This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google search page redirection, one user account can&#

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Did everything in the self-help post.
Ran ATFCleaner
Installed malwarebytes, ran and cleaned everything it found.
Have backup of registry with ERUNT

Like the Topic title says, one user accounts is notgood up, I can't set a background image and in the Start Menu for XP above the 'All Programs' where all the recently used items are it is blank. Also my NEC dvd writer isn't being detected by Nero anymore. It is there in the drive list and it can read dvds but whenever I put in a blank dvd to burn something, the drive changes to a cd drive and Nero doesn't see it.
I tried deleting it from the hardware list and let it reinstall but that did no good.
I also tried installing AShampoo Burning Studio 6 Free edition and it doesn't find my dvd writer either.

HiJack This log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:36:03 PM, on 8/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Prevx\prevx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\UAService7.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Prevx\prevx.exe
D:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
D:\Program Files\refreshLock\refreshlock\RefreshLock.exe
D:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CASIO\YouTube Uploader for CASIO\YStart.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - D:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RefreshLock] D:\Program Files\refreshLock\refreshlock\RefreshLock.exe
O4 - HKLM\..\Run: [AVG8_TRAY] D:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: YouTube Uploader for CASIO.lnk = C:\Program Files\CASIO\YouTube Uploader for CASIO\YStart.exe
O8 - Extra context menu item: &Clean Traces - d:\Program Files\DAP\Privacy Package\dapcleanerie.htm
O8 - Extra context menu item: &Download with &DAP - D:\Program Files\DAP\dapextie.htm
O8 - Extra context menu item: Download &all with DAP - D:\Program Files\DAP\dapextie2.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ActiveGS.cab - http://www.virtualapple.org/activegs.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} (Auctiva Image Uploader Control) - http://www.auctiva.com/Aurigma/ImageUploader55.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/…can8/oscan8.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - D:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: CSIScanner - Prevx - C:\Program Files\Prevx\prevx.exe
O23 - Service: Contivity VPN Service (ExtranetAccess) - Nortel Networks NA, Inc. - C:\Program Files\Xerox External Access Network\Extranet_serv.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\WINDOWS\system32\UAService7.exe

–
End of file - 8651 bytes


******* THIS IS BEFORE LOG FOR MALWAREBYTES****** I ran it after this and it came up with nothing detected.

Malwarebytes' Anti-Malware 1.40
Database version: 2637
Windows 5.1.2600 Service Pack 2

8/16/2009 10:29:27 PM
mbam-log-2009-08-16 (22-29-27).txt

Scan type: Quick Scan
Objects scanned: 98693
Time elapsed: 2 minute(s), 34 second(s)

Memory Processes Infected: 1
Memory Modules Infected: 1
Registry Keys Infected: 22
Registry Values Infected: 14
Registry Data Items Infected: 9
Folders Infected: 0
Files Infected: 16

Memory Processes Infected:
C:\WINDOWS\system32\sofatnet.exe (Backdoor.Bot) -> Unloaded process successfully.

Memory Modules Infected:
c:\WINDOWS\system32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\evdoserver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sofatnet (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e24211b3-a78a-c6a9-d317-70979ace5058} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f54af7de-6038-4026-8433-cc30e3f17212} (Rogue.ASC-AntiSpyware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{248dd890-bb45-11cf-9abc-0080c7e7b78d} (Worm.Nyxem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{248dd892-bb45-11cf-9abc-0080c7e7b78d} (Worm.Nyxem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{248dd893-bb45-11cf-9abc-0080c7e7b78d} (Worm.Nyxem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{248dd896-bb45-11cf-9abc-0080c7e7b78d} (Worm.Nyxem) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{248dd897-bb45-11cf-9abc-0080c7e7b78d} (Worm.Nyxem) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Monopod (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\NordBull (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\Root\LEGACY_ANTIPPRO2009_12 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\AntipPro2009_12 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\netcard (Rootkit.Agent) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\chris (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\BuildW (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\FirstInstallFlag (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\guid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\i (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mEv (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\mso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\udso (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Ulrn (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Update (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateNew (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.bat\(default) (Hijacked.BatFile) -> Bad: (csfile) Good: (batfile) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\.com\(default) (Hijacked.ComFile) -> Bad: (csfile) Good: (comfile) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\evdoserver.dll (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\sofatnet.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Chris\Chris.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\dvdpaly.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\MSWINSCK.OCX (Worm.Nyxem) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wiwow64.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bennuar.old (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\bincd32.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\FInstall.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\onhelp.htm (Rogue.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sonhelp.htm (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\sysnet.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wiawow32.sys (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\ppp3.dat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\ppp4.dat (Malware.Trace) -> Quarantined and deleted successfully.
Hello.

Please run DDS followed by GMER.

Download and run DDS

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results soon.
  • Follow the instructions that pop up for posting the results and then click Ok.
  • The black and message box window shall then disappear.
  • Please save both log files on your desktop and post the DDS.txt and zip up and attach Attach.txt as instructed.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

Download and Run Scan with GMER

We will use GMER to scan for rootkits. This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop. Unzip/extract the file to its own folder. (Click here for information on how to do this if not sure. Win 2000 users click here.

  • Close any and all open programs, as this process may crash your computer.
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • When you have done this, close all running programs.
    There is a small chance this application may crash your computer so save any work you have open.
  • Double-click on Gmer.exe to start the program. Right-click and select Run As Administrator… if you are using Vista
  • Allow the gmer.sys driver to load if asked.
    If it detects rootkit activity, you will receive a prompt (refer below) to run a full scan. Click NO..
    [external image: Posted Image]

  • In the right panel, you will see several boxes that have been checked. Please UNCHECK the following:
    • Sections
    • IAT/EAT
    • Registry
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show all (Don't miss this one!)
  • Click on [external image: Posted Image] and wait for the scan to finish.
  • If you see a rootkit warning window, click OK.
  • Push [external image: Posted Image] and save the logfile to your desktop.
  • Copy and Paste the contents of that file in your next post.

If GMER doesn't work in Normal Mode try running it in Safe Mode

Note: Do Not run any program while GMER is running
*Note*: Rootkit scans often produce false positives. Do NOT take any actions on "<— ROOKIT" entries

Post back with both logs in your next reply. You may attach the GMER log, if it's too large to post into one reply.

Thanks.

With Regards,
Extremeboy
Thanks a lot for your help!

After doing the above I ran the Kaspersky On-line Scanner and it did not find anything. I also ran ComboFix and the log is at the bottom.

I think my PC is OK now, at least I'm not getting redirected anymore and my DVD drive can burn again.
What scans should I run to make sure I'm OK.

Thanks
Chris


**************************************** Here is the DDS.txt ********************************************************************************
**


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 19:27:21.09 on Mon 08/17/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_07
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.462 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
C:\WINDOWS\system32\svchost -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Prevx\prevx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\UAService7.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Prevx\prevx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
D:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
D:\Program Files\refreshLock\refreshlock\RefreshLock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\CASIO\YouTube Uploader for CASIO\YStart.exe
D:\Program Files\zsnes\zsnesw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
C:\WINDOWS\system32\rundll32.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\My Documents\Downloads\dds.scr
C:\WINDOWS\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mSearchAssistant = hxxp://www.google.com
mWinlogon: Userinit=c:\windows\system32\userinit.exe,c:\windows\system32\sdra64.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - d:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\progra~1\spybot~1\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [BitTorrent DNA] "c:\program files\dna\btdna.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Google Update] "c:\documents and settings\chris\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
uRun: [autochk] rundll32.exe c:\docume~1\chris\protect.dll,_IWMPEvents@16
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0_07\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [RefreshLock] d:\program files\refreshlock\refreshlock\RefreshLock.exe
mRun: [AVG8_TRAY] d:\progra~1\avg\avg8\avgtray.exe
mRun: [autochk] rundll32.exe c:\windows\system32\autochk.dll,_IWMPEvents@16
dRun: [autochk] rundll32.exe c:\docume~1\locals~1\protect.dll,_IWMPEvents@16
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\documents and settings\chris\start menu\programs\startup\ChkDisk.dll
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\chkdisk.lnk - c:\windows\system32\rundll32.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - d:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\youtub~1.lnk - c:\program files\casio\youtube uploader for casio\YStart.exe
IE: &Clean Traces - d:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - d:\program files\dap\dapextie.htm
IE: Download &all with DAP - d:\program files\dap\dapextie2.htm
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\progra~1\spybot~1\SDHelper.dll
DPF: ActiveGS.cab - hxxp://www.virtualapple.org/activegs.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - d:\program files\avg\avg8\avgpp.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - d:\progra~1\dap\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - d:\progra~1\dap\dapie.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\wc565qf3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: d:\program files\avg\avg8\firefox\components\avgssff.dll
FF - component: d:\program files\dap\dapfirefox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\chris\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: d:\program files\adobe\reader 9.0\reader\browser\nppdf32.dll
FF - plugin: d:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: d:\program files\divx\divx web player\npdivx32.dll
FF - plugin: d:\program files\itunes\mozilla plugins\npitunes.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 pxscan;pxscan;c:\windows\system32\drivers\pxscan.sys [2009-8-16 22024]
R0 pxsec;pxsec;c:\windows\system32\drivers\pxsec.sys [2009-8-16 27656]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-7 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-2-5 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-7 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\avg\avg8\avgemc.exe [2009-8-7 908056]
R2 avg8wd;AVG Free8 WatchDog;d:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-7 297752]
R2 CSIScanner;CSIScanner;c:\program files\prevx\prevx.exe [2009-8-16 4368952]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2008-2-7 26137]
R3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [2009-7-2 7548]
S2 Ias;Microsoft Security Services Management;c:\windows\system32\svchost.exe -k netsvcs [2004-8-4 14336]
S2 xaedstonrq;xaedstonrq;\??\c:\windows\system32\drivers\jbttcxlhuvpxcnl.sys –> c:\windows\system32\drivers\jbttcxlhuvpxcnl.sys [?]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\xerox external access network\Extranet_serv.exe [2008-2-7 811008]
S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2008-2-7 155152]
S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?]

=============== Created Last 30 ================

2009-08-17 07:26 –dsh— c:\windows\system32\lowsec
2009-08-17 07:21 20,992 a–sh— c:\documents and settings\chris\protect.dll
2009-08-17 07:21 20,992 a–sh— c:\windows\system32\autochk.dll
2009-08-16 22:24 –d—– c:\docume~1\chris\applic~1\Malwarebytes
2009-08-16 22:24 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-16 22:24 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-16 22:24 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-16 22:09 –d—– c:\program files\Trend Micro
2009-08-16 18:21 27,656 a——- c:\windows\system32\drivers\pxsec.sys
2009-08-16 18:21 22,024 a——- c:\windows\system32\drivers\pxscan.sys
2009-08-16 18:21 –d—– c:\program files\Prevx
2009-08-16 18:21 –d—– c:\docume~1\alluse~1\applic~1\PrevxCSI
2009-08-16 15:50 –d—– c:\docume~1\chris\applic~1\Ashampoo
2009-08-16 15:50 –d—– c:\docume~1\alluse~1\applic~1\ashampoo
2009-08-15 23:17 362 a——- c:\windows\Shortcut to WINDOWS.lnk
2009-08-15 22:59 2,359,350 a——- C:\viruses.bmp
2009-08-07 20:31 –d-h— C:\$AVG8.VAULT$
2009-08-07 16:29 –d—– c:\program files\DAEMON Tools
2009-08-07 08:41 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-07 08:41 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-07 08:41 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-07 08:41 –d—– c:\windows\system32\drivers\Avg
2009-08-07 08:40 –d—– c:\program files\AVG
2009-08-07 08:40 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-08-07 08:37 –d—– c:\docume~1\chris\applic~1\AVG8
2009-08-05 21:33 526 a——- c:\windows\wininit.ini
2009-08-01 12:53 20,976 a——- c:\windows\system\CTL3D.DLL

==================== Find3M ====================

2009-08-07 16:09 107,888 a——- c:\windows\system32\CmdLineExt.dll
2008-11-06 23:25 87,608 a——- c:\docume~1\chris\applic~1\inst.exe
2008-11-06 23:25 47,360 a——- c:\docume~1\chris\applic~1\pcouffin.sys

============= FINISH: 19:29:08.45 ===============




****************************************Here is gmer log *********************************************************************




GMER 1.0.15.15077 [j9ztm8lv.exe] - http://www.gmer.net
Rootkit scan 2009-08-17 19:43:59
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

Code 86EBE0F0 ZwEnumerateKey
Code 86EB8E98 ZwFlushInstructionCache
Code 86F3DDEE ZwSaveKey
Code 86F38056 ZwSaveKeyEx
Code 86EC024E IofCallDriver
Code 86EBF9E6 IofCompleteRequest

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 871651E8
Device \FileSystem\Fastfat \FatCdrom 863AE1E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C1B2312C-FCD7-431F-8CC3-25B48C597C95} 863901E8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbohci \Device\USBPDO-0 86F971E8
Device \Driver\usbehci \Device\USBPDO-1 86F661E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 871671E8
Device \Driver\dmio \Device\DmControl\DmConfig 871671E8
Device \Driver\dmio \Device\DmControl\DmPnP 871671E8
Device \Driver\dmio \Device\DmControl\DmInfo 871671E8

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 871D21E8
Device \Driver\nvata \Device\00000071 871661E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 871D21E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 871D21E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 871D21E8
Device \Driver\usbstor \Device\00000080 871141E8
Device \Driver\usbstor \Device\00000081 871141E8
Device \Driver\usbstor \Device\00000082 871141E8
Device \Driver\usbstor \Device\00000083 871141E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 863901E8
Device \Driver\PCI_NTPNP9564 \Device\0000004b sptd.sys
Device \Driver\NetBT \Device\NetbiosSmb 863901E8
Device \Driver\usbstor \Device\00000079 871141E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{AF92FFB7-0589-4498-983A-EC7A422555BD} 863901E8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbohci \Device\USBFDO-0 86F971E8
Device \Driver\nvata \Device\0000006c 871661E8
Device \Driver\nvata \Device\0000006d 871661E8
Device \Driver\usbehci \Device\USBFDO-1 86F661E8
Device \Driver\nvata \Device\NvAta0 871661E8
Device \Driver\nvata \Device\0000006e 871661E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86477790
Device \Driver\nvata \Device\NvAta1 871661E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86477790
Device \Driver\nvata \Device\NvAta2 871661E8
Device \Driver\Ftdisk \Device\FtControl 871D21E8
Device \Driver\azm2kun6 \Device\Scsi\azm2kun61Port3Path0Target0Lun0 86E991E8
Device \Driver\azm2kun6 \Device\Scsi\azm2kun61 86E991E8
Device \FileSystem\Fastfat \Fat 863AE1E8

AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device \FileSystem\Cdfs \Cdfs 86DDD610

—- Services - GMER 1.0.15 —-

Service C:\WINDOWS\system32\drivers\vsfocexvkbqxyl.sys (*** hidden *** ) [SYSTEM] vsfocelvcgwibo <– ROOTKIT !!!

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\vsfocexvkbqxyl.sys 68096 bytes <– ROOTKIT !!!
File C:\WINDOWS\system32\sdra64.exe 269824 bytes executable
File C:\WINDOWS\system32\vsfoceballhtpj.dat 37442 bytes
File C:\WINDOWS\system32\vsfoceboqvnliq.dll 19456 bytes
File C:\WINDOWS\system32\vsfocejdakatyi.dat 91 bytes
File C:\WINDOWS\system32\vsfoceqgkvxoye.dll 42496 bytes
File C:\WINDOWS\Temp\vsfocechamydfanm.tmp 91 bytes
File C:\WINDOWS\Temp\vsfocenmqqxbeorq.tmp 91 bytes

—- EOF - GMER 1.0.15 —-


************************************ COMBOX FIX LOG ********************************************

ComboFix 09-08-10.06 - Chris 08/18/2009 0:50.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.682 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Chris\Application Data\inst.exe
c:\documents and settings\Chris\autorun.inf
c:\documents and settings\Chris\protect.dll
c:\documents and settings\Chris\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\Chris\Start Menu\Programs\Startup\ChkDisk.lnk
c:\documents and settings\LocalService\protect.dll
c:\windows\Fonts\mlog
c:\windows\Install.txt
c:\windows\system32\autochk.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\drivers\vsfocexvkbqxyl.sys
c:\windows\system32\Ijl11.dll
c:\windows\system32\Install.txt
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\sdra64.exe
c:\windows\system32\vsfoceballhtpj.dat
c:\windows\system32\vsfoceboqvnliq.dll
c:\windows\system32\vsfocejdakatyi.dat
c:\windows\system32\vsfoceqgkvxoye.dll
c:\windows\wiaserviv.log

Infected copy of c:\windows\system32\winlogon.exe was found and disinfected
Restored copy from - c:\windows\system32\winlogon.bak

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_vsfocelvcgwibo
——-\Legacy_vsfocelvcgwibo
——-\Legacy_6TO4
——-\Legacy_IAS
——-\Legacy_NETCARD
——-\Service_6to4
——-\Service_Ias


((((((((((((((((((((((((( Files Created from 2009-07-18 to 2009-08-18 )))))))))))))))))))))))))))))))
.

2009-08-17 02:24 . 2009-08-17 02:24 ——– d—–w- c:\documents and settings\Chris\Application Data\Malwarebytes
2009-08-17 02:24 . 2009-08-03 17:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-17 02:24 . 2009-08-17 02:24 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Malwarebytes
2009-08-17 02:24 . 2009-08-03 17:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-17 02:16 . 2009-08-17 02:17 ——– d—–w- c:\program files\ERUNT
2009-08-17 02:09 . 2009-08-17 02:09 ——– d—–w- c:\program files\Trend Micro
2009-08-16 19:50 . 2009-08-16 19:50 ——– d—–w- c:\documents and settings\Chris\Application Data\Ashampoo
2009-08-16 19:50 . 2009-08-16 19:50 ——– d—–w- c:\documents and settings\Chris\Local Settings\Application Data\ashampoo
2009-08-16 19:50 . 2009-08-16 19:50 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\ashampoo
2009-08-08 00:31 . 2009-08-16 03:40 ——– d–h–w- C:\$AVG8.VAULT$
2009-08-07 20:29 . 2009-08-07 20:29 ——– d—–w- c:\program files\DAEMON Tools
2009-08-07 14:36 . 2009-08-07 14:36 ——– d—–w- c:\documents and settings\Amy\Local Settings\Application Data\Unity
2009-08-07 12:41 . 2009-08-07 12:41 335240 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-08-07 12:41 . 2009-08-07 12:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll
2009-08-07 12:41 . 2009-08-07 12:41 108552 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-08-07 12:41 . 2009-08-18 04:21 ——– d—–w- c:\windows\system32\drivers\Avg
2009-08-07 12:40 . 2009-08-16 03:25 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\avg8
2009-08-07 12:40 . 2009-08-07 12:40 ——– d—–w- c:\program files\AVG
2009-08-07 12:37 . 2009-08-07 12:37 ——– d—–w- c:\documents and settings\Chris\Application Data\AVG8
2009-08-07 02:49 . 2009-08-07 02:49 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Apple Computer
2009-08-07 02:49 . 2009-08-07 02:49 ——– d—–w- c:\documents and settings\LocalService\Application Data\Apple Computer
2009-08-07 02:30 . 2009-08-07 02:59 ——– d—–w- c:\windows\BDOSCAN8
2009-08-01 16:53 . 1994-09-16 18:00 20976 —-a-w- c:\windows\system\CTL3D.DLL
2009-08-01 16:53 . 2009-08-01 16:53 ——– d—–w- c:\documents and settings\Amy\WINDOWS
2009-07-19 22:59 . 2009-08-04 01:18 ——– d—–w- c:\documents and settings\Chris\Local Settings\Application Data\Temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-17 04:48 . 2008-02-02 05:12 ——– d—a-w- c:\docume~1\ALLUSE~1\APPLIC~1\TEMP
2009-08-16 20:39 . 2008-02-02 05:18 ——– d—–w- c:\docume~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2009-08-07 20:09 . 2008-02-02 03:43 107888 —-a-w- c:\windows\system32\CmdLineExt.dll
2009-08-07 12:41 . 2008-02-06 02:08 27784 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-08-06 11:36 . 2008-02-02 03:10 97144 —-a-w- c:\documents and settings\Chris\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-06 03:13 . 2008-02-02 02:45 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-06 02:59 . 2008-02-08 02:59 ——– d—–w- c:\documents and settings\Chris\Application Data\uTorrent
2009-08-01 16:55 . 2008-03-08 22:40 482 —-a-w- c:\windows\EReg077.dat
2009-07-02 18:59 . 2009-07-02 18:59 ——– d—–w- c:\program files\Game Elements
2009-07-02 18:48 . 2009-07-02 18:48 ——– d—–w- c:\program files\Unity
2009-07-01 12:26 . 2008-08-19 00:14 ——– d—–w- c:\program files\Microsoft Silverlight
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Google Update"="c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-04 133104]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-09-18 171464]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"zBrowser Launcher"="c:\program files\Logitech\iTouch\iTouch.exe" [2004-03-18 892928]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-10-11 7286784]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-10-11 86016]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-09-24 49152]
"iTunesHelper"="d:\program files\iTunes\iTunesHelper.exe" [2007-09-26 267064]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RefreshLock"="d:\program files\refreshLock\refreshlock\RefreshLock.exe" [2003-10-16 193536]
"AVG8_TRAY"="d:\progra~1\AVG\AVG8\avgtray.exe" [2009-08-17 2007832]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 158208]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2004-12-22 77824]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2004-03-03 19968]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2005-10-11 1519616]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" - c:\windows\system32\narrator.exe [2004-08-04 53760]

c:\documents and settings\Chris\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\docume~1\ALLUSE~1\STARTM~1\Programs\Startup\
Microsoft Office.lnk - d:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
YouTube Uploader for CASIO.lnk - c:\program files\CASIO\YouTube Uploader for CASIO\YStart.exe [2007-6-11 79488]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-07 12:41 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Chris^Start Menu^Programs^Startup^ChkDisk.dll]
path=c:\documents and settings\Chris\Start Menu\Programs\Startup\ChkDisk.dll
backup=c:\windows\pss\ChkDisk.dllStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Chris^Start Menu^Programs^Startup^ChkDisk.lnk]
path=c:\documents and settings\Chris\Start Menu\Programs\Startup\ChkDisk.lnk
backup=c:\windows\pss\ChkDisk.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\InterVideo\\DVD7\\WinDVD.exe"=
"d:\\Program Files\\DAP\\DAP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Xerox External Access Network\\Extranet_serv.exe"=
"d:\\Program Files\\Halo\\halo.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\iTunes\\iTunes.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"d:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

R3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [7/2/2009 2:59 PM 7548]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [8/7/2009 8:41 AM 335240]
S1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [8/7/2009 8:41 AM 108552]
S2 xaedstonrq;xaedstonrq;\??\c:\windows\system32\drivers\jbttcxlhuvpxcnl.sys –> c:\windows\system32\drivers\jbttcxlhuvpxcnl.sys [?]
S3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2/7/2008 11:05 PM 26137]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\Xerox External Access Network\Extranet_serv.exe [2/7/2008 11:05 PM 811008]
S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2/7/2008 11:05 PM 155152]
S4 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\AVG\AVG8\avgemc.exe [8/7/2009 8:40 AM 908056]
S4 avg8wd;AVG Free8 WatchDog;d:\progra~1\AVG\AVG8\avgwdsvc.exe [8/7/2009 8:40 AM 297752]
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BitTorrent DNA - c:\program files\DNA\btdna.exe
HKU-Default-Run-autochk - c:\docume~1\LOCALS~1\protect.dll


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
IE: &Clean Traces - d:\program files\DAP\Privacy Package\dapcleanerie.htm
IE: &Download with &DAP - d:\program files\DAP\dapextie.htm
IE: Download &all with DAP - d:\program files\DAP\dapextie2.htm
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - d:\progra~1\DAP\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - d:\progra~1\DAP\dapie.dll
DPF: ActiveGS.cab - hxxp://www.virtualapple.org/activegs.cab
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
FF - ProfilePath - c:\docume~1\Chris\APPLIC~1\Mozilla\Firefox\Profiles\wc565qf3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: d:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: d:\program files\DAP\DAPFireFox\components\DAPFireFox.dll
FF - plugin: c:\documents and settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: d:\program files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll
FF - plugin: d:\program files\DivX\DivX Content Uploader\npUpload.dll
FF - plugin: d:\program files\DivX\DivX Web Player\npdivx32.dll
FF - plugin: d:\program files\iTunes\Mozilla Plugins\npitunes.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-18 01:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-08-18 1:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-18 05:07

Pre-Run: 1,577,984,000 bytes free
Post-Run: 1,551,376,384 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
c:\myfreespire.bin="Freespire Linux"

Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
201 — E O F — 2008-04-18 00:16


Thanks again for your HELP!

Chris

Attachments:

  • [attachment removed: Attach.zip]
Hello.

One of the infection was a backdoor/rootkit infection. Combofix removed it however, but you should still read what it does and act accordingly.

Rootkits and backdoor Trojans are very dangerous because they use advanced techniques (backdoors) as a means of accessing a computer system that bypasses security mechanisms and steal sensitive information which they send back to the hacker. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. Remote attackers use backdoor Trojans and rootkits as part of an exploit to gain unauthorized access to a computer and take control of it without your knowledge.

If your computer was used for online banking, has credit card information or other sensitive data on it, you should immediately disconnect from the Internet until your system is cleaned. All passwords should be changed immediately to include those used for banking, email, eBay, paypal and online forums. You should consider them to be compromised. You should change each password by using a different computer and not the infected one. If not, an attacker may get the new passwords and transaction information. If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connect again. Banking and credit card institutions should be notified of the possible security breach. Because your computer was compromised please read How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

Although the rootkit has been identified and may be removed, your PC has likely been compromised and there is no way to be sure the computer can ever be trusted again. It is dangerous and incorrect to assume that because this malware has been removed the computer is now secure. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired. The malware may leave so many remnants behind that security tools cannot find them. Many experts in the security community believe that once infected with this type of malware, the best course of action is to wipe the drive clean, reformat and reinstall the OS. Please read: Should you decide not to follow that advice, we will do our best to help clean the computer of any infections but we cannot guarantee it to be trustworthy or that the removal will be successful. Tell me what you want to do.

–

Please update Java.

Update Java to Version 6 Update 16

Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) Version 6 and save it to your desktop.
  • Look for "Java Runtime Environment (JRE)" JRE 6 Update 16.
  • Click the Download button to the right.
  • Select your Platform: "Windows".
  • Select your Language: "Multi-language".
  • Read the License Agreement, and then check the box that says: "Accept License Agreement".
  • Click Continue and the page will refresh.
  • Under Required Files, check the box for Windows Offline Installation, click the link below it and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button and follow the onscreen instructions for the Java uninstaller.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u16-windows-i586.exe to install the newest version.
– If using Windows Vista and the installer refuses to launch due to insufficient user permissions, then Run As Administrator.
– If you choose to update via the Java applet in Control Panel, uncheck the option to install the Toolbar unless you want it.
– The uninstaller incorporated in this release removes previous Updates 10 and above, but does not remove older versions, so they still need to be removed manually.


Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click Ok and reboot your computer.

Please run another scan, since you ran the Kaspersky scan before you ran Combofix.

Run ESET Online Scan

  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]
You can refer to this animation by neomage if needed.

–

Please take a new DDS run afterwards and post back with the logs. Then, run GMER again like last time and post back with the GMER log as well.

For your next reply I would like to see:
-ESET Scan log
-The DDS logs
-New GMER scan log

Thanks.

With Regards,
Extremeboy
Hello again,
Thanks for the reply. So if I go the reinstall route, I assume I can save data to use after I reinstall like game state data, pictures, music, and the like. I would need to reinstall windows and all my apps right?

The ESET hung at 11%. It found 2 infections:
Win32/Bagle.gen.zip Worm
Win32/Bagle.gen.zip Worm

I ran ESET after DDS and GMER because it wasn't working before. I need to get to work, I'll try ESET again when I get home.

THANKS!

Here are the logs:
********************************************** ESET: ***************************************************
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DNSFlushcws1.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudAntivirusPlus4.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined


********************************************** DDS: ***************************************************


DDS (Ver_09-07-30.01) - NTFSx86
Run by [removed] at 8:24:13.57 on Wed 08/19/2009
Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_14
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1023.496 [GMT -4:00]

AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
D:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\UAService7.exe
D:\PROGRA~1\AVG\AVG8\avgemc.exe
D:\PROGRA~1\AVG\AVG8\avgrsx.exe
D:\PROGRA~1\AVG\AVG8\avgnsx.exe
D:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Logitech\iTouch\iTouch.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\refreshLock\refreshlock\RefreshLock.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Update\1.2.183.7\GoogleCrashHandler.exe
C:\Program Files\CASIO\YouTube Uploader for CASIO\YStart.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Chris\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\Chris\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - d:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - d:\progra~1\spybot~1\SDHelper.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Google Update] "c:\documents and settings\chris\local settings\application data\google\update\GoogleUpdate.exe" /c
uRun: [DAEMON Tools] "c:\program files\daemon tools\daemon.exe" -lang 1033
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SoundMan] SOUNDMAN.EXE
mRun: [zBrowser Launcher] c:\program files\logitech\itouch\iTouch.exe
mRun: [Logitech Utility] Logi_MwX.Exe
mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun: [nwiz] nwiz.exe /install
mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [iTunesHelper] "d:\program files\itunes\iTunesHelper.exe"
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [Adobe Reader Speed Launcher] "d:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [RefreshLock] d:\program files\refreshlock\refreshlock\RefreshLock.exe
mRun: [AVG8_TRAY] d:\progra~1\avg\avg8\avgtray.exe
dRunOnce: [RunNarrator] Narrator.exe
StartupFolder: c:\docume~1\chris\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - d:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\youtub~1.lnk - c:\program files\casio\youtube uploader for casio\YStart.exe
IE: &Clean Traces - d:\program files\dap\privacy package\dapcleanerie.htm
IE: &Download with &DAP - d:\program files\dap\dapextie.htm
IE: Download &all with DAP - d:\program files\dap\dapextie2.htm
IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - d:\progra~1\spybot~1\SDHelper.dll
DPF: ActiveGS.cab - hxxp://www.virtualapple.org/activegs.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {38AB0814-B09B-4378-9940-14A19638C3C2} - hxxp://www.auctiva.com/Aurigma/ImageUploader55.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_14-windows-i586.cab
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - d:\program files\avg\avg8\avgpp.dll
Name-Space Handler: ftp\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - d:\progra~1\dap\dapie.dll
Name-Space Handler: http\ZDA - {5BFA1DAF-5EDC-11D2-959E-00C00C02DA5E} - d:\progra~1\dap\dapie.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\wc565qf3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - component: d:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\chris\local settings\application data\google\update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\unity\webplayer\loader\npUnity3D32.dll
FF - plugin: d:\program files\adobe\reader 9.0\reader\browser\nppdf32.dll
FF - plugin: d:\program files\divx\divx content uploader\npUpload.dll
FF - plugin: d:\program files\divx\divx web player\npdivx32.dll
FF - plugin: d:\program files\itunes\mozilla plugins\npitunes.dll
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - d:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-8-7 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2008-2-5 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-8-7 108552]
R2 avg8emc;AVG Free8 E-mail Scanner;d:\progra~1\avg\avg8\avgemc.exe [2009-8-7 908056]
R2 avg8wd;AVG Free8 WatchDog;d:\progra~1\avg\avg8\avgwdsvc.exe [2009-8-7 297752]
R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\drivers\eacfilt.sys [2008-2-7 26137]
R3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [2009-7-2 7548]
S2 xaedstonrq;xaedstonrq;\??\c:\windows\system32\drivers\jbttcxlhuvpxcnl.sys –> c:\windows\system32\drivers\jbttcxlhuvpxcnl.sys [?]
S3 ExtranetAccess;Contivity VPN Service;c:\program files\xerox external access network\Extranet_serv.exe [2008-2-7 811008]
S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2008-2-7 155152]

=============== Created Last 30 ================

2009-08-19 08:20 –d-h— c:\windows\PIF
2009-08-19 08:17 410,984 a——- c:\windows\system32\deploytk.dll
2009-08-18 19:08 –d—– c:\program files\ESET
2009-08-18 02:08 502,272 a——- c:\windows\system32\winlogonYES.exeYES
2009-08-18 02:01 502,272 ——– c:\windows\system32\winlogon.exe
2009-08-18 01:06 -cd—– c:\windows\system32\dllcache\cache
2009-08-18 00:38 a-dshr– C:\cmdcons
2009-08-18 00:35 216,064 a——- c:\windows\PEV.exe
2009-08-18 00:35 161,792 a——- c:\windows\SWREG.exe
2009-08-18 00:35 98,816 a——- c:\windows\sed.exe
2009-08-18 00:35 –ds—- C:\ComboFix
2009-08-18 00:25 –d—– c:\windows\pss
2009-08-16 22:24 –d—– c:\docume~1\chris\applic~1\Malwarebytes
2009-08-16 22:24 38,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-16 22:24 19,096 a——- c:\windows\system32\drivers\mbam.sys
2009-08-16 22:24 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-08-16 22:09 –d—– c:\program files\Trend Micro
2009-08-16 15:50 –d—– c:\docume~1\chris\applic~1\Ashampoo
2009-08-16 15:50 –d—– c:\docume~1\alluse~1\applic~1\ashampoo
2009-08-15 23:17 362 a——- c:\windows\Shortcut to WINDOWS.lnk
2009-08-15 22:59 2,359,350 a——- C:\virusesblah.bmp
2009-08-07 20:31 –d-h— C:\$AVG8.VAULT$
2009-08-07 16:29 –d—– c:\program files\DAEMON Tools
2009-08-07 08:41 335,240 a——- c:\windows\system32\drivers\avgldx86.sys
2009-08-07 08:41 108,552 a——- c:\windows\system32\drivers\avgtdix.sys
2009-08-07 08:41 11,952 a——- c:\windows\system32\avgrsstx.dll
2009-08-07 08:41 –d—– c:\windows\system32\drivers\Avg
2009-08-07 08:40 –d—– c:\program files\AVG
2009-08-07 08:40 –d—– c:\docume~1\alluse~1\applic~1\avg8
2009-08-07 08:37 –d—– c:\docume~1\chris\applic~1\AVG8
2009-08-05 21:33 526 a——- c:\windows\wininit.ini
2009-08-01 12:53 20,976 a——- c:\windows\system\CTL3D.DLL

==================== Find3M ====================

2009-08-07 16:09 107,888 a——- c:\windows\system32\CmdLineExt.dll
2008-11-06 23:25 47,360 a——- c:\docume~1\chris\applic~1\pcouffin.sys

============= FINISH: 8:24:34.26 ===============



********************************************** GMER: ***************************************************


GMER 1.0.15.15077 [j9ztm8lv.exe] - http://www.gmer.net
Rootkit scan 2009-08-19 08:53:15
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.15 —-

SSDT sptd.sys ZwCreateKey [0xF73320D0]
SSDT sptd.sys ZwEnumerateKey [0xF7337FB2]
SSDT sptd.sys ZwEnumerateValueKey [0xF7338340]
SSDT sptd.sys ZwOpenKey [0xF73320B0]
SSDT sptd.sys ZwQueryKey [0xF7338418]
SSDT sptd.sys ZwQueryValueKey [0xF7338298]
SSDT sptd.sys ZwSetValueKey [0xF73384AA]

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 871D11E8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C1B2312C-FCD7-431F-8CC3-25B48C597C95} 865A41E8

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbohci \Device\USBPDO-0 870801E8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 871D31E8
Device \Driver\dmio \Device\DmControl\DmConfig 871D31E8
Device \Driver\dmio \Device\DmControl\DmPnP 871D31E8
Device \Driver\dmio \Device\DmControl\DmInfo 871D31E8
Device \Driver\usbehci \Device\USBPDO-1 870D91E8

AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\Ftdisk \Device\HarddiskVolume1 871661E8
Device \Driver\Ftdisk \Device\HarddiskVolume2 871661E8
Device \Driver\Cdrom \Device\CdRom0 86FD71E8
Device \Driver\nvata \Device\00000072 871D21E8
Device \Driver\Ftdisk \Device\HarddiskVolume3 871661E8
Device \Driver\Cdrom \Device\CdRom1 86FD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume4 871661E8
Device \Driver\Cdrom \Device\CdRom2 86FD71E8
Device \Driver\Ftdisk \Device\HarddiskVolume5 871661E8
Device \Driver\NetBT \Device\NetBt_Wins_Export 865A41E8
Device \Driver\NetBT \Device\NetbiosSmb 865A41E8
Device \Driver\PCI_NTPNP8204 \Device\0000004c sptd.sys
Device \Driver\NetBT \Device\NetBT_Tcpip_{AF92FFB7-0589-4498-983A-EC7A422555BD} 865A41E8

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\usbohci \Device\USBFDO-0 870801E8
Device \Driver\nvata \Device\0000006d 871D21E8
Device \Driver\usbstor \Device\0000007a 865921E8
Device \Driver\usbehci \Device\USBFDO-1 870D91E8
Device \Driver\nvata \Device\NvAta0 871D21E8
Device \Driver\nvata \Device\0000006e 871D21E8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 865941E8
Device \Driver\usbstor \Device\0000007b 865921E8
Device \Driver\nvata \Device\NvAta1 871D21E8
Device \FileSystem\MRxSmb \Device\LanmanRedirector 865941E8
Device \Driver\nvata \Device\0000006f 871D21E8
Device \Driver\usbstor \Device\0000007c 865921E8
Device \Driver\nvata \Device\NvAta2 871D21E8
Device \Driver\usbstor \Device\0000007d 865921E8
Device \Driver\Ftdisk \Device\FtControl 871661E8
Device \Driver\usbstor \Device\0000007e 865921E8
Device \Driver\a9dvky1w \Device\Scsi\a9dvky1w1 86FC6410
Device \Driver\a9dvky1w \Device\Scsi\a9dvky1w1Port3Path0Target0Lun0 86FC6410
Device \FileSystem\Cdfs \Cdfs 864FE790

—- EOF - GMER 1.0.15 —-

Attachments:

  • [attachment removed: Attach.zip]
Okay. Provide the full ESET Scan log once it's done.

Answer to your question:

Thanks for the reply. So if I go the reinstall route, I assume I can save data to use after I reinstall like game state data, pictures, music, and the like. I would need to reinstall windows and all my apps right?

Yes. You can backup certain types of files but no executables. These include: .exe, .scr, .com etc… anything that's executable, don't backup. Music files are okay, and so are data and pictures. Then you will need your Windows Disk and do a FORMAT, not just a repair install. Format, will remove Everything, so make sure you have everything ready before you do a format. If you have any questions regarding how to do a format or just formatting in general, please let me know and I can direct you somewhere if needed.

General rule of thumb:

1) Backup all your important data files, pictures, music, work etc… and save it onto an external hard-drive. These files usually include .doc, .txt, .mp3, .jpg etc…
2) Do not backup any executables files or any window files. These include .exe's, .scr, .com, .pif etc… as they may contain traces of malware. Also, .html or .htm files that are webpages should also be avoided.

Let me know what you decide to do.

With Regards,
Extremeboy
Thanks again for the help. I'll be formating the drive and reinstalling once I get all the stuff on the drive organzied and stored off somewhere. Here is the FULL eset log: C:\Documents and Settings\Chris\My Documents\Downloads\Nero-7.11.10.0_all_update.exe Win32/Toolbar.AskSBar application deleted C:\Qoobox\Quarantine\C\WINDOWS\system32\_sdra64_.exe.zip a variant of Win32/Spy.Zbot.PG trojan deleted - quarantined H:\DAP Downloads\MEAD-DAEMInst.exe Win32/Adware.WhenU.SaveNow application deleted - quarantined Thanks again! Chris
Okay. Thanks for letting me know. Good luck on the format. If you have any questions regarding it, feel free to ask. With Regards, Extremeboy
Hello again, Do you think my PC is as clean as it is going to get? Are there any other scans I should run? It will probably take at least a week or two to get all my data off and I just want to make sure it's clean for that time. Thanks again for all your help! Chris
Hello. So far, everything is looking good. Take a new DDS run for me and post back with the logs so I can see if there's anything else. ~Extremeboy
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI