Was infected with Win 7 2012 Security virus on 12/9/2011. Security warning pop-ups, web page redirects, then system went into windows update which was not successful and no internet access after system restarted. Tried self-help steps including system restore (received error message that could not restore due to windows update not completed) with final try being bleepingcomputer removal instructions. Still seeing fake security symbol next to anti-virus programs (avg, malwarebytes, iexplore.exe, ddr.scr, etc.) and many options in control panel (system restore, network center, etc.). Still cannot access internet - connection to wireless network is there, but connection from network to internet in constant "identifying" mode. Troubleshooter identifies this due to not being connected to Homegroup, but when I try to change to "Home" network, the "save changes" button has fake security shield and does not make change. Cannot turn off system restore or enable firewall (error code Ox80070424). Have tried all in both safe mode and regular mode.
.
DDS (Ver_2011-08-26.01) - NTFSx86 MINIMAL
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_18
Run by miznat at 9:46:34 on 2011-12-26
.
============== Running Processes ===============
.
C:\windows\system32\wininit.exe
C:\windows\system32\lsm.exe
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\windows\system32\DllHost.exe
F:\dds.scr
C:\windows\system32\conhost.exe
C:\windows\system32\svchost.exe -k DcomLaunch
C:\windows\system32\svchost.exe -k RPCSS
C:\windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\windows\system32\svchost.exe -k netsvcs
C:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\windows\system32\svchost.exe -k NetworkService
.
============== Pseudo HJT Report ===============
.
uStart Page = https://epic.picbusiness.com/5000/
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SearchHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110920002325.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll
uRun: [Google Update] "c:\users\miznat\appdata\local\google\update\GoogleUpdate.exe" /c
uRun: [googletalk] c:\users\miznat\appdata\roaming\google\google talk\googletalk.exe /autostart
uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
uRun: [Spyware Doctor] c:\users\miznat\desktop\sdsetup_revwire207.exe -min
mRun: [IAAnotif] c:\program files\intel\intel matrix storage manager\iaanotif.exe
mRun: [MDS_Menu] "c:\program files\lenovo\mediashow\muitransfer\muistartmenu.exe" "c:\program files\lenovo\mediashow" updatewithcreateonce "software\cyberlink\mediashow\4.1"
mRun: [IdeaNotesUser] c:\program files\ddni\lenovo idea notes\DDNIMSGUser.exe
mRun: [Alive Idea Desktop] %ProgramFiles%\Lenovo\Alive Idea Desktop\Alive Idea Desktop.exe -hang45000
mRun: [Lenovo SlideNav] "c:\program files\lenovo\lenovo slidenav\slidebarnavigator\SlidebarNavigator.exe"
mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
mRun: [RtHDVCpl] c:\program files\realtek\audio\hda\RtHDVCpl.exe -s
mRun: [OnekeyDM] c:\program files\lenovo\onekeydm\OnekeyDM.exe
mRun: [VeriFaceManager] c:\program files\lenovo\veriface\PManage.exe
mRun: [UpdateP2GShortCut] "c:\program files\lenovo\power2go\muitransfer\muistartmenu.exe" "c:\program files\lenovo\power2go" updatewithcreateonce "software\cyberlink\power2go\5.0"
mRun: [EnergyUtility] c:\program files\lenovo\energy management\utility.exe
mRun: [Energy Management] c:\program files\lenovo\energy management\Energy Management.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe"
mRun: [<NO NAME>]
mRun: [Adobe_ID0EYTHM] c:\progra~1\common~1\adobe\adobev~1\server\bin\VERSIO~2.EXE
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRunOnce: [WLStart] "c:\program files\windows live\installer\wlstart.exe" /nosearch /nohomepage
dRunOnce: [osk.exe] osk.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\lenovo\bluetooth software\btsendto_ie.htm
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxps://epic.picbusiness.com/5000/script/smsx.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_18-windows-i586.cab
TCP: DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{27C0F791-317A-4E69-9339-46E72B74E9FC} : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{27C0F791-317A-4E69-9339-46E72B74E9FC}\24C696E6B6138323E36416C6C6F6574724F697 : DhcpNameServer = 192.168.2.1
TCP: Interfaces\{27C0F791-317A-4E69-9339-46E72B74E9FC}\7534D455359434 : DhcpNameServer = 172.16.50.5
TCP: Interfaces\{27C0F791-317A-4E69-9339-46E72B74E9FC}\76F676F696E666C696768647 : DhcpNameServer = 172.19.134.2
TCP: Interfaces\{27C0F791-317A-4E69-9339-46E72B74E9FC}\C696E6B6379737 : DhcpNameServer = 209.18.47.61 209.18.47.62
TCP: Interfaces\{2AE78028-2F4E-43B8-A705-36834DF5DA0E} : DhcpNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\miznat\appdata\roaming\mozilla\firefox\profiles\q8t5foau.default\
FF - prefs.js: network.proxy.type - 4
FF - component: c:\program files\mozilla firefox\distribution\bundles\{d19ca586-dd6c-4a0a-96f8-14644f340d60}\components\scriptff.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\miznat\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
.
============= SERVICES / DRIVERS ===============
.
R? aswFsBlk;aswFsBlk
R? aswMonFlt;aswMonFlt
R? aswSnx;aswSnx
R? aswSP;aswSP
R? avast! Antivirus;avast! Antivirus
R? b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
R? Bridge0;Bridge0
R? btwl2cap;Bluetooth L2CAP Service
R? cfwids;McAfee Inc. cfwids
R? DDNIMSGService;DDNIMSGService
R? DDNIService;DDNIService
R? funfrm;funfrm
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? IGRS;IGRS
R? IntcHdmiAddService;Intel® High Definition Audio HDMI
R? k57nd60x;Broadcom NetLink Gigabit Ethernet - NDIS 6.0
R? Lenovo ReadyComm AppSvc;Lenovo ReadyComm AppSvc
R? Lenovo ReadyComm ConnSvc;Lenovo ReadyComm ConnSvc
R? MBAMProtector;MBAMProtector
R? MBAMService;MBAMService
R? McMPFSvc;McAfee Personal Firewall Service
R? McShield;McAfee McShield
R? mfeavfk;McAfee Inc. mfeavfk
R? mfebopk;McAfee Inc. mfebopk
R? mfefire;McAfee Firewall Core Service
R? mfefirek;McAfee Inc. mfefirek
R? mfehidk;McAfee Inc. mfehidk
R? mfenlfk;McAfee NDIS Light Filter
R? mferkdet;McAfee Inc. mferkdet
R? mfevtp;McAfee Validation Trust Protection Service
R? mfewfpk;McAfee Inc. mfewfpk
R? netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit
R? PS_MDP;ReadyComm Presentation Space Helper Service
R? ReadyComm.DirectRouter;ReadyComm.DirectRouter
R? RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader
R? usbsmi;Lenovo EasyCamera
R? vwififlt;Virtual WiFi Filter Driver
R? vwifimp;Microsoft Virtual WiFi Miniport Service
R? WatAdminSvc;Windows Activation Technologies Service
R? wdmirror;wdmirror
R? wsvd;wsvd
S? ACPIVPC;Lenovo Virtual Power Controller Driver
S? enecir;ENE CIR Receiver
S? enecirhid;ENE CIR HID Receiver
S? enecirhidma;ENE CIR HIDmini Filter
.
=============== Created Last 30 ================
.
2011-12-19 14:41:43 -------- d-----w- c:\users\miznat\appdata\local\NPE
2011-12-19 14:41:43 -------- d-----w- c:\programdata\Norton
2011-12-19 13:56:45 -------- d-----w- c:\programdata\PC Tools
2011-12-19 13:51:17 -------- d-----w- c:\programdata\RegCure
2011-12-18 05:15:07 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-12-18 04:50:25 -------- d--h--w- c:\programdata\Common Files
2011-12-18 04:49:25 -------- d-----w- c:\programdata\MFAData
2011-12-13 01:42:55 -------- d-----w- c:\users\miznat\appdata\roaming\Malwarebytes
2011-12-13 01:42:50 -------- d-----w- c:\programdata\Malwarebytes
2011-12-13 01:42:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-12-10 01:29:51 240008 ----a-w- c:\windows\system32\drivers\netio.sys
2011-12-09 15:53:18 -------- d-----w- c:\windows\system32\SPReview
2011-12-09 13:57:27 -------- d-----w- c:\programdata\AVAST Software
.
==================== Find3M ====================
.
2011-11-28 17:01:25 41184 ----a-w- c:\windows\avastSS.scr
2011-11-28 16:53:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-11-28 16:52:07 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-01 02:59:14 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-09-29 15:43:37 1285488 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-29 04:20:25 2339840 ----a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 9:47:28.45 ===============
Attached File(s)
-
Attach.txt (4.25K)
Number of downloads: 0 -
ark.zip (36.62K)
Number of downloads: 0

Help
This topic is locked

Back to top












