This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Browser Hijacked

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Task To Run: C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe update all silent


———————–

ComboFix 09-12-28.06 - alex 12/29/2009 10:10:26.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2574 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\alex\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-29 )))))))))))))))))))))))))))))))
.

2009-12-23 22:08 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-23 17:44 . 2009-12-23 17:44 ——– d—–w- c:\program files\Smart Projects
2009-12-22 21:53 . 2009-12-22 21:53 454656 —-a-w- C:\putty.exe
2009-12-22 21:11 . 2001-08-17 21:53 4992 -c–a-w- c:\windows\system32\dllcache\loop.sys
2009-12-22 21:11 . 2001-08-17 21:53 4992 —-a-w- c:\windows\system32\drivers\loop.sys
2009-12-22 19:47 . 2009-12-23 22:08 ——– d—–w- C:\DynaWorkDir
2009-12-22 19:46 . 2009-12-23 22:07 ——– d—–w- C:\projectGNS3
2009-12-22 19:41 . 2009-12-22 19:41 ——– d—–w- c:\program files\WinPcap
2009-12-22 19:41 . 2009-12-22 21:17 ——– d—–w- c:\program files\GNS3
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\program files\Cisco Systems
2009-12-22 19:11 . 1997-12-18 02:33 304128 —-a-w- c:\windows\IsUninst.exe
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\documents and settings\alex\WINDOWS
2009-12-22 18:28 . 2009-12-11 17:06 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 18:28 . 2009-12-11 17:06 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-22 18:28 . 2009-12-18 19:38 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-18 19:47 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-18 19:47 . 2009-12-18 19:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 19:47 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 06:17 . 2009-12-17 06:17 1956528 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-12-16 20:18 . 2009-12-16 20:18 ——– d—–w- c:\program files\MSXML 4.0
2009-12-16 20:07 . 2009-12-16 20:07 12568 —-a-w- c:\windows\system32\drivers\PROCEXP111.SYS
2009-12-16 02:18 . 2009-12-16 02:18 ——– d—–w- c:\program files\ERUNT
2009-12-16 01:47 . 2009-12-16 01:47 56532 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-16 01:47 . 2009-12-16 01:47 ——– d—–w- c:\program files\Safari
2009-12-16 00:03 . 2009-12-16 01:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-15 22:59 . 2009-12-15 22:59 ——– d—–w- c:\program files\Trend Micro
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\MSSOAP
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\Webroot
2009-12-15 22:24 . 2009-12-15 22:24 164 —-a-w- c:\windows\install.dat
2009-12-15 22:01 . 2009-12-15 22:01 ——– d—–w- c:\documents and settings\alex\Local Settings\Application Data\Threat Expert
2009-12-15 21:44 . 2009-10-30 19:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-15 21:43 . 2009-11-09 19:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-15 21:43 . 2009-10-07 00:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-15 21:43 . 2009-09-03 17:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-15 21:43 . 2009-12-15 21:49 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-15 21:43 . 2009-12-16 02:24 ——– d—–w- c:\program files\Spyware Doctor
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\alex\Application Data\PC Tools
2009-12-15 21:42 . 2009-12-19 16:42 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-14 18:52 . 2009-12-16 18:54 ——– d—–w- c:\documents and settings\alex\Packet Tracer 5.2
2009-12-12 21:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2009-12-12 21:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-12-12 21:02 . 2001-08-17 21:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-12-12 21:02 . 2001-08-17 21:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\alex\Application Data\Malwarebytes
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-12 19:38 . 2009-12-12 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-12 19:38 . 2009-12-12 19:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-12 18:27 . 2009-12-13 03:34 ——– d—–w- c:\program files\Visual CertExam Suite
2009-12-12 16:42 . 2003-06-23 10:44 1415680 —-a-w- c:\windows\system32\WMV9VCM.DLL
2009-12-12 16:42 . 1999-12-16 08:01 49152 —-a-w- c:\windows\system32\TSCCVID.DLL
2009-12-12 16:41 . 2009-12-12 17:26 ——– d—–w- c:\program files\TESTOUT
2009-12-11 17:06 . 2009-12-11 17:05 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-09 19:32 . 2009-12-09 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson Software
2009-12-08 03:46 . 2009-12-08 03:46 ——– d—–w- c:\program files\gs
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\program files\PlotSoft
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2009-12-07 17:51 . 2009-12-07 17:51 ——– d—–w- c:\documents and settings\alex\Application Data\Foxit Software
2009-12-02 00:33 . 2009-12-23 17:09 ——– d—–w- c:\documents and settings\alex\Application Data\dvdcss
2009-11-30 18:42 . 2009-11-30 19:46 ——– d—–w- c:\documents and settings\alex\Application Data\TeamViewer
2009-11-30 18:42 . 2009-11-30 18:42 ——– d—–w- c:\program files\TeamViewer
2009-11-30 18:41 . 2009-11-30 18:41 ——– d—–w- c:\documents and settings\alex\temp
2009-11-29 21:36 . 2009-11-29 21:36 ——– d—–w- c:\documents and settings\alex\Application Data\UltraVNC
2009-11-29 21:33 . 2009-11-29 21:33 20672 —-a-w- c:\windows\system32\mv2.dll
2009-11-29 21:33 . 2009-11-29 21:33 10688 —-a-w- c:\windows\system32\drivers\mv2.sys
2009-11-29 21:33 . 2009-11-30 18:38 ——– d—–w- c:\program files\UltraVNC

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 01:05 . 2009-11-20 21:51 39 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences.dat
2009-12-29 01:03 . 2009-11-20 21:52 69 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences2.dat
2009-12-26 19:24 . 2009-11-20 19:40 ——– d—–w- c:\documents and settings\alex\Application Data\Skype
2009-12-26 19:13 . 2009-11-20 19:41 ——– d—–w- c:\documents and settings\alex\Application Data\skypePM
2009-12-24 05:59 . 2009-11-20 21:54 ——– d—–w- c:\documents and settings\alex\Application Data\vlc
2009-12-24 00:01 . 2009-11-20 19:48 ——– d—–w- c:\documents and settings\alex\Application Data\uTorrent
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-17 06:22 . 2009-11-20 19:42 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-16 01:47 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\alex\Application Data\Apple Computer
2009-12-16 01:46 . 2009-11-24 04:21 ——– d—–w- c:\program files\Common Files\Apple
2009-12-15 01:08 . 2009-11-20 20:10 ——– d—–w- c:\program files\age
2009-12-12 18:27 . 2009-11-20 17:56 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-11 19:59 . 2009-11-20 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-11 17:05 . 2009-11-22 17:44 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-28 19:22 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-11-28 19:21 . 2009-11-28 19:21 ——– d—–w- c:\program files\Microsoft
2009-11-28 19:21 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live
2009-11-28 19:19 . 2009-11-28 19:19 ——– d—–w- c:\program files\Common Files\Windows Live
2009-11-24 19:16 . 2009-11-24 19:15 ——– d—–w- c:\program files\Packet Tracer 5.2
2009-11-24 19:06 . 2009-11-20 18:06 69232 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-24 19:04 . 2009-11-24 19:04 ——– d—–w- c:\program files\Reference Assemblies
2009-11-24 18:53 . 2009-11-24 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson
2009-11-24 18:52 . 2009-11-24 18:52 127 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\fusioncache.dat
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut2_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut1_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 26694 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\ARPPRODUCTICON.exe
2009-11-24 18:51 . 2009-11-24 18:51 ——– d—–w- c:\program files\Boson Software
2009-11-24 06:26 . 2009-11-24 06:26 0 —-a-w- c:\windows\nsreg.dat
2009-11-24 04:28 . 2009-11-24 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iTunes
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iPod
2009-11-24 04:23 . 2009-11-24 04:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\Bonjour
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\QuickTime
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\Apple Software Update
2009-11-23 21:39 . 2009-11-23 21:39 8854 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\readme_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 40960 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\NewShortcut1_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 1078 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\ARPPRODUCTICON.exe
2009-11-23 21:39 . 2009-11-23 21:39 ——– d—–w- c:\program files\Hewlett-Packard
2009-11-21 22:24 . 2009-11-21 18:29 ——– d—–w- c:\program files\DVDFab 6
2009-11-21 22:11 . 2009-11-21 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-21 18:29 . 2009-11-21 18:29 ——– d—–w- c:\documents and settings\alex\Application Data\Vso
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 17:57 . 2009-11-21 17:56 ——– d—–w- c:\program files\Ahead
2009-11-21 17:57 . 2009-11-21 17:57 ——– d—–w- c:\program files\Common Files\Ahead
2009-11-21 02:22 . 2009-11-21 02:22 ——– d—–w- c:\program files\CDisplay
2009-11-21 00:51 . 2009-11-21 00:51 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-20 21:53 . 2009-11-20 21:53 ——– d—–w- c:\program files\VideoLAN
2009-11-20 21:30 . 2009-11-20 21:30 ——– d—–w- c:\program files\Bitcricket
2009-11-20 21:07 . 2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-20 21:07 . 2009-11-20 21:07 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-20 21:07 . 2009-11-20 21:07 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 ——– d—–w- c:\program files\AVG
2009-11-20 21:07 . 2009-11-20 21:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-11-20 20:31 . 2009-11-20 20:11 ——– d—–w- c:\program files\Microsoft Works
2009-11-20 20:24 . 2009-11-20 20:24 ——– d—–w- c:\program files\TTERMPRO
2009-11-20 20:14 . 2009-11-20 20:14 ——– d—–w- c:\program files\MSECache
2009-11-20 20:10 . 2009-11-20 20:10 ——– d—–w- c:\program files\MSBuild
2009-11-20 19:48 . 2009-11-20 19:48 ——– d—–w- c:\program files\uTorrent
2009-11-20 19:46 . 2009-11-20 19:46 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-20 19:46 . 2009-11-20 19:46 ——– d—–w- c:\program files\Java
2009-11-20 19:45 . 2009-11-20 19:45 152576 —-a-w- c:\documents and settings\alex\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 19:44 . 2009-11-20 19:44 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-20 19:43 . 2009-11-20 19:43 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-11-20 19:42 . 2009-11-20 19:42 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-20 19:41 . 2009-11-20 19:41 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-11-20 19:40 . 2009-11-20 19:39 ——– d—–r- c:\program files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\program files\Common Files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-11-20 19:36 . 2009-11-20 19:36 ——– d—–w- c:\program files\PowerISO
2009-11-20 19:10 . 2009-11-20 17:43 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-20 18:10 . 2009-11-20 18:10 ——– d—–w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-11-20 18:03 . 2009-11-20 18:03 ——– d—–w- c:\program files\Wireless LAN
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Apoint2K
2009-11-20 18:02 . 2009-11-20 17:52 ——– d—–w- c:\program files\Common Files\InstallShield
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Power Manager
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\DIFX
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\CONEXANT
2009-11-20 18:00 . 2009-11-20 18:00 ——– d—–w- c:\program files\Hotkey Management
2009-11-20 17:56 . 2009-11-20 17:56 ——– d—–w- c:\program files\Realtek
2009-11-20 17:44 . 2009-11-20 17:44 ——– d—–w- c:\program files\microsoft frontpage
2009-11-20 17:39 . 2009-11-20 17:39 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-11-09 03:21 . 2009-11-09 03:21 59388 —-a-w- c:\windows\system32\drivers\scdemu.sys
2009-11-06 05:16 . 2009-11-06 05:16 73728 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-10-29 07:45 . 2004-08-04 07:56 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 07:56 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 07:56 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 07:56 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-10 07:07 . 2009-11-28 19:28 38208 —-a-w- c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\Default User\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-13 16264192]
"FuncKey"="c:\program files\Hotkey Management\FuncKey.exe" [2006-10-09 139264]
"PowerManager"="c:\program files\Power Manager\PM.exe" [2006-10-09 151552]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-10-02 151552]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-20 149280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-11 2033432]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]

c:\documents and settings\alex\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 20:47 1243088 —-a-w- c:\program files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-08-16 18:42 7585792 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-08-16 18:42 1617920 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-17 02:04 2879488 —-a-w- c:\windows\SkyTel.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\MYTH-age2_x1.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\Packet Tracer 5.2\\bin\\PacketTracer5.exe"=
"c:\\Program Files\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\age\\MYTH-age2_x1.exe"=
"c:\\Program Files\\Cisco Systems\\Cisco TFTP Server\\TFTPServer.exe"=
"c:\\Program Files\\GNS3\\Dynamips\\dynamips-wxp.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/15/2009 1:43 PM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/20/2009 1:07 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/20/2009 1:07 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/20/2009 1:07 PM 285392]
S3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [11/29/2009 1:33 PM 10688]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 12:22 PM 34064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/15/2009 1:43 PM 359624]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\alex\Application Data\Mozilla\Firefox\Profiles\8smgit17.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
MSConfigStartUp-SpySweeper - c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 10:17
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(624)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-12-29 10:19:21
ComboFix-quarantined-files.txt 2009-12-29 18:19

Pre-Run: 3,746,861,056 bytes free
Post-Run: 3,937,693,696 bytes free

- - End Of File - - DDA64117AB3BE5045DA9C5B8677EFDCC
Hi,

Please do the following:

Open Notepad and copy/paste the entire contents of the codebox below into Notepad:
dir /a /s "C:\windows\tasks" > log.txt
notepad log.txt
del peek.bat
Save this as peek.bat and choose to Save as type: - All Files then close the Notepad file.
It should look like this: [external image: Posted Image]

Double-click on peek.bat and allow it to run. A Notepad file will open. Post the contents of that file in your next reply.



Please advise how your computer is running now and if there are any outstanding issues
Volume in drive C has no label. Volume Serial Number is AC8F-0025 Directory of C:\windows\tasks 12/15/2009 05:24 PM . 12/15/2009 05:24 PM .. 12/22/2009 04:07 PM 472 Ad-Aware Update (Weekly).job 08/23/2001 04:00 AM 65 desktop.ini 12/29/2009 11:00 AM 6 SA.DAT 12/29/2009 11:00 AM 314 yvvukb.job 4 File(s) 857 bytes Total Files Listed: 4 File(s) 857 bytes 2 Dir(s) 3,952,537,600 bytes free
Hi,

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Browser_Hijacked_t108908.html&view=findpost&p=620552#entry620552

Collect::
C:\windows\tasks\yvvukb.job

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

NEXT

Please advise how your computer is running now and if you have any outstanding issues
ComboFix 09-12-28.06 - alex 12/29/2009 16:01:46.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2386 [GMT -8:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\alex\Desktop\cfscript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\windows\tasks\yvvukb.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\tasks\yvvukb.job

.
((((((((((((((((((((((((( Files Created from 2009-11-28 to 2009-12-30 )))))))))))))))))))))))))))))))
.

2009-12-23 22:08 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\drivers\hidserv.dll
2009-12-23 17:44 . 2009-12-23 17:44 ——– d—–w- c:\program files\Smart Projects
2009-12-22 21:53 . 2009-12-22 21:53 454656 —-a-w- C:\putty.exe
2009-12-22 21:11 . 2001-08-17 21:53 4992 -c–a-w- c:\windows\system32\dllcache\loop.sys
2009-12-22 21:11 . 2001-08-17 21:53 4992 —-a-w- c:\windows\system32\drivers\loop.sys
2009-12-22 19:47 . 2009-12-23 22:08 ——– d—–w- C:\DynaWorkDir
2009-12-22 19:46 . 2009-12-23 22:07 ——– d—–w- C:\projectGNS3
2009-12-22 19:41 . 2009-12-22 19:41 ——– d—–w- c:\program files\WinPcap
2009-12-22 19:41 . 2009-12-22 21:17 ——– d—–w- c:\program files\GNS3
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\program files\Cisco Systems
2009-12-22 19:11 . 1997-12-18 02:33 304128 —-a-w- c:\windows\IsUninst.exe
2009-12-22 19:11 . 2009-12-22 19:11 ——– d—–w- c:\documents and settings\alex\WINDOWS
2009-12-22 18:28 . 2009-12-11 17:06 4043032 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgui.exe
2009-12-22 18:28 . 2009-12-11 17:06 3776280 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\setup.exe
2009-12-22 18:28 . 2009-12-18 19:38 294656 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avglngx.dll
2009-12-18 19:47 . 2009-12-04 00:14 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-18 19:47 . 2009-12-18 19:47 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-18 19:47 . 2009-12-04 00:13 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-12-17 06:17 . 2009-12-17 06:17 1956528 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player_ax.exe
2009-12-16 20:18 . 2009-12-16 20:18 ——– d—–w- c:\program files\MSXML 4.0
2009-12-16 20:07 . 2009-12-16 20:07 12568 —-a-w- c:\windows\system32\drivers\PROCEXP111.SYS
2009-12-16 02:18 . 2009-12-16 02:18 ——– d—–w- c:\program files\ERUNT
2009-12-16 01:47 . 2009-12-16 01:47 56532 —ha-w- c:\windows\system32\mlfcache.dat
2009-12-16 01:47 . 2009-12-16 01:47 ——– d—–w- c:\program files\Safari
2009-12-16 00:03 . 2009-12-16 01:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-12-15 22:59 . 2009-12-15 22:59 ——– d—–w- c:\program files\Trend Micro
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\MSSOAP
2009-12-15 22:25 . 2009-12-15 22:25 ——– d—–w- c:\program files\Webroot
2009-12-15 22:24 . 2009-12-15 22:24 164 —-a-w- c:\windows\install.dat
2009-12-15 22:01 . 2009-12-15 22:01 ——– d—–w- c:\documents and settings\alex\Local Settings\Application Data\Threat Expert
2009-12-15 21:44 . 2009-10-30 19:11 233136 —-a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-12-15 21:43 . 2009-11-09 19:20 207792 —-a-w- c:\windows\system32\drivers\PCTCore.sys
2009-12-15 21:43 . 2009-10-07 00:31 87784 —-a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-12-15 21:43 . 2009-09-03 17:45 70408 —-a-w- c:\windows\system32\drivers\pctplsg.sys
2009-12-15 21:43 . 2009-12-15 21:49 ——– d—–w- c:\program files\Common Files\PC Tools
2009-12-15 21:43 . 2009-12-16 02:24 ——– d—–w- c:\program files\Spyware Doctor
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\All Users\Application Data\PC Tools
2009-12-15 21:43 . 2009-12-15 21:43 ——– d—–w- c:\documents and settings\alex\Application Data\PC Tools
2009-12-15 21:42 . 2009-12-19 16:42 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-12-14 18:52 . 2009-12-16 18:54 ——– d—–w- c:\documents and settings\alex\Packet Tracer 5.2
2009-12-12 21:02 . 2008-04-14 00:11 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2009-12-12 21:02 . 2008-04-14 00:11 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-12-12 21:02 . 2001-08-17 21:48 12160 -c–a-w- c:\windows\system32\dllcache\mouhid.sys
2009-12-12 21:02 . 2001-08-17 21:48 12160 —-a-w- c:\windows\system32\drivers\mouhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 -c–a-w- c:\windows\system32\dllcache\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:39 14592 —-a-w- c:\windows\system32\drivers\kbdhid.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 -c–a-w- c:\windows\system32\dllcache\hidusb.sys
2009-12-12 21:02 . 2008-04-13 18:45 10368 —-a-w- c:\windows\system32\drivers\hidusb.sys
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\alex\Application Data\Malwarebytes
2009-12-12 19:47 . 2009-12-12 19:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-12 19:38 . 2009-12-12 20:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-12 19:38 . 2009-12-12 19:38 ——– d—–w- c:\program files\Spybot - Search & Destroy
2009-12-12 18:27 . 2009-12-13 03:34 ——– d—–w- c:\program files\Visual CertExam Suite
2009-12-12 16:42 . 2003-06-23 10:44 1415680 —-a-w- c:\windows\system32\WMV9VCM.DLL
2009-12-12 16:42 . 1999-12-16 08:01 49152 —-a-w- c:\windows\system32\TSCCVID.DLL
2009-12-12 16:41 . 2009-12-12 17:26 ——– d—–w- c:\program files\TESTOUT
2009-12-11 17:06 . 2009-12-11 17:05 2352920 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgresf.dll
2009-12-09 19:32 . 2009-12-09 19:32 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson Software
2009-12-08 03:46 . 2009-12-08 03:46 ——– d—–w- c:\program files\gs
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\program files\PlotSoft
2009-12-08 03:45 . 2009-12-08 03:45 ——– d—–w- c:\documents and settings\All Users\Application Data\PlotSoft
2009-12-02 00:33 . 2009-12-23 17:09 ——– d—–w- c:\documents and settings\alex\Application Data\dvdcss
2009-11-30 18:42 . 2009-11-30 19:46 ——– d—–w- c:\documents and settings\alex\Application Data\TeamViewer
2009-11-30 18:42 . 2009-11-30 18:42 ——– d—–w- c:\program files\TeamViewer
2009-11-30 18:41 . 2009-11-30 18:41 ——– d—–w- c:\documents and settings\alex\temp

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-29 01:05 . 2009-11-20 21:51 39 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences.dat
2009-12-29 01:03 . 2009-11-20 21:52 69 —-a-w- c:\documents and settings\alex\jagex_runescape_preferences2.dat
2009-12-26 19:24 . 2009-11-20 19:40 ——– d—–w- c:\documents and settings\alex\Application Data\Skype
2009-12-26 19:13 . 2009-11-20 19:41 ——– d—–w- c:\documents and settings\alex\Application Data\skypePM
2009-12-24 05:59 . 2009-11-20 21:54 ——– d—–w- c:\documents and settings\alex\Application Data\vlc
2009-12-24 00:01 . 2009-11-20 19:48 ——– d—–w- c:\documents and settings\alex\Application Data\uTorrent
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-12-23 22:09 . 2009-12-23 22:09 0 —ha-w- c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-12-17 06:22 . 2009-11-20 19:42 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2009-12-16 01:47 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\alex\Application Data\Apple Computer
2009-12-16 01:46 . 2009-11-24 04:21 ——– d—–w- c:\program files\Common Files\Apple
2009-12-15 01:08 . 2009-11-20 20:10 ——– d—–w- c:\program files\age
2009-12-12 18:27 . 2009-11-20 17:56 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-12-11 19:59 . 2009-11-20 20:02 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-12-11 17:05 . 2009-11-22 17:44 3967256 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgcorex.dll
2009-11-30 18:38 . 2009-11-29 21:33 ——– d—–w- c:\program files\UltraVNC
2009-11-29 21:33 . 2009-11-29 21:33 20672 —-a-w- c:\windows\system32\mv2.dll
2009-11-29 21:33 . 2009-11-29 21:33 10688 —-a-w- c:\windows\system32\drivers\mv2.sys
2009-11-28 19:22 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live SkyDrive
2009-11-28 19:21 . 2009-11-28 19:21 ——– d—–w- c:\program files\Microsoft
2009-11-28 19:21 . 2009-11-28 19:22 ——– d—–w- c:\program files\Windows Live
2009-11-28 19:19 . 2009-11-28 19:19 ——– d—–w- c:\program files\Common Files\Windows Live
2009-11-24 19:16 . 2009-11-24 19:15 ——– d—–w- c:\program files\Packet Tracer 5.2
2009-11-24 19:06 . 2009-11-20 18:06 69232 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-24 19:04 . 2009-11-24 19:04 ——– d—–w- c:\program files\Reference Assemblies
2009-11-24 18:53 . 2009-11-24 18:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Boson
2009-11-24 18:52 . 2009-11-24 18:52 127 —-a-w- c:\documents and settings\alex\Local Settings\Application Data\fusioncache.dat
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut2_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 69632 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\NewShortcut1_12F69331DCBB46D5B4756BFD0F9048B3.exe
2009-11-24 18:51 . 2009-11-24 18:51 26694 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{12F69331-DCBB-46D5-B475-6BFD0F9048B3}\ARPPRODUCTICON.exe
2009-11-24 18:51 . 2009-11-24 18:51 ——– d—–w- c:\program files\Boson Software
2009-11-24 06:26 . 2009-11-24 06:26 0 —-a-w- c:\windows\nsreg.dat
2009-11-24 04:28 . 2009-11-24 04:21 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iTunes
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\iPod
2009-11-24 04:23 . 2009-11-24 04:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-11-24 04:23 . 2009-11-24 04:23 ——– d—–w- c:\program files\Bonjour
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\QuickTime
2009-11-24 04:22 . 2009-11-24 04:22 ——– d—–w- c:\program files\Apple Software Update
2009-11-23 21:39 . 2009-11-23 21:39 8854 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\readme_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 40960 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\NewShortcut1_DC5EDBF7D08241849400BC64FF8DD4BE.exe
2009-11-23 21:39 . 2009-11-23 21:39 1078 —-a-r- c:\documents and settings\alex\Application Data\Microsoft\Installer\{EFBD6F61-53E8-4F5F-8B30-1BB65BAD3EE6}\ARPPRODUCTICON.exe
2009-11-23 21:39 . 2009-11-23 21:39 ——– d—–w- c:\program files\Hewlett-Packard
2009-11-21 22:24 . 2009-11-21 18:29 ——– d—–w- c:\program files\DVDFab 6
2009-11-21 22:11 . 2009-11-21 22:11 ——– d—–w- c:\documents and settings\All Users\Application Data\vsosdk
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\windows\system32\drivers\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 18:29 . 2009-11-21 18:29 47360 —-a-w- c:\documents and settings\alex\Application Data\pcouffin.sys
2009-11-21 17:57 . 2009-11-21 17:56 ——– d—–w- c:\program files\Ahead
2009-11-21 17:57 . 2009-11-21 17:57 ——– d—–w- c:\program files\Common Files\Ahead
2009-11-21 02:22 . 2009-11-21 02:22 ——– d—–w- c:\program files\CDisplay
2009-11-21 00:51 . 2009-11-21 00:51 ——– d—–w- c:\program files\Microsoft Silverlight
2009-11-20 21:53 . 2009-11-20 21:53 ——– d—–w- c:\program files\VideoLAN
2009-11-20 21:30 . 2009-11-20 21:30 ——– d—–w- c:\program files\Bitcricket
2009-11-20 21:07 . 2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2009-11-20 21:07 . 2009-11-20 21:07 360584 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2009-11-20 21:07 . 2009-11-20 21:07 333192 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 28424 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-11-20 21:07 . 2009-11-20 21:07 ——– d—–w- c:\program files\AVG
2009-11-20 21:07 . 2009-11-20 21:06 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2009-11-20 20:31 . 2009-11-20 20:11 ——– d—–w- c:\program files\Microsoft Works
2009-11-20 20:24 . 2009-11-20 20:24 ——– d—–w- c:\program files\TTERMPRO
2009-11-20 20:14 . 2009-11-20 20:14 ——– d—–w- c:\program files\MSECache
2009-11-20 20:10 . 2009-11-20 20:10 ——– d—–w- c:\program files\MSBuild
2009-11-20 19:48 . 2009-11-20 19:48 ——– d—–w- c:\program files\uTorrent
2009-11-20 19:46 . 2009-11-20 19:46 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-11-20 19:46 . 2009-11-20 19:46 ——– d—–w- c:\program files\Java
2009-11-20 19:45 . 2009-11-20 19:45 152576 —-a-w- c:\documents and settings\alex\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-20 19:44 . 2009-11-20 19:44 ——– d—–w- c:\program files\Common Files\Adobe
2009-11-20 19:43 . 2009-11-20 19:43 ——– d—–w- c:\program files\Common Files\Adobe AIR
2009-11-20 19:42 . 2009-11-20 19:42 86016 —-a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2009-11-20 19:41 . 2009-11-20 19:41 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-11-20 19:40 . 2009-11-20 19:39 ——– d—–r- c:\program files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\program files\Common Files\Skype
2009-11-20 19:39 . 2009-11-20 19:39 ——– d—–w- c:\documents and settings\All Users\Application Data\Skype
2009-11-20 19:36 . 2009-11-20 19:36 ——– d—–w- c:\program files\PowerISO
2009-11-20 19:10 . 2009-11-20 17:43 86327 —-a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-11-20 18:10 . 2009-11-20 18:10 ——– d—–w- c:\documents and settings\All Users\Application Data\nView_Profiles
2009-11-20 18:03 . 2009-11-20 18:03 ——– d—–w- c:\program files\Wireless LAN
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Apoint2K
2009-11-20 18:02 . 2009-11-20 17:52 ——– d—–w- c:\program files\Common Files\InstallShield
2009-11-20 18:02 . 2009-11-20 18:02 ——– d—–w- c:\program files\Power Manager
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\DIFX
2009-11-20 18:01 . 2009-11-20 18:01 ——– d—–w- c:\program files\CONEXANT
2009-11-20 18:00 . 2009-11-20 18:00 ——– d—–w- c:\program files\Hotkey Management
2009-11-20 17:56 . 2009-11-20 17:56 ——– d—–w- c:\program files\Realtek
2009-11-20 17:44 . 2009-11-20 17:44 ——– d—–w- c:\program files\microsoft frontpage
2009-11-20 17:39 . 2009-11-20 17:39 21640 —-a-w- c:\windows\system32\emptyregdb.dat
2009-11-09 03:21 . 2009-11-09 03:21 59388 —-a-w- c:\windows\system32\drivers\scdemu.sys
2009-11-06 05:16 . 2009-11-06 05:16 73728 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-10-29 07:45 . 2004-08-04 07:56 916480 ——w- c:\windows\system32\wininet.dll
2009-10-21 05:38 . 2004-08-04 07:56 75776 —-a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:38 . 2004-08-04 07:56 25088 —-a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-04 06:00 265728 —-a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:30 . 2004-08-04 07:56 270336 —-a-w- c:\windows\system32\oakley.dll
2009-10-12 13:38 . 2004-08-04 07:56 149504 —-a-w- c:\windows\system32\rastls.dll
2009-10-12 13:38 . 2004-08-04 07:56 79872 —-a-w- c:\windows\system32\raschap.dll
2009-10-10 07:07 . 2009-11-28 19:28 38208 —-a-w- c:\documents and settings\HelpAssistant\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2009-10-10 07:07 . 2009-11-20 19:43 38208 —-a-w- c:\documents and settings\alex\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
.

((((((((((((((((((((((((((((( SnapShot@2009-12-29_18.17.27 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-29 19:00 . 2009-12-29 19:00 16384 c:\windows\Temp\Perflib_Perfdata_124.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-09-13 16264192]
"FuncKey"="c:\program files\Hotkey Management\FuncKey.exe" [2006-10-09 139264]
"PowerManager"="c:\program files\Power Manager\PM.exe" [2006-10-09 151552]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2006-10-02 151552]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-20 149280]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2009-12-11 2033432]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]

c:\documents and settings\alex\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-11-20 21:07 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISTray]
2009-11-18 20:47 1243088 —-a-w- c:\program files\Spyware Doctor\pctsTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 19:50 155648 —-a-w- c:\windows\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-08-16 18:42 7585792 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-08-16 18:42 1617920 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2006-05-17 02:04 2879488 —-a-w- c:\windows\SkyTel.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\TeamViewer\\Version4\\TeamViewer.exe"=
"c:\\Program Files\\TESTOUT\\Cmi\\Navigator.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\MYTH-age2_x1.exe"=
"c:\\Documents and Settings\\alex\\Desktop\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\Packet Tracer 5.2\\bin\\PacketTracer5.exe"=
"c:\\Program Files\\age\\Age2_x1\\age2_x1.exe"=
"c:\\Program Files\\age\\MYTH-age2_x1.exe"=
"c:\\Program Files\\Cisco Systems\\Cisco TFTP Server\\TFTPServer.exe"=
"c:\\Program Files\\GNS3\\Dynamips\\dynamips-wxp.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5900:TCP"= 5900:TCP:vnc5900
"5800:TCP"= 5800:TCP:vnc5800
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [12/15/2009 1:43 PM 207792]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [11/20/2009 1:07 PM 333192]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [11/20/2009 1:07 PM 360584]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [11/20/2009 1:07 PM 285392]
S3 mv2;mv2;c:\windows\system32\drivers\mv2.sys [11/29/2009 1:33 PM 10688]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [11/6/2007 12:22 PM 34064]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [12/15/2009 1:43 PM 359624]
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\alex\Application Data\Mozilla\Firefox\Profiles\8smgit17.default\
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-12-29 16:06
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2009-12-29 16:07:50
ComboFix-quarantined-files.txt 2009-12-30 00:07
ComboFix2.txt 2009-12-29 18:19

Pre-Run: 3,941,142,528 bytes free
Post-Run: 3,913,080,832 bytes free

- - End Of File - - C1936105F42598DD5C1B55F1C6043A7E
Upload was successful
Hi,

Just some housekeeping to do now,

Please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]



NEXT

Now to remove the rest of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.

If you have any other logs on your desktop > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them

    Then consider a password keeper, to keep all your passwords safe.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.


    WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox, IE and chrome.

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.
  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.
  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI