This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with win32.downloader.gen [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Help was requested before, my internet stopped working and topic was closed due to inactivity. sorry for the duplicate post DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.21.2 Run by [removed] at 0:08:00 on 2013-08-18 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.139 [GMT -6:00] . AV: avast! Antivirus *Enabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: avast! Antivirus *Disabled* . ============== Running Processes ================ . C:\WINDOWS\system32\ibmpmsvc.exe C:\Program Files\AVAST Software\Avast\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\tp4mon.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\AVAST Software\Avast\avastUI.exe C:\Program Files\Ask.com\Updater\Updater.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe C:\Program Files\LENOVO\HOTKEY\tposdsvc.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre7\bin\jqs.exe C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\WINDOWS\explorer.exe C:\Program Files\Google\Chrome\Application\chrome.exe C:\Documents and Settings\Owner\My Documents\Downloads\OTL.exe C:\Program Files\Application Updater\ApplicationUpdater.exe C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe C:\Documents and Settings\Owner\Application Data\Slick Savings\CouponsHelper.exe C:\Program Files\Vuze\Azureus.exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup C:\WINDOWS\system32\svchost.exe -k NetworkService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k LocalService C:\WINDOWS\system32\svchost.exe -k bthsvcs C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\System32\svchost.exe -k HTTPFilter . ============== Pseudo HJT Report =============== . uStart Page = hxxp://search.yahoo.com?type=994519&fr=spigot-yhp-ie uURLSearchHooks: Vuze Remote Toolbar: {05478A66-EDB6-4A22-A870-A5987F80A7DA} - c:\program files\vuze remote toolbar\ie\7.4\vuzeToolbarIE.dll uURLSearchHooks: TrustWorthy Toolbar: {8480b7b1-a45c-4feb-8653-60f834f7ca4b} - c:\program files\trustworthy\prxtbTrus.dll BHO: Vuze Remote Toolbar: {05478A66-EDB6-4A22-A870-A5987F80A7DA} - c:\program files\vuze remote toolbar\ie\7.4\vuzeToolbarIE.dll BHO: Slick Savings: {34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} - c:\documents and settings\owner\application data\slick savings\Coupons.dll BHO: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: TrustWorthy Toolbar: {8480b7b1-a45c-4feb-8653-60f834f7ca4b} - c:\program files\trustworthy\prxtbTrus.dll BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll BHO: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll TB: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - c:\program files\avast software\avast\aswWebRepIE.dll TB: Ask Toolbar: {D4027C7F-154A-4066-A1AD-4243D8127440} - TB: TrustWorthy Toolbar: {8480b7b1-a45c-4feb-8653-60f834f7ca4b} - c:\program files\trustworthy\prxtbTrus.dll TB: Vuze Remote Toolbar: {05478A66-EDB6-4A22-A870-A5987F80A7DA} - c:\program files\vuze remote toolbar\ie\7.4\vuzeToolbarIE.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe uRun: [ConduitFloatingPlugin_dkjaldeegndmngnahlmdbfnejdobkmil] "c:\windows\system32\rundll32.exe" "c:\program files\conduit\ct3309758\plugins\TBVerifier.dll",RunConduitFloatingPlugin dkjaldeegndmngnahlmdbfnejdobkmil uRun: [Slick Savings] "c:\documents and settings\owner\application data\slick savings\CouponsHelper.exe" mRun: [TrackPointSrv] tp4mon.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [LenovoAutoScrollUtility] c:\program files\lenovo\virtscrl\virtscrl.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe" mRun: [SearchSettings] "c:\program files\common files\spigot\search settings\SearchSettings.exe" mRunOnce: [SpUninstallCleanUp] REG delete HKEY_CURRENT_USER\Software\SearchProtect /f StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1301095190906 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab TCP: NameServer = 8.8.8.8 8.8.4.4 66.62.161.193 TCP: Interfaces\{A2775735-E1D5-4F8B-B582-2CE294A0DA14} : DHCPNameServer = 8.8.8.8 8.8.4.4 [removed] Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\28.0.1500.95\installer\chrmstp.exe" –configure-user-settings –verbose-logging –system-level –multi-install –chrome Hosts: 127.0.0.1 www.spywareinfo.com . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\6o41ph79.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT3309758&CUI=UN14806301332351523&UM=2&SearchSource=3&q={searchTerms} FF - prefs.js: browser.startup.homepage - hxxp://search.yahoo.com?type=994519&fr=spigot-yhp-ff FF - prefs.js: browser.search.selectedEngine - Yahoo FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=994519&p= FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\google\update\1.3.21.145\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre7\bin\plugin2\npjp2.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_7_700_202.dll FF - plugin: c:\windows\system32\npdeployJava1.dll FF - plugin: c:\windows\system32\npptools.dll FF - ExtSQL: 2013-08-17 23:52; [removed]; c:\documents and settings\owner\application data\mozilla\firefox\profiles\6o41ph79.default\extensions\[removed] . ============= SERVICES / DRIVERS =============== . R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [2013-4-16 49376] R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [2013-4-16 175176] R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [2013-7-4 21576] R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2012-6-5 770344] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2012-6-5 369584] R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [2011-3-25 13680] R2 Application Updater;Application Updater;c:\program files\application updater\ApplicationUpdater.exe [2013-8-8 807800] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2012-6-5 29816] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-4-16 66336] R2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2012-6-5 46808] R2 Motorola Device Manager;Motorola Device Manager Service;c:\program files\motorola mobility\motorola device manager\MotoHelperService.exe [2013-3-25 121144] R2 TPHKLOAD;Lenovo Hotkey Client Loader;c:\program files\lenovo\hotkey\tphkload.exe [2011-3-25 99328] R2 TPHKSVC;On Screen Display;c:\program files\lenovo\hotkey\TPHKSVC.exe [2011-3-25 64440] S0 cerc6;cerc6; [x] S2 LENOVO.MICMUTE;Lenovo Microphone Mute;c:\program files\lenovo\hotkey\micmute.exe [2011-3-25 45496] S3 BTCFilterService;USB Networking Driver Filter Service;c:\windows\system32\drivers\motfilt.sys [2013-5-11 6016] S3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\drivers\motccgp.sys [2013-5-11 20864] S3 motccgpfl;MotCcgpFlService;c:\windows\system32\drivers\motccgpfl.sys [2013-5-11 8448] S3 Motousbnet;Motorola USB Networking Driver Service;c:\windows\system32\drivers\Motousbnet.sys [2013-5-11 23808] S3 motusbdevice;Motorola USB Dev Driver;c:\windows\system32\drivers\motusbdevice.sys [2013-5-11 11008] . =============== Created Last 30 ================ . 2013-08-18 06:03:34 ——– d—–w- c:\documents and settings\owner\.swt 2013-08-18 05:52:58 ——– d—–w- c:\documents and settings\owner\local settings\application data\Slick Savings 2013-08-18 05:52:53 ——– d—–w- c:\documents and settings\owner\application data\Slick Savings 2013-08-18 05:52:53 ——– d—–w- c:\documents and settings\owner\application data\Search Settings 2013-08-18 05:52:31 ——– d—–w- c:\program files\Application Updater 2013-08-18 05:52:14 ——– d—–w- c:\program files\Vuze Remote Toolbar 2013-08-18 05:52:14 ——– d—–w- c:\program files\common files\Spigot 2013-08-18 05:49:11 ——– d—–w- c:\documents and settings\owner\application data\Azureus 2013-08-18 05:49:04 ——– d—–w- c:\program files\Vuze 2013-08-18 05:05:49 ——– d—–w- c:\documents and settings\owner\.frostwire5 2013-08-18 05:04:21 ——– d—–w- c:\program files\FrostWire 5 2013-08-18 05:00:32 ——– d—–w- c:\documents and settings\owner\local settings\application data\TrustWorthy 2013-08-18 05:00:28 ——– d—–w- c:\program files\TrustWorthy 2013-08-18 04:59:47 ——– d—–w- c:\program files\Conduit 2013-08-18 04:59:47 ——– d—–w- c:\documents and settings\owner\local settings\application data\CRE 2013-08-18 04:59:47 ——– d—–w- c:\documents and settings\owner\local settings\application data\Conduit 2013-08-18 04:59:01 770384 —-a-w- c:\windows\system32\msvcr100.dll 2013-08-18 04:59:01 421200 —-a-w- c:\windows\system32\msvcp100.dll 2013-08-18 04:57:24 ——– d—–w- c:\documents and settings\owner\application data\OpenCandy 2013-08-18 04:57:20 ——– d—–w- c:\program files\GetPrivate . ==================== Find3M ==================== . 2013-06-30 00:09:05 770344 —-a-w- c:\windows\system32\drivers\aswSnx.sys 2013-06-30 00:09:05 175176 —-a-w- c:\windows\system32\drivers\aswVmm.sys 2013-06-14 01:00:17 71048 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-06-14 01:00:17 692104 —-a-w- c:\windows\system32\FlashPlayerApp.exe . ============= FINISH: 0:09:00.40 =============== . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 3/25/2011 5:04:29 PM System Uptime: 8/13/2013 6:20:24 PM (102 hours ago) . Motherboard: LENOVO | | 1707W9L Processor: Intel® Core™ Duo CPU T2400 @ 1.83GHz | None | 1828/167mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 75 GiB total, 58.947 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP104: 7/13/2013 2:55:21 PM - System Checkpoint RP105: 7/14/2013 3:25:15 PM - System Checkpoint RP106: 7/15/2013 4:19:45 PM - System Checkpoint RP107: 7/16/2013 5:14:10 PM - System Checkpoint RP108: 7/17/2013 6:08:35 PM - System Checkpoint RP109: 7/18/2013 7:03:02 PM - System Checkpoint RP110: 7/19/2013 7:12:32 PM - System Checkpoint RP111: 7/20/2013 7:53:01 PM - System Checkpoint RP112: 7/21/2013 8:47:30 PM - System Checkpoint RP113: 7/22/2013 9:41:58 PM - System Checkpoint RP114: 7/23/2013 10:36:27 PM - System Checkpoint RP115: 7/24/2013 11:30:55 PM - System Checkpoint RP116: 7/26/2013 12:25:26 AM - System Checkpoint RP117: 7/27/2013 1:19:57 AM - System Checkpoint RP118: 7/28/2013 2:14:25 AM - System Checkpoint RP119: 7/29/2013 3:08:54 AM - System Checkpoint RP120: 7/30/2013 4:03:27 AM - System Checkpoint RP121: 7/31/2013 11:32:09 AM - System Checkpoint RP122: 8/1/2013 12:40:56 PM - System Checkpoint RP123: 8/2/2013 1:10:34 PM - System Checkpoint RP124: 8/3/2013 2:00:02 PM - System Checkpoint RP125: 8/4/2013 2:26:24 PM - System Checkpoint RP126: 8/5/2013 2:57:39 PM - System Checkpoint RP127: 8/6/2013 4:06:49 PM - System Checkpoint RP128: 8/7/2013 4:51:05 PM - System Checkpoint RP129: 8/8/2013 5:49:55 PM - System Checkpoint RP130: 8/9/2013 6:41:09 PM - System Checkpoint RP131: 8/10/2013 7:37:50 PM - System Checkpoint RP132: 8/13/2013 7:18:28 PM - System Checkpoint RP133: 8/14/2013 7:40:12 PM - System Checkpoint RP134: 8/15/2013 8:34:41 PM - System Checkpoint RP135: 8/16/2013 9:30:16 PM - System Checkpoint RP136: 8/17/2013 9:43:52 PM - System Checkpoint RP137: 8/17/2013 11:56:42 PM - OTL Restore Point - 8/17/2013 11:56:26 PM . ==== Installed Programs ====================== . Adobe Flash Player 11 ActiveX
Hello Frikx and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.


The last time one of the Malware Team replied, you didn’t respond.

We all do this on a voluntary basis and most of us also have day jobs and families, so please be gracious enough to reply even if it is only to say that you will be busy for a couple of days or no longer require help. Thanks


Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Due to what has been seen in your logs, it is important that you run these in the order given in the instructions.

===================================================

Disable Spybot’s TeaTimer

Spybot’s TeaTimer can sometimes prevent some things from being fixed.

Please disable TeaTimer for now until you are clean: it can be re-activated once your log is clean.
  • open Spybot Search & Destroy
  • in the Mode menu click "Advanced mode" if not already selected
  • choose "Yes" at the Warning prompt
  • expand the "Tools" menu
  • click "Resident"
  • uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box
  • in the File menu click "Exit" to exit Spybot Search & Destroy.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Logs to include with next post:

AdwCleaner log
OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Hi It has been a couple of days since I replied to your request for help with your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI