Page 3 of 8 FirstFirst 1234567 ... LastLast
Results 21 to 30 of 73

Thread: Internet Redirect - iexplorer - shutting down select programs - help?

  1. #21
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    I don't think ComboFix update caused the issue there. Since those recovery steps didn't work I'm afraid there's no other possibility left than reformat. You could try to attach the drive to other system as slave drive to backup pictures, music and videos.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  2. #22
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default

    Thanks for your assistance with this attempt. Please post your standard advise on proper protective configuration so I will have it for when I complete a new Windows installation.

    Also - I'm fortunate to have multiple drives connected to the computer with many of my important files residing off the c drive. What procedure should I follow to make sure the malware isn't hiding in any of those files once I begin rebuilding?

  3. #23
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Please, find below some tips to keep system safer in future:

    UPDATING WINDOWS AND INTERNET EXPLORER

    IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.

    If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.


    Make your Internet Explorer more secure

    This can be done by following these simple instructions:
    From within Internet Explorer click on the Tools menu and then click on Options.
    Click once on the Security tab
    Click once on the Internet icon so it becomes highlighted.
    Click once on the Custom Level button.
    Change the Download signed ActiveX controls to Prompt
    Change the Download unsigned ActiveX controls to Disable
    Change the Initialize and script ActiveX controls not marked as safe to Disable
    Change the Installation of desktop items to Prompt
    Change the Launching programs and files in an IFRAME to Prompt
    Change the Navigate sub-frames across different domains to Prompt
    When all these settings have been made, click on the OK button.
    If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.



    The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.

    • Download Adaware
      Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial
      The program is available for download here
    • Download Spybot
      Spybot is a scanner like adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and pretection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
      To see how to set this up as well as more spybot features, see here
      Spybot can be downloaded at this location
    • hosts file:
      • Every version of windows has a hosts file as part of them.
      • In a very basic sense, they are used to locate webpages.
      • We can customize a hosts file so that it blocks certain webpages.
      • However, it can slow down certain computers.
      • This is why using a hosts file is optional!!

      Download it here. Make sure you read the instructions on how to install the hosts file. There is a good tutorial here
      If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
      1. Click the start button (at the lower left hand corner of your screen)
      2. Click run
      3. In the dialog box, type services.msc
      4. hit enter, then locate dns client
      5. Highlight it, then double-click it.
      6. On the dropdown box, change the setting from automatic to manual.
      7. Click ok

    • Get Anti Virus Software and keep it updated - Most AVs will update automatically, but if not I would recommend making updating the AV the first job every time the PC is connected to the internet. An AV that is using defs that are seven days old is not going to be much protection. If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out. Good free antivirus programs are:
      Antivir
      Avast!
    • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
      If you don't have a 3rd party firewall or a router behind NAT then I recommend getting one. I recommend either Online Armor Free or Comodo Firewall Pro (If you choose Comodo: Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and install firewall ONLY!).



    Just a final reminder for you. I am trying to stress these two points.
    UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
    Make sure all of your security programs are up to date.
    Run the spybot and adaware regularly. (Once or twice a week minimum.)
    Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.



    What procedure should I follow to make sure the malware isn't hiding in any of those files once I begin rebuilding?
    You should scan your other drives with antivirus scanner. Also, running an online scan (with Kaspersky Online Scanner for example) wouldn't make any harm.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  4. #24
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default Update

    Used recovery panel to restore autobackup by ERUNT from back a little further in time and was able to get Windows to start. Carefully ran instructions to run ComboFix and got the blue screen stop error again. Restored again and skipped the ComboFix step.

    Deleted all old installations of Java and installed the JRE6 Update 13 as instructed.

    Downloaded ATF and cleaned up all temp files.

    The Kaspersky Online Scanner will not run. I get a script error in the bottom left hand corner of IE... when I double click that I get the standard script error window, but with no detail and I have to close the window multiple times to get back to IE7.

    I currently get a single extra copy of iexplorer.exe in the processes Window. If I "end process" that process, it takes longer to come back, but still comes back. AND Microsoft Money still will not run.

    What's my next step? -- a new hjt log follows in the next post.

    Here's the uninstall file:
    123 Free Solitaire
    1Click DVD to Divx Avi 2.12
    2Wire Wireless Client
    AccuChef
    Active Disk
    Actual Checkers 2000 R
    Adaptec EZ-SCSI Standard Edition 5.0
    Adobe After Effects 5.5
    Adobe Atmosphere Player for Acrobat and Adobe Reader
    Adobe Flash Player 10 ActiveX
    Adobe Flash Player Plugin
    Adobe GoLive 6.0
    Adobe Illustrator 10.0.3
    Adobe PageMaker 6.5
    Adobe Photoshop 6.0
    Adobe Photoshop 7.0
    Adobe Reader 7.0.5 Language Support
    Adobe Reader 7.1.0
    Adobe SVG Viewer 3.0
    Adobe Type Manager Deluxe 4.1
    Adobe® Photoshop® Album Starter Edition 3.2
    AniRez
    Apple Mobile Device Support
    Apple Software Update
    ATI Display Driver
    ATI Multimedia Center
    Autodesk DWF Viewer
    AWSPS 4.02
    Beyond TV DVD Burning Foundation
    Beyond TV DVD Burning Foundation
    Calculator Powertoy for Windows XP
    Chessmaster 8000
    Command & Conquer Generals
    Command & Conquer Red Alert 2
    Command & Conquer Tiberian Sun
    Command && Conquer Red Alert 2 - Yuri's Revenge
    Command and ConquerTM Generals Zero Hour
    Cover Art Downloader v1.2
    Critical Update for Windows Media Player 11 (KB959772)
    CuteFTP 5.0 XP
    dBpowerAMP Music Converter
    DesignPro 5.0 Limited Edition
    Desktop Architect
    Dialog Box Assistant 1.01
    DING!
    Director 8 Shockwave Studio
    DirectVobSub (remove only)
    DivX Codec
    DivX Converter
    DivX Player
    DivX Web Player
    Doppler 10 Pinpoint Alert
    DR-92 Manager
    Elecard MPEG Player
    Empire Earth
    Enable S3 for USB Device
    ERUNT 1.1j
    Eudora
    FastTrak RAID controller utility
    FontLook
    getPlus(R) for Adobe
    GetRight
    GoldLeo DVD Ripper 2.2
    Hauppauge WinTV Scheduler
    Hauppauge WinTV2000
    Hauppauge WinTV-PVR 150 Drivers
    Hello (remove only)
    HijackThis 2.0.2
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    hp deskjet 840c series
    hp deskjet 840c series (Remove only)
    HTMLPad 2004 Pro v5.0
    HyperCD
    ICQ
    IKEA HomePlanner Kitchen
    InterVideo FilterSDK for Hauppauge
    Iomega App Services
    IomegaWare
    iSofter DVD Ripper Platinum 3.0.2007.228
    iTunes
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment Standard Edition v1.3.1
    Java 2 Runtime Environment, SE v1.4.2_06
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    JMail
    LiveUpdate 2.5 (Symantec Corporation)
    Logitech Desktop Messenger
    Logitech MouseWare 9.41 .1
    Macromedia Dreamweaver 4
    Macromedia Extension Manager
    Macromedia Flash 5
    Macromedia FreeHand 9
    Macromedia Generator 2
    Macromedia Shockwave Player
    Malwarebytes' Anti-Malware
    Media Cleaner Pro
    Media Library Management Wizard
    microKORG SoundEditor
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 1
    Microsoft .NET Framework 3.0
    Microsoft .NET Framework 3.0
    Microsoft Age of Empires II
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Data Access Components KB870669
    Microsoft Interactive CD Sampler
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft Money Plus
    Microsoft Money Shared Libraries
    Microsoft National Language Support Downlevel APIs
    Microsoft Office XP Professional with FrontPage
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Windows Media Video 9 VCM
    Microsoft Windows XP Video Decoder Checkup Utility
    Microsoft Word 97 Time Mgmt Wizard Pack (Remove only)
    Movavi Video Converter 6
    Movie Maker Background Music Files
    Movie Maker Sound Effects
    Movie Maker Title Images
    Mozilla Firefox (2.0.0.8)
    MSN Entertainment Download Troubleshooter
    MSN Music Assistant
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6.0 Parser (KB933579)
    Multimedia Card Reader
    Musicmatch® Jukebox
    Musicnotes Player V1.23.1 and Viewer
    MySQL Connector/ODBC 3.51
    Myst IV - Revelation
    nanoPEG-Editor 2.2 Hauppauge Edition
    Napster
    NEC-Mitsubishi NaViSet
    NetAccountability
    Netflix Movie Viewer
    Norton Ghost
    NovaBACKUP
    NovaBACKUP
    NVIDIA Drivers
    OpenMG Limited Patch 3.4-04-16-16-01
    OpenMG Secure Module 3.4.01
    Opera 9.10
    Palm Desktop
    Personal Color Viewer 2.0
    Plus! MP3 Audio Converter LE
    PolderbitS Sound Recorder and Editor
    QTam Bitmap to Icon 3.5
    QuickTime
    Ray Dream Studio v5.0
    Real Alternative 1.52 Lite
    REALmagic Hollywood Plus
    Red Alert Windows 95
    Roxio Burn Engine
    Roxio Easy Media Creator 7
    Safari
    SCRABBLE
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953155)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Shockwave
    Sid Meier's Alpha Centauri
    SimCity 3000
    SnapStream Beyond TV 4.6.1
    SnapStream Firefly Mini 1.0.2
    Solid Oak Software WhatsMyDNS 1.8.2.23
    Sonic CinePlayer MPEG Combo Pack
    Sound Blaster PCI128
    Spybot - Search & Destroy
    SuperDVD Player V4.0
    SureThing CD Labeler 4 SE
    Ten Thumbs 4.3
    Ten Thumbs Typing Tutor
    TPP Storage Class Driver
    TrayDay
    TWC Customer Controls
    Tweaki...for Power Users
    Tweakui Powertoy for Windows XP
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    USB 2.0 Host Controller Driver
    Visual C++ 2008 x86 Runtime - (v9.0.30729)
    Visual C++ 2008 x86 Runtime - v9.0.30729.01
    Visual Studio 2005 Redist Package
    VNC Free Edition 4.1.1
    WavePad Uninstall
    Westwood Shared Internet Components
    Windows Communication Foundation
    Windows Genuine Advantage v1.3.0254.0
    Windows Imaging Component
    Windows Media Bonus Pack for Windows XP
    Windows Media Format 11 runtime
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows Media Player 11
    Windows Media Player Playlist Import to Excel Wizard
    Windows Media Player Skin Importer
    Windows Media Player Tray Control
    Windows Presentation Foundation
    Windows Workflow Foundation
    Windows XP Service Pack 3
    WinRAR archiver
    WinZip
    WordPerfect Office 2002
    WordPerfect Office 2002
    Wtcc II
    XviD MPEG-4 Video Codec

  5. #25
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default htj log 5/5

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:50:00 PM, on 5/5/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16791)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
    C:\Program Files\Promise\FastTrak\FtrakSvc.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\PROGRA~1\Iomega\System32\AppServices.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\Program Files\Iomega\AutoDisk\ADService.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\PRISMSVR.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ezSP_Px.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
    C:\Program Files\TrayDay\TrayDay.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - E:\Program Files\GetRight\xx2gr.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\system32\ezSP_Px.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [C2K] C:\WINDOWS\cyb2k.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
    O4 - Startup: TrayDay.lnk = C:\Program Files\TrayDay\TrayDay.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: Logitech Desktop Messenger.lnk = E:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
    O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
    O9 - Extra button: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
    O9 - Extra 'Tools' menuitem: Net2Phone - {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/ (file missing)
    O9 - Extra button: Share in Hello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
    O9 - Extra 'Tools' menuitem: Share in H&ello - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - C:\Program Files\Hello\PicasaCapture.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {16BF42FD-CA0A-4f48-819D-B0343254DD67} - file://C:\Program Files\UpromiseRemindU\System\Temp\upromise_script0.htm (file missing) (HKCU)
    O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/game...ts/y/kt0_x.cab
    O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommo...ad/tgctlcm.cab
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
    O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://gulllake.gospelcom.net/unsecu...iews/ipixx.cab
    O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnotes.com/download/mnviewer.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} (Live365PlayerVIP Class) - http://www.live365.com/players/p365vip.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.co...veX/winrep.cab
    O16 - DPF: {5197842F-0557-48AE-9552-7594F7C98F04} (PWReset Control) - http://www.cybersitter.com/recovery/...swordReset.ocx
    O16 - DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} (Install Class) - http://updates.lifescapeinc.com/inst...l/pinstall.cab
    O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} (MsneDiag Class) - http://entimg.msn.com/client/msnediag3518.cab
    O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://picture.vzw.com/activex/Veriz...oadControl.cab
    O16 - DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C} -
    O16 - DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} (Autodesk DWF Viewer Control) - http://www.autodesk.com/global/dwfvi...iewerSetup.cab
    O16 - DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} (WebResponseAttachments Control) - https://webresponse.one.microsoft.co...X/FileXfer.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - http://us.dl1.yimg.com/download.yaho...tocomplete.cab
    O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - http://support.f-secure.com/ols/fscax.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab
    O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite...ITDetector.cab
    O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax3518.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: Backup Scheduler - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdlerSRVC.exe
    O23 - Service: Promise FastTrak Log Service (FastTrakSvc) - Promise Technology Inc. - C:\Program Files\Promise\FastTrak\FtrakSvc.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NovaStor NovaBACKUP Backup/Copy Engine (NsService) - NovaStor - C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
    O23 - Service: Real time Backup Loader - Unknown owner - C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
    O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
    O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe

    --
    End of file - 11132 bytes

  6. #26
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    I assume that uninstall list was taken before all old Java removes etc. Is that right?

    Start hjt, do a system scan, check (if found):
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Close browsers and fix checked.


    AND Microsoft Money still will not run.
    Can't recall if this was mentioned earlier. Do you get any error message?


    Please try download and run DDS. Post back dds.txt contents.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #27
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default

    Yes - uninstall list was generated before JAVA was removed.

    hjt can not remove:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    The rest of the lines deleted successfully.

    Microsoft Money says:

    Error - Shutting down...
    Money has experienced a problem and cannot continue.
    If you are running low on memory, try closing some programs and running Money again.

    Memory is not an issue so I can't explain the error.

    Here's the DDS log - please note, I uninstalled AVG during this process and wanted to get protection going so this didn't get any worse - so I installed avast.


    DDS (Ver_09-03-16.01) - FAT32x86
    Run by David Wilson at 18:41:18.01 on Wed 05/06/2009
    Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1535.1134 [GMT -4:00]

    AV: avast! antivirus 4.8.1335 [VPS 090506-0] *On-access scanning enabled* (Updated)

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\CBP\DCSchdler.exe
    C:\Program Files\Promise\FastTrak\FtrakSvc.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\NsService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\NovaStor\NovaStor NovaBACKUP\DR\Fsloader.exe
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\WINDOWS\System32\snmp.exe
    C:\Program Files\Iomega\AutoDisk\ADService.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\WINDOWS\system32\PRISMSVR.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ezSP_Px.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
    C:\Program Files\TrayDay\TrayDay.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Documents and Settings\David Wilson\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
    BHO: bho2gr Class: {31ff080d-12a3-439a-a2ef-4ba95a3148e8} - e:\program files\getright\xx2gr.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    TB: Plaxo: {81ca3009-6200-4a6d-93c6-f1e9a6821c7f} -
    TB: {724D43A0-0D85-11D4-9908-00400523E39A} - No File
    TB: {06E58E5E-F8CB-4049-991E-A41C03BD419E} - No File
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [LDM] \Program\BackWeb-8876480.exe
    mRun: [PRISMSVR.EXE] "c:\windows\system32\PRISMSVR.EXE" /APPLY
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    mRun: [nwiz] nwiz.exe /install
    mRun: [ezShieldProtector for Px] c:\windows\system32\ezSP_Px.exe
    mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
    mRun: [C2K] c:\windows\cyb2k.exe
    mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe
    StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\trayday.lnk - c:\program files\trayday\TrayDay.exe
    StartupFolder: c:\docume~1\davidw~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - e:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\2wirew~1.lnk - c:\program files\2wire 802.11g wireless\PRISMCFG.exe
    uPolicies-explorer: NoFavoritesMenu = 1 (0x1)
    dPolicies-explorer: NoFavoritesMenu = 1 (0x1)
    IE: {4B30061A-5B39-11D3-80F8-0090276F843F} - http://www.net2phone.com/
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - {B13B4423-2647-4cfc-A4B3-C7D56CB83487} - c:\program files\hello\PicasaCapture.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: DirectAnimation Java Classes - file://c:\windows\system\dajava.cab
    DPF: Internet Explorer Classes for Java - file://c:\windows\system\iejava.cab
    DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
    DPF: Yahoo! Checkers - hxxp://download.games.yahoo.com/games/clients/y/kt0_x.cab
    DPF: Yahoo! Chess - hxxp://download.yahoo.com/games/clients/y/cr1_x.cab
    DPF: Yahoo! Hearts - hxxp://download.yahoo.com/games/clients/y/hr1_x.cab
    DPF: Yahoo! Pool 2 - hxxp://download.yahoo.com/games/clients/y/por9_x.cab
    DPF: {00000075-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/voxmsdec.CAB
    DPF: {00000160-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/msaudio.cab
    DPF: {01113300-3E00-11D2-8470-0060089874ED} - hxxp://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
    DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/templates/ieawsdc.cab
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} - hxxp://gulllake.gospelcom.net/unsecure/other_media/views/ipixx.cab
    DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} - hxxp://www.musicnotes.com/download/mnviewer.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
    DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files\yahoo!\common\yinsthelper.dll
    DPF: {31564D57-0000-0010-8000-00AA00389B71} - hxxp://codecs.microsoft.com/codecs/i386/wmvax.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {40272BF7-4FF5-4D6F-9BAD-3C1D3CB32982} - hxxp://www.live365.com/players/p365vip.cab
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
    DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
    DPF: {5197842F-0557-48AE-9552-7594F7C98F04} - hxxp://www.cybersitter.com/recovery/ocx/PasswordReset.ocx
    DPF: {6BEA1C48-1850-486C-8F58-C7354BA3165E} - hxxp://updates.lifescapeinc.com/installers/pinstall/pinstall.cab
    DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} - hxxp://entimg.msn.com/client/msnediag3518.cab
    DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} - hxxp://picture.vzw.com/activex/VerizonWirelessUploadControl.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {924C1588-90C3-4910-B6CA-D57A1C0418FE} - hxxp://download.yahoo.com/dl/bookmarks/ybconvfav030408.cab
    DPF: {94B82441-A413-4E43-8422-D49930E69764} - hxxp://rtc.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
    DPF: {9DBAFCCF-592F-FFFF-FFFF-00608CEC297C}
    DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - hxxp://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38079.8121527778
    DPF: {A662DA7E-CCB7-4743-B71A-D817F6D575DF} - hxxp://www.autodesk.com/global/dwfviewer/installer/DwfViewerSetup.cab
    DPF: {A7E092C3-692A-11D0-A7E5-08002B322F3B} - hxxps://webresponse.one.microsoft.com/oas/ActiveX/FileXfer.cab
    DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} - hxxp://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} - hxxp://support.f-secure.com/ols/fscax.cab
    DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.0/jinstall-1_4_0-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
    DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} - hxxp://www.live365.com/players/play365.cab
    DPF: {CEBC955E-58AF-11D2-A30A-00A0C903492B} - hxxp://windowsupdate.microsoft.com/R848/V31Controls/x86/w98/en/actsetup.cab
    DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} - hxxp://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
    DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - hxxp://entimg.msn.com/client/msnmusax3518.cab
    Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    SEH: Eudora's Shell Extension: {edb0e980-90bd-11d4-8599-0008c7d3b6f8} - e:\program files\eudora\EUSHLEXT.DLL

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\davidw~1\applic~1\mozilla\firefox\profiles\5nzx41m4.default\
    FF - prefs.js: browser.search.selectedEngine - Google

    ============= SERVICES / DRIVERS ===============

    R0 amdagp10;AMD IG AGP Bus Filter;c:\windows\system32\drivers\amdagp10.sys [2003-3-25 22994]
    R0 dcsnap;dcsnap;c:\windows\system32\drivers\dcsnap.sys [2008-10-11 77472]
    R0 fasttrak;fasttrak;c:\windows\system32\drivers\Fasttrak.sys [2005-1-14 70656]
    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-5-6 114768]
    R1 Cinemsup;Cinemsup;c:\windows\system32\drivers\cinemsup.sys [2002-7-19 6656]
    R1 DCDisk;DCDisk;c:\windows\system32\drivers\DCDisk.sys [2008-10-11 155648]
    R1 GhPciScan;GhostPciScanner;c:\program files\symantec\norton ghost 2003\GhPciScan.sys [2003-12-17 5632]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-5-6 20560]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast4\ashServ.exe [2009-5-6 138680]
    R2 Iprip;RIP Listener;c:\windows\system32\svchost.exe -k netsvcs [2001-8-23 14336]
    R2 NsService;NovaStor NovaBACKUP Backup/Copy Engine;c:\program files\novastor\novastor novabackup\NsService.exe [2008-6-17 207936]
    R2 Real time Backup Loader;Real time Backup Loader;c:\program files\novastor\novastor novabackup\dr\FsLoader.exe [2008-10-11 93248]
    R3 4mmdat;4mmdat;c:\windows\system32\drivers\4mmdat.sys [2001-8-17 12288]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast4\ashMaiSv.exe [2009-5-6 254040]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast4\ashWebSv.exe [2009-5-6 352920]
    S1 efbDisk;efbDisk; [x]
    S2 Backup Scheduler;Backup Scheduler;c:\program files\novastor\novastor novabackup\dr\cbp\DCSchdlerSRVC.exe [2008-10-11 98304]
    S3 ati2mpaa;ati2mpaa;c:\windows\system32\drivers\ati2mpaa.sys [2002-3-23 281856]
    S3 ATIVRVXX;ATI Rage Theatre Video (ATIRTCAP);c:\windows\system32\drivers\atirtcap.sys [2002-3-23 49920]
    S3 DDCCI;DDC/CI monitor;c:\windows\system32\drivers\Moni2c.sys [2003-3-30 6494]
    S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2008-10-4 33752]
    S3 hcwPVRP2;Hauppauge WinTV PVR PCI II (Encoder);c:\windows\system32\drivers\hcwPVRP2.sys [2005-5-22 814464]
    S3 zremote;zremote;c:\windows\system32\drivers\zremote.sys [2005-5-22 10368]

    =============== Created Last 30 ================

    2009-05-06 00:03 147,100 a---h--- c:\windows\system32\mlfcache.dat
    2009-05-05 22:38 410,984 a------- c:\windows\system32\deploytk.dll
    2009-05-05 22:38 73,728 a------- c:\windows\system32\javacpl.cpl
    2009-05-05 22:27 0 a------- c:\windows\system32\REN33.tmp
    2009-05-05 22:27 0 a------- c:\windows\system32\REN32.tmp
    2009-05-05 22:16 652 a------- c:\windows\system32\snetfil.dll
    2009-05-05 22:16 540 a------- c:\windows\system32\srchfrgn.dll
    2009-05-05 22:16 258 a------- c:\windows\system32\srchout.dll
    2009-05-05 22:16 306 a------- c:\windows\system32\picsfil.dll
    2009-05-05 22:16 194 a------- c:\windows\system32\igefil.dll
    2009-05-05 22:16 116 a------- c:\windows\system32\nfil.dll
    2009-05-05 22:16 34 a------- c:\windows\system32\macfil.dll
    2009-05-05 22:16 18 a------- c:\windows\system32\lastupdate.dll
    2009-05-05 22:16 400 a------- c:\windows\system32\bsnlst.dll
    2009-05-05 22:16 100 a------- c:\windows\system32\bnrfil.dll
    2009-05-05 22:11 2,709 a------- c:\windows\system32\gibbebx.dat
    2009-05-05 22:10 1,024 ----h--- C:\diskfile1
    2009-05-05 22:10 16,384 ----h--- C:\logicinf.bin
    2009-05-05 22:01 60,416 a------- c:\windows\system32\drivers\Combo-Fix.sys
    2009-05-05 21:58 389,120 a------- c:\windows\system32\CF11739.exe
    2009-05-05 21:58 <DIR> --d----- C:\ComboFix
    2009-05-05 21:58 389,120 a------- c:\windows\system32\CF11674.exe
    2009-05-05 21:57 389,120 a------- c:\windows\system32\CF11570.exe
    2009-05-05 21:53 2,709 a------- c:\windows\system32\dllgidoor.dat
    2009-04-23 20:40 389,120 a------- c:\windows\system32\CF18599.exe
    2009-04-23 20:39 389,120 a------- c:\windows\system32\CF18413.exe
    2009-04-22 18:53 <DIR> a-dshr-- C:\cmdcons
    2009-04-22 18:52 161,792 a------- c:\windows\SWREG.exe
    2009-04-22 18:52 98,816 a------- c:\windows\sed.exe
    2009-04-19 18:34 360,021 a------- C:\something.scr
    2009-04-18 00:21 <DIR> --d----- c:\program files\Spybot - Search & Destroy
    2009-04-18 00:21 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2009-04-17 21:04 <DIR> --d----- c:\docume~1\davidw~1\applic~1\Malwarebytes
    2009-04-17 21:04 15,504 a------- c:\windows\system32\drivers\mbam.sys
    2009-04-17 21:04 38,496 a------- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-17 21:04 <DIR> --d----- c:\program files\Malwarebytes' Anti-Malware
    2009-04-17 21:04 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2009-04-17 19:53 66 a------- c:\windows\wininit.ini
    2009-04-17 08:22 <DIR> --d----- C:\!KillBox
    2009-04-16 21:00 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{A21E413E-98CC-4ABB-9843-E6AA4F456F61}
    2009-04-14 09:44 <DIR> --d----- C:\fixwareout
    2009-04-14 09:40 <DIR> --d----- c:\program files\Trend Micro
    2009-04-13 21:09 <DIR> --d----- c:\program files\AVG
    2009-04-13 21:09 <DIR> --d----- c:\docume~1\alluse~1\applic~1\avg8

    ==================== Find3M ====================

    2009-04-22 19:04 5,880 a------- c:\windows\system32\wfileu.drv
    2009-02-09 07:13 1,846,784 -------- c:\windows\system32\win32k.sys
    2009-02-09 07:13 1,846,784 -------- c:\windows\system32\dllcache\win32k.sys
    2008-12-16 19:23 726,008 a------- c:\documents and settings\david wilson\gotomypc_438.exe
    2008-11-06 12:33 726,008 a------- c:\documents and settings\david wilson\gotomypc_437.exe
    2001-11-06 00:23 266 ---sh--- c:\program files\desktop.ini
    2001-11-06 00:23 11,079 ----h--- c:\program files\folder.htt
    2001-01-19 12:04 21,841 a------- c:\program files\common files\tppupd2k.dll
    2001-01-19 11:04 21,329 -------- c:\program files\common files\tppupd98.dll
    2008-10-04 15:44 32,768 a--sh--- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008100420081005\index.dat
    2001-11-13 10:18 8 ---sh--- c:\windows\all users\drm\pdrm.dat

    ============= FINISH: 18:41:57.28 ===============

  8. #28
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    hjt can not remove:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

    The rest of the lines deleted successfully.
    Hi

    Those are not malicious so we can leave them there


    Microsoft Money says:

    Error - Shutting down...
    Money has experienced a problem and cannot continue.
    If you are running low on memory, try closing some programs and running Money again.
    Could you try to reinstall MS Money? It's possible that infection has harmed it.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  9. #29
    Member
    Join Date
    Apr 2009
    Posts
    57

    Default

    New/continued symptoms:

    1. Continued instance of IEXPLORE.EXE process in task manager - even when program is not running.

    2. Executing commands in My Computer window causes Explorer.exe to re-start and triggers the execution of multiple instances of IEXPLORE.EXE. I can not copy and paste or drag files between folders without this happening. (Does windows XP use IEXPLORE to navigate folders??)

    3. When typing in a web address, about half the time I get a white screen with the message (your explorer window is blocking attempts to redirect, please click here). If I don't click, the site I want eventually opens... if I do click, I end up somewhere else.

    4. Uninstalling and then re-installing Money did not fix the problem with that program.

  10. #30
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi

    Let's get some more info and after that run ComboFix again.

    Download GMER and save it your desktop:
    • Extract it to your desktop and double-click GMER.exe
    • Click rootkit-tab and then scan.
    • Don't check
      Show All
      box while scanning in progress!
    • When scanning is ready, click Copy.
    • This copies log to clipboard
    • Post log in your reply.


    Please run ComboFix normally by double clicking it (let it update if asked for a permission). Post back its log & a fresh dds.txt log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •