McAffe was telling me that it had blocked a trojan, and the taskbar was warning that I had serious errors with my hard drive, RAM, bad clusters, etc.
Then System Check popped up. It looked very official, and I allowed it to scan, and attempt to 'fix' the problems.
Once it popped up to tell me that I needed to BUY something to fix it, I knew that I had been had.
Interestingly, my screen still had the standard background, not black.
All of my icons disappeared, and no programs appeared in my start menu. I claimed that I had no programs, and could not find my hard drive. Thankfully, I found out that these were simply hidden, not eliminated.
I then began to look around on the internet to how to Remove System Check. The guide on this site was very instructive, so I used it.
The steps I took were:
- Entered Safe Mode
- Downloaded and ran Rkill (Rkill did not say it stopped any processes, but System Check closed)
- Downloaded and ran TDSSkiller (Did not pick up any threats)
- I was unable to load MalWarebytes, as it would claim 'Access Denied' during setup (I already use Malwarebytes).
I finally figured out how to load Malwarebytes from the Run Box, and it completed the scan.
It found PUM.hijack.startmenu (several differnt ones).
It said it quarantined and removed them, and asked for a reboot.
Once it was rebooted in Normal mode, System Check immediately restarted - this time my background went black.
I have run the above steps several times, and even though MalWarebytes claims it has removed this problem, if loading in Normal mode, System Check is still there.
As per the Preparation Guide I have added the DDS log, Attach log, and GMER log - all were created from Safe Mode.
If anyone can help me, I would really appreciate it. THANKS!!
DDS LOG:
DDS (Ver_09-07-30.01) - NTFSx86
Run by Earl at 22:43:12.71 on Sun 08/23/2009
Internet Explorer: 6.0.2900.5512
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3070.2411 [GMT -6:00]
AV: McAfee VirusScan *On-access scanning enabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
============== Running Processes ===============
C:\Program Files\Webroot\Spy Sweeper\WRConsumerService.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
svchost.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
svchost.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Earl\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
uRun: [SUPERAntiSpyware] "c:\program files\superantispyware\SUPERAntiSpyware.exe"
uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe"
mRun: [ehTray] "c:\windows\ehome\ehtray.exe"
mRun: [IAAnotif] "c:\program files\intel\intel application accelerator\iaanotif.exe"
mRun: [IntelMeM] "c:\program files\intel\modem event monitor\IntelMEM.exe"
mRun: [CTSysVol] "c:\program files\creative\sbaudigy2zs\surround mixer\CTSysVol.exe" /r
mRun: [CTDVDDET] "c:\program files\creative\sbaudigy2zs\dvdaudio\CTDVDDET.EXE"
mRun: [CTHelper] "c:\windows\system32\CTHELPER.EXE"
mRun: [UpdReg] "c:\windows\UpdReg.EXE"
mRun: [DVDLauncher] "c:\program files\cyberlink\powerdvd\DVDLauncher.exe"
mRun: [UpdateManager] "c:\program files\common files\sonic\update manager\sgtray.exe" /r
mRun: [mmtask] "c:\program files\musicmatch\musicmatch jukebox\mmtask.exe"
mRun: [dla] "c:\windows\system32\dla\tfswctrl.exe"
mRun: [MaxtorOneTouch] "c:\progra~1\maxtor\onetouch\utils\OneTouch.exe"
mRun: [RetroExpress] "c:\progra~1\dantz\retros~1\RetroExpress.exe" /h
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [NvCplDaemon] "RUNDLL32.EXE" c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] "nwiz.exe" /install
mRun: [NvMediaCenter] "RUNDLL32.EXE" c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [MXOBG] "c:\windows\MXOALDR.EXE"
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SpySweeper] "c:\program files\webroot\spy sweeper\SpySweeperUI.exe" /startintray
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\acroba~1.lnk - c:\program files\adobe\acrobat 6.0\distillr\acrotray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\apcups~1.lnk - c:\program files\apc\apc powerchute personal edition\Display.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pictur~2.lnk - c:\program files\sony corporation\picture package\picture package menu\SonyTray.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony corporation\picture package\picture package applications\Residence.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} - hxxp://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5691/mcfscan.cab
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
LSA: Notification Packages = scecli scecli
============= SERVICES / DRIVERS ===============
R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2008-8-9 29808]
R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2007-6-4 214024]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2009-7-28 9968]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-7-28 74480]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2007-6-4 359952]
R2 McrdSvc;Media Center Extender Service;c:\windows\ehome\mcrdsvc.exe [2005-8-5 99328]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2007-6-4 144704]
R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\spy sweeper\SpySweeper.exe [2009-4-21 4048240]
R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\spy sweeper\WRConsumerService.exe [2008-12-5 1205760]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2007-6-4 606736]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2007-6-4 79880]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2007-6-4 35272]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2007-6-4 40552]
R3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-7-28 7408]
S3 DPCNET5U;Satellite USB Driver;c:\windows\system32\drivers\dpcnet5u.sys --> c:\windows\system32\drivers\dpcnet5u.sys [?]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2007-6-4 34216]
=============== Created Last 30 ================
2009-08-23 22:41 <DIR> --d----- C:\_OTM
2009-08-21 21:16 23,392 -------- c:\windows\system32\nscompat.tlb
2009-08-21 21:16 16,832 -------- c:\windows\system32\amcompat.tlb
2009-08-21 20:50 <DIR> --d----- c:\windows\system32\scripting
2009-08-21 20:50 <DIR> --d----- c:\windows\l2schemas
2009-08-21 20:50 <DIR> --d----- c:\windows\system32\en
2009-08-21 20:50 <DIR> --d----- c:\windows\system32\bits
2009-08-21 20:44 <DIR> --d----- c:\windows\network diagnostic
2009-08-21 20:40 617,472 a------- c:\windows\system32\advapi32.dll
2009-08-21 20:15 73,728 -------- c:\windows\system32\javacpl.cpl
2009-08-17 22:36 <DIR> --ds---- c:\documents and settings\earl\UserData
2009-08-17 17:43 <DIR> --dshr-- C:\autorun.inf
2009-08-16 10:42 <DIR> --d----- c:\windows\system32\dllcache\cache
2009-08-16 10:28 <DIR> --dshr-- C:\cmdcons
2009-08-13 18:43 118 -------- c:\windows\system32\MRT.INI
2009-08-13 18:42 <DIR> --d----- c:\windows\ServicePackFiles
2009-08-13 18:35 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
2009-08-09 13:05 <DIR> --d----- c:\windows\system32\NtmsData
2009-08-05 03:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-03 20:27 <DIR> --d----- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2009-08-03 20:27 <DIR> --d----- c:\program files\SUPERAntiSpyware
2009-08-03 20:27 <DIR> --d----- c:\docume~1\earl\applic~1\SUPERAntiSpyware.com
2009-07-29 23:49 <DIR> --d----- c:\docume~1\earl\applic~1\Malwarebytes
2009-07-29 23:48 38,160 -------- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-29 23:48 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
2009-07-29 23:48 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-29 23:48 19,096 -------- c:\windows\system32\drivers\mbam.sys
2009-07-29 17:22 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Citrix
2009-07-29 17:18 <DIR> --d----- c:\program files\Citrix
2009-07-29 17:18 61,224 -------- c:\documents and settings\earl\GoToAssistDownloadHelper.exe
2009-07-28 21:34 <DIR> --d----- c:\windows\McAfee.com
==================== Find3M ====================
2009-08-21 22:57 89,375 -------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-08-21 20:15 411,368 -------- c:\windows\system32\deploytk.dll
2009-08-05 03:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-07-18 10:20 3,062,272 -------- c:\windows\system32\dllcache\cache\mshtml.dll
2009-07-18 10:05 3,069,440 -------- c:\windows\system32\dllcache\mshtml.dll
2009-07-18 10:05 1,509,888 -------- c:\windows\system32\dllcache\shdocvw.dll
2009-07-17 13:01 58,880 a------- c:\windows\system32\atl.dll
2009-07-17 13:01 58,880 -------- c:\windows\system32\dllcache\atl.dll
2009-07-13 10:08 286,720 a------- c:\windows\system32\wmpdxm.dll
2009-07-13 10:08 286,720 -------- c:\windows\system32\dllcache\wmpdxm.dll
2009-07-13 10:08 5,537,792 -------- c:\windows\system32\dllcache\wmp.dll
2009-06-26 10:50 666,624 a------- c:\windows\system32\wininet.dll
2009-06-26 10:50 666,624 -------- c:\windows\system32\dllcache\wininet.dll
2009-06-26 10:50 620,032 -------- c:\windows\system32\dllcache\urlmon.dll
2009-06-26 10:50 81,920 a------- c:\windows\system32\ieencode.dll
2009-06-26 10:50 81,920 -------- c:\windows\system32\dllcache\ieencode.dll
2009-06-26 10:18 659,456 -------- c:\windows\system32\dllcache\cache\wininet.dll
2009-06-25 02:25 730,112 a------- c:\windows\system32\lsasrv.dll
2009-06-25 02:25 301,568 a------- c:\windows\system32\kerberos.dll
2009-06-25 02:25 147,456 a------- c:\windows\system32\schannel.dll
2009-06-25 02:25 136,192 a------- c:\windows\system32\msv1_0.dll
2009-06-25 02:25 56,832 a------- c:\windows\system32\secur32.dll
2009-06-25 02:25 54,272 a------- c:\windows\system32\wdigest.dll
2009-06-25 02:25 730,112 -------- c:\windows\system32\dllcache\lsasrv.dll
2009-06-25 02:25 301,568 -------- c:\windows\system32\dllcache\kerberos.dll
2009-06-25 02:25 147,456 -------- c:\windows\system32\dllcache\schannel.dll
2009-06-25 02:25 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
2009-06-25 02:25 56,832 -------- c:\windows\system32\dllcache\secur32.dll
2009-06-25 02:25 54,272 -------- c:\windows\system32\dllcache\wdigest.dll
2009-06-24 05:18 92,928 -------- c:\windows\system32\dllcache\ksecdd.sys
2009-06-22 05:49 117,248 a------- c:\windows\system32\mqtgsvc.exe
2009-06-22 05:49 19,968 a------- c:\windows\system32\mqbkup.exe
2009-06-22 05:49 117,248 -------- c:\windows\system32\dllcache\mqtgsvc.exe
2009-06-22 05:49 19,968 -------- c:\windows\system32\dllcache\mqbkup.exe
2009-06-22 05:49 4,608 a------- c:\windows\system32\mqsvc.exe
2009-06-22 05:49 4,608 -------- c:\windows\system32\dllcache\mqsvc.exe
2009-06-22 05:48 91,776 -------- c:\windows\system32\dllcache\mqac.sys
2009-06-16 08:36 119,808 a------- c:\windows\system32\t2embed.dll
2009-06-16 08:36 81,920 a------- c:\windows\system32\fontsub.dll
2009-06-16 08:36 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-06-16 08:36 81,920 -------- c:\windows\system32\dllcache\fontsub.dll
2009-06-12 06:31 80,896 a------- c:\windows\system32\tlntsess.exe
2009-06-12 06:31 80,896 -------- c:\windows\system32\dllcache\tlntsess.exe
2009-06-12 06:31 76,288 a------- c:\windows\system32\telnet.exe
2009-06-12 06:31 76,288 -------- c:\windows\system32\dllcache\telnet.exe
2009-06-10 09:19 2,066,432 a------- c:\windows\system32\mstscax.dll
2009-06-10 09:19 2,066,432 -------- c:\windows\system32\dllcache\mstscax.dll
2009-06-10 08:13 84,992 a------- c:\windows\system32\avifil32.dll
2009-06-10 08:13 84,992 -------- c:\windows\system32\dllcache\avifil32.dll
2009-06-10 00:14 132,096 a------- c:\windows\system32\wkssvc.dll
2009-06-10 00:14 132,096 -------- c:\windows\system32\dllcache\wkssvc.dll
2009-06-05 11:42 2,060,288 -------- c:\windows\system32\usbaaplrc.dll
2009-06-03 13:09 1,291,264 a------- c:\windows\system32\quartz.dll
2009-06-03 13:09 1,291,264 -------- c:\windows\system32\dllcache\quartz.dll
2009-03-08 11:54 7,460 -------- c:\docume~1\earl\applic~1\ViewerApp.dat
============= FINISH: 22:44:11.10 ===============
Attached File(s)
-
ark.txt (12.95K)
Number of downloads: 0 -
Attach.txt (10.25K)
Number of downloads: 1
This post has been edited by MileHighV: 29 January 2012 - 10:43 AM
Reason for edit: Moved from XP to Malware Removal Logs.

Help
This topic is locked


Back to top












