Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: HELP! Virus/spyware is preventing internet access!  (Read 21682 times)

0 Members and 1 Guest are viewing this topic.

iHabNoTeef

    Topic Starter


    Greenhorn

    HELP! Virus/spyware is preventing internet access!
    « on: January 13, 2009, 04:18:57 PM »
    Hi, I am running Windows XP and I believe my computer is infected with spyware that prevents internet access. Last week, I had spyware that I removed using SUPERAntiSpyware that would constantly crash and restart explorer.exe and prevent access to antivirus websites. I realized yesterday that my computer was infected with spyware because I would get a fake wallpaper warning me about spyware and an icon in the taskbar saying my computer was infected--this was the actual spyware. The taskbar icon told me to go to real-av.org and download the antivirus scanner, but I did not. I was sent to the site automatically though. I scanned my computer again with SUPERAntiSpyware and it removed the spyware and I do not get that message anymore. But now, as soon as I started up my computer, I did not have internet access. I could type a URL into Internet Explorer and FireFox but it would not go to the site. Both browsers would just stop after I entered in the URL, there were no messages saying I could not connect to the website--just the same blank screen as when I opened the browser up. Also, I do know that the spyware is not completely gone because it is still trying to send me to a website, but it is a different one than before. Any help would be greatly appreciated!

    Also, I have checked my hosts file.

    EDIT: I keep getting sent to www!.lsp-test-nax.ind.in/land/eurl?code=15, I believe that is the only site not blocked on my computer.
    « Last Edit: January 13, 2009, 06:00:41 PM by iHabNoTeef »

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: HELP! Virus/spyware is preventing internet access!
    « Reply #1 on: January 13, 2009, 06:21:46 PM »
    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
    • Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    • Then search for TDSSserv.sys
    • Let me know if you find this or not.
    • If you do find it, right click on it, and select “Disable”. Do not try to uninstall it.
    • Also if this is found and you disable it.
    • Now reboot and see if you can run the other scans that would not run.
    .
    ----------

    Now try to run the scans found here http://www.computerhope.com/forum/index.php/topic,46313.0.html

    Post the 3 logs when complete.

    iHabNoTeef

      Topic Starter


      Greenhorn

      Re: HELP! Virus/spyware is preventing internet access!
      « Reply #2 on: January 15, 2009, 05:02:25 PM »
      HijackThis log:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 6:57:18 PM, on 1/15/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\CTsvcCDA.EXE
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
      c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
      C:\WINDOWS\system32\CTHELPER.EXE
      C:\WINDOWS\system32\dla\tfswctrl.exe
      C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
      C:\Program Files\PowerISO\PWRISOVM.EXE
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
      C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\UltraMon\UltraMon.exe
      C:\Documents and Settings\Albert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
      C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
      C:\Program Files\UltraMon\UltraMonTaskbar.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Trend Micro\HijackThis\sniper.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/yme/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://91.121.105.86:18080/gui/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
      O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Catcher Class - {ADECBED6-0366-4377-A739-E69DFBA04663} - C:\Program Files\Moyea\FLV Downloader\MoyeaCth.dll
      O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: OToolbarHelper Class - {EAD3A971-6A23-4246-8691-C9244E858967} - C:\Program Files\PayPal\PayPal Plug-In\PayPalHelper.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
      O3 - Toolbar: PayPal Plug-In - {DC0F2F93-27FA-4f84-ACAA-9416F90B9511} - C:\Program Files\PayPal\PayPal Plug-In\OToolbar.dll
      O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
      O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
      O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
      O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
      O4 - HKLM\..\Run: [Adobe Version Cue CS2] c:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
      O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [UltraMon] "C:\Program Files\UltraMon\UltraMon.exe" /auto
      O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Albert\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
      O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\DOCUME~1\Albert\LOCALS~1\Temp\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware
      O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Download with ImTOO YouTube Video Converter - C:\Program Files\ImTOO\YouTube Video Converter\upod_link.HTM
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
      O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
      O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
      O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
      O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
      O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Broken Internet access because of LSP provider 'c:\windows\temp\ntdll64.dll' missing
      O16 - DPF: vzTCPConfig - http://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
      O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommon/download/FIOS/tgctlcm.cab
      O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} - http://gamedownload.ijjimax.com/gamedownload/dist/hgstart/HGPlugin11USA.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1134240680890
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140987175750
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Protocol: talkto - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - c:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
      O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
      O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
      O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
      O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: OracleDBConsoleorcl - Oracle Corporation - C:\oracle\product\10.2.0\db_1\bin\nmesrvc.exe
      O23 - Service: OracleOraDb10g_home1iSQL*Plus - Oracle - C:\oracle\product\10.2.0\db_1\bin\isqlplussvc.exe
      O23 - Service: OracleOraDb10g_home1TNSListener - Unknown owner - C:\oracle\product\10.2.0\db_1\BIN\TNSLSNR.exe
      O23 - Service: OracleServiceORCL - Oracle Corporation - c:\oracle\product\10.2.0\db_1\bin\ORACLE.EXE
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
      O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe

      --
      End of file - 15077 bytes


      The other logs are attached.

      [attachment deleted by admin]

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: HELP! Virus/spyware is preventing internet access!
      « Reply #3 on: January 15, 2009, 05:49:54 PM »
      Everything in the MBAM log says No action taken. Please run it again and let it fix what it finds. Post the new log.

      ---

      After that is complete.

      Download random's system information tool (RSIT) by random/random from and save it to your Desktop.

      • Double click on RSIT.exe to run.
      • Click Continue at the disclaimer screen.
      • Once it has finished, two logs will open.
      • log.txt <will be maximized and info.txt <will be minimized
      • Please post the contents of both logs in the next reply.

      the_phantom_boy



        Greenhorn

        Re: HELP! Virus/spyware is preventing internet access!
        « Reply #4 on: January 16, 2009, 09:13:33 AM »
        Did u try <<LINK REMOVED>>
        It was made for removal of the "smithfraud" malware, but it can fix a lot of corruptions or your system (and the internet access problem)...

        Please see here http://www.computerhope.com/forum/index.php/topic,57605.0.html
        « Last Edit: January 16, 2009, 01:46:07 PM by evilfantasy »

        iHabNoTeef

          Topic Starter


          Greenhorn

          Re: HELP! Virus/spyware is preventing internet access!
          « Reply #5 on: January 16, 2009, 10:54:33 PM »
          I've attached two mbam logs, one is after deleting the items in the previous logs. Also, there is another one that I got more recently.

          [attachment deleted by admin]

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: HELP! Virus/spyware is preventing internet access!
          « Reply #6 on: January 17, 2009, 06:21:16 PM »
          A malicious .DLL file is disrupting the LSP chain on your computer. We need to get rid of it.

          • Please download LSPFix
          • Run the LSPFix.exe that you have just finished downloading.
          • Check the I know what I'm doing box.
          • In the Keep box you should see one or more instances of ntdll64.dll
          • Select every instance of ntdll64.dll and move each one to the Remove box by clicking the >> button.
          • If the ntdll64.dll file only appears on the right side then just click fix checked and close the program.
          • When you are done click Finish>>
          .
          Reboot the computer.

          ----------

          Open HijackThis and select Do a system scan only.

          Place a check mark next to the following entries: (if there)

          - R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/yme/*http://www.yahoo.com
          - R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search
          - R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          - R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          - R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
          - R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
          - O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
          - O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\DOCUME~1\Albert\LOCALS~1\Temp\SSUPDATE.EXE Software\SUPERAntiSpyware.com\SUPERAntiSpyware


          Important: Close all open windows except for HijackThis and then click Fix checked.

          Once completed, exit HijackThis and restart the computer.

          Do you have internet connection now?

          iHabNoTeef

            Topic Starter


            Greenhorn

            Re: HELP! Virus/spyware is preventing internet access!
            « Reply #7 on: January 17, 2009, 07:06:15 PM »
            Everything works now, thanks a lot!  ;D

            Are there any programs that you recommend buying or downloading to prevent this from happening in the future?

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: HELP! Virus/spyware is preventing internet access!
            « Reply #8 on: January 17, 2009, 07:21:33 PM »
            Yes we need to make sure everything is gone now.

            Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

            Link #1
            Link #2

            **Note:  It is important that it is saved directly to your Desktop

            Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

            Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
             
            Double click combofix.exe & follow the prompts.

            For Windows XP Systems install the Recovery Console:

            - If you are using Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is active (if possible) and click Yes.
            - If for some reason your Internet is not working click No.
            - If you are not using Windows XP, you will not be prompted.
            - When prompted to accept the EULA click OK.
            - Accept Microsoft's EULA (Click Yes).
            - When you are told that the RC is installed correctly click YES to continue scanning for malware.

            When finished ComboFix will produce a log for you.
            Post the ComboFix log in your next reply.

            Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

            Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

            iHabNoTeef

              Topic Starter


              Greenhorn

              Re: HELP! Virus/spyware is preventing internet access!
              « Reply #9 on: January 18, 2009, 09:35:22 PM »
              The ComboFix log is attached.

              [attachment deleted by admin]

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: HELP! Virus/spyware is preventing internet access!
              « Reply #10 on: January 18, 2009, 10:55:58 PM »
                OK getting closer.

                • Click START then RUN
                • Now type Combofix /u in the runbox
                • Make sure there's a space between Combofix and /u
                • Then hit Enter.
                • The above procedure will:
                • Delete the following:
                • ComboFix and its associated files and folders.
                • Reset the clock settings.
                • Hide file extensions, if required.
                • Hide System/Hidden files, if required.
                • Set a new, clean Restore Point.
                ----------

                Download
              ATF Cleaner by Atribune to your Desktop.

              Alternate download link

              Note: Vista users must use Run As Administrator
              • Under Main: Select Files to Delete choose: Select All.
              • Click the Empty Selected button.
              • If you use Firefox browser click Firefox at the top and choose: Select All
              • Click the Empty Selected button.
                If you would like to keep your saved passwords click No at the prompt.
              • If you use Opera browser click Opera at the top and choose: Select All
              • Click the Empty Selected button.
                If you would like to keep your saved passwords click No at the prompt.
              • Click Exit on the Main menu to close the program.
              Note that your system will run slower for a reboot or two after having used this tool so don't panic.

              ----------

              Download OTCleanIt.exe and save it to your Desktop.
              • Double-click OTCleanIt.exe.
              • Click the CleanUp! button.
              • Select Yes when the "Begin cleanup Process?" prompt appears.
              • If you are prompted to Reboot during the cleanup, select Yes.
              • The tool will delete itself once it finishes, if not delete it yourself.
              .
              Important: Restart the computer before continuing.

              ----------

              Run the Kaspersky Online Scanner

              In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

              • Click on SCAN NOW
              • Click Accept.
              • The program will then begin downloading the latest definition files.
              • Once the files have been downloaded locate the Scan Settings and have it scan My Computer.
              • The scan will take a while, so be patient and let it finish.
              When the scan is done, in the Scan is complete window, any infection is displayed.
              There is no option to clean/disinfect, however, we need to analyze the information on the report.

              To obtain the report:
              Click on: Save Report As
              • Next, in the Save as prompt, Save in area, select: Desktop.
              • In the File name area use KScan, or something similar.
              • In Save as type: click the drop arrow and select: Text file [*.txt]
              • Then, click: Save


              Copy and paste the Kaspersky Online Scanner Report in your next reply.

              Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

              iHabNoTeef

                Topic Starter


                Greenhorn

                Re: HELP! Virus/spyware is preventing internet access!
                « Reply #11 on: January 19, 2009, 12:22:27 PM »
                Ok, so far everything has been completed except for the Kaspersky scan. It has been 11 hours and the scan is only at 14%. Does it usually take that long?

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: HELP! Virus/spyware is preventing internet access!
                « Reply #12 on: January 19, 2009, 12:27:14 PM »
                No it shouldn't take more than a few hours at most. Has it found anything?

                iHabNoTeef

                  Topic Starter


                  Greenhorn

                  Re: HELP! Virus/spyware is preventing internet access!
                  « Reply #13 on: January 19, 2009, 12:29:39 PM »
                  So far it found Exploit.Java.Gimsh.a in my Java folder.

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: HELP! Virus/spyware is preventing internet access!
                  « Reply #14 on: January 19, 2009, 12:30:37 PM »
                  Let it go for a while longer then. Hopefully it will speed up after it gets through scanning certain files.