Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Formatted still not sure its okay

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Formatted still not sure its okay

Unread postby BJBilly » July 12th, 2011, 8:45 pm

used a back up image of my partition as I feared my secuirty had been compromised and passwords taken due to my being stupid

have re-installed everything but number of problems, computer takes a long time to shut down and when the welcome screen appears it takes a long time before the windows screen comes up
also mozilla and malwarebytes keep *not responding*

DDS (Ver_2011-06-23.01) - NTFSx86
Internet Explorer: 8.0.6001.19088
Run by Chris at 1:43:23 on 2011-07-13
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.3060.1975 [GMT 1:00]
.
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Secunia\PSI\PSIA.exe
C:\Program Files\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Secunia\PSI\sua.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\real\realplayer\Update\realsched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Secunia\PSI\psi_tray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\System32\notepad.exe
C:\Windows\System32\wsqmcons.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uSearch Page = hxxp://www.visagecomputers.co.uk/
uStart Page = hxxp://www.visagecomputers.co.uk/
uWindow Title = Visage Computers
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton internet security\engine\18.6.0.29\coIEPlg.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton internet security\engine\18.6.0.29\ips\IPSBHO.DLL
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton internet security\engine\18.6.0.29\coIEPlg.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\secuni~1.lnk - c:\program files\secunia\psi\psi_tray.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shoc ... tor/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/fl ... rashim.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.0.1
TCP: Interfaces\{24808C3F-DF8E-4DBB-B40F-D7DB39A51B71} : DhcpNameServer = 192.168.0.203
TCP: Interfaces\{C010AF49-0C76-4353-BB35-19AE24C74C4F} : DhcpNameServer = 192.168.0.1
Notify: igfxcui - igfxdev.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\chris\appdata\roaming\mozilla\firefox\profiles\3co3mo8b.default\
FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nis\1206000.01d\symds.sys [2011-7-12 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nis\1206000.01d\symefa.sys [2011-7-12 744568]
R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\bashdefs\20110701.001\BHDrvx86.sys [2011-7-1 810616]
R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nis_18.1.0.37\definitions\ipsdefs\20110712.033\IDSvix86.sys [2011-7-12 367736]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nis\1206000.01d\ironx86.sys [2011-7-12 136312]
R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\nis\1206000.01d\symtdiv.sys [2011-7-12 331384]
R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2011-6-6 64952]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-21 21504]
R2 NIS;Norton Internet Security;c:\program files\norton internet security\engine\18.6.0.29\ccsvchst.exe [2011-7-12 130008]
R2 Secunia PSI Agent;Secunia PSI Agent;c:\program files\secunia\psi\psia.exe [2011-4-19 993848]
R2 Secunia Update Agent;Secunia Update Agent;c:\program files\secunia\psi\sua.exe [2011-4-19 399416]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-7-12 105592]
R3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [2010-9-1 15544]
R4 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-7-13 39984]
S3 MOSUMAC;USB-Ethernet Driver;c:\windows\system32\drivers\MOSUMAC.SYS [2010-11-19 43520]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-07-12 23:51:17 876032 ----a-w- c:\windows\system32\XpsPrint.dll
2011-07-12 23:45:57 -------- d-----w- c:\users\chris\appdata\local\Mozilla
2011-07-12 23:45:00 -------- d-----w- c:\program files\common files\xing shared
2011-07-12 23:40:08 -------- d-----w- c:\users\chris\appdata\roaming\Malwarebytes
2011-07-12 23:39:38 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-12 23:39:38 -------- d-----w- c:\programdata\Malwarebytes
2011-07-12 23:39:34 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-12 23:39:34 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-12 23:38:32 -------- d-----w- c:\users\chris\appdata\local\Secunia PSI
2011-07-12 23:37:55 -------- d-----w- c:\program files\Secunia
2011-07-12 23:34:21 -------- d-----w- c:\users\chris\appdata\local\Adobe
2011-07-12 23:32:02 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 23:24:27 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-07-12 23:01:12 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2011-07-12 23:01:12 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2011-07-12 22:59:55 305152 ----a-w- c:\windows\system32\drivers\srv.sys
2011-07-12 22:55:03 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-07-12 22:55:03 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-07-12 22:55:03 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-07-12 22:53:52 758784 ----a-w- c:\program files\common files\microsoft shared\vgx\VGX.dll
2011-07-12 22:53:49 677888 ----a-w- c:\windows\system32\mstsc.exe
2011-07-12 22:53:49 2067968 ----a-w- c:\windows\system32\mstscax.dll
2011-07-12 22:53:46 276992 ----a-w- c:\windows\system32\schannel.dll
2011-07-12 22:53:43 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-07-12 22:53:40 49152 ----a-w- c:\windows\system32\csrsrv.dll
2011-07-12 22:53:40 375808 ----a-w- c:\windows\system32\winsrv.dll
2011-07-12 22:49:08 744568 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\symefa.sys
2011-07-12 22:49:08 50168 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\srtspx.sys
2011-07-12 22:49:08 340088 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\symds.sys
2011-07-12 22:49:08 331384 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\symtdiv.sys
2011-07-12 22:49:08 296568 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\symnets.sys
2011-07-12 22:49:07 516216 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\srtsp.sys
2011-07-12 22:49:07 136312 ----a-w- c:\windows\system32\drivers\nis\1206000.01d\ironx86.sys
2011-07-12 22:49:02 -------- d-----w- c:\windows\system32\drivers\nis\1206000.01D
2011-07-12 22:43:40 -------- d-----w- c:\programdata\Symantec
2011-07-12 22:43:36 126584 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2011-07-12 22:43:36 -------- d-----w- c:\program files\Symantec
2011-07-12 22:43:36 -------- d-----w- c:\program files\common files\Symantec Shared
2011-07-12 22:43:09 -------- d-----w- c:\windows\system32\drivers\NIS
2011-07-12 22:43:07 -------- d-----w- c:\programdata\Norton
2011-07-12 22:43:07 -------- d-----w- c:\program files\Norton Internet Security
2011-07-12 22:43:02 -------- d-----w- c:\program files\NortonInstaller
2011-07-12 22:38:27 -------- d-----w- c:\programdata\NortonInstaller
.
==================== Find3M ====================
.
2011-07-12 23:44:21 499712 ----a-w- c:\windows\system32\msvcp71.dll
2011-07-12 23:44:21 348160 ----a-w- c:\windows\system32\msvcr71.dll
2011-06-02 13:34:49 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-05-28 06:08:58 916480 ----a-w- c:\windows\system32\wininet.dll
2011-05-28 06:04:30 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-05-28 06:04:17 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-05-28 06:04:03 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-05-28 06:04:03 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-05-28 05:10:26 385024 ----a-w- c:\windows\system32\html.iec
2011-05-28 04:33:03 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-05-28 04:31:44 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-04-29 13:25:10 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-04-29 13:25:09 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-04-21 13:58:27 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-04-14 14:59:03 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
.
============= FINISH: 1:43:51.31 ===============

BJBilly wrote:UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-06-23.01)
.
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume1
Install Date: 04/02/2011 10:32:19
System Uptime: 13/07/2011 00:57:28 (1 hours ago)
.
Motherboard: Dell Inc. | | 0K216C
Processor: Intel(R) Core(TM)2 Duo CPU E6750 @ 2.66GHz | Socket 775 | 1998/333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 288 GiB total, 263.44 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 3.888 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP16: 12/07/2011 23:36:00 - Windows Update
RP17: 13/07/2011 00:00:06 - Windows Update
RP18: 13/07/2011 00:21:09 - Windows Update
RP19: 13/07/2011 00:22:59 - Installed Java(TM) 6 Update 26
RP20: 13/07/2011 00:35:07 - Installed Adobe Reader X (10.1.0).
RP21: 13/07/2011 00:41:16 - Windows Update
RP22: 13/07/2011 00:53:28 - Windows Update
.
==== Installed Programs ======================
.
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader X (10.1.0)
Adobe Shockwave Player 11.6
EasyBCD 1.7
ffdshow [rev 2180] [2008-10-04]
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Intel(R) Graphics Media Accelerator Driver
Java Auto Updater
Java(TM) 6 Update 26
Malwarebytes' Anti-Malware version 1.51.0.1200
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Silverlight
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Mozilla Firefox 5.0.1 (x86 en-GB)
Nero 7 Lite 7.10.1.2
Norton Internet Security
PowerDVD
RealPlayer
Secunia PSI (2.0.0.3003)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
swMSM
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Windows Live installer
Windows Live Messenger
WinRAR archiver
.
==== Event Viewer Messages From Past Week ========
.
13/07/2011 01:03:48, Error: Service Control Manager [7022] - The KtmRm for Distributed Transaction Coordinator service hung on starting.
13/07/2011 00:49:12, Error: Microsoft-Windows-WindowsUpdateClient [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Windows Internet Explorer 9 for Windows Vista.
13/07/2011 00:36:41, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
13/07/2011 00:36:41, Error: Service Control Manager [7000] - The Windows Search service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.
13/07/2011 00:36:41, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
.
==== End Of File ===========================
Last edited by NonSuch on July 13th, 2011, 2:41 am, edited 1 time in total.
Reason: Edited to add content of second post to first post.
BJBilly
Active Member
 
Posts: 3
Joined: July 12th, 2011, 3:57 pm
Advertisement
Register to Remove

Re: Formatted still not sure its okay

Unread postby askey127 » July 16th, 2011, 6:53 am

Hi BJBilly,

Your machine doesn't show any evils that I can see.
In your situation, I would do the following:
  • Shut off Secunia PSI temporarily, so it doesn't start automatically.
  • Run TFC to clean out Temp Files. All the updates will generate a mountain of them.
    Download and Run Temp File Cleaner (TFC.exe)
    Download Temp File Cleaner and save it to your desktop.
    You might want to Copy/Paste/Print these instructions and Save any unsaved work. TFC will close ALL open programs... including your browser!
    Right click the TFC icon and choose Run as Administrator to run it. OK the UAC.
    If you have a lot of junk files to remove, it could take a while, so please be patient and let it finish.
    When it's done, it will report the total size of files removed. If it asks to Reboot, choose to do so. This will remove files that could not be removed while Windows was running.
    After Restart, log back in to your usual account.
  • Check the time/date stamp showing in your system tray and update it if necessary.
  • Go to Windows Update and let it install any/all missing updates.
  • Run TFC again.

Let me know how it goes.
askey127
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA

Re: Formatted still not sure its okay

Unread postby askey127 » July 19th, 2011, 8:16 am

Due to Lack of Response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
askey127
Admin/Teacher
Admin/Teacher
 
Posts: 14025
Joined: April 17th, 2005, 3:25 pm
Location: New Hampshire USA


Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 297 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware