Possible virus?

By Zachareye
Sep 12, 2010
  1. Symptoms:
    1) Firefox and Google Crome are not loading paiges that the once had (e.g. despite trying to update the website plugin and even java plugin.
    2) Google Crome will open random tabs when trying to open a link (not related to anything), sometimes will redirect me from sites like pandora saying the site can be a virus and harmful (when not even at the computer)
    3) Malwarebytes Anti-Malware and SuperAntispyware will not update adjusting firewall settings to allow access and even disabling Norton.
    4) Media Center for the internet tv will give me to box to check to agree, then I click the install button and nothing happens

    What I have tried:
    1) Scan with Norton 2010
    2) Scan with Avast Free
    3) Scan with Malwarebytes Anti-Malware (not up-to date)
    4) Scan with SuperAntiSpyware (not up-to date)
    All of which have not fixed the problems described.

    I have attached HJT Log

    I am running Windows 7 Home Premium 64bit OS

    Please let me know you suggestions?

    Attached Files:

  Zachareye

    Wow, guess it's been a while since I have had any problem, will do.

    Thank you
  Zachareye

    Okay, so step 1 done. step 2 done. step 3 would not update (even with firewall disabled) and when i ran the scan anyway it ended up crashing my system and reboot. step 4 skiped because i have windows 7 64 bit. step 5 is attached.

    Attached Files:

    Download MBRCheck to your desktop

    Double click MBRCheck.exe to run (Vista and Windows 7 users, right click and select Run as Administrator).
    It will show a black screen with some data on it.
    Enter N to exit.
    A report called MBRcheckxxxx.txt will be on your desktop
    Open this report and post its content in your next reply.


    Download OTL to your Desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Under the Custom Scan box paste this in:

    %systemroot%\*. /mp /s
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %PROGRAMFILES%\Common Files\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %USERPROFILE%\Favorites\*.url /x
    %ALLUSERSPROFILE%\*.dat /x
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %systemroot%\pchealth\helpctr\System\*.exe /s
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
    Part 1 the MBRCheck:
    And the second step crashed and rebooted my system twice
    Not the best choice, but try to run OTL from Safe Mode.
    OTL results in Safemode w/out customer scan, because I couldn't get online to copy and past, but i will boot again in safemode and save the customer scan on my notepad so I can run again too: Text was too long so i have attached it

    Attached Files:

    • OTL.Txt
      File size:
      151.2 KB
    So for some reason I have been unable to f8 into safemode but I am given the option after the system crashes, so I ran the OTL scan again with the custom information included with the intention of crashing my system, this time I decided to disable my virus/firewall protection and it ran without crashing (might be useful for other having similar problems).

    Attached Files:

    I can see two AV programs running, Avast and Norton.
    One of them has to go.
    If Norton, make sure to use Norton Removal Tool:
    If Norton goes, make sure to turn Windows firewall ON.


    Uninstall, known adware.


    Update your Java version here:

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java version and its remnants...

    Download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.


    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      PRC - [2010/09/08 19:40:30 | 000,057,616 | ---- | M] () -- C:\ProgramData\ZwankySearch\zwankysearch149.exe
      PRC - [2010/09/08 19:40:30 | 000,057,616 | ---- | M] () -- C:\Program Files (x86)\ZwankySearch\zwankysearch.exe
      MOD - [2010/09/08 19:41:06 | 000,577,536 | ---- | M] () -- C:\Program Files (x86)\ZwankySearch\zwankysearch.dll
      SRV - [2010/09/08 19:40:30 | 000,057,616 | ---- | M] () [Auto | Running] -- C:\ProgramData\ZwankySearch\zwankysearch149.exe -- (ZwankySearch Service)
      [2010/09/08 21:49:06 | 000,000,000 | ---D | M] (ZwankySearch) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{5F321A53-3F65-45F2-9903-587E3CA15404}
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
      O4 - HKCU..\Run: [RemoteControl] File not found
      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer =,
      O18:64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
      O18:64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
      O18:64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
      O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
      O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
      [2 C:\Users\Zachareye\*.tmp files -> C:\Users\Zachareye\*.tmp -> ]
      [2010/03/13 13:30:28 | 000,000,088 | RHS- | C] () -- C:\ProgramData\464B05520D.sys
      @Alternate Data Stream - 76 bytes -> C:\Users\Zachareye\Documents\hells choirs the song movie_0001.wmv:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\Zachareye\Documents\billing_315664045_4b63051fe9445.txt:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\Zachareye\Documents\015.JPG:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\Zachareye\Documents\007 (2).JPG:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\Zachareye\Documents\006 (2).JPG:Roxio EMC Stream
      @Alternate Data Stream - 76 bytes -> C:\Users\Zachareye\Documents\004.JPG:Roxio EMC Stream
      @Alternate Data Stream - 1161 bytes -> C:\Users\Zachareye\AppData\Local\Temp:XO3mxP5FCFJ7Hb7Gti27k
      @Alternate Data Stream - 1146 bytes -> C:\ProgramData\Microsoft:gpGsYheuPiHZzNpBhxrFcB
      @Alternate Data Stream - 1111 bytes -> C:\Users\Zachareye\AppData\Local\Temp:uJ3rYPnJDKxkets5e6tPD1iRPU
      @Alternate Data Stream - 1110 bytes -> C:\Users\Zachareye\AppData\Local\Temp:71bKPnAsXDylFi1I2iW0x6k9
      @Alternate Data Stream - 1079 bytes -> C:\ProgramData\Microsoft:uGPTw8s383GO1QncBySMV6UuyReE2
      @Alternate Data Stream - 1014 bytes -> C:\Users\Zachareye\AppData\Local\BmMRwwWJgvC:oz0qeERBVTxx15Uurziwc
      C:\Program Files (x86)\ZwankySearch
      ipconfig /flushdns /c
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.
    • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
    All done and both logs are attached

    Attached Files:

    Run OTL
    • Under the Custom Scans/Fixes box at the bottom, paste in the following

      IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\\GenericAskToolbar.dll File not found
      FF - prefs.js..extensions.enabledItems:
      [2010/09/12 10:15:15 | 000,002,555 | ---- | M] () -- C:\Users\Zachareye\AppData\Roaming\Mozilla\Firefox\Profiles\z474j2fa.default\searchplugins\askcom.xml
      O2 - BHO: (ZiggyTV Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\\GenericAskToolbar.dll File not found
      O3 - HKLM\..\Toolbar: (ZiggyTV Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\\GenericAskToolbar.dll File not found
      O3 - HKCU\..\Toolbar\WebBrowser: (ZiggyTV Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\\GenericAskToolbar.dll File not found
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.


    Last scans....

    1. Download Security Check from HERE, and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    2. Download Temp File Cleaner (TFC)
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    3. Go to Kaspersky website and perform an online antivirus scan.

    • Disable your active antivirus program.
    • Read through the requirements and privacy statement and click on Accept button.
    • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    • When the downloads have finished, click on Settings.
    • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
      • Archives
      • Mail databases
    • Click on My Computer under Scan.
    • Once the scan is complete, it will display the results. Click on View Scan Report.
    • You will see a list of infected items there. Click on Save Report As....
    • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
    Here are two of the three attachments, with the Kaspersky online scanner I ran into problems with all three browsers, crome tells me I don't meet the requirements, IE and Firefox tell me the following:

    Update has failed The program could not be started. Please close the window of Kaspersky Online Scanner 7.0 and start the program again from the web site of Kaspersky Lab.

    Successful updating of Kaspersky Online Scanner 7.0 and scanning of your computer requires uninterrupted Internet connection. Please make sure that the Internet connection is established. [ERROR: Connection to updates source cannot be established]

    I have disable Norton and tried several attempts with no other windows open at all, so I am not sure what to do from here.

    Attached Files:

    Instead of Kaspersky...

    Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • IMPORTANT! UN-check Remove found threats
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Push Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.


    Update Adobe Reader

    You can download it from
    After installing the latest Adobe Reader, uninstall all previous versions.
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or other garbage.
    On this page:


    make sure, you have both boxes UN-checked AND (important!) click on Decline button
    I can't get to the ESET page, I even tried google'ing it and still nothing, i can get to the page, and other countries too but not the .com page.
    Please run a BitDefender Online Scan

    • Disable your antivirus program.
    • Click Start Scanner button.
    • Click Start scan button
    • Allow browser plug-in to be installed when prompted.
    • Click I Agree to agree to the EULA.
    • Please refrain from using the computer until the scan is finished.
    • When the scan is finished, click on View log.
    • Notepad will open with scan results.
    • Save the report to your desktop and post its content in your next reply.
    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!:

    12. Please, let me know, how is your computer doing.
    Still having problems:
    Windows Update will not run and hasn't since 8/19 (error: Code 80072EE2) witch says the server may be busy but I have made several attempts over the past few days at different times of day and end up with the same result.

    Malwarebyte still will not update neither will Superantispyware

    Crome still opens tabs when clicking links, switched to Firefox and it will open a new window when clicking on links and the tab/window doesn't always pop up but it is never related to anything I am doing. To give you an example on Techspot I click on My Posts, the page directs me to my posts but a new tab/window opens up most recent looking for the following address ( injury attorney,backfill_conducive/l=COND) then give an "Oops could not find". I tried to get another example but it is not 100% of the time that it does this so that's the only one so far.
    I just re-read the topic and I can see I missed the fact that your MBR seems to be infected.

    Please download NTBR by noahdfear and save it to your Desktop.
    File size: 2.44 MB (2,565,432 bytes)

    • Place a blank CD in your CD drive.
    • Double click on NTBR_CD.exe file and a folder of the same name will appear.
    • Open the folder and double click on BurnItCD.cmd file. If your CD drive will open, simply close it back.
    • Follow the prompts to burn the CD.
    • Now you will need to set the CD-Rom as first boot device if it isn't already (if you don't know how to do it, see HERE)
    • If you have any questions about this step, ask before you proceed. If you enter the BIOS and are unsure if you have carried out the step correctly, there should be an option to exit without keeping changes, so you won't do any harm.
    • Insert the newly created CD into your infected PC and reboot your computer.
    • Once you have rebooted please press Enter when prompted to continue booting from CD - you have a whole 15 seconds to do this!
    • Read the warning and then continue as prompted.
    • You first need to select your keyboard layout - press Enter for English.
    • Next you want to select the appropriate tool. Enter 1 to choose 1. MBRWORK
    • On the following screen enter 5 to select Install Standard MBR code.
    • Enter 2 to overwrite the infected MBR Code with the Windows 7 MBR code.
    • When asked to confirm please do so.
    • Afterwards, please enter E to leave MBRWORK, then 6 to leave the bootable CD.
    • Eject the disc and then press ctrl+alt+del to reboot the PC.
    Once rebooted, run MBRCheck again and post its log.
    It tells me there is a problem loading the page when i click on the link, i have tried just going to and same thing, even tried googling it with the same thing, so i am led to believe that there truly is a problem loading that site, i will try again tomorrow.
    The site seems to be down.
    Hold on for a moment, I'll provide my own copy.
    Get it from HERE
Similar Topics

