I've been trying to squash this bug for three days straight. As a freelancer, I'm losing money the longer my computer is out of commission. I can usually get rid of these viruses, but this one just keeps coming back, no matter what I do. I've run about 10 different antivirus programs, a rootkit remover, and a registry cleaner. Nothing works. I have two browsers I use -- Firefox and Maxthon. My Google searches in Firefox get occasionally redirected to ad/spam sites (maybe one in every three or four clicks). In Maxthon (which is IE-based, in case you haven't heard of it), I get "operation aborted" notices when trying to go to sites like Bleepingcomputer, or this one. (So far, Firefox seems unaffected in that regard.)
Can't run GMER, as I'm on 64-bit Win7. MBAM and DDS logs follow. "Attach" exceeds 20K characters, so it's included here as an attachment.
----------------------------------------
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4661
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
22-Sep-10 8:40:13
mbam-log-2010-09-22 (08-40-13).txt
Scan type: Quick scan
Objects scanned: 137652
Time elapsed: 5 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
-----------------------------------------------------------------------------------------------
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 13-Sep-10 16:47:32
System Uptime: 22-Sep-10 8:30:07 (0 hours ago)
Motherboard: TOSHIBA | | Portable PC
Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz | CPU | 2194/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 222 GiB total, 181.71 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP31: 20-Sep-10 11:51:47 - Installed FreeUndelete
RP32: 20-Sep-10 12:01:02 - Installed ParetoLogic Data Recovery.
RP33: 20-Sep-10 13:33:30 - printer fixed
RP34: 20-Sep-10 19:15:51 - after norton scan
RP35: 21-Sep-10 6:42:28 - avast! Free Antivirus Setup
RP36: 21-Sep-10 7:50:34 - Removed ParetoLogic Data Recovery.
RP37: 21-Sep-10 7:52:22 - Removed FreeUndelete
RP38: 21-Sep-10 11:13:38 - avast! Free Antivirus Setup
RP39: 21-Sep-10 11:39:31 - apparently safe
RP40: 21-Sep-10 22:52:03 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP41: 22-Sep-10 5:45:58 - StopZILLA! Restore Point.
RP43: 22-Sep-10 8:32:08 - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
==== Installed Programs ======================
Adobe AIR
Adobe Community Help
Adobe Dreamweaver CS5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe InDesign CS5
Adobe Media Player
Adobe Reader 9.3
AIM 7
Apple Application Support
Apple Software Update
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Atheros Driver Installation Program
Audacity 1.3.12 (Unicode)
Auslogics Registry Cleaner
Avira AntiVir Personal - Free Antivirus
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
DHTML Editing Component
DJ_AIO_05_F4400_Software_Min
Download Updater (AOL LLC)
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Gtk# for .Net 2.12.9
HijackThis 2.0.2
Hitman Pro 3.5
HP Photo Creations
HP Update
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 21
Junk Mail filter update
Label@Once 1.0
LAME v3.98.2 for Audacity
Malwarebytes' Anti-Malware
Maxthon2
Microsoft Choice Guard
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox (3.6.10)
MSVCRT
MSXML 4.0 SP3 Parser (KB973685)
Norton AntiVirus
OpenOffice.org 3.2
OpenVPN 2.1.3
PandoraRecovery (Remove Only)
PDF Settings CS5
PhotoImpact X3
PolarClock3 Screen Saver
QuickTime
Realtek USB 2.0 Card Reader
Scan
Sophos Anti-Rootkit 1.5.4
Spybot - Search & Destroy
Toolbox
TOSHIBA Application Installer
TOSHIBA Assist
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
TOSHIBA Media Controller
TOSHIBA Media Controller Plug-in
TOSHIBA Quality Application
TOSHIBA ReelTime
TOSHIBA Service Station
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
==== Event Viewer Messages From Past Week ========
22-Sep-10 8:30:49, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: is3srv SAVRKBootTasks
22-Sep-10 8:28:45, Error: Service Control Manager [7034] - The STOPzilla Service service terminated unexpectedly. It has done this 1 time(s).
22-Sep-10 5:50:54, Error: bowser [8003] - The master browser has received a server announcement from the computer ORLANDO that believes that it is the master browser for the domain on transport NetBT_Tcpip_{13084601-1182-4B83-A822-E79BD39E97D1}. The master browser is stopping or an election is being forced.
22-Sep-10 5:45:06, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
22-Sep-10 5:44:51, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SAVRKBootTasks
21-Sep-10 6:34:29, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
21-Sep-10 3:12:27, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx64 DfsC discache eeCtrl IDSVia64 NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr SRTSP SRTSPX SymIRON SymNetS tdx vwififlt Wanarpv6 WfpLwf
21-Sep-10 3:12:27, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
21-Sep-10 22:40:29, Error: Service Control Manager [7000] - The MEMSWEEP2 service failed to start due to the following error: This driver has been blocked from loading
21-Sep-10 22:40:29, Error: Application Popup [1060] - \??\C:\windows\system32\EB0A.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 22:38:03, Error: Application Popup [1060] - \??\C:\windows\system32\9D86.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 22:29:50, Error: Application Popup [1060] - \??\C:\windows\system32\4D12.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 21:52:30, Error: Application Popup [1060] - \??\C:\windows\system32\1002.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 2:28:47, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
20-Sep-10 22:23:41, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{13084601-1182-4B83-A822-E79BD39E97D1} because another computer on the network has the same name. The server could not start.
20-Sep-10 11:48:37, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
20-Sep-10 11:48:07, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
20-Sep-10 11:47:37, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service.
18-Sep-10 12:28:06, Error: bowser [8003] - The master browser has received a server announcement from the computer TONY that believes that it is the master browser for the domain on transport NetBT_Tcpip_{390E530B-D42C-4C75-931E-255B69283D1B}. The master browser is stopping or an election is being forced.
17-Sep-10 12:30:14, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
16-Sep-10 16:15:33, Error: Service Control Manager [7031] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
==== End Of File ===========================
Can't run GMER, as I'm on 64-bit Win7. MBAM and DDS logs follow. "Attach" exceeds 20K characters, so it's included here as an attachment.
----------------------------------------
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4661
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
22-Sep-10 8:40:13
mbam-log-2010-09-22 (08-40-13).txt
Scan type: Quick scan
Objects scanned: 137652
Time elapsed: 5 minute(s), 15 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
-----------------------------------------------------------------------------------------------
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows 7 Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 13-Sep-10 16:47:32
System Uptime: 22-Sep-10 8:30:07 (0 hours ago)
Motherboard: TOSHIBA | | Portable PC
Processor: Intel(R) Celeron(R) CPU 900 @ 2.20GHz | CPU | 2194/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 222 GiB total, 181.71 GiB free.
D: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP31: 20-Sep-10 11:51:47 - Installed FreeUndelete
RP32: 20-Sep-10 12:01:02 - Installed ParetoLogic Data Recovery.
RP33: 20-Sep-10 13:33:30 - printer fixed
RP34: 20-Sep-10 19:15:51 - after norton scan
RP35: 21-Sep-10 6:42:28 - avast! Free Antivirus Setup
RP36: 21-Sep-10 7:50:34 - Removed ParetoLogic Data Recovery.
RP37: 21-Sep-10 7:52:22 - Removed FreeUndelete
RP38: 21-Sep-10 11:13:38 - avast! Free Antivirus Setup
RP39: 21-Sep-10 11:39:31 - apparently safe
RP40: 21-Sep-10 22:52:03 - Installed STOPzilla. Available with Windows Installer version 1.2 and later.
RP41: 22-Sep-10 5:45:58 - StopZILLA! Restore Point.
RP43: 22-Sep-10 8:32:08 - Removed STOPzilla. Available with Windows Installer version 1.2 and later.
==== Installed Programs ======================
Adobe AIR
Adobe Community Help
Adobe Dreamweaver CS5
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe InDesign CS5
Adobe Media Player
Adobe Reader 9.3
AIM 7
Apple Application Support
Apple Software Update
Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
Atheros Driver Installation Program
Audacity 1.3.12 (Unicode)
Auslogics Registry Cleaner
Avira AntiVir Personal - Free Antivirus
Compatibility Pack for the 2007 Office system
Coupon Printer for Windows
DHTML Editing Component
DJ_AIO_05_F4400_Software_Min
Download Updater (AOL LLC)
Google Chrome
Google Toolbar for Internet Explorer
Google Update Helper
Gtk# for .Net 2.12.9
HijackThis 2.0.2
Hitman Pro 3.5
HP Photo Creations
HP Update
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 21
Junk Mail filter update
Label@Once 1.0
LAME v3.98.2 for Audacity
Malwarebytes' Anti-Malware
Maxthon2
Microsoft Choice Guard
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Home and Student 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Single Image 2010
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Works
Microsoft_VC80_ATL_x86
Microsoft_VC80_CRT_x86
Microsoft_VC80_MFC_x86
Microsoft_VC80_MFCLOC_x86
Microsoft_VC90_ATL_x86
Microsoft_VC90_CRT_x86
Microsoft_VC90_MFC_x86
Mozilla Firefox (3.6.10)
MSVCRT
MSXML 4.0 SP3 Parser (KB973685)
Norton AntiVirus
OpenOffice.org 3.2
OpenVPN 2.1.3
PandoraRecovery (Remove Only)
PDF Settings CS5
PhotoImpact X3
PolarClock3 Screen Saver
QuickTime
Realtek USB 2.0 Card Reader
Scan
Sophos Anti-Rootkit 1.5.4
Spybot - Search & Destroy
Toolbox
TOSHIBA Application Installer
TOSHIBA Assist
TOSHIBA Hardware Setup
TOSHIBA HDD/SSD Alert
TOSHIBA Media Controller
TOSHIBA Media Controller Plug-in
TOSHIBA Quality Application
TOSHIBA ReelTime
TOSHIBA Service Station
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
ToshibaRegistration
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Mail
Windows Live Messenger
Windows Live Movie Maker
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Upload Tool
Windows Live Writer
==== Event Viewer Messages From Past Week ========
22-Sep-10 8:30:49, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: is3srv SAVRKBootTasks
22-Sep-10 8:28:45, Error: Service Control Manager [7034] - The STOPzilla Service service terminated unexpectedly. It has done this 1 time(s).
22-Sep-10 5:50:54, Error: bowser [8003] - The master browser has received a server announcement from the computer ORLANDO that believes that it is the master browser for the domain on transport NetBT_Tcpip_{13084601-1182-4B83-A822-E79BD39E97D1}. The master browser is stopping or an election is being forced.
22-Sep-10 5:45:06, Error: Microsoft-Windows-WMPNSS-Service [14332] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(CLSID_UPnPDeviceFinder) encountered error '0x80004005'. Verify that the UPnPHost service is running and that the UPnPHost component of Windows is installed properly.
22-Sep-10 5:44:51, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: SAVRKBootTasks
21-Sep-10 6:34:29, Error: Service Control Manager [7006] - The ScRegSetValueExW call failed for Start with the following error: Access is denied.
21-Sep-10 3:12:27, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD BHDrvx64 DfsC discache eeCtrl IDSVia64 NetBIOS NetBT nsiproxy Psched rdbss SASDIFSV SASKUTIL spldr SRTSP SRTSPX SymIRON SymNetS tdx vwififlt Wanarpv6 WfpLwf
21-Sep-10 3:12:27, Error: Service Control Manager [7001] - The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
21-Sep-10 22:40:29, Error: Service Control Manager [7000] - The MEMSWEEP2 service failed to start due to the following error: This driver has been blocked from loading
21-Sep-10 22:40:29, Error: Application Popup [1060] - \??\C:\windows\system32\EB0A.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 22:38:03, Error: Application Popup [1060] - \??\C:\windows\system32\9D86.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 22:29:50, Error: Application Popup [1060] - \??\C:\windows\system32\4D12.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 21:52:30, Error: Application Popup [1060] - \??\C:\windows\system32\1002.tmp has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.
21-Sep-10 2:28:47, Error: Service Control Manager [7030] - The Lavasoft Ad-Aware Service service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.
20-Sep-10 22:23:41, Error: Server [2505] - The server could not bind to the transport \Device\NetBT_Tcpip_{13084601-1182-4B83-A822-E79BD39E97D1} because another computer on the network has the same name. The server could not start.
20-Sep-10 11:48:37, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
20-Sep-10 11:48:07, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the LanmanServer service.
20-Sep-10 11:47:37, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WSearch service.
18-Sep-10 12:28:06, Error: bowser [8003] - The master browser has received a server announcement from the computer TONY that believes that it is the master browser for the domain on transport NetBT_Tcpip_{390E530B-D42C-4C75-931E-255B69283D1B}. The master browser is stopping or an election is being forced.
17-Sep-10 12:30:14, Error: Disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1.
16-Sep-10 16:15:33, Error: Service Control Manager [7031] - The Windows Installer service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
==== End Of File ===========================