Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser(s) hijacked + freezing OS


  • This topic is locked This topic is locked
2 replies to this topic

#1 passlion

passlion

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:08:18 PM

Posted 19 October 2010 - 04:32 PM

Hello, new to this and hopefully someone can help me out~

My computer (Win 7) was infected by Win32/Alureon.V which opened the doors to other trojans and crap
(made my PC download a fake virus scan prgm called "ThinkPoint")

So I did my own removal work and thought I removed it all, but browsers are trying to redirect me when I click on google results and the like.

A few occasion the following would happen:
I run HJT or an online virus scan and it freezes THEN
I clicked on run task manager and it doesn't open AND
Explorer window freezes and pretty much everything else freezes as well.
Ctrl + Alt + Del shows blank screen with message saying it can't display properly, click ok, bounce me back.
When I restart it's either on that same blank screen or stuck on "logging off".

A few times I ran ComboFix (safe mode) and during Stage 2, windows pop-up saying "PEV.cfxxe" encountered a problem and has to close.
Couple instances during Stage 2 or 3 (can't see which) my PC BSOD'd saying "a problem was detected and window has to shut down".

OK, with all that in mind, here is the HJT log.
My ComboFix log is either missing or got erased when I ran it and encountered the BSOD, so I'll run it again.

========================

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:11:10 PM, on 10/19/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16671)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\CNYHKey.exe
C:\Windows\ModLEDKey.exe
C:\Windows\GWHotKey.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\sttray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe
C:\Windows\System32\StikyNot.exe
C:\Users\passLion\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files\HiJAckThis\Trend Micro\HiJackThis\HiJackThis.exe
C:\Users\passLion\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\passLion\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\passLion\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\passLion\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\passLion\AppData\Local\Google\Chrome\Application\chrome.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - C:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - C:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [MoLed] ModLEDKey.exe
O4 - HKLM\..\Run: [Multi-function Keyboard] GWHotKey.exe
O4 - HKLM\..\Run: [mumservice] C:\Program Files\Motorola\Software Update\mumservice.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\Ringz Studio\Storm Codec\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DiscWizardMonitor.exe] C:\Program Files\Seagate\DiscWizard\DiscWizardMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Seagate\DiscWizard\TimounterMonitor.exe
O4 - HKLM\..\Run: [Seagate Scheduler2 Service] "C:\Program Files\Common Files\Seagate\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [combofix] "C:\ComFix\CF8925.cfxxe" /c "C:\ComFix\C.bat"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
O4 - HKCU\..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe
O4 - HKCU\..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe /minimized
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O4 - HKCU\..\Run: [Google Update] "C:\Users\passLion\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\RazaWebHook32.dll/3000
O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm
O8 - Extra context menu item: 使用迅雷下载 - C:\Users\passLion\Desktop\Desktop\Thunder\Program\geturl.htm
O8 - Extra context menu item: 使用迅雷下载全部链接 - C:\Users\passLion\Desktop\Desktop\Thunder\Program\getallurl.htm
O9 - Extra button: ????5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe (file missing)
O9 - Extra 'Tools' menuitem: ????5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - C:\Program Files\Thunder Network\Thunder\Thunder.exe (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) - http://download.eset.com/special/eos/OnlineScanner.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Intel® Alert Service (AlertService) - Intel® Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DQLWinService - Unknown owner - C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PEVSystemStart - Unknown owner - C:\ComFix\PEV.cfxxe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Seagate Scheduler2 Service (SgtSch2Svc) - Seagate - C:\Program Files\Common Files\Seagate\Schedule2\schedul2.exe
O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Windows\System32\STacSV.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 12671 bytes
===================================================

Hope this is enough info to get started.
Thanks in advance!

Here's the combofix from midnight:
Following: the quarantined files list from the first run just in case.


=====================================
ComboFix 10-10-18.03 - passLion 10/19/2010 0:05.3.2 - x86 MINIMAL
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.2046.1172 [GMT -7:00]
Running from: c:\users\passLion\Desktop\ComFix.exe
AV: AVG Anti-Virus Network Edition *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
SP: AVG Anti-Virus Network Edition *enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2010-09-19 to 2010-10-19 )))))))))))))))))))))))))))))))
.

2010-10-19 07:17 . 2010-10-19 07:19 -------- d-----w- c:\users\passLion\AppData\Local\temp
2010-10-19 07:17 . 2010-10-19 07:17 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Local\temp
2010-10-19 07:17 . 2010-10-19 07:17 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-10-19 07:17 . 2010-10-19 07:17 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-10-19 06:59 . 2010-10-19 07:00 -------- d-----w- C:\32788R22FWJFW
2010-10-18 22:31 . 2010-10-18 22:31 -------- d-----w- c:\program files\CCleaner
2010-10-18 10:19 . 2010-10-18 10:19 -------- d-----w- c:\users\passLion\AppData\Roaming\NVIDIA
2010-10-17 11:35 . 2010-10-17 11:35 -------- d-----w- c:\users\passLion\AppData\Local\2K Games
2010-10-17 11:12 . 2010-10-19 06:30 -------- d-----w- c:\users\passLion\AppData\Roaming\Google Chrome Backup
2010-10-17 11:12 . 2010-10-17 11:12 -------- d-----w- c:\program files\Google Chrome Backup
2010-10-17 11:10 . 2010-10-17 11:10 388096 ----a-r- c:\users\passLion\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-16 21:50 . 2010-10-18 06:45 -------- d-----w- c:\windows\system32\MpEngineStore
2010-10-16 11:24 . 2010-10-16 11:24 70144 --sha-r- c:\windows\system32\jscriptd.dll
2010-10-16 11:24 . 2010-10-18 07:58 -------- d-----w- c:\programdata\Update
2010-10-16 11:23 . 2010-10-16 11:23 -------- d-----w- c:\program files\2K Games
2010-10-16 01:10 . 2008-10-15 13:22 452440 ----a-w- c:\windows\system32\d3dx10_40.dll
2010-10-16 01:10 . 2008-10-15 13:22 2036576 ----a-w- c:\windows\system32\D3DCompiler_40.dll
2010-10-16 01:10 . 2008-10-15 13:22 4379984 ----a-w- c:\windows\system32\D3DX9_40.dll
2010-10-16 01:07 . 2010-10-16 01:07 -------- d-----w- c:\program files\Ubisoft
2010-10-16 00:57 . 2010-09-09 22:52 6084944 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{FDF9FAB8-C650-4B94-8477-C15F6EE4869C}\mpengine.dll
2010-10-16 00:44 . 2010-03-04 03:57 190976 ----a-w- c:\windows\system32\drivers\ks.sys
2010-10-16 00:43 . 2010-06-19 06:15 2048 ----a-w- c:\windows\system32\tzres.dll
2010-10-16 00:43 . 2010-08-21 05:36 224256 ----a-w- c:\windows\system32\schannel.dll
2010-10-16 00:43 . 2010-09-01 04:26 164864 ----a-w- c:\program files\Windows Media Player\wmplayer.exe
2010-10-16 00:43 . 2010-09-01 04:23 12625408 ----a-w- c:\windows\system32\wmploc.DLL
2010-10-16 00:39 . 2010-08-26 04:39 109056 ----a-w- c:\windows\system32\t2embed.dll
2010-10-16 00:38 . 2010-05-05 06:46 363520 ----a-w- c:\windows\system32\StructuredQuery.dll
2010-10-16 00:38 . 2010-08-27 05:30 13312 ----a-w- c:\program files\Internet Explorer\iecompat.dll
2010-10-15 06:10 . 2010-10-15 06:10 -------- d-----w- c:\users\passLion\AppData\Roaming\FreeArc
2010-10-15 06:09 . 2010-10-15 06:09 -------- d-----w- c:\program files\FreeArc
2010-10-13 07:07 . 2010-10-13 07:07 -------- d-----w- c:\users\passLion\AppData\Local\Jaksta_Pty_Ltd
2010-10-13 07:03 . 2010-10-13 07:07 -------- d-----w- c:\users\passLion\AppData\Roaming\Replay Media Catcher 4
2010-10-13 07:02 . 2010-10-13 07:04 -------- d-----w- c:\program files\Replay Media Catcher 4
2010-10-11 21:12 . 2010-10-11 21:12 -------- d-----w- c:\programdata\Seagate
2010-10-11 21:12 . 2010-10-11 21:12 44384 ----a-w- c:\windows\system32\drivers\tifsfilt.sys
2010-10-11 21:12 . 2010-10-11 21:12 441760 ----a-w- c:\windows\system32\drivers\timntr.sys
2010-10-11 21:11 . 2010-10-11 21:11 132224 ----a-w- c:\windows\system32\drivers\snapman.sys
2010-10-11 21:11 . 2010-10-11 21:11 368480 ----a-w- c:\windows\system32\drivers\tdrpman.sys
2010-10-11 21:11 . 2010-10-11 21:22 -------- d-----w- c:\program files\Seagate
2010-10-11 21:11 . 2010-10-11 21:11 -------- d-----w- c:\program files\Common Files\Seagate
2010-10-07 03:15 . 2010-10-07 03:15 -------- d-----w- c:\program files\iPod
2010-10-07 03:14 . 2010-10-07 03:15 -------- d-----w- c:\program files\iTunes
2010-10-02 08:00 . 2010-10-02 08:00 -------- d-----w- c:\program files\Common Files\Skype
2010-10-01 09:15 . 2009-02-18 17:41 127058 ----a-w- c:\windows\system32\mncmpeg4.dll
2010-10-01 09:15 . 2008-10-21 16:49 127044 ----a-w- c:\windows\system32\mnmpeg4.dll
2010-10-01 09:15 . 2005-10-29 01:15 53248 ----a-w- c:\windows\system32\txsadp32.acm
2010-09-30 04:21 . 2010-10-04 09:52 -------- d-----w- c:\users\passLion\AppData\Roaming\ooVoo Details
2010-09-30 04:20 . 2010-09-30 04:20 -------- d-----w- c:\program files\ooVoo
2010-09-23 21:42 . 2010-09-23 21:42 95672 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2010-09-20 23:08 . 2010-09-20 23:08 -------- d-----w- c:\program files\Apple Software Update
2010-09-19 10:23 . 2010-08-21 05:32 316928 ----a-w- c:\windows\system32\spoolsv.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-08 07:44 . 2007-07-06 04:19 67688 ----a-w- c:\program files\mozilla firefox\components\jar50.dll
2009-04-08 07:44 . 2007-07-06 04:19 54368 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll
2009-04-08 07:44 . 2007-07-06 04:19 34944 ----a-w- c:\program files\mozilla firefox\components\myspell.dll
2009-04-08 07:44 . 2007-07-06 04:19 46712 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll
2009-04-08 07:44 . 2007-07-06 04:19 172136 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll
2006-05-03 09:06 163328 --sha-r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 31232 --sha-r- c:\windows\System32\msfDX.dll
2007-12-17 12:43 27648 --sha-w- c:\windows\System32\Smab0.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2009-07-14 144384]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
"RESTART_STICKY_NOTES"="c:\windows\System32\StikyNot.exe" [2009-07-14 354304]
"ooVoo.exe"="c:\program files\ooVoo\oovoo.exe" [2010-08-13 19084472]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2009-11-15 33120]
"Google Update"="c:\users\passLion\AppData\Local\Google\Update\GoogleUpdate.exe" [2010-10-14 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-11-16 151552]
"ledpointer"="CNYHKey.exe" [2006-11-10 5585408]
"MoLed"="ModLEDKey.exe" [2006-11-10 53248]
"Multi-function Keyboard"="GWHotKey.exe" [2000-07-19 70656]
"mumservice"="c:\program files\Motorola\Software Update\mumservice.exe" [2009-05-19 996608]
"NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-07-08 2048352]
"SigmatelSysTrayApp"="sttray.exe" [2007-03-01 303104]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-09-24 40368]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"QuickTime Task"="c:\program files\Ringz Studio\Storm Codec\QTTask.exe" [2010-09-08 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-09-24 421160]
"DiscWizardMonitor.exe"="c:\program files\Seagate\DiscWizard\DiscWizardMonitor.exe" [2009-10-17 1325936]
"AcronisTimounterMonitor"="c:\program files\Seagate\DiscWizard\TimounterMonitor.exe" [2009-10-17 904840]
"Seagate Scheduler2 Service"="c:\program files\Common Files\Seagate\Schedule2\schedhlp.exe" [2009-10-17 136544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

c:\users\passLion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKLM\~\startupfolder\C:^Users^passLion^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GigaTribe.lnk]
path=c:\users\passLion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GigaTribe.lnk
backup=c:\windows\pss\GigaTribe.lnk.Startup
backupExtension=.Startup

[HKLM\~\startupfolder\C:^Users^passLion^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MEMonitor.lnk]
backup=c:\windows\pss\MEMonitor.lnk.Startup
backupExtension=.Startup
path=c:\users\passLion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEMonitor.lnk

[HKLM\~\startupfolder\C:^Users^passLion^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Trillian.lnk]
backup=c:\windows\pss\Trillian.lnk.Startup
backupExtension=.Startup
path=c:\users\passLion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk

[HKLM\~\startupfolder\C:^Users^passLion^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^YouTube Uploader.lnk]
backup=c:\windows\pss\YouTube Uploader.lnk.Startup
backupExtension=.Startup
path=c:\users\passLion\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\YouTube Uploader.lnk

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-09-24 09:10 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LWS]
2010-05-08 01:35 165208 ----a-w- c:\program files\Logitech\LWS\Webcam Software\LWS.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-08-19 01:27 5137648 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-08-08 17:25 1828136 ----a-w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 23:57 153136 ----a-w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-09-08 18:17 421888 ----a-w- c:\program files\Ringz Studio\Storm Codec\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SansaDispatch]
2010-04-28 06:41 79872 ----a-w- c:\users\passLion\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-02-18 18:43 248040 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-12-01 13:40 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
2009-11-13 11:31 247144 ----a-w- c:\program files\TomTom HOME 2\TomTomHOMERunner.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
2009-08-19 01:27 5137648 ----a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\Drivers\avgldx86.sys [2009-08-03 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\System32\Drivers\avgtdix.sys [2009-04-26 108552]
R1 vuzuzlhf;vuzuzlhf;c:\windows\system32\drivers\vuzuzlhf.sys [x]
R2 avg8emc;AVG8 E-mail Scanner;c:\program files\AVG\AVG8\avgemc.exe [2009-08-03 908056]
R2 avg8wd;AVG8 WatchDog;c:\program files\AVG\AVG8\avgwdsvc.exe [2009-08-03 297752]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-10-08 133104]
R2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\system32\DRIVERS\nmsgopro.sys [2006-09-28 28672]
R2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 7424]
R2 SgtSch2Svc;Seagate Scheduler2 Service;c:\program files\Common Files\Seagate\Schedule2\schedul2.exe [2009-10-17 431456]
R2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [2009-11-13 92008]
R3 appliand;Applian Network Service;c:\windows\system32\DRIVERS\appliand.sys [2010-06-24 28256]
R3 appliandMP;appliandMP;c:\windows\system32\DRIVERS\appliand.sys [2010-06-24 28256]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2007-11-06 34064]
R3 PPJoyBus;Parallel Port Joystick Bus Enumerator;c:\windows\system32\DRIVERS\PPJoyBus.sys [2009-11-04 15936]
R3 PPortJoystick;Parallel Port Joystick Device Driver;c:\windows\system32\DRIVERS\PPortJoy.sys [2009-11-04 31808]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-30 1343400]
R3 xcbdaNtscV;ViXS Tuner Card (NTSC) - V;c:\windows\system32\DRIVERS\xcbdaV.sys [2009-07-13 157568]
R4 BOHCI;BOHCI; [x]
R4 BUHCI;BUHCI; [x]
R4 BUSBD;BUSBD; [x]
R4 sptd;sptd;c:\windows\system32\Drivers\sptd.sys [2010-10-15 697328]
S0 AvgRkx86;avgrkx86.sys;c:\windows\System32\Drivers\avgrkx86.sys [2009-04-26 12552]
S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2007-03-08 5504]

.
Contents of the 'Scheduled Tasks' folder

2010-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-08 06:38]

2010-10-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-10-08 06:38]

2010-10-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4061656674-1504037461-3971444157-1001Core.job
- c:\users\passLion\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-19 22:04]

2010-10-19 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4061656674-1504037461-3971444157-1001UA.job
- c:\users\passLion\AppData\Local\Google\Update\GoogleUpdate.exe [2010-10-19 22:04]

2010-10-19 c:\windows\Tasks\User_Feed_Synchronization-{072BAD85-4677-4EE1-B958-48C2D9AEA6D9}.job
- c:\windows\system32\msfeedssync.exe [2010-10-16 04:25]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local;<local>
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/201
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: &Grab video by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/204
IE: Copy to Semagic - c:\program files\Semagic\copy.htm
IE: Do&wnload selected by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/203
IE: Down&load all by Orbit - c:\program files\Orbitdownloader\orbitmxt.dll/202
IE: Download with &Shareaza - c:\program files\Shareaza\RazaWebHook32.dll/3000
IE: Semagic - c:\program files\Semagic\link.htm
IE: 使用迅雷下载 - c:\users\passLion\Desktop\Desktop\Thunder\Program\geturl.htm
IE: 使用迅雷下载全部链接 - c:\users\passLion\Desktop\Desktop\Thunder\Program\getallurl.htm
IE: ?????? - c:\users\passLion\Desktop\Desktop\Thunder\Program\geturl.htm
IE: ?????????? - c:\users\passLion\Desktop\Desktop\Thunder\Program\getallurl.htm
IE: ?????? - c:\program files\Thunder Network\Thunder\Program\GetUrl.htm
IE: ?????????? - c:\program files\Thunder Network\Thunder\Program\GetAllUrl.htm
IE: {{09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - c:\program files\Thunder Network\Thunder\Thunder.exe
Trusted Zone: bluecubesoft.com\chevron
Trusted Zone: chevron.com\businesspoint
Trusted Zone: intuit.com\ttlc
Trusted Zone: turbotax.com
FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

HKLM-RunOnce-<NO NAME> - (no file)



**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x855BE446]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
IoDeviceObjectType -> DumpProcedure -> 0xd46a624f
SecurityProcedure -> 0x83eeacf8
QueryNameProcedure -> 0x83eeae88
user & kernel MBR OK

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-4061656674-1504037461-3971444157-1001\Software\SecuROM\License information*]
"datasecu"=hex:da,b8,96,31,f1,ba,28,50,6e,9c,d5,8b,92,80,1d,5b,7c,3f,40,1f,3a,
4e,ad,d4,46,27,a9,83,dc,9b,f2,b3,f4,f4,9f,c4,ed,a2,b5,9f,3e,ea,ca,61,78,52,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CakewalkPlugIns\/*]
"Description"="Cakewal"
"HelpFilePath"=""
"HelpFileTopic"=""

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'lsass.exe'(732)
c:\windows\system32\relog_ap.DLL
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\conhost.exe
.
**************************************************************************
.
Completion time: 2010-10-19 00:25:14 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-19 07:25
ComboFix2.txt 2010-10-19 03:58

Pre-Run: 20,355,751,936 bytes free
Post-Run: 20,297,334,784 bytes free

- - End Of File - - C28C4C06BE0617BD717F911D5338BF09
=====================================================



=======================================================

2010-10-19 07:17:08 . 2010-10-19 07:17:08 107,162 ----a-w- C:\Qoobox\Quarantine\C\Users\passLion\Documents\_My downloads_.zip
2010-10-19 03:57:20 . 2010-10-19 03:57:20 874 ----a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-WinampAgent.reg.dat
2010-10-19 03:57:19 . 2010-10-19 03:57:19 880 ----a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-MySpaceIM.reg.dat
2010-10-19 03:57:18 . 2010-10-19 03:57:18 958 ----a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-Google Update.reg.dat
2010-10-19 02:40:21 . 2010-10-19 02:40:58 3,880,194 ----a-w- C:\Qoobox\Quarantine\C\123.exe.vir
2010-10-16 11:24:35 . 2010-10-19 03:27:38 252 ----a-w- C:\Qoobox\Quarantine\C\Windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job.vir
2008-12-17 08:03:21 . 2003-06-14 01:23:00 4,304 ----a-w- C:\Qoobox\Quarantine\C\Windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb.vir
2008-09-24 06:54:31 . 2008-09-24 06:54:38 1,658 ----a-w- C:\Qoobox\Quarantine\C\Windows\ST6UNST.000.vir
2008-09-12 04:54:39 . 2008-09-12 04:54:39 156 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKU-Default-Run-MsnMsgr.reg.dat
2008-09-12 04:54:39 . 2008-09-12 04:54:39 157 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SBC_McciTrayApp.reg.dat
2008-09-12 04:54:36 . 2008-09-12 04:54:36 169 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-SRS Audio Sandbox.reg.dat
2008-09-12 04:43:24 . 2010-10-19 07:17:08 952 ----a-w- C:\Qoobox\Quarantine\catchme.log
2008-09-12 04:42:50 . 2008-09-12 04:42:50 984 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_srosa.reg.dat
2008-09-12 04:42:37 . 2010-10-19 07:15:35 5,684 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2008-09-04 07:46:24 . 2008-09-06 03:21:47 2,290 ----a-w- C:\Qoobox\Quarantine\C\Users\passLion\AppData\Roaming\Microsoft\Windows\Cookies\passlion@nicovideo[1].txt.vir
2008-06-02 02:11:40 . 2008-06-02 02:11:42 14,966 ----a-w- C:\Qoobox\Quarantine\C\Windows\System32\ban_list.txt.vir
2007-07-19 17:46:02 . 2007-07-19 17:46:02 34,494 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Outerinfo\outerinfo.ico.vir
=====================================================

EDIT: Posts merged ~BP

Edited by Budapest, 21 October 2010 - 04:08 PM.


BC AdBot (Login to Remove)

 


#2 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 PM

Posted 28 October 2010 - 05:29 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine.

If you have not done so, include a clear description of the problems you're having, along with any steps you may have performed so far.

Please refrain from running tools or applying updates other than those we suggest while we are cleaning up your computer. The reason for this is so we know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process. Please also continue to work with me until I give you the all clear. Even if your computer appears to act better, you may still be infected.

Even if you have already provided information about your PC, we need a new log to see what has changed since you originally posted your problem.

Once we start working together, please reply back within 3 days or this thread may be closed so we can help others who are waiting.

We need to create an OTL report,
  • Please download OTL from this link.
  • Save it to your desktop.
  • Double click on the Posted Image icon on your desktop.
  • Click the "Scan All Users" checkbox.
  • Under the Custom Scan box paste this in:

    netsvcs
    msconfig
    drivers32 /all
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\system32\*.sys /90
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\System32\config\*.sav
    %SYSTEMDRIVE%\*.*
    %systemroot%\system32\Spool\prtprocs\w32x86\*.dll
    %systemroot%\*. /mp /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    CREATERESTOREPOINT

  • Click the Quick Scan button.
  • The scan should take a few minutes.
  • Please copy and paste both logs in your reply.

We also need a new log from the GMER anti-rootkit scanner. Please first disable any CD emulation programs using the steps found in this topic:

Why we request you disable CD Emulation when receiving Malware Removal Advice

Then create another GMER log and post it as an attachment to the reply where you post your new OTL log. Instructions on how to properly create a GMER log can be found here:

How to create a GMER log


In your reply, please post both OTL logs and the GMER log.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 


#3 etavares

etavares

    Bleepin' Remover


  • Malware Response Team
  • 15,514 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:18 PM

Posted 02 November 2010 - 06:00 PM

Due to the lack of feedback, this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.


If I don't respond within 2 days, please feel free to PM me.
Please don't ask for help via PM. The forums are there for a reason. Please post in the forums so others may benefit as well.

Posted Image
Unified Network of Instructors and Trusted Eliminators
 





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users