TechSpot

Windows Vista Recovery/PC Peformance and Stability Virus

Inactive
By bigdfromaz
May 24, 2011
Topic Status:
Not open for further replies.
  1. I was using my comp this morning and kept getting a message to allow a program to install. I wouldn't let it install and finally restarted the comp. Incidentally the program was 02500701a.exe. After restarting the comp I got the popup window with the title in the post. I also kept getting popup messages saying my hard drive has bad sectors and my RAM is full (or something like that). I also am unable to view ANY personal files, i.e. pics, videos, music, documents.
    I started task manager and ended the process for a program titled 485533440.exe, which is the only way I've been allowed to go online. I did some research and the virus looked almost exactly like one some others were calling System Defragmenter. I followed the instructions for removing that which included downloading RKill and Malwarebytes and I am still experiencing the same problem. Luckily I found this site and I hope someone can help.

    Here are the results of my Malwarebytes scan:
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6664

    Windows 6.0.6001 Service Pack 1 (Safe Mode)
    Internet Explorer 7.0.6001.18000

    5/24/2011 2:26:21 PM
    mbam-log-2011-05-24 (14-26-21).txt

    Scan type: Quick scan
    Objects scanned: 160952
    Time elapsed: 2 minute(s), 39 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\Users\Dave\downloads\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Not selected for removal.

    I'm having trouble with this, so I'm going to have to post each scan separately first. Thanks for understanding.

    GMER
    I followed the instructions for this, but I am not getting any type of log once I complete the scan.

    DDS
    .
    DDS (Ver_11-05-19.01) - NTFSx86 NETWORK
    Internet Explorer: 7.0.6001.18000
    Run by Dave at 15:23:00 on 2011-05-24
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.3932.2989 [GMT -6:00]
    .
    AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
    SP: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ============== Running Processes ===============
    .
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\Explorer.EXE
    C:\Windows\system32\NOTEPAD.EXE
    C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
    C:\Users\Dave\Downloads\dds.scr
    C:\Windows\SysWOW64\WSCRIPT.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    .
    ============== Pseudo HJT Report ===============
    .
    uStart Page = hxxp://www.toshibadirect.com/dpdstart
    uDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
    mDefault_Page_URL = hxxp://www.toshibadirect.com/dpdstart
    uInternet Settings,ProxyOverride = *.local
    mWinlogon: Userinit=userinit.exe,
    BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files (x86)\AVG\AVG10\avgssie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre1.6.0_06\bin\ssv.dll
    BHO: Skype Plug-In: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
    BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    uRun: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
    uRun: [Google Update] "C:\Users\Dave\AppData\Local\Google\Update\GoogleUpdate.exe" /c
    uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
    uRun: [gStart] C:\Garmin\gStart.exe
    uRun: [WorkForce 630(Network)] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGBA.EXE /FU "C:\Windows\TEMP\E_SB7B.tmp" /EF "HKCU"
    uRun: [TLxbxUUdsBf] C:\ProgramData\TLxbxUUdsBf.exe
    mRun: [ITSecMng] %ProgramFiles%\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe /START
    mRun: [PCMAgent] "C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\PCMAgent.exe"
    mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\PowerCinema for TOSHIBA\Kernel\CLML\CLMLSvc.exe"
    mRun: [NDSTray.exe] NDSTray.exe
    mRun: [cfFncEnabler.exe] cfFncEnabler.exe
    mRun: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe" /start
    mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    mRun: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG10\avgtray.exe
    mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
    mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
    mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
    mRun: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
    mRun: [AgentMonitor] "C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe"
    mRun: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
    mRun: [FUFAXSTM] "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
    mRun: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\BLUETO~1.LNK - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
    StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
    IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC} - C:\Program Files (x86)\Java\jre1.6.0_06\bin\ssv.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
    IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
    IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
    DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab
    Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG10\avgpp.dll
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
    Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
    BHO-X64: AVG Safe Search: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG10\avgssiea.dll
    BHO-X64: WormRadar.com IESiteBlocker.NavFilter - No File
    BHO-X64: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
    BHO-X64: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL
    BHO-X64: URLRedirectionBHO - No File
    mRun-x64: [IgfxTray] C:\Windows\system32\igfxtray.exe
    mRun-x64: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    mRun-x64: [Persistence] C:\Windows\system32\igfxpers.exe
    mRun-x64: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    mRun-x64: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
    mRun-x64: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
    mRun-x64: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
    mRun-x64: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
    mRun-x64: [IAAnotif] "C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe"
    mRun-x64: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun-x64: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
    SEH-X64: Groove GFS Stub Execution Hook: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL
    .
    ================= FIREFOX ===================
    .
    FF - ProfilePath - C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\pxbgqgg5.default\
    FF - component: C:\Program Files (x86)\AVG\AVG10\Firefox4\components\avgssff4.dll
    FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
    FF - plugin: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
    FF - plugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
    FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.53\npGoogleUpdate3.dll
    FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrlui.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
    FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
    FF - plugin: C:\Users\Dave\AppData\Local\Google\Update\1.3.21.53\npGoogleUpdate3.dll
    FF - plugin: C:\Users\Dave\AppData\Roaming\Move Networks\plugins\npqmp071706000001.dll
    FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
    .
    ============= SERVICES / DRIVERS ===============
    .
    R0 AVGIDSEH;AVGIDSEH;C:\Windows\system32\DRIVERS\AVGIDSEH.Sys --> C:\Windows\system32\DRIVERS\AVGIDSEH.Sys [?]
    R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\system32\DRIVERS\avgrkx64.sys --> C:\Windows\system32\DRIVERS\avgrkx64.sys [?]
    R0 tos_sps64;TOSHIBA tos_sps64 Service;C:\Windows\system32\DRIVERS\tos_sps64.sys --> C:\Windows\system32\DRIVERS\tos_sps64.sys [?]
    R1 Avgtdia;AVG TDI Driver;C:\Windows\system32\DRIVERS\avgtdia.sys --> C:\Windows\system32\DRIVERS\avgtdia.sys [?]
    R3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ;C:\Windows\system32\DRIVERS\NETw5v64.sys --> C:\Windows\system32\DRIVERS\NETw5v64.sys [?]
    R3 O2MDRDR;O2MDRDR;C:\Windows\system32\DRIVERS\o2mdx64.sys --> C:\Windows\system32\DRIVERS\o2mdx64.sys [?]
    R3 O2SDRDR;O2SDRDR;C:\Windows\system32\DRIVERS\o2sdx64.sys --> C:\Windows\system32\DRIVERS\o2sdx64.sys [?]
    R3 QIOMem;Generic IO & Memory Access;C:\Windows\system32\DRIVERS\QIOMem.sys --> C:\Windows\system32\DRIVERS\QIOMem.sys [?]
    R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x64.sys --> C:\Windows\system32\DRIVERS\yk60x64.sys [?]
    S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\system32\DRIVERS\avgldx64.sys --> C:\Windows\system32\DRIVERS\avgldx64.sys [?]
    S1 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\system32\DRIVERS\avgmfx64.sys --> C:\Windows\system32\DRIVERS\avgmfx64.sys [?]
    S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2011-4-18 7398752]
    S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG10\avgwdsvc.exe [2011-2-8 269520]
    S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
    S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
    S2 ConfigFree Gadget Service;ConfigFree Gadget Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFProcSRVC.exe [2008-4-3 36864]
    S2 ConfigFree Service;ConfigFree Service;C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe [2008-4-17 40960]
    S2 FlipShareServer;FlipShare Server;C:\Program Files (x86)\Flip Video\FlipShareServer\FlipShareServer.exe [2010-12-15 1085440]
    S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-20 136176]
    S2 OpenLibSys;OpenLibSys;C:\Program Files (x86)\NXP\FM Radio\OpenLibSysX64.sys [2011-3-4 14544]
    S2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [2007-12-3 175104]
    S3 AVGIDSDriver;AVGIDSDriver;C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys --> C:\Windows\system32\DRIVERS\AVGIDSDriver.Sys [?]
    S3 AVGIDSFilter;AVGIDSFilter;C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys --> C:\Windows\system32\DRIVERS\AVGIDSFilter.Sys [?]
    S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-3-20 136176]
    S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-3-25 30969208]
    S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184]
    S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
    S3 SmartFaceVWatchSrv;SmartFaceVWatchSrv;C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatchSrv.exe [2008-4-24 84992]
    S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
    S3 WMZuneComm;Zune Windows Mobile Connectivity Service;C:\Program Files\Zune\WMZuneComm.exe [2010-11-11 306416]
    S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
    S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2011-3-11 93184]
    S4 KR10I64;KR10I64;C:\Windows\system32\drivers\kr10i64.sys --> C:\Windows\system32\drivers\kr10i64.sys [?]
    S4 KR10N64;KR10N64;C:\Windows\system32\drivers\kr10n64.sys --> C:\Windows\system32\drivers\kr10n64.sys [?]
    .
    =============== Created Last 30 ================
    .
    2011-05-24 17:07:33 -------- d--h--w- C:\Users\Dave\AppData\Roaming\Malwarebytes
    2011-05-24 17:07:30 38224 ----a-w- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
    2011-05-24 17:07:30 -------- d--h--w- C:\ProgramData\Malwarebytes
    2011-05-24 17:07:27 24152 ----a-w- C:\Windows\System32\drivers\mbam.sys
    2011-05-24 17:07:27 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
    2011-05-24 16:13:38 475648 ---ha-w- C:\ProgramData\TLxbxUUdsBf.exe
    2011-05-18 01:28:05 404640 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
    2011-05-15 09:01:28 2409784 ----a-w- C:\Program Files\Windows Mail\OESpamFilter.dat
    2011-05-15 09:01:28 2409784 ----a-w- C:\Program Files (x86)\Windows Mail\OESpamFilter.dat
    2011-05-11 13:19:59 89048 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libEGL.dll
    2011-05-11 13:19:59 781272 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozsqlite3.dll
    2011-05-11 13:19:59 465880 ----a-w- C:\Program Files (x86)\Mozilla Firefox\libGLESv2.dll
    2011-05-11 13:19:59 1874904 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
    2011-05-11 13:19:59 15832 ----a-w- C:\Program Files (x86)\Mozilla Firefox\mozalloc.dll
    2011-05-11 13:19:58 1974616 ----a-w- C:\Program Files (x86)\Mozilla Firefox\D3DCompiler_42.dll
    2011-05-11 13:19:58 1892184 ----a-w- C:\Program Files (x86)\Mozilla Firefox\d3dx9_42.dll
    2011-05-11 13:19:58 142296 ----a-w- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
    2011-05-06 02:14:27 -------- d--h--w- C:\Users\Dave\AppData\Roaming\Flip Video
    2011-05-06 02:13:43 -------- d--h--w- C:\ProgramData\Flip Video
    2011-05-06 02:13:41 -------- d-----w- C:\Program Files (x86)\Flip Video
    2011-04-27 23:51:45 4240384 ----a-w- C:\Windows\SysWow64\GameUXLegacyGDFs.dll
    2011-04-27 23:51:45 4240384 ----a-w- C:\Windows\System32\GameUXLegacyGDFs.dll
    2011-04-27 23:51:45 32256 ----a-w- C:\Windows\System32\Apphlpdm.dll
    2011-04-27 23:51:45 28672 ----a-w- C:\Windows\SysWow64\Apphlpdm.dll
    2011-04-25 18:08:18 77824 ---ha-w- C:\Windows\SysWow64\EBAPI.dll
    2011-04-25 18:08:18 65536 ---ha-w- C:\Windows\SysWow64\EEBUtil.dll
    2011-04-25 18:08:18 55808 ---ha-w- C:\Windows\SysWow64\EEBSDKIF.dll
    2011-04-25 18:08:18 135168 ---ha-w- C:\Windows\SysWow64\EEBAPI.dll
    2011-04-25 18:08:18 110592 ---ha-w- C:\Windows\SysWow64\EEBDSCVR.dll
    2011-04-25 18:06:44 -------- d-----w- C:\Program Files\Common Files\EPSON
    2011-04-25 18:06:11 -------- d-----w- C:\Program Files (x86)\EpsonNet
    2011-04-25 18:05:41 558592 ----a-w- C:\Windows\System32\ensppmon.dll
    2011-04-25 18:05:41 558592 ----a-w- C:\Windows\System32\enppmon.dll
    2011-04-25 18:05:41 538112 ----a-w- C:\Windows\System32\ensppui.dll
    2011-04-25 18:05:41 538112 ----a-w- C:\Windows\System32\enppui.dll
    2011-04-25 18:05:41 250880 ----a-w- C:\Windows\System32\enspres.dll
    2011-04-25 18:05:41 250880 ----a-w- C:\Windows\System32\enpres.dll
    2011-04-25 18:05:41 -------- d-----w- C:\Program Files\EpsonNet
    2011-04-25 18:05:26 -------- d-----w- C:\Program Files (x86)\Common Files\EPSON
    2011-04-25 18:03:32 -------- d-----w- C:\Program Files (x86)\Epson Software
    2011-04-25 18:02:45 80024 ----a-w- C:\Windows\SysWow64\PICSDK.dll
    2011-04-25 18:02:45 51360 ----a-w- C:\Windows\SysWow64\EpPicPrt.dll
    2011-04-25 18:02:45 51360 ----a-w- C:\Windows\SysWow64\EpPicMgr.dll
    2011-04-25 18:02:45 501912 ----a-w- C:\Windows\SysWow64\PICSDK2.dll
    2011-04-25 18:02:45 108704 ----a-w- C:\Windows\SysWow64\PICEntry.dll
    2011-04-25 18:01:23 118784 ----a-w- C:\Windows\System32\E_ILMGBA.DLL
    2011-04-25 18:01:21 88064 ----a-w- C:\Windows\System32\E_IBCBGBA.DLL
    2011-04-25 18:00:32 -------- d--h--w- C:\ProgramData\EPSON
    2011-04-25 17:58:24 128392 ----a-w- C:\Windows\System32\esdevapp.exe
    2011-04-25 17:58:23 464384 ----a-w- C:\Windows\System32\esxw2ud.dll
    2011-04-25 17:58:23 17408 ----a-w- C:\Windows\System32\esxcdev.dll
    2011-04-25 17:58:17 -------- d-----w- C:\Program Files (x86)\epson
    .
    ==================== Find3M ====================
    .
    2011-04-15 03:28:12 117328 ----a-w- C:\Windows\System32\drivers\AVGIDSDriver.sys
    2011-04-05 06:59:54 377936 ----a-w- C:\Windows\System32\drivers\avgtdia.sys
    2011-03-18 18:32:10 71072 ----a-w- C:\Windows\CouponPrinter.ocx
    2011-03-16 22:03:18 37456 ----a-w- C:\Windows\System32\drivers\avgrkx64.sys
    2011-03-10 16:30:11 1360384 ----a-w- C:\Windows\System32\mfc42u.dll
    2011-03-10 16:30:10 1398784 ----a-w- C:\Windows\System32\mfc42.dll
    2011-03-10 16:12:54 1161728 ----a-w- C:\Windows\SysWow64\mfc42u.dll
    2011-03-10 16:12:54 1136640 ----a-w- C:\Windows\SysWow64\mfc42.dll
    2011-03-04 22:23:56 13 --sh--r- C:\Windows\SysWow64\drivers\fbd.sys
    2011-03-03 15:09:00 975872 ----a-w- C:\Windows\System32\inetcomm.dll
    2011-03-03 15:06:28 100352 ----a-w- C:\Windows\apppatch\AppPatch64\acspecfc.dll
    2011-03-03 15:06:27 331776 ----a-w- C:\Windows\apppatch\AppPatch64\AcLayers.dll
    2011-03-03 15:06:27 281600 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
    2011-03-03 15:00:15 738816 ----a-w- C:\Windows\SysWow64\inetcomm.dll
    2011-03-03 14:56:29 173056 ----a-w- C:\Windows\apppatch\AcXtrnal.dll
    2011-03-03 14:56:26 459776 ----a-w- C:\Windows\apppatch\AcSpecfc.dll
    2011-03-03 14:56:25 541696 ----a-w- C:\Windows\apppatch\AcLayers.dll
    2011-03-03 14:56:25 2153984 ----a-w- C:\Windows\apppatch\AcGenral.dll
    2011-03-03 13:15:30 2760704 ----a-w- C:\Windows\System32\win32k.sys
    2011-03-02 15:10:39 117760 ----a-w- C:\Windows\System32\dnsrslvr.dll
    2011-03-01 20:25:18 41552 ----a-w- C:\Windows\System32\drivers\avgmfx64.sys
    2011-02-27 15:53:47 18320 ----a-w- C:\Windows\System32\kdcom.dll
    2011-02-27 15:53:46 1075600 ----a-w- C:\Windows\System32\winload.efi
    2011-02-27 15:53:45 990096 ----a-w- C:\Windows\System32\winresume.efi
    2011-02-27 15:53:45 979344 ----a-w- C:\Windows\System32\winresume.exe
    2011-02-27 15:53:45 20880 ----a-w- C:\Windows\System32\kdusb.dll
    2011-02-27 15:53:45 18832 ----a-w- C:\Windows\System32\kd1394.dll
    2011-02-27 15:53:45 1062800 ----a-w- C:\Windows\System32\winload.exe
    .
    ============= FINISH: 15:23:17.82 ===============
    and

    .
    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT
    .
    DDS (Ver_11-05-19.01)
    .
    Microsoft® Windows Vista™ Home Premium
    Boot Device: \Device\HarddiskVolume2
    Install Date: 3/4/2011 2:19:16 PM
    System Uptime: 5/24/2011 2:18:31 PM (1 hours ago)
    .
    Motherboard: TOSHIBA | | Satellite U405
    Processor: Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz | U2E1 | 1995/200mhz
    .
    ==== Disk Partitions =========================
    .
    C: is FIXED (NTFS) - 282 GiB total, 173.924 GiB free.
    D: is CDROM ()
    .
    ==== Disabled Device Manager Items =============
    .
    ==== System Restore Points ===================
    .
    .
    ==== Installed Programs ======================
    .
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9 ActiveX
    Adobe Reader 8.1.2
    Apple Application Support
    Apple Software Update
    BufferChm
    Camera Assistant Software for Toshiba
    CD/DVD Drive Acoustic Silencer
    Compatibility Pack for the 2007 Office system
    Copy
    Coupon Printer for Windows
    CustomerResearchQFolder
    CyberLink PowerCinema for TOSHIBA
    Definition update for Microsoft Office 2010 (KB982726)
    Destination Component
    DeviceDiscovery
    DeviceManagementQFolder
    DJ_AIO_03_F4200_ProductContext
    DJ_AIO_03_F4200_Software
    DJ_AIO_03_F4200_Software_Min
    DVD Decrypter (Remove Only)
    DVD MovieFactory for TOSHIBA
    DVD Shrink 3.2
    Epson Event Manager
    Epson FAX Utility
    Epson PC-FAX Driver
    EPSON Scan
    EpsonNet Print
    EpsonNet Setup 3.3
    eSupportQFolder
    F4200
    F4200_Help
    FlipShare
    FM Tuner Utility
    Garmin Training Center
    Garmin USB Drivers
    Google Chrome
    Google Earth
    Google Update Helper
    GPBaseService
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    HP Photosmart Essential 2.5
    HP Update
    HPProductAssistant
    HPSSupply
    ImgBurn
    Java(TM) 6 Update 6
    Learning Lodge Navigator
    Malwarebytes' Anti-Malware
    MarketResearch
    Media Manager for WALKMAN 1.2
    Memeo AutoBackup
    Microsoft Office Access MUI (English) 2010
    Microsoft Office Access Setup Metadata MUI (English) 2010
    Microsoft Office Excel MUI (English) 2010
    Microsoft Office Groove MUI (English) 2010
    Microsoft Office InfoPath MUI (English) 2010
    Microsoft Office OneNote MUI (English) 2010
    Microsoft Office Outlook MUI (English) 2010
    Microsoft Office PowerPoint MUI (English) 2010
    Microsoft Office PowerPoint Viewer 2007 (English)
    Microsoft Office Professional Plus 2010
    Microsoft Office Proof (English) 2010
    Microsoft Office Proof (French) 2010
    Microsoft Office Proof (Spanish) 2010
    Microsoft Office Proofing (English) 2010
    Microsoft Office Publisher MUI (English) 2010
    Microsoft Office Shared MUI (English) 2010
    Microsoft Office Shared Setup Metadata MUI (English) 2010
    Microsoft Office Suite Activation Assistant
    Microsoft Office Word MUI (English) 2010
    Microsoft Silverlight
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
    Microsoft Works
    Microsoft XML Parser
    Move Media Player
    Mozilla Firefox 4.0.1 (x86 en-US)
    Mozilla Thunderbird (3.1.10)
    MSXML 4.0 SP2 (KB941833)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    OverDrive Media Console
    Pocket-DVD Studio(remove only)
    PQ DVD to iPod Video Suite (remove only)
    PSSWCORE
    QuickBooks Financial Center
    QuickTime
    Safari
    Scan
    Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2160841)
    Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
    Security Update for Microsoft Excel 2010 (KB2466146)
    Security Update for Microsoft Office 2010 (KB2289078)
    Security Update for Microsoft Office 2010 (KB2289161)
    Security Update for Microsoft PowerPoint 2010 (KB2519975)
    Security Update for Microsoft Publisher 2010 (KB2409055)
    Security Update for Microsoft Word 2010 (KB2345000)
    Security Update for Windows Media Encoder (KB2447961)
    Skype Toolbars
    Skype™ 5.1
    SmartWebPrintingOC
    SolutionCenter
    Status
    Toolbox
    Toshiba Assist
    TOSHIBA ConfigFree
    TOSHIBA DVD PLAYER
    TOSHIBA Extended Tiles for Windows Mobility Center
    TOSHIBA Face Recognition
    TOSHIBA Games
    TOSHIBA Hardware Setup
    TOSHIBA PowerCinema Helper
    Toshiba Registration
    TOSHIBA Software Upgrades
    TOSHIBA Speech System Applications
    TOSHIBA Speech System SR Engine(U.S.) Version1.0
    TOSHIBA Speech System TTS Engine(U.S.) Version1.0
    TOSHIBA Supervisor Password
    TOSHIBA Value Added Package
    TrayApp
    UnloadSupport
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
    Update for Microsoft Office 2010 (KB2202188)
    Update for Microsoft Office 2010 (KB2413186)
    Update for Microsoft Office 2010 (KB2494150)
    Update for Microsoft OneNote 2010 (KB2493983)
    Update for Microsoft Outlook Social Connector (KB2441641)
    VideoToolkit01
    Visual Studio 2008 x64 Redistributables
    VTech Download Agent Library
    WebReg
    Windows Media Encoder 9 Series
    Windows Media Player Firefox Plugin
    .
    ==== Event Viewer Messages From Past Week ========
    .
    5/24/2011 2:22:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
    5/24/2011 11:55:21 AM, Error: ACPI [13] - : The embedded controller (EC) did not respond within the specified timeout period. This may indicate that there is an error in the EC hardware or firmware or that the BIOS is accessing the EC incorrectly. You should check with your computer manufacturer for an upgraded BIOS. In some situations, this error may cause the computer to function incorrectly.
    5/24/2011 10:57:31 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: Avgldx64 Avgmfx64 spldr Tosrfcom Wanarpv6
    5/24/2011 10:57:31 AM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
    5/24/2011 10:56:34 AM, Error: Microsoft-Windows-WLAN-AutoConfig [10000] - WLAN Extensibility Module has failed to start. Module Path: C:\Windows\System32\IWMSSvc.dll Error Code: 21
    5/24/2011 10:56:29 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
    5/24/2011 10:56:25 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
    5/24/2011 10:56:19 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
    5/24/2011 10:36:45 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
    5/24/2011 10:28:06 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting.
    5/17/2011 6:55:32 PM, Error: Service Control Manager [7022] - The HP CUE DeviceDiscovery Service service hung on starting.
    .
    ==== End Of File ===========================
  2. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Welcome to TechSpot!This has been a very popular malware program lately.

    This is a rogue program. It will falsely alert you to problems that don't actually exist except for you to be scammed into clicking on some site for removal ($$$$. So it's important you don't act on any of these 'alerts'.

    You mentioned following some directions that included Rkill, then Malwarebytes. Since I wasn't the one who gave this instruction, I don't know if it was appropriate at that time. Malware cleaning instructions are speific to the person who is being assisted. You may have been following a general/generic removal instruction.

    Were you unable to run Mbam? I would like for you to uninstall both Mbam and Rkill. Then go through the steps on the thread. If you cannot run Malwarebytes, please let me know and I will help you with it.

    Please follow the steps in the Preliminary Virus and Malware Removal thread HERE.

    NOTE: If you already have any of the scanning programs on the computer, please remove them and download the versions in these links.

    When you have finished, leave the logs for review in your next reply .
    NOTE: Logs must be pasted in the replies. Attached logs will not be reviewed.

    Please do not use any other cleaning programs or scans while I'm helping you, unless I direct you to. Do not use a Registry cleaner or make any changes in the Registry.

    If GMER won't run in Normal Mode, try it in Safe Mode. If the scan won't run, okay to hold off on it until we can get rid of some of the malware.
  3. bigdfromaz

    bigdfromaz Newcomer, in training Topic Starter

    I removed Malwarebytes and RKill and reinstalled Malwarebytes. I've been doing all of this in Safe Mode. Here is the results of my Malwarebytes scan

    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org

    Database version: 6667

    Windows 6.0.6001 Service Pack 1 (Safe Mode)
    Internet Explorer 7.0.6001.18000

    5/24/2011 4:08:11 PM
    mbam-log-2011-05-24 (16-08-11).txt

    Scan type: Quick scan
    Objects scanned: 161120
    Time elapsed: 41 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    c:\Users\Dave\downloads\eXplorer.exe (Heuristics.Reserved.Word.Exploit) -> Quarantined and deleted successfully.


    Thank you again.
  4. Bobbye

    Bobbye Helper on the Fringe Posts: 16,392   +36

    Let's go on to the following 2 scans. Scans should be run in Normal Mode-if possible-

    • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
      ESETOnlineScan
    • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
      [o] Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
      [o] Double click on the [​IMG]on your desktop.
    • Check 'Yes I accept terms of use.'
    • Click Start button
    • Accept any security warnings from your browser.
      [​IMG]
    • Uncheck 'Remove found threats'
    • Check 'Scan archives/
    • Leave remaining settings as is.
    • Press the Start button.
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please wait for the scan to finish.
    • When the scan completes, press List of found threats
    • Push Export of text file and save the file to your desktop using a unique name, such as ESETScan. Paste this log in your next reply.
    • Push the Back button
    • Push Finish

    NOTE: If no malware is found then no log will be produced. Let me know if this is the case.
    ====================================
    Please note: If you have Combofix on the desktop already, please uninstall it. Then download the current version and do the scan: Uninstall directions, if needed
    • [
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there./list]
      --------------------------------------
      Download Combofix from HERE or HERE and save to the desktop
      • Double click combofix.exe & follow the prompts.
      • ComboFix will check to see if the Microsoft Windows Recovery Console is installed. It is recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode if needed.
        **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
      • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
      • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
        [​IMG]
      • .Click on Yes, to continue scanning for malware
      • .If Combofix asks you to update the program, allow
      • .Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
      • .Close any open browsers.
      • .Double click combofix.exe[​IMG] & follow the prompts to run.
      • When the scan completes , a report will be generated-it will open a text window. Please paste the C:\ComboFix.txt in next reply..
      Re-enable your Antivirus software.
      Notes:
      1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
      2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
      3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
      4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.