This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] browser corrupted ?

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I'm afraid that this did not work , the installation from administrator failed just like I described in post 57 . Would it make any sense to re-do the fixes in post 46 , but this time try them in safe mode ?
Well , I was delayed in posting because I had quite a morning here . I was so tired last night that I turned off the monitor without turning off the infected computer . This morning when I went to the computer and saw it was still on , when I went to turn the monitor back on , I got just a black screen as I told about in an earlier post . I can only see the white cursor arrow as I move it around the screen , and a few spots on the black screen will flash a white square as the cursor moves over it . So I did a power off forced shut down . The computer restarted and the monitor came on OK , it went through a disk check , because of improper shutdown , on the blue screen , and booted up to desk top . I had a feeling something was different , and when I clicked on the My Computer , everything opened IMMEDIATELY showing the icons for all the drives ! When I tried to download and save a file to the hd , the save to box worked perfectly , I could navigate from drive to drive and folder to folder . I opened Outlook Express and new mail downloaded , and I burned some files onto a disk with the NTI burner program which previously could not navigate between drives to find files . In other words , EVERYTHING WAS NORMAL ! Well I started to think about how I was going to organize my day to catch up on all the work I missed from the computer infection , and I went to look for the spare monitor I have to deal with this black screen business . I was getting used to the Firefox browser , and even downloaded an add on , but when the computer restarted after the install , ALL THE INFECTIONS WERE BACK . MY Computer buggy again , can't choose a folder to save to , no e-mail . How I wish I had set a restore point while it was working right for that 2 hours or so . The restore points it has now (last 3 or 4 days) don't change anything that cures the problems Now I'll tell you why I could tell the computer was different earlier when I had the 2 hours of good operation . When I looked at the icons on the monitor desk top , they were all crisply and clearly defined , and lightly colored . The reason I say this is that in times over the last 2 years or so when I have had computer problems, the icons on the desktop look heavy and blurry , even as if they had a dark outline . I could even see this happen as the computer boots up every day , the desktop icons show clearly for about 4 or 5 seconds , then the screen shifts and the all take on this darker "blurred" look . Have you ever worked with pictures printed on a clear plastic sheets , and overlayed one picture over another ? See how if you even have 2 identical pictures overlayed on top of the other , you will see the same picture but it will have a darker and slightly less defined look . That I think is just what is happening here with this computer , somehow it is installing TWO desktops , perhaps the computer is being remotely compromised . When the desktop icons are crisp and bright , the computer works fine , when they are dark and heavy , the computer has problems . I have been seeing this for about two years now . When I installed PrevX a few years ago , it seemed to clear all this up , but there was some small utility on another program that PrevX was uncompatable with and when I went to uninstall PrevX , like so many others, I was angry and uncertain when I found it couldn't be uninstalled . I found out how to disable it , but it did deal with what ever was disabling the computer as shown my the distorted desktop view . All the while this was happening today , the infected computer was connected to the net with DSL , and no firewall . One of the things I noticed this morning while the computer was working OK , is that Firefox had seemed to replace all of the Microsoft Windows indentifier marks on file desciptions and folder icons . Maybe the computer worked good when the new Firefox was controlling , but now even the Firefox is corrupted and the computer is showing the problems again . Maybe I can try to uninstall and reinstall a clean Firefox . Well , this computer was so near to being fixed , I have decided I will start all over again , I am doing the "before you post HJ log" fixes , I have done the ATF clean , and I am in the middle the Malwarebites scan now , a DEEP and COMPLETE scan including the thumbdrive I have been using this week and a SD chip I use daily with my camera . I see it has already found 4 objects infected . I will also update AdAware , AVG , and Spybot and do deep scans and attach logs . This may take most of this afternoon , but if you have any ideas please post them. Thanks
Latest logs

Malwarebytes' Anti-Malware 1.30
Database version: 1373
Windows 5.1.2600 Service Pack 2

2008-11-08 14:38:32
mbam-log-2008-11-08 (14-38-32).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|K:\|)
Objects scanned: 380555
Time elapsed: 1 hour(s), 26 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3aa42713-5c1e-48e2-b432-d8bf420dd31d} (Rogue.Antivirus2008) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\vp^\Desktop\RARextract\rap\winrar.v3.6b5_incl\Unipatch.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{32C1D3EE-62E1-4318-A1DD-66D71B99ADB2}\RP1091\A0216751.dll (Trojan.Pakes) -> Quarantined and deleted successfully.
D:\System Volume Information\_restore{32C1D3EE-62E1-4318-A1DD-66D71B99ADB2}\RP1092\A0217549.dll (Trojan.Pakes) -> Quarantined and deleted successfully.




Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:48, on 2008-11-08
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\acer\Acer eConsole\MediaServerService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Cathy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://cgi.verizon.net/bookmarks/bmredir.a…p;bm=bz_welcome
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: vzTCPConfig -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1158766737609
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1163900908375
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} (SABScanProcesses Class) - http://www.superadblocker.com/activex/sabspx.cab
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O20 - Winlogon Notify: origami - C:\WINDOWS\system32\hlolink.dll (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\acer\Acer eConsole\MediaServerService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 5749 bytes
I am finding malware hiding in a folder I have barely noticed before , it is on the D drive (half of my hard drive) it's called System Volume Information . I didn't have any programs installed on this drive , just files downloaded and saved for future reference or burn to disc . It my have something to do with system restore , but can I just delete it ?
The AVG scan found 2 instances of something called , I think , Dropper.agent.uba , which it quarenteened . They were in that folder on the D: drive which I deleted as you recommended . I am in the middle of the Spybot scan now . I happened to be watching it a short time ago and in the progress bar at the botttom it still showed that it was scanning files called Zlob.Downloader , it has done this in the past and not reported this as an infection , but I will post what it does find when i finishes . Then I will reboot and see how the computer runs but without an Internet connection . I may want to uninstall the Firefox on the infected computer and re-install from a new download . I may want to do this without the computer being connected to the net , could the installer be downloaded to the laptop and copied to the thumbdrive and installed to the infected computer from there ?
Yeah , I am still trying to straighten this computer out . I finished the Spybot scan and did recommended actions with the problems it found . I re-installed the Firefox but it hasn't brought the system back . Same problems with accessing drives through My Computer . Programs which seem to use the same utility to navigate from drive to drive in the computer are also not working , like my cd/dvd burner and my Adobe Photoshop , and of course , the "save download to" utility . I am assuming the e-mail progrem problem is still there too but I haven't put the infected computer back on line yet , not sure if malware will again start to infect again . Anyway , I wanted to get back to the point where the computer was working Saturday morning , so I looked into repair/re-installing XP over the infected OS with the new disk I bought . I found some web blogs which described how to do this , andI started the repair install , but I encounterd a problem that apperantly is common with this proceedure , the hang up during "Installing devices" . When the reinstall stopped I was able to use the laptop to find out the reasons and fixes (missin drivers etc), but I did not know how to make them work within the install process . Mainly , I didn't undrstand how to abort/cancel the install to start over . I think I read to just remove the install disk from the optical drive and shut down cold , but each time I do this the bluescreen re-install starts again and it asks for the disk to resume the install , which will start and again hang up at the 34 minute mark . How do I get out of this loop of booting up again and again only to reinstall , and get back to a normal boot up ? Should I be trying this reinstall now ?
I have started a new topic on the other forum to get through this reinstall . If it works and the computer gets back to normal , maybe I can ask one more time for your help in a final scan for malware , and if it is clear , installing a firewall from the thumbdrive before going back on the net . Would it make much of a difference to do malware scans both from normal mode and safe mode ?
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI