I've somehow received an unusual virus. I've tried removing it with TrendMicro, Malwarebytes and Spybot, but nothing has worked.I've noticed new popup windows in my Vista toolbar mostly from Internet Explorer (although I never use it) and Mozilla. I haven't noticed any in Chrome.However, even when clicking on a google search result in Chrome, it will open a completely different search engine page instead of the desired link, followed by a new popup window in Internet Explorer.I wish I could at least remove Internet Explorer. Any help?
2/21/2010 11:34:03 PM
sounds like someone's hijacked your TCP stack, if i had to take a guess based on this info.http://free.antivirus.com/hijackthis/runpost report herewe will help
2/21/2010 11:41:11 PM
2/22/2010 3:45:19 PM
2/22/2010 4:14:39 PM
http://www.bleepingcomputer.com/combofix/how-to-use-combofix
2/22/2010 8:23:50 PM
Why didn't you just copy and paste the log file into a new message and save yourself some time?
2/22/2010 10:23:39 PM
yeah, seriously, please just copy and paste it, haha
2/22/2010 11:07:58 PM
what are these?
2/23/2010 10:14:39 AM
combofix if you have a 32-bit OSotherwise, is it similar to what i was experiencing a few weeks back?message_topic.aspx?topic=585361
2/23/2010 11:01:15 AM
VUNDOVIRTUMONDEIf you have it - then I have the 3 fix files. I have only found ONE way to eradicate this.
2/23/2010 2:44:13 PM
HijackThis, for whatever reason, pulled up a blank text file instead of text file with the log report, so I was unable to copy and paste those results.ComboFix seemed to just stop running during its scan, so I never received any log report from it.Using DDS, I was able to copy a paste this log report:DDS (Ver_09-12-01.01) - NTFSx86 Run by Owner at 16:20:52.98 on Tue 02/23/2010Internet Explorer: 8.0.6001.18882Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.2813.1279 [GMT -5:00]AV: Trend Micro AntiVirus *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5}SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}============== Running Processes ===============C:\Windows\system32\wininit.exeC:\Windows\system32\lsm.exeC:\Windows\system32\svchost.exe -k DcomLaunchC:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exeC:\Windows\system32\svchost.exe -k rpcssC:\Windows\system32\Ati2evxx.exeC:\Windows\System32\svchost.exe -k LocalServiceNetworkRestrictedC:\Windows\System32\svchost.exe -k LocalSystemNetworkRestrictedC:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\STacSV.exeC:\Windows\system32\svchost.exe -k GPSvcGroupC:\Windows\system32\SLsvc.exeC:\Windows\system32\svchost.exe -k LocalServiceC:\Windows\system32\Hpservice.exeC:\Windows\system32\svchost.exe -k NetworkServiceC:\Windows\system32\WLANExt.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exe -k LocalServiceNoNetworkC:\Windows\system32\Ati2evxx.exeC:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskeng.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\IDT\WDM\sttray.exeC:\Program Files\HP\QuickPlay\QPService.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exeC:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exeC:\Program Files\HP\HP Software Update\hpwuSchd2.exeC:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exeC:\Program Files\Java\jre1.6.0_05\bin\jusched.exeC:\Program Files\Winamp\winampa.exeC:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exeC:\WINDOWS\ehome\ehtray.exeC:\Users\Owner\AppData\Local\Temp\win16.exeC:\Program Files\Trend Micro\BM\TMBMSRV.exeC:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f691e717\aestsrv.exeC:\Program Files\Spybot - Search & Destroy\TeaTimer.exeC:\Windows\system32\agrsmsvc.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\Program Files\WiFiConnector\NintendoWFCReg.exeC:\Users\Owner\AppData\Local\Autobahn\autobahn.exeC:\Program Files\Microsoft Office\Office12\ONENOTEM.EXEC:\Program Files\Bonjour\mDNSResponder.exeC:\Windows\system32\svchost.exe -k hpdevmgmtC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Windows\System32\svchost.exe -k HPZ12C:\Windows\System32\svchost.exe -k HPZ12C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestrictedC:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exeC:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exeC:\Windows\SMINST\BLService.exeC:\Program Files\CyberLink\Shared Files\RichVideo.exeC:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exeC:\Program Files\Trend Micro\Internet Security\SfCtlCom.exeC:\Windows\system32\svchost.exe -k imgsvcC:\Program Files\Trend Micro\Internet Security\TmProxy.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\Program Files\Webroot\WebrootSecurity\SpySweeper.exeC:\Windows\System32\svchost.exe -k WerSvcGroupC:\Windows\system32\SearchIndexer.exeC:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exeC:\Windows\ehome\ehmsas.exeC:\Program Files\Webroot\WebrootSecurity\SSU.EXEC:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exeC:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exeC:\Windows\System32\alg.exeC:\Windows\system32\wbem\wmiprvse.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exeC:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXEC:\Program Files\Hewlett-Packard\Shared\HpqToaster.exeC:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exeC:\Program Files\HP\Digital Imaging\bin\hpqbam08.exeC:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exec:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exeC:\Windows\system32\wuauclt.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Google\Chrome\Application\chrome.exeC:\Program Files\Google\Chrome\Application\chrome.exeC:\Program Files\Google\Chrome\Application\chrome.exeC:\Program Files\Google\Chrome\Application\chrome.exeC:\Windows\system32\SearchProtocolHost.exeC:\Windows\system32\SearchFilterHost.exeC:\Users\Owner\Documents\Downloads\dds.scrC:\Windows\system32\wbem\wmiprvse.exe
2/23/2010 4:27:58 PM
============== Pseudo HJT Report ===============uStart Page = hxxp://www.google.com/uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnbmStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnbmDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnbuInternet Settings,ProxyOverride = *.localBHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dllBHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dllBHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dllBHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_05\bin\ssv.dllBHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dllBHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dllTB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dllTB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dlluRun: [Sidebar] "c:\program files\windows sidebar\sidebar.exe" /autoRunuRun: [WindowsWelcomeCenter] "rundll32.exe" oobefldr.dll,ShowWelcomeCenteruRun: [LightScribe Control Panel] "c:\program files\common files\lightscribe\LightScribeControlPanel.exe" -hiddenuRun: [ehTray.exe] "c:\windows\ehome\ehTray.exe"uRun: [uishf9wuifwuh387fh3wufinhjfdwefe] "c:\users\owner\appdata\local\temp\ub81r5eabf.exe"uRun: [asg984jgkfmgasi8ug98jgkfgfb] c:\users\owner\appdata\local\temp\win16.exeuRun: [Fnudumegede] rundll32.exe "c:\users\owner\appdata\local\ijurediqa.dll",StartupuRun: [kugazegag] Rundll32.exe "c:\progra~2\sojenatu\sojenatu.dll",auRun: [SpybotSD TeaTimer] "c:\program files\spybot - search & destroy\TeaTimer.exe"mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe"mRun: [SynTPEnh] "c:\program files\synaptics\syntp\SynTPEnh.exe"mRun: [SysTrayApp] "%ProgramFiles%\IDT\WDM\sttray.exe"mRun: [UCam_Menu] "c:\program files\cyberlink\youcam\muitransfer\muistartmenu.exe" "c:\program files\cyberlink\youcam" update "software\cyberlink\youcam\2.0"mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe"mRun: [Windows Defender] "%ProgramFiles%\Windows Defender\MSASCui.exe" -hidemRun: [QlbCtrl.exe] "c:\program files\hewlett-packard\hp quick launch buttons\QlbCtrl.exe" /StartmRun: [OnScreenDisplay] "c:\program files\hewlett-packard\hp quicktouch\HPKBDAPP.exe"mRun: [hpqSRMon] "c:\program files\hp\digital imaging\bin\hpqSRMon.exe"mRun: [HP Health Check Scheduler] "c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe"mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"mRun: [hpWirelessAssistant] "c:\program files\hewlett-packard\hp wireless assistant\HPWAMain.exe"mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_05\bin\jusched.exe"mRun: [WinampAgent] "c:\program files\winamp\winampa.exe"mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe"mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottimemRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscriptmRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintrayStartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\autobahn.lnk - c:\users\owner\appdata\local\autobahn\autobahn.exeStartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXEStartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exeStartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\runreg~1.lnk - c:\program files\wificonnector\NintendoWFCReg.exemPolicies-system: EnableUIADesktopToggle = 0 (0x0)IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_05\bin\ssv.dllIE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dllIE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLLIE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - c:\program files\hp\digital imaging\smart web printing\hpswp_BHO.dllIE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dllDPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cabDPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cabDPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cabmASetup: {10880D85-AAD9-4558-ABDC-2AB1552D831F} - "c:\program files\common files\lightscribe\LSRunOnce.exe"
2/23/2010 4:28:23 PM
================= FIREFOX ===================FF - ProfilePath - c:\users\owner\appdata\roaming\mozilla\firefox\profiles\7u7qk0t5.default\FF - prefs.js: browser.search.selectedEngine - Ask.comFF - prefs.js: browser.startup.homepage - http://www.google.comFF - prefs.js: keyword.URL - hxxp://supertoolbar.ask.com/redirect?client=ff&src=kw&tb=WBR&o=13993&locale=en_US&q=FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dllFF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dllFF - plugin: c:\program files\mozilla firefox\plugins\npwachk.dllFF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dllFF - plugin: c:\users\owner\appdata\roaming\move networks\plugins\npqmp071503000010.dllFF - plugin: c:\users\owner\appdata\roaming\move networks\plugins\npqmp071701000002.dllFF - plugin: c:\users\owner\appdata\roaming\move networks\plugins\npqmp071705000014.dllFF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\---- FIREFOX POLICIES ----c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);============= SERVICES / DRIVERS ===============R0 Amddfltr;Amd Disk Lower Filter Driver;c:\windows\system32\drivers\Amddfltr.sys [2009-5-31 15416]R3 enecir;ENE CIR Receiver;c:\windows\system32\drivers\enecir.sys [2008-1-23 52736]=============== Created Last 30 ================2010-02-23 02:30:45 0 d-s---w- C:\ComboFix2010-02-23 01:49:13 77312 ----a-w- c:\windows\MBR.exe2010-02-23 01:49:13 261632 ----a-w- c:\windows\PEV.exe2010-02-23 01:49:12 98816 ----a-w- c:\windows\sed.exe2010-02-23 01:49:12 161792 ----a-w- c:\windows\SWREG.exe2010-02-22 05:19:37 0 d-----w- c:\program files\TrendMicro2010-02-21 05:19:10 0 d-----w- c:\programdata\Spybot - Search & Destroy2010-02-21 05:19:10 0 d-----w- c:\program files\Spybot - Search & Destroy2010-02-18 04:41:28 10752 ----a-w- c:\windows\DCEBoot.exe2010-02-18 00:06:22 0 d-----w- c:\programdata\sojenatu2010-02-18 00:06:21 0 d-----w- c:\programdata\wawuhana2010-02-18 00:06:21 0 d-----w- c:\programdata\nosamoti2010-02-17 23:56:25 0 d-----w- c:\programdata\pupepiba2010-02-17 23:56:25 0 d-----w- c:\programdata\malevinu2010-02-17 23:56:25 0 d-----w- c:\programdata\duyotilu2010-02-10 14:28:07 98304 ----a-w- c:\windows\system32\drivers\srvnet.sys2010-02-10 14:28:07 301568 ----a-w- c:\windows\system32\drivers\srv.sys2010-02-10 14:28:04 3597912 ----a-w- c:\windows\system32\ntkrnlpa.exe2010-02-10 14:28:03 3546200 ----a-w- c:\windows\system32\ntoskrnl.exe2010-02-06 04:03:15 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll2010-02-06 04:03:14 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll2010-02-06 04:01:55 0 d-----w- c:\program files\Winamp Detect2010-01-27 03:04:54 72704 ----a-w- c:\windows\system32\admparse.dll2010-01-26 04:14:48 0 d-----w- c:\program files\GPL MPEG Decoder==================== Find3M ====================2010-02-21 04:40:49 2768 ----a-w- c:\users\owner\appdata\roaming\wklnhst.dat2010-01-02 06:38:20 916480 ----a-w- c:\windows\system32\wininet.dll2010-01-02 06:32:33 71680 ----a-w- c:\windows\system32\iesetup.dll2010-01-02 06:32:33 109056 ----a-w- c:\windows\system32\iesysprep.dll2010-01-02 04:57:00 133632 ----a-w- c:\windows\system32\ieUnatt.exe2009-12-28 12:35:50 11776 ----a-w- c:\windows\system32\tsbyuv.dll2009-12-28 12:35:00 1314816 ----a-w- c:\windows\system32\quartz.dll2009-12-28 12:32:34 22528 ----a-w- c:\windows\system32\msyuv.dll2009-12-28 12:32:32 31744 ----a-w- c:\windows\system32\msvidc32.dll2009-12-28 12:32:32 123904 ----a-w- c:\windows\system32\msvfw32.dll2009-12-28 12:32:25 13312 ----a-w- c:\windows\system32\msrle32.dll2009-12-28 12:31:22 82944 ----a-w- c:\windows\system32\mciavi32.dll2009-12-28 12:31:01 50176 ----a-w- c:\windows\system32\iyuv_32.dll2009-12-28 12:28:43 91136 ----a-w- c:\windows\system32\avifil32.dll2009-12-28 12:28:43 65024 ----a-w- c:\windows\system32\avicap32.dll2009-12-28 05:48:49 51200 ----a-w- c:\windows\inf\infpub.dat2009-12-28 05:48:49 143360 ----a-w- c:\windows\inf\infstrng.dat2009-12-28 05:48:43 86016 ----a-w- c:\windows\inf\infstor.dat2009-06-02 07:28:23 665600 ----a-w- c:\windows\inf\drvindex.dat2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat============= FINISH: 16:25:42.69 ===============
2/23/2010 4:28:47 PM