I have a similar problem as another user of this forum regarding poping up new tabs with random webpages in firefox and windows update error 80072EFE. Before I ran several anti malware programs i also had this online norton antivirus message. I appreciate any help, and thanks in advance!
Here is the Hijack log
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 21:03:25, on 24.08.2010 Platform: Windows 7 (WinNT 6.00.3504) MSIE: Internet Explorer v8.00 (8.00.7600.16385) Boot mode: Normal
Welcome. Thank you for using Dell Community Forums.
I am reviewing your log. In the meantime, you can help me by addressing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE.
* Some CD Emulators use a hidden driver which can be seen as a rootkit, and can also interfere with a correct read of the state of the machine by our tools.
Please uninstall the following software before performing any of the pre-posting scans. It can be re-installed once your helper has determined the cleaning process is complete. The following should be uninstalled via the Control Panel: Daemon Tools and Daemon Tools Lite Alcohol 120% and 52% AstroBurn StarBurn For a complete uninstall, and so our tools may run unhindered, please also follow the steps on DuplexSecure's page for uninstalling the SPTD driver which these emulators use. http://www.duplexsecure.com/en/faq Scroll down to: Quote: Q: How can I remove SPTD driver on 32-bit OS?
Follow the instructions. Quote: Q: How can I remove SPTD driver on 32-bit OS? A: To remove SPTD, simply download SPTD setup file "SPTDinst-v162-x86.exe" for Windows 2000/XP/2003/Vista (32-bit) [911,856 bytes] and execute it. In dialog that appears press "Uninstall" button and then SPTD will remove itself from your Windows installation.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.
* During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.
* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
I look forward to your reply so we can begin cleaning.
No Reply within 3 days will result in this topic being closed, and I will remove it from my subscriptions. If you require more time, please let me know.
Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.
Hi Ive done everything you did write above except the system restore function. Except my optical drive there are no HD appearing in the window for selecting the drive for the stored windows state. Furthermore there are no drives (except optical) listed in the Drive Administration (I dont know the respective englisch name for german "Datenträgerverwaltung" - its the window where you create and modify partitions in windows 7)
A small box will open, with an explanation about the tool.
Click Yes at the prompt for Optional Scan.
When done, DDS will open two (2) logs
1. DDS.txt 2. Attach.txt
Save both reports to your desktop.
Copy/paste both logs to your reply on the forum. Do not attach them.
Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.
I see that you have Malwarebytes' Anti-Malware installed. Please update, run a scan and post the log.
If you encounter any problems while downloading the updates,
manually download them fromhere and just double-click on mbam-rules.exe to install. Alternatively, you can update through MBAM's interface from a clean computer, copy the definitions (rules.ref) located in C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
On the Scanner tab:
Make sure the "Perform Quick Scan" option is selected.
Then click on the Scan button.
If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
The scan will begin and "Scan in progress" will show at the top.
It may take some time to complete so please be patient.
When the scan is finished, a message box will say "The scan completed successfully.
Click 'Show Results' to display all objects found".
Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
Click on the Show Results button to see a list of any malware that was found.
Make sure that everything is checked, and click Remove Selected.
When removal is completed, a log report will open in Notepad.
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report along with a fresh HijackThis log into your next reply and exit MBAM.
Note:-- If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
-- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes.
**If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from HERE
DDS (Ver_10-03-17.01) - NTFSx86 Run by S. Manna at 2:04:15,15 on 06.09.2010 Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20 Microsoft Windows 7 Professional 6.1.7600.0.1252.49.1031.18.2038.1048 [GMT 2:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft Windows 7 Professional Boot Device: \Device\HarddiskVolume1 Install Date: 12.05.2010 21:24:49 System Uptime: 09.05.2010 21:59:03 (2861 hours ago)
Motherboard: Dell Inc. | | 0N6705 Processor: Intel(R) Core(TM)2 Duo CPU T5250 @ 1.50GHz | Microprocessor | 1500/166mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 24 GiB total, 5,742 GiB free. D: is FIXED (NTFS) - 0 GiB total, 0,07 GiB free. E: is FIXED (NTFS) - 98 GiB total, 66,324 GiB free. F: is FIXED (NTFS) - 176 GiB total, 13,402 GiB free. G: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
No restore point in system.
==== Installed Programs ======================
32 Bit HP CIO Components Installer Acrobat.com Adobe AIR Adobe Encore CS4 Codecs Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Media Encoder CS4 Exporter Adobe Media Encoder CS4 Importer Adobe Media Player Adobe Premiere Pro CS4 Third Party Content Adobe Setup Adobe Soundbooth CS4 Codecs AGI License Manager Anki Apple Application Support Apple Mobile Device Support Apple Software Update Audacity 1.2.6 Avira AntiVir Personal - Free Antivirus Bamboo Dock Bamboo Dock 3.3 Bonjour BufferChm CamStudio Codec Pack - All In 1 6.0.3.0 Condor: The Competition Soaring Simulator 1.1.0 Copy CoreAVC Professional Edition (remove only) Corel Painter X Cursor Attention Dell AIO Printer A920 Dell Driver Download Manager Destinations DeviceDiscovery DJ_AIO_06_F2400_SW_Min EasternAlps Scenery 2.0 ElsterFormular F2400 Fax-Lösungen Free Audio CD Burner version 1.4 Free YouTube to MP3 Converter version 3.7 FreeTrack v2.2.0.279 GPBaseService2 Haali Media Splitter HP Customer Participation Program 13.0 HP Deskjet F2400 All-In-One Driver Software 13.0 Rel .6 HP Imaging Device Functions 13.0 HP Print Projects 1.0 HP Smart Web Printing 4.60 HP Solution Center 13.0 HP Update HPPhotoGadget hpPrintProjects HPProductAssistant hpWLPGInstaller ImageMixer 3 SE Ver.3 IrfanView (remove only) iTunes Java Auto Updater Java(TM) 6 Update 20 Laptop Integrated Webcam Driver (1.04.01.1011) Live 8.0.4 Malwarebytes' Anti-Malware MarketResearch Mathcad 15 F000 MathPlayer Microsoft Camcorder Microsoft Primary Interoperability Assemblies 2005 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Mozilla Firefox (3.6.8) neroxml PC Connectivity Solution QuickTime SAMSUNG Mobile Composite Device Software Samsung Mobile Modem Device Software SAMSUNG Mobile Modem Driver Set Samsung Mobile phone USB driver Drive Software SAMSUNG Mobile USB Modem 1.0 Software SAMSUNG Mobile USB Modem Software Samsung New PC Studio Samsung New PC Studio USB Driver Installer SAMSUNG USB Mobile Device Software SamsungConnectivityCableDriver Scan SeaTools for Windows SigmaTel Audio Skype Toolbars Skype™ 4.2 SmartWebPrinting SolutionCenter Status Stifttablett STK 9 System Requirements Lab for Intel Toolbox TrayApp Trust WB-3400T Webcam Uninstall 1.0.0.1 VLC media player 1.0.5 Warcraft III Warcraft III: All Products WebReg Windows-Treiberpaket - Nokia pccsmcfd (10/12/2007 6.85.4.0) WinRAR XviD Video Codec (remove only)
I tried to do the scan several times but it always stops at a the same file in the windows temp directory and is not able to move on. i tried to reinstall MBAM and also deactivate my Antivir during the scan process but it didnt help. i used MBAM before i opened the thread here and it worked then. it found a few JAVA. malware and i removed them into quarantine. after i scanned again to be sure, and it found 0 infected objects.
It appears that your system is not a 64-bit Windows 7, therefore we can run Combofix. If you are not sure of whether you are running a 32-bit or a 64-bit version of Microsoft Windows 7: * Try right-clicking on the Computer icon on the Desktop and selecting Properties from the popup context menu. In the System Type it should say whether it is a 32-bit or a 64-bit operating system. If it is NOT 64-bit we are okay with ComboFix.
Please visit this webpage for download links, and instructions for running ComboFix (If you have a prior copy of Combofix, delete it now!) :
Please login as Administrator. Do not attempt to simply run ComboFix with Admin Approval Mode. Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. <-- Important
Double click on ComboFix.exe & follow the prompts.
As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
* Additional information on A/V control HERE. * ComboFix is not intended for use with servers.
While Running combofix there was the message that rootkit activity was detected and a restart is nececcassary. after the scan completed and the "logfile will be displayed soon" there was an error message saying that a certain registry entry could not be deleted. I dont remember exactly what this message was saying. Anyway, combofix seamed to fix something, Windows updates are possible now, the harddrives are displayed correctly, until now there were no redirects in firefox and MBAM could perform a full scan with no infections found. Can you tell what the problem was, or what kind of infections i had to deal with, and were was it from? Is it possible that data was being stolen?
And: thanks for now, of what I can see now, you really helped me!
here is the Combofix logfile:
ComboFix 10-09-07.01 - S. Manna 07.09.2010 21:52:16.1.2 - x86 Microsoft Windows 7 Professional 6.1.7600.0.1252.49.1031.18.2038.1143 [GMT 2:00] ausgeführt von:: c:\users\S. Manna\Desktop\ComboFix.exe .
(((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) .
Infizierte Kopie von c:\windows\system32\drivers\rdyboost.sys wurde gefunden und desinfiziert Kopie von - Kitty had a snack :p wurde wiederhergestellt . ((((((((((((((((((((((( Dateien erstellt von 2010-08-07 bis 2010-09-07 )))))))))))))))))))))))))))))) .
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor Ver.3.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ImageMixer 3 SE Camera Monitor Ver.3.lnk backup=c:\windows\pss\ImageMixer 3 SE Camera Monitor Ver.3.lnk.CommonStartup backupExtension=.CommonStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FaxCenterServer] 2006-11-03 15:09 312200 ----a-w- c:\program files\Dell PC Fax\fm3032.exe
I don't read German well, but it appears that you had a rootkit infecting a system file. The file was disinfected and restored because there was a backup on the system, thanks to ComboFix. Please run an online virus scan by Kaspersky from HERE.
1. At the main page. Press on " Accept". After reading the contents. 2. At the next window Select Update. Allow the Database to update. Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run. 3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. The scan may take a few minutes to complete. 4. Select Scan Report. 5. If any threats were found they will appear in the report 6. Select "Save error report as" Then in the file name just type in kaspersky Under "save as type" select text .txt Save it to your Desktop.
Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well. If that report looks good and everything is running well, we'll update Java, remove our tools, reset System Restore, and you'll be good to go, so let me know how things are running when your return.
Bugbatter
4 Apprentice
•
20487 Posts
596
0
Posted September 4th, 2010 06:00
Welcome. Thank you for using Dell Community Forums.
I am reviewing your log. In the meantime, you can help me by addressing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE.
* Some CD Emulators use a hidden driver which can be seen as a rootkit, and can also interfere with a correct read of the state of the machine by our tools.
Please uninstall the following software before performing any of the pre-posting scans. It can be re-installed once your helper has determined the cleaning process is complete.
The following should be uninstalled via the Control Panel:
Daemon Tools and Daemon Tools Lite
Alcohol 120% and 52%
AstroBurn
StarBurn
For a complete uninstall, and so our tools may run unhindered, please also follow the steps on DuplexSecure's page for uninstalling the SPTD driver which these emulators use.
http://www.duplexsecure.com/en/faq
Scroll down to:
Quote:
Q: How can I remove SPTD driver on 32-bit OS?
Follow the instructions.
Quote:
Q: How can I remove SPTD driver on 32-bit OS?
A: To remove SPTD, simply download SPTD setup file "SPTDinst-v162-x86.exe" for Windows 2000/XP/2003/Vista (32-bit) [911,856 bytes] and execute it.
In dialog that appears press "Uninstall" button and then SPTD will remove itself from your Windows installation.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.
* During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.
* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
I look forward to your reply so we can begin cleaning.
No Reply within 3 days will result in this topic being closed, and I will remove it from my subscriptions. If you require more time, please let me know.
Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.