This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect Spyware Problem

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My laptop (Windows XP Professional 5.1.2600) running IE recently became infected with whatever it is that redirects you when you click on a search result in Google. I'm running AVG Free 8.5 but that (of course) doesn't find the problem. I've read several forums now and it's obvious that I'm going to need some direction so I've gone ahead and downloaded HJT and ran it a few minutes ago (hopefully, I ran it correctly) … here are the results:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:17:01 PM, on 8/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mcneese.edu/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Version Cue CS2] C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVSync Manager (AvSynMgr) - Unknown owner - C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McShield - Unknown owner - C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe

–
End of file - 7927 bytes
Hi,

Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.


STEP #2


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • Sections
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries




NEXT


We Need to check for Rootkits with RootRepeal
  • Download RootRepeal from the following location and save it to your desktop.
  • Extract RootRepeal.exe from the archive.
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check all seven boxes: [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:), and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your next reply, please.
Thank you so much for your help. Sorry for my slow response - I had to wait until the weekend so I would have enough time to run the different scans.
—————————————————————————————-

DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 2:23:16.17 on Sat 08/15/2009
Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1006.294 [GMT -5:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Documents and Settings\MSU\Desktop\dds.pif

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.mcneese.edu/
uInternet Settings,ProxyOverride =
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: Adobe PDF: {182ec0be-5110-49c8-a062-beb1d02a220b} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll
EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Version Cue CS2] c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
dRunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
IE: Convert link target to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath -
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 NaiFsRec;NaiFsRec;c:\windows\system32\drivers\naifsrec.sys [2001-4-30 4512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-13 335752]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-13 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-13 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-13 298776]
R2 AvSynMgr;AVSync Manager;c:\program files\network associates\virusscan\Avsynmgr.exe [2001-11-26 155665]
R2 prt1xw2k;SEM 11 Mbps Wireless Card NDIS Interface;c:\windows\system32\drivers\PRT1XW2K.SYS [2009-2-24 13056]
R3 McShield;McShield;c:\program files\common files\network associates\mcshield\Mcshield.exe [2001-11-26 225403]
R3 NaiFiltr;NaiFiltr;c:\program files\common files\network associates\mcshield\naifiltr.sys [2001-11-26 23856]
R3 SWLD23;Netopia 802.11b WLAN Cardbus Card;c:\windows\system32\drivers\swld23.sys [2009-2-24 68224]

=============== Created Last 30 ================

2009-08-09 12:16 –d—– c:\program files\Trend Micro
2009-08-01 09:22 410,984 a——- c:\windows\system32\deploytk.dll
2009-08-01 09:22 73,728 a——- c:\windows\system32\javacpl.cpl
2009-07-26 08:46 –d—– c:\program files\MSECache
2009-07-23 08:36 –d—– c:\program files\iPod

==================== Find3M ====================

2009-08-01 09:22 335,752 a——- c:\windows\system32\drivers\avgldx86.sys
2009-07-09 12:16 2,060,288 a——- c:\windows\system32\usbaaplrc.dll
2009-07-09 12:16 39,424 a——- c:\windows\system32\drivers\usbaapl.sys
2009-06-16 09:55 119,808 a——- c:\windows\system32\t2embed.dll
2009-06-16 09:55 82,432 a——- c:\windows\system32\fontsub.dll
2009-06-16 09:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll
2009-06-16 09:55 82,432 ——– c:\windows\system32\dllcache\fontsub.dll
2009-06-13 07:21 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-06-03 14:27 1,290,752 a——- c:\windows\system32\quartz.dll
2009-06-03 14:27 1,290,752 ——– c:\windows\system32\dllcache\quartz.dll

============= FINISH: 2:25:32.80 ===============

((((((((((((((((((((((((((((((( Next Report )))))))))))))))))))))))))))))))))))))))))

GMER 1.0.15.15020 [gmer.exe] - http://www.gmer.net
Rootkit scan 2009-08-15 03:26:26
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code 8695A5A8 ZwEnumerateKey
Code 8695A208 ZwFlushInstructionCache
Code 868B2BFE IofCallDriver
Code 85F1C426 IofCompleteRequest

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs NaiFiltr.sys
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \FileSystem\Fastfat \Fat ECB50C8A

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat NaiFiltr.sys

Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
—- Processes - GMER 1.0.15 —-

Library C:\Program (*** hidden *** ) @ C:\WINDOWS\system32\spoolsv.exe [672] 0x16080000
Library C:\Program (*** hidden *** ) @ C:\WINDOWS\system32\svchost.exe [1584] 0x16080000
Library C:\Program (*** hidden *** ) @ C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe [2236] 0x16080000

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys (*** hidden *** ) [SYSTEM] SKYNETgixetjlb <– ROOTKIT !!!

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb@imagepath \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETfmuwqjol.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETwkwqqltk.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETohiwtosy.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETvksnbaim.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@start 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@type 1
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@group file system
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb@imagepath \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main@aid 10096
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main@sid 0
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\injector@* SKYNETwsp.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\drivers\SKYNETamhiybct.sys
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETfmuwqjol.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETwkwqqltk.dat
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETohiwtosy.dll
Reg HKLM\SYSTEM\ControlSet003\Services\SKYNETgixetjlb\[removed] \systemroot\system32\SKYNETvksnbaim.dat

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys 68608 bytes executable <– ROOTKIT !!!
File C:\WINDOWS\system32\SKYNETfmuwqjol.dll 44032 bytes executable
File C:\WINDOWS\system32\SKYNETohiwtosy.dll 20992 bytes executable
File C:\WINDOWS\system32\SKYNETvksnbaim.dat 91 bytes
File C:\WINDOWS\system32\SKYNETwkwqqltk.dat 780224 bytes
File C:\WINDOWS\Temp\SKYNETjgcynmwpmi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqndxgbxtit.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETuxmjvweiip.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETvjpxrorcnn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETvsectplabn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETwdkbrewhtv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETwpcvkorori.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETwpcynvxufp.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETxdutojutlv.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETyaprpepuqs.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETygxnboteof.tmp 20992 bytes executable
File C:\WINDOWS\Temp\T30DebugLogFile.txt 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4L5PL4HT 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\4L5PL4HT\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DPFJA2PV 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DPFJA2PV\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\EFEKH1Q9 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\EFEKH1Q9\desktop.ini 67 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\index.dat 16384 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KHOWVCJV 0 bytes
File C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KHOWVCJV\desktop.ini 67 bytes
File C:\WINDOWS\Temp\teredo.txt 108 bytes
File C:\WINDOWS\Temp\Thumbs.db 6144 bytes
File C:\WINDOWS\Temp\uxeventlog.txt 280032 bytes
File C:\WINDOWS\Temp\WebPoolFileFile 261 bytes
File C:\WINDOWS\Temp\_coInst.log 1016 bytes
File C:\WINDOWS\Temp\_scan_buttons.log 1159 bytes
File C:\WINDOWS\Temp\SKYNETjmlfucnhsf.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETjqqdalrjsr.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkdbynxgade.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkjenuscexn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETkmwsonlycx.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlbdworvjki.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETleaxjatqnt.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETljgjxvawui.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlqmbvgfcpb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETlyigqyontl.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETmahuymspyl.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETmuidvvummp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETnrfuyrfdax.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETnrhrulmomy.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNEToiorjkiknv.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETopviyqgtel.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETortbfxpesu.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETpmduckppkb.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETprhqcdxbqo.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETptepusfwhq.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETpyqrnsmapj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqdrtfnnvnn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqelogcofpy.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETapvaxratpw.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETaqslhyvwne.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETbdgcxjkipm.tmp 18944 bytes
File C:\WINDOWS\Temp\SKYNETbrxejfifny.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETbulfxmptcn.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETbyfnkwtbru.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETcakoquqlog.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETchutnjwvja.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETcqcjomoiib.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETcsgwgqauyh.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETdfwbwhjfva.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETelercajvdj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETevccrpprrn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETevrknosdmn.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETfesucvpmta.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETfvnqnsvmti.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETfvtaknvrad.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETgekyjcxjib.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNEThofqoqrljc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETifxrximird.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETikxsgefuso.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETisvjkpacjr.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETitnvoiwgbg.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETixqfiivxap.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETixvlhmxmdb.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETqpxodlccpq.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqqmdevsjsu.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETqwdfvaqayp.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETrirbcjqexj.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETroicoecifm.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETrpcibmxvpc.tmp 18432 bytes
File C:\WINDOWS\Temp\SKYNETrppplwtsox.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETsbaohbbcxe.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETscrlckapgi.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETsegickkosj.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETsevpusyapu.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETsmqbvfulmx.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETtalknbpavo.tmp 20992 bytes executable
File C:\WINDOWS\Temp\SKYNETtfdxwreewi.tmp 17408 bytes
File C:\WINDOWS\Temp\SKYNETthqmjsotaf.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETubqresjtuw.tmp 18944 bytes executable
File C:\WINDOWS\Temp\SKYNETufxgcixlob.tmp 18944 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.refparser.golive_2.0.0\res\Settings\MarkupGlue\html\chtml\com.adobe.versioncue.controller.imprt.jar 66145 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.refparser.golive_2.0.0\res\Settings\MarkupGlue\html\chtml\META-INF 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.refparser.golive_2.0.0\res\Settings\MarkupGlue\html\chtml\plugin.xml 1386 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\Communicator 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\FileMapping 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\ImportFromPrint 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\InCopy 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\MarkupGlue 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\SiteDesign 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\SiteSettings 0 bytes
File C:\Program Files\Adobe\Adobe Version Cue CS2\plugins\com.adobe.versioncue.soap.genericcall_2.0.0\UserAgentProfile 0 bytes

—- EOF - GMER 1.0.15 —-

(((((((((((((((((((((((((((((((((((((( Next Report )))))))))))))))))))))))))))))))))))))))

ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/15 03:29
Program Version: Version 1.3.5.0
Windows Version: Windows XP SP2
==================================================

Drivers
——————-
Name: aujasnkj.sys
Image Path: C:\DOCUME~1\MSU\LOCALS~1\Temp\aujasnkj.sys
Address: 0xECB6C000 Size: 83584 File Visible: No Signed: -
Status: -

Name: dump_atapi.sys
Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
Address: 0xEDF89000 Size: 98304 File Visible: No Signed: -
Status: -

Name: dump_WMILIB.SYS
Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
Address: 0xF7AA9000 Size: 8192 File Visible: No Signed: -
Status: -

Name: rootrepeal.sys
Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
Address: 0xECE27000 Size: 49152 File Visible: No Signed: -
Status: -

Name: SKYNETamhiybct.sys
Image Path: C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys
Address: 0xEE27B000 Size: 163840 File Visible: - Signed: -
Status: Hidden from the Windows API!

Hidden/Locked Files
——————-
Path: C:\hiberfil.sys
Status: Locked to the Windows API!

Path: C:\WINDOWS\system32\SKYNETfmuwqjol.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETohiwtosy.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETvksnbaim.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\SKYNETwkwqqltk.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETjgcynmwpmi.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETqndxgbxtit.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETuxmjvweiip.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETvjpxrorcnn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETvsectplabn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETwdkbrewhtv.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETwpcvkorori.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETwpcynvxufp.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETxdutojutlv.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETyaprpepuqs.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETygxnboteof.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\T30DebugLogFile.txt
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\Temporary Internet Files
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\teredo.txt
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\Thumbs.db
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\uxeventlog.txt
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\WebPoolFileFile
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\_coInst.log
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\_scan_buttons.log
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETjmlfucnhsf.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETjqqdalrjsr.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETkdbynxgade.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETkjenuscexn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETkmwsonlycx.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETlbdworvjki.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETleaxjatqnt.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETljgjxvawui.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETlqmbvgfcpb.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETlyigqyontl.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETmahuymspyl.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETmuidvvummp.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETnrfuyrfdax.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETnrhrulmomy.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNEToiorjkiknv.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETopviyqgtel.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETortbfxpesu.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETpmduckppkb.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETprhqcdxbqo.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETptepusfwhq.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETpyqrnsmapj.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETqdrtfnnvnn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETqelogcofpy.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETapvaxratpw.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETaqslhyvwne.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETbdgcxjkipm.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETbrxejfifny.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETbulfxmptcn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETbyfnkwtbru.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETcakoquqlog.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETchutnjwvja.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETcqcjomoiib.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETcsgwgqauyh.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETdfwbwhjfva.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETelercajvdj.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETevccrpprrn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETevrknosdmn.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETfesucvpmta.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETfvnqnsvmti.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETfvtaknvrad.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETgekyjcxjib.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNEThofqoqrljc.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETifxrximird.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETikxsgefuso.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETisvjkpacjr.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETitnvoiwgbg.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETixqfiivxap.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETixvlhmxmdb.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETqpxodlccpq.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETqqmdevsjsu.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETqwdfvaqayp.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETrirbcjqexj.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETroicoecifm.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETrpcibmxvpc.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETrppplwtsox.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETsbaohbbcxe.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETscrlckapgi.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETsegickkosj.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETsevpusyapu.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETsmqbvfulmx.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETtalknbpavo.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETtfdxwreewi.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETthqmjsotaf.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETubqresjtuw.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\SKYNETufxgcixlob.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys
Status: Invisible to the Windows API!

Path: c:\windows\softwaredistribution\eventcache\{c0869723-c560-4179-9175-e41ada305cd4}.bin
Status: Allocation size mismatch (API: 8, Raw: 0)

Stealth Objects
——————-
Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: winlogon.exe (PID: 1256) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: services.exe (PID: 1304) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: lsass.exe (PID: 1316) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETfmuwqjol.dll]
Process: svchost.exe (PID: 1480) Address: 0x008d0000 Size: 57344

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1480) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1584) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1648) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1756) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1940) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Explorer.EXE (PID: 2044) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: spoolsv.exe (PID: 672) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 336) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: VersionCueCS2.exe (PID: 412) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: AppleMobileDeviceService.exe (PID: 432) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgwdsvc.exe (PID: 456) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Avsynmgr.exe (PID: 548) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: jqs.exe (PID: 164) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 1024) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: VsStat.exe (PID: 1216) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Vshwin32.exe (PID: 1492) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgrsx.exe (PID: 1860) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Avconsol.exe (PID: 928) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: mysqld-nt.exe (PID: 2236) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: Mcshield.exe (PID: 2628) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: alg.exe (PID: 2916) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: hkcmd.exe (PID: 3160) Address: 0x00890000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: SynTPLpr.exe (PID: 3176) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: SynTPEnh.exe (PID: 3192) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: tfswctrl.exe (PID: 3200) Address: 0x00920000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: issch.exe (PID: 3368) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: jusched.exe (PID: 3544) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: VersionCueCS2Tray.exe (PID: 3560) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgtray.exe (PID: 3576) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: QTTask.exe (PID: 3584) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: iTunesHelper.exe (PID: 3612) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: ctfmon.exe (PID: 3624) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: DLG.exe (PID: 3664) Address: 0x00d70000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: iPodService.exe (PID: 2032) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: svchost.exe (PID: 880) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: iexplore.exe (PID: 3816) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: avgnsx.exe (PID: 10692) Address: 0x10000000 Size: 32768

Object: Hidden Module [Name: SKYNETohiwtosy.dll]
Process: RootRepeal.exe (PID: 12088) Address: 0x10000000 Size: 32768

Hidden Services
——————-
Service Name: SKYNETgixetjlb
Image Path: C:\WINDOWS\system32\drivers\SKYNETamhiybct.sys

==EOF==

Attachments:

Hi,

Please do the following:

Download Combofix from either of the links below. You must rename it before saving it.
Save it to your desktop.

**Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**

  • If you are using Firefox, make sure that your download settings are as follows:
  • Tools->Options->Main tab
  • Set to "Always ask me where to Save the files".


Link 1
Link 2



During the download, rename Combofix to Combo-Fix as follows:

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–
  • It is important you rename Combofix during the download, but not after.
  • Please do not rename Combofix to other names, but only to the one indicated.


———————————————————–

  • Double click on Combo-Fix.exe & follow the prompts.
    • When finished, it will produce a report for you.
    • Please post the "C:\Combo-Fix.txt" for further review.
    **Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**


    ———————————————————–

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

    ———————————————————–


NOTE: ComboFix shall request to install the Recovery Console, please ALLOW it to do so.
ComboFix 09-08-10.06 - dclaire 08/15/2009 6:45.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1006.501 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Installer\589029.msp
c:\windows\system32\drivers\SKYNETamhiybct.sys
c:\windows\system32\SKYNETfmuwqjol.dll
c:\windows\system32\SKYNETohiwtosy.dll
c:\windows\system32\SKYNETvksnbaim.dat
c:\windows\system32\SKYNETwkwqqltk.dat

—– BITS: Possible infected sites —–

hxxp://update.mcneese.edu
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_SKYNETgixetjlb
——-\Legacy_SKYNETgixetjlb


((((((((((((((((((((((((( Files Created from 2009-07-15 to 2009-08-15 )))))))))))))))))))))))))))))))
.

2009-08-09 17:16 . 2009-08-09 17:16 ——– d—–w- c:\program files\Trend Micro
2009-08-01 14:22 . 2009-08-01 14:22 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-08-01 14:21 . 2009-08-01 14:21 152576 —-a-w- c:\documents and settings\MSU\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-26 13:46 . 2009-07-26 13:46 ——– d—–w- c:\program files\MSECache
2009-07-23 17:15 . 2009-07-23 17:15 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-23 13:36 . 2009-07-23 13:36 ——– d—–w- c:\program files\iPod
2009-07-23 13:29 . 2009-07-23 13:29 75040 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 14:22 . 2009-06-13 12:21 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-01 14:22 . 2005-06-10 02:18 ——– d—–w- c:\program files\Java
2009-07-26 15:24 . 2005-06-28 20:14 179744 —-a-w- c:\documents and settings\MSU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-26 15:22 . 2009-07-26 15:22 204397 —-a-w- c:\windows\Fonts\AdobeFnt09.lst
2009-07-23 13:56 . 2009-05-10 10:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-23 13:42 . 2009-05-10 10:38 ——– d—–w- c:\program files\iTunes
2009-07-23 13:36 . 2009-05-10 10:35 ——– d—–w- c:\program files\Common Files\Apple
2009-07-23 13:34 . 2006-08-22 13:06 ——– d—–w- c:\program files\QuickTime
2009-07-13 22:01 . 2009-07-13 16:07 ——– d—–w- c:\documents and settings\All Users\Application Data\14529004
2009-07-13 21:58 . 2005-06-27 19:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-11 11:50 . 2009-06-13 12:21 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-09 17:16 . 2009-05-10 10:36 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-09 17:16 . 2009-05-10 10:36 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-16 14:55 . 2004-08-11 22:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2004-08-11 22:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-13 12:21 . 2009-06-13 12:21 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-13 12:21 . 2009-06-13 12:21 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-03 19:27 . 2004-08-11 22:00 1290752 —-a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10b.exe" [2009-02-03 240544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-21 118784]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-01 148888]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-13 1948440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-6-9 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-13 12:21 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FileZilla\\filezilla.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSU-Jabber\\MSU-Jabber.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 8 (0x8)
"AllowInboundTimestampRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)
"AllowInboundRouterRequest"= 0 (0x0)
"AllowOutboundDestinationUnreachable"= 0 (0x0)
"AllowOutboundSourceQuench"= 0 (0x0)
"AllowOutboundParameterProblem"= 0 (0x0)
"AllowOutboundTimeExceeded"= 0 (0x0)
"AllowRedirect"= 0 (0x0)
"AllowOutboundPacketTooBig"= 0 (0x0)

R0 NaiFsRec;NaiFsRec;c:\windows\system32\drivers\naifsrec.sys [4/30/2001 4:51 AM 4512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/13/2009 7:21 AM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/13/2009 7:21 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/13/2009 7:21 AM 298776]
R2 AvSynMgr;AVSync Manager;c:\program files\Network Associates\VirusScan\Avsynmgr.exe [11/26/2001 4:51 PM 155665]
R2 prt1xw2k;SEM 11 Mbps Wireless Card NDIS Interface;c:\windows\system32\drivers\PRT1XW2K.SYS [2/24/2009 10:02 AM 13056]
R3 NaiFiltr;NaiFiltr;c:\program files\Common Files\Network Associates\McShield\naifiltr.sys [11/26/2001 4:51 PM 23856]
R3 SWLD23;Netopia 802.11b WLAN Cardbus Card;c:\windows\system32\drivers\swld23.sys [2/24/2009 10:00 AM 68224]
.
Contents of the 'Scheduled Tasks' folder

2009-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.mcneese.edu/
uInternet Settings,ProxyOverride =
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\MSU\Application Data\Mozilla\Firefox\Profiles\x73eq028.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.mcneese.edu/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit1319.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-15 06:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-08-15 6:53
ComboFix-quarantined-files.txt 2009-08-15 11:53

Pre-Run: 58,650,947,584 bytes free
Post-Run: 59,540,119,552 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

159 — E O F — 2009-07-30 02:30
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

Folder::
c:\documents and settings\All Users\Application Data\14529004

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
ComboFix 09-08-10.06 - dclaire 08/15/2009 7:48.2.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1006.420 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\MSU\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\14529004
c:\documents and settings\All Users\Application Data\14529004\14529004

.
((((((((((((((((((((((((( Files Created from 2009-07-15 to 2009-08-15 )))))))))))))))))))))))))))))))
.

2009-08-09 17:16 . 2009-08-09 17:16 ——– d—–w- c:\program files\Trend Micro
2009-08-01 14:22 . 2009-08-01 14:22 410984 —-a-w- c:\windows\system32\deploytk.dll
2009-08-01 14:21 . 2009-08-01 14:21 152576 —-a-w- c:\documents and settings\MSU\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-26 13:46 . 2009-07-26 13:46 ——– d—–w- c:\program files\MSECache
2009-07-23 17:15 . 2009-07-23 17:15 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-07-23 13:36 . 2009-07-23 13:36 ——– d—–w- c:\program files\iPod
2009-07-23 13:29 . 2009-07-23 13:29 75040 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-01 14:22 . 2009-06-13 12:21 335752 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-01 14:22 . 2005-06-10 02:18 ——– d—–w- c:\program files\Java
2009-07-26 15:24 . 2005-06-28 20:14 179744 —-a-w- c:\documents and settings\MSU\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-26 15:22 . 2009-07-26 15:22 204397 —-a-w- c:\windows\Fonts\AdobeFnt09.lst
2009-07-23 13:56 . 2009-05-10 10:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-07-23 13:42 . 2009-05-10 10:38 ——– d—–w- c:\program files\iTunes
2009-07-23 13:36 . 2009-05-10 10:35 ——– d—–w- c:\program files\Common Files\Apple
2009-07-23 13:34 . 2006-08-22 13:06 ——– d—–w- c:\program files\QuickTime
2009-07-13 21:58 . 2005-06-27 19:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-07-11 11:50 . 2009-06-13 12:21 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-07-09 17:16 . 2009-05-10 10:36 39424 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-09 17:16 . 2009-05-10 10:36 2060288 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-06-16 14:55 . 2004-08-11 22:00 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:55 . 2004-08-11 22:00 82432 —-a-w- c:\windows\system32\fontsub.dll
2009-06-13 12:21 . 2009-06-13 12:21 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-06-13 12:21 . 2009-06-13 12:21 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-03 19:27 . 2004-08-11 22:00 1290752 —-a-w- c:\windows\system32\quartz.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-08-21 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-08-21 118784]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-14 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-14 536576]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-01 148888]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-04 856064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-13 1948440]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="c:\windows\Installer\TSClientMsiTrans\tscuinst.vbs" [2006-11-07 12451]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-6-9 24576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-13 12:21 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\FileZilla\\filezilla.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSU-Jabber\\MSU-Jabber.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 8 (0x8)
"AllowInboundTimestampRequest"= 0 (0x0)
"AllowInboundMaskRequest"= 0 (0x0)
"AllowInboundRouterRequest"= 0 (0x0)
"AllowOutboundDestinationUnreachable"= 0 (0x0)
"AllowOutboundSourceQuench"= 0 (0x0)
"AllowOutboundParameterProblem"= 0 (0x0)
"AllowOutboundTimeExceeded"= 0 (0x0)
"AllowRedirect"= 0 (0x0)
"AllowOutboundPacketTooBig"= 0 (0x0)

R0 NaiFsRec;NaiFsRec;c:\windows\system32\drivers\naifsrec.sys [4/30/2001 4:51 AM 4512]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [6/13/2009 7:21 AM 335752]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [6/13/2009 7:21 AM 108552]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [6/13/2009 7:21 AM 298776]
R2 AvSynMgr;AVSync Manager;c:\program files\Network Associates\VirusScan\Avsynmgr.exe [11/26/2001 4:51 PM 155665]
R2 prt1xw2k;SEM 11 Mbps Wireless Card NDIS Interface;c:\windows\system32\drivers\PRT1XW2K.SYS [2/24/2009 10:02 AM 13056]
R3 NaiFiltr;NaiFiltr;c:\program files\Common Files\Network Associates\McShield\naifiltr.sys [11/26/2001 4:51 PM 23856]
R3 SWLD23;Netopia 802.11b WLAN Cardbus Card;c:\windows\system32\drivers\swld23.sys [2/24/2009 10:00 AM 68224]
.
Contents of the 'Scheduled Tasks' folder

2009-08-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.mcneese.edu/
uInternet Settings,ProxyOverride =
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\MSU\Application Data\Mozilla\Firefox\Profiles\x73eq028.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.mcneese.edu/
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit1319.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-15 07:52
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-08-15 7:54
ComboFix-quarantined-files.txt 2009-08-15 12:53
ComboFix2.txt 2009-08-15 11:53

Pre-Run: 59,540,840,448 bytes free
Post-Run: 59,536,138,240 bytes free

138 — E O F — 2009-07-30 02:30


((((((((((((((((((((((((((((((((((((( Next Log )))))))))))))))))))))))))))))))))))))))

Malwarebytes' Anti-Malware 1.40
Database version: 2629
Windows 5.1.2600 Service Pack 2

8/15/2009 8:08:58 AM
mbam-log-2009-08-15 (08-08-58).txt

Scan type: Quick Scan
Objects scanned: 102784
Time elapsed: 5 minute(s), 26 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\TypeLib\{df058c45-cd18-453e-8745-5a77f60722ab} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{b5a33c35-7298-4d15-8753-a2e851e2eab3} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f0d2b812-752d-4af1-a2fb-968c4d8446db} (Adware.Gdown) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e856b973-45fd-4559-8f82-eab539144667} (Adware.Gdown) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\GTDownDE_87.ocx (Adware.Gdown) -> Quarantined and deleted successfully.

((((((((((((((((((((((((((((((((((( Next Log ))))))))))))))))))))))))))))))))))))))

——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Saturday, August 15, 2009
Operating system: Microsoft Windows XP Professional Service Pack 2 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, August 15, 2009 14:52:41
Records in database: 2631373
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\

Scan statistics:
Objects scanned: 74251
Threats found: 2
Infected objects found: 4
Suspicious objects found: 0
Scan duration: 01:34:45


File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\SKYNETamhiybct.sys.vir Infected: Trojan.Win32.TDSS.amgd 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETohiwtosy.dll.vir Infected: Trojan.Win32.Small.bzc 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP0\A0000001.sys Infected: Trojan.Win32.TDSS.amgd 1
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP0\A0000003.dll Infected: Trojan.Win32.Small.bzc 1

Selected area has been scanned.
Hi, The items found are in quarantine, which we will be cleaning up shortly, please post a fresh DDS and Attach.txt and describe how the computer is running now and if there are any outstanding issues
YOU ARE A-W-E-S-O-M-E!!!!! My Google search this morning took me to the actual pages when I clicked on the result links. THANK YOU SOOOOOO MUCH!!!! What an annoying problem. Here are my latest scan results. DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 8:49:11.84 on Sun 08/16/2009 Internet Explorer: 7.0.5730.11 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1006.514 [GMT -5:00] AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Digital Line Detect\DLG.exe svchost.exe C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\Network Associates\VirusScan\Avconsol.exe C:\Program Files\Adobe\Adobe Version Cue CS2\data\database\bin\mysqld-nt.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\internet explorer\iexplore.exe C:\WINDOWS\system32\ctfmon.exe c:\progra~1\common~1\instal~1\update~1\isuspm.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe C:\Documents and Settings\MSU\Desktop\spyware issue 8-09\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://www.mcneese.edu/ uInternet Settings,ProxyOverride = BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\adobe acrobat 7.0\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: AcroIEToolbarHelper Class: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll EB: &Yahoo! Messenger: {4528bbe0-4e08-11d5-ad55-00010333d0ad} - c:\progra~1\yahoo!\common\yhexbmesus.dll uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Adobe Version Cue CS2] c:\program files\adobe\adobe version cue cs2\controlpanel\VersionCueCS2Tray.exe mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe IE: Convert link target to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\adobe\adobe acrobat 7.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\msu\applic~1\mozilla\firefox\profiles\x73eq028.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.mcneese.edu/ FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPJinit1319.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} ============= SERVICES / DRIVERS =============== R0 NaiFsRec;NaiFsRec;c:\windows\system32\drivers\naifsrec.sys [2001-4-30 4512] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-6-13 335752] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-6-13 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-6-13 108552] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-6-13 298776] R2 AvSynMgr;AVSync Manager;c:\program files\network associates\virusscan\Avsynmgr.exe [2001-11-26 155665] R2 prt1xw2k;SEM 11 Mbps Wireless Card NDIS Interface;c:\windows\system32\drivers\PRT1XW2K.SYS [2009-2-24 13056] R3 NaiFiltr;NaiFiltr;c:\program files\common files\network associates\mcshield\naifiltr.sys [2001-11-26 23856] R3 SWLD23;Netopia 802.11b WLAN Cardbus Card;c:\windows\system32\drivers\swld23.sys [2009-2-24 68224] S3 McShield;McShield;c:\program files\common files\network associates\mcshield\Mcshield.exe [2001-11-26 225403] =============== Created Last 30 ================ 2009-08-15 08:01 –d—– c:\docume~1\msu\applic~1\Malwarebytes 2009-08-15 08:01 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-08-15 08:01 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-08-15 08:01 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-08-15 08:01 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-08-15 07:47 –ds—- C:\Combo-Fix 2009-08-15 06:52 –d—– c:\windows\system32\dllcache\cache 2009-08-15 06:36 a-dshr– C:\cmdcons 2009-08-15 06:31 216,064 a——- c:\windows\PEV.exe 2009-08-15 06:31 161,792 a——- c:\windows\SWREG.exe 2009-08-15 06:31 98,816 a——- c:\windows\sed.exe 2009-08-09 12:16 –d—– c:\program files\Trend Micro 2009-08-01 09:22 410,984 a——- c:\windows\system32\deploytk.dll 2009-08-01 09:22 73,728 a——- c:\windows\system32\javacpl.cpl 2009-07-26 08:46 –d—– c:\program files\MSECache 2009-07-23 08:36 –d—– c:\program files\iPod ==================== Find3M ==================== 2009-08-01 09:22 335,752 a——- c:\windows\system32\drivers\avgldx86.sys 2009-07-09 12:16 2,060,288 a——- c:\windows\system32\usbaaplrc.dll 2009-07-09 12:16 39,424 a——- c:\windows\system32\drivers\usbaapl.sys 2009-06-16 09:55 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 09:55 82,432 a——- c:\windows\system32\fontsub.dll 2009-06-16 09:55 119,808 ——– c:\windows\system32\dllcache\t2embed.dll 2009-06-16 09:55 82,432 ——– c:\windows\system32\dllcache\fontsub.dll 2009-06-13 07:21 11,952 a——- c:\windows\system32\avgrsstx.dll 2009-06-03 14:27 1,290,752 a——- c:\windows\system32\quartz.dll 2009-06-03 14:27 1,290,752 ——– c:\windows\system32\dllcache\quartz.dll ============= FINISH: 8:49:41.36 ===============

Attachments:

Hi,

You are clean,

just some housekeeping to do now.

Please do the following:

Please download JavaRa to your desktop and unzip it to its own folder.
  • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions
  • Accept any prompts.
  • Open JavaRa.exe again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button.
  • Scroll down to the Java SE Runtime Environment (JRE) option.
  • Download and install the latest Java Runtime Environment (JRE) version for your computer.(version 6, update 16)


NEXT

Visit ADOBEand download the latest version of Acrobat Reader (version 9.1)
Having the latest updates ensures there are no security vulnerabilities in your system.


NEXT

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]


NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

Note: if any of the logs or programs that we used remain after using this tool - right click and delete them, except keep the MalwareBytes Program, update it and run it regularly.

NEXT

Below I have included a number of recommendations for how to protect your computer against malware infections.


  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • For Firefox, I highly recommend this add-on to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Thank you again! I've installed all of the utilities you've recommended. I'm looking forward to being able to access internet content again without all of the goofy re-directs. THANKS!!!!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI