This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser gets redirected

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi and Welcome,

NOTE:
  • Malware removal is NOT instantaneous, most infections require several courses of action to completely eradicate.
  • Absence of symptoms does not always mean the computer is clean
  • Kindly follow my instructions in the order posted.
  • Please DO NOT run any scans or fix items without my direction.



Please do the following:

STEP #1

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Okay. Here are the three logs you requested.





UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-07-30.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/23/2008 1:28:27 PM
System Uptime: 7/30/2009 6:12:14 PM (0 hours ago)

Motherboard: Dell Inc. | | 0WY383
Processor: Mobile AMD Sempron™ Processor 3600+ | Socket M2/S1G1 | 1994/200mhz

==== Disk Partitions =========================

C: is FIXED (NTFS) - 149 GiB total, 137.82 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP51: 4/29/2009 11:12:49 PM - System Checkpoint
RP52: 5/1/2009 10:11:55 AM - System Checkpoint
RP53: 5/2/2009 10:37:51 AM - System Checkpoint
RP54: 5/3/2009 11:12:55 AM - System Checkpoint
RP55: 5/4/2009 10:17:52 PM - System Checkpoint
RP56: 5/6/2009 12:49:54 AM - Software Distribution Service 3.0
RP57: 5/7/2009 7:17:37 AM - System Checkpoint
RP58: 5/8/2009 8:33:53 PM - System Checkpoint
RP59: 5/13/2009 5:26:27 PM - Software Distribution Service 3.0
RP60: 5/17/2009 9:31:20 AM - Avg8 Update
RP61: 5/17/2009 9:53:46 AM - Avg8 Update
RP62: 5/20/2009 12:13:34 PM - System Checkpoint
RP63: 5/21/2009 2:08:05 PM - System Checkpoint
RP64: 5/22/2009 9:01:49 AM - Avg8 Update
RP65: 5/22/2009 9:13:10 AM - Avg8 Update
RP66: 5/23/2009 11:24:02 AM - System Checkpoint
RP67: 5/24/2009 3:38:21 PM - Removed Ad-Aware
RP68: 5/25/2009 7:05:26 PM - System Checkpoint
RP69: 5/27/2009 11:18:02 AM - Restore Operation
RP70: 5/28/2009 11:58:47 AM - System Checkpoint
RP71: 5/30/2009 1:20:18 PM - System Checkpoint
RP72: 6/1/2009 10:11:33 PM - System Checkpoint
RP73: 6/3/2009 12:37:37 AM - System Checkpoint
RP74: 6/7/2009 3:09:27 PM - System Checkpoint
RP75: 6/8/2009 10:04:15 PM - System Checkpoint
RP76: 6/9/2009 8:34:19 PM - Restore Operation
RP77: 6/9/2009 8:50:39 PM - Restore Operation
RP78: 6/10/2009 1:48:14 AM - Software Distribution Service 3.0
RP79: 6/10/2009 11:16:54 AM - Software Distribution Service 3.0
RP80: 6/11/2009 9:13:35 PM - System Checkpoint
RP81: 6/12/2009 3:00:14 AM - Software Distribution Service 3.0
RP82: 6/13/2009 6:08:52 PM - System Checkpoint
RP83: 6/14/2009 10:17:48 PM - System Checkpoint
RP84: 6/15/2009 10:27:34 PM - System Checkpoint
RP85: 6/17/2009 1:24:15 PM - System Checkpoint
RP86: 6/18/2009 3:13:17 PM - System Checkpoint
RP87: 6/19/2009 4:39:09 PM - System Checkpoint
RP88: 6/20/2009 6:37:15 PM - System Checkpoint
RP89: 6/20/2009 8:32:58 PM - Installed Logitech Desktop Messenger
RP90: 6/20/2009 9:16:10 PM - Removed Logitech QuickCam
RP91: 6/20/2009 9:17:12 PM - Removed Logitech Desktop Messenger
RP92: 6/20/2009 9:22:08 PM - Installed Webcam 1200
RP93: 6/20/2009 9:25:36 PM - Installed VideoImpression
RP94: 6/20/2009 9:26:44 PM - Installed PhotoImpression
RP95: 6/20/2009 9:28:44 PM - Installed WebCam Companion
RP96: 6/20/2009 9:30:13 PM - Installed Magic-i
RP97: 6/22/2009 12:14:54 AM - System Checkpoint
RP98: 6/23/2009 1:00:02 AM - System Checkpoint
RP99: 6/24/2009 10:14:35 AM - System Checkpoint
RP100: 6/25/2009 10:55:20 AM - System Checkpoint
RP101: 6/26/2009 9:17:13 PM - System Checkpoint
RP102: 6/27/2009 9:52:44 PM - System Checkpoint
RP103: 6/28/2009 10:32:25 PM - System Checkpoint
RP104: 6/29/2009 11:27:24 PM - System Checkpoint
RP105: 7/1/2009 9:22:20 AM - System Checkpoint
RP106: 7/2/2009 5:42:42 PM - System Checkpoint
RP107: 7/3/2009 6:41:48 PM - System Checkpoint
RP108: 7/4/2009 7:08:27 PM - System Checkpoint
RP109: 7/5/2009 10:10:04 PM - System Checkpoint
RP110: 7/7/2009 12:07:54 AM - System Checkpoint
RP111: 7/8/2009 12:40:33 AM - System Checkpoint
RP112: 7/8/2009 8:35:22 AM - Avg8 Update
RP113: 7/8/2009 9:58:07 AM - Avg8 Update
RP114: 7/9/2009 1:59:13 PM - System Checkpoint
RP115: 7/10/2009 3:02:02 PM - System Checkpoint
RP116: 7/11/2009 3:45:52 PM - System Checkpoint
RP117: 7/12/2009 4:17:36 PM - System Checkpoint
RP118: 7/13/2009 4:23:08 PM - System Checkpoint
RP119: 7/14/2009 4:58:42 PM - System Checkpoint
RP120: 7/16/2009 2:14:13 AM - System Checkpoint
RP121: 7/17/2009 3:00:17 AM - Software Distribution Service 3.0
RP122: 7/18/2009 4:09:32 AM - System Checkpoint
RP123: 7/19/2009 4:14:38 AM - System Checkpoint
RP124: 7/20/2009 6:13:43 PM - System Checkpoint
RP125: 7/22/2009 12:07:15 AM - System Checkpoint
RP126: 7/23/2009 9:59:09 PM - System Checkpoint
RP127: 7/24/2009 10:04:23 PM - System Checkpoint
RP128: 7/26/2009 9:22:21 PM - System Checkpoint
RP129: 7/27/2009 10:40:25 PM - Installed Windows Media Player 11

==== Installed Programs ======================

AAC Decoder
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
ArcSoft Magic-i 3
ArcSoft PhotoImpression 5
ArcSoft VideoImpression 2
ArcSoft WebCam Companion 2
AT&T Communication Manager
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
AutoUpdate
AVG Free 8.5
Broadcom 440x 10/100 Integrated Controller
CCleaner (remove only)
Conexant HDA D330 MDC V.92 Modem
Crawler Toolbar
Dell Touchpad
Dell Wireless WLAN Card
Digital Line Detect
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
Driver Installer
FrostWire 4.17.2
Google Chrome
H.264 Decoder
High Definition Audio Driver Package - KB835221
Home Network Manager
Hotfix for Windows XP (KB952287)
Java™ 6 Update 11
Java™ 6 Update 7
Malwarebytes' Anti-Malware
Microsoft .NET Framework 2.0 Service Pack 1
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Visual C++ 2005 Redistributable
MKV Splitter
Modem Diagnostic Tool
Mozilla Firefox (3.0.12)
MSN
OpenOffice.org 3.0
PowerDVD
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB936782)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB973346)
SigmaTel Audio
Skype web features
Skype™ 4.1
Update for Windows Internet Explorer 8 (KB968220)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC80CRTRedist - 8.0.50727.762
Webcam 1200
WebFldrs XP
Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Live Messenger
Windows Live Sign-in Assistant
Windows XP Service Pack 3
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar

==== Event Viewer Messages From Past Week ========

7/30/2009 6:24:34 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the rpcapd service.
7/30/2009 6:13:03 PM, error: Service Control Manager [7000] - The My Web Search Service service failed to start due to the following error: The system cannot find the path specified.
7/29/2009 8:07:07 PM, error: Service Control Manager [7016] - The MgiSvr service has reported an invalid current state 32.
7/24/2009 11:31:23 AM, error: Service Control Manager [7000] - The XAudioService service failed to start due to the following error: %1 is not a valid Win32 application.

==== End Of File ===========================





DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 18:26:31.82 on Thu 07/30/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1210 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe
C:\Program Files\WinPcap\rpcapd.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\CenturyTel\Home Network Manager\HomeNetworkManager.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\CenturyTel\Home Network Manager\ndis_events.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Owner\Desktop\dds(2).pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uWindow Title = Windows Internet Explorer provided by Yahoo!
uDefault_Page_URL = hxxp://www.yahoo.com/?fr=fp-yie8
uSearch Bar = hxxp://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60111
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
mSearchAssistant = hxxp://www.crawler.com/search/ie.aspx?tb_id=60111
mCustomizeSearch = hxxp://dnl.crawler.com/support/sa_customize.aspx?TbId=60111
uURLSearchHooks: N/A: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\ctbr.dll
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\ctbr.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\ctbr.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [MyWebSearch Email Plugin] c:\progra~1\mywebs~1\bar\1.bin\mwsoemon.exe
uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background
uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized
mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe"
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe"
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [InstaLAN] "c:\program files\centurytel\home network manager\HomeNetworkManager.exe" startup
mRun: []
mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a
mRun: [MyWebSearch Plugin] rundll32 c:\progra~1\mywebs~1\bar\1.bin\M3PLUGIN.DLL,UPF
mRun: [My Web Search Bar Search Scope Monitor] "c:\progra~1\mywebs~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
mRun: [MyWebSearch Email Plugin] c:\progra~1\mywebs~1\bar\1.bin\mwsoemon.exe
mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe
mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe
dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x08da -f video -m logitech -d 11.1.0.2016
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: &Search
IE: Crawler Search - tbr:iemenu
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\crawler\ctbr.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\rep6cf1f.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKman000&fl=0&ptb=LDum5v9GOUsJScGzqoNx2Q&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - plugin: c:\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\divx\divx web player\npdivx32.dll
FF - plugin: c:\documents and settings\owner\desktop\my music\new folder\divx\divx player\npDivxPlayerPlugin.dll
FF - plugin: c:\documents and settings\owner\desktop\my music\new folder\divx\divx web player\npdivx32.dll
FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-13 327688]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-13 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-13 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-4-11 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-11 298776]
R2 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [2009-2-8 32512]
S2 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe –> c:\progra~1\mywebs~1\bar\1.bin\mwssvc.exe [?]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-10-23 20160]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-21 113152]
S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [2009-6-20 611584]

=============== Created Last 30 ================

2009-07-30 18:23 –d-h— c:\windows\PIF
2009-07-30 17:59 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2009-07-30 17:59 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-30 17:59 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-07-30 17:59 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-07-30 17:59 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-07-05 21:43 56 a—h— c:\windows\system32\ezsidmv.dat
2009-07-05 20:57 –d–r– c:\program files\Skype
2009-07-05 19:31 1,278,104 a—-r– c:\windows\system32\drivers\LV302V32.SYS
2009-07-01 07:20 –d—– C:\divx

==================== Find3M ====================

2009-07-08 09:57 327,688 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-08 09:57 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-16 09:36 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:36 81,920 a——- c:\windows\system32\fontsub.dll
2009-06-03 14:09 1,291,264 a——- c:\windows\system32\quartz.dll
2009-05-13 00:15 915,456 a——- c:\windows\system32\wininet.dll
2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll
2009-01-13 11:49 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011320090114\index.dat

============= FINISH: 18:27:11.26 ===============




GMER 1.0.15.15011 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-07-30 18:31:57
Windows 5.1.2600 Service Pack 3


—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp tcpipBM.SYS (Bytemobile Kernel Network Provider/Bytemobile, Inc.)

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
ComboFix 09-07-29.04 - Owner 07/30/2009 19:56.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1187 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\WinPCap
c:\program files\WinPCap\daemon_mgm.exe
c:\program files\WinPCap\npf_mgm.exe
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MYWEBSEARCHSERVICE
——-\Legacy_NPF
——-\Service_MyWebSearchService
——-\Service_NPF


((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.

2009-07-30 23:23 . 2009-07-30 23:23 ——– d–h–w- c:\windows\PIF
2009-07-30 22:59 . 2009-07-30 22:59 ——– d—–w- c:\docume~1\Owner\APPLIC~1\Malwarebytes
2009-07-30 22:59 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-30 22:59 . 2009-07-30 22:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-30 22:59 . 2009-07-30 22:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-30 22:59 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-18 23:23 . 2009-07-18 23:33 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2009-07-06 02:43 . 2009-07-30 22:29 ——– d—–w- c:\docume~1\Owner\APPLIC~1\skypePM
2009-07-06 02:43 . 2009-07-06 02:43 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-07-06 02:36 . 2009-07-31 00:59 ——– d—–w- c:\docume~1\Owner\APPLIC~1\Skype
2009-07-06 01:57 . 2009-07-06 01:57 ——– d—–w- c:\program files\Common Files\Skype
2009-07-06 01:57 . 2009-07-06 02:14 ——– d—–r- c:\program files\Skype
2009-07-06 01:04 . 2009-07-06 01:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-07-06 00:31 . 2007-07-19 00:39 1278104 —-a-r- c:\windows\system32\drivers\LV302V32.SYS
2009-07-01 12:20 . 2009-07-12 16:32 ——– d—–w- C:\divx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-30 23:12 . 2009-04-11 03:56 ——– d—–w- c:\program files\MSN Messenger
2009-07-17 02:23 . 2009-05-17 20:11 ——– d—–w- c:\program files\Crawler
2009-07-12 16:32 . 2009-06-30 00:51 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-07-09 05:00 . 2009-01-17 05:24 ——– d—–w- c:\docume~1\Owner\APPLIC~1\FrostWire
2009-07-08 14:57 . 2009-01-13 20:06 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-07-08 14:57 . 2009-01-13 20:06 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-08 14:57 . 2009-01-13 20:06 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-06 00:50 . 2009-06-21 02:32 ——– d—–w- c:\docume~1\Owner\APPLIC~1\ArcSoft
2009-07-01 11:43 . 2009-06-30 17:09 ——– d—–w- c:\docume~1\Owner\APPLIC~1\DivX
2009-06-21 02:30 . 2009-06-21 02:25 ——– d—–w- c:\program files\ArcSoft
2009-06-21 02:30 . 2008-10-23 18:32 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-21 02:29 . 2009-06-21 02:26 ——– d—–w- c:\program files\Common Files\ArcSoft
2009-06-21 02:22 . 2009-06-21 02:22 ——– d—–w- c:\program files\Webcam 1200
2009-06-21 02:16 . 2009-06-21 01:26 ——– d—–w- c:\program files\Common Files\logishrd
2009-06-21 02:16 . 2009-06-21 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2009-06-18 05:05 . 2009-05-06 04:08 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2009-06-16 14:36 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 08:07 . 2009-01-13 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-06-03 19:09 . 2004-08-04 10:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-17 20:03 . 2009-05-17 20:03 0 -c–a-w- c:\windows\nsreg.dat
2009-05-17 14:53 . 2009-01-13 20:06 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-13 05:15 . 2006-03-04 03:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 10:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-07-23 02:17 . 2009-05-17 20:03 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-17 133104]
"FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2009-05-17 1591808]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1024000]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-08 1948440]
"InstaLAN"="c:\program files\CenturyTel\Home Network Manager\HomeNetworkManager.exe" [2008-10-14 1127712]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2008-12-01 33280]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-07-03 64000]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-07-19 439568]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-10-23 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-08 14:57 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^FrostWire On Startup.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk
backup=c:\windows\pss\FrostWire On Startup.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\CenturyTel\\Home Network Manager\\HomeNetworkManager.exe"=
"c:\\WINDOWS\\system32\\mshearts.exe"=
"c:\\Program Files\\AT&T\\Communication Manager\\ATTCM.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/13/2009 3:06 PM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/13/2009 3:06 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [4/11/2009 2:03 PM 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [4/11/2009 2:03 PM 298776]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [10/23/2008 1:34 PM 20160]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [11/21/2008 12:07 AM 113152]
S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [6/20/2009 9:22 PM 611584]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-343818398-725345543-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-17 20:05]

2009-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-343818398-725345543-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-17 20:05]

2009-07-30 c:\windows\Tasks\User_Feed_Synchronization-{7656ED77-0E7E-475E-829C-E64FDFD57624}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]

2009-07-31 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 05:18]
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
HKLM-Run-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Search
IE: Crawler Search - tbr:iemenu
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\rep6cf1f.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKman000&fl=0&ptb=LDum5v9GOUsJScGzqoNx2Q&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\divx\DivX Player\npDivxPlayerPlugin.dll
FF - plugin: c:\divx\DivX Web Player\npdivx32.dll
FF - plugin: c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-30 20:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1547161642-343818398-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(832)
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'explorer.exe'(572)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\WLTRYSVC.EXE
c:\windows\system32\BCMWLTRY.EXE
c:\program files\CenturyTel\Home Network Manager\AffinegyService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\ArcSoft\Magic-i 3\uMgiSvr.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
c:\program files\CenturyTel\Home Network Manager\ndis_events.exe
c:\program files\OpenOffice.org 3\program\soffice.exe
c:\program files\OpenOffice.org 3\program\soffice.bin
c:\program files\ATI Technologies\ATI.ACE\CLI.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-07-31 20:04 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-31 01:04

Pre-Run: 147,895,005,184 bytes free
Post-Run: 147,844,538,368 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

222 — E O F — 2009-07-17 08:03
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

DDS::
IE: Crawler Search - tbr:iemenu
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\ctbr.dll

FireFox::
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\rep6cf1f.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZKman000&fl=0&ptb=LDum5v9GOUsJScGzqoNx2Q&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

NEXT
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT

Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
ComboFix 09-07-29.04 - Owner 07/30/2009 21:06.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1506 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\progra~1\Crawler\ctbr.dll

.
((((((((((((((((((((((((( Files Created from 2009-06-28 to 2009-07-31 )))))))))))))))))))))))))))))))
.

2009-07-30 23:23 . 2009-07-30 23:23 ——– d–h–w- c:\windows\PIF
2009-07-30 22:59 . 2009-07-30 22:59 ——– d—–w- c:\docume~1\Owner\APPLIC~1\Malwarebytes
2009-07-30 22:59 . 2009-07-13 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-30 22:59 . 2009-07-30 22:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-07-30 22:59 . 2009-07-30 22:59 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-30 22:59 . 2009-07-13 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-07-18 23:23 . 2009-07-18 23:33 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2009-07-06 02:43 . 2009-07-30 22:29 ——– d—–w- c:\docume~1\Owner\APPLIC~1\skypePM
2009-07-06 02:43 . 2009-07-06 02:43 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-07-06 02:36 . 2009-07-31 02:02 ——– d—–w- c:\docume~1\Owner\APPLIC~1\Skype
2009-07-06 01:57 . 2009-07-06 01:57 ——– d—–w- c:\program files\Common Files\Skype
2009-07-06 01:57 . 2009-07-06 02:14 ——– d—–r- c:\program files\Skype
2009-07-06 01:04 . 2009-07-06 01:57 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-07-06 00:31 . 2007-07-19 00:39 1278104 —-a-r- c:\windows\system32\drivers\LV302V32.SYS
2009-07-01 12:20 . 2009-07-12 16:32 ——– d—–w- C:\divx

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-31 02:09 . 2009-05-17 20:11 ——– d—–w- c:\program files\Crawler
2009-07-30 23:12 . 2009-04-11 03:56 ——– d—–w- c:\program files\MSN Messenger
2009-07-12 16:32 . 2009-06-30 00:51 ——– d—–w- c:\program files\Common Files\DivX Shared
2009-07-09 05:00 . 2009-01-17 05:24 ——– d—–w- c:\docume~1\Owner\APPLIC~1\FrostWire
2009-07-08 14:57 . 2009-01-13 20:06 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-07-08 14:57 . 2009-01-13 20:06 327688 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-07-08 14:57 . 2009-01-13 20:06 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-06 00:50 . 2009-06-21 02:32 ——– d—–w- c:\docume~1\Owner\APPLIC~1\ArcSoft
2009-07-01 11:43 . 2009-06-30 17:09 ——– d—–w- c:\docume~1\Owner\APPLIC~1\DivX
2009-06-21 02:30 . 2009-06-21 02:25 ——– d—–w- c:\program files\ArcSoft
2009-06-21 02:30 . 2008-10-23 18:32 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-06-21 02:29 . 2009-06-21 02:26 ——– d—–w- c:\program files\Common Files\ArcSoft
2009-06-21 02:22 . 2009-06-21 02:22 ——– d—–w- c:\program files\Webcam 1200
2009-06-21 02:16 . 2009-06-21 01:26 ——– d—–w- c:\program files\Common Files\logishrd
2009-06-21 02:16 . 2009-06-21 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2009-06-18 05:05 . 2009-05-06 04:08 ——– d—–w- c:\documents and settings\All Users\Application Data\PCPitstop
2009-06-16 14:36 . 2004-08-04 10:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 10:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-12 08:07 . 2009-01-13 20:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2009-06-03 19:09 . 2004-08-04 10:00 1291264 —-a-w- c:\windows\system32\quartz.dll
2009-05-17 20:03 . 2009-05-17 20:03 0 -c–a-w- c:\windows\nsreg.dat
2009-05-17 14:53 . 2009-01-13 20:06 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-13 05:15 . 2006-03-04 03:33 915456 —-a-w- c:\windows\system32\wininet.dll
2009-05-07 15:32 . 2004-08-04 10:00 345600 —-a-w- c:\windows\system32\localspl.dll
2009-07-23 02:17 . 2009-05-17 20:03 134648 —-a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-07-31_01.01.36 )))))))))))))))))))))))))))))))))))))))))
.
- 2004-08-04 10:00 . 2009-07-30 23:17 60182 c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2009-07-31 01:05 60182 c:\windows\system32\perfc009.dat
+ 2004-08-04 10:00 . 2009-07-31 01:05 398128 c:\windows\system32\perfh009.dat
- 2004-08-04 10:00 . 2009-07-30 23:17 398128 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-17 133104]
"FreeRAM XP"="c:\program files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" [2009-05-17 1591808]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-06-26 25604904]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-10-26 1024000]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 405504]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-10-10 2183168]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-13 136600]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-07-08 1948440]
"InstaLAN"="c:\program files\CenturyTel\Home Network Manager\HomeNetworkManager.exe" [2008-10-14 1127712]
"AT&T Communication Manager"="c:\program files\AT&T\Communication Manager\ATTCM.exe" [2008-12-01 33280]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-07-03 64000]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="c:\program files\Common Files\logishrd\WUApp32.exe" [2007-07-19 439568]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-10-23 50688]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-08 14:57 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^FrostWire On Startup.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\FrostWire On Startup.lnk
backup=c:\windows\pss\FrostWire On Startup.lnkStartup

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\CenturyTel\\Home Network Manager\\HomeNetworkManager.exe"=
"c:\\WINDOWS\\system32\\mshearts.exe"=
"c:\\Program Files\\AT&T\\Communication Manager\\ATTCM.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/13/2009 3:06 PM 327688]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/13/2009 3:06 PM 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [4/11/2009 2:03 PM 906520]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [4/11/2009 2:03 PM 298776]
S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [10/23/2008 1:34 PM 20160]
S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [11/21/2008 12:07 AM 113152]
S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [6/20/2009 9:22 PM 611584]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder

2009-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-343818398-725345543-1003Core.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-17 20:05]

2009-07-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-343818398-725345543-1003UA.job
- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-05-17 20:05]

2009-07-31 c:\windows\Tasks\User_Feed_Synchronization-{7656ED77-0E7E-475E-829C-E64FDFD57624}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 11:31]

2009-07-31 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-06 05:18]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: &Search
FF - ProfilePath - c:\docume~1\Owner\APPLIC~1\Mozilla\Firefox\Profiles\rep6cf1f.default\
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-30 21:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1547161642-343818398-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(832)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-07-31 21:10
ComboFix-quarantined-files.txt 2009-07-31 02:10
ComboFix2.txt 2009-07-31 01:04

Pre-Run: 147,824,742,400 bytes free
Post-Run: 147,824,975,872 bytes free

171 — E O F — 2009-07-17 08:03






KASPERSKY ONLINE SCANNER 7.0 REPORT
Friday, July 31, 2009
Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Program database last update: Friday, July 31, 2009 03:24:45
Records in database: 2565300
Scan settings
Scan using the following database extended
Scan archives yes
Scan mail databases yes
Scan area My Computer
C:\
D:\
Scan statistics
Files scanned 55564
Threat name 7
Infected objects 11
Suspicious objects 0
Duration of the scan 01:48:05

File name Threat name Threats count
C:\Documents and Settings\Owner\Desktop\My Music\2Pac & Dr. Dre - - California love.mp3 Infected: Trojan-Downloader.WMA.GetCodec.c 1
C:\Documents and Settings\Owner\My Documents\FrostWire\Incomplete\Preview-T-2550591-stand up comedy howie mandel.wma Infected: Trojan-Downloader.Multi.MusLdr.c 1
C:\Documents and Settings\Owner\My Documents\FrostWire\Incomplete\T-2550591-stand up comedy howie mandel.wma Infected: Trojan-Downloader.Multi.MusLdr.c 1
C:\Documents and Settings\Owner\My Documents\FrostWire\Saved\we made you eminem feat (best quality).mp3 Infected: Trojan-Downloader.WMA.GetCodec.u 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP129\A0061444.DLL Infected: not-a-virus:Monitor.Win32.Agent.c 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP129\A0061447.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ax 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP129\A0061452.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.cl 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP69\A0033948.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ff 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP69\A0033952.EXE Infected: not-a-virus:AdTool.Win32.MyWebSearch.cl 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP69\A0033961.DLL Infected: not-a-virus:WebToolbar.Win32.MyWebSearch.ax 1
C:\System Volume Information\_restore{E0DB3488-823B-4963-8428-057E1596F880}\RP69\A0033965.DLL Infected: not-a-virus:Monitor.Win32.Agent.c 1
The selected area was scanned.







Malwarebytes' Anti-Malware 1.39
Database version: 2534
Windows 5.1.2600 Service Pack 3

7/31/2009 12:12:04 AM
mbam-log-2009-07-31 (00-12-04).txt

Scan type: Quick Scan
Objects scanned: 85547
Time elapsed: 3 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi

Please do the following:

Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Files
C:\Documents and Settings\Owner\Desktop\My Music\2Pac & Dr. Dre - - California love.mp3 
C:\Documents and Settings\Owner\My Documents\FrostWire\Incomplete\Preview-T-2550591-stand up comedy howie mandel.wma
C:\Documents and Settings\Owner\My Documents\FrostWire\Incomplete\T-2550591-stand up comedy howie mandel.wma
C:\Documents and Settings\Owner\My Documents\FrostWire\Saved\we made you eminem feat (best quality).mp3 

:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



NEXT


As clearly witnessed by the Kaspersky results

P2P - I see you have P2P software Frostwire installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall these now. You can do so via Control Panel >> Add or Remove Programs.


NEXT


[external image: Posted Image]
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 14. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u14-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH CheckedApplications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window

    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
Okay I am downloading and updating java. Will have that done soon. Thanks for the frostwire info. I am helping a friend do this and didn't know for sure what that was. Its gone now though. Let me know if anything else needs to be done. Thanks All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== FILES ========== File/Folder C:\Documents and Settings\Owner\Desktop\My Music\2Pac & Dr. Dre - - California love.mp3 not found. C:\Documents and Settings\Owner\My Documents\FrostWire\Incomplete\Preview-T-2550591-stand up comedy howie mandel.wma moved successfully. C:\Documents and Settings\Owner\My Documents\FrostWire\Incomplete\T-2550591-stand up comedy howie mandel.wma moved successfully. C:\Documents and Settings\Owner\My Documents\FrostWire\Saved\we made you eminem feat (best quality).mp3 moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Owner ->Temp folder emptied: 75047763 bytes ->Temporary Internet Files folder emptied: 37414642 bytes ->Java cache emptied: 127542 bytes ->FireFox cache emptied: 40480826 bytes ->Google Chrome cache emptied: 5013556 bytes %systemdrive% .tmp files removed: 0 bytes C:\WINDOWS\msdownld.tmp folder deleted successfully. %systemroot% .tmp files removed: 2195181 bytes %systemroot%\System32 .tmp files removed: 2577 bytes Windows Temp folder emptied: 483 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 152.89 mb OTM by OldTimer - Version 3.0.0.5 log created on 07312009_101525 Files moved on Reboot… Registry entries deleted on Reboot…
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_09-07-30.01) Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 10/23/2008 1:28:27 PM System Uptime: 7/31/2009 10:16:56 AM (2 hours ago) Motherboard: Dell Inc. | | 0WY383 Processor: Mobile AMD Sempron™ Processor 3600+ | Socket M2/S1G1 | 1994/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 136.618 GiB free. D: is CDROM () ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP51: 4/29/2009 11:12:49 PM - System Checkpoint RP52: 5/1/2009 10:11:55 AM - System Checkpoint RP53: 5/2/2009 10:37:51 AM - System Checkpoint RP54: 5/3/2009 11:12:55 AM - System Checkpoint RP55: 5/4/2009 10:17:52 PM - System Checkpoint RP56: 5/6/2009 12:49:54 AM - Software Distribution Service 3.0 RP57: 5/7/2009 7:17:37 AM - System Checkpoint RP58: 5/8/2009 8:33:53 PM - System Checkpoint RP59: 5/13/2009 5:26:27 PM - Software Distribution Service 3.0 RP60: 5/17/2009 9:31:20 AM - Avg8 Update RP61: 5/17/2009 9:53:46 AM - Avg8 Update RP62: 5/20/2009 12:13:34 PM - System Checkpoint RP63: 5/21/2009 2:08:05 PM - System Checkpoint RP64: 5/22/2009 9:01:49 AM - Avg8 Update RP65: 5/22/2009 9:13:10 AM - Avg8 Update RP66: 5/23/2009 11:24:02 AM - System Checkpoint RP67: 5/24/2009 3:38:21 PM - Removed Ad-Aware RP68: 5/25/2009 7:05:26 PM - System Checkpoint RP69: 5/27/2009 11:18:02 AM - Restore Operation RP70: 5/28/2009 11:58:47 AM - System Checkpoint RP71: 5/30/2009 1:20:18 PM - System Checkpoint RP72: 6/1/2009 10:11:33 PM - System Checkpoint RP73: 6/3/2009 12:37:37 AM - System Checkpoint RP74: 6/7/2009 3:09:27 PM - System Checkpoint RP75: 6/8/2009 10:04:15 PM - System Checkpoint RP76: 6/9/2009 8:34:19 PM - Restore Operation RP77: 6/9/2009 8:50:39 PM - Restore Operation RP78: 6/10/2009 1:48:14 AM - Software Distribution Service 3.0 RP79: 6/10/2009 11:16:54 AM - Software Distribution Service 3.0 RP80: 6/11/2009 9:13:35 PM - System Checkpoint RP81: 6/12/2009 3:00:14 AM - Software Distribution Service 3.0 RP82: 6/13/2009 6:08:52 PM - System Checkpoint RP83: 6/14/2009 10:17:48 PM - System Checkpoint RP84: 6/15/2009 10:27:34 PM - System Checkpoint RP85: 6/17/2009 1:24:15 PM - System Checkpoint RP86: 6/18/2009 3:13:17 PM - System Checkpoint RP87: 6/19/2009 4:39:09 PM - System Checkpoint RP88: 6/20/2009 6:37:15 PM - System Checkpoint RP89: 6/20/2009 8:32:58 PM - Installed Logitech Desktop Messenger RP90: 6/20/2009 9:16:10 PM - Removed Logitech QuickCam RP91: 6/20/2009 9:17:12 PM - Removed Logitech Desktop Messenger RP92: 6/20/2009 9:22:08 PM - Installed Webcam 1200 RP93: 6/20/2009 9:25:36 PM - Installed VideoImpression RP94: 6/20/2009 9:26:44 PM - Installed PhotoImpression RP95: 6/20/2009 9:28:44 PM - Installed WebCam Companion RP96: 6/20/2009 9:30:13 PM - Installed Magic-i RP97: 6/22/2009 12:14:54 AM - System Checkpoint RP98: 6/23/2009 1:00:02 AM - System Checkpoint RP99: 6/24/2009 10:14:35 AM - System Checkpoint RP100: 6/25/2009 10:55:20 AM - System Checkpoint RP101: 6/26/2009 9:17:13 PM - System Checkpoint RP102: 6/27/2009 9:52:44 PM - System Checkpoint RP103: 6/28/2009 10:32:25 PM - System Checkpoint RP104: 6/29/2009 11:27:24 PM - System Checkpoint RP105: 7/1/2009 9:22:20 AM - System Checkpoint RP106: 7/2/2009 5:42:42 PM - System Checkpoint RP107: 7/3/2009 6:41:48 PM - System Checkpoint RP108: 7/4/2009 7:08:27 PM - System Checkpoint RP109: 7/5/2009 10:10:04 PM - System Checkpoint RP110: 7/7/2009 12:07:54 AM - System Checkpoint RP111: 7/8/2009 12:40:33 AM - System Checkpoint RP112: 7/8/2009 8:35:22 AM - Avg8 Update RP113: 7/8/2009 9:58:07 AM - Avg8 Update RP114: 7/9/2009 1:59:13 PM - System Checkpoint RP115: 7/10/2009 3:02:02 PM - System Checkpoint RP116: 7/11/2009 3:45:52 PM - System Checkpoint RP117: 7/12/2009 4:17:36 PM - System Checkpoint RP118: 7/13/2009 4:23:08 PM - System Checkpoint RP119: 7/14/2009 4:58:42 PM - System Checkpoint RP120: 7/16/2009 2:14:13 AM - System Checkpoint RP121: 7/17/2009 3:00:17 AM - Software Distribution Service 3.0 RP122: 7/18/2009 4:09:32 AM - System Checkpoint RP123: 7/19/2009 4:14:38 AM - System Checkpoint RP124: 7/20/2009 6:13:43 PM - System Checkpoint RP125: 7/22/2009 12:07:15 AM - System Checkpoint RP126: 7/23/2009 9:59:09 PM - System Checkpoint RP127: 7/24/2009 10:04:23 PM - System Checkpoint RP128: 7/26/2009 9:22:21 PM - System Checkpoint RP129: 7/27/2009 10:40:25 PM - Installed Windows Media Player 11 RP130: 7/30/2009 7:16:05 PM - System Checkpoint RP131: 7/31/2009 9:55:14 AM - Software Distribution Service 3.0 RP132: 7/31/2009 12:34:46 PM - Removed Java™ 6 Update 11 RP133: 7/31/2009 12:35:27 PM - Removed Java™ 6 Update 7 RP134: 7/31/2009 12:36:23 PM - Installed Java™ SE Development Kit 6 Update 14 RP135: 7/31/2009 12:37:22 PM - Installed Java™ 6 Update 14 RP136: 7/31/2009 12:38:22 PM - Installed JavaFX™ 1.2 SDK ==== Installed Programs ====================== AAC Decoder Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin ArcSoft Magic-i 3 ArcSoft PhotoImpression 5 ArcSoft VideoImpression 2 ArcSoft WebCam Companion 2 AT&T Communication Manager ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver AutoUpdate AVG Free 8.5 Broadcom 440x 10/100 Integrated Controller CCleaner (remove only) Conexant HDA D330 MDC V.92 Modem Crawler Toolbar Dell Touchpad Dell Wireless WLAN Card Digital Line Detect DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Version Checker DivX Web Player Driver Installer Google Chrome H.264 Decoder High Definition Audio Driver Package - KB835221 Home Network Manager Hotfix for Windows XP (KB952287) Java DB 10.4.2.1 Java™ 6 Update 14 Java™ SE Development Kit 6 Update 14 JavaFX™ 1.2 SDK Malwarebytes' Anti-Malware Microsoft .NET Framework 2.0 Service Pack 1 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Visual C++ 2005 Redistributable MKV Splitter Modem Diagnostic Tool Mozilla Firefox (3.0.12) MSN NetBeans IDE 6.5.1 OpenOffice.org 3.0 PowerDVD Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 8 (KB969897) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956390) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB973346) SigmaTel Audio Skype web features Skype™ 4.1 Update for Windows Internet Explorer 8 (KB968220) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) VC80CRTRedist - 8.0.50727.762 Webcam 1200 WebFldrs XP Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04) Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Internet Explorer 7 Windows Internet Explorer 8 Windows Live Messenger Windows Live Sign-in Assistant Windows XP Service Pack 3 Yahoo! Messenger Yahoo! Software Update Yahoo! Toolbar ==== Event Viewer Messages From Past Week ======== 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The Yahoo! Updater service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The MgiSvr service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The Dell Wireless WLAN Tray Service service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The Ati HotKey Poller service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7034] - The AffinegyService service terminated unexpectedly. It has done this 1 time(s). 7/31/2009 10:15:25 AM, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 7/30/2009 8:00:48 PM, error: Service Control Manager [7000] - The Remote Packet Capture Protocol v.0 (experimental) service failed to start due to the following error: The system cannot find the path specified. 7/30/2009 7:58:52 PM, error: Service Control Manager [7034] - The Remote Packet Capture Protocol v.0 (experimental) service terminated unexpectedly. It has done this 1 time(s). 7/30/2009 7:56:31 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the PEVSystemStart service to connect. 7/30/2009 6:24:34 PM, error: Service Control Manager [7011] - Timeout (30000 milliseconds) waiting for a transaction response from the rpcapd service. 7/30/2009 6:13:03 PM, error: Service Control Manager [7000] - The My Web Search Service service failed to start due to the following error: The system cannot find the path specified. 7/29/2009 8:07:07 PM, error: Service Control Manager [7016] - The MgiSvr service has reported an invalid current state 32. 7/27/2009 7:31:59 PM, error: Service Control Manager [7000] - The XAudioService service failed to start due to the following error: %1 is not a valid Win32 application. ==== End Of File =========================== DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 12:55:39.06 on Fri 07/31/2009 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_14 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1918.1208 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe C:\WINDOWS\system32\Ati2evxx.exe svchost.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\CenturyTel\Home Network Manager\AffinegyService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\ArcSoft\Magic-i 3\uMgiSvr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe C:\WINDOWS\system32\WLTRAY.exe C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\CenturyTel\Home Network Manager\HomeNetworkManager.exe C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe C:\WINDOWS\PixArt\PAC207\Monitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\CenturyTel\Home Network Manager\ndis_events.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Owner\Desktop\dds(3).pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8 mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com uURLSearchHooks: N/A: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\ctbr.dll BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - c:\progra~1\crawler\ctbr.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - c:\progra~1\crawler\ctbr.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Google Update] "c:\documents and settings\owner\local settings\application data\google\update\GoogleUpdate.exe" /c uRun: [FreeRAM XP] "c:\program files\yourware solutions\freeram xp pro\FreeRAM XP Pro.exe" -win uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [msnmsgr] "c:\program files\msn messenger\msnmsgr.exe" /background uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [PDVDDXSrv] "c:\program files\cyberlink\powerdvd dx\PDVDDXSrv.exe" mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\CLIStart.exe" mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [InstaLAN] "c:\program files\centurytel\home network manager\HomeNetworkManager.exe" startup mRun: [AT&T Communication Manager] "c:\program files\at&t\communication manager\ATTCM.exe" -a mRun: [ArcSoft Connection Service] c:\program files\common files\arcsoft\connection service\bin\ACDaemon.exe mRun: [Monitor] c:\windows\pixart\pac207\Monitor.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" dRunOnce: [WUAppSetup] c:\program files\common files\logishrd\WUApp32.exe -v 0x046d -p 0x08da -f video -m logitech -d 11.1.0.2016 StartupFolder: c:\docume~1\owner\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: &Search IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} - hxxp://utilities.pcpitstop.com/Optimize3/pcpitstop2.dll Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\rep6cf1f.default\ FF - plugin: c:\divx\divx player\npDivxPlayerPlugin.dll FF - plugin: c:\divx\divx web player\npdivx32.dll FF - plugin: c:\documents and settings\owner\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-13 327688] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-13 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-13 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-4-11 906520] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-4-11 298776] R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392] S3 ADM8511;ADMtek ADM8511/AN986 USB To Fast Ethernet Converter;c:\windows\system32\drivers\ADM8511.SYS [2008-10-23 20160] S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\at&t\communication manager\RcAppSvc.exe [2008-11-21 113152] S3 PAC207;Webcam 1200;c:\windows\system32\drivers\PFC027.SYS [2009-6-20 611584] =============== Created Last 30 ================ 2009-07-31 12:54 –d—– c:\documents and settings\owner\.netbeans 2009-07-31 12:54 –d—– c:\documents and settings\owner\.netbeans-registration 2009-07-31 12:52 –d—– c:\program files\NetBeans 6.5.1 2009-07-31 12:51 –d—– c:\documents and settings\owner\.nbi 2009-07-31 12:38 –d—– c:\program files\JavaFX 2009-07-31 12:37 –d—– c:\program files\Sun 2009-07-31 12:37 73,728 a——- c:\windows\system32\javacpl.cpl 2009-07-31 10:15 –d—– C:\_OTM 2009-07-30 21:05 –ds—- C:\ComboFix 2009-07-30 20:03 -cd—– c:\windows\system32\dllcache\cache 2009-07-30 19:56 a-dshr– C:\cmdcons 2009-07-30 19:53 219,648 a——- c:\windows\PEV.exe 2009-07-30 19:53 161,792 a——- c:\windows\SWREG.exe 2009-07-30 19:53 98,816 a——- c:\windows\sed.exe 2009-07-30 18:23 –d-h— c:\windows\PIF 2009-07-30 17:59 –d—– c:\docume~1\owner\applic~1\Malwarebytes 2009-07-30 17:59 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-07-30 17:59 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-07-30 17:59 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-07-30 17:59 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-07-05 21:43 56 a—h— c:\windows\system32\ezsidmv.dat 2009-07-05 20:57 –d–r– c:\program files\Skype 2009-07-05 19:31 1,278,104 a—-r– c:\windows\system32\drivers\LV302V32.SYS ==================== Find3M ==================== 2009-07-31 12:37 410,984 ac—— c:\windows\system32\deploytk.dll 2009-07-08 09:57 327,688 a——- c:\windows\system32\drivers\avgldx86.sys 2009-07-08 09:57 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-07-03 12:09 915,456 a——- c:\windows\system32\wininet.dll 2009-06-16 09:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 09:36 81,920 a——- c:\windows\system32\fontsub.dll 2009-06-03 14:09 1,291,264 a——- c:\windows\system32\quartz.dll 2009-05-07 10:32 345,600 a——- c:\windows\system32\localspl.dll 2009-01-13 11:49 32,768 ac-sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011320090114\index.dat ============= FINISH: 12:55:56.35 ===============
Hi,

You are clean, just some housekeeping to do now.

Please do the following

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them


    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI