This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected and hijacked homepage [Solved]

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ComboFix 12-03-17.01 - BeBop 03/21/2012 11:26:56.4.4 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2960 [GMT -4:00] Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\BeBop\Desktop\CFScript.txt ((((((((((((((((((((((((( Files Created from 2012-02-21 to 2012-03-21 ))))))))))))))))))))))))))))))) 2012-03-14 17:32:19 . 2012-03-14 17:32:19 ——– d—–w- C:\_OTL 2012-03-10 18:42:09 . 2012-03-10 18:42:09 ——– d—–w- C:\$AVG 2012-03-10 18:22:21 . 2012-03-10 18:22:21 ——– d–h–w- C:\Documents and Settings\All Users\Application Data\Common Files 2012-03-10 18:21:23 . 2012-03-10 18:21:23 ——– d—–w- C:\Program Files\AVG 2012-03-10 18:18:53 . 2012-03-21 15:18:20 ——– d—–w- C:\Documents and Settings\All Users\Application Data\MFAData 2012-03-05 22:18:13 . 2012-03-05 22:18:13 ——– d-sh–w- C:\Documents and Settings\BeBop\IECompatCache . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) 2012-02-17 14:55:53 . 2011-06-17 16:09:41 414368 —-a-w- C:\WINDOWS\system32\FlashPlayerCPLApp.cpl 2012-02-03 09:22:18 . 2008-04-13 22:00:12 1860096 —-a-w- C:\WINDOWS\system32\win32k.sys 2012-01-11 19:06:47 . 2012-02-15 14:16:55 3072 ——w- C:\WINDOWS\system32\iacenc.dll 2012-01-09 16:20:25 . 2009-01-16 15:38:22 139784 —-a-w- C:\WINDOWS\system32\drivers\rdpwd.sys 2012-02-06 13:23:08 . 2011-09-15 14:05:06 134104 —-a-w- C:\Program Files\mozilla firefox\components\browsercomps.dll ——- Sigcheck ——- Note: Unsigned files aren't necessarily malware. [-] 2009-01-11 21:14:47 . 362BC5AF8EAF712832C58CC13AE05750 . 1614848 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\sfcfiles.dll ((((((((((((((((((((((((((((( SnapShot@2012-03-18_17.23.24 ))))))))))))))))))))))))))))))))))))))))) - 2001-08-23 11:00:00 . 2012-03-11 15:31:14 68272 C:\WINDOWS\system32\perfc009.dat + 2001-08-23 11:00:00 . 2012-03-18 17:27:11 68272 C:\WINDOWS\system32\perfc009.dat + 2009-01-16 15:40:29 . 2012-03-19 20:34:48 86327 C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat - 2009-01-16 15:40:29 . 2009-01-16 15:40:32 86327 C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat + 2009-01-16 15:40:28 . 2012-03-19 20:34:48 2850 C:\WINDOWS\pchealth\helpctr\PackageStore\SkuStore.bin - 2001-08-23 11:00:00 . 2012-03-11 15:31:14 433760 C:\WINDOWS\system32\perfh009.dat + 2001-08-23 11:00:00 . 2012-03-18 17:27:11 433760 C:\WINDOWS\system32\perfh009.dat + 2012-03-18 18:30:56 . 2012-03-18 18:30:56 4698112 C:\WINDOWS\Installer\1a51d2.msi + 2012-03-18 18:30:07 . 2012-03-18 18:30:07 2186240 C:\WINDOWS\Installer\1a51ce.msi ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 23:36:46 30040] "APSDaemon"="C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 11:22:28 59240] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2011-10-09 22:06:40 421736] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2011-10-24 18:28:52 421888] "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-12-19 04:42:58 76304] "SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2009-07-25 09:23:12 149280] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 02:42:30 53760] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk] backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^BeBop^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk] backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2008-06-19 21:20:52 57344 —-a-w- C:\WINDOWS\ALCMTR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 02:42:18 15360 —-a-w- C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2009-02-26 23:36:46 30040 —-a-w- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2008-12-08 20:50:04 54576 —-a-w- C:\Program Files\HP\HP Software Update\hpwuschd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon] 2008-08-20 14:54:08 150016 —-a-w- C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer] 2008-12-19 04:42:58 76304 —-a-w- C:\WINDOWS\KHALMNPR.Exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer] 2008-12-19 04:42:58 76304 —-a-w- C:\WINDOWS\KHALMNPR.Exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)] 2012-01-13 19:53:16 981680 —-a-w- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] 2010-10-16 16:04:16 13851752 —-a-w- C:\WINDOWS\system32\nvcpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] 2010-10-16 16:04:16 110696 —-a-w- C:\WINDOWS\system32\nvmctray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL] 2008-12-30 19:58:28 18082304 —-a-w- C:\WINDOWS\RTHDCPL.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpamBully 3 for Outlook Express] 2005-09-01 09:56:34 665088 —-a-w- C:\Program Files\Axaware\Spam Bully 3 for OE\sb3oe.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2009-07-25 09:23:12 149280 —-a-w- C:\Program Files\Java\jre6\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher] 1999-11-01 05:30:00 102400 —-a-w- C:\PROGRA~1\Logitech\iTouch\iTouch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "ose"=3 (0x3) "odserv"=3 (0x3) "Microsoft Office Groove Audit Service"=3 (0x3) "LBTServ"=3 (0x3) "JavaQuickStarterService"=2 (0x2) "iPod Service"=3 (0x3) "idsvc"=3 (0x3) "IDriverT"=3 (0x3) "Bonjour Service"=2 (0x2) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"= "C:\\WINDOWS\\system32\\sessmgr.exe"= "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "24018:TCP"= 24018:TCP:spport "8078:TCP"= 8078:TCP:spport "25777:TCP"= 25777:TCP:spport "12787:TCP"= 12787:TCP:spport "11997:TCP"= 11997:TCP:spport "21921:TCP"= 21921:TCP:spport "12792:TCP"= 12792:TCP:spport "15554:TCP"= 15554:TCP:spport "18687:TCP"= 18687:TCP:spport "23897:TCP"= 23897:TCP:spport [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R1 lkbdhlpr;Logitech Keyboard Class Helper Driver;C:\WINDOWS\system32\drivers\lkbdhlpr.sys [5/25/2009 7:36:30 PM 10112] R3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;C:\WINDOWS\system32\drivers\RTS5121.sys [1/21/2009 7:12:05 PM 160256] S3 Rts516xIR;Realtek IR Driver;C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys –> C:\WINDOWS\system32\DRIVERS\Rts516xIR.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 HPService REG_MULTI_SZ HPSLPSVC hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc Contents of the 'Scheduled Tasks' folder 2012-03-16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 16:50:20 . 2011-06-01 21:57:16] 2012-03-21 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-299502267-1801674531-1003Core.job - C:\Documents and Settings\BeBop\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-06 14:30:35 . 2012-02-06 14:30:35] 2012-03-21 C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1644491937-299502267-1801674531-1003UA.job - C:\Documents and Settings\BeBop\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-02-06 14:30:35 . 2012-02-06 14:30:35]
C:\System Volume Information\_restore{670BD264-7225-4054-A0B2-DBBFBEA97B19}\RP242\A0016611.EXE Win32/Adware.WBug.A application E:\Stored Programs\Progams\CLONE\CloneCDCr.zip probably a variant of Win32/IRCBot.BVAJEYN trojan E:\Stored Programs\Progams\Ewido & crack\ewido.security.suite.plus.3.x.keygen-icu.zip probably a variant of Win32/Agent.DXXNJEF trojan G:\registryfix.exe a variant of Win32/Adware.ErrorClean application G:\Programs Stored\Progams\CLONE\CloneCDCr.zip probably a variant of Win32/IRCBot.BVAJEYN trojan G:\Programs Stored\Progams\Ewido & crack\ewido.security.suite.plus.3.x.keygen-icu.zip probably a variant of Win32/Agent.DXXNJEF trojan
Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Satchfan
CKScanner - Additional Security Risks - These are not necessarily bad c:\program files\jv16 powertools\crack.exe scanner sequence 3.NA.11.TDAPSW —– EOF —–
I see that you accessed a “crack” for jv16 powertools. Cracks install the malware on your system.

If you visit crack sites you'll ALWAYS get infected. This is not only because of the crack itself, but because one single click entering that site may already download and install a load of malware.

I suggest you remove it.

Apart from that, are you experiencing any problems now?
I have removed the jvc item. Also, computer is running well - it has been since one of the steps got rid of the btsearch which had taken over my home page. Since that has been gone it has been running beautifully. Thank you so much for your help!!!!!
Hi bebopp

Thank you so much for your help!!!!!

You're welcome.Good job :thumbup:

Now that you’re free from malware, as long as your computer seems to be running well, please follow these simple steps to tidy up you computer and decrease the likelihood of getting infected again:

Uninstall Combofix

Follow these steps to uninstall Combofix
  • click START then RUN
  • now type Combofix /uninstall in the runbox and click OK.
Note the space between the X and the /, it needs to be there.
🖼Click to load external image (Posted Image)
  • please follow the prompts to uninstall Combofix.
  • once it's finished uninstalling itself you will receive a message saying Combofix was uninstalled successfully.
===================================================

Uninstall OTL
  • Double-click OTL.exe
  • Click the CleanUp! button.
  • Select Yes when the Begin cleanup Process? prompt appears.
  • If you are prompted to reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
NOTE: If you receive a warning from your firewall or other security programs regarding OTL attempting to contact the internet, please allow it to do so.

===================================================

Firewall

I see no evidence of a firewall. I suggest you get one in place now. I can’t stress how important it is that you use a firewall on your computer. This is one of the ways computers are open to Malware. Without a firewall, your computer is susceptible to being attacked again. Windows XP firewall is not adequate protection.

If you have a router with firewall features that’s fine – if not, I suggest you do the following:

Download one of the following firewalls:

ZoneAlarm
Sunbelt Personal Firewall

NOTE only install one firewall. Having more than one could cause many programs to stop working altogether. Also, the firewalls may get in each others' way and cause some security holes that would not be there with just one firewall.

For a tutorial on Firewalls and a listing of some other available ones see Understanding and Using Firewalls

===================================================

Uninstall and update Java

One version you have is old and therefore vulnerable to infections.

Remove all versions of Java or JRE environment
  • click on Start, Settings, Control Panel.
  • double-click Add Remove Programs.
  • look for all versions of Java or Java Rintime Environment, and click Uninstall. Alternatively, right-click the program and select Uninstall.
Install Version 6 Update 310, from here

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

===================================================

Install Spybot - Search and Destroy - Download and install Spybot Search and Destroy which provides real time spyware and hijacker protection .

You should scan your computer with the program on a regular basis as you would with your anti-virus software.

A tutorial on installing and using SS&D can be found here:

===================================================

Update and run Malwarebytes. This really is an excellent program that you should also update and run on a regular basis, probably weekly.

===================================================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

===================================================

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

===================================================

I also recommend that you read the following:

How to prevent malware by miekiemoes

Safe computing

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI