowMon) - Broadcom Corp. - C:\Program Files\Broadcom\BPowMon\BPowMon.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SQL Anywhere - aspen.NEWGUY (SQLANYs_aspen.NEWGUY) - iAnywhere Solutions, Inc. - C:\Program Files\SQL Anywhere 11\bin32\dbsrv11.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

–
End of file - 9185 bytes


Thanks
Hi Lyon,

Welcome to WhattheTech. My name is Blottedisk and I will be helping you with your malware issues. Before we delve into this, please take a look at the following notes:

  • Please subscribe to this topic, if you haven't already. You can subscribe by clicking the Watch Topic button to the right of your topic title and then choosing the notification method ( Recommended: Inmediate Notification)
  • Please avoid installing/uninstalling or updating any programs and attempting any unsupervised fixes or scans. This can make helping you impossible.
  • The forum is busy and we need to have replies as soon as possible. If I haven't had a reply after 3 days I will bump the topic and if you do not reply by the following day after that then the thread will be locked due to inactivity. However, if you will be away, let us know and we will be sure to keep the thread open.
——————————————————-

Ok, let's get started. Please follow the steps below in order:


Step 1 | Download DDS from any of the links below:

Link 1
Link 2
Link 2

——————————————————————–
  • Save it to your desktop.
  • Please disable any anti-malware program that will block scripts from running before running DDS.
  • Double-Click on dds and a command window will appear. This is normal.
  • Shortly after two logs will appear:
    • DDS.txt
    • Attach.txt
  • A window will open instructing you save & post the logs.
  • Save the logs to a convenient place such as your desktop.
  • Post the contents of the DDS.txt report in your next reply.
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.


Step 2 | Please download GMER from one of the following locations and save it to your desktop:

Main Mirror - This version will download a randomly named file (Recommended)
Zipped Mirror - This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.

——————————————————————–

  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Right-click on the randomly named GMER file (i.e. n7gmo46c.exe) and choose "Run as administrator" to run it. Allow the gmer.sys driver to load if asked.

Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then right-click on gmer.exe and choose "Run as administrator".

[external image: Posted Image]

  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system…click NO.
  • Make sure these options are all checked:
  • Services
  • Registry
  • Files
  • Systemdrive drive/partition, which is typically C:\
  • ADS

[external image: Posted Image]
Click the image to enlarge it

  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save… button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
– If you encounter any problems, try running GMER in Safe Mode.


Step 3 | Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
. DDS (Ver_11-03-05.01) - NTFSx86 Run by [removed] at 8:33:16.21 on 05/02/2011 Internet Explorer: 8.0.7601.17514 Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.3037.2175 [GMT -6:00] . SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\ASPEN Information Service\ASPENInformationService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Broadcom\BPowMon\BPowMon.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Symantec AntiVirus\SavRoam.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\SQL Anywhere 11\bin32\dbsrv11.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Symantec AntiVirus\VPTray.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\System32\ctfmon.exe C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Common Files\Java\Java Update\jucheck.exe C:\Users\tim\Desktop\HiJackThis.exe C:\Windows\system32\calc.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\tim\Desktop\dds.scr C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=c:\windows\system32\userinit.exe BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.5126.1836\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) dPolicies-explorer: HideSCAHealth = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\mif5ba~1\office11\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mif5ba~1\office11\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Notify: igfxcui - igfxdev.dll . ============= SERVICES / DRIVERS =============== . R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656] R2 AERTFilters;Andrea RT Filters Service;c:\program files\realtek\audio\hda\AERTSrv.exe [2010-11-9 81920] R2 ASPEN Information Service;ASPEN Information Service;c:\program files\aspen information service\ASPENInformationService.exe [2010-7-7 52736] R2 BPowMon;Broadcom Power monitoring service;c:\program files\broadcom\bpowmon\BPowMon.exe [2009-8-17 79168] R2 SavRoam;SavRoam;c:\program files\symantec antivirus\SavRoam.exe [2009-9-16 121744] R2 SQLANYs_aspen.NEWGUY;SQL Anywhere - aspen.NEWGUY;c:\program files\sql anywhere 11\bin32\dbsrv11.exe -hvsqlanys_aspen.newguy –> c:\program files\sql anywhere 11\bin32\dbsrv11.exe -hvSQLANYs_aspen.NEWGUY [?] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2009-9-16 1961768] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-4-18 102448] R3 k57nd60x;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\k57nd60x.sys [2010-11-9 273960] R3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-7-13 17920] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-23 136176] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2011-4-29 1153368] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-23 136176] S3 StorSvc;Storage Service;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 20992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2011-3-16 52224] . =============== File Associations =============== . exefile="%1" %*g??? . =============== Created Last 30 ================ . 2011-04-29 19:47:20 ——– d—–w- c:\program files\Spybot - Search & Destroy 2011-04-25 21:33:12 ——– d–h–w- C:\LocalSymbols 2011-04-21 15:45:48 ——– d–h–w- c:\windows\system32\Wat 2011-04-20 20:49:54 ——– d—–w- c:\program files\iPod 2011-04-20 20:47:15 ——– d—–w- c:\program files\Bonjour 2011-04-20 13:18:48 ——– d–h–w- c:\progra~2\SUPERAntiSpyware.com 2011-04-20 13:18:48 ——– d—–w- c:\users\tim\appdata\roaming\SUPERAntiSpyware.com 2011-04-20 13:18:43 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-04-19 17:23:46 ——– d—–w- C:\AspenWebWorkspace 2011-04-19 16:09:08 264192 —-a-w- c:\windows\system32\Incinerator.dll 2011-04-19 16:09:08 25600 —-a-w- c:\windows\Inetmib1.dll 2011-04-19 16:09:07 22528 —-a-w- c:\windows\Snmpapi.dll 2011-04-19 16:09:07 ——– d—–w- c:\program files\iolo 2011-04-19 16:00:57 ——– d—–w- c:\users\tim\appdata\roaming\GenuineRegistryDoctor 2011-04-19 16:00:57 ——– d—–w- c:\progra~2\GenuineRegistryDoctor 2011-04-19 14:45:39 16968 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys 2011-04-19 14:45:27 ——– d–h–w- c:\progra~2\Hitman Pro 2011-04-19 13:28:01 ——– d—–w- c:\users\tim\appdata\local\VirtualStore 2011-04-18 22:03:19 123952 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS 2011-04-18 19:11:23 ——– d—–w- c:\users\tim\appdata\local\The_Imaging_Source_Europe 2011-04-18 18:28:49 ——– d—–w- c:\users\tim\appdata\roaming\Sammsoft 2011-04-18 15:41:02 ——– d–h–w- c:\progra~2\Spybot - Search & Destroy 2011-04-18 14:45:20 311808 —-a-w- c:\windows\system32\drivers\srv.sys 2011-04-18 14:45:20 310272 —-a-w- c:\windows\system32\drivers\srv2.sys 2011-04-18 14:45:20 114176 —-a-w- c:\windows\system32\drivers\srvnet.sys 2011-04-18 14:44:56 428032 —-a-w- c:\windows\system32\vbscript.dll 2011-04-18 14:42:32 2333184 —-a-w- c:\windows\system32\win32k.sys 2011-04-18 14:42:27 191488 —-a-w- c:\windows\system32\FXSCOVER.exe 2011-04-18 14:42:22 288256 —-a-w- c:\windows\system32\XpsGdiConverter.dll 2011-04-18 14:41:56 741376 —-a-w- c:\windows\system32\inetcomm.dll 2011-04-18 14:41:32 1164288 —-a-w- c:\windows\system32\mfc42u.dll 2011-04-18 14:41:32 1137664 —-a-w- c:\windows\system32\mfc42.dll 2011-04-18 14:41:24 96768 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys 2011-04-18 14:41:24 69632 —-a-w- c:\windows\system32\drivers\bowser.sys 2011-04-18 14:41:24 223232 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys 2011-04-18 14:41:24 123904 —-a-w- c:\windows\system32\drivers\mrxsmb.sys 2011-04-15 16:24:46 232916 —h–w- c:\temp\8a702136-2fcf-42b5-a671-c7b38facb426\OfferApp-2538.exe 2011-04-15 15:52:13 ——– d—–w- c:\users\tim\appdata\local\Symantec 2011-04-15 15:48:14 ——– d—–w- c:\program files\Symantec 2011-04-15 15:48:05 ——– d—–w- c:\program files\Symantec AntiVirus 2011-04-15 15:48:05 ——– d—–w- c:\program files\common files\Symantec Shared 2011-04-15 15:48:05 ——– d—–w- c:\progra~2\Symantec 2011-04-15 15:22:16 ——– d–h–w- C:\Sun 2011-04-15 15:18:47 ——– d–h–w- C:\Microsoft 2011-04-14 09:39:02 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2011-04-13 13:49:40 ——– d—–w- c:\users\tim\appdata\local\{3B1F24C1-7759-4A73-9838-1DB911F05C28} 2011-04-06 22:20:16 91424 —-a-w- c:\windows\system32\dnssd.dll 2011-04-06 22:20:16 75040 —-a-w- c:\windows\system32\jdns_sd.dll 2011-04-06 22:20:16 197920 —-a-w- c:\windows\system32\dnssdX.dll 2011-04-06 22:20:16 107808 —-a-w- c:\windows\system32\dns-sd.exe . ==================== Find3M ==================== . 2011-03-17 13:11:29 152576 —-a-w- c:\windows\system32\msclmd.dll 2011-03-07 05:33:13 981504 —-a-w- c:\windows\system32\wininet.dll 2011-03-07 03:52:25 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-03-03 05:38:01 132608 —-a-w- c:\windows\system32\dnsrslvr.dll 2011-03-03 05:36:16 28672 —-a-w- c:\windows\system32\dnscacheugc.exe 2011-02-25 21:17:56 634880 —-a-w- c:\windows\system32\AtgEncryptionD.dll 2011-02-25 20:57:27 423656 —-a-w- c:\windows\system32\deployJava1.dll 2011-02-19 06:30:54 805376 —-a-w- c:\windows\system32\FntCache.dll 2011-02-19 06:30:51 1076736 —-a-w- c:\windows\system32\DWrite.dll 2011-02-19 06:30:50 739840 —-a-w- c:\windows\system32\d2d1.dll 2011-02-19 06:30:46 34304 —-a-w- c:\windows\system32\atmlib.dll 2011-02-19 04:34:54 294912 —-a-w- c:\windows\system32\atmfd.dll . ============= FINISH: 8:33:46.05 ===============

Attachments:

Okay I've attached those files. However, the GMER has been running since I last posted and then about 5 minutes ago I got the blue screen of death. The attached file was what I save before noon. Hopefully that will give you enough to go on for now, unless you need me to try running GMER again?

Attachments:

Here is the GMER file:

GMER 1.0.15.15572 - http://www.gmer.net
Rootkit scan 2011-05-02 11:31:53
Windows 6.1.7601 Service Pack 1 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 SAMSUNG_HD253GJ rev.1AJ10001
Running: 47519zqb.exe; Driver: C:\Users\tim\AppData\Local\Temp\pwldipoc.sys


—- System - GMER 1.0.15 —-

SSDT 86520830 ZwAlertResumeThread
SSDT 86520910 ZwAlertThread
SSDT 865252A8 ZwAllocateVirtualMemory
SSDT 865930B0 ZwConnectPort
SSDT 864C5F38 ZwCreateMutant
SSDT 864F9828 ZwCreateThread
SSDT 865B6280 ZwFreeVirtualMemory
SSDT 86520670 ZwImpersonateAnonymousToken
SSDT 86520750 ZwImpersonateThread
SSDT 865092C8 ZwMapViewOfSection
SSDT 864C5E78 ZwOpenEvent
SSDT 864BA5E8 ZwOpenProcessToken
SSDT 865D3258 ZwOpenThreadToken
SSDT 86509428 ZwResumeThread
SSDT 865D3178 ZwSetContextThread
SSDT 865D3328 ZwSetInformationProcess
SSDT 865D3088 ZwSetInformationThread
SSDT 864C5D98 ZwSuspendProcess
SSDT 86520A58 ZwSuspendThread
SSDT 86520210 ZwTerminateProcess
SSDT 86520B38 ZwTerminateThread
SSDT 865B64B8 ZwUnmapViewOfSection
SSDT 864904E8 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

.text ntkrnlpa.exe!ZwSaveKey + 13C1 82A86339 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82ABFD52 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10DB 82AC6DD0 8 Bytes [30, 08, 52, 86, 10, 09, 52, …] {XOR [EAX], CL; PUSH EDX; XCHG [EAX], DL; OR [EDX-0x7a], EDX}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82AC6DE8 4 Bytes [A8, 52, 52, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82AC6E88 4 Bytes [B0, 30, 59, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82AC6EC4 4 Bytes [38, 5F, 4C, 86]
.text ntkrnlpa.exe!KeRemoveQueueEx + 1203 82AC6EF8 4 Bytes [28, 98, 4F, 86]
.text …
? C:\Users\tim\AppData\Local\Temp\mbr.sys The system cannot find the file specified. !

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] ole32.dll!OleLoadFromStream 76436143 5 Bytes JMP 64F381EC C:\Program Files\Common Files\Microsoft Shared\office11\mso.dll (Microsoft Office 2003 component/Microsoft Corporation)
.text C:\Windows\Explorer.EXE[3788] WININET.dll!HttpAddRequestHeadersA 7541DCD2 5 Bytes JMP 003018D5
.text C:\Windows\Explorer.EXE[3788] WININET.dll!HttpAddRequestHeadersW 75424FAE 5 Bytes JMP 00301A9D

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [74FFFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [74FFFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [74FFFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [74FFFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\ole32.dll [USER32.dll!GetSystemMetrics] [68024F42] C:\Windows\AppPatch\AcSpecfc.DLL (Windows Compatibility DLL/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [74FFFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)
IAT C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE[3324] @ C:\Windows\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [74FFFFF6] C:\Windows\system32\apphelp.dll (Application Compatibility Client Library/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device \Driver\ACPI_HAL \Device\00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)

AttachedDevice \Driver\tdx \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)
AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 85F751ED
Device \Driver\atapi \Device\Ide\IdePort0 85F751ED
Device \Driver\atapi \Device\Ide\IdePort1 85F751ED
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-1 85F751ED

AttachedDevice \Driver\tdx \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- Threads - GMER 1.0.15 —-

Thread System [4:252] 85F79E7A
Thread System [4:256] 85F7C008
Hi Lyon,


Please download Combofix from either of the links below and save it to your desktop:

Link 1
Link 2


**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

  • Right-click and choose "Run as administrator" on Combofix & follow the prompts. When finished, it will produce a report for you.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]



  • Click on Yes, to continue scanning for malware.
  • When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply.

If you need help, see this link:
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
Something bizarre just happened… I got a warning that windows needed to shut down and when it restarted some bogus Microsoft antivirus software remover appeared and then went to the blue screen of death. I then selected to start it Safe Mode and ran ComboFix again. Attached is the text file of the results.

Attachments:

Hi Lyon,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
After I ran the Malwarebytes' Anti-Malware I selected to remove the trojan. Once I did that and emailed you the bogus scanware started again and disabled my access to everything. I couldn't even run ComboFix or Malwarebytes' Anti-Malware. So I restored my system back to the point where ComboFix save the restore point. Now what?
I ran the Malwarebytes again but used performed the full scan, then removed the items, and here is the saved log results: Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 6500 Windows 6.1.7601 Service Pack 1 Internet Explorer 8.0.7601.17514 05/03/2011 11:38:25 AM mbam-log-2011-05-03 (11-38-25).txt Scan type: Full scan (C:\|) Objects scanned: 540222 Time elapsed: 43 minute(s), 43 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\Windows\system32\config\systemprofile\AppData\Local\hyg.exe" -a "C:\Program Files\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\Qoobox\quarantine\C\programdata\ca28604ojdel28604\ca28604ojdel28604.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\Users\tim\AppData\Roaming\dwm.exe.vir (Backdoor.Cycbot.Gen) -> Quarantined and deleted successfully. c:\Qoobox\quarantine\C\Users\tim\AppData\Roaming\microsoft\conhost.exe.vir (Backdoor.Cycbot.Gen) -> Quarantined and deleted successfully. c:\Temp\8a702136-2fcf-42b5-a671-c7b38facb426\offerapp-2538.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI