A while back I started getting Google search redirects and my antivirus and spyware protection didn't pick anything up. Recently I switched to Norton Security Suite and the scan results indicate that I have been infected with trojan.zeroaccess.b, and it indicates that manual removal is required. I have not been able to remove the threat when following their instructions. Also, when performing a full system scan with Norton Security Suite, it restarts the computer at the end to finalize the process and the computer will not restart without going back to the most recent working recovery point. I have followed the instructions Preparation Guide. Please note that the computer is 64 bit so I was unable to create a GMER log. Your help in fixing this issue is greatly appreciated!
.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_13
Run by Jerry at 14:25:08 on 2012-02-05
.
============== Running Processes ===============
.
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Windows\SysWOW64\DllHost.exe
C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\ccSvcHst.exe
C:\Windows\SysWOW64\ping.exe
C:\Users\Jerry\Desktop\dds.scr
.
============== Pseudo HJT Report ===============
.
uWindow Title = Internet Explorer
mWinlogon: Userinit=C:\Windows\SysWOW64\Userinit.exe
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\PROGRA~2\mcafee\msk\mskapbho.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
uRun: [ehTray.exe] C:\Windows\ehome\ehTray.exe
uRun: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: DisableCAD = 1 (0x1)
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
LSP: mswsock.dll
DPF: {43E3F87D-DE7F-4087-BD4F-0DC854981158} - hxxp://download.microsoft.com/download/7/3/8/7384c441-3721-41ee-ae15-b678888f00dd/clearadj.CAB
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{9735849C-CD89-471A-B21B-4937C64FE4CB} : DhcpNameServer = 75.75.75.75 75.75.76.76
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~2\MICROS~1\Office12\GR99D3~1.DLL
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL
LSA: Notification Packages = scecli psqlpwd
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: McAfee Phishing Filter: {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~2\mcafee\msk\mskapbho.dll
BHO-X64: McAfee Phishing Filter - No File
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Spybot-S&D IE Protection: {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~2\SPYBOT~1\SDHelper.dll
BHO-X64: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO-X64: Symantec NCO BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
BHO-X64: Symantec NCO BHO - No File
BHO-X64: Symantec Intrusion Prevention: {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\IPS\IPSBHO.DLL
BHO-X64: Symantec Intrusion Prevention - No File
BHO-X64: Search Helper: {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
BHO-X64: Search Helper - No File
BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL
BHO-X64: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO-X64: Windows Live Toolbar Helper: {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB-X64: &Windows Live Toolbar: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB-X64: {DE9C389F-3316-41A7-809B-AA305ED9D922} - No File
TB-X64: Norton Toolbar: {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\5.1.0.29\coIEPlg.dll
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~2\MICROS~1\Office12\GRA8E1~1.DLL
Hosts: 127.0.0.1 www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jerry\AppData\Roaming\Mozilla\Firefox\Profiles\jmtyczgf.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll
FF - plugin: C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
.
---- FIREFOX POLICIES ----
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R? cfwids;McAfee Inc. cfwids
R? clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64
R? clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86
R? clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64
R? gupdate;Google Update Service (gupdate)
R? gupdatem;Google Update Service (gupdatem)
R? HTCAND64;HTC Device Driver
R? McMPFSvc;McAfee Personal Firewall
R? McNaiAnn;McAfee VirusScan Announcer
R? McProxy;McAfee Proxy Service
R? McShield;McShield
R? mfeavfk;McAfee Inc. mfeavfk
R? mfefire;McAfee Firewall Core Service
R? mfefirek;McAfee Inc. mfefirek
R? mfehidk;McAfee Inc. mfehidk
R? mfenlfk;McAfee NDIS Light Filter
R? mferkdet;McAfee Inc. mferkdet
R? mfevtp;McAfee Validation Trust Protection Service
R? mfewfpk;McAfee Inc. mfewfpk
R? PerfHost;Performance Counter DLL Host
R? SBSDWSCService;SBSD Security Center Service
R? TVICHW64;TVICHW64
R? WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0
R? WSDPrintDevice;WSD Print Support via UMB
S? AESTFilters;Andrea ST Filters Service
S? b57nd60a;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0
S? BHDrvx64;BHDrvx64
S? DockLoginService;Dock Login Service
S? FontCache;Windows Font Cache Service
S? IDSVia64;IDSVia64
S? N360;Norton Security Suite
S? PxHlpa64;PxHlpa64
S? SymDS;Symantec Data Store
S? SymEFA;Symantec Extended File Attributes
S? SymIRON;Symantec Iron Driver
S? SYMTDIv;Symantec Vista Network Dispatch Driver
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2012-02-05 17:26:20 0 --sha-w- C:\Windows\System32\dds_trash_log.cmd
2012-02-01 03:41:51 525544 ----a-w- C:\Windows\System32\deployJava1.dll
2012-02-01 03:39:44 414368 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-02-01 03:33:48 -------- d-----w- C:\Windows\System32\drivers\NBRTWizardx64\0401000.00F
2012-02-01 03:33:48 -------- d-----w- C:\Windows\System32\drivers\NBRTWizardx64
2012-02-01 03:33:45 -------- d-----w- C:\Program Files (x86)\Norton Bootable Recovery Tool Wizard
2012-02-01 03:16:32 432760 ----a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\symtdiv.sys
2012-02-01 03:16:31 912504 ----a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\symefa64.sys
2012-02-01 03:16:31 744568 ----a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\srtsp64.sys
2012-02-01 03:16:31 450680 ----a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\symds64.sys
2012-02-01 03:16:31 40568 ----a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\srtspx64.sys
2012-02-01 03:16:31 382584 ----a-w- C:\Windows\System32\drivers\N360x64\0501000.01D\symnets.sys
2012-02-01 03:16:31 171128 ----a-r- C:\Windows\System32\drivers\N360x64\0501000.01D\ironx64.sys
2012-02-01 03:16:17 -------- d-----w- C:\Windows\System32\drivers\N360x64\0501000.01D
2012-02-01 03:12:52 34152 ----a-w- C:\Windows\System32\drivers\GEARAspiWDM.sys
2012-02-01 03:12:45 174200 ----a-w- C:\Windows\System32\drivers\SYMEVENT64x86.SYS
2012-02-01 03:12:45 -------- d-----w- C:\Program Files\Symantec
2012-02-01 03:12:45 -------- d-----w- C:\Program Files\Common Files\Symantec Shared
2012-02-01 03:12:14 -------- d-----w- C:\Windows\System32\drivers\N360x64
2012-02-01 03:12:12 -------- d-----w- C:\Program Files (x86)\Norton Security Suite
2012-02-01 03:11:49 -------- d-----w- C:\Program Files (x86)\NortonInstaller
2012-02-01 02:53:59 -------- d-----w- C:\Users\Jerry\AppData\Roaming\Tific
2012-02-01 02:53:56 -------- d-----w- C:\Users\Jerry\AppData\Local\Symantec
2012-01-28 19:35:48 -------- d-----w- C:\Program Files\Waterfox
2012-01-28 19:22:30 -------- d-----w- C:\Program Files (x86)\Common Files\Symantec Shared
2012-01-28 19:20:01 125872 ----a-w- C:\Windows\System32\GEARAspi64.dll
2012-01-28 19:20:01 106928 ----a-w- C:\Windows\SysWow64\GEARAspi.dll
2012-01-28 19:15:42 -------- d-----w- C:\ProgramData\NortonInstaller
2012-01-28 19:07:44 -------- d-----w- C:\ProgramData\IsolatedStorage
2012-01-28 19:07:43 -------- d-----w- C:\Users\Jerry\AppData\Local\ID Vault
2012-01-28 18:38:26 -------- d-----w- C:\Users\Jerry\AppData\Roaming\ID Vault
2012-01-28 18:35:48 -------- d-----w- C:\Program Files (x86)\Constant Guard Protection Suite
2012-01-28 18:35:36 -------- d-----w- C:\ProgramData\White Sky, Inc
2012-01-27 02:26:57 515968 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2012-01-27 02:26:57 442368 ----a-w- C:\Windows\System32\winhttp.dll
2012-01-27 02:26:57 347136 ----a-w- C:\Windows\System32\schannel.dll
2012-01-27 02:26:57 278528 ----a-w- C:\Windows\SysWow64\schannel.dll
2012-01-27 02:26:57 1689600 ----a-w- C:\Windows\System32\lsasrv.dll
2012-01-27 02:26:56 94720 ----a-w- C:\Windows\System32\secur32.dll
2012-01-27 02:26:56 77312 ----a-w- C:\Windows\SysWow64\secur32.dll
2012-01-27 02:26:56 377344 ----a-w- C:\Windows\SysWow64\winhttp.dll
2012-01-27 02:26:56 11264 ----a-w- C:\Windows\System32\lsass.exe
2012-01-21 18:26:04 -------- d-----we C:\Windows\system64
2012-01-14 02:20:06 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
2012-01-14 02:20:06 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
2012-01-14 02:20:04 497152 ----a-w- C:\Windows\SysWow64\qdvd.dll
2012-01-14 02:20:04 1570816 ----a-w- C:\Windows\System32\quartz.dll
2012-01-14 02:20:04 1314816 ----a-w- C:\Windows\SysWow64\quartz.dll
2012-01-14 02:20:03 352256 ----a-w- C:\Windows\System32\qdvd.dll
2012-01-14 02:20:01 1585152 ----a-w- C:\Windows\System32\ntdll.dll
2012-01-14 02:20:01 1167984 ----a-w- C:\Windows\SysWow64\ntdll.dll
2012-01-14 02:19:57 48128 ----a-w- C:\Windows\System32\mcicda.dll
2012-01-14 02:19:57 28672 ----a-w- C:\Windows\System32\mciwave.dll
2012-01-14 02:19:57 28160 ----a-w- C:\Windows\System32\mciseq.dll
2012-01-14 02:19:57 23552 ----a-w- C:\Windows\SysWow64\mciseq.dll
2012-01-14 02:19:57 211968 ----a-w- C:\Windows\System32\winmm.dll
2012-01-14 02:19:57 189952 ----a-w- C:\Windows\SysWow64\winmm.dll
2012-01-14 02:19:55 451072 ----a-w- C:\Windows\System32\winsrv.dll
2012-01-14 02:19:50 76800 ----a-w- C:\Windows\System32\packager.dll
2012-01-14 02:19:50 66560 ----a-w- C:\Windows\SysWow64\packager.dll
.
==================== Find3M ====================
.
2011-11-23 13:57:38 2764800 ----a-w- C:\Windows\System32\win32k.sys
2011-11-08 14:58:31 2048 ----a-w- C:\Windows\System32\tzres.dll
2011-11-08 14:42:19 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
.
============= FINISH: 14:26:03.30 ===============
Attached File(s)
-
Attach.txt (3.39K)
Number of downloads: 2

Help
This topic is locked


Back to top











