Google Redirects and Suspicious activity, possibly a Hijack

Posted 20 May 2010 - 05:51 AM

Hey there! Before i start i'd like to express my gratitude at any and all attempts to help me with my situation smile.gif

My computer's security used to be pretty good, however recently ive been hit with a number of attacks. In the the past 2 weeks ive been infected with Fake antivirus software on more than 3 occasions. Initially i was able to remove it manually with the help of an online guide, until the other day where i got infected with one which removed my Regedit and task manager privlages. I ran Malwarebytes and it managed to fix the constant fake antivirus popups etc however i started getting some weird notifications and i noticed my connection speed and general speed of my computer is at an all time low!

Note: After that most recent attack i realised my firewall wasnt up to the challenge, before i was simply using the windows firewall as my norton antivirus ran out not so long ago, however i downloaded and installed Comodo to cope with the problem.

Heres some of the problems ive been getting

- Regular "Host Process for Windows has stopped working" and "Application layer gateway" notifications, too frequent to ignore.

- Also sometimes i get another notification similar to the one before only for randomly named exe files (Alarming!)

- Ive noticed that a number of times my desktop does a weird change where the start bar and explorer window change, sort of to the older style like seen in windows 98 etc. This kinda made me think it was rootkit related like i was getting remote accessed or something!

- The main problem which drew my attention was the regular google search redirects i get, which send me to a random page when i click a result, sometimes related, sometimes not.

- Im also getting alot of failed attempts to connect to websites, sometimes it takes a refresh or 2 to get the page to display.

Ive been running back to back AVG and Malwarebytes scans to try and fix the problem however they dont seem to be able to find anything. I Also had a look at my Hijackthis log and found a suspicious .exe file but it seems a little tricky to get rid of. Since installing Comodo, this program in particular has been flagged as trying to connect elsewhere and connections coming in to it. In my logs its called Pcwcorwo.exe.

Ive insert the DDS file below and attached the other log, however while i was trying to follow the guide for posting, i was unable to get Gmer to work properly. As soon as it opens it starts scanning, giving me no option to pause and untick the options suggested. It then crashes about 5-10 seconds into it everytime.

Thanks for reading!

DDS (Ver_10-03-17.01) - NTFSx86
Run by Aquari at 9:16:50.75 on 20/05/2010
Internet Explorer: 7.0.6000.17037 BrowserJavaVersion: 1.6.0_11
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.3071.1631 [GMT 1:00]

AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
SP: Windows Defender *disabled* (Outdated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
SP: Norton Internet Security *enabled* (Outdated) {CBB7EE13-8244-4DAB-8B55-D5C7AA91E59A}
FW: COMODO Firewall Pro *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

============== Running Processes ===============

C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\ASUS\SmartLogon\smartlogon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
C:\Program Files\ATK Hotkey\ASLDRSrv.exe
C:\Program Files\ATKGFNEX\GFNEXSrv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\ATK Hotkey\Hcontrol.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\ASUS\ASUS CopyProtect\aspg.exe
C:\Program Files\P4G\BatteryLife.exe
C:\Program Files\ASUS\Splendid\ACMON.exe
C:\Program Files\ATK Hotkey\ATKOSD.exe
C:\Program Files\ATK Hotkey\KBFiltr.exe
C:\Program Files\ATK Hotkey\WDC.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\COMODO\Firewall\cmdagent.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Users\Aquari\AppData\Local\TVersity\Media Server\MediaServer.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\SetPoint\SetPoint.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\COMODO\Firewall\cfp.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.asus.com
uDefault_Page_URL = hxxp://www.asus.com
mDefault_Page_URL = hxxp://www.asus.com
uInternet Settings,ProxyServer = http=
uInternet Settings,ProxyOverride = <local>
TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.5\UIBHO.dll
TB: {32099AAC-C132-4136-9E9A-4E364A424E17} - No File
mRun: [13714] c:\users\aquari\appdata\local\temp\pcwcorwo.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\reader 8.0\reader\reader_sl.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adober~2.lnk - c:\program files\adobe\reader 8.0\reader\AdobeCollabSync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\logite~1.lnk - c:\program files\setpoint\SetPoint.exe
uPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: EnableLUA = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
TCP: NameServer =,
TCP: {84F409C6-5437-4399-BB8C-31DED8BFDEFA} =,
TCP: {B4503AE0-47EC-4416-862A-1D3A5716A15E} =,
TCP: {E3CE52A1-9F61-4CF8-BA3B-1D5390C6752C} =,
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
AppInit_DLLs: c:\windows\system32\guard32.dll
mASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"

================= FIREFOX ===================

FF - ProfilePath - c:\users\aquari\appdata\roaming\mozilla\firefox\profiles\u4z03tak.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://is-nice.org/bias/index.php?sid=62617f6540dbc888344f844cfc2ccfa7
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?FORM=IEFM1&q=
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\users\aquari\appdata\roaming\mozilla\firefox\profiles\u4z03tak.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1636.7222\npCIDetect13.dll
FF - plugin: c:\program files\google\update\\npGoogleOneClick8.dll
FF - plugin: c:\program files\opera\program\plugins\npdivx32.dll
FF - plugin: c:\users\aquari\appdata\roaming\mozilla\firefox\profiles\u4z03tak.default\extensions\iaplayer@instantaction.com\plugins\npiaplayer.dll
FF - plugin: c:\users\aquari\appdata\roaming\mozilla\firefox\profiles\u4z03tak.default\extensions\npdyyno@dyyno.com\plugins\npDyyno.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: XULRunner: {CDD852E8-FF14-4B05-9517-BFC4B473F24A} - c:\users\aquari\appdata\local\{CDD852E8-FF14-4B05-9517-BFC4B473F24A}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 iaNvStor;Intel® Turbo Memory Controller;c:\windows\system32\drivers\iaNvStor.sys [2007-10-2 220696]
R0 lullaby;lullaby;c:\windows\system32\drivers\lullaby.sys [2008-5-27 15416]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-15 216200]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-15 29512]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-15 242896]
R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2010-5-20 85008]
R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-5-20 25104]
R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20090407.002\IDSvix86.sys [2009-4-14 272432]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-15 308064]
R2 hasplms;HASP License Manager;c:\windows\system32\hasplms.exe -run --> c:\windows\system32\hasplms.exe -run [?]
R3 Symantec Core LC;Symantec Core LC;c:\program files\common files\symantec shared\ccpd-lc\symlcsvc.exe [2009-1-18 1251720]
S2 gupdate1c9fce1456e56b0;Google Update Service (gupdate1c9fce1456e56b0);c:\program files\google\update\GoogleUpdate.exe [2009-7-4 133104]
S2 MSIU-ca1a35d6;MSIU-ca1a35d6;c:\windows\system32\-ca1a35d6.exe [2010-5-20 71168]
S3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2008-10-3 37936]

=============== Created Last 30 ================

2010-05-20 07:38:53 0 d-----w- c:\programdata\Office Genuine Advantage
2010-05-20 00:40:08 23040 ----a-w- C:\lsass.exe
2010-05-19 23:54:16 0 d-----w- c:\users\aquari\appdata\roaming\Comodo
2010-05-19 23:54:07 85008 ----a-w- c:\windows\system32\drivers\cmdguard.sys
2010-05-19 23:54:07 25104 ----a-w- c:\windows\system32\drivers\cmdhlp.sys
2010-05-19 23:54:07 143104 ----a-w- c:\windows\system32\guard32.dll
2010-05-19 23:54:07 0 d-----w- c:\programdata\comodo
2010-05-19 23:51:16 0 d-----w- c:\program files\COMODO
2010-05-19 23:35:32 20 ----a-w- c:\users\aquari\appdata\roaming\wpcalv.dat
2010-05-19 23:35:18 194048 ----a-w- c:\windows\Jxocoa.exe
2010-05-19 23:34:50 71168 ----a-w- c:\windows\system32\-ca1a35d6.exe
2010-05-18 18:03:04 0 d-----w- c:\program files\common files\Steam
2010-05-18 18:03:02 0 d-----w- c:\program files\Steam
2010-05-15 16:57:57 0 d-----w- c:\program files\CCleaner
2010-05-15 12:39:51 0 d-----w- c:\program files\Trend Micro
2010-05-15 03:18:19 0 d--h--w- C:\$AVG
2010-05-15 03:15:50 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-05-15 03:15:42 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-15 03:15:32 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-15 03:15:20 0 d-----w- c:\windows\system32\drivers\Avg
2010-05-15 03:07:24 0 d-----w- c:\program files\AVG
2010-05-15 03:06:53 0 d-----w- c:\programdata\avg9
2010-05-15 02:23:43 0 d-----w- c:\users\aquari\appdata\roaming\ATManager
2010-05-15 02:23:33 0 d-----w- c:\users\aquari\appdata\roaming\72AFE4C9D578D4F801489958EFC8A85B
2010-04-29 12:20:01 0 d-----w- c:\programdata\e-Safekey
2010-04-28 15:57:28 25088 ----a-w- c:\users\aquari\Accounting Information SystemsTutorial Week 10.doc

==================== Find3M ====================

2010-05-20 07:36:36 45056 ----a-w- c:\windows\system32\acovcnt.exe
2010-05-20 00:26:55 86016 ----a-w- c:\windows\inf\infstrng.dat
2010-05-20 00:26:55 51200 ----a-w- c:\windows\inf\infpub.dat
2010-05-20 00:26:54 86016 ----a-w- c:\windows\inf\infstor.dat
2010-05-19 12:25:53 27934 ----a-w- c:\users\aquari\appdata\roaming\nvModes.dat
2010-04-29 14:39:38 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 14:39:26 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-09 16:54:49 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-09 16:50:34 56320 ----a-w- c:\windows\system32\iesetup.dll
2010-03-09 16:50:25 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-09 16:48:34 72704 ----a-w- c:\windows\system32\admparse.dll
2010-03-09 14:17:48 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2010-03-09 12:43:52 48128 ----a-w- c:\windows\system32\mshtmler.dll
2010-03-04 19:24:26 434176 ----a-w- c:\windows\system32\vbscript.dll
2010-02-20 23:54:40 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-02-20 23:51:43 31232 ----a-w- c:\windows\system32\httpapi.dll
2009-06-29 02:14:39 284 --sh--w- c:\program files\desktop.ini
2009-01-18 19:10:45 665600 ----a-w- c:\windows\inf\drvindex.dat
2008-12-13 03:04:26 362 ----a-w- c:\program files\Searches.lnk
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 9:21:42.41 ===============

#2 aquari

Posted 20 May 2010 - 08:22 PM

I cant see where to delete this topic, but just to let you all know ive decided to format my drive and start over. It's about time i cleaned this thing up ;) Thanks for looking anyways!

#3 Budapest


Posted 20 May 2010 - 09:01 PM

Topic closed at member's request.
