Your computer is quite badly infected. Yet another example of how useless Norton is.
Download Malwarebytes' Anti-Malware to your desktop.
* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure to checkmark the Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.
Make sure that you restart the computer.
Once done, post a fresh HJT log too.
Rik from RCE
Nearly a Posting Maven
2,335 posts since May 2009
Reputation Points: 127
Solved Threads: 199
Turn on "show hidden files and folders". INSTRUCTIONS
Locate and delete the following. Only delete the things that are in bold.
C:\Program Files\GetModule\GetModule27.exe
c:\program files\common files\is3\anti-spyware\is3lsp.dll
once done, open HJT and place a tick next to each entry (if there).
O4 - HKUS\S-1-5-20\..\Run: [GetModule27] C:\Program Files\GetModule\GetModule27.exe (User 'NETWORK SERVICE')
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll (there are 4 of these, tick them all)
Then close all browsers and click the "fix checked" button.
Now reboot your PC and post a fresh HJT log.
Rik from RCE
Nearly a Posting Maven
2,335 posts since May 2009
Reputation Points: 127
Solved Threads: 199
C:\QooBox\Quarantine\C\Program Files\GetModule is a directory created by combofix. It is a quarantined directory. When did you run combofix? And can you post it's log?
See if you can uninstall GetModule in add / remove programs.
Rik from RCE
Nearly a Posting Maven
2,335 posts since May 2009
Reputation Points: 127
Solved Threads: 199
Ok, it may be worth running combofix on the machine as combofix is often updated. You can get it HERE . Post it's resulting log.
Rik from RCE
Nearly a Posting Maven
2,335 posts since May 2009
Reputation Points: 127
Solved Threads: 199
It's looking like the machine may need to be formatted and reinstalled from scratch. The malware is obviously fighting back.
Rik from RCE
Nearly a Posting Maven
2,335 posts since May 2009
Reputation Points: 127
Solved Threads: 199
If I may Rik, the poster IS correct, these Winsock entries are related to Stopzilla.
Their "home company name is iS3
I think the poster should Uninstall Stopzilla.
This is a program with a "so-so" reputation. This other files you are looking for;
C:\Program Files\GetModule\GetModule27.exe
Does not show as running, at least during the latest HJT scan. The key files with this were removed by MBA-M.
Uninstall all that Stopzilla stuff, it's running all the time and is basically worthless, plus may be causing these difficulties.
If poster must, he can boot to Safe Mode and do all this removal along with those old combofix files he found.
Are all those pop-up warnings from Stopzilla? If so they very well could be false positives. Also Stopzilla may be causing the problem with combofix.
Uninstall it and be advised, it can be VERY Difficult to uninstall.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340
Boot to Safe Mode to do all this. This should bypass the Stopzilla stuff. Then do the uninstalls from there. IF there really is a missing .dll file it likely was removed by MBA-M since this didn't happen until that program was run.
Boot to Safe Mode by shutting down, reboot and immediately begin tapping the F8 key. You should get a "choice screen" choose Safe Mode. Your desk top will look much different because video files are not loaded. Once the computer is fully booted into Safe Mode then begin by going to Add/Remove and uninstall everything Stopzilla. Then do a file search for Stopzilla by going to Start, Search, Files and Folders and be sure to also use the advanced options of searching in system files, hidden files and sub folders.
While you are there also do a search for GetModule and see if anything turns up, if it does, delete it. You might also look for Combofix and see if any files are found if you find them, delete them.
Once you have removed all that stuff then reboot to normal mode and see what happens. Obviously this stems from way back when the first infection was removed by somebody else, but the job wasn't completed, thus making it hard for you now.
jholland1964
Posting Expert
5,785 posts since Jul 2008
Reputation Points: 725
Solved Threads: 340