Quantcast
Channel: Tech Support Forum - Virus/Trojan/Spyware Help
Viewing all articles
Browse latest Browse all 2798

Homepage Changed Without My Doing, Other Issues

$
0
0
Yesterday after some time on the computer - general browsing and whatnot - I noticed my homepage was changed. I never actually use homepages, so seeing Bing set when I opened a new tab seemed strange. Whatever, I know it's a virus, I'll fix this in the morning. Well, today rolls around and after altering my Chrome settings to where the homepage should otherwise be gone, it instead persists as if I didn't do anything. To make matters worse, I think it might be blocking AVG from scanning in Safe Mode; out of Safe Mode it works, but in SM, "Scan" doesn't do anything.

Suspects
This was never an issue until after I downloaded Virtual Router Plus, so I'm willing to bet that's the primary suspect. Prior to then, the last downloads I did were from Nexus mods (which scans just about any file uploaded iirc).

Other info
Access to install disc?
- Yes, though I couldn't say where the case went (disc is in the tray).

Windows version?
- Windows 7 Professional (Service pack 1)

In the .zip file I've attached, you'll find two separate Ark files. I scanned my C: and D: drives separately so as to make analyzing the two easier.

===================================

DDS (Ver_2012-11-20.01) - NTFS_AMD64 NETWORK
Internet Explorer: 11.0.9600.17496
Run by JKrie at 14:28:29 on 2015-01-10
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.8084.6890 [GMT -8:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Windows\system32\ctfmon.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.trovi.com/?gd=&ctid=CT3322294&octid=EB_ORIGINAL_CTID&ISID=M84C34AD1-1591-40BC-814E-87D8E54CB96A&SearchSource=55&CUI=&UM=8&UP=SP8B125856-4C15-4A6B-8CE1-BF531680CCE0&SSPV=
mWinlogon: Userinit = userinit.exe
uRun: [ClamWin] "C:\Program Files (x86)\ClamWin\bin\ClamTray.exe" --logon
uRun: [GoogleChromeAutoLaunch_CE2937F89DFC808FE1C3584770E38EE0] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [Clam Sentinel] C:\Program Files (x86)\ClamSentinel\ClamSentinel.exe
mRun: [iTunesHelper] "D:\Programs\iTunes\iTunesHelper.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2015\avgui.exe" /TRAYONLY
dRunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{B703228E-E45C-4B52-ABFE-CCE6B60A2E73} : DHCPNameServer = 75.75.75.75 75.75.76.76
AppInit_DLLs= C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\39.0.2171.95\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2014-11-18 203544]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2014-7-18 313624]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2014-10-5 124184]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2014-6-18 31512]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2014-10-10 274200]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2013-2-25 2426672]
S1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2014-6-18 153368]
S1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2014-12-8 260888]
S1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2014-8-28 243480]
S2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [2014-12-18 3432976]
S2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [2014-12-18 298080]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 CltMngSvc;Search Protect Service;C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe [2015-1-5 3342608]
S2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service;C:\Windows\System32\igfxCUIService.exe [2014-10-1 319376]
S2 SkypeUpdate;Skype Updater;"C:\Program Files (x86)\Skype\Updater\Updater.exe" --> C:\Program Files (x86)\Skype\Updater\Updater.exe [?]
S3 CMUSBDAC;USB Audio Class 1.0 and 2.0 DAC Device Driver;C:\Windows\System32\drivers\CMUSBDAC.sys [2014-9-19 594944]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-12-28 114688]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-12-30 19456]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-12-30 57856]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2014-12-28 1255736]
.
=============== Created Last 30 ================
.
2015-01-10 22:06:09 -------- d-----w- C:\Users\JKrie\AppData\Roaming\AVG2015
2015-01-10 22:06:01 -------- d-----w- C:\Users\JKrie\AppData\Roaming\TuneUp Software
2015-01-10 22:05:58 -------- d--h--w- C:\$AVG
2015-01-10 22:05:58 -------- d-----w- C:\ProgramData\AVG2015
2015-01-10 22:05:54 -------- d-----w- C:\Program Files (x86)\AVG
2015-01-10 21:53:14 -------- d-----w- C:\Users\JKrie\AppData\Local\ElevatedDiagnostics
2015-01-10 21:50:34 -------- d-----w- C:\Windows\pss
2015-01-10 03:05:24 -------- d-----w- C:\Users\JKrie\AppData\Local\VirtualRouterPlus
2015-01-10 03:03:51 -------- d-----w- C:\Users\JKrie\AppData\Local\SearchProtect
2015-01-10 03:03:50 -------- d-----w- C:\Program Files (x86)\SearchProtect
2015-01-10 03:03:33 -------- d-----w- C:\Users\JKrie\AppData\Local\Downloaded Installations
2015-01-10 01:42:56 11870360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{56A0711B-2357-48BE-8C5E-7AF8C4903DA9}\mpengine.dll
2015-01-04 13:05:01 -------- d-----w- C:\Program Files (x86)\Bethesda Softworks
2014-12-31 00:34:05 44032 ----a-w- C:\Windows\System32\tsgqec.dll
2014-12-31 00:34:05 37376 ----a-w- C:\Windows\SysWow64\tsgqec.dll
2014-12-31 00:34:05 322560 ----a-w- C:\Windows\System32\aaclient.dll
2014-12-31 00:34:05 3179520 ----a-w- C:\Windows\System32\rdpcorets.dll
2014-12-31 00:34:05 16384 ----a-w- C:\Windows\System32\RdpGroupPolicyExtension.dll
2014-12-31 00:34:05 1125888 ----a-w- C:\Windows\System32\mstsc.exe
2014-12-31 00:34:05 1050112 ----a-w- C:\Windows\SysWow64\mstsc.exe
2014-12-31 00:34:04 5780480 ----a-w- C:\Windows\System32\mstscax.dll
2014-12-31 00:34:04 4922368 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-12-31 00:34:04 269312 ----a-w- C:\Windows\SysWow64\aaclient.dll
2014-12-30 13:27:06 -------- d-----w- C:\Users\JKrie\AppData\Local\Skyrim
2014-12-30 13:26:58 5631312 ----a-w- C:\Windows\System32\D3DX9_40.dll
2014-12-30 13:26:58 519000 ----a-w- C:\Windows\System32\d3dx10_40.dll
2014-12-30 13:26:58 452440 ----a-w- C:\Windows\SysWow64\d3dx10_40.dll
2014-12-30 13:26:58 4379984 ----a-w- C:\Windows\SysWow64\D3DX9_40.dll
2014-12-30 13:26:58 2605920 ----a-w- C:\Windows\System32\D3DCompiler_40.dll
2014-12-30 13:26:58 2036576 ----a-w- C:\Windows\SysWow64\D3DCompiler_40.dll
2014-12-30 10:57:41 -------- d-----w- C:\Users\JKrie\AppData\Local\Black_Tree_Gaming
2014-12-30 09:49:15 144 ----a-w- C:\Windows\System32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-12-30 09:44:50 -------- d-----w- C:\Program Files\Microsoft Mouse and Keyboard Center
2014-12-30 09:43:38 -------- d-----w- C:\Windows\System32\MRT
2014-12-30 09:34:44 -------- d-sh--w- C:\Users\JKrie\IntelGraphicsProfiles
2014-12-30 09:34:43 451 ----a-w- C:\Windows\System32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-12-30 09:31:53 64000 ----a-w- C:\Windows\System32\OpenCL.DLL
2014-12-30 09:31:53 60416 ----a-w- C:\Windows\SysWow64\OpenCL.DLL
2014-12-30 09:31:53 -------- d-----w- C:\Intel
2014-12-30 09:31:50 -------- d-----w- C:\Program Files (x86)\Common Files\Intel
2014-12-30 09:11:06 -------- d-----w- C:\Users\JKrie\AppData\Local\Fallout3
2014-12-30 09:10:52 -------- d-----w- C:\Windows\SysWow64\xlive
2014-12-30 09:10:52 -------- d-----w- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2014-12-30 01:23:50 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-12-30 01:23:50 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-12-29 11:00:21 2777088 ----a-w- C:\Windows\System32\msmpeg2vdec.dll
2014-12-29 11:00:21 2285056 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2014-12-29 05:01:15 465920 ----a-w- C:\Windows\System32\WMPhoto.dll
2014-12-29 05:00:19 67072 ----a-w- C:\Windows\splwow64.exe
2014-12-29 05:00:19 559104 ----a-w- C:\Windows\System32\spoolsv.exe
2014-12-29 04:58:28 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-12-29 04:58:27 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-12-28 16:02:40 -------- d-----w- C:\Windows\System32\appraiser
2014-12-28 16:02:38 -------- d-----w- C:\Windows\SysWow64\Wat
2014-12-28 16:02:38 -------- d-----w- C:\Windows\System32\Wat
2014-12-28 11:58:15 167424 ----a-w- C:\Program Files\Windows Media Player\wmplayer.exe
2014-12-28 11:58:15 164864 ----a-w- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
2014-12-28 11:58:14 12625920 ----a-w- C:\Windows\System32\wmploc.DLL
2014-12-28 11:58:14 12625408 ----a-w- C:\Windows\SysWow64\wmploc.DLL
2014-12-28 11:50:18 -------- d-----w- C:\Windows\Migration
2014-12-28 11:38:29 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-28 11:21:05 2560 ----a-w- C:\Windows\System32\drivers\en-US\wdf01000.sys.mui
2014-12-28 11:07:45 55808 ----a-w- C:\Windows\System32\rrinstaller.exe
2014-12-28 11:07:45 50176 ----a-w- C:\Windows\SysWow64\rrinstaller.exe
2014-12-28 11:07:45 4121600 ----a-w- C:\Windows\System32\mf.dll
2014-12-28 11:07:45 3209728 ----a-w- C:\Windows\SysWow64\mf.dll
2014-12-28 11:07:45 24576 ----a-w- C:\Windows\System32\mfpmp.exe
2014-12-28 11:07:45 23040 ----a-w- C:\Windows\SysWow64\mfpmp.exe
2014-12-28 11:07:45 206848 ----a-w- C:\Windows\System32\mfps.dll
2014-12-28 11:07:45 2048 ----a-w- C:\Windows\SysWow64\mferror.dll
2014-12-28 11:07:45 2048 ----a-w- C:\Windows\System32\mferror.dll
2014-12-28 11:07:45 103424 ----a-w- C:\Windows\SysWow64\mfps.dll
2014-12-28 11:06:47 87040 ----a-w- C:\Windows\System32\drivers\WUDFPf.sys
2014-12-28 11:06:47 84992 ----a-w- C:\Windows\System32\WUDFSvc.dll
2014-12-28 11:06:47 744448 ----a-w- C:\Windows\System32\WUDFx.dll
2014-12-28 11:06:47 45056 ----a-w- C:\Windows\System32\WUDFCoinstaller.dll
2014-12-28 11:06:47 229888 ----a-w- C:\Windows\System32\WUDFHost.exe
2014-12-28 11:06:47 198656 ----a-w- C:\Windows\System32\drivers\WUDFRd.sys
2014-12-28 11:06:47 194048 ----a-w- C:\Windows\System32\WUDFPlatform.dll
2014-12-28 11:02:30 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
2014-12-28 11:02:30 5120 ----a-w- C:\Windows\System32\wmi.dll
2014-12-28 11:02:30 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2014-12-28 11:00:34 99480 ----a-w- C:\Windows\SysWow64\infocardapi.dll
2014-12-28 11:00:34 8856 ----a-w- C:\Windows\SysWow64\icardres.dll
2014-12-28 11:00:34 8856 ----a-w- C:\Windows\System32\icardres.dll
2014-12-28 11:00:34 619672 ----a-w- C:\Windows\SysWow64\icardagt.exe
2014-12-28 11:00:34 171160 ----a-w- C:\Windows\System32\infocardapi.dll
2014-12-28 11:00:34 1389208 ----a-w- C:\Windows\System32\icardagt.exe
2014-12-28 11:00:31 35480 ----a-w- C:\Windows\SysWow64\TsWpfWrp.exe
2014-12-28 11:00:31 35480 ----a-w- C:\Windows\System32\TsWpfWrp.exe
2014-12-28 01:26:09 -------- d-----w- C:\Program Files (x86)\Common Files\Steam
2014-12-28 01:13:55 224256 ----a-w- C:\Windows\System32\wintrust.dll
2014-12-28 01:12:58 515584 ----a-w- C:\Windows\System32\timedate.cpl
2014-12-28 01:11:57 81920 ----a-w- C:\Windows\SysWow64\davclnt.dll
2014-12-28 01:10:57 680960 ----a-w- C:\Windows\System32\audiosrv.dll
2014-12-28 01:09:59 1499136 ----a-w- C:\Program Files\Common Files\System\ado\msado15.dll
2014-12-28 01:04:34 -------- d-----w- C:\Users\JKrie\AppData\Local\Skype
2014-12-28 01:00:24 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll
2014-12-28 01:00:24 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys
2014-12-28 01:00:24 1031680 ----a-w- C:\Windows\System32\rdpcore.dll
2014-12-27 22:53:31 -------- d-----w- C:\Users\JKrie\Powersaves3DS
2014-12-27 22:53:30 -------- d-----w- C:\Program Files (x86)\Action Replay PowerSaves 3DS
2014-12-27 22:53:25 -------- d-----w- C:\Users\JKrie\AppData\Local\Programs
2014-12-27 03:22:33 -------- d-----w- C:\Windows\System32\SPReview
2014-12-19 11:00:00 -------- d-----w- C:\Windows\System32\EventProviders
2014-12-19 08:15:11 48976 ----a-w- C:\Windows\System32\netfxperf.dll
2014-12-19 08:13:57 529408 ----a-w- C:\Windows\System32\wbemcomn.dll
.
==================== Find3M ====================
.
2015-01-06 12:36:02 298120 ------w- C:\Windows\System32\MpSigStub.exe
2015-01-05 08:40:28 245008 ----a-w- C:\Windows\apppatch\AppPatch64\VCLdr64.dll
2015-01-05 08:40:26 215312 ----a-w- C:\Windows\apppatch\nbin\VC32Loader.dll
2014-12-28 11:38:29 9728 ---ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-27 03:23:27 175616 ----a-w- C:\Windows\System32\msclmd.dll
2014-12-27 03:23:27 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2014-12-09 05:24:26 260888 ----a-w- C:\Windows\System32\drivers\avgidsdrivera.sys
2014-12-04 02:50:55 413184 ----a-w- C:\Windows\System32\generaltel.dll
2014-12-04 02:50:45 741376 ----a-w- C:\Windows\System32\invagent.dll
2014-12-04 02:50:40 396800 ----a-w- C:\Windows\System32\devinv.dll
2014-12-04 02:50:38 830976 ----a-w- C:\Windows\System32\appraiser.dll
2014-12-04 02:50:37 227328 ----a-w- C:\Windows\System32\aepdu.dll
2014-12-04 02:50:37 192000 ----a-w- C:\Windows\System32\aepic.dll
2014-12-04 02:44:48 1083392 ----a-w- C:\Windows\System32\aeinv.dll
2014-12-01 23:28:44 1232040 ----a-w- C:\Windows\System32\aitstatic.exe
2014-11-22 02:26:31 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-11-19 05:42:04 203544 ----a-w- C:\Windows\System32\drivers\avgidsha.sys
2014-11-11 03:08:52 241152 ----a-w- C:\Windows\System32\pku2u.dll
2014-11-11 03:08:48 728064 ----a-w- C:\Windows\System32\kerberos.dll
2014-11-11 02:44:32 186880 ----a-w- C:\Windows\SysWow64\pku2u.dll
2014-11-11 02:44:25 550912 ----a-w- C:\Windows\SysWow64\kerberos.dll
2014-11-11 01:46:26 119296 ----a-w- C:\Windows\System32\drivers\tdx.sys
2014-11-08 03:16:08 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-11-08 02:45:09 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-10-30 02:03:43 165888 ----a-w- C:\Windows\System32\charmap.exe
2014-10-30 01:45:43 155136 ----a-w- C:\Windows\SysWow64\charmap.exe
2014-10-25 01:57:59 77824 ----a-w- C:\Windows\System32\packager.dll
2014-10-25 01:32:37 67584 ----a-w- C:\Windows\SysWow64\packager.dll
2014-10-18 02:05:23 861696 ----a-w- C:\Windows\System32\oleaut32.dll
2014-10-18 01:33:18 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2014-10-14 02:16:37 155064 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2014-10-14 02:13:06 683520 ----a-w- C:\Windows\System32\termsrv.dll
2014-10-14 02:13:00 3241984 ----a-w- C:\Windows\System32\msi.dll
2014-10-14 02:12:57 1460736 ----a-w- C:\Windows\System32\lsasrv.dll
2014-10-14 02:09:31 146432 ----a-w- C:\Windows\System32\msaudite.dll
2014-10-14 02:07:31 681984 ----a-w- C:\Windows\System32\adtschema.dll
2014-10-14 01:50:47 22016 ----a-w- C:\Windows\SysWow64\secur32.dll
2014-10-14 01:50:41 2363904 ----a-w- C:\Windows\SysWow64\msi.dll
2014-10-14 01:49:38 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2014-10-14 01:47:30 146432 ----a-w- C:\Windows\SysWow64\msaudite.dll
2014-10-14 01:46:02 681984 ----a-w- C:\Windows\SysWow64\adtschema.dll
.
============= FINISH: 14:28:35.92 ===============

Attached Files
File Type: zip Attach.zip.zip (3.5 KB)

Viewing all articles
Browse latest Browse all 2798

Trending Articles