[Resolved] Automatically loading bizrumour
-
re: [Resolved] Automatically loading bizrumour
Broni, here's what came up after I hit the "reanalyze" button:
Antivirus Version Last Update Result
a-squared 4.5.0.41 2009.10.30 -
AhnLab-V3 5.0.0.2 2009.10.29 -
AntiVir 7.9.1.50 2009.10.29 -
Antiy-AVL 2.0.3.7 2009.10.27 -
Authentium 5.1.2.4 2009.10.29 -
Avast 4.8.1351.0 2009.10.29 -
AVG 8.5.0.423 2009.10.29 -
BitDefender 7.2 2009.10.30 -
CAT-QuickHeal 10.00 2009.10.30 -
ClamAV 0.94.1 2009.10.30 -
Comodo 2774 2009.10.30 -
DrWeb 5.0.0.12182 2009.10.29 -
eSafe 7.0.17.0 2009.10.29 -
eTrust-Vet 35.1.7092 2009.10.29 -
F-Prot 4.5.1.85 2009.10.29 -
F-Secure 9.0.15370.0 2009.10.27 -
Fortinet 3.120.0.0 2009.10.29 -
GData 19 2009.10.30 -
Ikarus T3.1.1.72.0 2009.10.30 -
Jiangmin 11.0.800 2009.10.30 -
K7AntiVirus 7.10.883 2009.10.29 -
Kaspersky 7.0.0.125 2009.10.30 -
McAfee 5786 2009.10.29 -
McAfee+Artemis 5786 2009.10.29 -
McAfee-GW-Edition 6.8.5 2009.10.29 -
Microsoft 1.5202 2009.10.29 -
NOD32 4556 2009.10.29 -
Norman 6.03.02 2009.10.29 -
nProtect 2009.1.8.0 2009.10.29 -
Panda 10.0.2.2 2009.10.29 -
PCTools 4.4.2.0 2009.10.19 -
Prevx 3.0 2009.10.30 -
Rising 21.53.40.00 2009.10.30 -
Sophos 4.47.0 2009.10.30 -
Sunbelt 3.2.1858.2 2009.10.29 -
Symantec 1.4.4.12 2009.10.30 -
TheHacker 6.5.0.2.056 2009.10.28 -
TrendMicro 8.950.0.1094 2009.10.29 -
VBA32 3.12.10.11 2009.10.29 -
ViRobot 2009.10.30.2012 2009.10.30 -
VirusBuster 4.6.5.0 2009.10.29 -
Additional information
File size: 368912 bytes
MD5...: 9d1864ae5f6ff8bbde86a3f5a448110d
SHA1..: 912dba207d17697be8196e46a0cb1dc13f291519
SHA256: ddf8f7366a4e44bd7efcad0b3f20c8b0eb82185cc909b03ce6 935415bd8c6a10
ssdeep: 6144:uLa8OZI7UqK2EltlXtHTIo3+CAOlvddPxsCzp84J:/I7fKplthtHTIbUV7P
x
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x21e20
timedatestamp.....: 0x32830805 (Fri Nov 08 10:14:29 1996)
machinetype.......: 0x14c (I386)
( 7 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x2cc76 0x2ce00 6.67 5afb75a21cfc246a78e80326db1be4a1
ENGINE 0x2e000 0x1322d 0x13400 6.27 7b88cbfbc0cbe147cf4c48f18253b2bf
.rdata 0x42000 0x5a89 0x5c00 4.31 f4687d67bd8dc380be049a086874f636
.data 0x48000 0x5118 0x3600 4.11 c8cc09e4c250d3569331c689f376a2b7
.idata 0x4e000 0x1358 0x1400 5.44 528b2dc0b98748c9ea0abd0f85e66818
.rsrc 0x50000 0xac80 0xae00 4.71 a6510ca60216bd36d78063f2c3fea304
.reloc 0x5b000 0x45b2 0x4600 6.37 1766ce30be79a3da93a744200a112a0b
( 5 imports )
> ole32.dll: CoCreateInstance, CreateBindCtx, MkParseDisplayName, BindMoniker, CLSIDFromProgID, CoRevokeClassObject, CoRegisterClassObject, CoGetMalloc, OleBuildVersion
> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
> USER32.dll: CharToOemA, OemToCharA, CharLowerA, WaitForInputIdle, GetActiveWindow, GetDesktopWindow, IsWindowEnabled, IsWindowVisible, GetWindowTextA, SetForegroundWindow, SetFocus, GetWindow, GetForegroundWindow, MessageBeep, GetKeyboardLayout, SendMessageA, FindWindowA, FindWindowW, SetKeyboardState, CharLowerBuffW, CharUpperBuffA, CharUpperBuffW, GetSystemMetrics, LoadStringA, keybd_event, GetKeyboardState, VkKeyScanW, VkKeyScanA, SetWindowsHookExW, SetWindowsHookExA, UnhookWindowsHookEx, CallNextHookEx, GetAsyncKeyState, AttachThreadInput, GetWindowThreadProcessId, CharLowerBuffA
> KERNEL32.dll: GlobalLock, GetLastError, VirtualQuery, WriteFile, ReadFile, GetFileType, MoveFileA, DeleteFileA, RemoveDirectoryA, CreateDirectoryA, SetEnvironmentVariableA, SetCurrentDirectoryA, GetCurrentDirectoryA, FlushFileBuffers, FindNextFileA, HeapFree, HeapAlloc, GetFullPathNameA, GetCommandLineA, RtlUnwind, GetUserDefaultLCID, lstrlenA, GetDateFormatA, CreateProcessA, CreateProcessW, GetCurrentProcess, SetLocalTime, GetLocalTime, GetFileAttributesA, FindFirstFileA, FindClose, SetFileAttributesA, FileTimeToLocalFileTime, FileTimeToSystemTime, GetFileTime, SetFileTime, CloseHandle, GetVolumeInformationA, GetTimeZoneInformation, GetStringTypeW, SetEndOfFile, SetStdHandle, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, HeapSize, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetOEMCP, GetACP, GetCPInfo, DeleteCriticalSection, GetStartupInfoA, GetStdHandle, SetHandleCount, HeapDestroy, HeapCreate, TlsGetValue, TlsFree, TlsAlloc, TlsSetValue, GetCurrentThreadId, HeapReAlloc, TerminateProcess, ExitProcess, UnlockFile, LockFile, WideCharToMultiByte, MultiByteToWideChar, GetTickCount, Sleep, RaiseException, GetProcAddress, GetModuleHandleA, GetVersion, FreeLibrary, DisableThreadLibraryCalls, GetSystemDefaultLangID, GetUserDefaultLangID, IsDBCSLeadByte, lstrcmpiA, LCMapStringA, GetStringTypeA, GlobalFree, GlobalUnlock, GlobalHandle, SetFilePointer, GlobalAlloc, CompareStringW, SetLastError, CompareStringA, LCMapStringW, LoadLibraryA, GetDriveTypeA, GetLocaleInfoW, GetLocaleInfoA, CreateFileA, FormatMessageW, GetModuleFileNameA, GetModuleFileNameW, SetErrorMode
> ADVAPI32.dll: RegEnumValueA, RegQueryInfoKeyA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, RegCreateKeyA, RegCreateKeyW, RegQueryValueExA, RegQueryValueExW, RegEnumValueW, RegEnumKeyA, RegEnumKeyW, RegDeleteValueA, RegDeleteValueW, RegDeleteKeyA, RegDeleteKeyW, RegOpenKeyA, RegOpenKeyW, RegSetValueExA, RegSetValueExW
( 225 exports )
CopyRecord, CreateIExprSrvObj, DllFunctionCall, EbGetHandleOfExecutingProject, EbGetObjConnectionCounts, EbGetVBAObject, EbLibraryLoad, EbLibraryUnload, EbLoadRunTime, EbResetProject, EbResetProjectNormal, GetMem1, GetMem2, GetMem4, GetMem8, GetMemEvent, GetMemNewObj, GetMemObj, GetMemStr, GetMemVar, IID_IVbaHost, MethCallEngine, ProcCallEngine, PutMem1, PutMem2, PutMem4, PutMem8, PutMemEvent, PutMemNewObj, PutMemObj, PutMemStr, PutMemVar, SetMemEvent, SetMemNewObj, SetMemObj, SetMemVar, TipCreateInstanceProject, TipGetAddressOfPredeclaredInstance, TipInvokeMethod, TipInvokeMethod2, TipUnloadProject, VarPtr, __vbaRecAssign, __vbaRecDestruct, rtBoolFromErrVar, rtBstrFromErrVar, rtCyFromErrVar, rtDecFromVar, rtI2FromErrVar, rtI4FromErrVar, rtR4FromErrVar, rtR8FromErrVar, rtUI1FromErrVar, rtcAbsVar, rtcAnsiValueBstr, rtcAppActivate, rtcAppleScript, rtcArray, rtcAtn, rtcBeep, rtcBstrFromAnsi, rtcBstrFromByte, rtcBstrFromChar, rtcBstrFromError, rtcBstrFromFormatVar, rtcByteValueBstr, rtcCVErrFromVar, rtcChangeDir, rtcChangeDrive, rtcCharValueBstr, rtcChoose, rtcCommandBstr, rtcCommandVar, rtcCompareBstr, rtcCos, rtcCreateObject, rtcCurrentDir, rtcCurrentDirBstr, rtcDDB, rtcDateAdd, rtcDateDiff, rtcDateFromVar, rtcDatePart, rtcDeleteSetting, rtcDir, rtcDoEvents, rtcEndOfFile, rtcEnvironBstr, rtcEnvironVar, rtcErrObj, rtcExp, rtcFV, rtcFileAttributes, rtcFileCopy, rtcFileDateTime, rtcFileLen, rtcFileLength, rtcFileLocation, rtcFileReset, rtcFileSeek, rtcFileWidth, rtcFixVar, rtcFreeFile, rtcGetAllSettings, rtcGetCurrentCalendar, rtcGetDateBstr, rtcGetDateValue, rtcGetDateVar, rtcGetDayOfMonth, rtcGetDayOfWeek, rtcGetErl, rtcGetFileAttr, rtcGetHourOfDay, rtcGetMinuteOfHour, rtcGetMonthOfYear, rtcGetObject, rtcGetPresentDate, rtcGetSecondOfMinute, rtcGetSetting, rtcGetTimeBstr, rtcGetTimeValue, rtcGetTimeVar, rtcGetTimer, rtcGetYear, rtcHexBstrFromVar, rtcHexVarFromVar, rtcIMEStatus, rtcIPMT, rtcIRR, rtcImmediateIf, rtcInStr, rtcInStrChar, rtcInputBox, rtcInputCharCount, rtcInputCharCountVar, rtcInputCount, rtcInputCountVar, rtcIntVar, rtcIsArray, rtcIsDate, rtcIsEmpty, rtcIsError, rtcIsMissing, rtcIsNull, rtcIsNumeric, rtcIsObject, rtcKillFiles, rtcLeftBstr, rtcLeftCharBstr, rtcLeftCharVar, rtcLeftTrimBstr, rtcLeftTrimVar, rtcLeftVar, rtcLenCharVar, rtcLenVar, rtcLog, rtcLowerCaseBstr, rtcLowerCaseVar, rtcMIRR, rtcMacId, rtcMakeDir, rtcMidBstr, rtcMidCharBstr, rtcMidCharVar, rtcMidVar, rtcMsgBox, rtcNPV, rtcNPer, rtcOctBstrFromVar, rtcOctVarFromVar, rtcPMT, rtcPPMT, rtcPV, rtcPackDate, rtcPackTime, rtcPartition, rtcQBColor, rtcR8ValFromBstr, rtcRandomNext, rtcRandomize, rtcRate, rtcRemoveDir, rtcRgb, rtcRightBstr, rtcRightCharBstr, rtcRightCharVar, rtcRightTrimBstr, rtcRightTrimVar, rtcRightVar, rtcSLN, rtcSYD, rtcSaveSetting, rtcSendKeys, rtcSetCurrentCalendar, rtcSetDateBstr, rtcSetDateVar, rtcSetFileAttr, rtcSetTimeBstr, rtcSetTimeVar, rtcSgnVar, rtcShell, rtcSin, rtcSpaceBstr, rtcSpaceVar, rtcSqr, rtcStrConvVar, rtcStrFromVar, rtcStringBstr, rtcStringVar, rtcSwitch, rtcTan, rtcTrimBstr, rtcTrimVar, rtcTypeName, rtcUpperCaseBstr, rtcUpperCaseVar, rtcVarBstrFromAnsi, rtcVarBstrFromByte, rtcVarBstrFromChar, rtcVarDateFromVar, rtcVarFromError, rtcVarFromFormatVar, rtcVarFromVar, rtcVarStrFromVar, rtcVarType
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable MS Visual C++ (generic) (65.1%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher....: Microsoft Corporation
copyright....: Copyright (c) Microsoft Corp. 1993-1996
product......: Microsoft Visual Basic for Applications
description..: Visual Basic for Applications Runtime - Expression Service
original name: VBAR332.DLL
internal name: VBAR332.DLL
file version.: 3.0.6908
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
ThreatExpert info: <a href='http://www.threatexpert.com/report.aspx?md5=9d1864ae5f6ff8bbde86a3f5a448110d' target='_blank'>http://www.threatexpert.com/report.aspx?md5=9d1864ae5f6ff8bbde86a3f5a448110d</a>
-
OK.
Print these instructions out.
NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe
***VERY IMPORTANT! Make sure, you update Superantispyware, and Malwarebytes before running the scans.***
STEP 1. Download SUPERAntiSpyware Free for Home Users:
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!
* Double-click SUPERAntiSpyware.exe and use the default settings for installation.
* An icon will be created on your desktop. Double-click that icon to launch the program.
* If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download and unzip them from here: SUPERAntiSpyware.com - Database Definition Information.)
* Close SUPERAntiSpyware.
PHYSICALLY DISCONNECT FROM THE INTERNET
Restart computer in Safe Mode.
To enter Safe Mode, restart computer, and keep tapping F8 key, until menu appears; select Safe Mode; you'll see "Safe Mode" in all four corners of your screen
* Open SUPERAntiSpyware.
* Click Scan your Computer... button.
* Click Scanning Preferences/Control Center... button.
* Under General and Startup tab, make sure, Start SUPERAntiSpyware when Windows starts option is UN-checked.
* Click the Scanning Control tab.
* Under Scanner Options make sure the following are checked (leave all others unchecked):
- Close browsers before scanning.
- Terminate memory threats before quarantining.
* Click the Close button to leave the control center screen.
* On the left, make sure you check C:\Fixed Drive.
* On the right, choose Perform Complete Scan.
* Click Next to start the scan. Please be patient while it scans your computer.
* After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click OK.
* Make sure everything has a checkmark next to it and click Next.
* A notification will appear that Quarantine and Removal is Complete. Click OK and then click the Finish button to return to the main menu.
* If asked if you want to reboot, click Yes.
* To retrieve the removal information after reboot, launch SUPERAntispyware again.
- Click Preferences, then click the Statistics/Logs tab.
- Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
- If there are several logs, click the current dated log and press View log. A text file will open in your default text editor.
- Please copy and paste the Scan Log results in your next reply.
* Click Close to exit the program.
Post SUPERAntiSpyware log.
RECONNECT TO THE INTERNET
RESTART COMPUTER!
STEP 2. Download Malwarebytes' Anti-Malware: Malwarebytes.org to your desktop.
(Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
RESTART COMPUTER!
STEP 4.
Post fresh HijackThis log.
NOTE. If you're using Vista, right click on HijackThis, and click Run as Administrator
Do NOT attempt to "fix" anything!
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!
-
Broni, it took a few hours to scan the computer! Here are the logs:
Superantispyware:
SUPERAntiSpyware Scan Log
SUPERAntiSpyware.com | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!
Generated 10/29/2009 at 10:42 PM
Application Version : 4.29.1004
Core Rules Database Version : 4212
Trace Rules Database Version: 2119
Scan type : Complete Scan
Total Scan Time : 01:20:45
Memory items scanned : 275
Memory threats detected : 0
Registry items scanned : 6549
Registry threats detected : 0
File items scanned : 139428
File threats detected : 0
Malwarebytes:
For this, I am having a hard time getting the log. When I try to go into the Application data folder, it says access denied. And under program files/malware bytes, there is no log folder. But when the program ran, it did not detect anything infected.
New HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:28 AM, on 10/30/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/56.25/uploader2.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
--
End of file - 5393 bytes
-
Also, ever since I ran combofix, the IE problem has not occured. But then I have not used the internet much because I have been scanning the machine, so I don't know whether the problem was fixed or I just haven't encountered it yet.
-
Uninstall Combofix:
Go Start > Run
Type in:
combofix /u
Note the space between the "combofix" and the "/u"
Restart computer.
================================================== =========
You're not running any AV program, so please, download and install one of these:
- Avira free antivirus: Avira AntiVir Personal - FREE Antivirus
- Avast! free antivirus: Download FREE antivirus software - avast! Home Edition
- free Comodo Internet Security (firewall + AV): Firewall and AntiVirus Free Software Download from Comodo
NOTE. During installation, Comodo will also allow you to install AV only, or firewall only, if you prefer to combine one Comodo product with some other product.
If you decide to install Avast, or Avira, make sure, Windows firewall is turned on, or use Comodo firewall..
If you decide to install Comodo Internet Security, or just Comodo firewall, make sure, Windows firewall is turned off.
IMPORTANT! Make sure, you use only ONE antivirus, and ONE firewall.
================================================== ==============
Please download JavaRa to your desktop and unzip it to its own folder
- Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
- Accept any prompts.
- Open JavaRa.exe again and select Search For Updates.
- Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.
================================================== =============
Print this post out, since you won't have an access to it, at some point.
1. Open HijackThis.
2. Close all windows, except for HijackThis.
3. Put checkmarks next to the following HijackThis entries:
- O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
- O4 - Global Startup: Bluetooth.lnk = ?
4. You should also checkmark following entries (these are unnecessary startups; no actual programs will be removed):
- O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
- O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
5. Click on Fix checked button.
6. Restart computer.
7. Post new HijackThis log.
-
Broni, thanks for all your help. The problem seems to have been removed. If you recall, I had to run combofix twice because spybot intrrupted its running upon reboot. I suspect the first run of combofix removed the malware and that's why the other programs showed no infection. (Combofix had reported some rootkit activity on the first run.)
Here's the latest HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:22:55 PM, on 10/30/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18828)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = Hotmail, News, Sport, Music, Movies, Money, Cars, Shopping, Windows Live from MSN UK
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O16 - DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} (UploadListView Class) - http://picasaweb.google.com/s/v/56.25/uploader2.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/de...e/HPDEXAXO.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe
--
End of file - 5087 bytes
The log is a lot smaller than the previous ones so some garbage has certainly gone away. Thankss again for your guidance!
-
Excellent 
Your computer is clean 
1. Download Temp File Cleaner (TFC)
Double click on TFC.exe to run the program.
Click on Start button to begin cleaning process.
TFC will close all running programs, and it may ask you to restart computer.
2. Turn off System Restore:
- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK
3. Restart computer.
4. Turn System Restore on.
5. Make sure, Windows Updates are current.
6. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!
7. Download, and install WOT (Web OF Trust): Internet Security | WOT Web of Trust. It'll warn you (in most cases) about dangerous web sites.
8. Run defrag at your convenience.
9. Read How did I get infected?, With steps so it does not happen again!: How did I get infected?
10. Please, let me know, how is your computer doing.
-
Thanks, Broni. Everything is working perfectly now! I really appreciate your fantastic help.
-
You're very welcome