This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] IE explorer and Mozilla hijack

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,
Similar to other people posting on this forum whenever I access the internet and use Google as my search engine, my search results become hijacked by ABCjump, r.php, findwhat.dll etc. I have tried several free mmalware removel programs, registry cleaners (easy cleaner) etc to no avail. I have included my Hijack this scan results and wanted to see if someone could help? Any help would be


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:09:37 AM, on 10/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\FSGK32.EXE
C:\Program Files\Optus Internet Security Suite\Common\FSMB32.EXE
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Optus Internet Security Suite\Common\FCH32.EXE
C:\Program Files\Optus Internet Security Suite\Common\FAMEH32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsqh.exe
C:\Program Files\Optus Internet Security Suite\FSPC\fspc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsaua.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fssm32.exe
C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsus.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Program Files\Optus Internet Security Suite\FSGUI\fsguidll.exe
C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Ibis\Desktop\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Optus Internet Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe
O9 - Extra button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {447F8438-8124-4369-905B-A249E13CBBFC} (LgbContent Control) - http://pickles.liveglobalbid.com/install/new/lgbkc.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 7152 bytes
Hi Ibis,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Then

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot (shut down your computer then restart it).
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hi Tomk, Your help is much appreciated. I am sorry about the delay in replying but I was away for work (here in Australia) for a few days. I tried downloading ATF cleaner with both Mozilla and IE with no success. I wonder if the trojan horse or whatever problem is aflicting this computer is blocking my attempts. I will have to download ATF cleaner at work on Monday. A few week ago I downloaded Malwarebytes Antimalware and it could find no problem but that is before running ATF Cleaner. I tried running easycleaner tonight to remove temporarary IE files but received a message that it could not remove all files. So, I will download ATF Cleaner at work on Monday Australian time, load it onto this machine, run it, and get back to you. That ABCjump is bad! Thanks and cheers Ibis
Ibis,

If you are able, let's try to skip ahead a little.

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link –> http://forums.whatthetech.com/How_Disable_…ams_t96260.html

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi Tomk, I ran Combofix as per your instructions but got the blue screen of death and had to restart. Have pasted the combofix.txt and bug.txt files below. I wont re-run combofix as per your instructions unless you give me the all clear. Cheers Ivars Combofix.txt output below ComboFix 09-03-15.01 - Ibis 2009-03-16 21:42:48.1 - NTFSx86 Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe AV: Optus Internet Security Suite 2008 7.00 *On-access scanning disabled* (Updated) FW: Optus Internet Security Suite 2008 7.00 *disabled* WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . Bug.txt output below Killing 'n.com' PUSHD "C:\32788R22FWJFW" 1 file(s) copied. IF NOT EXIST C:\WINDOWS\system32\cmd.exe GOTO Not_NT VER 1>OsVer GREP.cfexe -F "5.2." OsVer IF 1 == 0 GOTO Not_NT GREP.cfexe -F "5.1.2" OsVer Microsoft Windows XP [Version 5.1.2600] IF 0 == 0 GOTO NT IF NOT DEFINED RKEY_ GOTO :EOF CLS CHCP 1252 Active code page: 1252 START n.com infobox "Incompatible OS. ComboFix only works for workstations with Windows 2000 and XP~n~nOS incompatible. ComboFix ne fonctionne que pour Windows 2000 et XP~n~nOS niet compatibel. ComboFix kan enkel gebruikt worden voor Windows 2000 en XP~n~nInkompatibles Betriebssystem. ComboFix läuft nur unter Windows 2000 und XP~n~nKäyttöjärjestelmä ei ole yhteensopiva. ComboFix toimii vain Windows 2000- ja XP-käyttöjärjestelmissä.~n~nSistema Operativo Incompatvel. ComboFix apenas funciona em Windows 2000 e XP~n~nSO. Incompatible. ComboFix funciona śnicamente en Windows 2000 y XP~n~nOS Incompatibile. Combofix funziona solo su windows 2000 e XP" "Error - Win32 only" EXIT
Ibis,

Let's run a different tool first.

Download Rooter.exe to your desktop

  • Then doubleclick it to start the tool
  • A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
Hi Tomk, Here is the file from Rooter.exe. I ran it twice as the first time (pasted below) I forgot to shut off my anti virus software. The second run with antivirus turned off is also pasted below. Thanks in advance for your help - much appreciated. Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3 C:\ [Fixed] - NTFS - (Total:38115 Mo/Free:3879 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) 2009-03-19|22:23 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\System32\Ati2evxx.exe ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe ———- C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE ———- C:\Program Files\Optus Internet Security Suite\Common\FSMB32.EXE ———- C:\Program Files\Spyware Doctor\pctsAuxs.exe ———- C:\Program Files\Spyware Doctor\pctsSvc.exe ———- C:\Program Files\Optus Internet Security Suite\Common\FCH32.EXE ———- C:\Program Files\Optus Internet Security Suite\Common\FAMEH32.EXE ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsqh.exe ———- C:\Program Files\Optus Internet Security Suite\FSPC\fspc.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsaua.exe ———- C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsus.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ———- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ———- C:\Program Files\QuickTime\qttask.exe ———- C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE ———- C:\Program Files\Spyware Doctor\pctsTray.exe ———- C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe ———- C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe ———- C:\Program Files\Optus Internet Security Suite\FSGUI\fsguidll.exe ———- C:\Program Files\Mozilla Firefox\firefox.exe ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsav32.exe ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\FSGK32.EXE ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\fssm32.exe ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - 2009-03-19|22:28 ———————-\\ Scan completed at 22:28 Here is the Rooter.exe scan after disabling my anti-virus software C:\ [Fixed] - NTFS - (Total:38115 Mo/Free:3859 Mo) D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo) 2009-03-19|22:37 ———————-\\ Processes.. –Locked– [System Process] ———- System ———- \SystemRoot\System32\smss.exe ———- \??\C:\WINDOWS\system32\csrss.exe ———- \??\C:\WINDOWS\system32\winlogon.exe ———- C:\WINDOWS\system32\services.exe ———- C:\WINDOWS\system32\lsass.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\system32\svchost.exe ———- C:\WINDOWS\system32\spoolsv.exe ———- C:\WINDOWS\System32\Ati2evxx.exe ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe ———- C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE ———- C:\Program Files\Optus Internet Security Suite\FSPC\fspc.exe ———- C:\WINDOWS\System32\svchost.exe ———- C:\WINDOWS\System32\alg.exe ———- C:\WINDOWS\Explorer.EXE ———- C:\WINDOWS\system32\ctfmon.exe ———- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe ———- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe ———- C:\Program Files\QuickTime\qttask.exe ———- C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe ———- C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe ———- C:\Program Files\Mozilla Firefox\firefox.exe ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\FSGK32.EXE ———- C:\Program Files\Optus Internet Security Suite\Anti-Virus\fssm32.exe ———- C:\Program Files\Optus Internet Security Suite\Common\FSLAUNCH.EXE ———- C:\WINDOWS\system32\cmd.exe ———- C:\Rooter$\RK.exe ———————-\\ Search.. ———————-\\ ROOTKIT !! 1 - "C:\Rooter$\Rooter_1.txt" - 2009-03-19|22:28 2 - "C:\Rooter$\Rooter_2.txt" - 2009-03-19|22:37 ———————-\\ Scan completed at 22:37
Ibis, Now please just drag your copy of ComboFix to your recycle bin. Then re-download per previous instructions and try to run again.
Hi Tomk,
Ran combofix as per instructions. Log below.

ComboFix 09-03-19.01 - Ibis 2009-03-20 22:03:02.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1257.371.1033.18.510.244 [GMT 11:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix2.exe
AV: Optus Internet Security Suite 2008 7.00 *On-access scanning disabled* (Updated)
FW: Optus Internet Security Suite 2008 7.00 *disabled*
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
—- Previous Run ——-
.
c:\windows\qkjfqqk.wix
c:\windows\system32\ntnet.drv
c:\windows\system32\setup.exe.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_WKSPATCH
——-\Legacy_WKSPATCH


((((((((((((((((((((((((( Files Created from 2009-02-20 to 2009-03-20 )))))))))))))))))))))))))))))))
.

2009-03-19 22:23 . 2009-03-19 22:37 d——– C:\Rooter$
2009-03-16 21:40 . 2009-03-20 22:00 d——– C:\ComboFix
2009-03-07 10:14 . 2009-03-07 10:14 0 –a—— c:\windows\nsreg.dat

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 11:36 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-19 11:31 ——— d—–w c:\program files\Spyware Doctor
2009-03-19 11:03 ——— d—–w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-05 10:08 ——— d—–w c:\program files\Optus Internet Security Suite
2009-02-17 10:32 ——— d—–w c:\documents and settings\Ibis\Application Data\U3
2009-02-11 09:40 ——— d—–w c:\documents and settings\Ibis\Application Data\Malwarebytes
2009-02-11 09:39 ——— d—–w c:\program files\Malwarebytes' Anti-Malware
2009-02-11 09:36 ——— d—–w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-09 11:13 1,846,784 —-a-w c:\windows\SYSTEM32\win32k.sys
2009-02-09 11:13 1,846,784 ——w c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2009-02-09 07:36 1,625 —-a-w c:\windows\OEM0.tmp
2009-02-09 07:35 4,901 —-a-w c:\windows\MultiLanguage.tmp
2009-01-28 01:38 ——— d—–w c:\program files\Common Files\Symantec Shared
2009-01-28 01:21 ——— d—–w c:\program files\Norton Security Scan
2009-01-26 22:46 ——— d—–w c:\program files\TSN Internet
2009-01-26 22:32 ——— d–h–w c:\program files\InstallShield Installation Information
2009-01-26 22:32 ——— d—–w c:\program files\ToniArts
2009-01-26 22:08 ——— d—–w c:\program files\RegistryCleanerPro
2009-01-21 09:32 ——— d—–w c:\documents and settings\Ibis\Application Data\MSN6
2009-01-20 11:31 ——— d—–w c:\program files\Google
2009-01-20 11:08 81,288 —-a-w c:\windows\system32\drivers\iksyssec.sys
2009-01-20 11:08 66,952 —-a-w c:\windows\system32\drivers\iksysflt.sys
2009-01-20 11:08 40,840 —-a-w c:\windows\system32\drivers\ikfilesec.sys
2009-01-20 10:34 ——— d—–w c:\documents and settings\Ibis\Application Data\PC Tools
2009-01-16 10:35 3,594,752 —-a-w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2005-09-15 04:26 581,930 —-a-w c:\program files\avanti-cat-fitness.pdf
2005-08-19 12:46 10,958,640 —-a-w c:\program files\GoogleEarth.exe
2008-10-23 16:19 32,768 –sha-w c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\MSHist012008102420081025\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"OM2_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-05-28 95800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-17 110592]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-17 569344]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 282624]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"F-Secure Manager"="c:\program files\Optus Internet Security Suite\Common\FSM32.EXE" [2007-04-27 183208]
"F-Secure TNB"="c:\program files\Optus Internet Security Suite\FSGUI\TNBUtil.exe" [2007-04-27 740208]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Wireless Configuration Utility.lnk - c:\program files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe [2003-08-08 425984]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"= c:\windows\system32\..\qkjfqqk.wix

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Ibis^Start Menu^Programs^Startup^Microsoft Find Fast.lnk]
path=c:\documents and settings\Ibis\Start Menu\Programs\Startup\Microsoft Find Fast.lnk
backup=c:\windows\pss\Microsoft Find Fast.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Ibis^Start Menu^Programs^Startup^Office Startup.lnk]
path=c:\documents and settings\Ibis\Start Menu\Programs\Startup\Office Startup.lnk
backup=c:\windows\pss\Office Startup.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdaptecDirectCD]
–a—— 2002-12-17 15:28 684032 c:\program files\Roxio\Easy CD Creator 5\DirectCD\Directcd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
–a—— 2008-04-14 11:12 15360 c:\windows\SYSTEM32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDSentry]
–a—— 2002-07-17 13:18 28672 c:\windows\SYSTEM32\DSentry.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2006-09-01 16:57 282624 c:\program files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange]
–a—— 2002-08-28 20:17 28672 c:\windows\SYSTEM32\Ati2mdxx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CARPService]
–a—— 2003-01-23 18:06 4608 c:\windows\SYSTEM32\carpserv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

R0 FSFW;F-Secure Firewall Driver;c:\windows\SYSTEM32\DRIVERS\fsdfw.sys [2008-09-11 51072]
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Optus Internet Security Suite\HIPS\fshs.sys [2008-09-11 41184]
R2 BCMNTIO;BCMNTIO;c:\progra~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2006-12-12 3744]
R2 MAPMEM;MAPMEM;c:\progra~1\CheckIt\DIAGNO~1\MAPMEM.sys [2006-12-12 3904]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Optus Internet Security Suite\Anti-Virus\minifilter\fsgk.sys [2008-09-11 77824]
R3 rtl8180;IEEE 802.11b Wireless Cardbus/PCI Adapter;c:\windows\SYSTEM32\DRIVERS\rtl8180.sys [2003-06-16 158848]
R3 SjyPkt;SjyPkt;c:\windows\SYSTEM32\DRIVERS\SjyPkt.sys [2002-10-02 13532]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-31 31592]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2009-01-20 356920]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Optus Internet Security Suite\Anti-Virus\win2k\fsfilter.sys [2008-09-11 40048]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Optus Internet Security Suite\Anti-Virus\win2k\fsrec.sys [2008-09-11 25456]
.
Contents of the 'Scheduled Tasks' folder

2009-03-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-20 21:25]

2009-01-20 c:\windows\Tasks\Norton Security Scan for Ibis.job
- c:\program files\Norton Security Scan\Nss.exe [2008-12-11 17:49]

2009-03-20 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\OPTUSI~1\ANTI-V~1\fsav.exe [2007-04-26 22:42]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com.au/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {447F8438-8124-4369-905B-A249E13CBBFC} - hxxp://pickles.liveglobalbid.com/install/new/lgbkc.cab
FF - ProfilePath - c:\documents and settings\Ibis\Application Data\Mozilla\Firefox\Profiles\oexj0qe3.default\
FF - plugin: c:\program files\Google\Google Updater\2.4.1441.4352\npCIDetect13.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-20 22:10:54
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(824)
c:\program files\Optus Internet Security Suite\FWES\Program\fsdc.dll

- - - - - - - > 'lsass.exe'(888)
c:\program files\Optus Internet Security Suite\FWES\Program\fsdc.dll

- - - - - - - > 'explorer.exe'(3212)
c:\program files\Optus Internet Security Suite\Spam Control\fsscoepl.dll

- - - - - - - > 'csrss.exe'(800)
c:\program files\Optus Internet Security Suite\FWES\Program\fsdc.dll
.
———————— Other Running Processes ————————
.
c:\windows\SYSTEM32\ati2evxx.exe
c:\program files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
c:\program files\Optus Internet Security Suite\Common\FSMA32.EXE
c:\program files\Optus Internet Security Suite\Anti-Virus\fsgk32.exe
c:\program files\Optus Internet Security Suite\Common\FSMB32.EXE
c:\program files\Optus Internet Security Suite\Common\FCH32.EXE
c:\program files\Optus Internet Security Suite\Anti-Virus\fssm32.exe
c:\program files\Optus Internet Security Suite\Common\FAMEH32.EXE
c:\program files\Optus Internet Security Suite\Anti-Virus\fsqh.exe
c:\program files\Optus Internet Security Suite\FSAUA\program\fsaua.exe
c:\program files\Optus Internet Security Suite\FWES\program\fsdfwd.exe
c:\program files\Optus Internet Security Suite\FSPC\fspc.exe
c:\program files\Optus Internet Security Suite\FSAUA\program\fsus.exe
c:\progra~1\OPTUSI~1\Common\FSM32.EXE
c:\progra~1\OPTUSI~1\FSGUI\fsguidll.exe
c:\program files\Optus Internet Security Suite\Anti-Virus\fsav32.exe
.
**************************************************************************
.
Completion time: 2009-03-20 22:21:33 - machine was rebooted [Ibis]
ComboFix-quarantined-files.txt 2009-03-20 11:20:40

Pre-Run: 12,580,491,264 bytes free
Post-Run: 12,599,349,248 bytes free

202 — E O F — 2009-03-13 11:12:35
Hi Tomk, Malwarebytes log below, a new hijack this log below that. Computer seems a little faster. Malwarebytes' Anti-Malware 1.33 Database version: 1747 Windows 5.1.2600 Service Pack 3 21/03/2009 7:03:37 AM mbam-log-2009-03-21 (07-03-37).txt Scan type: Quick Scan Objects scanned: 51426 Time elapsed: 4 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Malwarebytes' Anti-Malware 1.33 Database version: 1747 Windows 5.1.2600 Service Pack 3 21/03/2009 7:03:37 AM mbam-log-2009-03-21 (07-03-37).txt Scan type: Quick Scan Objects scanned: 51426 Time elapsed: 4 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi Tomk,
OOps, pasted Hijackthis log below:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:08:23 AM, on 21/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
C:\Program Files\Optus Internet Security Suite\Anti-Virus\FSGK32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Optus Internet Security Suite\Anti-Virus\fssm32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Optus Internet Security Suite\Common\FSLAUNCH.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ibis\Desktop\HiJackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Optus Internet Security Suite\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Optus Internet Security Suite\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Wireless Configuration Utility.lnk = C:\Program Files\802.11 Wireless LAN\802.11b Wireless CardBus & PCI Adapter HW.11 V1.10\WlanCU.exe
O9 - Extra button: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Parental… - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\Optus Internet Security Suite\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {447F8438-8124-4369-905B-A249E13CBBFC} (LgbContent Control) - http://pickles.liveglobalbid.com/install/new/lgbkc.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.safety.live.com/resource/d…lscbase8460.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p…obat/nos/gp.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Optus Internet Security Suite\Common\FSMA32.EXE
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 5996 bytes
Ibis,


Please go to Kaspersky website and perform an online antivirus scan.

  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.

Also please let me know how it's running.
Hi Tomk, Ran Kaspersky on My computer (everything) and also critical areas (more limited scan). Both came back with no malware or anything infectious or suspicious. There is no log to post as the scans were totally clean. Computer is running alot faster, booting faster and google searches are not being redirected now. Not sure what we should do from here but certainly everything you have done has helped heaps. Thanks very much. I will be away for work for a week now so wont be able to access this forum till I get back. Thanks and cheers Ivars

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI