ChiefsPlanet

ChiefsPlanet (https://www.chiefsplanet.com/BB/index.php)
-   Media Center (https://www.chiefsplanet.com/BB/forumdisplay.php?f=2)
-   -   Computers The Official Malware/Antivirus Thread - Need help or general advice? Read this first! (https://www.chiefsplanet.com/BB/showthread.php?t=232173)

Sofa King 01-11-2011 03:08 PM

Quote:

Originally Posted by KC Fish (Post 7346927)
Hmmm.... Are you sure you don't have a CD or DVD in your drive that it's trying to boot to? Or another HD with a Vista install on it? This is really bizarre...

Positive there's no cd in there.




any idea on the "memory" defrag/anti virus stuff?

Bearcat 01-11-2011 03:23 PM

Quote:

Originally Posted by Sofa King (Post 7346879)
negative. i didn't have it installed because i thought malwarebytes was the almighty.

now i can't get into safe to download it, and it wont let me do it out of safe mode either.

Yeah, the Safe Mode issue is strange... you might check out the 2nd to last section in the OP about the BSoD when going into Safe Mode. It does seem like something else is going on, but you might try restoring those registry keys and trying again.

What do you mean by it won't let you download it? Are you being redirected when you click the link in the OP, you can't connect to the internet, you can download it but can't install it... ?

This link includes HiJackThis... http://www.elitekiller.com/files/rogueremoval.zip

You might need to find a recordable CD or DVD... you could download and burn them from another computer, and try installing them that way.

Sofa King 01-11-2011 03:48 PM

Alrighty. I did a system restore, and it got rid of some of the issues, except now my symantec, which was the only thing that found something, is disabled and i can't get it turned back on.

Now i have managed to get my stuff off of my usb card, so now i have a hijack this report, but i'm very leary about hooking that comp back up to the internet. the whole "your private data is at risk" warning made me gun shy.

any idea what i should look for in the report? i'm trying to find a way to print it, scan it, and then upload the scan to the other comp, but no luck so far.

Sofa King 01-11-2011 04:12 PM

just occured to me... my scanner is hooked up to the bad comp... FML...

i'm not going to transfer this to my billing comp...

Fish 01-11-2011 05:40 PM

Quote:

Originally Posted by Sofa King (Post 7347049)
Alrighty. I did a system restore, and it got rid of some of the issues, except now my symantec, which was the only thing that found something, is disabled and i can't get it turned back on.

Now i have managed to get my stuff off of my usb card, so now i have a hijack this report, but i'm very leary about hooking that comp back up to the internet. the whole "your private data is at risk" warning made me gun shy.

any idea what i should look for in the report? i'm trying to find a way to print it, scan it, and then upload the scan to the other comp, but no luck so far.

The bug might have hosed Symantec. You may have to reinstall it.

It's not really worth it to try and tell you what to look for in your HijackThis log. There's too many possibilities to begin. We'll have to look at it and see what doesn't belong, as opposed to telling you what could be there. But I don't think you have anything to worry about by hooking it back up to the internet. The "Your private data is at risk" statement is slightly over dramatized. A HijackThis log only collects system and application data. It doesn't really do anything else. It will show every program that's running on your computer at that moment. That's about as personal as the information gets. There's zero harm in doing so, unless you just don't want people to know what apps you're running.

Sofa King 01-11-2011 05:52 PM

i forgot i had this pile of crap laptop. i don't care if this things blows up, so i transfered the info the the card and took it home.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:51:33 PM, on 1/11/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17093)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sharp\Button Manager T\btnman.exe
F:\rogueremoval\HiJack This\HijackThis.exe
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
F:\rogueremoval\Sysinternals\ProcessExplorer\procexp.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SescLU.exe
C:\WINDOWS\explorer.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USREL/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = http://g.msn.com/USREL/1
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:59274
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Sharp Button Manager T.lnk = C:\Program Files\Sharp\Button Manager T\btnman.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1250961608046
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{83B5B9D7-CF40-4A93-849D-3652116F7768}: NameServer = 64.251.191.5,64.251.160.2
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe

--
End of file - 7452 bytes

Sofa King 01-11-2011 05:53 PM

perhaps a dumb question, but if i turn the internet back on that comp, can the virus/whatever transfer basically anything they want to from the comp? can they transfer anything? info, saved passwords, etc?

Mr. Laz 01-11-2011 05:55 PM

Quote:

Originally Posted by Sofa King (Post 7347434)
perhaps a dumb question, but if i turn the internet back on that comp, can the virus/whatever transfer basically anything they want to from the comp? can they transfer anything? info, saved passwords, etc?

Yes, if that is what the virus is programmed to do.

Fish 01-11-2011 06:09 PM

Quote:

Originally Posted by Sofa King (Post 7347432)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:59274

Looks like you have a proxy server set. If you didn't intentionally set that, you might want to turn it off.

Go to Control Panel\Internet Options\Connections\LAN settings
Uncheck the box that says Use Proxy server at the bottom.
The only thing on that LAN settings page that should be checked is Automatically detect settings.

Other than that, your log file looks pretty clean. Nothing really sticks out.

Fish 01-11-2011 06:17 PM

Quote:

Originally Posted by Sofa King (Post 7347434)
perhaps a dumb question, but if i turn the internet back on that comp, can the virus/whatever transfer basically anything they want to from the comp? can they transfer anything? info, saved passwords, etc?

Not really. In the old days, there were apps like Back Orifice, in which you could do stuff like that. But it's been patched since the days of Win95. To do what you're indicating, someone would have to have physical access to the computer and manually load things without your knowledge. You're not going to catch a bug while watching gay midget porn that would have the capabilities of that. It's possible, but so unlikely that you shouldn't worry about it.

Sofa King 01-11-2011 06:23 PM

well that's good. i was actually really suprised to see the system restore worked as well as it did while not in safe mode. i figured it was changed or something. hopefully it wasn't just something set deep in the comp that will appear again next time i turn the comp on, on a certain date or something. can't believe malwarebytes wasn't working.

what has me snowed is the fact that i can't turn my antivirus back on. and that Rkill keeps terminating some program still.

i guess i'll work on it some more tomorrow or friday. thanks for the help.

Sofa King 01-11-2011 06:25 PM

Quote:

Originally Posted by KC Fish (Post 7347481)
Not really. In the old days, there were apps like Back Orifice, in which you could do stuff like that. But it's been patched since the days of Win95. To do what you're indicating, someone would have to have physical access to the computer and manually load things without your knowledge. You're not going to catch a bug while watching gay midget porn that would have the capabilities of that. It's possible, but so unlikely that you shouldn't worry about it.

LMAO. you caught me. i love me some midgets.


actually, i believe i got it when i was trying to look for pics of that sexy blonde oregon cheerleader with the sexy eyes.

i havent had an erection last that long since the days of middle school.

markmax 01-24-2011 07:26 AM

Hi,

Thanks a lot dude.Actually I was searching such type of tools.

Sure-Oz 01-24-2011 07:04 PM

Anyone heard of this bitch called 'windows utility tool'? I got this shit popping up on my dads cpu...he has avast on it and malware bytes but the ****er wont let him run them.

Sure-Oz 01-24-2011 07:47 PM

http://www.bleepingcomputer.com/viru...s-utility-tool

found this to help but in safe mode im crippled...wont let me run shit and if i start it exits out ****

Sure-Oz 01-24-2011 07:51 PM

This ****er even turned off system restore god damnit

Sure-Oz 01-24-2011 07:53 PM

Crossing my fingers system restore works from a few days ago so i can run shit

Sure-Oz 01-24-2011 07:57 PM

Desktop just sitting here doing nothing, awesome

Sure-Oz 01-24-2011 08:00 PM

Well **** me its loading....run malware bytes run (crosses fingers)

Sure-Oz 01-24-2011 08:18 PM

Ok i ran a system restore to a previous date now running malwarebytes updated full scan, i assume if it doesnt find shit and avast already removed a few things prior to the infection will it be ok to use?

Bearcat 01-24-2011 10:11 PM

Quote:

Originally Posted by Sure-Oz (Post 7381327)
Ok i ran a system restore to a previous date now running malwarebytes updated full scan, i assume if it doesnt find shit and avast already removed a few things prior to the infection will it be ok to use?

Glad we could help. :D

If Safe Mode is working, I'd run the scan there, and you could post a HiJackThis log, too.

Sure-Oz 01-24-2011 10:13 PM

Quote:

Originally Posted by Bearcat (Post 7381558)
Glad we could help. :D

If Safe Mode is working, I'd run the scan there, and you could post a HiJackThis log, too.

Going to run safe mode now and run malware bytes

here is the current hijack this

Ok, did a system restore to like 4 days ago since that stupid windows utility tool malware was not letting me do ****. Ran an updated version of malware bytes and it removed 2 trojans. Ran Spybot and it removed 1 file as well, and avast ran a full scan as well and found 1 html file and all were removed and the pc rebooted and scanned again.

Here is the hijack this...super cpu guys see anything out of the ordinary?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:09:27 PM, on 1/24/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Documents and Settings\Shizzy.HOME\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.35.1.253:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: GoZone iSync.lnk = C:\Program Files\GoZone\GoZone_iSync.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1242228432890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1242343626562
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSC...ws-i586-jc.cab
O16 - DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} (WebSlingPlayer) - http://plugin.slingbox.com/downloads...lingPlayer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe

--
End of file - 8163 bytes
__________________

Sure-Oz 01-24-2011 10:35 PM

Malware Bytes full scan came up clean on safe mode. So far so good

Bearcat 01-24-2011 10:54 PM

Quote:

Originally Posted by Sure-Oz (Post 7381563)
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 10.35.1.253:80
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

If you're not intentionally going through a proxy server, delete those.

Quote:

Originally Posted by Sure-Oz (Post 7381563)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)

Everything else looks good... you can delete those two BHO (no name) entries, just to clean up.


If you want it to start up a little faster, you could get rid of the O4 - HKLM entries for QuickTime, Adobe, and iTunes (or uncheck them in msconfig), and go to Start -> Run -> services.msc and set the Apple/Bounjour/iPod services to Manual. But, it's XP, so there probably won't be much of a difference.... I'm just anal about Apple processes. :)

I usually run them until I get one good clean scan, so looks like you're set.

Sure-Oz 01-24-2011 10:59 PM

Quote:

Originally Posted by Bearcat (Post 7381613)
If you're not intentionally going through a proxy server, delete those.



Everything else looks good... you can delete those two BHO (no name) entries, just to clean up.


If you want it to start up a little faster, you could get rid of the O4 - HKLM entries for QuickTime, Adobe, and iTunes (or uncheck them in msconfig), and go to Start -> Run -> services.msc and set the Apple/Bounjour/iPod services to Manual. But, it's XP, so there probably won't be much of a difference.... I'm just anal about Apple processes. :)

I usually run them until I get one good clean scan, so looks like you're set.

Thanks for your help man, appreciate it! :)

Sure-Oz 01-24-2011 11:16 PM

As for the proxy server, im not sure it's intentional or not. Dad has has a DSL router/modem in 1 from at&t yahoo and has multiple pcs and phones connected. Would removing the proxy stuff above effect any of that?

Bearcat 01-24-2011 11:44 PM

Quote:

Originally Posted by Sure-Oz (Post 7381636)
As for the proxy server, im not sure it's intentional or not. Dad has has a DSL router/modem in 1 from at&t yahoo and has multiple pcs and phones connected. Would removing the proxy stuff above effect any of that?

I can't tell you for sure... my guess is those entries remain from the malware, but I couldn't tell you if your dad has a use for it.

If he's not aware of needing a proxy server, it's safe to delete them and easy to replace them later. You would just need to go to that location in regedit and recreate those keys.

Sure-Oz 01-25-2011 12:40 AM

Quote:

Originally Posted by Bearcat (Post 7381657)
I can't tell you for sure... my guess is those entries remain from the malware, but I couldn't tell you if your dad has a use for it.

If he's not aware of needing a proxy server, it's safe to delete them and easy to replace them later. You would just need to go to that location in regedit and recreate those keys.

I assume there is no use for them, my dad is not cpu savy at all and i assume the router didn't create those on its own.

Bearcat 01-27-2011 06:00 PM

I'm updating the OP. I added the online analyze for HiJackThis, and I'm going to add some stuff about Windows services and msconfig.

So, keep the suggestions coming, and I'll try to update it more often... and if you've already suggested something that's not in the OP and you still think it should be included, suggest it again and the worst I'll do is ignore it again. :D

RedNFeisty 01-31-2011 10:52 PM

Question, after reading EliteKille, it suggests I may need to reinstall an OS, but I am using a little tiny notepad that does not have a disk drive. So, I can not put in a disk to reinstall anything....suggestions??

Awesome Thread, btw!

chasedude 02-08-2011 02:59 PM

Quote:

Originally Posted by RedNFeisty (Post 7397061)
Question, after reading EliteKille, it suggests I may need to reinstall an OS, but I am using a little tiny notepad that does not have a disk drive. So, I can not put in a disk to reinstall anything....suggestions??

Awesome Thread, btw!

I've never tried it but it might be possible to load the disk onto a USB flash drive. Of course you would need another computer to do this.

You could then boot your laptop to USB using the flash drive and load the OS that way.

I have loaded OS's through the network before.

Sure-Oz 02-26-2011 03:05 PM

I copied this from another forum: since my dads pc has this exact issue:

cant hyperlink from search engine (google). it redirects me to ads or other pages and says url fraudcheck in the information bar at the bottom of the screen.

browser has been hijacked. any ideas to rectify this. done malwarebytes scan and antivirus and super antispyware scan. still the same

Any ideas? ran malwarebytes, avast antivirus scan and spybot nothing found.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 3:05:30 PM, on 2/26/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Motive\McciCMService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Documents and Settings\Shizzy.HOME\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [HitmanPro35] "C:\Program Files\Hitman Pro 3.5\HitmanPro35.exe" /scan:boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: GoZone iSync.lnk = C:\Program Files\GoZone\GoZone_iSync.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OneNote Table Of Contents.onetoc2
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1242228432890
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1242343626562
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-09.sun.com/s/ESD7/JSC...ws-i586-jc.cab
O16 - DPF: {B80CD4E6-5B02-4B6C-99BE-68F1511E9549} (WebSlingPlayer) - http://plugin.slingbox.com/downloads...lingPlayer.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe...bat/nos/gp.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe

--
End of file - 8186 bytes

QuikSsurfer 02-26-2011 05:36 PM

Quote:

Originally Posted by Sure-Oz (Post 7454846)
I copied this from another forum: since my dads pc has this exact issue:

cant hyperlink from search engine (google). it redirects me to ads or other pages and says url fraudcheck in the information bar at the bottom of the screen.

Sounds like a corrupt host file..

check the entries in the file
c:\Windows\System32\drivers\etc\hosts

select to open with notepad --- copy and paste the jazz here.

chasedude 03-03-2011 12:43 PM

Quote:

Originally Posted by Sure-Oz (Post 7454846)
I copied this from another forum: since my dads pc has this exact issue:

cant hyperlink from search engine (google). it redirects me to ads or other pages and says url fraudcheck in the information bar at the bottom of the screen.

This maybe nothing but I notice both McAFee and Avast programs listed.

I'm assuming you've loaded avast after the McAfee script ran out.

I have had systems run into conflicts before with 2 different antivirus' running.

See if a uninstall of McAfee and a reboot can help in your troubles.

This may not be a fix for your situation, but when troubleshooting these damn machines it's worth a step to try.

Good Luck!

ThaVirus 04-01-2011 07:53 PM

Ok, so I ran into a virus thing today. Was browsing the web and all of a sudden my comp started telling me my hard drive had failed and all kinds of crazy stuff. So some WindowsHelper thing popped up and began "searching for any problems" and "found" 11 of them. It looked legit and wouldn't let me touch anything else so I clicked OK like a dumbass. Then shit started ****ing up and got even worse.

Anyway, I started the Task Manager and found a couple odd programs running: one of which was "483080805740..." (a bunch of numbers-not accurate) and another "A1Ashfjdhf..." (a bunch of letters-again not accurate). So I ended the processes and was able to open other things in my comp again. After I updated Malware Bytes I ran the check and it found 5 problems (2 of which were the ones already mentioned and the other 3 I didn't recognize). Anyway, I removed them and now I can access all processes of my comp.

Here's the issue: all of my data and files have been wiped out. Since my comp is just for schoolwork, music and browsing the web I didn't have many important files saved in the first place so I'm fine with that. The thing is, when I move the cursor over any of the folders- let's just say Music- all of the information pertaining to it shows up. So it says my Music folder has 9.84 GBs worth of files and when it was created and all of that, but none of it is showing up. All of my songs even exist and play perfectly in iTunes, it's pretty bizarre.

I've been browsing the web on how to restore lost information and am not computer savy enough to figure out their instructions. I haven't run any "System Restore" or "Recovery" programs yet. So my questions to you guys are:
1. Is there anyway to recover all of my "lost" data and files?
2. Since Malware apparently deleted any traces of the virus, is it safe to be browsing on the same comp again? (Which I'm doing now, by the way)
3. I've accessed my credit card/bank accounts and have applied for several jobs on this comp (so I've entered in a lot of my personal information). I have never saved any of this information or any of these passwords (just entered them in and submitted them) so is there anyway that this virus possibly could have stolen any of that info?

***EDIT: As I said earlier, none of the files on the comp were extremely vital to me so I never ran any backup, transferring of the files to an external hard drive, etc. I'm sure that will come back to bite me in the ass now but I figured it was pertinent information for you to help me.

Bearcat 04-01-2011 08:31 PM

Quote:

Originally Posted by ThaVirus (Post 7532130)
Ok, so I ran into a virus thing today. Was browsing the web and all of a sudden my comp started telling me my hard drive had failed and all kinds of crazy stuff. So some WindowsHelper thing popped up and began "searching for any problems" and "found" 11 of them. It looked legit and wouldn't let me touch anything else so I clicked OK like a dumbass. Then shit started ****ing up and got even worse.

Anyway, I started the Task Manager and found a couple odd programs running: one of which was "483080805740..." (a bunch of numbers-not accurate) and another "A1Ashfjdhf..." (a bunch of letters-again not accurate). So I ended the processes and was able to open other things in my comp again. After I updated Malware Bytes I ran the check and it found 5 problems (2 of which were the ones already mentioned and the other 3 I didn't recognize). Anyway, I removed them and now I can access all processes of my comp.

Here's the issue: all of my data and files have been wiped out. Since my comp is just for schoolwork, music and browsing the web I didn't have many important files saved in the first place so I'm fine with that. The thing is, when I move the cursor over any of the folders- let's just say Music- all of the information pertaining to it shows up. So it says my Music folder has 9.84 GBs worth of files and when it was created and all of that, but none of it is showing up. All of my songs even exist and play perfectly in iTunes, it's pretty bizarre.

I've been browsing the web on how to restore lost information and am not computer savy enough to figure out their instructions. I haven't run any "System Restore" or "Recovery" programs yet. So my questions to you guys are:
1. Is there anyway to recover all of my "lost" data and files?
2. Since Malware apparently deleted any traces of the virus, is it safe to be browsing on the same comp again? (Which I'm doing now, by the way)
3. I've accessed my credit card/bank accounts and have applied for several jobs on this comp (so I've entered in a lot of my personal information). I have never saved any of this information or any of these passwords (just entered them in and submitted them) so is there anyway that this virus possibly could have stolen any of that info?

***EDIT: As I said earlier, none of the files on the comp were extremely vital to me so I never ran any backup, transferring of the files to an external hard drive, etc. I'm sure that will come back to bite me in the ass now but I figured it was pertinent information for you to help me.

Windows XP or 7?

I'm taking off soon, so don't know how much detail I'll be able to get into.... if you Google 'Windows XP restore' or 'Windows 7 restore', you can find info on how to do a restore. That will restore your computer back to a certain date, so you would lose anything new from that date until today. If you have Windows CDs, you could also do a fresh install, which would obviously delete everything.

As far as the virus, I wouldn't assume it's gone. I would follow some of the instructions in the OP... look at the elitekiller site, download the toolkit, and run the scans from Safe Mode (reboot and press f8 a few times (it's in the OP, too)).

As far as the files... the folder says there's stuff in it, but you don't see anything? Usually if it's corrupt, you'll at least see icons, but either way... if they're gone or corrupt, you're probably SOL.

As far as the personal information, I doubt any of it is at risk... you could always change important passwords, but if you haven't saved bank/CC info anywhere on the PC, I wouldn't worry about it.


So.... for a basic gameplan,
1) I think a restore is your best option at this point, and Google (or someone who's going to be here later tonight) should be able to help you there... if you're not comfortable doing what Google says, or need verification on anything, feel free to post it here, but you might have to wait a little while for feedback.

2) If you're not doing the restore right away, while you're waiting, I'd look at the OP and run the scans in Safe Mode... that will at least get you to a point where your computer is cleaned up, and there's a smaller risk of something else going wrong.

ThaVirus 04-01-2011 08:48 PM

Thanks for the prompt response, my man. I'm getting ready to hit the town so I'll take a look at all that stuff tomorrow.. Let you guys know how it goes.

Bearcat 04-04-2011 05:34 PM

Quote:

Originally Posted by ThaVirus (Post 7532278)
Thanks for the prompt response, my man. I'm getting ready to hit the town so I'll take a look at all that stuff tomorrow.. Let you guys know how it goes.

Did you get it fixed?

salame 04-10-2011 02:17 AM

****ing malware man

Bowser 04-11-2011 02:19 PM

Ok, so my avast starts going apeshit with a malware warning. I open it up, delete it, restart, and get to a window where everything looks like it's from 1988, asking if I want to delete the problem. I click yes, and it goes nuts deleting stuff. Now, I am looking at a line that reads thusly -

File C:\windows\help\mui\0409\aclui.CHM>html\066cfb1-0e68-40bb-b889-6268f1308575.htm is infected by HTML:Script-inf
File is in windows folder, are you sure?
1-Yes, 2-Yes all, 3-No, Esc-Exit :

I have no idea where this shit is. I'm assuming I click yes all, but is that right? (And btw, the avast went apeshit on me as soon as I left ChiefsPlanet)

QuikSsurfer 04-11-2011 02:21 PM

run hijackthis and post your log here please

http://www.trendmicro.com/ftp/produc...HijackThis.exe

Bowser 04-11-2011 02:28 PM

Quote:

Originally Posted by QuikSsurfer (Post 7554481)
run hijackthis and post your log here please

http://www.trendmicro.com/ftp/produc...HijackThis.exe

Me? I will as soon as I answer the question it asked me about a file being in a windows folder, which I'm not sure if it is. That was what I was asking in the post - do I click yes, yes all, no, or just escape out of it? (And apologies for my lack of 'puter knowledge. It's kinda like trying to teach a kindergartner trigonometry sometimes with me)

Fish 04-11-2011 02:38 PM

Quote:

Originally Posted by Bowser (Post 7554474)
Ok, so my avast starts going apeshit with a malware warning. I open it up, delete it, restart, and get to a window where everything looks like it's from 1988, asking if I want to delete the problem. I click yes, and it goes nuts deleting stuff. Now, I am looking at a line that reads thusly -

File C:\windows\help\mui\0409\aclui.CHM>html\066cfb1-0e68-40bb-b889-6268f1308575.htm is infected by HTML:Script-inf
File is in windows folder, are you sure?
1-Yes, 2-Yes all, 3-No, Esc-Exit :

I have no idea where this shit is. I'm assuming I click yes all, but is that right? (And btw, the avast went apeshit on me as soon as I left ChiefsPlanet)

Sounds like you have malware that's spoofing Windows system messages, and you just clicked yes to it.

If you don't see anything on the message box that's branding it as from a legit source(Avast, Microsoft, etc.), then I'd cancel out of it and run Malwarebytes first thing.

thecoffeeguy 04-11-2011 02:41 PM

Quote:

Originally Posted by Bowser (Post 7554474)
Ok, so my avast starts going apeshit with a malware warning. I open it up, delete it, restart, and get to a window where everything looks like it's from 1988, asking if I want to delete the problem. I click yes, and it goes nuts deleting stuff. Now, I am looking at a line that reads thusly -

File C:\windows\help\mui\0409\aclui.CHM>html\066cfb1-0e68-40bb-b889-6268f1308575.htm is infected by HTML:Script-inf
File is in windows folder, are you sure?
1-Yes, 2-Yes all, 3-No, Esc-Exit :

I have no idea where this shit is. I'm assuming I click yes all, but is that right? (And btw, the avast went apeshit on me as soon as I left ChiefsPlanet)

Sounds like Fake Anti-virus warning. Shit load of it is going around as a result of Lizamoon

Download Microsoft Security Essentials (Yes Microsoft), update the definitions and run a full scan.

Security essentials is very very good at finding this nasty stuff believe it or not.

Bowser 04-11-2011 02:43 PM

Quote:

Originally Posted by KC Fish (Post 7554530)
Sounds like you have malware that's spoofing Windows system messages, and you just clicked yes to it.

If you don't see anything on the message box that's branding it as from a legit source(Avast, Microsoft, etc.), then I'd cancel out of it and run Malwarebytes first thing.

Awesome. Here's a line right on the screen that's right over the question -

File C:\users\owner\AppData\Local\Temp\nss778A.tmp\Setup.dll is infected by win32: PUP-gen [PUP]
Deleted

So, I am to escape out of this, dowload Malwarebytes, and run it as soon as possible, yes?

Bowser 04-11-2011 02:45 PM

Quote:

Originally Posted by thecoffeeguy (Post 7554537)
Sounds like Fake Anti-virus warning. Shit load of it is going around as a result of Lizamoon

Download Microsoft Security Essentials (Yes Microsoft), update the definitions and run a full scan.

Security essentials is very very good at finding this nasty stuff believe it or not.

Cool. I'll get that one, too.

Is it any coincidence that I downloaded IE 9 like two days ago that this shit is happening?

Fish 04-11-2011 02:49 PM

Quote:

Originally Posted by Bowser (Post 7554546)
Awesome. Here's a line right on the screen that's right over the question -

File C:\users\owner\AppData\Local\Temp\nss778A.tmp\Setup.dll is infected by win32: PUP-gen [PUP]
Deleted

So, I am to escape out of this, dowload Malwarebytes, and run it as soon as possible, yes?

Yes.

Fish 04-11-2011 02:49 PM

Quote:

Originally Posted by Bowser (Post 7554548)
Cool. I'll get that one, too.

Is it any coincidence that I downloaded IE 9 like two days ago that this shit is happening?

No.

QuikSsurfer 04-11-2011 02:55 PM

Quote:

Originally Posted by Bowser (Post 7554502)
Me? I will as soon as I answer the question it asked me about a file being in a windows folder, which I'm not sure if it is. That was what I was asking in the post - do I click yes, yes all, no, or just escape out of it? (And apologies for my lack of 'puter knowledge. It's kinda like trying to teach a kindergartner trigonometry sometimes with me)

It's a rogue (fake av). And you'd be better off running a updated ver of malwarebytes in safe mode.

Fish 04-11-2011 03:03 PM

I would like to reiterate what a great investment it is to purchase the full version of Malwarebytes Anti-Malware.

It's only $25, and that gives you a version of Malwarebytes that is always running, and scans each file you access in real-time exactly like your virus scanner does. This catches spyware and malware before it has a chance to infect anything. This program has completely eliminated monthly visits to fix my grandmother's computer. And I can't tell you how much of an accomplishment and endorsement for the product that is.

https://store.malwarebytes.org/342/p...am_page_button

Bowser 04-11-2011 03:14 PM

This is interesting. Everytime I go to try and get to MS's website, avast pops up with a malware warning....

Bowser 04-11-2011 03:15 PM

And I'm gonna take you up on your recommendation, Fish. Our desktop is relatively new, and I don't want it to get fried out.

Fish 04-11-2011 03:27 PM

If the malware has infected the machine, it may be screwing with your internet settings. Hence the malware warning when viewing the M$ site. I'd download Malwarebytes, then reboot into Safe Mode and run Malwarebytes from there. Then after you've run a complete scan in Safe Mode and hopefully removed the malware, I'd boot back up normally and run it again.

And you won't be disappointed with Malwarebytes Pro. It's worth every stinkin penny IMO....

Sure-Oz 04-11-2011 03:28 PM

My dads cpu is getting alot of avast shit too saying its blocked like js shit like 200 times...while malwarebytes was running it popped up 20 times.

running spybot, and malwarebytes in safe right now...going to dl microsoft sec. essentials next. Also spybot found and removed a browser hijacker registry on svchost or whatever.

Fish 04-11-2011 03:38 PM

Once you run Malwarebytes Pro a little while, you'll be shocked at the frequency of the attack attempts on your machine. It will pop up a little dialog box every time it blocks something harmful. Which you'll eventually have to turn the dialog box off, because it's popping up all the damn time and becomes annoying. But it serves as a good reminder of how much harmful shit is out there waiting to exploit something on your machine.

Fish 04-11-2011 03:44 PM

Also, while this thread is humming....

If you haven't upgraded Firefox >= 3.6.16, you really should do so. There was an SSL certificate authority that was recently compromised, and some legit certificates were stolen. Some of which includes <!--[if gte mso 9]><xml> <o:OfficeDocumentSettings> <o:AllowPNG/> </o:OfficeDocumentSettings> </xml><![endif]--><!--[if gte mso 9]><xml> <w:WordDocument> <w:View>Normal</w:View> <w:Zoom>0</w:Zoom> <w:TrackMoves/> <w:TrackFormatting/> <w:PunctuationKerning/> <w:ValidateAgainstSchemas/> <w:SaveIfXMLInvalid>false</w:SaveIfXMLInvalid> <w:IgnoreMixedContent>false</w:IgnoreMixedContent> <w:AlwaysShowPlaceholderText>false</w:AlwaysShowPlaceholderText> <w:DoNotPromoteQF/> <w:LidThemeOther>EN-US</w:LidThemeOther> <w:LidThemeAsian>X-NONE</w:LidThemeAsian> <w:LidThemeComplexScript>X-NONE</w:LidThemeComplexScript> <w:Compatibility> <w:BreakWrappedTables/> <w:SnapToGridInCell/> <w:WrapTextWithPunct/> <w:UseAsianBreakRules/> <w:DontGrowAutofit/> <w:SplitPgBreakAndParaMark/> <w:EnableOpenTypeKerning/> <w:DontFlipMirrorIndents/> <w:OverrideTableStyleHps/> </w:Compatibility> <w:DoNotOptimizeForBrowser/> <m:mathPr> <m:mathFont m:val="Cambria Math"/> <m:brkBin m:val="before"/> <m:brkBinSub m:val="&#45;-"/> <m:smallFrac m:val="off"/> <m:dispDef/> <m:lMargin m:val="0"/> <m:rMargin m:val="0"/> <m:defJc m:val="centerGroup"/> <m:wrapIndent m:val="1440"/> <m:intLim m:val="subSup"/> <m:naryLim m:val="undOvr"/> </m:mathPr></w:WordDocument> </xml><![endif]--><!--[if gte mso 9]><xml> <w:LatentStyles DefLockedState="false" DefUnhideWhenUsed="true" DefSemiHidden="true" DefQFormat="false" DefPriority="99" LatentStyleCount="267"> <w:LsdException Locked="false" Priority="0" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Normal"/> <w:LsdException Locked="false" Priority="9" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="heading 1"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 2"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 3"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 4"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 5"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 6"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 7"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 8"/> <w:LsdException Locked="false" Priority="9" QFormat="true" Name="heading 9"/> <w:LsdException Locked="false" Priority="39" Name="toc 1"/> <w:LsdException Locked="false" Priority="39" Name="toc 2"/> <w:LsdException Locked="false" Priority="39" Name="toc 3"/> <w:LsdException Locked="false" Priority="39" Name="toc 4"/> <w:LsdException Locked="false" Priority="39" Name="toc 5"/> <w:LsdException Locked="false" Priority="39" Name="toc 6"/> <w:LsdException Locked="false" Priority="39" Name="toc 7"/> <w:LsdException Locked="false" Priority="39" Name="toc 8"/> <w:LsdException Locked="false" Priority="39" Name="toc 9"/> <w:LsdException Locked="false" Priority="35" QFormat="true" Name="caption"/> <w:LsdException Locked="false" Priority="10" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Title"/> <w:LsdException Locked="false" Priority="1" Name="Default Paragraph Font"/> <w:LsdException Locked="false" Priority="11" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Subtitle"/> <w:LsdException Locked="false" Priority="22" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Strong"/> <w:LsdException Locked="false" Priority="20" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Emphasis"/> <w:LsdException Locked="false" Priority="59" SemiHidden="false" UnhideWhenUsed="false" Name="Table Grid"/> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Placeholder Text"/> <w:LsdException Locked="false" Priority="1" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="No Spacing"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading Accent 1"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List Accent 1"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid Accent 1"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1 Accent 1"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2 Accent 1"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1 Accent 1"/> <w:LsdException Locked="false" UnhideWhenUsed="false" Name="Revision"/> <w:LsdException Locked="false" Priority="34" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="List Paragraph"/> <w:LsdException Locked="false" Priority="29" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Quote"/> <w:LsdException Locked="false" Priority="30" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Intense Quote"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2 Accent 1"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1 Accent 1"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2 Accent 1"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3 Accent 1"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List Accent 1"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading Accent 1"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List Accent 1"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid Accent 1"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading Accent 2"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List Accent 2"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid Accent 2"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1 Accent 2"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2 Accent 2"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1 Accent 2"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2 Accent 2"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1 Accent 2"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2 Accent 2"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3 Accent 2"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List Accent 2"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading Accent 2"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List Accent 2"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid Accent 2"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading Accent 3"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List Accent 3"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid Accent 3"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1 Accent 3"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2 Accent 3"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1 Accent 3"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2 Accent 3"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1 Accent 3"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2 Accent 3"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3 Accent 3"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List Accent 3"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading Accent 3"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List Accent 3"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid Accent 3"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading Accent 4"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List Accent 4"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid Accent 4"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1 Accent 4"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2 Accent 4"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1 Accent 4"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2 Accent 4"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1 Accent 4"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2 Accent 4"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3 Accent 4"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List Accent 4"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading Accent 4"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List Accent 4"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid Accent 4"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading Accent 5"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List Accent 5"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid Accent 5"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1 Accent 5"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2 Accent 5"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1 Accent 5"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2 Accent 5"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1 Accent 5"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2 Accent 5"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3 Accent 5"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List Accent 5"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading Accent 5"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List Accent 5"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid Accent 5"/> <w:LsdException Locked="false" Priority="60" SemiHidden="false" UnhideWhenUsed="false" Name="Light Shading Accent 6"/> <w:LsdException Locked="false" Priority="61" SemiHidden="false" UnhideWhenUsed="false" Name="Light List Accent 6"/> <w:LsdException Locked="false" Priority="62" SemiHidden="false" UnhideWhenUsed="false" Name="Light Grid Accent 6"/> <w:LsdException Locked="false" Priority="63" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 1 Accent 6"/> <w:LsdException Locked="false" Priority="64" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Shading 2 Accent 6"/> <w:LsdException Locked="false" Priority="65" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 1 Accent 6"/> <w:LsdException Locked="false" Priority="66" SemiHidden="false" UnhideWhenUsed="false" Name="Medium List 2 Accent 6"/> <w:LsdException Locked="false" Priority="67" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 1 Accent 6"/> <w:LsdException Locked="false" Priority="68" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 2 Accent 6"/> <w:LsdException Locked="false" Priority="69" SemiHidden="false" UnhideWhenUsed="false" Name="Medium Grid 3 Accent 6"/> <w:LsdException Locked="false" Priority="70" SemiHidden="false" UnhideWhenUsed="false" Name="Dark List Accent 6"/> <w:LsdException Locked="false" Priority="71" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Shading Accent 6"/> <w:LsdException Locked="false" Priority="72" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful List Accent 6"/> <w:LsdException Locked="false" Priority="73" SemiHidden="false" UnhideWhenUsed="false" Name="Colorful Grid Accent 6"/> <w:LsdException Locked="false" Priority="19" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Subtle Emphasis"/> <w:LsdException Locked="false" Priority="21" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Intense Emphasis"/> <w:LsdException Locked="false" Priority="31" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Subtle Reference"/> <w:LsdException Locked="false" Priority="32" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Intense Reference"/> <w:LsdException Locked="false" Priority="33" SemiHidden="false" UnhideWhenUsed="false" QFormat="true" Name="Book Title"/> <w:LsdException Locked="false" Priority="37" Name="Bibliography"/> <w:LsdException Locked="false" Priority="39" QFormat="true" Name="TOC Heading"/> </w:LatentStyles> </xml><![endif]--><!--[if gte mso 10]> <style> /* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;} </style> <![endif]-->login.live.com, login.yahoo.com, login.skype.com, and mail.google.com. Meaning that those pages could potentially be spoofed and you'd never know the difference, giving hackers your info.

Both Firefox and IE could be affected by this. So if you haven't updated your browser recently, DO IT NOW!

More info:

http://www.microsoft.com/technet/sec...y/2524375.mspx

http://blog.mozilla.com/security/201...-certificates/

Sure-Oz 04-11-2011 03:46 PM

Ran Malware bytes in safe along with spybot and it was clean. if i go to the cc cleaner website or microsoft security essentials avast keeps detecting that its a bad site and stops it, weird!

i got sec. essentials another way and am installing

Sure-Oz 04-11-2011 04:17 PM

Well i ran MSE as well as malwarebytes, spybot S&D and nothing has been found, no threats. I noticed now avast isnt going batshit crazy by trying to open the MSE site or CC Cleaner site. weird

Sure-Oz 04-11-2011 04:17 PM

Quote:

Originally Posted by Bowser (Post 7554653)
This is interesting. Everytime I go to try and get to MS's website, avast pops up with a malware warning....

Is yours still doing that?

Galileo Humpkins 04-11-2011 05:24 PM

For anyone still experiencing issues with Avast, I would recommend reading this blog update:

https://blog.avast.com/2011/04/11/fa...defs-110411-1/

Had the same issue with another computer I oversee earlier today. If you do a manual update of Avast, the pop-up error should disappear.

Sure-Oz 04-11-2011 05:28 PM

Quote:

Originally Posted by Galileo Humpkins (Post 7554932)
For anyone still experiencing issues with Avast, I would recommend reading this blog update:

https://blog.avast.com/2011/04/11/fa...defs-110411-1/

Had the same issue with another computer I oversee earlier today. If you do a manual update of Avast, the pop-up error should disappear.

Excellent, that explains why its stopped now. Thank You.

Dayze 04-11-2011 07:39 PM

...so, how bad is it?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:38:39 PM, on 4/11/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\vsnp2uvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Brad\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IA82SPBQ\HijackThis[1].exe
C:\Windows\system32\SearchProtocolHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://chiefsplanet.com/BB/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9158 bytes

Sure-Oz 04-11-2011 08:00 PM

So i guess all those false positives with avast put a bunch of .js files from the temp internet files in there, i assume its safe to leave it there? they show no viruses but there is so many of them that i can't restore all without manually selecting since some are real malware viruses from the past.

DaFace 04-11-2011 09:09 PM

On a random Avast side note, any of you ever had it lose its ability to access the internet? I got a little minor gremlin a week or so ago. I removed it immediately, and it really didn't do anything, but somewhere in the removal process something got screwy. Avast won't update, and if I turn the web shield on, all my browsers are blocked.

I've done a full uninstall/reinstall, all of the typical scanners come up clean, everything seems fine, etc. Hosts file is fine. Hijack this doesn't seem to have anything out of the ordinary. Everything works fine except that one program. I almost don't even care (it's just my media center pc), but it's got me stumped.

chasedude 04-13-2011 01:14 PM

Quote:

Originally Posted by Dayze (Post 7555233)
...so, how bad is it?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:38:39 PM, on 4/11/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19019)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\system32\WerCon.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\vsnp2uvc.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Brad\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IA82SPBQ\HijackThis[1].exe
C:\Windows\system32\SearchProtocolHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://chiefsplanet.com/BB/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\IPSBHO.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\coIEPlg.dll
O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: HP Connections.lnk = C:\Program Files\HP Connections\6811507\Program\HP Connections.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...Uploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intuit Update Service (IntuitUpdateService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Alcatel-Lucent - C:\Program Files\Common Files\Motive\McciCMService.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.8.0.5\ccSvcHst.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 9158 bytes

I uploaded your log file to the site I get my recommendations from
hijackthis.de and didn't see anthing malicious. There's a few recommendations to remove unnecessary junk, I highlighted your original post. Are you having specific problems?

chasedude 04-13-2011 01:16 PM

Quote:

Originally Posted by DaFace (Post 7555512)
On a random Avast side note, any of you ever had it lose its ability to access the internet? I got a little minor gremlin a week or so ago. I removed it immediately, and it really didn't do anything, but somewhere in the removal process something got screwy. Avast won't update, and if I turn the web shield on, all my browsers are blocked.

I've done a full uninstall/reinstall, all of the typical scanners come up clean, everything seems fine, etc. Hosts file is fine. Hijack this doesn't seem to have anything out of the ordinary. Everything works fine except that one program. I almost don't even care (it's just my media center pc), but it's got me stumped.

So Avast has lost the ability to access the net now?

Dayze 04-13-2011 01:37 PM

Quote:

Originally Posted by chasedude (Post 7561446)
I uploaded your log file to the site I get my recommendations from
hijackthis.de and didn't see anthing malicious. There's a few recommendations to remove unnecessary junk, I highlighted your original post. Are you having specific problems?

cool thanks;
nothing too bad; I spent a few hours on Monday night running malwarebytes, hijackthis, etc and cleaned up a few things as far as start up processes (could probably even do that again, I just did a quick fly-by). this log i posted was after I had done everything I thought I could do, restarted etc.

up until then, my computer was just slow, starting up slow; locking up etc. and I primarily only use it for email/web etc so not a lot of extra stuff/software downloaded to it.

I think it was running like that because it's about 5 years old, and I hadn't done any sort cleanup etc...
we'll see how it goes...

chasedude 04-13-2011 01:42 PM

Quote:

Originally Posted by Dayze (Post 7561528)
nothing too bad; I spend a few hours on Monday night running malwarebytes, hijackthis, etc and cleaned up a few things as far as start up processes (could probably even do that again, I just did a quick fly-by). this log i posted was after I had done everything I thought I could do, restarted etc.

up until then, my computer was just slow, starting up slow; locking up etc. and I primarily only use it for email/web etc so not a lot of extra stuff/software downloaded to it.

I think it was running like that because it's about 5 years old, and I hadn't done any sort cleanup etc...
we'll see how it goes...

Just curious if you've cracked the case and given it a good dusting inside too. There's always an accumulation of crap on the processors heatsink. I just take an air compressor and blow it out, outside of course, and plug it back in. By doing this the core temp will go down and give me a little increase in speed.

Dayze 04-13-2011 01:44 PM

Quote:

Originally Posted by chasedude (Post 7561538)
Just curious if you've cracked the case and given it a good dusting inside too. There's always an accumulation of crap on the processors heatsink. I just take an air compressor and blow it out, outside of course, and plug it back in. By doing this the core temp will go down and give me a little increase in speed.

that's the other thing; it's a lap top and gets really hot sometimes when nothing is really going on...

chasedude 04-13-2011 01:58 PM

Quote:

Originally Posted by Dayze (Post 7561551)
that's the other thing; it's a lap top and gets really hot sometimes when nothing is really going on...

I had a laptop that was running really hot and fans at full blast. I installed process explorer on it to view my cpu usage and found my lexmark printer software was using 50% of my cpu when doing nothing. I assumed that that program had a memory leak and needed dumping. After the uninstall it now runs cool and quiet. I still blow the air through the exhaust port on my cpu occasionally too with the compressor. Alot of dust can collect on the cooling fan in laptops too.

Dayze 04-13-2011 02:30 PM

Quote:

Originally Posted by chasedude (Post 7561645)
I had a laptop that was running really hot and fans at full blast. I installed process explorer on it to view my cpu usage and found my lexmark printer software was using 50% of my cpu when doing nothing. I assumed that that program had a memory leak and needed dumping. After the uninstall it now runs cool and quiet. I still blow the air through the exhaust port on my cpu occasionally too with the compressor. Alot of dust can collect on the cooling fan in laptops too.

cool; I'm running an HP wireless printer that never gets used.

if one were to turn off a printer from a process standpoint, would they be able to print if need be? so like, turn it off since 99% of time we never use it, but if we did need to - still be able to print?

DaFace 04-13-2011 04:36 PM

Quote:

Originally Posted by chasedude (Post 7561451)
So Avast has lost the ability to access the net now?

Yup. But that's it. Everything else is peachy. I can manually update it by downloading the file from Avast, and that works fine. Scans come up clean. I can't use the web shield (since that works as a proxy that sends all HTTP communications through Avast), but that and updating are really the only issues.

Fish 04-13-2011 04:58 PM

Quote:

Originally Posted by DaFace (Post 7555512)
On a random Avast side note, any of you ever had it lose its ability to access the internet? I got a little minor gremlin a week or so ago. I removed it immediately, and it really didn't do anything, but somewhere in the removal process something got screwy. Avast won't update, and if I turn the web shield on, all my browsers are blocked.

I've done a full uninstall/reinstall, all of the typical scanners come up clean, everything seems fine, etc. Hosts file is fine. Hijack this doesn't seem to have anything out of the ordinary. Everything works fine except that one program. I almost don't even care (it's just my media center pc), but it's got me stumped.

Hmmm.. That's weird.. never heard of such a thing.

You might try Avast's uninstaller app... http://www.avast.com/uninstall-utility

Usually when they release their own uninstall app, it's because the Windows one isn't sufficient in some cases. I'd uninstall through windows, then run the Avast uninstall and let it clean up anything the Windows uninstaller might have missed. Then reinstall newest version. You might try and uninstall/reinstall with another admin account too. Determine if it might be a user setting specific to your account.

DaFace 04-13-2011 06:51 PM

Quote:

Originally Posted by KC Fish (Post 7562371)
Hmmm.. That's weird.. never heard of such a thing.

You might try Avast's uninstaller app... http://www.avast.com/uninstall-utility

Usually when they release their own uninstall app, it's because the Windows one isn't sufficient in some cases. I'd uninstall through windows, then run the Avast uninstall and let it clean up anything the Windows uninstaller might have missed. Then reinstall newest version. You might try and uninstall/reinstall with another admin account too. Determine if it might be a user setting specific to your account.

Yeah, I tried that. Haven't done it from safe mode, which I've seen suggested on other forums. I'll try it from a different account as well, just to say I did.

It's kind of a weird issue. It doesn't really matter that much, but it's certainly perplexing.

chasedude 04-14-2011 12:03 AM

Quote:

Originally Posted by Dayze (Post 7561827)
cool; I'm running an HP wireless printer that never gets used.

if one were to turn off a printer from a process standpoint, would they be able to print if need be? so like, turn it off since 99% of time we never use it, but if we did need to - still be able to print?

Print spooling is about the only process windows uses to handle print jobs and it only starts when you send a job through the queue. Most of the problems created today are the additional software loaded with most home deskjets.

The services I had problems with from my lexmark software wouldn't let me close the process. My only solution was to uninstall it.

I miss the old days when all you had to do was install a driver and done. Too much unnecessary software bogging down the system only creates problems in the end.

Fish 05-11-2011 09:25 AM

Google Image Poisoning and FakeAV attacks

FYI on Google Image Poisoning.... which is the general cause for the FakeAV popups that so many people have issues with.

These FakeAV programs are rather tricky, in that they're not easily classified, and they never work the same. Therefore, your various AV/Spyware/Malware scanners might not think that it's malicious behavior at the time of infection.

The FakeAV attacks seem to come in 3 flavors of increasing complexity:

1) "The Nag". Terminate the process and delete the file. Doesn't care that you run other programs.

2) "The Pain in the Ass". Doesn't let you run any exe because it latches into the .exe file registry keys. We have an inf that reverts the registry change, then we terminate and delete the exe.

3) "The Real Pain in the Ass". Does the same as number two, but has the additional side effect of fudging permissions all over the system. It screws them up so bad that you can't run any of your applications anymore. When computers get these, we usually just reimage them. But they can be salvaged if it's worth a bit of work to you.

If you've experienced these, here's why you got it, and here's how to prevent it in the future.

Full article: http://isc.sans.edu/diary/More+on+Go...oisoning/10822

Another very In-depth article with additional info: http://blog.unmaskparasites.com/2011...earch-results/

Quote:

For last couple of weeks we received quite a bit of reports of images on Google leading to (usually) FakeAV web sites.
Google is doing a relatively good job removing (or at least marking) links leading to malware in normal searches, however, Google’s image search seem to be plagued with malicious links. So how do they do this?

The attackers compromise a number of legitimate web sites. I have noticed that they usually attack Wordpress installations, but any widely spread software that has known vulnerabilities can be exploited.
.
.
.
.
.
Now, when a user searches for something through the Google image search function, thumbnails of pictures are displayed. Depending on the automatically generated content in step 3), number of links to the web page and other parameters known to Google, the attacker’s page will be shown at a certain position in the results web page. The exploit happens when a user clicks on the thumbnail.
Google now shows a special page that shows the thumbnail in the center of the page, links to the original image (no matter where it is located) on the right and the original web site (the one that contained the image) in the background. This is where the “vulnerability” is.

The user’s browser will automatically send a request to the bad page which runs the attacker’s script (the one set in step 1). This script checks that the request’s referrer field and if it contains Google (meaning this was a click on the results page in Google), the script displays a small JavaScript script.

This causes the browser to be redirected to another site that is serving FakeAV.

As we can see, the whole story behind this is relatively simple (for the attackers). There is a number of things to do here to protect against this attack, depending if we are looking at servers or clients. For a standard user, the best protection (besides not clicking on images) is to install a Mozilla Firefox addon such as NoScript. Google could step up a bit as well, especially since this has been going on for more than a month already and there are numerous complaints on Google’s forums about this. Since there are so many poisoned images they could maybe modify the screen that displays the results so it does not include the iframe – that will help in first step only, since if the user lands on the malicious web page there is nothing Google can do really.
Here's the link to NoScript. The thing about NoScript though, is that it can be overkill in many situations, and requires you to fine tune it or add exceptions to make some of your normal websites function properly. This normally just consists of navigating to your trusted websites and telling NoScript to allow an exception for that site. But for some people, I imagine it could be confusing. If you have any questions about it, post em in here....

Stanley Nickels 05-20-2011 09:07 AM

We're having a whale of a time dealing with less-computer-literate folks installing Mac Defender or Mac Protector. Making things worse, those trojans pop-up gay porn, of all things, then present the user with a virus warning. The worst part about this is trying to explain to someone how the program got there; their admin password HAD to be entered, but they draw no correlation between the installing of an anti-virus and the subsequent porn/virus "infection". Ugh.

Fish 05-20-2011 11:15 AM

Quote:

Originally Posted by Stanley Nickels (Post 7652176)
We're having a whale of a time dealing with less-computer-literate folks installing Mac Defender or Mac Protector. Making things worse, those trojans pop-up gay porn, of all things, then present the user with a virus warning. The worst part about this is trying to explain to someone how the program got there; their admin password HAD to be entered, but they draw no correlation between the installing of an anti-virus and the subsequent porn/virus "infection". Ugh.

LMAO Seriously?

First off.... never ever ever give complete idiot users admin rights. That's just asking for headaches.

You could install ClamXAV on the machines. It's free, and effective. It's very easy to use, just tell it what to actively monitor. You can configure it to monitor the User folders, the normal startup and launch folders, etc. if you don't want it to scan the entire drive.

Stanley Nickels 05-20-2011 11:48 AM

Right now we're simply removing the program, and reassuring them their computer is in no danger (while politely implying that they were the idiots that did this). Removal is easy: Activity Monitor- Force Quit; Remove from Applications; Remove from Login Items; Safari-Preferences-uncheck Open "Safe" Files.

rocknrolla 05-28-2011 10:22 PM

Thank you, This thread freaking saved me soooo much time.


All times are GMT -6. The time now is 06:12 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.