bkstr7
Topic Starter
Windows XP home , IE7 , DSL connection , Acer Desktop Computer .
I was surfing the internet on my desktop and had several pages open when my old Adobe 6 Reader opened up by itself and my browser pages all froze . I have heard that Adobe can sometimes enable malware , but I could not shut down computer to stop installation . Then the computer shut itself down ( maybe because I also tried to use control+alt+delete to stop processes) , when it restarted , I had the following problems
The computer boots up OK to desktop with all icons present
When I try to open My Computer icon in start menu , the screen is blank except for the swiveling flashlight , for 3 MINUTES before it shows icons for the removable and fixed drives . If I click on the icon that drive will open , but if I go back up , the 3 minute delay happens. It has never been in any way slow before . However , I had some shortcuts on my desktop to various folders on my fixed drive (partitioned into 2) , C and D , and those folders open instantly , then I am able to go to any folder or file on that drive by clicking on it , or by changing the location in the address bar .
When I run Windows explorer , and I click on the My computer icon in the tree on the left window , nothing happens .Nothing appears in the right window , but if I click on other icons on left , things open on right .
I can open my IE7 browser , it has always been set to open my home page on blank . But when I try to go to any page on the internet , either by clicking on a favorites bookmark , or by typing a simple address into the address bar , like www.google.com , the browser freezes , nothing at all downloads or shows , and I have to use task manager to close the browser window (red x at upper right doesn't work) .
However , I AM connected to the internet , because when I started to scan with my malware fixers , I was able to download updates , I downloaded a Windows critical update while I was working on this , and I can still get new e-mail through Outlook Express .
I also noted when I tried to save scan logs , I can not change the "save to" location , when I click on the little down arrow , no "tree" of drive icons appears , nothing happens and the process freezes , so it is stuck on the last folder I saved to before the trouble started , but I can save the logs there .
I also noticed on my NTI CD/DVD burner program, I can not navigate to any folder in the file selection window , I see icons for the various drives but nothing happens when I click on them . However , I also have Nero burner installed , and with that I can navigate from drive to drive and folder to folder to make selections , it doesn't seem to be affected .
What I am guessing is that whatever malware installed through adobe , it has corrupted my OS or browser , but maybe in a simple way that can be fixed . However , I do not have a Windows XP disk , only my Acer Computer recovery disks from pre-installed program .
The fixes already tried today :
Scan with AVG Anti spyware , I was able to update it , it found only cookies , which I deleted .
Scan with Spybot search and destroy , I was able to update it , it found just 2 malware , but they were two that had been found and deleted before : Microsoft.WindowsSecurityCenter.FirewallOveride , and Microsoft.WindowsSecurityCenter_disabled . I had Spybot delete these two again .
Scan with new AdAware , I could not update this as apparently it accesses a web page , but I had updated it in August , and when I scaned , it found 16 malwares , which I had it delete .
I also scaned with SmitfraudFix , and had it fix what it found , and saved logs.
I have also used ATF CLeaner and CC Cleaner .
I downloaded and installed the newest HijackThis program today .
I had some trouble a few months ago with Zlob Downloader but I thought I had fixed it .
Because I can't navigate to any page on the Internet , I dug out and set up my old Dell laptop with Win2K on it , and that's what I am using to post this message . Laptop has only CD/DVD reader drive and 3.5 floppy drive . If I have to download any fixes , I have to download them to laptop drive, copy to a USB thumbdrive , plug the thumbdrive into the desktop and install from there to the desktop drive . If I get a log file from the desktop , I have to copy it to thumbdrive , transfer thumbdrive to laptop , copy log to laptop drive , and upload from there .
So thats where I stand :connected to Internet , browser unable to find or connect with Internet pages , unable to navigate to computer drives except by "backdoors" .
I don't know if this is a HJT forum thread , but if it will save a few steps ,I have posted my latest HJT log file .
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:58:31, on 11/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
–
End of file - 5992 bytes
I was surfing the internet on my desktop and had several pages open when my old Adobe 6 Reader opened up by itself and my browser pages all froze . I have heard that Adobe can sometimes enable malware , but I could not shut down computer to stop installation . Then the computer shut itself down ( maybe because I also tried to use control+alt+delete to stop processes) , when it restarted , I had the following problems
The computer boots up OK to desktop with all icons present
When I try to open My Computer icon in start menu , the screen is blank except for the swiveling flashlight , for 3 MINUTES before it shows icons for the removable and fixed drives . If I click on the icon that drive will open , but if I go back up , the 3 minute delay happens. It has never been in any way slow before . However , I had some shortcuts on my desktop to various folders on my fixed drive (partitioned into 2) , C and D , and those folders open instantly , then I am able to go to any folder or file on that drive by clicking on it , or by changing the location in the address bar .
When I run Windows explorer , and I click on the My computer icon in the tree on the left window , nothing happens .Nothing appears in the right window , but if I click on other icons on left , things open on right .
I can open my IE7 browser , it has always been set to open my home page on blank . But when I try to go to any page on the internet , either by clicking on a favorites bookmark , or by typing a simple address into the address bar , like www.google.com , the browser freezes , nothing at all downloads or shows , and I have to use task manager to close the browser window (red x at upper right doesn't work) .
However , I AM connected to the internet , because when I started to scan with my malware fixers , I was able to download updates , I downloaded a Windows critical update while I was working on this , and I can still get new e-mail through Outlook Express .
I also noted when I tried to save scan logs , I can not change the "save to" location , when I click on the little down arrow , no "tree" of drive icons appears , nothing happens and the process freezes , so it is stuck on the last folder I saved to before the trouble started , but I can save the logs there .
I also noticed on my NTI CD/DVD burner program, I can not navigate to any folder in the file selection window , I see icons for the various drives but nothing happens when I click on them . However , I also have Nero burner installed , and with that I can navigate from drive to drive and folder to folder to make selections , it doesn't seem to be affected .
What I am guessing is that whatever malware installed through adobe , it has corrupted my OS or browser , but maybe in a simple way that can be fixed . However , I do not have a Windows XP disk , only my Acer Computer recovery disks from pre-installed program .
The fixes already tried today :
Scan with AVG Anti spyware , I was able to update it , it found only cookies , which I deleted .
Scan with Spybot search and destroy , I was able to update it , it found just 2 malware , but they were two that had been found and deleted before : Microsoft.WindowsSecurityCenter.FirewallOveride , and Microsoft.WindowsSecurityCenter_disabled . I had Spybot delete these two again .
Scan with new AdAware , I could not update this as apparently it accesses a web page , but I had updated it in August , and when I scaned , it found 16 malwares , which I had it delete .
I also scaned with SmitfraudFix , and had it fix what it found , and saved logs.
I have also used ATF CLeaner and CC Cleaner .
I downloaded and installed the newest HijackThis program today .
I had some trouble a few months ago with Zlob Downloader but I thought I had fixed it .
Because I can't navigate to any page on the Internet , I dug out and set up my old Dell laptop with Win2K on it , and that's what I am using to post this message . Laptop has only CD/DVD reader drive and 3.5 floppy drive . If I have to download any fixes , I have to download them to laptop drive, copy to a USB thumbdrive , plug the thumbdrive into the desktop and install from there to the desktop drive . If I get a log file from the desktop , I have to copy it to thumbdrive , transfer thumbdrive to laptop , copy log to laptop drive , and upload from there .
So thats where I stand :connected to Internet , browser unable to find or connect with Internet pages , unable to navigate to computer drives except by "backdoors" .
I don't know if this is a HJT forum thread , but if it will save a few steps ,I have posted my latest HJT log file .
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:58:31, on 11/1/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\WINDOWS\system32\VTTimer.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
–
End of file - 5992 bytes