Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Security Protection malware

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Security Protection malware

Unread postby vegetasaiyan » September 1st, 2011, 6:37 pm

.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 7.0.6002.18005 BrowserJavaVersion: 1.6.0_23
Run by Eric at 18:11:40 on 2011-09-01
Microsoft® Windows Vista™ Home Basic 6.0.6002.2.1252.1.1033.18.1789.964 [GMT -4:00]
.
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Windows\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACA ... spire_5515
uURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
mURLSearchHooks: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\programdata\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
BHO: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: uTorrentBar Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - c:\program files\utorrentbar\tbuTor.dll
TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [BkupTray] "c:\program files\newtech infosystems\nti backup now 5\BkupTray.exe"
mRun: [Acer Assist Launcher] c:\program files\acer\acer assist\launcher.exe
mRun: [Acer Product Registration] "c:\program files\acer\acer registration\ACE1.exe" /startup
mRun: [eRecoveryService]
mRun: [LManager] c:\progra~1\launch~1\LManager.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe"
mRun: [vptray] c:\progra~1\symant~1\VPTray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [TkBellExe] "c:\program files\real\realplayer\update\realsched.exe" -osboot
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [Malwarebytes' Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\iexplorer.exe" /runcleanupscript
mRun: [dvd43] c:\program files\dvd43\dvd43_tray.exe
mRun: [<NO NAME>]
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [utilman] c:\windows\system32\config\systemprofile\appdata\local\utilman.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinsta ... s-i586.cab
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{F58A4BAD-9EC6-425C-ABE2-579EFA8C8897} : DhcpNameServer = 192.168.2.1
Hosts: 95.64.61.141 www.google.com
Hosts: 95.64.61.142 www.bing.com
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\eric\appdata\roaming\mozilla\firefox\profiles\er2y2olw.default\
FF - prefs.js: network.proxy.type - 0
FF - component: c:\users\eric\appdata\roaming\mozilla\firefox\profiles\er2y2olw.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}\components\RadioWMPCoreGecko19.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\programdata\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: uTorrentBar Community Toolbar: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - %profile%\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
.
R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2008-4-3 1956240]
S1 SASDIFSV;SASDIFSV;c:\users\eric\appdata\local\temp\sas_selfextract\sasdifsv.sys [2011-7-22 12880]
S1 SASKUTIL;SASKUTIL;c:\users\eric\appdata\local\temp\sas_selfextract\saskutil.sys [2011-7-12 67664]
S2 BUNAgentSvc;NTI Backup Now 5 Agent Service;c:\program files\newtech infosystems\nti backup now 5\client\Agentsvc.exe [2008-3-3 16384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 ETService;Empowering Technology Service;c:\program files\acer\empowering technology\service\ETService.exe [2010-9-10 24576]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
S2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-4-13 366640]
S2 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files\newtech infosystems\nti backup now 5\BackupSvc.exe [2008-4-26 45056]
S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files\newtech infosystems\nti backup now 5\SchedulerSvc.exe [2008-4-26 131072]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-4-17 11032]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-8-5 105592]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-4-13 20952]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-4-13 39984]
S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2008-4-3 121744]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-09-01 21:34:51 830976 ----a-w- c:\programdata\defender.exe
2011-08-30 17:16:01 841728 ----a-w- c:\programdata\6870.tmp
2011-08-30 17:16:01 841728 ----a-w- c:\programdata\1059.tmp
2011-08-30 17:16:01 841216 ----a-w- c:\programdata\DAC4.tmp
2011-08-30 17:16:01 841216 ----a-w- c:\programdata\901E.tmp
2011-08-30 17:16:01 841216 ----a-w- c:\programdata\733C.tmp
2011-08-30 17:16:01 841216 ----a-w- c:\programdata\7024.tmp
2011-08-30 17:16:01 841216 ----a-w- c:\programdata\43B3.tmp
2011-08-30 17:16:01 841216 ----a-w- c:\programdata\2D37.tmp
2011-08-30 17:16:01 840704 ----a-w- c:\programdata\D6ED.tmp
2011-08-30 17:16:01 840704 ----a-w- c:\programdata\3678.tmp
2011-08-30 02:53:34 388096 ----a-r- c:\users\eric\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-08-28 17:32:54 841728 ----a-w- c:\programdata\B5A7.tmp
2011-08-28 17:32:54 840704 ----a-w- c:\programdata\BC2D.tmp
2011-08-28 17:32:54 840704 ----a-w- c:\programdata\9388.tmp
2011-08-28 17:32:54 839680 ----a-w- c:\programdata\3439.tmp
2011-08-28 17:32:54 839680 ----a-w- c:\programdata\2FD6.tmp
2011-08-28 17:32:54 839680 ----a-w- c:\programdata\161E.tmp
2011-08-28 17:32:54 818176 ----a-w- c:\programdata\B55.tmp
2011-08-27 17:56:57 -------- d-----w- c:\program files\Trend Micro
2011-08-26 21:41:12 -------- d--h--w- c:\windows\PIF
2011-08-26 20:15:11 -------- d-----w- c:\users\eric\appdata\roaming\SUPERAntiSpyware.com
2011-08-26 20:15:11 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2011-08-26 19:45:44 -------- d-----w- c:\programdata\PC Tools
2011-08-26 19:43:26 872960 ----a-w- c:\programdata\DB70.tmp
2011-08-26 19:43:26 872960 ----a-w- c:\programdata\B432.tmp
2011-08-19 15:03:38 -------- d-----w- c:\windows\system32\wbem\repository
2011-08-19 15:02:27 -------- d-----w- c:\windows\Registration
2011-08-04 02:02:56 -------- d-----w- c:\program files\Bonjour
.
==================== Find3M ====================
.
2011-07-31 20:20:54 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-07-12 15:20:54 83816 ----a-w- c:\windows\system32\dns-sd.exe
2011-07-12 15:20:54 73064 ----a-w- c:\windows\system32\dnssd.dll
2011-07-12 15:20:54 50536 ----a-w- c:\windows\system32\jdns_sd.dll
2011-07-12 15:20:54 178536 ----a-w- c:\windows\system32\dnssdX.dll
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 6.0.6002 Disk: Hitachi_ rev.1.10 -> Harddisk0\DR0 ->
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x860A97D8]<<
_asm { PUSH EBP; CALL 0x6; }
1 ntkrnlpa!IofCallDriver[0x81E80912] -> \Device\Harddisk0\DR0[0x84A674E8]
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV DI, 0x5; XOR AX, AX; MOV DL, 0x80; INT 0x13; JAE 0x2d; DEC DI; }
detected disk devices:
\Device\00000063 -> \??\SCSI#Disk&Ven_Hitachi&Prod_HTS543216L9A3#4&1daa7e31&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
user & kernel MBR OK
error: Read Insufficient system resources exist to complete the requested service.
.
============= FINISH: 18:12:42.71 ===============
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2011-08-26.01)
.
Microsoft® Windows Vista™ Home Basic
Boot Device: \Device\HarddiskVolume2
Install Date: 9/10/2010 11:15:53 PM
System Uptime: 9/1/2011 5:18:09 PM (1 hours ago)
.
Motherboard: Acer | | Nile
Processor: AMD Athlon(tm) Processor 2650e | Socket M2/S1G1 | 1596/200mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 70 GiB total, 24.66 GiB free.
D: is FIXED (NTFS) - 70 GiB total, 69.421 GiB free.
E: is CDROM ()
.
==== Disabled Device Manager Items =============
.
==== System Restore Points ===================
.
RP384: 8/11/2011 3:17:11 AM - Scheduled Checkpoint
RP385: 8/12/2011 3:20:43 AM - Scheduled Checkpoint
RP386: 8/12/2011 1:36:29 PM - Windows Update
RP387: 8/13/2011 3:32:46 AM - Scheduled Checkpoint
RP388: 8/15/2011 1:01:49 AM - Scheduled Checkpoint
RP389: 8/15/2011 3:00:15 AM - Windows Update
RP390: 8/16/2011 4:01:10 PM - Windows Update
RP391: 8/17/2011 11:58:33 AM - Scheduled Checkpoint
RP392: 8/17/2011 5:07:52 PM - Windows Update
.
==== Installed Programs ======================
.
Update for Microsoft Office 2007 (KB2508958)
µTorrent
AC3Filter 1.63b
Acer Assist
Acer Crystal Eye Webcam
Acer Empowering Technology
Acer eRecovery Management
Acer Mobility Center Plug-In
Acer Registration
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Ask Toolbar
ATI Catalyst Install Manager
AviSynth 2.5
Bonjour
Canon iP2600 series
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
Catalyst Control Center Localization Chinese Standard
Catalyst Control Center Localization Chinese Traditional
Catalyst Control Center Localization Czech
Catalyst Control Center Localization Danish
Catalyst Control Center Localization Dutch
Catalyst Control Center Localization Finnish
Catalyst Control Center Localization French
Catalyst Control Center Localization German
Catalyst Control Center Localization Greek
Catalyst Control Center Localization Hungarian
Catalyst Control Center Localization Italian
Catalyst Control Center Localization Japanese
Catalyst Control Center Localization Korean
Catalyst Control Center Localization Norwegian
Catalyst Control Center Localization Polish
Catalyst Control Center Localization Portuguese
Catalyst Control Center Localization Russian
Catalyst Control Center Localization Spanish
Catalyst Control Center Localization Swedish
Catalyst Control Center Localization Thai
Catalyst Control Center Localization Turkish
ccc-core-static
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
Conduit Engine
Download Updater (AOL LLC)
DVD Decrypter (Remove Only)
DVD Shrink 3.2
DVD43 v4.6.0
ffdshow v1.1.3800 [2011-03-28]
FrostWire 4.21.7
Haali Media Splitter
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
InterVideo WinDVD 8
Java Auto Updater
Java(TM) 6 Update 23
Launch Manager
Lernout & Hauspie TruVoice American English TTS Engine
LightScribe 1.4.142.1
LiveUpdate 3.3 (Symantec Corporation)
Malwarebytes' Anti-Malware version 1.51.0.1200
MediaImpression 2.0 for PENTAX
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Professional 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Suite Activation Assistant
Microsoft Office Word MUI (English) 2007
Microsoft Silverlight
Microsoft Text-to-Speech Engine 4.0 (English)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ Run Time Lib Setup
Microsoft Works
Mozilla Firefox (3.6.18)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
NTI Backup Now 5
NTI Backup Now Standard
NTI Media Maker 8
OGA Notifier 2.0.0048.0
QuickTime
RealNetworks - Microsoft Visual C++ 2008 Runtime
RealPlayer
Realtek 8169 8168 8101E 8102E Ethernet Driver
Realtek High Definition Audio Driver
RealUpgrade 1.1
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2509488)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft Office 2007 System (KB2541012)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2541007)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Skins
Speakonia
Symantec AntiVirus
Synaptics Pointing Device Driver
TomTom HOME Visual Studio Merge Modules
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2509470)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2553975)
uTorrentBar Toolbar
WinRAR 4.00 (32-bit)
Yahoo! Software Update
.
==== Event Viewer Messages From Past Week ========
.
9/1/2011 6:05:05 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service MSIServer with arguments "" in order to run the server: {000C101C-0000-0000-C000-000000000046}
9/1/2011 5:25:15 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030}
9/1/2011 5:20:11 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo eeCtrl SASDIFSV SASKUTIL SPBBCDrv spldr SRTSP SRTSPX sxjr SYMTDI Wanarpv6
9/1/2011 5:20:11 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start.
9/1/2011 5:20:11 PM, Error: Service Control Manager [7000] - The WinDefend service failed to start due to the following error: The system cannot find the path specified.
9/1/2011 5:19:51 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
9/1/2011 5:19:43 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC}
9/1/2011 5:18:53 PM, Error: EventLog [6008] - The previous system shutdown at 5:17:23 PM on 9/1/2011 was unexpected.
9/1/2011 4:04:12 PM, Error: Service Control Manager [7001] - The MBAMService service depends on the MBAMProtector service which failed to start because of the following error: MBAMService is not a valid Win32 application.
9/1/2011 4:04:12 PM, Error: Service Control Manager [7000] - The MBAMProtector service failed to start due to the following error: MBAMProtector is not a valid Win32 application.
9/1/2011 4:02:24 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo SASDIFSV SASKUTIL sxjr
9/1/2011 4:02:24 PM, Error: Service Control Manager [7000] - The Parallel port driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
9/1/2011 12:11:30 PM, Error: EventLog [6008] - The previous system shutdown at 7:01:18 PM on 8/31/2011 was unexpected.
8/30/2011 1:10:47 PM, Error: EventLog [6008] - The previous system shutdown at 11:25:55 PM on 8/29/2011 was unexpected.
8/29/2011 9:53:23 PM, Error: Microsoft-Windows-WMPNSS-Service [14365] - Proximity detection failed due to unknown error '0x80004004'. The best proximity time detected was -1 milliseconds.
8/29/2011 9:36:34 PM, Error: EventLog [6008] - The previous system shutdown at 9:33:21 PM on 8/29/2011 was unexpected.
8/29/2011 3:15:17 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC djvo eeCtrl NetBIOS netbt nsiproxy PSched RasAcd rdbss SASDIFSV SASKUTIL Smb SPBBCDrv spldr SRTSP SRTSPX sxjr SYMTDI Tcpip tdx Wanarpv6
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The TCP/IP Registry Compatibility service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The Bonjour Service service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:52 PM, Error: Service Control Manager [7001] - The Apple Mobile Device service depends on the TCP/IP Protocol Driver service which failed to start because of the following error: A device attached to the system is not functioning.
8/29/2011 3:14:42 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89}
8/29/2011 3:14:42 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}
8/29/2011 3:13:34 PM, Error: EventLog [6008] - The previous system shutdown at 3:11:32 PM on 8/29/2011 was unexpected.
8/29/2011 3:07:52 PM, Error: EventLog [6008] - The previous system shutdown at 3:05:05 PM on 8/29/2011 was unexpected.
8/29/2011 11:03:21 AM, Error: EventLog [6008] - The previous system shutdown at 4:41:34 PM on 8/28/2011 was unexpected.
8/29/2011 10:57:15 PM, Error: EventLog [6008] - The previous system shutdown at 10:55:15 PM on 8/29/2011 was unexpected.
8/28/2011 9:20:52 AM, Error: EventLog [6008] - The previous system shutdown at 7:30:28 PM on 8/27/2011 was unexpected.
8/28/2011 4:18:55 PM, Error: EventLog [6008] - The previous system shutdown at 2:26:59 PM on 8/28/2011 was unexpected.
8/28/2011 10:23:56 AM, Error: EventLog [6008] - The previous system shutdown at 10:15:15 AM on 8/28/2011 was unexpected.
8/28/2011 10:13:35 AM, Error: EventLog [6008] - The previous system shutdown at 10:10:31 AM on 8/28/2011 was unexpected.
8/28/2011 1:56:19 PM, Error: EventLog [6008] - The previous system shutdown at 1:54:17 PM on 8/28/2011 was unexpected.
8/28/2011 1:46:36 PM, Error: EventLog [6008] - The previous system shutdown at 1:43:49 PM on 8/28/2011 was unexpected.
8/28/2011 1:43:47 PM, Error: Service Control Manager [7031] - The Symantec Settings Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 100 milliseconds: Restart the service.
8/28/2011 1:43:47 PM, Error: Service Control Manager [7031] - The Symantec Event Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 200 milliseconds: Restart the service.
8/28/2011 1:43:29 PM, Error: Service Control Manager [7034] - The Symantec AntiVirus service terminated unexpectedly. It has done this 3 time(s).
8/28/2011 1:33:14 PM, Error: Service Control Manager [7031] - The Symantec AntiVirus service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
8/28/2011 1:33:13 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Symantec Settings Manager service, but this action failed with the following error: An instance of the service is already running.
8/28/2011 1:33:13 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Symantec Event Manager service, but this action failed with the following error: An instance of the service is already running.
8/28/2011 1:33:03 PM, Error: Service Control Manager [7031] - The Symantec AntiVirus service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
8/28/2011 1:29:11 PM, Error: EventLog [6008] - The previous system shutdown at 11:45:35 AM on 8/28/2011 was unexpected.
8/27/2011 7:24:49 PM, Error: EventLog [6008] - The previous system shutdown at 7:21:55 PM on 8/27/2011 was unexpected.
8/27/2011 2:45:33 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Symantec Settings Manager service to connect.
8/27/2011 2:41:10 PM, Error: EventLog [6008] - The previous system shutdown at 2:06:37 PM on 8/27/2011 was unexpected.
8/27/2011 1:52:50 PM, Error: EventLog [6008] - The previous system shutdown at 1:50:12 PM on 8/27/2011 was unexpected.
8/27/2011 1:29:55 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service LiveUpdate with arguments "" in order to run the server: {03E0E6C2-363B-11D3-B536-00902771A435}
8/27/2011 1:28:34 PM, Error: EventLog [6008] - The previous system shutdown at 1:26:09 PM on 8/27/2011 was unexpected.
8/27/2011 1:21:28 PM, Error: EventLog [6008] - The previous system shutdown at 6:24:21 PM on 8/26/2011 was unexpected.
8/26/2011 5:39:34 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC djvo eeCtrl NetBIOS netbt nsiproxy PSched RasAcd rdbss SASDIFSV SASKUTIL Smb SPBBCDrv spldr SRTSP SRTSPX SYMTDI Tcpip tdx Wanarpv6
8/26/2011 5:38:43 PM, Error: EventLog [6008] - The previous system shutdown at 5:36:21 PM on 8/26/2011 was unexpected.
8/26/2011 5:33:37 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo eeCtrl SASDIFSV SASKUTIL SPBBCDrv spldr SRTSP SRTSPX SYMTDI Wanarpv6
8/26/2011 5:32:44 PM, Error: EventLog [6008] - The previous system shutdown at 5:30:35 PM on 8/26/2011 was unexpected.
8/26/2011 5:30:28 PM, Error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:28 PM, Error: Service Control Manager [7034] - The NTI Backup Now 5 Scheduler Service service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:28 PM, Error: Service Control Manager [7034] - The NTI Backup Now 5 Backup Service service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:28 PM, Error: Service Control Manager [7034] - The MobilityService service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:28 PM, Error: Service Control Manager [7034] - The LightScribeService Direct Disc Labeling Service service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:28 PM, Error: Service Control Manager [7034] - The IviRegMgr service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:28 PM, Error: Service Control Manager [7031] - The Empowering Technology Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/26/2011 5:30:27 PM, Error: Service Control Manager [7034] - The NTI Backup Now 5 Agent Service service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:27 PM, Error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:27 PM, Error: Service Control Manager [7034] - The Ati External Event Utility service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:27 PM, Error: Service Control Manager [7034] - The ArcSoft Connect Daemon service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 5:30:27 PM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
8/26/2011 5:29:06 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo SASDIFSV SASKUTIL
8/26/2011 5:13:50 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo
8/26/2011 5:13:48 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Empowering Technology Service service to connect.
8/26/2011 4:23:11 PM, Error: EventLog [6008] - The previous system shutdown at 4:21:14 PM on 8/26/2011 was unexpected.
8/26/2011 4:09:37 PM, Error: Service Control Manager [7034] - The PC Tools Security Service service terminated unexpectedly. It has done this 1 time(s).
8/26/2011 4:00:17 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334}
8/26/2011 3:40:27 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: djvo eeCtrl SPBBCDrv spldr SRTSP SRTSPX SYMTDI Wanarpv6
8/26/2011 3:39:39 PM, Error: EventLog [6008] - The previous system shutdown at 3:36:53 PM on 8/26/2011 was unexpected.
8/26/2011 3:33:08 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD DfsC djvo eeCtrl NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb SPBBCDrv spldr SRTSP SRTSPX SYMTDI Tcpip tdx Wanarpv6
8/26/2011 3:32:16 PM, Error: EventLog [6008] - The previous system shutdown at 3:30:09 PM on 8/26/2011 was unexpected.
8/26/2011 3:23:31 PM, Error: EventLog [6008] - The previous system shutdown at 3:20:45 PM on 8/26/2011 was unexpected.
.
==== End Of File ===========================
it wont let me access the folders with infected files to delete them,i cant run my computer in normal mode im in safe networking. My OS is vista home edt. i have a acer aspire. ive ran mbam several times yet its still there. "Security protection" found w32blaster wurm.
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm
Advertisement
Register to Remove

Re: Security Protection malware

Unread postby deltalima » September 3rd, 2011, 11:34 am

Checking your log - back soon.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Security Protection malware

Unread postby deltalima » September 3rd, 2011, 11:53 am

Hi vegetasaiyan,

Welcome to the forum.

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Please note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please do not run any scans or make any changes to the system unless I ask you too.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • If after 3 days you have not responded to this topic, it will be closed, and you will need to start a new one.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please Note:
The programs I ask you to run need to be run in Administrator Mode by... Right clicking the program file and selecting: Run as Administrator.
Additionally, the built-in User Account Control (UAC) utility, if enabled, may prompt you for permission to run the program.
When prompted, please select: Allow. Reference: User Account Control (UAC) and Running as Administrator

Remove P2P Programs

  • I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    µTorrent
    FrostWire 4.21.7
    uTorrentBar Toolbar


  • Please read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.
  • Note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

  • Click on start
  • Then Run
  • In the open text entry box please copy/paste appwiz.cpl Then click enter.
  • Press the "Remove" or "Change/Remove"...button to uninstall the programs listed above (in red) and any other P2P you have installed NOW.
  • Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

CKScanner

  • Please download CKScanner from here to your Desktop.
  • Make sure that CKScanner.exe is on the your Desktop before running the application!
  • Right click on CKScanner.exe and select: Run as Administrator then click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify the file saved
  • Double-click on the CKFiles.txt icon on your Desktop and copy/paste the contents in your next reply.

Next

  • Please download this tool from Microsoft.
  • Right click on MGADiag.exe and select: Run as Administrator.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in the window.
  • Save this file and copy/paste it in your next reply.

Please let me know if the computer is used for home or for business use.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Security Protection malware

Unread postby vegetasaiyan » September 3rd, 2011, 2:27 pm

ok i uninstalled the p2p stuff. The laptop is for home use. heres the logs,thank you for your help.

CKScanner - Additional Security Risks - These are not necessarily bad
scanner sequence 3.RP.11.BMAAVX
----- EOF -----

Diagnostic Report (1.9.0027.0):
-----------------------------------------
Windows Validation Data-->
Validation Status: Genuine
Validation Code: 0
Cached Online Validation Code: N/A, hr = 0x80070426
Windows Product Key: *****-*****-Q9CM8-KTDKK-8QXTR
Windows Product Key Hash: OI3PQUp2nK/Ysh5U6MY15ORIfio=
Windows Product ID: 89572-OEM-7332166-00029
Windows Product ID Type: 2
Windows License Type: OEM SLP
Windows OS version: 6.0.6002.2.00010300.2.0.002
ID: {BCEFF997-944D-4F20-A0E6-B7FB8BCA390F}(1)
Is Admin: Yes
TestCab: 0x0
LegitcheckControl ActiveX: N/A, hr = 0x80070002
Signed By: N/A, hr = 0x80070002
Product Name: Windows Vista (TM) Home Basic
Architecture: 0x00000000
Build lab: 6002.vistasp2_gdr.101014-0432
TTS Error:
Validation Diagnostic:
Resolution Status: N/A

Vista WgaER Data-->
ThreatID(s): N/A, hr = 0x80070002
Version: N/A, hr = 0x80070002

Windows XP Notifications Data-->
Cached Result: N/A, hr = 0x80070002
File Exists: No
Version: N/A, hr = 0x80070002
WgaTray.exe Signed By: N/A, hr = 0x80070002
WgaLogon.dll Signed By: N/A, hr = 0x80070002

OGA Notifications Data-->
Cached Result: N/A, hr = 0x80070002
Version: 2.0.48.0
OGAExec.exe Signed By: Microsoft
OGAAddin.dll Signed By: Microsoft

OGA Data-->
Office Status: 100 Genuine
Microsoft Office Professional 2007 - 100 Genuine
Microsoft Office Home and Student 2007 - 100 Genuine
OGA Version: Registered, 2.0.48.0
Signed By: Microsoft
Office Diagnostics: 77F760FE-153-80070002_7E90FEE8-175-80070002_025D1FF3-364-80041010_025D1FF3-229-80041010_025D1FF3-230-1_025D1FF3-517-80040154_025D1FF3-237-80040154_025D1FF3-238-2_025D1FF3-244-80070002_025D1FF3-258-3_E2AD56EA-765-d003_E2AD56EA-766-0_E2AD56EA-134-80004005_E2AD56EA-765-800a_E2AD56EA-766-191_E2AD56EA-148-80004005_16E0B333-89-80004005_B4D0AA8B-1029-80004005_B4D0AA8B-920-80070057

Browser Data-->
Proxy settings: N/A
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Win32)
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
Download signed ActiveX controls: Prompt
Download unsigned ActiveX controls: Disabled
Run ActiveX controls and plug-ins: Allowed
Initialize and script ActiveX controls not marked as safe: Disabled
Allow scripting of Internet Explorer Webbrowser control: Disabled
Active scripting: Allowed
Script ActiveX controls marked as safe for scripting: Allowed

File Scan Data-->

Other data-->
Office Details: <GenuineResults><MachineData><UGUID>{BCEFF997-944D-4F20-A0E6-B7FB8BCA390F}</UGUID><Version>1.9.0027.0</Version><OS>6.0.6002.2.00010300.2.0.002</OS><Architecture>x32</Architecture><PKey>*****-*****-*****-*****-8QXTR</PKey><PID>89572-OEM-7332166-00029</PID><PIDType>2</PIDType><SID>S-1-5-21-2590969754-410994182-1006661355</SID><SYSTEM><Manufacturer>Acer </Manufacturer><Model>Aspire 5515 </Model></SYSTEM><BIOS><Manufacturer>Acer</Manufacturer><Version>V1.00 </Version><SMBIOSVersion major="2" minor="4"/><Date>20081203000000.000000+000</Date></BIOS><HWID>EC323507018400F6</HWID><UserLCID>0409</UserLCID><SystemLCID>0409</SystemLCID><TimeZone>Eastern Standard Time(GMT-05:00)</TimeZone><iJoin>0</iJoin><SBID><stat>3</stat><msppid></msppid><name></name><model></model></SBID><OEM><OEMID>ACRSYS</OEMID><OEMTableID>ACRPRDCT</OEMTableID></OEM><GANotification><File Name="OGAAddin.dll" Version="2.0.48.0"/></GANotification></MachineData><Software><Office><Result>100</Result><Products><Product GUID="{91120000-0014-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Professional 2007</Name><Ver>12</Ver><Val>A2D6DC64913A778</Val><Hash>F0/Ly2xnH4rPr2w8pE+1IL99Orc=</Hash><Pid>81605-956-6525316-65055</Pid><PidType>1</PidType></Product><Product GUID="{91120000-002F-0000-0000-0000000FF1CE}"><LegitResult>100</LegitResult><Name>Microsoft Office Home and Student 2007</Name><Ver>12</Ver><PidType>19</PidType></Product></Products><Applications><App Id="15" Version="12" Result="100"/><App Id="16" Version="12" Result="100"/><App Id="18" Version="12" Result="100"/><App Id="19" Version="12" Result="100"/><App Id="1A" Version="12" Result="100"/><App Id="1B" Version="12" Result="100"/><App Id="A1" Version="12" Result="100"/></Applications></Office></Software></GenuineResults>

Spsys.log Content: 0x80070002

Licensing Data-->
Software Licensing service is not running.

Windows Activation Technologies-->
N/A

HWID Data-->
HWID Hash Current: NAAAAAEAAgABAAEAAwAAAAAAAwABAAEAJJTM9NiEfI24kcYXIEemevL0FBieFBr8rFYCtA==

OEM Activation 1.0 Data-->
N/A

OEM Activation 2.0 Data-->
BIOS valid for OA 2.0: yes
Windows marker version: 0x20000
OEMID and OEMTableID Consistent: yes
BIOS Information:
ACPI Table Name OEMID Value OEMTableID Value
APIC PTLTD APIC
FACP ATI Moray
HPET PTLTD HPETTBL
MCFG PTLTD MCFG
SLIC ACRSYS ACRPRDCT
EINJ PTL WHEAPTL
HEST PTL WHEAPTL
BERT PTL WHEAPTL
SSDT wheaos wheaosc
ERST PTL WHEAPTL
SSDT wheaos wheaosc
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware

Unread postby deltalima » September 3rd, 2011, 3:10 pm

Hi vegetasaiyan,

  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs,
    highlight Ask Toolbar
    click Remove
    highlight Conduit Engine
    click Remove
  • Close the Add or Remove Programs and the Control Panel windows.

Upload a File to Virustotal

Please go to Virustotal

Copy/paste this file and path into the white box at the top:
c:\windows\system32\config\systemprofile\appdata\local\utilman.exe

Press Submit - this will submit the file for testing.
Please wait for all the scanners to finish then copy and paste the results in your next response.

Download and run OTL
Download OTL by Old Timer and save it to your Desktop.
  • Right click on OTL.exe and select: Run as Administrator.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened
    • Extras.txt <-- Will be minimized
  • Please post the contents of these 2 Notepad files in your next reply.

Please download GMER Rootkit Scanner from here.
  • Right click the .exe file and select: Run as Administrator. If asked to allow gmer.sys driver to load, please consent
  • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan...click NO.
  • Run Gmer again and click on the Rootkit tab.
  • Look at the right hand side (under Files) and uncheck all drives with the exception of your C drive.
  • Make sure all other boxes on the right of the screen are checked, EXCEPT for "Show All".
  • Click on the "Scan" and wait for the scan to finish.
    Note: Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan.
  • When completed, click on the Copy button and right-click on your Desktop, choose "New" > Text document. Once the file is created, open it and right-click again and choose Paste or Ctrl+V. Save the file as gmer.txt and copy the information in your next reply.
  • Note: If you have any problems, try running GMER in SAFE MODE
Important! Please do not select the "Show all" checkbox during the scan..

Please post the GMER log along with OTL.txt and Extras.txt from the OTL scan into your next reply.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Security Protection malware

Unread postby vegetasaiyan » September 3rd, 2011, 5:13 pm

hi,im having a problem removing the ask toolbar its giving me an error message that the windows installer service cannot be accessed,and i dont see conduit listed in the programs. I'm running in safe mode with networking,when i try to run in normal the fake "security protection" pops up or it freezes. should i continue with the instructions or try to resolve this first?
vegetasaiyan
Member+
 
Posts: 12
Joined: September 1st, 2011, 6:23 pm

Re: Security Protection malware

Unread postby deltalima » September 3rd, 2011, 5:16 pm

should i continue with the instructions or try to resolve this first?


Please continue with the rest of the instructions, we will remove those programs later once the infections have been removed.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK

Re: Security Protection malware

Unread postby deltalima » September 6th, 2011, 5:08 pm

Due to a lack of response, this topic is now closed.

If you still require help, please open a new thread in the Infected? Virus, malware, adware, ransomware, oh my! forum, include a fresh FRST log, and wait for a new helper.
User avatar
deltalima
Admin/Teacher
Admin/Teacher
 
Posts: 7614
Joined: February 28th, 2009, 4:38 pm
Location: UK
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 130 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware