![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 9
OS: Vista
|
Threat Found
This is my first run through for this, if I did not follow the instructions correctly, I apologize.
My Virus Scanner (McAfee) found a threat called Artemis!1E0F82E7BDA9 under Files D:\HP\APPS\APP11301 \SRC\INSTALL\GAMES\POLARGOLFERPINE-SETUP.EXE It attempted to remove it, but it could not fully remove it. My other Virus Scanner (Avast) did not find this threat before or after McAfee attempted to remove it. I tried to find the file location, I think I did & I deleted the file & deleted it in my recycle bin with CCleaner. If it is still around (& I think it is) my McAfee currently has whatever is left quarantined. So far, my only problem was that my Internet Explorer closed on me when I was logged in my email. I have misplaced my Vista install disk or a BOOT CD. DDS (Ver_09-09-29.01) - NTFSx86 Run by owner at 18:54:01.44 on Mon 10/05/2009 Internet Explorer: 8.0.6001.18813 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.945 [GMT -7:00] SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k hpdevmgmt c:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe C:\Windows\system32\rundll32.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdController.exe C:\Program Files\RosettaStoneLtdServices\RosettaStoneLtdServer.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\Program Files\Windows Defender\MSASCui.exe C:\hp\support\hpsysdrv.exe C:\hp\KBD\kbd.exe C:\Windows\RtHDVCpl.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\Alwil Software\Avast4\ashDisp.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Hewlett-Packard\HP Advisor\SSDK04.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\UI0Detect.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\owner\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8 uWindow Title = Windows Internet Explorer provided by Yahoo! uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8 mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=71&bd=Pavilion&pf=desktop uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll BHO: HP Print Clips: {053f9267-dc04-4294-a72c-58f732d338c0} - c:\program files\hp\smart web printing\hpswp_framework.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn1\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn1\yt.dll TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [HPAdvisor] c:\program files\hewlett-packard\hp advisor\HPAdvisor.exe uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [NVIDIA nTune] "c:\program files\nvidia corporation\ntune\nTuneCmd.exe" clear uRun: [AROReminder] c:\program files\advanced registry optimizer\ARO.exe -rem uRun: [cdloader] "c:\users\owner\appdata\roaming\mjusbsp\cdloader2.exe" MAGICJACK uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [hpsysdrv] c:\hp\support\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [<NO NAME>] mRun: [OneCareUI] "c:\program files\microsoft windows onecare live\winssnotify.exe" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey mRun: [avast!] c:\progra~1\alwils~1\avast4\ashDisp.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe dRun: [DelayShred] c:\progra~1\mcafee\mshr\shrcl.exe /p7 /q c:\users\owner\appdata\local\temp\tempor~1\content.sh! c:\users\owner\appdata\local\temp\tempor~1.sh! c:\users\owner\appdata\local\temp\history\history.sh! c:\users\owner\appdata\local\temp\history.sh! c:\users\owner\appdata\local\temp\Cookies.SH! StartupFolder: c:\users\owner\appdata\roaming\micros~1\windows\startm~1\programs\startup\imvu.lnk - c:\users\owner\appdata\roaming\imvuclient\IMVUQualityAgent.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: {d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\owner\appdata\roaming\microsoft\windows\start menu\programs\imvu\Run IMVU.lnk IE: {58ECB495-38F0-49cb-A538-10282ABF65E7} - {E763472E-A716-4CD9-89BD-DBDA6122F741} - c:\program files\hp\smart web printing\hpswp_extensions.dll IE: {700259D7-1666-479a-93B1-3250410481E8} - {A93C41D8-01F8-4F8B-B14C-DE20B117E636} - c:\program files\hp\smart web printing\hpswp_extensions.dll DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} - hxxp://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll ============= SERVICES / DRIVERS =============== R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-3-21 114768] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-3-21 20560] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-3-21 51792] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2009-3-21 92296] R3 dc3d;USBCCGP filter driver (dc3d);c:\windows\system32\drivers\dc3d.sys [2009-1-15 15360] =============== Created Last 30 ================ 2009-10-02 19:07 195,440 -------- c:\windows\system32\MpSigStub.exe 2009-10-01 19:05 107,368 a------- c:\windows\system32\GEARAspi.dll 2009-10-01 19:05 26,600 a------- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-10-01 19:05 <DIR> --d----- c:\program files\iPod 2009-10-01 19:05 <DIR> --d----- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-01 19:05 <DIR> --d----- c:\program files\iTunes 2009-10-01 19:05 <DIR> --d----- c:\progra~2\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2009-10-01 17:34 2,421,760 a------- c:\windows\system32\wucltux.dll 2009-10-01 17:34 87,552 a------- c:\windows\system32\wudriver.dll 2009-10-01 17:33 171,608 a------- c:\windows\system32\wuwebv.dll 2009-10-01 17:33 33,792 a------- c:\windows\system32\wuapp.exe 2009-09-08 19:07 904,776 a------- c:\windows\system32\drivers\tcpip.sys 2009-09-08 19:07 105,984 a------- c:\windows\system32\netiohlp.dll 2009-09-08 19:07 27,136 a------- c:\windows\system32\NETSTAT.EXE 2009-09-08 19:07 19,968 a------- c:\windows\system32\ARP.EXE 2009-09-08 19:07 9,728 a------- c:\windows\system32\TCPSVCS.EXE 2009-09-08 19:07 10,240 a------- c:\windows\system32\finger.exe 2009-09-08 19:07 8,704 a------- c:\windows\system32\HOSTNAME.EXE 2009-09-08 19:07 30,720 a------- c:\windows\system32\drivers\tcpipreg.sys 2009-09-08 19:07 17,920 a------- c:\windows\system32\ROUTE.EXE 2009-09-08 19:07 11,264 a------- c:\windows\system32\MRINFO.EXE 2009-09-08 19:07 17,920 a------- c:\windows\system32\netevent.dll 2009-09-08 19:06 2,868,224 a------- c:\windows\system32\mf.dll 2009-09-08 19:06 302,592 a------- c:\windows\system32\wlansec.dll 2009-09-08 19:06 293,376 a------- c:\windows\system32\wlanmsm.dll 2009-09-08 19:06 127,488 a------- c:\windows\system32\L2SecHC.dll 2009-09-08 19:06 2,501,921 a------- c:\windows\system32\wlan.tmf 2009-09-08 19:06 65,024 a------- c:\windows\system32\wlanapi.dll 2009-09-08 19:06 513,536 a------- c:\windows\system32\wlansvc.dll 2009-09-06 10:44 <DIR> --d----- c:\users\owner\appdata\roaming\PeerNetworking ==================== Find3M ==================== 2009-10-05 18:42 24,494 a------- c:\users\owner\appdata\roaming\wklnhst.dat 2009-10-01 19:00 143,360 a------- c:\windows\inf\infstrng.dat 2009-10-01 19:00 86,016 a------- c:\windows\inf\infstor.dat 2009-10-01 19:00 51,200 a------- c:\windows\inf\infpub.dat 2009-08-28 19:30 173,056 a------- c:\windows\apppatch\AcXtrnal.dll 2009-08-28 19:30 458,752 a------- c:\windows\apppatch\AcSpecfc.dll 2009-08-28 19:30 2,159,616 a------- c:\windows\apppatch\AcGenral.dll 2009-08-28 19:30 542,720 a------- c:\windows\apppatch\AcLayers.dll 2009-08-28 17:27 4,240,384 a------- c:\windows\system32\GameUXLegacyGDFs.dll 2009-08-28 17:14 28,672 a------- c:\windows\system32\Apphlpdm.dll 2009-08-04 09:17 1,265,696 a------- c:\windows\system32\RtkPgExt.dll 2009-08-04 09:17 52,256 a------- c:\windows\system32\RtkCoInst.dll 2009-08-04 09:17 2,898,464 a------- c:\windows\system32\RtkAPO.dll 2009-08-04 09:17 326,176 a------- c:\windows\system32\RtkApoApi.dll 2009-07-21 14:52 915,456 a------- c:\windows\system32\wininet.dll 2009-07-21 14:47 109,056 a------- c:\windows\system32\iesysprep.dll 2009-07-21 14:47 71,680 a------- c:\windows\system32\iesetup.dll 2009-07-21 14:01 266,240 a------- c:\windows\system32\FMAPO.dll 2009-07-21 13:13 133,632 a------- c:\windows\system32\ieUnatt.exe 2009-07-17 06:54 71,680 a------- c:\windows\system32\atl.dll 2009-07-15 05:40 8,147,456 a------- c:\windows\system32\wmploc.DLL 2009-07-15 05:39 313,344 a------- c:\windows\system32\wmpdxm.dll 2009-07-15 05:39 4,096 a------- c:\windows\system32\dxmasf.dll 2009-07-15 05:39 7,680 a------- c:\windows\system32\spwmp.dll 2009-05-26 17:05 665,600 a------- c:\windows\inf\drvindex.dat 2008-06-19 15:08 174 a--sh--- c:\program files\desktop.ini 2006-11-02 05:42 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 05:42 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 05:42 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 05:42 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 02:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 02:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 02:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 02:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat 2007-04-04 18:06 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2007-04-04 18:06 32,768 a--sh--- c:\windows\serviceprofiles\localservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2007-04-04 18:06 16,384 a--sh--- c:\windows\serviceprofiles\localservice\appdata\roaming\microsoft\windows\cookies\index.dat 2007-12-21 13:31 16,384 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\history\history.ie5\index.dat 2007-12-21 13:31 32,768 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\local\microsoft\windows\temporary internet files\content.ie5\index.dat 2007-12-21 13:31 16,384 a--sh--- c:\windows\serviceprofiles\networkservice\appdata\roaming\microsoft\windows\cookies\index.dat 2008-07-05 01:14 23 a--sh--- c:\windows\system32\aeebb9_d.dll 2008-07-05 00:55 23 a--sh--- c:\windows\system32\aeebb9_g.dll 2008-07-05 01:33 5 a--sh--- c:\windows\system32\dbdbdfa2_g.dll 2009-05-25 16:34 16,384 a--sh--- c:\windows\system32\%appdata%\microsoft\windows\ietldcache\index.dat ============= FINISH: 18:56:02.56 =============== |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#3 (permalink) |
|
Registered User
Join Date: Oct 2009
Posts: 9
OS: Vista
|
Re: Threat Found
Forgot to include this part of my post:
So the founded threat (That Artemis!1E0F82E7BDA9) seems to not have fully been removed from my computer. What can/should I do to make it go away? I also checked a few virus databases & that specific Artmeis! is not on any databases. So I do not know if this is a real threat or a new threat that no one else has yet to discover...which worries me a lot. |
|
|
|
|
#4 (permalink) | |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,618
OS: 2000 Pro; XP Pro; XP Home
|
Re: Threat Found
Hi -
Some info on McAfee's Artemis technology here http://www.mcafee.com/us/enterprise/...ogy/index.html An Artemis find by McAfee is essentially an in-the-cloud, always on and updating detection. I do think however, that the file you listed in your initial post is a false positive, as it seems part of your HP install, in the recovery partition, which is usually not accessible via normal means. I don't see any sign of active infection. You may want to submit that file to McAfee and see if they agree that it's a false positive. The biggest issue I do see is that there's more than one AntiVirus installed on this machine. As stated in our pre-posting sticky topic... NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help Quote:
I see you have more than one Anti-Virus program installed, Avast! and McAfee. Choose one to keep and uninstall the other. Any antivirus program must be removed via add/remove program. For any program that doesn't have an add/remove entry, you will have to do this: re-install the program -> reboot -> uninstall-----------------------------------------------------------------------
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
|
#5 (permalink) | |
|
Registered User
Join Date: Oct 2009
Posts: 9
OS: Vista
|
Re: Threat Found
Quote:
Thank You for the information about the Artemis & other help, it was a huge weight that was lifted off of my shoulders. |
|
|
|
|
|
#6 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,618
OS: 2000 Pro; XP Pro; XP Home
|
Re: Threat Found
If it isn't a false positive, then yes, it would be a possible threat. However, I think the threat would be minimal based on some research and it's location. It would seem to be some sort of game from WildTangent, which can be classified as adware, but based on it's location in your recovery partition, I'd be inclined to leave it alone.
Have you uninstalled on the the two AntiVirus I saw installed in the initial logs?
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
|
|
#7 (permalink) |
|
Manager, Security Center, TSF Academy; Analyst, Security Team
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,618
OS: 2000 Pro; XP Pro; XP Home
|
Re: Threat Found
Since this issue appears to be resolved, this topic will now be archived. If you need continued support, please begin a new thread, and provide a link to this topic. This applies only to the original topic starter. Everyone else please begin a New Topic, after following the steps outlined here:
NEW INSTRUCTIONS - Read This Before Posting For Malware Removal Help
__________________
Practice Safe Surfing Because what you don't know, CAN hurt you. Microsoft MVP - Consumer Security 2009
|
|
|
| Thread Tools | |
|
|