Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Virus launches and redirects iexplorer windows


  • This topic is locked This topic is locked
4 replies to this topic

#1 kmwpurple

kmwpurple

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:20 PM

Posted 09 January 2009 - 12:02 AM

My pc recently became infected with a virus(es) that created multiple explorer windows and pop-ups, making the machine almost unusable when connected to the internet. I downloaded SpyBot, which found various malware among which was Vundo, Virtumonde, SmitFraud and various others. I followed instructions found here at bleepingcomputer.com and was able to resolve everything except for SmitFraud. Now, there are occasional launches of new explorer windows which are then redirected to some unwanted site. After a few hours the machine seems sluggish and unresponsive. The symptoms do not match the SmitFraud descriptions but this is what SpyBot finds, along with Right Media and sometimes also it detects the condition that Microsoft Security Center has been disabled (but I check and the firewall is still active).

Here is the DDS.txt log:


DDS (Ver_09-01-07.01) - NTFSx86
Run by Owner at 22:40:49.68 on Thu 01/08/2009
Internet Explorer: 6.0.2900.5512 BrowserJavaVersion: 1.6.0_11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.850 [GMT -6:00]

AV: Norton AntiVirus *On-access scanning enabled* (Outdated)
FW: Norton AntiVirus *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Norton Ghost\Agent\VProSvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\PROGRA~1\Dantz\RETROS~1\wdsvc.exe
C:\WINDOWS\system32\RioMSC.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy Media Creator 8\Drag to Disc\DrgToDsc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Norton Ghost\Agent\VProTray.exe
C:\WINDOWS\system32\sstray.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SpyCatcher\Scheduler daemon.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\Webshots\Webshots.scr
C:\Program Files\Yahoo!\Widgets\YahooWidgets.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.foxnews.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://www.foxnews.com/
uInternet Settings,ProxyOverride = localhost;*.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn6\yt.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn6\yt.dll
BHO: NoExplorer - No File
BHO: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Yahoo! IE Services Button: {5bab4b5b-68bc-4b02-94d6-2fc0de4a7897} - c:\program files\yahoo!\common\yiesrvc.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
BHO: NoExplorer - No File
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn6\YTSingleInstance.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn6\yt.dll
TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {4982D40A-C53B-4615-B15B-B5B5E98D167C} - No File
TB: {C17590D2-ECB4-4B15-8820-F58798DCC118} - No File
EB: Real.com: {fe54fa40-d68c-11d2-98fa-00c0f0318afe} - c:\windows\system32\Shdocvw.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll"
mRun: [WD Button Manager] WDBtnMgr.exe
mRun: [Traymin900] %SystemRoot%\System32\drivers\Tray900.exe
mRun: [SunKistEM] c:\program files\digital media reader\shwiconem.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [RoxioDragToDisc] "c:\program files\roxio\easy media creator 8\drag to disc\DrgToDsc.exe"
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [PhiBtn] %SystemRoot%\System32\drivers\PhiBtn.exe
mRun: [osCheck] "c:\program files\norton antivirus\osCheck.exe"
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [Norton Ghost 14.0] "c:\program files\norton ghost\agent\VProTray.exe"
mRun: [nForce Tray Options] sstray.exe /r
mRun: [LVCOMSX] c:\windows\system32\LVCOMSX.EXE
mRun: [LogitechVideoRepair] c:\program files\logitech\video\ISStart.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [hpqSRMon] c:\program files\hewlett-packard\digital imaging\bin\hpqSRMon.exe
mRun: [HPHmon03] c:\windows\system32\hphmon03.exe
mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [MSConfig] c:\windows\pchealth\helpctr\binaries\MSCONFIG.EXE /auto
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\schedu~1.lnk - c:\program files\spycatcher\Scheduler daemon.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\webshots.lnk - c:\program files\webshots\Launcher.exe
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\yahoo!~1.lnk - c:\program files\yahoo!\widgets\YahooWidgets.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hewlett-packard\digital imaging\bin\hpqtra08.exe
IE: &AOL Toolbar search - c:\program files\aol toolbar\toolbar.dll/SEARCH.HTML
IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm
IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - c:\program files\yahoo!\common\yiesrvc.dll
IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\window~4\MpShHook.dll

================= FIREFOX ===================

FF - ProfilePath -

============= SERVICES / DRIVERS ===============

R1 usbhubb;usbhubb;c:\windows\system32\drivers\usbhubb.sys [2009-1-5 86272]
R3 camvid40;Philips SPC 900NC PC Camera;c:\windows\system32\drivers\camdrv41.sys [2008-7-15 1240576]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2008-1-18 109616]
R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20080308.006\NAVENG.SYS [2008-3-8 82256]
R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20080308.006\NAVEX15.SYS [2008-3-8 895408]
R3 SymSnapService;SymSnapService;c:\program files\norton ghost\shared\drivers\SymSnapService.exe [2007-12-20 1558000]
R4 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-9-25 574808]
R4 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-9 108648]
R4 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSvcHst.exe [2007-1-9 108648]
R4 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2007-1-26 1251720]
R4 Symantec SymSnap VSS Provider;Symantec SymSnap VSS Provider;c:\windows\system32\dllhost.exe [2004-10-14 5120]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-1-10 24652]
R4 WinDefend;Windows Defender;c:\program files\windows defender\MsMpEng.exe [2006-11-3 13592]
S3 Dot4Usb HPH09;Dot4Usb HPH09;c:\windows\system32\drivers\hphius09.sys [2003-1-30 18864]
S3 Fadpu16E;Fadpu16E;\??\c:\docume~1\owner\locals~1\temp\fadpu16e.sys --> c:\docume~1\owner\locals~1\temp\Fadpu16E.sys [?]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\google\google desktop search\GoogleDesktop.exe [2006-11-8 29744]
S3 USBVSP;USBVSP;c:\windows\system32\drivers\usbvsp.sys --> c:\windows\system32\drivers\Usbvsp.sys [?]

=============== Created Last 30 ================

2009-01-08 22:15 34,890 ac------ c:\windows\system32\dllcache\wlandrv2.sys
2009-01-08 22:14 604,253 ac------ c:\windows\system32\dllcache\vmodem.sys
2009-01-08 22:13 69,632 ac------ c:\windows\system32\dllcache\umaxu12.dll
2009-01-08 22:12 31,744 ac------ c:\windows\system32\dllcache\tp4.dll
2009-01-08 22:11 3,968 ac------ c:\windows\system32\dllcache\swusbflt.sys
2009-01-08 22:10 20,752 ac------ c:\windows\system32\dllcache\sonync.sys
2009-01-08 22:09 94,698 ac------ c:\windows\system32\dllcache\sk98xwin.sys
2009-01-08 22:08 17,664 ac------ c:\windows\system32\dllcache\sermouse.sys
2009-01-08 22:07 62,496 ac------ c:\windows\system32\dllcache\s3mtrio.dll
2009-01-08 22:06 19,584 ac------ c:\windows\system32\dllcache\rasirda.sys
2009-01-08 22:05 19,840 ac------ c:\windows\system32\dllcache\philtune.sys
2009-01-08 22:04 351,616 ac------ c:\windows\system32\dllcache\ovcodek2.sys
2009-01-08 22:03 32,840 ac------ c:\windows\system32\dllcache\ngrpci.sys
2009-01-08 22:02 49,024 ac------ c:\windows\system32\dllcache\mstape.sys
2009-01-08 22:01 65,536 ac------ c:\windows\system32\dllcache\OLD599.tmp
2009-01-08 22:00 8,192 ac------ c:\windows\system32\dllcache\kbdkor.dll
2009-01-08 21:59 372,824 ac------ c:\windows\system32\dllcache\iconf32.dll
2009-01-08 21:58 542,879 ac------ c:\windows\system32\dllcache\hsf_msft.sys
2009-01-08 21:57 907,456 ac------ c:\windows\system32\dllcache\hcf_msft.sys
2009-01-08 21:56 12,362 ac------ c:\windows\system32\dllcache\f3ab18xi.sys
2009-01-08 21:55 66,591 ac------ c:\windows\system32\dllcache\el90xbc5.sys
2009-01-08 21:54 131,156 ac------ c:\windows\system32\dllcache\digidbp.dll
2009-01-08 21:53 248,064 ac------ c:\windows\system32\dllcache\cl546xm.sys
2009-01-08 21:52 66,082 ac------ c:\windows\system32\dllcache\OLD1FA.tmp
2009-01-08 21:51 97,354 ac------ c:\windows\system32\dllcache\OLDE6.tmp
2009-01-08 21:50 598,071 ac------ c:\windows\system32\dllcache\OLD44.tmp
2009-01-08 21:23 13,824 ac------ c:\windows\system32\dllcache\bulltlp3.sys
2009-01-08 21:22 19,456 ac------ c:\windows\system32\dllcache\brbidiif.dll
2009-01-08 21:22 102,400 ac------ c:\windows\system32\dllcache\binlsvc.dll
2009-01-08 21:14 46,112 ac------ c:\windows\system32\dllcache\adptsf50.sys
2009-01-08 20:28 6,878 a------- c:\windows\system32\tmp.reg
2009-01-08 19:10 <DIR> --d----- c:\temp\tn3
2009-01-06 22:00 167,976 -------- c:\windows\system32\drivers\core.cache.dsk
2009-01-06 21:50 <DIR> --d----- c:\windows\ERUNT
2009-01-06 09:38 <DIR> --d----- C:\SDFix
2009-01-06 08:10 <DIR> a-dshr-- C:\cmdcons
2009-01-06 08:04 161,792 a------- c:\windows\SWREG.exe
2009-01-06 08:04 98,816 a------- c:\windows\sed.exe
2009-01-05 22:44 <DIR> --d----- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-01-05 22:44 <DIR> --d----- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-01-05 22:44 <DIR> --d----- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-01-05 22:44 <DIR> --d----- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-01-05 18:36 86,272 a------- c:\windows\system32\drivers\usbhubb.sys
2009-01-05 18:36 <DIR> --d----- c:\temp\REX81
2009-01-05 18:36 <DIR> --d----- c:\windows\system32\n
2009-01-04 01:52 <DIR> --d----- c:\program files\MSECache
2008-12-30 23:31 243 a------- C:\karenboot.ini
2008-12-29 20:49 <DIR> --d----- c:\program files\Western Digital
2008-12-21 19:10 128,104 a------- c:\windows\system32\drivers\WimFltr.sys
2008-12-21 19:10 15,088 a------- c:\windows\system32\drivers\vproeventmonitor.sys
2008-12-21 19:10 38,112 a------- c:\windows\system32\drivers\v2imount.sys
2008-12-21 19:10 138,080 a------- c:\windows\system32\drivers\symsnap.sys
2008-12-21 19:08 <DIR> --d----- c:\program files\Norton Ghost
2008-12-16 18:21 <DIR> --d----- c:\windows\system32\scripting
2008-12-16 18:21 <DIR> --d----- c:\windows\system32\en
2008-12-16 18:21 <DIR> --d----- c:\windows\l2schemas
2008-12-16 18:21 <DIR> --d----- c:\windows\system32\bits
2008-12-16 18:18 <DIR> --d----- c:\windows\ServicePackFiles
2008-12-16 18:16 <DIR> --d----- c:\windows\network diagnostic
2008-12-16 18:11 <DIR> --d----- c:\windows\EHome
2008-12-15 07:06 410,984 a------- c:\windows\system32\deploytk.dll

==================== Find3M ====================

2008-12-16 18:25 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-11-26 12:02 10,344 a------- c:\windows\system32\drivers\symlcbrd.sys
2008-10-23 06:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 14:06 268,648 a------- c:\windows\system32\mucltui.dll
2008-10-16 14:06 208,744 a------- c:\windows\system32\muweb.dll
2008-10-15 19:00 666,112 a------- c:\windows\system32\wininet.dll
2007-01-29 20:53 1,408 -------- c:\docume~1\owner\applic~1\wklnhst.dat

============= FINISH: 22:41:26.37 ===============




Based on reading other posts, I decided to download and run Malwarebytes' Anti-Malware. I did the quick scan and it found 8 infections which appear to have been successfully removed. I will run full scan tomorrow. I have not seen any random explorer windows launched yet after almost 10 minutes (usually takes only one minute or so).

Unfortunately I do not have a valid/updated license to run Norton Anti-Virus. Original license became invalidated when I cloned a new hard drive just last week. I am pretty sure my problems are a result of not having this running. New software is in the mail - hope it arrives before the next virus attack!!!

I will provide an update tomorrow after system has been up and running.

Attached Files


Edited by kmwpurple, 09 January 2009 - 02:30 AM.


BC AdBot (Login to Remove)

 


#2 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:08:20 PM

Posted 22 January 2009 - 04:26 PM

Howdy, my name is Hoov, and I will be helping you with your dilemma.

Please make sure you watch this thread for responses. If you click the options tab at the top of your first post, you can select to track this thread.

Here is what I am asking you to do during the repair of your computer

*Tell me everything that you have done, if anything, to try and fix this problem.

*Please only use 1 forum to help clear up your problem. Posting on more than 1 and following instructions from more than 1 forum will cause those helping you to pull out thier hair.

*Follow my instructions - If you can't for some reason, or if you don't understand something, please tell me. If you deviate from my instructions, tell me, it may make a difference on where we go. Don't install anything, even other programs that have nothing to do with security or malware, it could cause things to change, and I would never know it.

*Have faith. I will do all I can to get your computer working, and if I can't - someone else here will know something else to try.

*Stick with me to the end. My aim is to fix your problems, and give you the tools and knowledge to keep this from happening again.

Now onto trying to fix your computer.

How did the full Malwarebytes' Anti-Malware scan go?
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#3 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:08:20 PM

Posted 27 January 2009 - 12:36 PM

if you still need help, please post something here to let me know you are still interested. If I don't hear anything in the next couple days, then this thread will be closed.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image

#4 kmwpurple

kmwpurple
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:09:20 PM

Posted 30 January 2009 - 01:22 PM

Thank you, but I managed to solve the problems I was having. The Malwarebytes scan helped me out enough that I was able to get back up and running. I have a new Symantec Norton license and all is well. Norton found a few problems and was able to clean them up. What a pain.

All is well ... for now.

You can close this topic.

#5 Hoov

Hoov

  • Malware Response Team
  • 3,519 posts
  • OFFLINE
  •  
  • Location:Mikado Michigan
  • Local time:08:20 PM

Posted 30 January 2009 - 05:56 PM

Thanks for letting us know.
Visiting From SpywareHammer.com and DonHoover.net

Tilting at windmills hurts you more than the windmills.
-From the Notebooks of Lazarus Long
Senior of the Howard Families

Posted Image




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users