Hi,
I think I have a serious problem with my home PC (this is my work laptop).
My sons were playing somewhere and clicked something and they got a virus warning from Norton 2009. They came and got me and I clicked on the action for Norton AV to delete the files (happened twice), but now I am getting:
1. popups on virtually every page I go to - prompting me for go211.com and other sites
2. i've lost the ability to start a lot of programs, including mozilla - when I click on it from the desktop, from program files..etc, from the run bar, etc. It'll show it working for a second and it will be shut down. I can see it starting in taskmanager, but then it disappears. The same thing with Combofix.exe. Shows up for a second and gone.
3. the ability to visit certain URL's - such as
http://forums.whatthetech.com/iesearch_hom...slo_t88970.htmlI tried copying and pasting into the address bar, clicking by sending myself a link via Yahoo messenger, etc. Nothing works. It goes to the "cannot display the page" error box. (yes, I did enter the correct URL. In fact, I copied it to a text file, moved it over to that pc via my thumb drive and pasted it into the address bar.)
4. i downloaded some of the malware removal things to this pc, copied them to my flash thumb drive and then copied them to the desktop of that pc. I tried running them and they wouldn't run (like Mozilla). These included combofix and mbam-setup.exe (i was able to run ATF-Cleaner)
I WAS able to start to run FixIEDef.exe - it starts but at about halfway through the file system scan, it gives me the following error: "AutoIt Error Line -1" Error: Variable must be of type "Object".
5. google searches will show results, but when I click the links, they will go to different ad sites.
6. inability to start some executables or files - like mozilla, those malware exe's, others.
Otherwise, it "appears" that the computer is running ok. I know I have one of these viruses. Please help me to remove it.
I was just now able to do a Hijack this...here's the result file (i couldn't upload it to trendmicro, i got a "IE cannot display the webpage" error.)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:09:35, on 7/30/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchos
t.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\spools
v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
C:\Program Files\Symantec\LiveUpdate\
AluSchedul
erSvc.exe
C:\WINDOWS\system32\nvsvc3
2.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe
C:\WINDOWS\system32\HPZipm
12.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
C:\WINDOWS\System32\svchos
t.exe
C:\PROGRA~1\COMMON~1\SYMAN
T~1\CCPD-L
C\symlcsvc
.exe
F:\HiJackThis.exe
R0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://espn.go.com/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Window Title = Windows Internet Explorer provided by Comcast
R1 - HKCU\Software\Microsoft\Wi
ndows\Curr
entVersion
\Internet Settings,ProxyServer = :0
O2 - BHO: {63cf3c74-311e-e20a-7084-2
212826e740
3} - {3047e628-2122-4807-a02e-e
11347c3fc3
6} - C:\WINDOWS\system32\ccttiz
.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F
4628F01010
C} - C:\PROGRA~1\COMMON~1\SYMAN
T~1\IDS\IP
SBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D
4DAF1D92D4
3} - C:\Program Files\Java\jre1.6.0_02\bin
\ssv.dll
O2 - BHO: (no name) - {B48733BA-E9C0-4F04-863B-3
E138C0BD43
6} - C:\WINDOWS\system32\ddcCRK
da.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
dll,NvStar
tup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
ay.dll,NvT
askbarInit
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [ddoctorv2] "C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe" /P ddoctorv2
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin
\jusched.e
xe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKCU\..\Run: [IMC] C:\Program Files\FriendFinder\FriendF
inder Messenger 4\imc.exe
O4 - HKUS\S-1-5-21-117609710-84
2925246-10
60284298-1
003\..\Run
: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
.exe (User '?')
O4 - HKUS\S-1-5-21-117609710-84
2925246-10
60284298-1
003\..\Run
: [IMC] C:\Program Files\FriendFinder\FriendF
inder Messenger 4\imc.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICR
OS~1\DW\dw
trig20.exe
" -t (User '?')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICR
OS~1\DW\dw
trig20.exe
" -t (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1
\Office10\
EXCEL.EXE/
3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_02\bin
\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Program Files\Java\jre1.6.0_02\bin
\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Start WebEx MeetMeNow - {F5AD6CC5-776C-4DBB-B38F-F
5404A3582F
3} - C:\WINDOWS\Downlo~1\MyWebE
x\419\mwmi
e.dll
O9 - Extra 'Tools' menuitem: Start WebEx MeetMeNow - {F5AD6CC5-776C-4DBB-B38F-F
5404A3582F
3} - C:\WINDOWS\Downlo~1\MyWebE
x\419\mwmi
e.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-F
CFDF33E833
C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1167252926573O16 - DPF: {6A344D34-5231-452A-8A57-D
064AC9B786
2} (Symantec Download Manager) -
https://webdl.symantec.com/activex/symdlmgr.cabO20 - Winlogon Notify: ddcCRKda - ddcCRKda.dll (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
iceService
.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
AluSchedul
erSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\
LuComServe
r_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
2.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: SupportSoft Sprocket Service (ddoctorv2) (sprtsvc_ddoctorv2) - SupportSoft, Inc. - C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMAN
T~1\CCPD-L
C\symlcsvc
.exe
--
End of file - 6672 bytes
Start Free Trial