Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.


Can Only boot in Safe mode. Big Virus Blast

  • This topic is locked This topic is locked
2 replies to this topic

#1 jerrydwane


  • Members
  • 9 posts
  • Local time:01:27 PM

Posted 03 March 2010 - 04:47 PM

Referred from here: http://www.bleepingcomputer.com/forums/t/300062/can-only-boot-in-safe-mode-big-virus-blast/ ~ OB

Moved from several different post (sorry)
DDS log Included

Hi all, I'm glad I found your site and I hope you can help me.

I got hit yesterday with a blast trojan.hiloti, trojen.dropper, trojan.fake and the security tool virus along with 6 other Trojan variances etc. that made my vast go crazy until the virus finaly got through it. NOTE: I DO NOT have my original Win xp disc or system resore disc and I feel I may be stuck with loosing some valuable programs here.

What I have done so far. I have ran malwarebytes and it wound 7 infected files and successfully deleted them however there is something still wrong or went wrong durring the delete process etc because I can no longer use system restore and when I go into normal windows mode my pc will Lock up and or I can not use the lower bar where the start menu is.

I have ran hijackthis and combofix and have logs for them but I do not know what to delete etc. I think I read that I am not suppose to post any logs until ask to do so, so I will not do that as of yet.

Anyway I have also ran 3 different virus removal tools and they do not find anything. The only one that finds anything is spybot but then of course it wants me to pay 89.00 to remove it etc.

I can NOT even do a system restore as it fails each time and I receive error message "can not restore" and it doesn't matter what date I choose to restore to it simply will not restore.

I will have to hang around on these boards as it is very difficult for me to even get online. I have not however found any problems when running in safe mode (accept everything is slow)(pretty normal for safe mode) however if I even attempt to log into normal windows it will lock me up within 3-5 minutes.

I have also downloaded SP3 in hopes that would fix any registry problems but it did not help
I hope one of you pros will be willing to help me,
Thank you.

I have also noticed that this program/virus hijacks some of the google search links and overrides them with there own google ads code that will send me to a link that has nothing to do with the search.

I noticed someone else had a similar issue with this redirection in another post

DDS log per request of "boobme" NOTE: this log was ran in SAFE MODE as I can not stay in normal win mode. I'm sure there are other processes running there. Thank you

DDS (Ver_09-12-01.01) - NTFSx86 NETWORK
Run by Owner at 13:46:56.12 on Wed 03/03/2010
Internet Explorer: 7.0.5730.11
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1560 [GMT -8:00]

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\Program Files\NETGEAR\WG311v3\WG311v3.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&SubCH=nofound&Br=EM&Loc=ENG_US&Sys=DTP&M=W3650
uInternet Settings,ProxyOverride =
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
BHO: HP Print Enhancer: {0347c33e-8762-4905-bf09-768834316c61} - c:\program files\hp\smart web printing\hpswp_printenhancer.dll
BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No File
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
Trusted Zone: att.net
Trusted Zone: sbcglobal.net
Trusted Zone: yahoo.com\clientapps
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\Yinsthelper.dll
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1267520293156
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1267520560265
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_04-windows-i586.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\pizh2kw0.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\pizh2kw0.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\pizh2kw0.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}\platform\winnt_x86-msvc\components\pagespeed.dll
FF - plugin: c:\program files\google\update\\npGoogleOneClick8.dll
FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll

FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);

============= SERVICES / DRIVERS ===============

S3 iMSPCLOj;iMSPCLOj;\??\c:\docume~1\owner\locals~1\temp\imspcloj.sys --> c:\docume~1\owner\locals~1\temp\iMSPCLOj.sys [?]
S4 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-5 135664]

=============== Created Last 30 ================

2010-03-03 20:08:43 0 d-sha-r- C:\cmdcons
2010-03-03 20:07:35 98816 ----a-w- c:\windows\sed.exe
2010-03-03 20:07:35 77312 ----a-w- c:\windows\MBR.exe
2010-03-03 20:07:35 261632 ----a-w- c:\windows\PEV.exe
2010-03-03 20:07:35 161792 ----a-w- c:\windows\SWREG.exe
2010-03-02 14:07:06 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-03-02 10:23:45 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-02 10:23:44 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-02 10:23:44 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-02 10:15:59 0 d-----w- c:\windows\system32\PreInstall
2010-03-02 10:15:24 0 d-----w- c:\windows\system32\en
2010-03-02 10:15:23 0 d-----w- c:\windows\system32\bits
2010-03-02 10:12:33 0 d-----w- c:\windows\EHome
2010-03-02 10:12:26 0 d-----w- c:\windows\system32\SoftwareDistribution
2010-03-02 09:56:09 0 d-----w- C:\found.000
2010-03-02 09:26:27 0 d-----w- c:\windows\ServicePackFiles
2010-03-02 09:24:30 19569 ----a-w- c:\windows\002763_.tmp
2010-03-02 08:58:42 21728 ----a-w- c:\windows\system32\wucltui.dll.mui
2010-03-02 08:58:41 17632 ----a-w- c:\windows\system32\wuaueng.dll.mui
2010-03-02 08:58:41 15072 ----a-w- c:\windows\system32\wuaucpl.cpl.mui
2010-03-02 08:58:41 15064 ----a-w- c:\windows\system32\wuapi.dll.mui
2010-03-02 00:07:24 48640 ----a-w- c:\windows\csnfr32.dll
2010-03-01 23:05:11 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-03-01 23:04:59 8192 ----a-w- c:\windows\system32\drivers\changer.sys
2010-03-01 09:00:30 0 d-----w- c:\program files\Trend Micro
2010-03-01 08:15:18 0 d-----w- c:\windows\system32\wbem\Repository
2010-03-01 07:32:01 120 ----a-w- c:\windows\Bwuyis.dat
2010-03-01 07:32:01 0 ----a-w- c:\windows\Iqexitenim.bin
2010-03-01 07:28:05 24 ----a-w- c:\docume~1\owner\applic~1\rbuwzv.dat
2010-02-26 05:58:30 0 d-----w- c:\program files\Paws and Claws Pet School
2010-02-25 03:59:06 0 d-----w- c:\program files\WolfQuest
2010-02-20 15:30:03 0 d-----w- c:\docume~1\alluse~1\applic~1\Alwil Software
2010-02-07 22:43:11 0 d-----w- c:\program files\SecondLife

==================== Find3M ====================

2010-03-01 07:19:52 69 ----a-w- c:\documents and settings\owner\jagex_runescape_preferences.dat
2010-03-01 06:22:40 69 ----a-w- c:\documents and settings\owner\jagex_runescape_preferences2.dat
2007-05-24 22:58:00 249856 ----a-w- c:\windows\inf\wg311v3\InsDrv2k.exe
2006-12-04 19:38:30 212992 ----a-w- c:\windows\inf\wg311v3\CopyWHQLDriver.exe
2005-12-30 02:07:50 282624 ----a-r- c:\windows\inf\wg311v3\WG311v3XP.sys
2008-04-01 02:52:23 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\application data\microsoft\feeds cache\index.dat

============= FINISH: 13:47:01.81 ===============

Edited by Orange Blossom, 03 March 2010 - 07:00 PM.

BC AdBot (Login to Remove)


#2 myrti



  • Malware Study Hall Admin
  • 33,784 posts
  • Gender:Female
  • Location:At home
  • Local time:08:27 PM

Posted 07 March 2010 - 08:39 AM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

Please include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.
We need to create an OTL Report
  1. Please download OTL from one of the following mirrors:
  2. Save it to your desktop.
  3. Double click on the icon on your desktop.
  4. Click the "Scan All Users" checkbox.
  5. In the custom scan box paste the following:
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\*. /mp /s
  6. Push the button.
  7. Two reports will open, copy and paste them in a reply here:
    • OTL.txt <-- Will be opened
    • Extra.txt<--Will be minimized

In the upper right hand corner of the topic you will see a button called Options. If you click on this in the drop-down menu you can choose Track this topic. I suggest you do this and select Immediate E-Mail notification and click on Proceed. This way you will be advised when we respond to your topic and facilitate the cleaning of your machine.

After 5 days if a topic is not replied to we assume it has been abandoned and it is closed.

regards myrti

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!


Follow BleepingComputer on: Facebook | Twitter | Google+

#3 myrti



  • Malware Study Hall Admin
  • 33,784 posts
  • Gender:Female
  • Location:At home
  • Local time:08:27 PM

Posted 13 March 2010 - 07:45 AM

Due to lack of feedback, this topic is now Closed

If you need this topic reopened, please send me a PM.
Please include the address of this thread in your request.
This applies only to the original topic starter.

Everyone else please start a new topic.

With Regards,

is that a bird?  a plane? nooo it's the flying blueberry!

If I have been helping you and haven't replied in 2 days, feel free to shoot me a PM! Please don't send help request via PM, unless I am already helping you. Use the forums!


Follow BleepingComputer on: Facebook | Twitter | Google+

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users