I loaned my laptop out to a friend and when I received it back he said the internet didn't work anymore. I opened IE and also tried Chrome and it would give me a pop up saying your computer is infected and would try to re-direct me to a site to buy their malware software for $80. I have since been able to get rid of this nasty little thing but I still have a problem. My computer's taskbar shows me connected to the internet and I was even able to use the internet to update my MBA-M but anytime I open a webpage it says it can't be displayed, check to see if its typed correctly, etc, etc. I also couldn't log into any messenger program either. When I ran the MBA-M is got rid of 2 malwares and I re-booted and ran MBA-M again and it showed the same two infections again. Any ideas/help would be greatly appreciated, I am truly stumped!
MBA-M LOG
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4306
Windows 6.0.6000
Internet Explorer 7.0.6000.17037
7/12/2010 9:23:10 PM
mbam-log-2010-07-12 (21-23-10).txt
Scan type: Full scan (C:\|)
Objects scanned: 197070
Time elapsed: 46 minute(s), 33 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
GMER ONE LOG
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit quick scan 2010-07-12 20:01:48
Windows 6.0.6000
Running: yobgicfw.exe; Driver: C:\Users\Andrew\AppData\Local\Temp\uwliqpob.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
GMER TWO LOG
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-12 20:30:57
Windows 6.0.6000
Running: yobgicfw.exe; Driver: C:\Users\Andrew\AppData\Local\Temp\uwliqpob.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- EOF - GMER 1.0.15 ----
DDS LOG
DDS (Ver_10-03-17.01) - NTFSx86
Run by Andrew at 21:38:06.50 on Mon 07/12/2010
Internet Explorer: 7.0.6000.17037 BrowserJavaVersion: 1.6.0_15
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2941.2156 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
============== Running Processes ===============
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\Ati2evxx.exe
C:\Program Files\Stardock\MyColors\VistaSrv.exe
C:\Program Files\Stardock\MyColors\WBVista.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\bcmwltry.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\Andrew\Desktop\1\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.comcast.net?cid=NET_mmhpset
uInternet Settings,ProxyServer = http=127.0.0.1:5555
uInternet Settings,ProxyOverride = <local>
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [Desktop Software] "c:\program files\common files\supportsoft\bin\bcont.exe" /ini "c:\program files\comcastui\desktop software\uinstaller.ini" /fromrun /starthidden
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [MSConfig] "c:\windows\system32\msconfig.exe" /auto
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
============= SERVICES / DRIVERS ===============
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2009-8-2 24652]
=============== Created Last 30 ================
2010-07-13 00:33:28 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-13 00:33:27 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-07-12 19:23:26 0 d-----w- c:\users\andrew\appdata\roaming\Malwarebytes
2010-07-12 19:23:16 0 d-----w- c:\programdata\Malwarebytes
2010-07-12 19:23:16 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-07-03 20:27:25 65536 --sha-w- c:\users\andrew\NTUSER.DAT{4ec426ad-86e1-11df-9a0f-001d09365882}.TM.blf
2010-07-03 20:27:25 524288 --sha-w- c:\users\andrew\NTUSER.DAT{4ec426ad-86e1-11df-9a0f-001d09365882}.TMContainer00000000000000000002.regtrans-ms
2010-07-03 20:27:25 524288 --sha-w- c:\users\andrew\NTUSER.DAT{4ec426ad-86e1-11df-9a0f-001d09365882}.TMContainer00000000000000000001.regtrans-ms
==================== Find3M ====================
2010-07-12 23:32:11 51200 ----a-w- c:\windows\inf\infpub.dat
2010-07-12 23:32:10 86016 ----a-w- c:\windows\inf\infstrng.dat
2010-07-12 23:32:10 86016 ----a-w- c:\windows\inf\infstor.dat
2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
2009-07-24 23:39:56 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-07-23 17:16:59 174 --sha-w- c:\program files\desktop.ini
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
2010-03-16 00:42:02 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\cookies\index.dat
2010-03-16 00:42:02 16384 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\history\history.ie5\index.dat
2010-03-16 00:42:02 32768 --sha-w- c:\windows\serviceprofiles\localservice\appdata\local\temp\temporary internet files\content.ie5\index.dat
2007-02-21 19:49:52 8192 --sha-w- c:\windows\users\default\NTUSER.DAT
============= FINISH: 21:38:30.92 ===============
DDS ATTACH LOG
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft® Windows Vista™ Home Premium
Boot Device: \Device\HarddiskVolume3
Install Date: 7/23/2009 11:38:42 AM
System Uptime: 7/12/2010 9:25:43 PM (0 hours ago)
Motherboard: Dell Inc. | | 0D154D
Processor: AMD Turion(tm) 64 X2 Mobile Technology TL-60 | Microprocessor | 2000/100mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 137 GiB total, 91.5 GiB free.
D: is FIXED (NTFS) - 10 GiB total, 5.397 GiB free.
E: is CDROM ()
==== Disabled Device Manager Items =============
==== System Restore Points ===================
==== Installed Programs ======================
Acrobat.com
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Reader 9.2
ATI Catalyst Install Manager
Catalyst Control Center - Branding
Catalyst Control Center Core Implementation
Catalyst Control Center Graphics Full Existing
Catalyst Control Center Graphics Full New
Catalyst Control Center Graphics Light
Catalyst Control Center Graphics Previews Common
Catalyst Control Center Graphics Previews Vista
Catalyst Control Center InstallProxy
ccc-core-static
ccc-utility
CCC Help English
Cisco EAP-FAST Module
Cisco LEAP Module
Cisco PEAP Module
Comcast Desktop Software (v1.2.0.9)
Dell Driver Download Manager
Dell Resource CD
Dell Wireless WLAN Card
Download Updater (AOL LLC)
EverQuest Trilogy
EverQuest: Escape to Norrath
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
IZArc 4.0 beta 1
Java(TM) 6 Update 15
Laptop Integrated Webcam Driver (1.04.01.1011)
Malwarebytes' Anti-Malware
Microsoft .NET Framework 3.5 SP1
Microsoft Silverlight
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
QuickTime
Skins
Stardock MyColors
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Viewpoint Media Player
Xvid 1.2.2 final uninstall
==== End Of File ===========================
Once again thanks for any advice/help given. I truly do appreciate it!
Also I did the GMER exactly as told and both logs look small and identical. I hope I did it right.