This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Intermittent Hijacking of google redirects

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Got nasty virus a couple of days ago and have slowly been getting my computer back to normal. Most of my issues seem to be resolved except for I'm still getting the occasional Hijacking of links I click on in Google searches. I tried to install hijackthis, but got an error of not a valid win32 application. Please help. What should I do?
:welcome:

Please download RootRepeal one of these locations and save it to your desktop
Here
Here
Here
  • Open [external image: Posted Image] on your desktop.
  • Click the [external image: Posted Image] tab.
  • Click the [external image: Posted Image] button.
  • Check just these boxes:
  • [external image: Posted Image]
  • Push Ok
  • Check the box for your main system drive (Usually C:, and press Ok.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Include this report in your post.





  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<info.txt (<
Well I though I nipped most of this virus in the but, but not I got red x in the try that keeps telling me my computer is infected. I'm ignoring it seems rather fishy looking. For the RSIT report. I started to run it, but it quit on me. Whe I try and restart it, it gives me an alert popup that says "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions t access the item."
jamxi,

Your infected with a Rootkit that is responsible for that red x. The rootkit installs a rogue antivirus program. Lets get rid of it. Please do not attach any more logs , just copy and paste them into this thread.

Follow these instructions to rename Combofix as this rootkit will prevent it from running if its not renamed.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
It seemed to have some problems downloading and installing the recovery console. It managed to run through everything OK.

Here is the report:


ComboFix 09-09-06.03 - Owner 09/06/2009 23:46.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.271 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ctomfx.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\recycler\S-1-5-21-202484281-2063255866-616690263-1003
c:\windows\braviax.exe
c:\windows\cru629.dat
c:\windows\Installer\1324b.msi
c:\windows\system32\~.exe
c:\windows\system32\braviax.exe
c:\windows\system32\cru629.dat
c:\windows\system32\dllcache\beep.sys
c:\windows\system32\dllcache\figaro.sys
c:\windows\system32\drivers\rotscxpeouqsbp.sys
c:\windows\system32\drivers\UACrsvtcalxye.sys
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\rotscxbikoyipr.dat
c:\windows\system32\rotscxgowpseqm.dll
c:\windows\system32\rotscxiwwkicqf.dat
c:\windows\system32\rotscxxcwfvddr.dll
c:\windows\TEMP\logishrd\LVPrcInj01.dll
D:\Autorun.inf

c:\windows\system32\drivers\beep.sys . . . is infected!!

Infected copy of c:\windows\system32\eventlog.dll was found and disinfected
Restored copy from - c:\windows\system32\logevent.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_rotscxevsprxby
——-\Legacy_rotscxevsprxby
——-\Service_UACd.sys
——-\Legacy_UACd.sys
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}


((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.

2009-09-07 04:38 . 2009-09-07 04:38 ——– d—–w- C:\New Folder
2009-09-06 18:31 . 2009-09-06 18:31 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-09-06 17:15 . 2009-09-06 17:15 ——– d—–w- c:\program files\trend micro
2009-09-06 17:15 . 2009-09-06 17:15 ——– d—–w- C:\rsit
2009-09-06 16:43 . 2009-09-07 04:58 ——– d–h–w- c:\windows\PIF
2009-09-06 12:06 . 2009-09-06 12:07 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-09-05 06:44 . 2009-09-07 05:02 15648 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-05 06:44 . 2009-09-07 05:00 259872 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-05 06:17 . 2009-09-05 23:14 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-09-05 06:17 . 2009-09-05 23:14 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-09-05 06:17 . 2009-09-05 06:17 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-09-05 03:55 . 2009-09-05 06:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-05 03:55 . 2009-09-05 03:59 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-05 01:44 . 2009-09-05 02:25 ——– d—–w- c:\program files\Sandboxie
2009-09-05 01:08 . 2009-09-05 01:08 ——– d—–w- C:\Sandbox
2009-09-05 00:57 . 2009-09-05 00:57 ——– d—–w- c:\program files\KeyScrambler
2009-09-05 00:57 . 2008-03-22 21:37 113896 —-a-w- c:\windows\system32\drivers\keyscrambler.sys
2009-09-04 12:34 . 2009-09-04 12:34 163840 —-a-w- c:\windows\svchasts.exe
2009-09-04 05:13 . 2009-09-04 05:13 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-27 00:40 . 2009-08-27 00:45 ——– d—–w- c:\documents and settings\Owner\Application Data\PCF-VLC
2009-08-26 04:47 . 2009-08-26 04:47 ——– d—–w- c:\documents and settings\Owner\Application Data\Participatory Culture Foundation
2009-08-26 04:44 . 2009-08-26 04:44 ——– d—–w- c:\program files\Participatory Culture Foundation
2009-08-25 04:26 . 2009-08-25 04:26 ——– d—–w- c:\windows\Sun
2009-08-25 04:26 . 2009-08-25 04:26 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Identities
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\scripting
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\l2schemas
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\en
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\bits
2009-08-22 16:48 . 2009-08-22 16:48 ——– d—–w- c:\windows\EHome
2009-08-22 04:42 . 2009-08-22 04:42 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-22 04:41 . 2009-08-03 18:36 38160 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-22 04:41 . 2009-08-22 04:42 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-08-22 04:41 . 2009-08-22 04:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 04:41 . 2009-08-03 18:36 19096 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-08-22 04:20 . 2009-08-22 04:56 ——– d—–w- c:\program files\xeraqv
2009-08-18 22:07 . 2009-08-18 22:07 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-08-18 04:15 . 2009-09-05 06:17 33128 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 04:13 . 2009-08-18 04:13 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-08-18 04:13 . 2009-03-19 21:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-18 04:13 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-08-18 04:12 . 2009-08-18 04:12 ——– d—–w- c:\program files\iPod
2009-08-18 04:12 . 2009-08-18 04:13 ——– d—–w- c:\program files\iTunes
2009-08-18 04:12 . 2009-08-18 04:13 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-18 04:12 . 2009-08-18 04:12 ——– d—–w- c:\program files\Bonjour
2009-08-18 04:11 . 2009-08-18 04:12 ——– d—–w- c:\program files\Common Files\Apple
2009-08-13 04:40 . 2009-08-13 04:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Adobe
2009-08-12 06:12 . 2009-08-22 16:58 ——– d—–w- c:\windows\ServicePackFiles
2009-08-12 03:23 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 01:51 . 2009-08-11 01:51 ——– d—–w- c:\program files\Common Files\Logitech
2009-08-11 01:51 . 2009-09-05 06:16 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Downloaded Installations
2009-08-10 03:55 . 2009-08-10 03:55 ——– d—–w- c:\program files\MSXML 4.0
2009-08-10 00:51 . 2001-08-17 18:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-08-10 00:51 . 2001-08-17 18:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-08-10 00:51 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-08-09 23:01 . 2004-08-04 03:29 73216 ——w- c:\windows\system32\drivers\atintuxx.sys
2009-08-09 20:30 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-08-09 20:29 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-08-09 20:29 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-08-09 20:28 . 2009-03-06 14:22 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll
2009-08-09 20:28 . 2009-02-09 12:10 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll
2009-08-09 20:28 . 2009-02-06 11:11 110592 -c—-w- c:\windows\system32\dllcache\services.exe
2009-08-09 20:28 . 2009-02-09 12:10 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll
2009-08-09 20:28 . 2009-02-06 10:10 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe
2009-08-09 20:28 . 2009-06-25 08:25 730112 -c—-w- c:\windows\system32\dllcache\lsasrv.dll
2009-08-09 20:28 . 2009-02-09 12:10 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll
2009-08-09 20:28 . 2009-02-09 12:10 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-08-09 20:28 . 2009-02-09 12:10 714752 -c—-w- c:\windows\system32\dllcache\ntdll.dll
2009-08-09 20:28 . 2009-02-06 11:06 2145280 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-09 20:28 . 2009-02-06 11:08 2189056 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-09 20:28 . 2009-02-06 10:32 2023936 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-09 20:20 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-08-09 20:20 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-08-09 20:19 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-08-09 20:18 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-08-09 20:17 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-08-09 20:14 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-08-09 20:14 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-08-09 01:00 . 2009-03-30 15:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-09 01:00 . 2009-07-28 21:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-09 01:00 . 2009-02-13 17:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-08-09 01:00 . 2009-02-13 17:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2009-08-09 01:00 . 2009-08-09 01:00 ——– d—–w- c:\program files\Avira
2009-08-09 01:00 . 2009-08-09 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2009-08-08 22:36 . 2009-08-09 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-08 22:36 . 2009-08-09 01:00 ——– d—–w- c:\program files\NOS
2009-08-08 22:29 . 2009-08-08 22:29 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
2009-08-08 21:49 . 2005-07-19 02:05 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-08-08 21:48 . 2009-09-07 04:58 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\SampleView
2009-08-08 21:48 . 2009-08-08 21:12 ——– d—–w- c:\windows\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2009-08-08 21:48 . 2009-08-08 21:07 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-08-08 21:48 . 2009-08-08 20:41 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2009-08-08 21:47 . 2009-08-08 20:41 ——– d—–w- c:\documents and settings\Default User\WINDOWS
2009-08-08 21:22 . 2009-08-08 22:09 ——– d—–w- c:\program files\McAfee
2009-08-08 21:22 . 2009-08-08 21:22 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-08-08 21:21 . 2009-08-08 21:21 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-08 21:20 . 2007-08-11 01:46 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2009-08-08 21:19 . 2009-09-02 02:10 ——– d–h–w- c:\windows\$hf_mig$
2009-08-08 21:16 . 2009-08-08 21:16 ——– d—–w- c:\documents and settings\Owner\Application Data\SampleView
2009-08-08 21:16 . 2004-08-04 19:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-08-08 21:14 . 2003-03-25 12:00 67072 —-a-w- c:\windows\POWERCFG.EXE
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\program files\MSN Encarta Plus
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\documents and settings\Owner\Application Data\You've Got Pictures Screensaver
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\program files\Common Files\Nullsoft
2009-08-08 21:10 . 2009-08-08 20:00 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-08-08 21:10 . 2009-08-08 21:10 335 —-a-w- c:\windows\nsreg.dat
2009-08-08 21:10 . 2009-08-08 19:59 ——– d—–w- c:\program files\Common Files\AOL
2009-08-08 21:10 . 2009-08-08 21:10 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\program files\Napster
2009-08-08 21:08 . 2009-08-08 21:08 ——– d—–w- c:\program files\Intel
2009-08-08 21:08 . 2005-02-01 18:18 17992 —-a-w- c:\windows\system32\drivers\bcm42rly.sys
2009-08-08 21:08 . 2009-08-08 21:08 ——– d—–w- C:\ses2_client_bin_2_8_13g
2009-08-08 21:08 . 2009-08-08 21:08 4 —-a-w- c:\windows\Pix11.dat
2009-08-08 21:07 . 2009-08-08 21:08 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-08-08 21:07 . 2009-08-08 21:07 ——– d—–w- c:\program files\Java
2009-08-08 21:07 . 2009-08-08 21:07 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-08-08 21:06 . 2009-08-08 21:06 ——– d—–w- c:\program files\CyberLink
2009-08-08 21:06 . 2004-07-15 21:06 471298 —-a-w- c:\windows\wallpg.exe
2009-08-08 21:06 . 2009-08-08 21:48 ——– d—–w- c:\documents and settings\Administrator
2009-08-08 21:06 . 2004-11-05 01:47 90202 —-a-w- c:\windows\system32\SynTPAPI.dll
2009-08-08 21:06 . 2004-11-05 01:47 81920 —-a-w- c:\windows\system32\SynTPCo2.dll
2009-08-08 21:06 . 2004-11-05 01:47 77917 —-a-w- c:\windows\system32\SynCOM.dll
2009-08-08 21:06 . 2004-11-05 01:47 69722 —-a-w- c:\windows\system32\SynTPFcs.dll
2009-08-08 21:06 . 2004-11-05 01:47 185824 —-a-w- c:\windows\system32\drivers\SynTP.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 05:00 . 2009-08-08 20:09 0 —-a-w- c:\windows\system32\drivers\lvuvc.hs
2009-09-07 05:00 . 2009-08-08 20:08 0 —-a-w- c:\windows\system32\drivers\logiflt.iad
2009-09-07 04:59 . 2009-09-05 06:44 4484 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-07 04:59 . 2009-09-05 06:44 2468 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-07 04:39 . 2009-07-23 02:28 56320 —-a-w- c:\windows\system32\eventlog.dll
2009-08-10 15:36 . 2009-08-08 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2009-08-08 22:09 . 2009-08-08 21:11 ——– d—–w- c:\program files\Pure Networks
2009-08-08 21:14 . 2009-08-08 21:13 ——– d—–w- c:\program files\Microsoft Money 2005
2009-08-08 21:13 . 2009-08-08 21:12 ——– d—–w- c:\program files\Microsoft Works
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-08-08 21:11 . 2009-08-08 21:11 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Common Files\Real
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Real
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Viewpoint
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-08-08 21:09 . 2009-08-08 21:01 ——– d—–w- c:\program files\Common Files\InstallShield
2009-08-08 21:01 . 2009-08-08 21:00 ——– d—–w- c:\program files\Ahead
2009-08-08 21:00 . 2009-08-08 21:00 ——– d—–w- c:\program files\Common Files\Ahead
2009-08-08 20:41 . 2004-08-26 18:04 ——– d—–w- c:\program files\microsoft frontpage
2009-08-08 20:08 . 2009-08-08 20:04 ——– d—–w- c:\program files\Common Files\LogiShrd
2009-08-08 20:06 . 2009-08-08 20:06 127034 ——r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-08-08 20:06 . 2009-08-08 21:01 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-08 20:06 . 2009-08-08 20:06 ——– d—–w- c:\documents and settings\Owner\Application Data\Leadertech
2009-08-05 09:01 . 2009-07-23 02:30 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2009-07-23 02:27 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2009-07-23 02:32 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2009-07-23 02:32 827392 —-a-w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-23 02:29 78336 ——w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2009-07-23 02:27 17408 ——w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2009-07-23 02:32 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2009-07-23 02:31 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2009-07-23 02:31 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2009-07-23 02:30 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2009-07-23 02:30 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2009-07-23 02:29 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2009-07-23 02:29 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2009-07-23 02:32 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2009-07-23 02:28 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2009-07-23 02:32 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2009-07-23 02:30 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2009-07-23 02:27 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2009-07-23 02:32 132096 —-a-w- c:\windows\system32\wkssvc.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-25 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-8-8 66864]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/8/2009 8:00 PM 108289]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [9/4/2009 7:57 PM 113896]
.
Contents of the 'Scheduled Tasks' folder

2009-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: kaspersky.com\www
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\download
Trusted Zone: microsoft.com\update
Trusted Zone: windowsupdate.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8f0jyar.default\
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8f0jyar.default\extensions\[removed]\components\KeyScramblerIE.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 00:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(520)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
———————— Other Running Processes ————————
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Completion time: 2009-09-07 0:07 - machine was rebooted
ComboFix-quarantined-files.txt 2009-09-07 05:07

Pre-Run: 50,226,511,872 bytes free
Post-Run: 50,350,964,736 bytes free

358 — E O F — 2009-09-02 03:30
Hi,

Open Notepad Go to Start> All Programs> Assessories> Notepad ( this will only work with Notepad )and copy all the text inside the Codebox by highlighting it all and pressing CTRL C on your keyboard, then paste it into Notepad, make sure there is no space before and above Rootkit::


File::
c:\windows\svchasts.exe
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\drivers\logiflt.iad

Save this as CFScript to your desktop.

Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

[external image: Posted Image]


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a new HijackThis log.







Please download Malwarebytes' Anti-Malware from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report and also a new HJT log please



Post the new Combofix log, the Malwarebytes log and try and run HJT and post the log as well
Here is combo fix:

ComboFix 09-09-06.06 - Owner 09/07/2009 11:38.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.502.234 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ctomfx.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
FW: *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

FILE ::
"c:\windows\svchasts.exe"
"c:\windows\system32\drivers\logiflt.iad"
"c:\windows\system32\drivers\lvuvc.hs"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\svchasts.exe
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\drivers\lvuvc.hs

.
((((((((((((((((((((((((( Files Created from 2009-08-07 to 2009-09-07 )))))))))))))))))))))))))))))))
.

2009-09-07 05:53 . 2009-09-07 05:53 ——– d—–w- c:\program files\Intel Corporation
2009-09-07 04:38 . 2009-09-07 04:38 ——– d—–w- C:\New Folder
2009-09-06 18:31 . 2009-09-06 18:31 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-09-06 17:15 . 2009-09-06 17:15 ——– d—–w- c:\program files\trend micro
2009-09-06 17:15 . 2009-09-06 17:15 ——– d—–w- C:\rsit
2009-09-06 16:43 . 2009-09-07 04:58 ——– d–h–w- c:\windows\PIF
2009-09-06 12:06 . 2009-09-06 12:07 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\Adobe
2009-09-05 06:44 . 2009-09-07 16:44 372768 –sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-05 06:44 . 2009-09-07 16:43 23328 –sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-05 06:17 . 2009-09-05 23:14 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-09-05 06:17 . 2009-09-05 23:14 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic
2009-09-05 06:17 . 2009-09-05 06:17 ——– d—–w- c:\documents and settings\All Users\Application Data\ParetoLogic Anti-Virus PLUS
2009-09-05 03:55 . 2009-09-05 06:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-09-05 03:55 . 2009-09-05 03:59 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-09-05 01:44 . 2009-09-05 02:25 ——– d—–w- c:\program files\Sandboxie
2009-09-05 01:08 . 2009-09-05 01:08 ——– d—–w- C:\Sandbox
2009-09-05 00:57 . 2009-09-05 00:57 ——– d—–w- c:\program files\KeyScrambler
2009-09-05 00:57 . 2008-03-22 21:37 113896 —-a-w- c:\windows\system32\drivers\keyscrambler.sys
2009-09-04 05:13 . 2009-09-04 05:13 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2009-08-27 00:40 . 2009-08-27 00:45 ——– d—–w- c:\documents and settings\Owner\Application Data\PCF-VLC
2009-08-26 04:47 . 2009-08-26 04:47 ——– d—–w- c:\documents and settings\Owner\Application Data\Participatory Culture Foundation
2009-08-26 04:44 . 2009-08-26 04:44 ——– d—–w- c:\program files\Participatory Culture Foundation
2009-08-25 04:26 . 2009-08-25 04:26 ——– d—–w- c:\windows\Sun
2009-08-25 04:26 . 2009-08-25 04:26 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Identities
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\scripting
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\l2schemas
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\en
2009-08-22 17:05 . 2009-08-22 17:05 ——– d—–w- c:\windows\system32\bits
2009-08-22 16:48 . 2009-08-22 16:48 ——– d—–w- c:\windows\EHome
2009-08-22 04:42 . 2009-08-22 04:42 ——– d—–w- c:\documents and settings\Owner\Application Data\Malwarebytes
2009-08-22 04:41 . 2009-08-22 04:41 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-22 04:20 . 2009-08-22 04:56 ——– d—–w- c:\program files\xeraqv
2009-08-18 22:07 . 2009-08-18 22:07 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple
2009-08-18 04:15 . 2009-09-05 06:17 33128 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-18 04:13 . 2009-08-18 04:13 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2009-08-18 04:13 . 2009-03-19 21:32 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-08-18 04:13 . 2008-04-17 17:12 107368 —-a-w- c:\windows\system32\GEARAspi.dll
2009-08-18 04:12 . 2009-08-18 04:12 ——– d—–w- c:\program files\iPod
2009-08-18 04:12 . 2009-08-18 04:13 ——– d—–w- c:\program files\iTunes
2009-08-18 04:12 . 2009-08-18 04:13 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-18 04:12 . 2009-08-18 04:12 ——– d—–w- c:\program files\Bonjour
2009-08-18 04:11 . 2009-08-18 04:12 ——– d—–w- c:\program files\Common Files\Apple
2009-08-13 04:40 . 2009-08-13 04:40 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Adobe
2009-08-12 06:12 . 2009-08-22 16:58 ——– d—–w- c:\windows\ServicePackFiles
2009-08-12 03:23 . 2009-07-10 13:27 1315328 -c—-w- c:\windows\system32\dllcache\msoe.dll
2009-08-11 01:51 . 2009-08-11 01:51 ——– d—–w- c:\program files\Common Files\Logitech
2009-08-11 01:51 . 2009-09-05 06:16 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Downloaded Installations
2009-08-10 03:55 . 2009-08-10 03:55 ——– d—–w- c:\program files\MSXML 4.0
2009-08-10 00:51 . 2001-08-17 18:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-08-10 00:51 . 2001-08-17 18:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-08-10 00:51 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-08-09 23:01 . 2004-08-04 03:29 73216 ——w- c:\windows\system32\drivers\atintuxx.sys
2009-08-09 20:30 . 2008-06-17 19:02 8461312 -c—-w- c:\windows\system32\dllcache\shell32.dll
2009-08-09 20:29 . 2008-06-13 11:05 272128 -c—-w- c:\windows\system32\dllcache\bthport.sys
2009-08-09 20:29 . 2008-06-13 11:05 272128 ——w- c:\windows\system32\drivers\bthport.sys
2009-08-09 20:28 . 2009-03-06 14:22 284160 -c—-w- c:\windows\system32\dllcache\pdh.dll
2009-08-09 20:28 . 2009-02-09 12:10 401408 -c—-w- c:\windows\system32\dllcache\rpcss.dll
2009-08-09 20:28 . 2009-02-06 11:11 110592 -c—-w- c:\windows\system32\dllcache\services.exe
2009-08-09 20:28 . 2009-02-09 12:10 473600 -c—-w- c:\windows\system32\dllcache\fastprox.dll
2009-08-09 20:28 . 2009-02-06 10:10 227840 -c—-w- c:\windows\system32\dllcache\wmiprvse.exe
2009-08-09 20:28 . 2009-06-25 08:25 730112 -c—-w- c:\windows\system32\dllcache\lsasrv.dll
2009-08-09 20:28 . 2009-02-09 12:10 617472 -c—-w- c:\windows\system32\dllcache\advapi32.dll
2009-08-09 20:28 . 2009-02-09 12:10 453120 -c—-w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-08-09 20:28 . 2009-02-09 12:10 714752 -c—-w- c:\windows\system32\dllcache\ntdll.dll
2009-08-09 20:28 . 2009-02-06 11:06 2145280 -c—-w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-09 20:28 . 2009-02-06 11:08 2189056 -c—-w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-09 20:28 . 2009-02-06 10:32 2023936 -c—-w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-09 20:20 . 2008-05-08 14:02 203136 -c—-w- c:\windows\system32\dllcache\rmcast.sys
2009-08-09 20:20 . 2008-10-24 11:21 455296 -c—-w- c:\windows\system32\dllcache\mrxsmb.sys
2009-08-09 20:19 . 2008-12-11 10:57 333952 -c—-w- c:\windows\system32\dllcache\srv.sys
2009-08-09 20:18 . 2008-04-11 19:04 691712 -c—-w- c:\windows\system32\dllcache\inetcomm.dll
2009-08-09 20:17 . 2008-10-15 16:34 337408 -c—-w- c:\windows\system32\dllcache\netapi32.dll
2009-08-09 20:14 . 2008-05-03 11:55 2560 ——w- c:\windows\system32\xpsp4res.dll
2009-08-09 20:14 . 2008-04-21 12:08 215552 -c—-w- c:\windows\system32\dllcache\wordpad.exe
2009-08-09 01:00 . 2009-03-30 15:33 96104 —-a-w- c:\windows\system32\drivers\avipbb.sys
2009-08-09 01:00 . 2009-07-28 21:33 55656 —-a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-09 01:00 . 2009-02-13 17:29 22360 —-a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-08-09 01:00 . 2009-02-13 17:17 45416 —-a-w- c:\windows\system32\drivers\avgntdd.sys
2009-08-09 01:00 . 2009-08-09 01:00 ——– d—–w- c:\program files\Avira
2009-08-09 01:00 . 2009-08-09 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\Avira
2009-08-08 22:36 . 2009-08-09 01:00 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-08-08 22:36 . 2009-08-09 01:00 ——– d—–w- c:\program files\NOS
2009-08-08 22:29 . 2009-08-08 22:29 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Mozilla
2009-08-08 21:49 . 2005-07-19 02:05 135168 —-a-w- c:\windows\system32\igfxres.dll
2009-08-08 21:48 . 2009-08-08 21:07 ——– d—–w- c:\windows\system32\config\systemprofile\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-08-08 21:48 . 2009-08-08 20:41 ——– d—–w- c:\windows\system32\config\systemprofile\WINDOWS
2009-08-08 21:47 . 2009-08-08 20:41 ——– d—–w- c:\documents and settings\Default User\WINDOWS
2009-08-08 21:22 . 2009-08-08 22:09 ——– d—–w- c:\program files\McAfee
2009-08-08 21:22 . 2009-08-08 21:22 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com Personal Firewall
2009-08-08 21:21 . 2009-08-08 21:21 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee.com
2009-08-08 21:20 . 2007-08-11 01:46 26488 —-a-w- c:\windows\system32\spupdsvc.exe
2009-08-08 21:19 . 2009-09-02 02:10 ——– d–h–w- c:\windows\$hf_mig$
2009-08-08 21:16 . 2009-08-08 21:16 ——– d—–w- c:\documents and settings\Owner\Application Data\SampleView
2009-08-08 21:16 . 2004-08-04 19:00 221184 —-a-w- c:\windows\system32\wmpns.dll
2009-08-08 21:14 . 2003-03-25 12:00 67072 —-a-w- c:\windows\POWERCFG.EXE
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\program files\MSN Encarta Plus
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\documents and settings\Owner\Application Data\You've Got Pictures Screensaver
2009-08-08 21:12 . 2009-08-08 21:12 ——– d—–w- c:\program files\Common Files\Nullsoft
2009-08-08 21:10 . 2009-08-08 20:00 ——– d—–w- c:\documents and settings\All Users\Application Data\AOL
2009-08-08 21:10 . 2009-08-08 21:10 335 —-a-w- c:\windows\nsreg.dat
2009-08-08 21:10 . 2009-08-08 19:59 ——– d—–w- c:\program files\Common Files\AOL
2009-08-08 21:10 . 2009-08-08 21:10 ——– d—–w- c:\program files\Common Files\Adobe
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\program files\Common Files\Roxio Shared
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\documents and settings\All Users\Application Data\Napster
2009-08-08 21:09 . 2009-08-08 21:09 ——– d—–w- c:\program files\Napster
2009-08-08 21:08 . 2009-08-08 21:08 ——– d—–w- c:\program files\Intel
2009-08-08 21:08 . 2005-02-01 18:18 17992 —-a-w- c:\windows\system32\drivers\bcm42rly.sys
2009-08-08 21:08 . 2009-08-08 21:08 ——– d—–w- C:\ses2_client_bin_2_8_13g
2009-08-08 21:08 . 2009-08-08 21:08 4 —-a-w- c:\windows\Pix11.dat
2009-08-08 21:07 . 2009-08-08 21:08 ——– d—–w- c:\program files\Microsoft Digital Image 2006
2009-08-08 21:07 . 2009-08-08 21:07 ——– d—–w- c:\program files\Java
2009-08-08 21:07 . 2009-08-08 21:07 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\{3248F0A6-6813-11D6-A77B-00B0D0150020}
2009-08-08 21:06 . 2009-08-08 21:06 ——– d—–w- c:\program files\CyberLink
2009-08-08 21:06 . 2004-07-15 21:06 471298 —-a-w- c:\windows\wallpg.exe
2009-08-08 21:06 . 2009-08-08 21:48 ——– d—–w- c:\documents and settings\Administrator
2009-08-08 21:06 . 2004-11-05 01:47 90202 —-a-w- c:\windows\system32\SynTPAPI.dll
2009-08-08 21:06 . 2004-11-05 01:47 81920 —-a-w- c:\windows\system32\SynTPCo2.dll
2009-08-08 21:06 . 2004-11-05 01:47 77917 —-a-w- c:\windows\system32\SynCOM.dll
2009-08-08 21:06 . 2004-11-05 01:47 69722 —-a-w- c:\windows\system32\SynTPFcs.dll
2009-08-08 21:06 . 2004-11-05 01:47 185824 —-a-w- c:\windows\system32\drivers\SynTP.sys
2009-08-08 21:06 . 2004-11-05 01:47 114688 —-a-w- c:\windows\system32\SynCtrl.dll
2009-08-08 21:06 . 2009-08-08 21:06 ——– d—–w- c:\program files\Synaptics
2009-08-08 21:03 . 2004-03-22 22:17 24816 —-a-w- c:\windows\system32\mdimon.dll
2009-08-08 21:03 . 2009-08-08 21:03 ——– d—–w- c:\program files\Microsoft ActiveSync
2009-08-08 21:02 . 2009-08-08 21:02 ——– d—–w- c:\windows\SHELLNEW

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-07 04:59 . 2009-09-05 06:44 4484 –sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-07 04:59 . 2009-09-05 06:44 2468 –sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-07 04:39 . 2009-07-23 02:28 56320 ——w- c:\windows\system32\eventlog.dll
2009-08-10 15:36 . 2009-08-08 20:04 ——– d—–w- c:\documents and settings\All Users\Application Data\Logishrd
2009-08-08 22:09 . 2009-08-08 21:11 ——– d—–w- c:\program files\Pure Networks
2009-08-08 21:14 . 2009-08-08 21:13 ——– d—–w- c:\program files\Microsoft Money 2005
2009-08-08 21:13 . 2009-08-08 21:12 ——– d—–w- c:\program files\Microsoft Works
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\QuickTime
2009-08-08 21:11 . 2009-08-08 21:11 8552 —-a-w- c:\windows\system32\drivers\asctrm.sys
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Common Files\Real
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Real
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\program files\Viewpoint
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Viewpoint
2009-08-08 21:11 . 2009-08-08 21:11 ——– d—–w- c:\documents and settings\All Users\Application Data\Pure Networks
2009-08-08 21:09 . 2009-08-08 21:01 ——– d—–w- c:\program files\Common Files\InstallShield
2009-08-08 21:01 . 2009-08-08 21:00 ——– d—–w- c:\program files\Ahead
2009-08-08 21:00 . 2009-08-08 21:00 ——– d—–w- c:\program files\Common Files\Ahead
2009-08-08 20:41 . 2004-08-26 18:04 ——– d—–w- c:\program files\microsoft frontpage
2009-08-08 20:08 . 2009-08-08 20:04 ——– d—–w- c:\program files\Common Files\LogiShrd
2009-08-08 20:06 . 2009-08-08 20:06 127034 ——r- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-08-08 20:06 . 2009-08-08 21:01 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-08-08 20:06 . 2009-08-08 20:06 ——– d—–w- c:\documents and settings\Owner\Application Data\Leadertech
2009-08-05 09:01 . 2009-07-23 02:30 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-07-17 19:01 . 2009-07-23 02:27 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-13 15:08 . 2009-07-23 02:32 286720 —-a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 16:12 . 2009-07-23 02:32 827392 ——w- c:\windows\system32\wininet.dll
2009-06-29 16:12 . 2009-07-23 02:29 78336 ——w- c:\windows\system32\ieencode.dll
2009-06-29 16:12 . 2009-07-23 02:27 17408 ——w- c:\windows\system32\corpol.dll
2009-06-25 08:25 . 2009-07-23 02:32 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2009-07-23 02:31 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2009-07-23 02:31 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2009-07-23 02:30 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2009-07-23 02:30 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2009-07-23 02:29 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2009-07-23 02:29 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-16 14:36 . 2009-07-23 02:32 119808 —-a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2009-07-23 02:28 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-12 12:31 . 2009-07-23 02:32 76288 —-a-w- c:\windows\system32\telnet.exe
2009-06-10 14:19 . 2009-07-23 02:30 2066432 —-a-w- c:\windows\system32\mstscax.dll
2009-06-10 14:13 . 2009-07-23 02:27 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:14 . 2009-07-23 02:32 132096 —-a-w- c:\windows\system32\wkssvc.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-09-07_05.01.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-07 05:53 . 2009-09-07 05:53 253440 c:\windows\Installer\310c97.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-07-16 25604904]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-11-05 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-11-05 688218]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 32768]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2005-02-25 966656]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-14 212992]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-14 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-14 2407184]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-04-14 169984]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-8-8 66864]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Participatory Culture Foundation\\Miro\\Miro_Downloader.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [8/8/2009 8:00 PM 108289]
R3 KeyScrambler;KeyScrambler;c:\windows\system32\drivers\keyscrambler.sys [9/4/2009 7:57 PM 113896]
.
Contents of the 'Scheduled Tasks' folder

2009-09-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: kaspersky.com\www
Trusted Zone: microsoft.com\*.windowsupdate
Trusted Zone: microsoft.com\download
Trusted Zone: microsoft.com\update
Trusted Zone: windowsupdate.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8f0jyar.default\
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\d8f0jyar.default\extensions\[removed]\components\KeyScramblerIE.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-07 11:44
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-09-07 11:46
ComboFix-quarantined-files.txt 2009-09-07 16:46
ComboFix2.txt 2009-09-07 05:07

Pre-Run: 50,252,906,496 bytes free
Post-Run: 50,221,379,584 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

300 — E O F — 2009-09-02 03:30
Malwarebytes' Anti-Malware 1.40 Database version: 2751 Windows 5.1.2600 Service Pack 3 9/7/2009 12:04:14 PM mbam-log-2009-09-07 (12-04-14).txt Scan type: Quick Scan Objects scanned: 88844 Time elapsed: 6 minute(s), 34 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 4 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:32:52 PM, on 9/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16876)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gateway.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: CKeyScramblerBHO Object - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler… - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\KeyScramblerIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://www.kaspersky.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} -
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS

–
End of file - 7901 bytes
Things seemed to have cleared up after the first combofix run. Thanks for all your help. That folder you called out I don't know anything about. I'm assuming I should just delete it. There doesn't appear to be anything in it. Thanks again.
Hi,

If the folder is empty go ahead and delete it , leave it in the recycle bin for a few days in case some program needs it than you can restore it.

Lets double check to see if we missed anything.

Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Hey I haven't followed your next steps yet, but just noticed avira virus scanner has flagged the following. Virus or unwanted program 'TR/Trash.Gen [trojan]' detected in file 'C:\System Volume Information\_restore{F845E3DB-F751-4BE4-A620-64F2CA1BFB5F}\RP12\A0001241.sys. Action performed: Deny access I'll run the virus scan next and post the log.
What Avira found was in your System Restore Program, flushing it all out was part of the cleanup but we have not gotten to that yet, but you can do it now.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.

Reboot your computer

Turn ON System Restore.

  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.

Create a new Restore Point <– Very Important

  • Go to Start> All Programs> Assesories> System Tools> System Restore and create a New Restore Point
System Restore Tutorial <– If you need it

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI