This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

homepage changed to Bing w/AV scan popup [Solved]

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

There are a few strange things happening here that make no sense so I’d like you to run a couple more scans.

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.pif
DDS.com

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run CKScanner

Download CKScanner by askey127 from here & save it to your Desktop.
  • doubleclick CKScanner.exe then click Search For Files
  • when the cursor hourglass disappears, click Save List To File
  • a message box will verify the file saved
  • double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
Satchfan
G'day, will be here as long as it takes. Remember I am on a 2nd machine and using a flash drive to transport these URLs for the scans. My infected machine only gives me a white screen even if I key the URL in the command window or make it my homepage. I save to flash drive then copy it to desktop on the infected PC and run from there. Long way around but that works, logs are below. Many thx. . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 7 Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 7/25/2012 7:23:07 PM System Uptime: 4/10/2013 6:39:29 AM (2 hours ago) . Motherboard: Gateway | | VG50_HC_HR Processor: Intel® Pentium® CPU B950 @ 2.10GHz | U3E1 | 798/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 448 GiB total, 400.049 GiB free. D: is CDROM () F: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP47: 3/7/2013 7:36:22 AM - Scheduled Checkpoint RP48: 3/13/2013 6:54:11 PM - Windows Update RP49: 3/21/2013 12:19:54 PM - Scheduled Checkpoint RP50: 3/21/2013 7:08:28 PM - Windows Update RP51: 3/29/2013 7:06:05 AM - Scheduled Checkpoint RP52: 4/5/2013 4:45:41 PM - Windows Update RP53: 4/6/2013 9:00:49 AM - Removed Norton Online Backup RP54: 4/6/2013 9:01:58 AM - Removed Norton Online Backup RP55: 4/6/2013 9:02:19 AM - Removed Norton Online Backup RP56: 4/6/2013 9:04:36 AM - Removed Norton Online Backup RP57: 4/6/2013 1:59:53 PM - OTL Restore Point - 4/6/2013 1:59:52 PM RP58: 4/7/2013 8:42:45 PM - Windows Update RP59: 4/8/2013 2:29:05 PM - Removed AVG 2012 RP60: 4/8/2013 2:30:50 PM - Removed AVG 2012 RP61: 4/8/2013 2:32:41 PM - Removed AVG 2012 . ==== Installed Programs ====================== . clear.fi SDK- Movie 2 clear.fi SDK - MVP 2 Adobe AIR Adobe Flash Player 11 ActiveX 64-bit Adobe Reader X (10.1.4) MUI Agatha Christie - Death on the Nile Avira Free Antivirus Backup Manager V3 Bejeweled 3 Broadcom Card Reader Driver Installer Broadcom NetLink Controller Chronicles of Albian Chuzzle Deluxe clear.fi Media clear.fi Photo Cradle of Rome 2 CyberLink MediaEspresso D3DX10 Dora's World Adventure eBay Worldwide ETDWare PS/2-X64 10.6.9.9_WHQL Evernote v. 4.5.2 FastStone Image Viewer 4.6 FATE Final Drive: Nitro Fooz Kids Fooz Kids Platform Galerie de photos Windows Live Galería fotográfica de Windows Live Gateway Games Gateway MyBackup Gateway Power Management Gateway Recovery Management Gateway Registration Gateway ScreenSaver Gateway Social Networks Gateway Updater GoToMeeting 5.4.0.1083 Governor of Poker 2 Premium Edition Identity Card Intel® Control Center Intel® Management Engine Components Intel® OpenCL CPU Runtime Intel® Processor Graphics Intel® Rapid Storage Technology Intel® Trusted Connect Service Client Jewel Match 3 Jewel Quest Mysteries: The Seventh Gate Collector's Edition Junk Mail filter update Launch Manager magicJack Malwarebytes Anti-Malware version 1.62.0.1300 Mesh Runtime Microsoft .NET Framework 4 Client Profile Microsoft Application Error Reporting Microsoft Office 2010 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 MSVCRT MSVCRT_amd64 MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero Control Center 10 Nero ControlCenter 10 Help (CHM) Nero Core Components 10 Nero DiscSpeed 10 Nero DiscSpeed 10 Help (CHM) Nero Express 10 Nero Express 10 Help (CHM) Nero Multimedia Suite 10 Essentials Nero StartSmart 10 Nero StartSmart 10 Help (CHM) Nero Update OpenOffice.org 3.1 Penguins! Plants vs. Zombies - Game of the Year Polar Bowler Polar Golfer Qualcomm Atheros WiFi Driver Installation Realtek High Definition Audio Driver Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Skype™ 5.10 Torchlight Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update Installer for WildTangent Games App Video Web Camera Virtual Villagers 5 - New Believers Visual Studio 2008 x64 Redistributables Welcome Center WildTangent Games App Windows Live Windows Live Communications Platform Windows Live Essentials Windows Live Galeria de Fotos Windows Live ID Sign-in Assistant Windows Live Installer Windows Live Language Selector Windows Live Mail Windows Live Mesh Windows Live Messenger Windows Live MIME IFilter Windows Live Movie Maker Windows Live Photo Common Windows Live Photo Gallery Windows Live PIMT Platform Windows Live Remote Client Windows Live Remote Client Resources Windows Live Remote Service Windows Live Remote Service Resources Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack Windows Live Writer Windows Live Writer Resources Zuma's Revenge . ==== Event Viewer Messages From Past Week ======== . 4/9/2013 6:23:11 AM, Error: Service Control Manager [7030] - The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 4/9/2013 6:21:35 AM, Error: Application Popup [1060] - \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver. 4/8/2013 3:41:10 PM, Error: Schannel [36888] - The following fatal alert was generated: 40. The internal error state is 107. 4/8/2013 3:41:10 PM, Error: Schannel [36874] - An SSL 3.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed. . ==== End Of File =========================== DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16521 Run by [removed] at 8:36:31 on 2013-04-10 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3932.2631 [GMT -4:00] . AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\Launch Manager\dsiwmis.exe C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe C:\Program Files (x86)\Launch Manager\LMutilps32.exe C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe C:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Elantech\ETDCtrl.exe C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe C:\Windows\system32\igfxext.exe C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files (x86)\Launch Manager\LManager.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe C:\Program Files (x86)\Launch Manager\LMworker.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Gateway\Gateway Power Management\ePowerEvent.exe C:\Windows\system32\SearchIndexer.exe C:\Program Files\Elantech\ETDCtrlHelper.exe C:\Windows\system32\taskeng.exe C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Nero\Update\NASvc.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe C:\Windows\System32\WUDFHost.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.download.bleepingcomputer.com/sUBs/dds.com mWinlogon: Userinit = userinit.exe BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll mRun: [BackupManagerTray] "C:\Program Files (x86)\NTI\Gateway MyBackup\BackupManagerTray.exe" -h -k mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray mRun: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: ConsentPromptBehaviorAdmin = dword:5 mPolicies-System: ConsentPromptBehaviorUser = dword:3 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 TCP: NameServer = 192.168.1.1 68.238.112.12 TCP: Interfaces\{4423B56C-33B8-4BD7-A66E-B52E302F9417} : DHCPNameServer = 192.168.1.250 TCP: Interfaces\{C692ADA5-4D81-4D69-AB21-0888554351A7} : DHCPNameServer = 192.168.1.1 [removed] Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - x64-BHO: {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - x64-BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe x64-Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s x64-Run: [ETDCtrl] C:\Program Files (x86)\Elantech\ETDCtrl.exe x64-Run: [Power Management] C:\Program Files\Gateway\Gateway Power Management\ePowerTray.exe x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - x64-Notify: igfxcui - igfxdev.dll x64-SSODL: WebCheck - . ============= SERVICES / DRIVERS =============== . R1 avkmgr;avkmgr;C:\Windows\System32\drivers\avkmgr.sys [2013-4-6 28600] R2 AntiVirSchedulerService;Avira Scheduler;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2013-4-6 86752] R2 AntiVirService;Avira Real-Time Protection;C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2013-4-6 110816] R2 avgntflt;avgntflt;C:\Windows\System32\drivers\avgntflt.sys [2013-4-6 100712] R2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2012-3-19 355920] R2 ePowerSvc;ePower Service;C:\Program Files\Gateway\Gateway Power Management\ePowerSvc.exe [2012-4-17 871296] R2 GREGService;GREGService;C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe [2011-5-29 36456] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2012-3-19 13592] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-2-3 628448] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2012-4-17 161560] R2 Live Updater Service;Live Updater Service;C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe [2012-3-19 255376] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-8-2 655944] R2 NAUpdate;Nero Update;C:\Program Files (x86)\Nero\Update\NASvc.exe [2011-7-22 690472] R2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NTI\Gateway MyBackup\IScheduleSvc.exe [2012-1-5 256536] R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-4-17 363800] R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;C:\Program Files (x86)\Atheros\Ath_WlanAgent.exe [2012-4-17 72864] R3 b57xdbd;Broadcom xD Picture Bus Driver Service;C:\Windows\System32\drivers\b57xdbd.sys [2011-11-4 68648] R3 b57xdmp;Broadcom xD Picture vstorp client drv;C:\Windows\System32\drivers\b57xdmp.sys [2011-11-4 19496] R3 bScsiMSa;bScsiMSa;C:\Windows\System32\drivers\bScsiMSa.sys [2011-9-2 51752] R3 bScsiSDa;bScsiSDa;C:\Windows\System32\drivers\bScsiSDa.sys [2012-2-9 78888] R3 ETD;ELAN PS/2 Port Input Device;C:\Windows\System32\drivers\ETD.sys [2012-3-14 238384] R3 IntcDAud;Intel® Display Audio;C:\Windows\System32\drivers\IntcDAud.sys [2012-3-19 331264] R3 k57nd60a;Broadcom NetLink ™ Gigabit Ethernet - NDIS 6.0;C:\Windows\System32\drivers\k57nd60a.sys [2012-1-19 435240] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2012-8-2 24904] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-7-13 160944] S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072] S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392] S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232] S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-7-27 1255736] S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184] . =============== Created Last 30 ================ . 2013-04-10 10:38:30 ——– d—–w- C:\Users\-\AppData\Local\Programs 2013-04-09 20:10:29 ——– d-sh–w- C:\$RECYCLE.BIN 2013-04-09 18:59:43 ——– d-s—w- C:\ComboFix 2013-04-09 15:02:25 ——– d—–w- C:\_OTL 2013-04-09 12:37:09 ——– d—–w- C:\Users\-\AppData\Local\ElevatedDiagnostics 2013-04-09 10:02:35 98816 —-a-w- C:\Windows\sed.exe 2013-04-09 10:02:35 256000 —-a-w- C:\Windows\PEV.exe 2013-04-09 10:02:35 208896 —-a-w- C:\Windows\MBR.exe 2013-04-09 09:34:17 9311288 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A2FD5937-05A6-4DC8-ACB8-4E619AB3B40D}\mpengine.dll 2013-04-08 18:30:05 ——– d—–w- C:\Users\-\AppData\Roaming\TuneUp Software 2013-04-07 17:02:10 ——– d—–w- C:\Windows\ERUNT 2013-04-07 17:01:52 ——– d—–w- C:\JRT 2013-04-06 13:12:20 ——– d—–w- C:\Users\-\AppData\Roaming\Avira 2013-04-06 13:09:12 28600 —-a-w- C:\Windows\System32\drivers\avkmgr.sys 2013-04-06 13:09:12 100712 —-a-w- C:\Windows\System32\drivers\avgntflt.sys 2013-04-06 13:09:08 ——– d—–w- C:\ProgramData\Avira 2013-04-06 13:09:08 ——– d—–w- C:\Program Files (x86)\Avira 2013-03-21 10:12:32 19968 —-a-w- C:\Windows\System32\drivers\usb8023.sys 2013-03-14 19:23:45 ——– d—–w- C:\Users\-\AppData\Roaming\OpenOffice.org 2013-03-14 19:20:40 ——– d—–w- C:\Program Files (x86)\JRE 2013-03-14 19:20:37 ——– d—–w- C:\Program Files (x86)\OpenOffice.org 3 . ==================== Find3M ==================== . 2013-03-12 05:10:56 282744 ——w- C:\Windows\System32\MpSigStub.exe 2013-02-12 05:45:24 135168 —-a-w- C:\Windows\apppatch\AppPatch64\AcXtrnal.dll 2013-02-12 05:45:22 350208 —-a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll 2013-02-12 05:45:22 308736 —-a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll 2013-02-12 05:45:22 111104 —-a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll 2013-02-12 04:48:31 474112 —-a-w- C:\Windows\apppatch\AcSpecfc.dll 2013-02-12 04:48:26 2176512 —-a-w- C:\Windows\apppatch\AcGenral.dll 2013-01-13 21:17:03 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 21:17:02 2560 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 21:16:42 10752 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 21:12:46 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 21:11:21 4096 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 21:11:08 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 21:11:07 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:35:31 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-01-13 20:35:31 2560 —ha-w- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-01-13 20:35:18 10752 —ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-01-13 20:32:07 3584 —ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-01-13 20:31:48 4096 —ha-w- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-01-13 20:31:41 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-01-13 20:31:40 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-01-13 20:31:00 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll 2013-01-13 20:22:22 1988096 —-a-w- C:\Windows\SysWow64\d3d10warp.dll 2013-01-13 20:20:31 293376 —-a-w- C:\Windows\SysWow64\dxgi.dll 2013-01-13 20:09:00 249856 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll 2013-01-13 20:08:43 220160 —-a-w- C:\Windows\SysWow64\d3d10core.dll 2013-01-13 20:08:35 1504768 —-a-w- C:\Windows\SysWow64\d3d11.dll 2013-01-13 19:59:04 1643520 —-a-w- C:\Windows\System32\DWrite.dll 2013-01-13 19:58:28 1175552 —-a-w- C:\Windows\System32\FntCache.dll 2013-01-13 19:54:01 604160 —-a-w- C:\Windows\SysWow64\d3d10level9.dll 2013-01-13 19:53:58 207872 —-a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll 2013-01-13 19:53:14 187392 —-a-w- C:\Windows\SysWow64\UIAnimation.dll 2013-01-13 19:51:30 2565120 —-a-w- C:\Windows\System32\d3d10warp.dll 2013-01-13 19:49:17 363008 —-a-w- C:\Windows\System32\dxgi.dll 2013-01-13 19:48:47 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll 2013-01-13 19:46:25 1080832 —-a-w- C:\Windows\SysWow64\d3d10.dll 2013-01-13 19:43:21 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll 2013-01-13 19:38:39 333312 —-a-w- C:\Windows\System32\d3d10_1core.dll 2013-01-13 19:38:32 1887232 —-a-w- C:\Windows\System32\d3d11.dll 2013-01-13 19:38:21 296960 —-a-w- C:\Windows\System32\d3d10core.dll 2013-01-13 19:37:57 3419136 —-a-w- C:\Windows\SysWow64\d2d1.dll 2013-01-13 19:25:04 245248 —-a-w- C:\Windows\System32\WindowsCodecsExt.dll 2013-01-13 19:24:33 648192 —-a-w- C:\Windows\System32\d3d10level9.dll 2013-01-13 19:24:30 221184 —-a-w- C:\Windows\System32\UIAnimation.dll 2013-01-13 19:20:42 194560 —-a-w- C:\Windows\System32\d3d10_1.dll 2013-01-13 19:20:04 1238528 —-a-w- C:\Windows\System32\d3d10.dll 2013-01-13 19:15:40 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll 2013-01-13 19:10:36 3928064 —-a-w- C:\Windows\System32\d2d1.dll 2013-01-13 19:02:06 417792 —-a-w- C:\Windows\SysWow64\WMPhoto.dll 2013-01-13 18:34:58 364544 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2013-01-13 18:32:43 465920 —-a-w- C:\Windows\System32\WMPhoto.dll 2013-01-13 18:09:52 522752 —-a-w- C:\Windows\System32\XpsGdiConverter.dll 2013-01-13 17:26:42 1158144 —-a-w- C:\Windows\SysWow64\XpsPrint.dll 2013-01-13 17:05:09 1682432 —-a-w- C:\Windows\System32\XpsPrint.dll . ============= FINISH: 8:36:55.78 =============== CKScanner 2.1 - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11.XENAXT —– EOF —–
Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

Try starting in normal mode and let me know how it goes.

Thanks

Satchfan
Several seconds into scan this popped up: Warning! Error saving file C:\Windows\erdnt\Hiv-backup\BCD! Continue with next file? [RegCreateKeyEx:5 - Access is denied] Need your advice here . . . will await your reply
Let's try it this way:

Run MiniRegTool

Please download MiniRegTool and unzip it.
  • run the tool
  • copy and paste the following into the edit box:

    Windows Registry Editor Version 5.00
    
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

  • check Import radio button
  • press Go
Please post the log (Result.txt) in your reply.

Try starting the computer normally

Satchfan
Copied that statement into the edit window. There is no "import" radio button on screen. I clicked Go and nothing is happening. Closed and re-opened MiniRegTool, repeated process, nothing moving.
Very persistent so let's try another way. :)

Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
    
    
    :Commands
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post the OTL fix log
OK, am ready to go but this reminder: - ComboFix is still open - the warning popup is still open wanting a yes/no on continuing the registry backup Still a go?
OTL log file below. All processes killed ========== SERVICES/DRIVERS ========== ========== OTL ========== ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\"Userinit"|"C:\\WINDOWS\\system32\\userinit.exe," /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: - ->Temp folder emptied: 244017 bytes ->Temporary Internet Files folder emptied: 351378 bytes ->Flash cache emptied: 291 bytes User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 4061 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 04102013_131151 Files\Folders moved on Reboot… C:\Users\-\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. C:\Users\-\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. PendingFileRenameOperations files… Registry entries deleted on Reboot…
Windows opens fine on the infected PC. It appears we are back to the previous problem of homepage opening up and visible, but going anywhere from there…it results in a white screen.

It appears we are back to the previous problem of homepage opening up and visible, but going anywhere from there…it results in a white screen.

Is this only in Internet Explorer?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI