jdl
Topic Starter
My Dell laptop became infected with Security Tool. I downloaded malwarebytes anti malware and ran a quick scan that indicated 4 infected items. I deleted them and emptied the recycle bin. I also ran mbam and the atf cleaner. I will post the three notepad logs below my question:
I notice my internet address bar is http://m.www.yahoo.com the "m" will not disappear even when I try to reset the address bar through internet options to set the homepage. I'm wondering if this is caused by the Security Tool virus?
When I go to start, My Computer, C drive, there is no address bar. I tried to create an address bar through the tools, view address bar, but it still will not create an address bar. Is this caused by the Security Tool virus?
I am no longer experiencing the Security Tool pop-ups.
By reviewing the logs does it seem I've successfully/completely removed the Security Tool virus?
Here are the three logs:
"Attach" log:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 11/4/2008 6:36:17 PM
System Uptime: 12/29/2009 4:19:56 PM (0 hours ago)
Motherboard: Dell Inc. | | 0GD366
Processor: Intel® Pentium® M processor 1.73GHz | Microprocessor | 1729/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 34 GiB total, 23.995 GiB free.
D: is CDROM (CDFS)
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller
Device ID: PCI\VEN_8086&DEV_2792&SUBSYS_01C91028&REV_03\3&61AAA01&0&11
Manufacturer:
Name: Video Controller
PNP Device ID: PCI\VEN_8086&DEV_2792&SUBSYS_01C91028&REV_03\3&61AAA01&0&11
Service:
==== System Restore Points ===================
RP99: 9/29/2009 11:27:14 AM - System Checkpoint
RP100: 10/1/2009 8:45:39 PM - System Checkpoint
RP101: 10/14/2009 3:34:07 PM - System Checkpoint
RP102: 10/15/2009 2:32:39 PM - Software Distribution Service 3.0
RP103: 10/20/2009 9:36:27 AM - System Checkpoint
RP104: 10/20/2009 11:03:54 AM - Installed Compatibility Pack for the 2007 Office system
RP105: 10/20/2009 11:27:49 PM - Software Distribution Service 3.0
RP106: 10/21/2009 11:31:11 PM - System Checkpoint
RP107: 10/22/2009 12:05:23 AM - Software Distribution Service 3.0
RP108: 10/24/2009 2:50:17 PM - System Checkpoint
RP109: 10/25/2009 3:18:41 PM - System Checkpoint
RP110: 10/26/2009 4:29:10 PM - Software Distribution Service 3.0
RP111: 10/28/2009 8:25:54 AM - System Checkpoint
RP112: 10/28/2009 5:01:58 PM - Software Distribution Service 3.0
RP113: 10/28/2009 9:47:40 PM - Software Distribution Service 3.0
RP114: 10/29/2009 3:25:36 PM - Software Distribution Service 3.0
RP115: 10/31/2009 9:05:35 PM - System Checkpoint
RP116: 11/2/2009 10:34:05 AM - System Checkpoint
RP117: 11/3/2009 8:28:59 PM - System Checkpoint
RP118: 11/4/2009 10:44:14 PM - Software Distribution Service 3.0
RP119: 11/7/2009 2:53:17 PM - System Checkpoint
RP120: 11/9/2009 8:16:56 AM - System Checkpoint
RP121: 11/10/2009 7:33:04 PM - System Checkpoint
RP122: 11/11/2009 7:34:59 PM - System Checkpoint
RP123: 11/11/2009 7:41:38 PM - Software Distribution Service 3.0
RP124: 11/15/2009 1:55:54 PM - System Checkpoint
RP125: 11/19/2009 8:51:56 AM - System Checkpoint
RP126: 11/20/2009 12:39:52 PM - System Checkpoint
RP127: 11/22/2009 9:19:11 AM - System Checkpoint
RP128: 11/23/2009 8:31:32 PM - System Checkpoint
RP129: 11/25/2009 12:30:14 PM - System Checkpoint
RP130: 11/25/2009 4:26:00 PM - Software Distribution Service 3.0
RP131: 11/28/2009 9:13:42 PM - System Checkpoint
RP132: 12/4/2009 9:50:11 AM - System Checkpoint
RP133: 12/6/2009 8:08:02 PM - System Checkpoint
RP134: 12/8/2009 4:55:58 PM - Software Distribution Service 3.0
RP135: 12/10/2009 9:55:58 PM - System Checkpoint
RP136: 12/13/2009 9:10:40 PM - System Checkpoint
RP137: 12/16/2009 3:39:12 PM - System Checkpoint
RP138: 12/18/2009 1:37:07 PM - System Checkpoint
RP139: 12/18/2009 3:30:31 PM - Software Distribution Service 3.0
RP140: 12/19/2009 7:05:00 PM - System Checkpoint
RP141: 12/20/2009 9:51:24 PM - System Checkpoint
RP142: 12/24/2009 3:08:37 PM - System Checkpoint
RP143: 12/25/2009 4:00:12 PM - System Checkpoint
RP144: 12/26/2009 10:59:29 PM - System Checkpoint
RP145: 12/29/2009 4:26:58 PM - Software Distribution Service 3.0
==== Installed Programs ======================
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
ArcSoft PhotoImpression 6
ArcSoft Print Creations
Avira AntiVir Personal - Free Antivirus
Broadcom 440x 10/100 Integrated Controller
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Critical Update for Windows Media Player 11 (KB959772)
Dell Wireless WLAN Card
EPSON CX7400 User's Guide
EPSON Printer Software
Foxit Reader
GoToMeeting 4.1.0.366
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel® Graphics Media Accelerator Driver for Mobile
Linksys Wireless-G Print Server
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Resource Kit
Microsoft Office FrontPage 2003
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote 2003
Microsoft Office Professional Edition 2003
Microsoft Office Visio Professional 2003
Microsoft Project 98
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.0.10)
MSN
PANTECH UM175 Driver
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SigmaTel Audio
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VLC media player 0.9.9
VZAccess Manager
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
12/29/2009 4:27:46 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 8 for Windows XP.
12/29/2009 4:20:30 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
12/29/2009 4:20:29 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
12/29/2009 1:28:15 PM, error: PlugPlayManager [12] - The device 'PANTECH UM175 WWAN Driver #2' (USB\VID_106c&PID_3714&MI_03\6&26ebccad&0&8515) disappeared from the system without first being prepared for removal.
12/26/2009 4:24:20 PM, error: PlugPlayManager [12] - The device 'PANTECH UM175 WWAN Driver' (USB\VID_106c&PID_3714&MI_03\6&356b9120&0&8515) disappeared from the system without first being prepared for removal.
==== End Of File ===========================
"DDS" log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:48:32.84 on Tue 12/29/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1493 [GMT -8:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Gary\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Network EPSON Stylus CX7400 S…] c:\windows\system32\spool\drivers\w32x86\3\e_faticda.exe /fu "c:\docume~1\gary\locals~1\temp\E_SAD.tmp" /EF "HKCU"
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [52880831] c:\documents and settings\all users\application data\528808311\52880831.exe
StartupFolder: c:\docume~1\gary\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226176821642
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1226732385234
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\gary\applic~1\mozilla\firefox\profiles\e122f5ea.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2008-11-8 11608]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2008-11-8 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2008-11-8 151297]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2008-11-8 52056]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2008-11-14 12032]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2008-11-14 39424]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-1-12 33752]
S3 LKNUCMP;Linksys Network USB Composite Device;c:\windows\system32\drivers\lknucmp.sys [2008-11-14 14848]
S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2008-12-30 29824]
S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2008-12-30 41344]
S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2008-12-30 39936]
S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2008-12-30 59776]
=============== Created Last 30 ================
2009-12-29 16:00 –d—– c:\docume~1\gary\applic~1\Malwarebytes
2009-12-29 16:00 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-29 15:59 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-29 15:59 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-29 15:59 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-29 14:05 –d—– C:\9e968cd39b2ab478fd94cdcd137566
2009-12-29 14:05 –d—– C:\0d91a4a034c136c501987628de2d
2009-12-29 14:05 –d—– C:\f68023020d4e1a2ef0ddbd53da4113
2009-12-09 17:28 –d—– c:\program files\Yahoo!
==================== Find3M ====================
2009-10-28 23:46 832,512 a——- c:\windows\system32\wininet.dll
2009-10-28 23:46 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-28 23:46 17,408 a——- c:\windows\system32\corpol.dll
2009-10-20 21:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 21:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-13 02:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 05:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 05:38 79,872 a——- c:\windows\system32\raschap.dll
============= FINISH: 16:49:01.76 ===============
"mbam" log
Malwarebytes' Anti-Malware 1.42
Database version: 3453
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
12/29/2009 4:18:56 PM
mbam-log-2009-12-29 (16-18-56).txt
Scan type: Quick Scan
Objects scanned: 117497
Time elapsed: 16 minute(s), 34 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\All Users\Application Data\52880831 (Rogue.Multiple) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\All Users\Application Data\52880831\52880831.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gary\Desktop\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gary\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
I notice my internet address bar is http://m.www.yahoo.com the "m" will not disappear even when I try to reset the address bar through internet options to set the homepage. I'm wondering if this is caused by the Security Tool virus?
When I go to start, My Computer, C drive, there is no address bar. I tried to create an address bar through the tools, view address bar, but it still will not create an address bar. Is this caused by the Security Tool virus?
I am no longer experiencing the Security Tool pop-ups.
By reviewing the logs does it seem I've successfully/completely removed the Security Tool virus?
Here are the three logs:
"Attach" log:
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-06-26.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume2
Install Date: 11/4/2008 6:36:17 PM
System Uptime: 12/29/2009 4:19:56 PM (0 hours ago)
Motherboard: Dell Inc. | | 0GD366
Processor: Intel® Pentium® M processor 1.73GHz | Microprocessor | 1729/133mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 34 GiB total, 23.995 GiB free.
D: is CDROM (CDFS)
==== Disabled Device Manager Items =============
Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Video Controller
Device ID: PCI\VEN_8086&DEV_2792&SUBSYS_01C91028&REV_03\3&61AAA01&0&11
Manufacturer:
Name: Video Controller
PNP Device ID: PCI\VEN_8086&DEV_2792&SUBSYS_01C91028&REV_03\3&61AAA01&0&11
Service:
==== System Restore Points ===================
RP99: 9/29/2009 11:27:14 AM - System Checkpoint
RP100: 10/1/2009 8:45:39 PM - System Checkpoint
RP101: 10/14/2009 3:34:07 PM - System Checkpoint
RP102: 10/15/2009 2:32:39 PM - Software Distribution Service 3.0
RP103: 10/20/2009 9:36:27 AM - System Checkpoint
RP104: 10/20/2009 11:03:54 AM - Installed Compatibility Pack for the 2007 Office system
RP105: 10/20/2009 11:27:49 PM - Software Distribution Service 3.0
RP106: 10/21/2009 11:31:11 PM - System Checkpoint
RP107: 10/22/2009 12:05:23 AM - Software Distribution Service 3.0
RP108: 10/24/2009 2:50:17 PM - System Checkpoint
RP109: 10/25/2009 3:18:41 PM - System Checkpoint
RP110: 10/26/2009 4:29:10 PM - Software Distribution Service 3.0
RP111: 10/28/2009 8:25:54 AM - System Checkpoint
RP112: 10/28/2009 5:01:58 PM - Software Distribution Service 3.0
RP113: 10/28/2009 9:47:40 PM - Software Distribution Service 3.0
RP114: 10/29/2009 3:25:36 PM - Software Distribution Service 3.0
RP115: 10/31/2009 9:05:35 PM - System Checkpoint
RP116: 11/2/2009 10:34:05 AM - System Checkpoint
RP117: 11/3/2009 8:28:59 PM - System Checkpoint
RP118: 11/4/2009 10:44:14 PM - Software Distribution Service 3.0
RP119: 11/7/2009 2:53:17 PM - System Checkpoint
RP120: 11/9/2009 8:16:56 AM - System Checkpoint
RP121: 11/10/2009 7:33:04 PM - System Checkpoint
RP122: 11/11/2009 7:34:59 PM - System Checkpoint
RP123: 11/11/2009 7:41:38 PM - Software Distribution Service 3.0
RP124: 11/15/2009 1:55:54 PM - System Checkpoint
RP125: 11/19/2009 8:51:56 AM - System Checkpoint
RP126: 11/20/2009 12:39:52 PM - System Checkpoint
RP127: 11/22/2009 9:19:11 AM - System Checkpoint
RP128: 11/23/2009 8:31:32 PM - System Checkpoint
RP129: 11/25/2009 12:30:14 PM - System Checkpoint
RP130: 11/25/2009 4:26:00 PM - Software Distribution Service 3.0
RP131: 11/28/2009 9:13:42 PM - System Checkpoint
RP132: 12/4/2009 9:50:11 AM - System Checkpoint
RP133: 12/6/2009 8:08:02 PM - System Checkpoint
RP134: 12/8/2009 4:55:58 PM - Software Distribution Service 3.0
RP135: 12/10/2009 9:55:58 PM - System Checkpoint
RP136: 12/13/2009 9:10:40 PM - System Checkpoint
RP137: 12/16/2009 3:39:12 PM - System Checkpoint
RP138: 12/18/2009 1:37:07 PM - System Checkpoint
RP139: 12/18/2009 3:30:31 PM - Software Distribution Service 3.0
RP140: 12/19/2009 7:05:00 PM - System Checkpoint
RP141: 12/20/2009 9:51:24 PM - System Checkpoint
RP142: 12/24/2009 3:08:37 PM - System Checkpoint
RP143: 12/25/2009 4:00:12 PM - System Checkpoint
RP144: 12/26/2009 10:59:29 PM - System Checkpoint
RP145: 12/29/2009 4:26:58 PM - Software Distribution Service 3.0
==== Installed Programs ======================
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
ArcSoft PhotoImpression 6
ArcSoft Print Creations
Avira AntiVir Personal - Free Antivirus
Broadcom 440x 10/100 Integrated Controller
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Critical Update for Windows Media Player 11 (KB959772)
Dell Wireless WLAN Card
EPSON CX7400 User's Guide
EPSON Printer Software
Foxit Reader
GoToMeeting 4.1.0.366
High Definition Audio Driver Package - KB888111
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Intel® Graphics Media Accelerator Driver for Mobile
Linksys Wireless-G Print Server
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB953297)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Resource Kit
Microsoft Office FrontPage 2003
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote 2003
Microsoft Office Professional Edition 2003
Microsoft Office Visio Professional 2003
Microsoft Project 98
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Mozilla Firefox (3.0.10)
MSN
PANTECH UM175 Driver
Security Update for Windows Internet Explorer 7 (KB938127-v2)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956390)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
SigmaTel Audio
Synaptics Pointing Device Driver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VLC media player 0.9.9
VZAccess Manager
WebFldrs XP
Windows Genuine Advantage Validation Tool (KB892130)
Windows Internet Explorer 7
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Player 11
Windows Search 4.0
Windows XP Service Pack 3
Yahoo! Messenger
Yahoo! Search Protection
Yahoo! Software Update
Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
12/29/2009 4:27:46 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Internet Explorer 8 for Windows XP.
12/29/2009 4:20:30 PM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: PCIIde
12/29/2009 4:20:29 PM, error: sr [1] - The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume2'. It has stopped monitoring the volume.
12/29/2009 1:28:15 PM, error: PlugPlayManager [12] - The device 'PANTECH UM175 WWAN Driver #2' (USB\VID_106c&PID_3714&MI_03\6&26ebccad&0&8515) disappeared from the system without first being prepared for removal.
12/26/2009 4:24:20 PM, error: PlugPlayManager [12] - The device 'PANTECH UM175 WWAN Driver' (USB\VID_106c&PID_3714&MI_03\6&356b9120&0&8515) disappeared from the system without first being prepared for removal.
==== End Of File ===========================
"DDS" log:
DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 16:48:32.84 on Tue 12/29/2009
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2039.1493 [GMT -8:00]
AV: Avira AntiVir PersonalEdition *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
svchost.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Gary\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://www.yahoo.com/
mDefault_Page_URL = hxxp://www.yahoo.com
mStart Page = hxxp://www.yahoo.com
BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\progra~1\yahoo!\companion\installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\progra~1\yahoo!\companion\installs\cpn\yt.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [Network EPSON Stylus CX7400 S…] c:\windows\system32\spool\drivers\w32x86\3\e_faticda.exe /fu "c:\docume~1\gary\locals~1\temp\E_SAD.tmp" /EF "HKCU"
uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [Search Protection] c:\program files\yahoo!\search protection\SearchProtection.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe
mRun: [avgnt] "c:\program files\avira\antivir personaledition classic\avgnt.exe" /min
mRun: [PSDiagnosticM] "c:\program files\linksys wireless-g print server\PSDiagnosticM.exe"
mRun: [YSearchProtection] "c:\program files\yahoo!\search protection\SearchProtection.exe"
mRun: [52880831] c:\documents and settings\all users\application data\528808311\52880831.exe
StartupFolder: c:\docume~1\gary\startm~1\programs\startup\vzacce~1.lnk - c:\program files\verizon wireless\vzaccess manager\VZAccess Manager.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~2.lnk - c:\program files\microsoft office\office\FINDFAST.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office11\ONENOTEM.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\office~1.lnk - c:\program files\microsoft office\office\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1226176821642
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1226732385234
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
Notify: igfxcui - igfxdev.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\gary\applic~1\mozilla\firefox\profiles\e122f5ea.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
—- FIREFOX POLICIES —-
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
============= SERVICES / DRIVERS ===============
R1 avgio;avgio;c:\program files\avira\antivir personaledition classic\avgio.sys [2008-11-8 11608]
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler;c:\program files\avira\antivir personaledition classic\sched.exe [2008-11-8 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard;c:\program files\avira\antivir personaledition classic\avguard.exe [2008-11-8 151297]
R2 YahooAUService;Yahoo! Updater;c:\program files\yahoo!\softwareupdate\YahooAUService.exe [2008-11-9 602392]
R3 avgntflt;avgntflt;c:\program files\avira\antivir personaledition classic\avgntflt.sys [2008-11-8 52056]
R3 lknuhst;Linksys Network USB Host Controller;c:\windows\system32\drivers\lknuhst.sys [2008-11-14 12032]
R3 LKNUHUB;Linksys Network USB Root Hub;c:\windows\system32\drivers\lknuhub.sys [2008-11-14 39424]
S3 getPlus® Helper;getPlus® Helper;c:\program files\nos\bin\getPlus_HelperSvc.exe [2009-1-12 33752]
S3 LKNUCMP;Linksys Network USB Composite Device;c:\windows\system32\drivers\lknucmp.sys [2008-11-14 14848]
S3 PTDUBus;PANTECH UM175 Composite Device Driver ;c:\windows\system32\drivers\PTDUBus.sys [2008-12-30 29824]
S3 PTDUMdm;PANTECH UM175 Drivers;c:\windows\system32\drivers\PTDUMdm.sys [2008-12-30 41344]
S3 PTDUVsp;PANTECH UM175 Diagnostic Port;c:\windows\system32\drivers\PTDUVsp.sys [2008-12-30 39936]
S3 PTDUWWAN;PANTECH UM175 WWAN Driver;c:\windows\system32\drivers\PTDUWWAN.sys [2008-12-30 59776]
=============== Created Last 30 ================
2009-12-29 16:00 –d—– c:\docume~1\gary\applic~1\Malwarebytes
2009-12-29 16:00 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-29 15:59 19,160 a——- c:\windows\system32\drivers\mbam.sys
2009-12-29 15:59 –d—– c:\program files\Malwarebytes' Anti-Malware
2009-12-29 15:59 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2009-12-29 14:05 –d—– C:\9e968cd39b2ab478fd94cdcd137566
2009-12-29 14:05 –d—– C:\0d91a4a034c136c501987628de2d
2009-12-29 14:05 –d—– C:\f68023020d4e1a2ef0ddbd53da4113
2009-12-09 17:28 –d—– c:\program files\Yahoo!
==================== Find3M ====================
2009-10-28 23:46 832,512 a——- c:\windows\system32\wininet.dll
2009-10-28 23:46 78,336 a——- c:\windows\system32\ieencode.dll
2009-10-28 23:46 17,408 a——- c:\windows\system32\corpol.dll
2009-10-20 21:38 75,776 a——- c:\windows\system32\strmfilt.dll
2009-10-20 21:38 25,088 a——- c:\windows\system32\httpapi.dll
2009-10-13 02:30 270,336 a——- c:\windows\system32\oakley.dll
2009-10-12 05:38 149,504 a——- c:\windows\system32\rastls.dll
2009-10-12 05:38 79,872 a——- c:\windows\system32\raschap.dll
============= FINISH: 16:49:01.76 ===============
"mbam" log
Malwarebytes' Anti-Malware 1.42
Database version: 3453
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13
12/29/2009 4:18:56 PM
mbam-log-2009-12-29 (16-18-56).txt
Scan type: Quick Scan
Objects scanned: 117497
Time elapsed: 16 minute(s), 34 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\All Users\Application Data\52880831 (Rogue.Multiple) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\All Users\Application Data\52880831\52880831.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gary\Desktop\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.
C:\Documents and Settings\Gary\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.