Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Security Protection malware/virus

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Security Protection malware/virus

Unread postby vegetasaiyan » September 27th, 2011, 11:49 am

hi this is my 3rd time trying to post,my topic was closed because of the 72 hours. I had been unable to post any new information because "security protection" wasn't allowing me to access any websites even in safe mode with networking. I finally was able to run mbam and for the time being am able to run windows normal. But im still getting redirected to njksearch.com and security protection is still on desktop.first im running Windows vista home basic and my laptop is for home use. Heres the problems im having,im unable to access some folders and files or delete them its saying i dont have permission to do so,i have run mbam an it files infected files every time but doesn't completely get rid of the malware called "security protection" it eventually starts popping up again and says i have a blaster wurm and tries to scam me into buying the fake security protection. It even pops up during safemode. Heres the DDS files

.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Basic
Boot Device: \Device\HarddiskVolume2
Install Date: 9/10/2010 11:15:53 PM
System Uptime: 9/27/2011 11:30:31 AM (0 hours ago)
.
Motherboard: Acer | | Nile
Processor: AMD Athlon(tm) Processor 2650e | Socket M2/S1G1 | 1600/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 70 GiB total, 26.498 GiB free.
D: is FIXED (NTFS) - 70 GiB total, 69.421 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
AC3Filter 1.63b
Acer Assist
Acer Crystal Eye Webcam
Acer Empowering Technology
Acer eRecovery Management
Acer Mobility Center Plug-In
Acer Registration
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
ATI Catalyst Install Manager
AviSynth 2.5
Bonjour
Canon iP2600 series
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Download Updater (AOL LLC)
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVD43 v4.6.0
ffdshow v1.1.3800 [2011-03-28]
Haali Media Splitter
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
InterVideo WinDVD 8
Java Auto Updater
Java(TM) 6 Update 23
Launch Manager
Lernout & Hauspie TruVoice American English TTS Engine
LightScribe 1.4.142.1
LiveUpdate 3.3 (Symantec Corporation)
Malwarebytes' Anti-Malware version 1.51.2.1300
MediaImpression 2.0 for PENTAX
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ Run Time Lib Setup
Microsoft Works
Mozilla Firefox (3.6.18)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
OGA Notifier 2.0.0048.0
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek High Definition Audio Driver
RealUpgrade 1.1
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Skins
Speakonia
Symantec AntiVirus
Synaptics Pointing Device Driver
TomTom HOME Visual Studio Merge Modules
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2586924)
WinRAR 4.00 (32-bit)
Yahoo! Software Update
.
==== Event Viewer Messages From Past Week ========
.
9/27/2011 11:32:31 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo SASDIFSV SASKUTIL sxjr
9/27/2011 11:32:31 AM, Error: Service Control Manager [7000] - The WinDefend service failed to start due to the following error: The system cannot find the path specified.
9/27/2011 11:32:31 AM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
9/27/2011 11:31:34 AM, Error: EventLog [6008] - The previous system shutdown at 11:44:52 PM on 9/26/2011 was unexpected.
9/26/2011 4:25:01 PM, Error: EventLog [6008] - The previous system shutdown at 4:22:17 PM on 9/26/2011 was unexpected.
9/26/2011 11:38:10 PM, Error: EventLog [6008] - The previous system shutdown at 7:22:52 PM on 9/26/2011 was unexpected.
9/25/2011 4:24:44 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo eeCtrl SASDIFSV SASKUTIL SPBBCDrv spldr SRTSP SRTSPX sxjr SYMTDI Wanarpv6
9/25/2011 4:24:44 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
9/25/2011 4:24:42 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
9/25/2011 4:24:35 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/25/2011 4:24:27 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
9/25/2011 4:23:59 PM, Error: EventLog [6008] - The previous system shutdown at 12:29:29 AM on 9/25/2011 was unexpected.
9/24/2011 9:04:25 AM, Error: EventLog [6008] - The previous system shutdown at 8:39:55 PM on 9/23/2011 was unexpected.
9/23/2011 9:32:57 AM, Error: EventLog [6008] - The previous system shutdown at 7:49:50 PM on 9/22/2011 was unexpected.
9/23/2011 8:00:46 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
.
==== End Of File ===========================

.
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_23
Run by Eric at 11:37:04 on 2011-09-27
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1789.480 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Acer\Mobility Center\MobilityService.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
\\?\C:\Windows\system32\wbem\WMIADAP.EXE
C:\Windows\servicing\TrustedInstaller.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
uURLSearchHooks: H - No File
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [Acer Assist Launcher] c:\program files\acer\acer assist\launcher.exe
mRun: [Acer Product Registration] "c:\program files\acer\acer registration\ACE1.exe" /startup
mRun: [eRecoveryService]
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
mRun: [<NO NAME>]
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{F58A4BAD-9EC6-425C-ABE2-579EFA8C8897} : DhcpNameServer = 192.168.2.1
Hosts: 95.64.61.141 http://www.google.com
Hosts: 95.64.61.142 http://www.bing.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\eric\appdata\roaming\mozilla\firefox\profiles\er2y2olw.default\
FF - prefs.js: network.proxy.type - 0
FF - component: c:\users\eric\appdata\roaming\mozilla\firefox\profiles\er2y2olw.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-4-13 366152]
R2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
R2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2008-4-3 1956240]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-8-5 105592]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-4-13 22216]
S1 SASDIFSV;SASDIFSV;c:\users\eric\appdata\local\temp\sas_selfextract\sasdifsv.sys [2011-7-22 12880]
S1 SASKUTIL;SASKUTIL;c:\users\eric\appdata\local\temp\sas_selfextract\saskutil.sys [2011-7-12 67664]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2008-4-3 121744]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2010-9-10 24576]
.
=============== Created Last 30 ================
.
2011-09-11 00:29:59 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-09-11 00:29:41 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-09-11 00:29:15 2048 ----a-w- c:\windows\system32\tzres.dll
2011-09-11 00:24:37 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-09-11 00:23:27 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-09-11 00:23:26 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-09-11 00:23:19 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-03 18:19:15 -------- d-----w- C:\MGADiagToolOutput
2011-08-30 02:53:34 388096 ----a-r- c:\users\eric\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
.
==================== Find3M ====================
.
2011-08-31 21:00:50 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-31 20:20:54 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-22 13:54:40 1383424 ----a-w- c:\windows\system32\mshtml.tlb
2011-07-12 15:20:54 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20:54 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20:54 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20:54 178536 ----a-w- c:\windows\system32\dnssdX.dll
.
============= FINISH: 11:41:23.38 ===============

Thank you
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm
Advertisement
Register to Remove

Re: Security Protection malware/virus

Unread postby pgmigg » September 28th, 2011, 12:25 pm

Hello vegetasaiyan,

Welcome to the forum again! :)

My name is pgmigg and I'll be helping you with any malware problems.

Currently I am working under the guidance of the MRU teachers and everything I post to you, must first be approved by them.
This additional review process can add some extra time to my responses, but I will post back with instructions for you as soon as possible.


Before we begin, please read and follow these important guidelines, so things will proceed smoothly.
  1. The instructions being given are for YOUR computer and system only!
    Using these instructions on a different computer can cause damage to that computer and possibly render it inoperable!
  2. You must have Administrator rights, permissions for this computer.
  3. DO NOT run any other fix or removal tools unless instructed to do so!
  4. DO NOT install any other software (or hardware) during the cleaning process. This adds more items to be researched.
  5. Only post your problem at (1) one help site. Applying fixes from multiple help sites can cause problems.
  6. Print each set of instructions if possible - your Internet connection will not be available during some fix processes.
  7. Only reply to this thread, do not start another one. Please, continue responding, until I give you the "All Clean!" :cheers:
    Absence of symptoms does not mean that everything is clear.

I am currently reviewing your log and will return, as soon as possible, with additional instructions. In the meantime...
Please take time to read the Malware Removal Forum Guidelines and Rules where the conditions for receiving help at this forum are explained.

Please read all instructions carefully before executing and perform the steps, in the order given.
lf, you have any questions or problems, executing these instructions, <<STOP>> do not proceed, post back with the question or problem.
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » September 28th, 2011, 6:22 pm

k thnks
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware/virus

Unread postby pgmigg » September 29th, 2011, 11:52 am

Hello vegetasaiyan,

Thank you for your patience... :)

Step 1.
Run CKScanner
  1. Please download CKScanner from Here
  2. Important: - Save it to your Desktop.
  3. Right-click CKScanner.exe and select Run as administrator..., then click Search For Files.
  4. After a very short time, when the cursor hourglass disappears, click Save List To File.
  5. A message box will verify the file saved.
  6. Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

Step 2.
Retrieve Malwarebytes Anti-Malware (MBAM) Log(s)
You wrote that run MBAM and I need you to retrieve a scan log for me. Please do the following:
  1. Start MBAM, then click the Logs tab at the top.
    The log will be named by the date & time of scan in the following format: mbam-log-yyyy-mm-dd (time).txt
    If you have had multiple runs of MBAM, there may be several logs showing in the list.
  2. Click on the last (most recent) log name to highlight it, then click the Open button, at bottom left. The log should open in Notepad as a text file.
  3. Please copy and paste the entire mbam-log-yyyy-mm-dd (time).txt file in your next reply.
    Be sure to post the complete log, including the top portion showing MBAM's database version and your operating system.
  4. Exit MBAM when done.

Please include in your next reply:
  1. Did you have any problems executing the instructions?
  2. Contents of CKFiles.txt
  3. Contents of a log created by MBAM

Thanks,
pgmigg
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » September 29th, 2011, 2:16 pm

heres the mbam log

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 7802

Windows 6.0.6002 Service Pack 2
Internet Explorer 7.0.6002.18005

9/26/2011 6:50:37 PM
mbam-log-2011-09-26 (18-50-37).txt

Scan type: Full scan (C:\|D:\|E:\|)
Objects scanned: 290422
Time elapsed: 1 hour(s), 28 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 53

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\utilman (Trojan.Agent) -> Value: utilman -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\$RECYCLE.BIN\s-1-5-21-2590969754-410994182-1006661355-1000\$RMKE66G.exe (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\$RECYCLE.BIN\s-1-5-21-2590969754-410994182-1006661355-1000\$RNJOP08.exe (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\1059.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\161E.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\2D37.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\2FD6.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\3056.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\3439.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\3678.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\43B3.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\6355.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\6870.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\7024.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\733C.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\901E.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\9388.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\A18F.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\B432.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\B55.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\B5A7.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\BC2D.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\D6ED.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\DAC4.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\programdata\DB70.tmp (Rogue.SecurityProtection) -> Quarantined and deleted successfully.
c:\Windows\Temp\0.20096788513771058.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\Temp\12B5.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\2CBA.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\2EEC.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\2FD9.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\334F.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\359D.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\42C9.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\4930.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\4CB8.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\622D.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\666D.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\6E31.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\7213.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\7B37.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\845B.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\8F24.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\91D3.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\950D.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\A112.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\A1D.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\B2FA.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\B441.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\BAD5.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\CA60.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\D651.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\D9F9.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\DA76.tmp (Malware.Gen) -> Quarantined and deleted successfully.
c:\Windows\Temp\DAB.tmp (Malware.Gen) -> Quarantined and deleted successfully.

ck log

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.XOBBCA
----- EOF -----
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware/virus

Unread postby pgmigg » September 30th, 2011, 11:59 am

Hello vegetasaiyan,

Step 1.
Uninstall Programs
I need you to uninstall some program(s).
  1. Click on Start, then click the Start Search box on the Start Menu.
  2. Copy and paste the value below, into the open text entry box:
    control appwiz.cpl
      Depending on your current view setting...
    • Double click on Programs and Features.
    • Under Programs, click on Uninstall a program.
  3. Locate the following program(s):
    Ask Toolbar
  4. Select the program and click on Uninstall to uninstall it.
  5. When finished, close the Control Panel window.
  6. Reboot you computer in Normal mode.

Step 2.
Download and Run ComboFix
  1. Please download ComboFix from one of the following links.

    Link 1.

    Link 2.

    **IMPORTANT !!! Save ComboFix.exe to your Desktop**
  2. Please disable any Antivirus and Firewall you have active, as shown in this topic. Please close all open application windows.
  3. Double click on ComboFix.exe and follow the prompts.
  4. When finished, it shall produce a log for you. Please include the contents of C:\ComboFix.txt in your next reply
A word of warning: Neither I nor sUBs are responsible for any damage you may cause to your machine by running ComboFix on your own. This tool is not a toy and not for everyday use!
ComboFix SHOULD NOT be used unless requested by a forum helper.


Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Contents of the ComboFix.txt
  3. Do you see any changes in computer behavior?

Thanks,
pgmigg
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » October 1st, 2011, 1:52 pm

k heres the log it seems to be so far so good

ComboFix 11-10-01.03 - Eric 10/01/2011 13:28:16.1.1 - x86
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1789.1002 [GMT -4:00]
Running from: c:\users\Eric\Downloads\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\avbase.dat
c:\users\Public\Desktop\Security Protection.lnk
.
.
((((((((((((((((((((((((( Files Created from 2011-09-01 to 2011-10-01 )))))))))))))))))))))))))))))))
.
.
2011-10-01 17:39 . 2011-10-01 17:40 -------- d-----w- c:\users\Eric\AppData\Local\temp
2011-10-01 17:39 . 2011-10-01 17:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-09-28 22:21 . 2011-09-28 22:22 -------- d-----w- c:\program files\Google
2011-09-27 15:47 . 2011-08-10 12:14 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-09-11 00:29 . 2011-07-06 15:31 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-09-11 00:29 . 2011-06-17 16:03 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-09-11 00:29 . 2011-07-11 13:25 2048 ----a-w- c:\windows\system32\tzres.dll
2011-09-11 00:23 . 2011-06-20 08:54 3602832 ----a-w- c:\windows\system32\ntkrnlpa.exe
2011-09-11 00:23 . 2011-06-20 08:54 3550096 ----a-w- c:\windows\system32\ntoskrnl.exe
2011-09-11 00:23 . 2011-06-17 20:13 905104 ----a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-03 18:19 . 2011-09-03 18:19 -------- d-----w- C:\MGADiagToolOutput
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-31 21:00 . 2011-04-13 21:41 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-30 02:53 . 2011-08-30 02:53 388096 ----a-r- c:\users\Eric\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-07-31 20:20 . 2011-07-31 20:20 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 15:20 . 2011-07-12 15:20 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20 . 2011-07-12 15:20 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20 . 2011-07-12 15:20 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20 . 2011-07-12 15:20 178536 ----a-w- c:\windows\system32\dnssdX.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BkupTray"="c:\program files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672]
"Acer Assist Launcher"="c:\program files\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568]
"Acer Product Registration"="c:\program files\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2008-07-23 846344]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccEvtMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ccSetMgr]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Symantec Antivirus]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2008-02-01 05:25 115560 ----a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2011-08-31 21:00 449608 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware (reboot)]
2011-05-29 13:11 1047656 ----a-w- c:\program files\Malwarebytes' Anti-Malware\iexplorer.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 21:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
R0 djvo;djvo;c:\windows\System32\drivers\srijeid.sys [x]
R0 sxjr;sxjr;c:\windows\System32\drivers\okeg.sys [x]
R1 SASDIFSV;SASDIFSV;c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-28 136176]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-04-26 131072]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-09-28 136176]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2008-04-03 121744]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 ETService;Empowering Technology Service;c:\program files\Acer\Empowering Technology\Service\ETService.exe [2008-11-28 24576]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe [2008-03-03 16384]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 366152]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-04-26 45056]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-08-05 105592]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-08-31 22216]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-28 22:20]
.
2011-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-09-28 22:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\er2y2olw.default\
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-ApnUpdater - c:\program files\Ask.com\Updater\Updater.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-01 13:40
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2011-10-01 13:48:15
ComboFix-quarantined-files.txt 2011-10-01 17:48
.
Pre-Run: 27,980,468,224 bytes free
Post-Run: 28,604,784,640 bytes free
.
- - End Of File - - 2B87CDBD9894D54B36BD1F05C53A65F8
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware/virus

Unread postby pgmigg » October 2nd, 2011, 10:59 am

Hello vegetasaiyan,

Good job. Let continue out treatment...

Step 1.
TFC (Temp File Cleaner)
  1. Please download TFC.exe...by Old Timer. Save it to your desktop.
    Print these instructions. Save any unsaved work. TFC will close ALL open programs including your browser!
  2. Double click on TFC.exe to run it.
    TFC will begin cleaning up the "temp" files. It may take only a few seconds or it could be several minutes, depending on the amount of temp files found.
  3. If prompted to reboot, please click Yes.

! Important ! If TFC prompts you to reboot, please do so immediately, before proceeding to any other steps or other use of your computer.

Step 2.
ESET online scannner

Note 1: You can use either Internet Explorer or Mozilla FireFox for this scan.
Note 2: You will need to to right-click on the IE or FF icons on the Start Menu or Quick Launch Bar on the Taskbar and select "Run as Administrator" from the context menu.

  1. Firstly please Disable any Antivirus you have active, as shown in This topic.
  2. Note: Don't forget to re-enable it after the scan.
  3. Next please click on the following link to open a new window to ESET online scannner
  4. Then click on: Image
    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
  5. Select the option YES, I accept the Terms of Use then click on: Image
  6. When prompted allow the Add-On/Active X to install.
  7. Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  8. Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  9. Now click on: Image
  10. The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  11. When completed the Online Scan will begin automatically.
  12. Do not touch either the mouse or keyboard during the scan otherwise it may stall.
  13. When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  14. Now click on: Image
  15. Use notepad to open the log file located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  16. Copy and paste that log as a reply to this topic.

Please include in your next reply:
  1. Did you have any problems executing the instructions?
  2. Contents of ESET log.txt file
  3. Do you see any changes in computer behavior?

Thanks,
pgmigg
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » October 2nd, 2011, 4:08 pm

Still so far so good Eset did find 3 threats

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6528
# api_version=3.0.2
# EOSSerial=dacfc4c844cb3e499ae4c39283b81fcc
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-10-02 07:56:50
# local_time=2011-10-02 03:56:50 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.0.6002 NT Service Pack 2
# compatibility_mode=512 16777215 100 0 2187055 2187055 0 0
# compatibility_mode=5892 16776574 100 88 32130268 154184044 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=136945
# found=3
# cleaned=0
# scan_time=8938
C:\Documents and Settings\Eric\AppData\Roaming\FrostWire\.AppSpecialShare\frostwire-4.21.3.windows.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I
C:\Users\Eric\AppData\Roaming\FrostWire\.AppSpecialShare\frostwire-4.21.3.windows.exe Win32/OpenCandy application (unable to clean) 00000000000000000000000000000000 I
C:\Windows\System32\config\systemprofile\AppData\Local\imekifasocu.dll a variant of Win32/Kryptik.RXT trojan (unable to clean) 00000000000000000000000000000000 I
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware/virus

Unread postby pgmigg » October 3rd, 2011, 10:34 am

Hello vegetasaiyan,

Step 1.
Create a System Restore Point
  1. Right-click on Computer, then select Properties.
  2. In the left pane under Tasks please click System protection.
    If UAC prompts for an administrator password or approval, type the password or give your "permission to continue".
  3. Select System Protection, then choose Create.
  4. In the System Restore dialog box, type a description for the restore point, then click Create again.
    A window will pop up with "The Restore Point was created successfully" confirmation message.
  5. Click OK, then close the System Restore dialog.

If you have successfully created a System Restore Point...we can proceed.
If you have NOT successfully created a System Restore Point...do not go any further!
Please post back so we can determine why it was unsuccessful.


Step 2.
ComboFix - CFScript
This script is for this user and computer ONLY! Using this tool incorrectly could cause problems with your operating system... preventing it from ever starting again!
You will not have Internet access when you execute ComboFix. All open windows will need to be closed!
  1. Please open Notepad and copy/paste all the text below into the window:
    Code: Select all
    KILLALL::
    
    Driver::
    djvo
    sxjr
    
    File::
    c:\windows\System32\drivers\srijeid.sys
    c:\windows\System32\drivers\okeg.sys
    C:\Windows\System32\config\systemprofile\AppData\Local\imekifasocu.dll
    
    Folder::
    C:\Documents and Settings\Eric\AppData\Roaming\FrostWire
    C:\Users\Eric\AppData\Roaming\FrostWire
    
    DDS::
    uURLSearchHooks: H - No File
    TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
    TB: {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No File
    mRun: [eRecoveryService] 
    mRun: [<NO NAME>]
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
    DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
    
    Firefox::
    FF - ProfilePath - c:\users\eric\appdata\roaming\mozilla\firefox\profiles\er2y2olw.default\
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
    
  2. Save it to your Desktop as CFScript.txt
  3. Please disable any Antivirus and Firewall you have active, as shown in this topic. Please close all open application windows.
    *Only* when the 2 items above (Step 3) have been taken care of...
  4. Drag the CFScript.txt (icon) into the ComboFix.exe icon, as seen in the image below:
    Image
    This will cause ComboFix to run again.
    Do Not use your keyboard or mouse click anywhere in the ComboFix window, as this may cause the program to stall or crash.
    Do Not touch your computer when ComboFix is running!
  5. When finished ComboFix will create a log file... You can save this file to a convenient place.
Please copy/paste the ComboFix log file in your next reply.

Step 3.
Upload Files for testing

  1. Please go to jotti.org or Virustotal
  2. Copy/paste every file with path from the list by one into the white box at the top:
    c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS
    c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS
  3. Press Submit - this will submit the file for testing.
  4. Please wait for all the scanners to finish.
  5. Repeat steps 2-4 for every file in the list.
  6. Then copy and paste the permalinks (web address) in your next response.
    Example of web address:
    Image

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Contents of ComboFix log file
  3. Permalinks after online files scan
  4. Do you see any changes in computer behavior?

Thanks,
pgmigg
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » October 4th, 2011, 11:27 am

ive tried running combofix twice and it froze,i waited over an hour and the program didnt respond
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware/virus

Unread postby pgmigg » October 4th, 2011, 2:29 pm

Hello vegetasaiyan,

Step 1.
Please don't worry - such situations with ComboFix are possible.
But before we continue our treatment I would like to see a contents of the report created by ComboFix before it froze.
You need to find C:\Qoobox\ComboFix-quarantined-files.txt, open it with Notepad, select all, and then Copy/Paste it to the next reply.

Step 2.
Upload Files for testing

  1. Please go to jotti.org or Virustotal
  2. Copy/paste every file with path from the list by one into the white box at the top:
    c:\windows\system32\ntkrnlpa.exe
    c:\windows\system32\ntoskrnl.exe
    c:\windows\system32\drivers\tcpip.sys
    c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS
    c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS
  3. Press Submit - this will submit the file for testing.
  4. Please wait for all the scanners to finish.
  5. Repeat steps 2-4 for every file in the list.
  6. Then copy and paste the permalinks (web address) in your next response.
    Example of web address:
    Image

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Contents of the C:\Qoobox\ComboFix-quarantined-files.txt
  3. Permalinks after online files scan
  4. Do you see any changes in computer behavior?

Thanks,
pgmigg
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » October 4th, 2011, 5:07 pm

it said the last 2 files were not found
c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS
c:\users\Eric\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.SYS
i searched and could not find them

http://www.virustotal.com/file-scan/rep ... 317761461#

http://www.virustotal.com/file-scan/rep ... 1314524244

http://www.virustotal.com/file-scan/rep ... 1317761853

2011-10-01 17:46:52 . 2011-10-01 17:46:52 898 ----a-w- C:\Qoobox\Quarantine\Registry_backups\MSConfigStartUp-ApnUpdater.reg.dat
2011-10-01 17:46:39 . 2011-10-01 17:46:39 103 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-eRecoveryService.reg.dat
2011-10-01 17:46:32 . 2011-10-01 17:46:32 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC}.reg.dat
2011-10-01 17:46:32 . 2011-10-01 17:46:32 171 ----a-w- C:\Qoobox\Quarantine\Registry_backups\WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440}.reg.dat
2011-10-01 17:34:30 . 2011-10-01 17:34:30 4,832 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2011-10-01 17:25:15 . 2011-10-01 17:28:16 62 ----a-w- C:\Qoobox\Quarantine\catchme.log
2011-08-30 17:16:03 . 2011-09-02 00:46:22 593 ----a-w- C:\Qoobox\Quarantine\C\Users\Public\Desktop\Security Protection.lnk.vir
2011-08-28 17:43:47 . 2011-08-28 17:43:47 96 ----a-w- C:\Qoobox\Quarantine\C\ProgramData\avbase.dat.vir
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware/virus

Unread postby pgmigg » October 5th, 2011, 2:02 pm

Hello vegetasaiyan,

Let go forward by the other way...

Step 1.
Create a System Restore Point
  1. Right-click on Computer, then select Properties.
  2. In the left pane under Tasks please click System protection.
    If UAC prompts for an administrator password or approval, type the password or give your "permission to continue".
  3. Select System Protection, then choose Create.
  4. In the System Restore dialog box, type a description for the restore point, then click Create again.
    A window will pop up with "The Restore Point was created successfully" confirmation message.
  5. Click OK, then close the System Restore dialog.

If you have successfully created a System Restore Point...we can proceed.
If you have NOT successfully created a System Restore Point...do not go any further!
Please post back so we can determine why it was unsuccessful.


Step 2.
OTL - Run Fix Script
Please download OTL.exe by Old Timer and save it to your Desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
  1. Right click on OTL.exe select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  2. Copy and Paste the following code into the Image text box. Do not include the word Code
    Code: Select all
    :Processes
    killallprocesses
    
    :Services
    djvo
    sxjr
    
    :Files
    c:\windows\System32\drivers\srijeid.sys
    c:\windows\System32\drivers\okeg.sys
    C:\Windows\System32\config\systemprofile\AppData\Local\imekifasocu.dll
    C:\Documents and Settings\Eric\AppData\Roaming\FrostWire
    C:\Users\Eric\AppData\Roaming\FrostWire
    
    :Commands
    [PURITY]
    [EMPTYTEMP]
    [EMPTYFLASH]
    [REBOOT]
    
  3. Click under the Custom Scan/Fixes box and paste the copied text.
  4. Click the Run Fix button. If prompted... click OK.
  5. OTL may ask to reboot the machine. Please do so if asked.
  6. When the scan completes, Notepad will open with the scan results (OTL.txt). The report is saved in the same location as OTL.
  7. Please post the contents of report in your next reply.

Step 3.
OTL
I need you to run fresh OTL standard scan.
You should still have this on your desktop, if so, ignore the download instructions.
Please download OTL.exe by Old Timer and save it to your Desktop.
Important! Close all applications and windows so that you have nothing open and are at your Desktop.
  1. Right click on OTL.exe select "Run As Administrator..." to run it. If prompted by UAC, please allow it.
  2. Under Output, ensure that Minimal Output is selected.
  3. Click the Scan All Users checkbox.
    Leave the remaining selections to the default settings.
  4. Click on Run Scan at the top left hand corner.
  5. When done, two Notepad files will open.
    • OTL.txt <-- Will be opened, maximized
    • Extras.txt <-- Will be minimized on task bar.
  6. Please post the contents of OTL.txt file only in your next reply.

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Contents of OTL.txt report created after fixing
  3. Contents of OTL.txt log file created after fresh scan
  4. Do you see any changes in computer behavior?

Thanks,
pgmigg
User avatar
pgmigg
MRU Teacher
MRU Teacher
 
Posts: 3179
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Security Protection malware/virus

Unread postby vegetasaiyan » October 6th, 2011, 11:27 pm

im having connection issues im printing instructions at school/will up load results 2mrw
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm
Advertisement
Register to Remove

Next

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 57 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware