System is a Lenovo ThinkPad T60p-L34P86C, WinXPSP3.
I believe problem started on Thurs April7 , at least that is when i saw first evidence. I Had clicked on a program window that popped up instead of killing it in Task Manager and got infected by "Windows Restore".
Evidentally, this also opened the door for a bunch of other problem-ware.
I updated and ran Spybot, Malware Bytes and Avira Anti Virus; they all deleted some things
[attach logs if possible]
but evidentally not enough. (None of these deleted the 4 Windows Restore files in "~Application Data~" dir, had to delete manually, though the "Windows Restore" items have not shown up again. MB Did delete the Windows Restore Start Menu ShortCuts and Folder.)
Clicking on Goole search result links in IE now does not go to that site, goes to several other sites. also after a while started to get short bits of audio periodically, and other popups of IE Script errors, Internet Redirection warnings, even if no IE window open. [see screen prints] Started using the Lotus Symphony Web Browser (LS was already installed on system when recieved it, but have not used it much since first month Dec2009/Jan2010) as Google result links almost always worked through that.
When trying to follow the removal instructions at http://www.bleepingcomputer.com/virus-removal/remove-windows-restore
get below when running RKill , have tried most of the variant names with same result.
RKill Log File displays at last line in Cmd window:
FINDSTR: Search string too long.
[Log file available]
uninstalled Java, and Flash Player. on Monday started also getting prompts to install Flash player [see screen prints].
Have run Spybot, Malware Bytes and Avira Anti Virus again with seemingly no more than usual detections, will try to attach them too.
----
still getting these popups at intervals, wether IE is open or showing in running processes or not, sites vary, many different ones but sometimes ones that have shown up this way earlier
(i have gone to none of these sites intentionally before):
[can't seem to paste the images in, they are "Internet Explorer Script Error"s and "Internet Explorer cannot open the " , Internet Redirection warnings, Windows Explorer Security Warnings]
Thank You for your time and assistance,
Bryan Black
.-------------------------------------
DDS.txt:
.
DDS (Ver_11-03-05.01) - NTFSx86
Run by Daimyo at 14:38:14.29 on Tue 04/12/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1143 [GMT -4:00]
.
AV: AntiVir Desktop *Disabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
.
============== Running Processes ===============
.
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
svchost.exe
C:\Program Files\ThinkPad\ConnectUtilities\AcPrfMgrSvc.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\WINDOWS\system32\bmwebcfg.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\ThinkPad\ConnectUtilities\AcSvc.exe
C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE
C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe
C:\Program Files\ThinkPad\ConnectUtilities\SvcGuiHlpr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
C:\Program Files\Lenovo\Zoom\TpScrex.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACTray.exe
C:\Program Files\ThinkPad\ConnectUtilities\ACWLIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\IBM\Lotus\Symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090605-2002\soffice.exe
C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe
C:\Program Files\Secunia\PSI\psi.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\PWMUIAux.exe
C:\Program Files\IBM\Lotus\Symphony\framework\rcp\eclipse\plugins\com.ibm.rcp.base_6.2.0.20090505-1200\win32\x86\symphony.exe
C:\Program Files\Windows NT\Accessories\WORDPAD.EXE
C:\Program Files\IBM\Lotus\Symphony\framework\rcp\eclipse\plugins\com.ibm.rcp.swt.browser.dom.ie_6.2.0.20090505-1200\os\win32\x86\IEOOP.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\notepad.exe
C:\AV\BC-dds.scr
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uWindow Title =
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SODCPreLoad] c:\program files\ibm\lotus\symphony\framework\shared\eclipse\plugins\com.ibm.productivity.tools.base.app.win32_3.5.0.20090605-2002\preload.exe c:\docume~1\admini~1\ibm\lotus\symphony\.sodc\
mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe
mRun: [PSQLLauncher] "c:\program files\thinkvantage fingerprint software\launcher.exe" /startup
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"
mRun: [PWRMGRTR] rundll32 c:\progra~1\thinkpad\utilit~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
mRun: [BLOG] rundll32 c:\progra~1\thinkpad\utilit~1\BatLogEx.DLL,StartBattLog
mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
mRun: [SoundMAX] c:\program files\analog devices\soundmax\Smax4.exe /tray
mRun: [EZEJMNAP] c:\progra~1\thinkpad\utilit~1\EzEjMnAp.Exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [OpwareSE2] "c:\program files\scansoft\omnipagese2.0\OpwareSE2.exe"
mRun: [IMJPMIG8.1] "c:\windows\ime\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
mRun: [IMEKRMIG6.1] c:\windows\ime\imkr6_1\IMEKRMIG.EXE
mRun: [MSPY2002] c:\windows\system32\ime\pintlgnt\ImScInst.exe /SYNC
mRun: [PHIME2002ASync] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /SYNC
mRun: [PHIME2002A] c:\windows\system32\ime\tintlgnt\TINTSETP.EXE /IMEName
mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min
mRun: [ACTray] c:\program files\thinkpad\connectutilities\ACTray.exe
mRun: [ACWLIcon] c:\program files\thinkpad\connectutilities\ACWLIcon.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\admini~1\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe
IE: Send to &Bluetooth Device... - c:\program files\thinkpad\bluetooth software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
LSP: bmnet.dll
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://active.macromedia.com/director6/cabs/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: text/html - {35ee9500-064d-4284-b8a6-c8edbc027deb} -
Notify: ACNotify - ACNotify.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: psfus - c:\program files\thinkvantage fingerprint software\psqlpwd.dll
Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll
Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll
LSA: Notification Packages = scecli c:\program files\thinkvantage fingerprint software\psqlpwd.dll ACGina
.
============= SERVICES / DRIVERS ===============
.
R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2011-4-9 11608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2011-4-9 108289]
R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2011-4-9 185089]
R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2011-4-9 56816]
R2 Power Manager DBC Service;Power Manager DBC Service;c:\program files\thinkpad\utilities\PWMDBSVC.exe [2009-6-2 53248]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\common files\thinkvantage fingerprint software\drivers\smihlp.sys [2008-11-21 12560]
R3 GT72NDISIPXP;GT 72 IP NDIS;c:\windows\system32\drivers\Gt51Ip.sys [2008-2-18 105216]
R3 GT72UBUS;GT 72 U BUS;c:\windows\system32\drivers\gt72ubus.sys [2008-2-8 59264]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-7-7 14904]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-3-6 106496]
S3 swmx01;Sierra Wireless USB MUX Driver (#01);c:\windows\system32\drivers\swmx01.sys [2007-4-10 72576]
S3 SWNC5E01;Sierra Wireless MUX NDIS Driver (#01);c:\windows\system32\drivers\SWNC5E01.sys [2007-1-12 102144]
.
=============== Created Last 30 ================
.
2011-04-11 19:40:02 -------- d-----w- c:\program files\Secunia
2011-04-11 18:45:34 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-04-11 18:45:34 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-04-11 18:17:54 -------- d-----w- C:\e57f0a2b9c60ca553166dda0cb91
2011-04-11 18:10:14 4224 ----a-w- c:\windows\system32\drivers\IBMBLDID.sys
2011-04-11 18:10:14 11520 ----a-w- c:\windows\system32\drivers\ANC.sys
2011-04-10 20:24:19 966656 ----a-w- c:\program files\msn\msncorefiles\oobe\obemetal.dll
2011-04-10 20:24:19 86016 ----a-w- c:\program files\msn\msncorefiles\oobe\obepopc.dll
2011-04-10 20:24:19 77824 ----a-w- c:\program files\msn\msncorefiles\oobe\obemtllc.dll
2011-04-10 20:24:19 229376 ----a-w- c:\program files\msn\msncorefiles\oobe\obelog.dll
2011-04-10 20:24:18 884712 ----a-w- c:\program files\msn\msncorefiles\install\msn9components\Digcore.exe
2011-04-10 20:24:18 1327320 ----a-w- c:\program files\msn\msncorefiles\install\msnsusii.exe
2011-04-10 20:24:18 11053008 ----a-w- c:\program files\msn\msncorefiles\install\msn9components\Msncli.exe
2011-04-09 19:07:49 -------- d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes
2011-04-09 19:07:35 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-09 19:07:31 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-09 19:07:24 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-04-09 17:17:12 -------- d-----w- C:\AV
2011-04-09 16:55:39 56816 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2011-04-09 16:55:32 -------- d-----w- c:\program files\Avira
2011-04-09 16:55:32 -------- d-----w- c:\docume~1\alluse~1\applic~1\Avira
2011-04-08 17:01:12 -------- d-----w- c:\docume~1\admini~1\locals~1\applic~1\Help
.
==================== Find3M ====================
.
2011-04-11 19:03:17 672 ----a-w- C:\WU DetectNow.bat
2011-03-03 20:23:02 2855 ----a-w- c:\windows\system32\command.PIF
2011-02-09 13:53:52 270848 ----a-w- c:\windows\system32\sbe.dll
2011-02-09 13:53:52 186880 ----a-w- c:\windows\system32\encdec.dll
2011-02-02 07:58:35 2067456 ----a-w- c:\windows\system32\mstscax.dll
2011-01-27 11:57:06 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-01-21 14:44:37 439296 ----a-w- c:\windows\system32\shimgvw.dll
.
============= FINISH: 14:38:43.28 ===============
Sorry, forgot to put in original post:
I am considering going back to the Windows System Restore point from the day (or 2) before the first manifestation (prob should have done that before thrashing around the last 3 days...) if that is cleanest.
Does a Restore tend to be the best option in these (or this specific) case?
Thanks,
BB
EDIT: Posts merged ~Budapest
Attached File(s)
-
ark.txt (4.64K)
Number of downloads: 3 -
Attach041211.txt (14.11K)
Number of downloads: 0 -
AVSCAN-20110409-131025-2B58A7C6.LOG (28.64K)
Number of downloads: 1 -
AVSCAN-20110409-175855-43A65F51.LOG (28.21K)
Number of downloads: 1 -
AVSCAN-20110410-215713-48C611B1.LOG (21K)
Number of downloads: 1 -
mbam-log-2011-04-09 (17-09-58).txt (1.52K)
Number of downloads: 1 -
mbam-log-2011-04-09 (20-16-55).txt (1.78K)
Number of downloads: 1 -
mbam-log-2011-04-10 (11-32-05).txt (908bytes)
Number of downloads: 2 -
SBSnD-Fixes.110409-1039.txt (99.15K)
Number of downloads: 1 -
SBSnD-Fixes.110409-2104.txt (99.96K)
Number of downloads: 1 -
SBSnD-Fixes.110410-2030.txt (15.62K)
Number of downloads: 0
This post has been edited by Budapest: 12 April 2011 - 04:13 PM

Help
This topic is locked

Back to top


button.









