HPriser Posted November 23, 2008 Report Share Posted November 23, 2008 I’m getting Pop-Unders and Pop-Ups I never had before. I've seen this before here so it's not new but I can't follow the fixes described for other computers. Please help.Symptoms:There is an additional entry added to my System Configuration startup list:MSServerFollowed by the command: rundll32.exe C:\Windows\System32\tuvvSjvX.dll,#1and Location:HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunI ran ATF Cleaner.Here is my Hijack this file:Logfile of HijackThis v1.99.1Scan saved at 8:20:21 AM, on 11/23/2008Platform: Unknown Windows (WinNT 6.00.1905 SP1)MSIE: Internet Explorer v7.00 (7.00.6001.18000)Running processes:C:\Windows\system32\csrss.exeC:\Windows\system32\wininit.exeC:\Windows\system32\csrss.exeC:\Windows\system32\services.exeC:\Windows\system32\lsass.exeC:\Windows\system32\lsm.exeC:\Windows\system32\winlogon.exeC:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeC:\Windows\System32\svchost.exeC:\Windows\System32\svchost.exeC:\Windows\System32\svchost.exeC:\Windows\system32\svchost.exeC:\Windows\system32\SLsvc.exeC:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeC:\Windows\System32\spoolsv.exeC:\Windows\system32\svchost.exeC:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exeC:\Program Files\Pure Networks\Network Magic\nmapp.exeC:\Program Files\iRotate\iRotate.exeC:\Windows\system32\taskeng.exeC:\Windows\firefox.exec:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeC:\Windows\telnet.exeC:\Program Files\McAfee\VirusScan\McShield.exeC:\Program Files\McAfee\MPF\MPFSrv.exeC:\Windows\System32\svchost.exeC:\Program Files\SiteAdvisor\6253\SAService.exeC:\Windows\system32\DRIVERS\xaudio.exeC:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exeC:\PROGRA~1\McAfee\MSC\mcmscsvc.exeC:\Program Files\Windows Media Player\wmpnscfg.exeC:\Windows\system32\SearchIndexer.exeC:\Program Files\IncrediMail\bin\IMApp.exeC:\Windows\system32\SearchProtocolHost.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exec:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exeC:\Windows\system32\rundll32.exeC:\Windows\system32\SearchFilterHost.exeC:\Users\HPriser\Downloads\KEEPERS\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.surflite.info/search.phpR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files\IESurfBar\SurfLite Toolbar\tbhelper.dllO2 - BHO: TBSB01419 - {714758BE-281E-4BDA-9190-413BFBD3399B} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dllO2 - BHO: (no name) - {A878D9AC-C247-457D-AA2E-05D756334B4D} - C:\Windows\system32\mlJaWqQg.dllO2 - BHO: pl - {B200799F-9538-403d-9A6E-36F5942EC540} - C:\Windows\System32\fklame32.dllO3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dllO3 - Toolbar: (no name) - {91549F7B-90F9-4BBA-8599-7515EB4D87C1} - (no file)O3 - Toolbar: SurfLite Toolbar - {6226BA26-C017-4007-928C-DE9715C6FA68} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dllO4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkeyO4 - HKLM\..\Run: [nmctxth] "C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe"O4 - HKLM\..\Run: [nmapp] "C:\Program Files\Pure Networks\Network Magic\nmapp.exe" -autorun -nosplashO4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\tuvvSJbX.dll,#1O4 - HKCU\..\Run: [incrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /cO4 - Startup: iRotate.lnk = C:\Program Files\iRotate\iRotate.exeO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dllO9 - Extra button: SurfLite Toolbar - {6226BA26-C017-4007-928C-DE9715C6FA68} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dllO9 - Extra 'Tools' menuitem: SurfLite Toolbar - {6226BA26-C017-4007-928C-DE9715C6FA68} - C:\Program Files\IESurfBar\SurfLite Toolbar\dyn_surflite_aff_1000.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dllO11 - Options group: [iNTERNATIONAL] International*O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cabO16 - DPF: {1851174C-97BD-4217-A0CC-E908F60D5B7A} (Hewlett-Packard Online Support Services) - https://h20364.www2.hp.com/CSMWeb/Customer/...DataManager.CABO16 - DPF: {33415AC7-AFFA-4D55-B41C-C64C0D07DFCA} (Hewlett-Packard Printer Diagnostics) - http://h50203.www5.hp.com/HPISWeb/Customer...SWebManager.CABO16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file:///E:/CDVIEWER/CdViewer.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{3E8F4118-88CE-49D9-B170-C29BA859AB6E}: NameServer = 85.255.112.120;85.255.112.170O18 - Protocol: pure-go - {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dllO18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dllO23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\Windows\System32\CTSVCCDA.EXEO23 - Service: Network Service (firefox) - Unknown owner - C:\Windows\firefox.exeO23 - Service: Logical Disk Service (flashget) - Unknown owner - C:\Windows\flashget.exe (file missing)O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exeO23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exeO23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exeO23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeO23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\McShield.exeO23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exeO23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exeO23 - Service: Pure Networks Net2Go Service (nmraapache) - Unknown owner - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe" -k runservice (file missing)O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exeO23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6253\SAService.exeO23 - Service: Windows Tribute Service - Unknown owner - C:\Windows\system32\kdzmq.exeO23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe Link to post Share on other sites
HPriser Posted November 24, 2008 Author Report Share Posted November 24, 2008 (edited) SOLVEDOK. I solved the problem. Here is what I did:Downloaded Malwarebytes Anti-Malware (mbam) from http://www.besttechie.net/tools/mbam-setup.exe, and saved it. * Double-click on Download_mbam-setup.exe to install the application. * When the installation begins, follow the prompts and do not make any changes to default settings. * When installation has finished, make sure you leave both of these checked: o Update Malwarebytes' Anti-Malware o Launch Malwarebytes' Anti-Malware * Then click Finish. * MBAM will automatically start and you will be asked to update the program before performing a scan. If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.My notes for using MBAM are:Launch Malwarebytes’ Anti-MalwareCheck the Update Tab and check for updates.Click Scanner Tab and Check “Perform Full Scan.â€Â· Click “Scanâ€Â· Uncheck K drive and all other drives except C.· click on the “Start Scan†button. · The scan will begin and "Scan in progress" will show at the top. This will take about 1 hour 25 minutess to complete for C drive only.· When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".· Click OK to close the message box and continue with the removal process.· Back at the main Scanner screen, click on the Show Results button to see a list of any Malware that was found.· Make sure that everything is checked, and click Remove Selected.· When removal is completed, a log report will open in Notepad and you may be prompted to restart your computer. (see Note below)· The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.· Exit MBAM.Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware. Edited November 24, 2008 by HPriser Link to post Share on other sites
Andro1d Posted November 24, 2008 Report Share Posted November 24, 2008 Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. Link to post Share on other sites
Recommended Posts