This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google and Yahoo search redirecting

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all..Hopefully someone can help. using Vista 64bit. I have redirecting going on when I search with either Google or Yahoo. 99% of the time I use Firefox. Typically will redirect to questbooster.com, among others. I ran Malwarebytes initially and it removed some items and I thought I was in the clear. However, it is still occurring and now, Malwarebytes reports zero infections. GMER and F-Secure BlackLight report no rootkits. SuperAntiSpyware & Spybot also report nothing. Let me know if you need HiJackThis log file. Here is DDS log file (Attach.txt is attached): DDS (Ver_09-12-01.01) - NTFSX64 Run by [removed] at 8:58:49.47 on Fri 01/08/2010 Internet Explorer: 7.0.6001.18000 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.4094.2464 [GMT -5:00] SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\COMODO\COMODO Internet Security\cfp.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\CoreTemp64\Core Temp.exe C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files (x86)\ThreatFire\TFTray.exe C:\Program Files (x86)\Nitro PDF\Professional\NitroPDFPrinterMonitor.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe C:\Program Files (x86)\GIGABYTE\EnergySaver\GSvr.exe C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe C:\Program Files (x86)\Yahoo!\Widgets\YahooWidgets.exe C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\System32\svchost.exe -k HPZ12 C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\COMODO\COMODO BackUp\SynchronizationService.exe C:\Program Files (x86)\ThreatFire\TFService.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\sysWOW64\wbem\wmiprvse.exe C:\Windows\splwow64.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\New Gigabyte\Desktop\Computer Protection\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\syswow64\dvmurl.dll TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File uRun: [Core Temp] "c:\program files\coretemp64\Core Temp.exe" mRun: [JMB36X IDE Setup] c:\windows\raidtool\xInsIDE.exe mRun: [ThreatFire] "c:\program files (x86)\threatfire\TFTray.exe" mRun: [Nitro PDF Printer Monitor] "c:\program files (x86)\nitro pdf\professional\NitroPDFPrinterMonitor.exe" mRun: [avgnt] "c:\program files (x86)\avira\antivir desktop\avgnt.exe" /min /ns mRun: [BlackBerryAutoUpdate] c:\program files (x86)\common files\research in motion\auto update\RIMAutoUpdate.exe /background mRun: [StartCCC] "c:\program files (x86)\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [AdobeCS4ServiceManager] "c:\program files (x86)\common files\adobe\cs4servicemanager\CS4ServiceManager.exe" -launchedbylogin StartupFolder: c:\users\newgig~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\thunderbird.lnk - c:\program files (x86)\mozilla thunderbird\thunderbird.exe StartupFolder: c:\users\newgig~1\appdata\roaming\micros~1\windows\startm~1\programs\startup\yahoo! widgets.lnk - c:\program files (x86)\yahoo!\widgets\YahooWidgets.exe uPolicies-explorer: TaskbarNoNotification = 1 (0x1) uPolicies-explorer: HideSCABattery = 0 (0x0) uPolicies-explorer: HideSCANetwork = 0 (0x0) uPolicies-explorer: HideSCAVolume = 0 (0x0) mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0) mPolicies-explorer: TaskbarNoThumbnail = 0 (0x0) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~2\microsoft office\office12\EXCEL.EXE/3000 IE: Locate Spot on Map by GPS - c:\program files (x86)\opanda\iexif 2.3\IExifMap.htm IE: View Exif/GPS/IPTC with IExif - c:\program files (x86)\opanda\iexif 2.3\IExifCom.htm IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~2\microsoft office\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~2\microsoft office\office12\REFIEBAR.DLL DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - c:\program files (x86)\yahoo!\common\Yinsthelper.dll DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files (x86)\microsoft office\office12\GrooveSystemServices.dll Notify: !SASWinLogon - c:\program files (x86)\superantispyware\SASWINLO.dll AppInit_DLLs: c:\windows\syswow64\guard32.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files (x86)\microsoft office\office12\GrooveShellExtensions.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files (x86)\superantispyware\SASSEH.DLL mASetup: Nitro PDF Professional - cscript //B "c:\program files (x86)\nitro pdf\professional\RemoveOldAddins.vbs" TB-X64: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File mRun-x64: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h mRun-x64: [RtHDVCpl] c:\program files\realtek\audio\hda\RAVCpl64.exe -s AppInit_DLLs-X64: c:\windows\system32\guard64.dll ================= FIREFOX =================== FF - ProfilePath - c:\users\newgig~1\appdata\roaming\mozilla\firefox\profiles\aa8l98t3.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/ FF - plugin: c:\program files (x86)\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll FF - plugin: c:\program files (x86)\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files (x86)\google\update\1.2.183.13\npGoogleOneClick8.dll FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npq3plug.dll FF - plugin: c:\program files (x86)\mozilla firefox\plugins\npyaxmpb.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Internal security: No Registry Reference - c:\program files (x86)\mozilla firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D} —- FIREFOX POLICIES —- c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); ============= SERVICES / DRIVERS =============== R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [2010-1-2 37392] R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [2009-12-4 65072] R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [2009-12-4 59880] R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [2009-12-4 118600] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2009-12-4 33128] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-26 202752] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\avira\antivir desktop\sched.exe [2009-12-4 108289] R2 AntiVirService;Avira AntiVir Guard;c:\program files (x86)\avira\antivir desktop\avguard.exe [2009-12-4 185089] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2009-12-4 74880] R2 GEST Service;GEST Service for program management.;c:\program files (x86)\gigabyte\energysaver\GSvr.exe [2009-1-11 68136] R2 SynchronizationService.exe;Synchronization Service;c:\program files (x86)\comodo\comodo backup\SynchronizationService.exe [2009-10-30 658944] R2 ThreatFire;ThreatFire;c:\program files (x86)\threatfire\tfservice.exe service –> c:\program files (x86)\threatfire\TFService.exe service [?] R3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [2009-12-4 41888] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\spybot - search & destroy\SDWinSec.exe [2010-1-3 1153368] S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;c:\windows\microsoft.net\framework64\v2.0.50727\mscorsvw.exe [2009-12-4 93184] S3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\common files\macrovision shared\flexnet publisher\FNPLicensingService64.exe [2009-12-26 1038088] S3 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2009-12-27 135664] S3 PerfHost;Performance Counter DLL Host;c:\windows\syswow64\perfhost.exe [2008-1-20 19968] =============== Created Last 30 ================ 2010-01-07 14:48:06 0 d—–w- c:\program files (x86)\SUPERAntiSpyware 2010-01-07 14:47:19 0 d—–w- c:\program files (x86)\common files\Wise Installation Wizard 2010-01-06 22:01:21 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf 2010-01-05 21:29:55 0 d—–w- c:\users\newgig~1\appdata\roaming\Malwarebytes 2010-01-05 21:29:51 22104 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-01-05 21:29:51 0 d—–w- c:\programdata\Malwarebytes 2010-01-05 21:29:51 0 d—–w- c:\program files (x86)\Malwarebytes' Anti-Malware 2010-01-05 20:51:21 0 d—–w- c:\programdata\Lavasoft 2010-01-05 20:51:21 0 d—–w- c:\program files (x86)\Lavasoft 2010-01-05 00:13:21 0 d—–w- c:\program files\Adobe 2010-01-05 00:04:57 0 d—–w- c:\programdata\Adobe 2010-01-05 00:04:18 0 d—–w- c:\program files (x86)\common files\Macrovision Shared 2010-01-04 23:50:18 131896 —-a-w- c:\windows\syswow64\GDIPFONTCACHEV1.DAT 2010-01-04 22:58:51 0 d—–w- c:\program files\common files\Adobe 2010-01-04 13:41:15 0 d—–w- c:\users\newgig~1\appdata\roaming\AccurateRip 2010-01-04 05:50:20 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp FLAC Codec.bmp 2010-01-04 05:50:20 3024 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp FLAC Codec.dat 2010-01-04 05:46:16 0 d—–w- c:\program files (x86)\Illustrate 2010-01-04 04:36:53 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp WavPack Codec.bmp 2010-01-04 04:36:53 3013 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp WavPack Codec.dat 2010-01-04 04:36:38 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.bmp 2010-01-04 04:36:38 3036 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Ogg Vorbis Codec.dat 2010-01-04 04:36:03 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Musepack Codec.bmp 2010-01-04 04:36:03 3289 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Musepack Codec.dat 2010-01-04 04:35:48 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Monkeys Audio Codec.bmp 2010-01-04 04:35:48 3113 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Monkeys Audio Codec.dat 2010-01-04 04:35:11 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Midi Decoder.bmp 2010-01-04 04:35:11 2655 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp Midi Decoder.dat 2010-01-04 04:34:40 711 —-a-w- c:\windows\syswow64\SpoonUninstall-dBPowerAMP Dalet codec R2.dat 2010-01-04 04:34:40 28898 —-a-w- c:\windows\syswow64\SpoonUninstall-dBPowerAMP Dalet codec R2.bmp 2010-01-04 04:34:11 33846 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp CLI Encoder.bmp 2010-01-04 04:34:11 2989 —-a-w- c:\windows\syswow64\SpoonUninstall-dBpoweramp CLI Encoder.dat 2010-01-04 00:09:29 0 d—–w- c:\programdata\Spybot - Search & Destroy 2010-01-04 00:09:29 0 d—–w- c:\program files (x86)\Spybot - Search & Destroy 2010-01-03 22:56:50 0 d—–w- c:\users\newgig~1\appdata\roaming\SUPERAntiSpyware.com 2010-01-03 22:56:50 0 d—–w- c:\programdata\SUPERAntiSpyware.com 2010-01-03 21:32:04 0 d—–w- c:\programdata\F-Secure 2010-01-03 20:03:38 339968 —-a-w- c:\windows\update.exe 2010-01-03 18:28:57 0 d—–w- c:\program files (x86)\Panda Security 2010-01-02 18:43:12 0 d—–w- c:\programdata\Paragon 2010-01-02 18:41:47 0 d-sh–w- c:\users\newgig~1\appdata\roaming\SystemProc 2010-01-02 18:35:51 37392 —-a-w- c:\windows\system32\drivers\hotcore3.sys 2010-01-02 18:35:07 0 d—–w- c:\program files (x86)\Paragon_Software 2010-01-02 17:14:54 0 d—–w- c:\program files (x86)\WinMend 2010-01-02 16:40:35 0 —-a-w- c:\windows\system32\cbu_monitor_items 2010-01-02 16:38:50 0 d—–w- c:\program files (x86)\COMODO 2010-01-01 06:23:07 0 d—–w- c:\program files (x86)\Qtracker 2009-12-31 21:59:44 0 d—–w- c:\program files\7-Zip 2009-12-31 21:43:33 522928 —-a-w- c:\windows\syswow64\SpoonUninstall.exe 2009-12-31 05:08:09 178800 —-a-w- c:\windows\syswow64\CmdLineExt_x64.dll 2009-12-31 05:01:06 66872 —-a-w- c:\windows\syswow64\PnkBstrA.exe 2009-12-31 02:18:47 0 d—–w- c:\program files (x86)\Attribute Changer 2009-12-30 22:59:52 0 d—–w- c:\program files (x86)\palmOne 2009-12-30 22:58:12 94 —-a-w- c:\windows\family.ini 2009-12-30 16:45:52 0 d—–w- C:\Sony Handheld 2009-12-29 02:25:48 4608 —-a-w- c:\windows\syswow64\mbmiodrvr.sys 2009-12-29 01:57:25 45 —-a-w- c:\windows\syswow64\initdebug.nfo 2009-12-29 01:57:25 0 d—–w- c:\program files (x86)\SpeedFan 2009-12-29 00:25:35 0 d—–w- c:\program files (x86)\Yahoo! 2009-12-28 06:42:49 0 d—–w- c:\users\newgig~1\appdata\roaming\ExportTool 2009-12-28 05:28:44 0 d—–w- c:\program files (x86)\Motherboard Monitor 5 2009-12-28 01:33:43 0 d—–w- c:\program files (x86)\DesktopInfo081 2009-12-27 23:28:45 69 —-a-w- c:\windows\NeroDigital.ini 2009-12-27 22:41:53 0 d—–w- c:\program files (x86)\Nero 2009-12-27 22:41:28 0 d—–w- c:\programdata\Nero 2009-12-27 18:34:21 0 d—–w- c:\program files\DIPS64 2009-12-27 18:17:59 0 d—–w- c:\program files\xp-AntiSpy_english 2009-12-27 17:45:46 327168 —-a-w- c:\windows\syswow64\cutil32.dll 2009-12-27 17:45:46 285696 —-a-w- c:\windows\syswow64\cudart.dll 2009-12-27 17:45:46 27136 —-a-w- c:\windows\syswow64\PCWizard.cpl 2009-12-27 17:45:46 0 d—–w- c:\windows\Java 2009-12-27 17:45:45 0 d—–w- c:\program files (x86)\CPUID 2009-12-27 17:38:26 0 d—–w- c:\program files (x86)\cpuz64_153 2009-12-27 17:35:46 0 d—–w- c:\program files (x86)\HWMonitorPro64_108 2009-12-27 17:24:20 0 d—–w- c:\program files\CoreTemp64 2009-12-27 17:12:29 0 d—–w- c:\program files (x86)\Opanda 2009-12-27 16:55:55 0 d—–w- c:\users\newgig~1\appdata\roaming\PhotoFiltre 2009-12-27 16:55:53 0 d—–w- c:\program files (x86)\PhotoFiltre 2009-12-27 16:53:02 0 d—–w- c:\users\newgig~1\appdata\roaming\LockHunter 2009-12-27 16:52:47 0 d—–w- c:\program files\LockHunter 2009-12-27 02:50:27 0 d—–w- c:\program files (x86)\common files\Autodesk Shared 2009-12-27 02:49:31 0 d—–w- c:\program files\AutoCAD 2010 2009-12-27 02:00:11 0 d—–w- c:\programdata\FLEXnet 2009-12-27 01:54:24 0 d—–w- c:\program files\common files\Macrovision Shared 2009-12-27 01:52:35 0 d—–w- c:\program files\common files\Autodesk Shared 2009-12-27 01:51:59 529424 —-a-w- c:\windows\system32\d3dx10_37.dll 2009-12-27 01:51:59 4910088 —-a-w- c:\windows\system32\D3DX9_37.dll 2009-12-27 01:51:59 462864 —-a-w- c:\windows\syswow64\d3dx10_37.dll 2009-12-27 01:51:59 3786760 —-a-w- c:\windows\syswow64\D3DX9_37.dll 2009-12-27 01:51:59 1860120 —-a-w- c:\windows\system32\D3DCompiler_37.dll 2009-12-27 01:51:59 1420824 —-a-w- c:\windows\syswow64\D3DCompiler_37.dll 2009-12-27 01:51:47 2388176 —-a-w- c:\windows\syswow64\d3dx9_30.dll 2009-12-27 01:41:02 0 d—–w- C:\Autodesk 2009-12-26 21:35:23 0 d—–w- c:\programdata\Autodesk 2009-12-26 21:23:15 372736 —-a-w- c:\windows\system32\unregmp2.exe 2009-12-26 21:23:15 310784 —-a-w- c:\windows\syswow64\unregmp2.exe 2009-12-26 21:23:14 10624000 —-a-w- c:\windows\syswow64\wmp.dll 2009-12-26 21:23:12 8147456 —-a-w- c:\windows\syswow64\wmploc.DLL 2009-12-26 21:23:11 8147968 —-a-w- c:\windows\system32\wmploc.DLL 2009-12-26 21:22:57 28672 —-a-w- c:\windows\syswow64\Apphlpdm.dll 2009-12-26 21:22:56 4240384 —-a-w- c:\windows\syswow64\GameUXLegacyGDFs.dll 2009-12-26 21:22:56 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2009-12-26 21:22:56 32256 —-a-w- c:\windows\system32\Apphlpdm.dll 2009-12-26 21:22:54 880640 —-a-w- c:\windows\system32\timedate.cpl 2009-12-26 21:22:53 714240 —-a-w- c:\windows\syswow64\timedate.cpl 2009-12-26 20:17:34 0 d—–w- c:\programdata\ATI 2009-12-26 19:40:16 0 d—–w- c:\program files (x86)\WinAce 2009-12-26 06:36:28 0 d—a-w- c:\programdata\TEMP 2009-12-26 06:34:33 0 d—–w- c:\program files (x86)\IMSIDesign 2009-12-26 06:30:52 0 d—–w- c:\users\newgig~1\appdata\roaming\IMSIDesign 2009-12-26 05:22:48 23466 —-a-w- C:\acadminidump.dmp 2009-12-26 05:19:08 0 d—–w- c:\users\newgig~1\appdata\roaming\Autodesk 2009-12-25 16:49:31 19208 —-a-w- c:\windows\system32\drivers\ss_mdfl.sys 2009-12-25 16:49:31 15624 —-a-w- c:\windows\system32\drivers\ss_whnt.sys 2009-12-25 16:49:31 15624 —-a-w- c:\windows\system32\drivers\ss_wh.sys 2009-12-25 16:49:31 15112 —-a-w- c:\windows\system32\drivers\ss_cmnt.sys 2009-12-25 16:49:31 15112 —-a-w- c:\windows\system32\drivers\ss_cm.sys 2009-12-25 16:49:31 145160 —-a-w- c:\windows\system32\drivers\ss_mdm.sys 2009-12-25 16:49:31 108296 —-a-w- c:\windows\system32\drivers\ss_bus.sys 2009-12-25 16:49:31 0 d—–w- c:\windows\syswow64\Samsung_USB_Drivers 2009-12-25 16:49:26 766 —-a-w- c:\windows\syswow64\Uninstall.ico 2009-12-25 16:49:25 0 d—–w- c:\program files (x86)\Samsung 2009-12-25 06:27:42 8 —-a-w- c:\windows\system32\drivers\rtkhdaud.dat 2009-12-25 05:39:25 88064 —-a-w- c:\windows\system32\CmdRtr64.DLL 2009-12-25 05:39:25 72704 —-a-w- c:\windows\syswow64\CmdRtr.DLL 2009-12-25 05:39:25 188416 —-a-w- c:\windows\system32\APOMgr64.DLL 2009-12-25 05:39:25 159 —ha-r- c:\windows\ctfile.rfc 2009-12-25 05:39:25 146432 —-a-w- c:\windows\syswow64\APOMngr.DLL 2009-12-25 05:38:48 0 d—–w- c:\program files\Realtek 2009-12-25 05:32:31 0 d–h–w- c:\program files (x86)\Temp 2009-12-25 00:43:26 130 —-a-w- c:\windows\cfplogvw.INI 2009-12-24 16:18:59 0 d—–w- c:\program files (x86)\uTorrent 2009-12-24 16:18:19 0 d—–w- c:\users\newgig~1\appdata\roaming\uTorrent 2009-12-24 14:16:41 0 d—–w- c:\program files (x86)\DC++ 2009-12-24 13:37:38 0 d—–w- c:\users\newgig~1\appdata\roaming\DC++ 2009-12-24 05:35:20 0 d—–w- c:\program files (x86)\MSXML 4.0 2009-12-24 04:57:40 0 d—–w- c:\windows\PCHEALTH 2009-12-24 04:56:08 0 d—–w- c:\program files\Microsoft Office 2009-12-24 04:56:02 0 d—–w- c:\program files (x86)\Microsoft Visual Studio 8 2009-12-24 04:55:27 0 d—–w- c:\windows\SHELLNEW 2009-12-24 04:55:06 0 d—–w- c:\programdata\Microsoft Help 2009-12-24 04:26:17 0 d—–w- c:\program files (x86)\MozBackup 2009-12-24 04:17:28 0 d—–w- c:\program files (x86)\AnalogX 2009-12-24 03:15:31 0 d—–w- C:\Account Drawings 2009-12-24 03:07:04 256 —-a-w- c:\windows\syswow64\pool.bin 2009-12-24 03:06:51 0 d—–w- c:\users\newgig~1\appdata\roaming\Research In Motion 2009-12-24 03:05:27 31744 —-a-w- c:\windows\system32\drivers\RimSerial_AMD64.sys 2009-12-24 03:04:37 0 d—–w- c:\programdata\Research In Motion 2009-12-24 03:04:26 0 d—–w- c:\program files (x86)\common files\Research In Motion 2009-12-24 03:04:25 0 d—–w- c:\program files (x86)\Research In Motion 2009-12-24 02:57:32 0 d—–w- C:\Garland Company 2009-12-24 02:36:59 0 d—–w- c:\windows\pss 2009-12-24 02:25:44 0 d—–w- c:\users\newgig~1\appdata\roaming\Printer Info Cache 2009-12-24 02:20:09 0 d—–w- c:\programdata\HPSSUPPLY 2009-12-24 02:18:18 0 d—–w- c:\program files (x86)\common files\HP 2009-12-24 02:17:54 0 d—–w- c:\program files (x86)\common files\Hewlett-Packard 2009-12-24 02:17:50 0 d—–w- c:\windows\syswow64\spool 2009-12-24 02:16:34 0 d—–w- c:\programdata\Hewlett-Packard 2009-12-24 02:15:18 131072 —-a-w- c:\windows\system32\hpz3l4x6.dll 2009-12-24 02:15:07 0 d—–w- c:\windows\marco 2009-12-24 02:15:03 0 d—–w- c:\program files (x86)\HP 2009-12-24 02:14:20 136415 —-a-w- c:\windows\hpwins10.dat 2009-12-24 02:14:20 1042 ——w- c:\windows\hpwmdl10.dat 2009-12-24 02:14:15 0 d—–w- c:\programdata\HP 2009-12-24 02:14:09 861184 —-a-w- c:\windows\system32\hpwwiax2.dll 2009-12-24 02:14:09 540672 —-a-w- c:\windows\system32\hppldcoi.dll 2009-12-24 02:14:09 508928 —-a-w- c:\windows\system32\difxapi.dll 2009-12-24 02:14:09 488960 —-a-w- c:\windows\system32\hpovst11.dll 2009-12-24 02:14:09 1291776 —-a-w- c:\windows\system32\hpwtiop2.dll 2009-12-24 02:14:08 1651800 —-a-w- c:\windows\hpzshl40.exe 2009-12-24 02:14:08 1359960 —-a-w- c:\windows\hpzmsi40.exe 2009-12-24 02:14:06 10376 —-a-w- c:\windows\hpwscr10.dat 2009-12-24 02:00:59 0 d—–w- c:\program files (x86)\dayam NFO Viewer 2009-12-24 01:49:17 0 d—–w- C:\NotesSQL 2009-12-24 01:49:17 0 d—–w- C:\Notes 2009-12-24 01:22:11 0 d—–w- c:\program files (x86)\Winamp Detect 2009-12-23 23:46:39 33280 —-a-w- c:\windows\system32\drivers\HPZius12.sys 2009-12-23 23:46:39 269824 —-a-w- c:\windows\system32\drivers\HPZid412.sys 2009-12-23 23:46:38 51200 —-a-w- c:\windows\system32\drivers\HPZipr12.sys 2009-12-23 23:46:33 338944 —-a-w- c:\windows\system32\hpzids40.dll 2009-12-23 23:46:32 49152 —-a-w- c:\windows\system32\hpz3l4sa.dll 2009-12-23 23:46:09 286720 —-a-w- c:\windows\system32\HPZc3212.dll 2009-12-23 23:46:09 1314304 —-a-w- c:\windows\system32\hpwtiop1.dll 2009-12-23 23:46:09 1246208 —-a-w- c:\windows\system32\hpwwiax1.dll 2009-12-23 23:46:08 488960 —-a-w- c:\windows\system32\hpovst09.dll 2009-12-23 21:19:29 32768 —-a-w- c:\windows\system32\nshhttp.dll 2009-12-23 21:19:29 24064 —-a-w- c:\windows\syswow64\nshhttp.dll 2009-12-23 21:19:25 610304 —-a-w- c:\windows\system32\drivers\http.sys 2009-12-23 21:19:25 33792 —-a-w- c:\windows\system32\httpapi.dll 2009-12-23 21:19:25 31232 —-a-w- c:\windows\syswow64\httpapi.dll 2009-12-23 13:28:09 442368 —-a-w- c:\windows\system32\winhttp.dll 2009-12-23 13:28:09 378368 —-a-w- c:\windows\syswow64\winhttp.dll ==================== Find3M ==================== 2010-01-07 16:16:20 24072 —-a-w- c:\windows\gdrv.sys 2009-12-30 23:00:27 86016 —-a-w- c:\windows\inf\infstor.dat 2009-12-30 23:00:27 51200 —-a-w- c:\windows\inf\infpub.dat 2009-12-30 23:00:26 143360 —-a-w- c:\windows\inf\infstrng.dat 2009-12-29 02:10:25 6656 —-a-w- c:\windows\system32\lpcio.dll 2009-12-25 05:38:11 525792 —-a-w- c:\windows\DIFxAPI.dll 2009-12-23 13:17:29 74880 —-a-w- c:\windows\system32\drivers\avgntflt.sys 2009-12-11 00:32:16 1694240 —-a-w- c:\windows\system32\RtPgEx64.dll 2009-12-11 00:32:10 332320 —-a-w- c:\windows\system32\RtlCPAPI64.dll 2009-12-11 00:32:10 149536 —-a-w- c:\windows\system32\RtkCfg64.dll 2009-12-11 00:32:04 475168 —-a-w- c:\windows\system32\RtkApi64.dll 2009-12-11 00:32:04 1639968 —-a-w- c:\windows\system32\RtkAPO64.dll 2009-12-11 00:32:04 1201184 —-a-w- c:\windows\system32\RTCOM64.dll 2009-12-11 00:31:58 68640 —-a-w- c:\windows\system32\RCoInst64.dll 2009-12-10 22:38:22 2222624 —-a-w- c:\windows\system32\drivers\RTKVHD64.sys 2009-12-04 23:26:12 328096 —-a-w- c:\windows\system32\FMAPO64.dll 2009-12-04 21:03:56 33128 —-a-w- c:\windows\system32\drivers\cmdhlp.sys 2009-12-04 21:03:56 239616 —-a-w- c:\windows\system32\guard64.dll 2009-12-04 21:03:56 171552 —-a-w- c:\windows\syswow64\guard32.dll 2009-12-04 21:03:56 118600 —-a-w- c:\windows\system32\drivers\cmdguard.sys 2009-11-25 03:52:14 6174720 —-a-w- c:\windows\system32\drivers\atikmdag.sys 2009-11-25 03:18:02 446464 —-a-w- c:\windows\system32\ATIDEMGX.dll 2009-11-25 03:17:52 446976 —-a-w- c:\windows\system32\atieclxx.exe 2009-11-25 03:17:16 202752 —-a-w- c:\windows\system32\atiesrxx.exe 2009-11-25 03:15:54 120320 —-a-w- c:\windows\system32\atitmm64.dll 2009-11-25 03:15:36 421376 —-a-w- c:\windows\system32\atipdl64.dll 2009-11-25 03:15:28 356352 —-a-w- c:\windows\syswow64\atipdlxx.dll 2009-11-25 03:15:14 274432 —-a-w- c:\windows\syswow64\Oemdspif.dll 2009-11-25 03:15:06 12288 —-a-w- c:\windows\system32\atimuixx.dll 2009-11-25 03:15:02 59392 —-a-w- c:\windows\system32\atiedu64.dll 2009-11-25 03:14:58 43520 —-a-w- c:\windows\syswow64\ati2edxx.dll 2009-11-25 03:12:12 3055616 —-a-w- c:\windows\syswow64\atidxx32.dll 2009-11-25 03:04:30 3661824 —-a-w- c:\windows\system32\atidxx64.dll 2009-11-25 03:02:20 17625088 —-a-w- c:\windows\system32\atio6axx.dll 2009-11-25 02:55:58 3617792 —-a-w- c:\windows\syswow64\atiumdag.dll 2009-11-25 02:50:14 4683776 —-a-w- c:\windows\system32\atiumd64.dll 2009-11-25 02:44:56 13487616 —-a-w- c:\windows\syswow64\atioglxx.dll 2009-11-25 02:43:54 2601984 —-a-w- c:\windows\system32\atiumd6a.dll 2009-11-25 02:37:58 2899968 —-a-w- c:\windows\syswow64\atiumdva.dll 2009-11-25 02:25:46 53248 —-a-w- c:\windows\system32\atimpc64.dll 2009-11-25 02:25:46 53248 —-a-w- c:\windows\system32\amdpcom64.dll 2009-11-25 02:25:38 52224 —-a-w- c:\windows\syswow64\atimpc32.dll 2009-11-25 02:25:38 52224 —-a-w- c:\windows\syswow64\amdpcom32.dll 2009-11-25 02:25:16 312320 —-a-w- c:\windows\system32\atiadlxx.dll 2009-11-25 02:25:08 225280 —-a-w- c:\windows\syswow64\atiadlxy.dll 2009-11-25 02:21:54 43008 —-a-w- c:\windows\system32\aticalrt64.dll 2009-11-25 02:21:52 53248 —-a-w- c:\windows\syswow64\aticalrt.dll 2009-11-25 02:21:38 39936 —-a-w- c:\windows\system32\aticalcl64.dll 2009-11-25 02:21:36 53248 —-a-w- c:\windows\syswow64\aticalcl.dll 2009-11-25 02:21:24 4740096 —-a-w- c:\windows\system32\aticaldd64.dll 2009-11-25 02:20:26 3629056 —-a-w- c:\windows\syswow64\aticaldd.dll 2009-11-25 02:10:14 53248 —-a-w- c:\windows\system32\drivers\ati2erec.dll 2009-11-24 22:40:20 838176 —-a-w- c:\windows\RtlExUpd.dll 2009-11-24 14:55:08 518896 —-a-w- c:\windows\system32\SRSTSX64.dll 2009-11-24 14:55:08 211184 —-a-w- c:\windows\system32\SRSTSH64.dll 2009-11-24 14:55:08 198896 —-a-w- c:\windows\system32\SRSHP64.dll 2009-11-24 14:55:08 155888 —-a-w- c:\windows\system32\SRSWOW64.dll 2009-11-23 17:49:42 59880 —-a-w- c:\windows\system32\drivers\TfSysMon.sys 2009-11-23 17:49:42 41888 —-a-w- c:\windows\system32\drivers\TfNetMon.sys 2009-11-23 17:49:40 65072 —-a-w- c:\windows\system32\drivers\TfFsMon.sys 2009-11-19 03:02:14 4254224 —-a-w- c:\windows\syswow64\qtp-mt334.dll 2009-11-19 03:01:58 249872 —-a-w- c:\windows\syswow64\prgiso.dll 2009-11-18 23:42:48 325904 —-a-w- c:\windows\system32\MaxxAudioAPO20.dll 2009-11-18 23:42:48 2719504 —-a-w- c:\windows\system32\WavesGUILib.dll 2009-11-18 23:42:48 2197264 —-a-w- c:\windows\system32\MaxxAudioEQ.dll 2009-11-18 12:16:00 78936 —-a-w- c:\windows\system32\MBWrp64.dll 2009-11-18 12:13:00 64600 —-a-w- c:\windows\system32\MBppld64.dll 2009-11-18 12:13:00 607832 —-a-w- c:\windows\system32\MBAPO64.dll 2009-11-18 12:13:00 60504 —-a-w- c:\windows\system32\MBPPCn64.dll 2009-11-18 12:13:00 531032 —-a-w- c:\windows\syswow64\MBAPO32.dll 2009-11-17 23:12:40 108960 —-a-w- c:\windows\system32\AERTAR64.dll 2009-11-17 23:09:04 168864 —-a-w- c:\windows\system32\AERTAC64.dll 2009-11-13 20:16:02 95744 —-a-w- c:\windows\system32\RTEEL64A.dll 2009-11-13 20:16:02 73216 —-a-w- c:\windows\system32\RTEEG64A.dll 2009-11-13 20:16:02 363008 —-a-w- c:\windows\system32\RTEEP64A.dll 2009-11-13 20:16:02 198656 —-a-w- c:\windows\system32\RTEED64A.dll 2009-11-03 01:42:06 226688 ——w- c:\windows\system32\MpSigStub.exe 2009-10-29 10:00:13 2048 —-a-w- c:\windows\system32\tzres.dll 2009-10-29 09:41:23 2048 —-a-w- c:\windows\syswow64\tzres.dll 2009-10-27 13:45:07 1032704 —-a-w- c:\windows\system32\wininet.dll 2009-10-27 13:41:03 86528 —-a-w- c:\windows\system32\ieencode.dll 2009-10-27 13:20:19 833024 —-a-w- c:\windows\syswow64\wininet.dll 2009-10-27 13:20:05 1174528 —-a-w- c:\windows\syswow64\urlmon.dll 2009-10-27 13:18:49 146432 —-a-w- c:\windows\syswow64\occache.dll 2009-10-27 13:17:35 671232 —-a-w- c:\windows\syswow64\mstime.dll 2009-10-27 13:17:21 3584000 —-a-w- c:\windows\syswow64\mshtml.dll 2009-10-27 13:17:19 458240 —-a-w- c:\windows\syswow64\msfeeds.dll 2009-10-27 13:16:43 28160 —-a-w- c:\windows\syswow64\jsproxy.dll 2009-10-27 13:16:30 6069248 —-a-w- c:\windows\syswow64\ieframe.dll 2009-10-27 13:16:30 270848 —-a-w- c:\windows\syswow64\iertutil.dll 2009-10-27 13:16:28 78336 —-a-w- c:\windows\syswow64\ieencode.dll 2009-10-27 13:16:28 389120 —-a-w- c:\windows\syswow64\iedkcs32.dll 2009-10-27 13:16:28 380928 —-a-w- c:\windows\syswow64\ieapfltr.dll 2009-10-27 13:16:27 230400 —-a-w- c:\windows\syswow64\ieaksie.dll 2009-10-27 11:20:07 32768 —-a-w- c:\windows\system32\ieUnatt.exe 2009-10-27 10:55:39 26624 —-a-w- c:\windows\syswow64\ieUnatt.exe 2009-10-22 15:59:00 196565 —-a-w- c:\windows\system32\atiicdxx.dat 2009-01-11 17:35:01 665600 —-a-w- c:\windows\inf\drvindex.dat 2008-01-21 03:21:59 174 –sha-w- c:\program files\desktop.ini 2008-01-21 03:21:59 174 –sha-w- c:\program files (x86)\desktop.ini ============= FINISH: 9:01:02.25 =============== 📎Attach__DDS_.txt
Hi,

Interesting stuff, never seen this infection on a 64-bit computer. Ah well, there's a first for everything.

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • GooredFix will check for infections, and then a log will appear. Please post the contents of that log in your next reply (it can also be found on your desktop, called GooredFix.txt).

Let me know if you are still be redirected after that.
Thanks for quick response. I think that cleared it up. No more redirections. :thumbup: So, in so many words, was Firefox infected with a rogue extension or one of my extensions infected? Here is the GooreFix file: GooredFix by jpshortstuff (02.01.10.1) Log created at 13:05 on 08/01/2010 (New Gigabyte) Firefox version 3.5.6 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ [removed] [04:08 24/12/2009] {8CE11043-9A15-4207-A565-0C94C42D590D} [18:41 02/01/2010] {972ce4c6-7e08-4474-a285-3208198ce6fd} [05:16 24/12/2009] C:\Users\New Gigabyte\Application Data\Mozilla\Firefox\Profiles\aa8l98t3.default\extensions\ [removed] [05:16 24/12/2009] [removed] [15:55 04/12/2009] [removed] [05:17 24/12/2009] [removed] [21:24 03/01/2010] [removed] [00:04 13/01/2009] [removed] [12:52 08/01/2010] [removed] [04:28 24/12/2009] yetanothersmoothscrolling@kataho [05:17 24/12/2009] {03B08592-E5B4-45ff-A0BE-C1D975458688} [05:17 24/12/2009] {0545b830-f0aa-4d7e-8820-50a4629a56fe} [05:17 24/12/2009] {0cdfdd5e-eea6-45ff-b035-81243cf02efb} [00:04 13/01/2009] {0e477422-b71d-11db-8314-0800200c9a66} [00:04 13/01/2009] {20a82645-c095-46ed-80e3-08825760534b} [13:55 23/12/2009] {4BBDD651-70CF-4821-84F8-2B918CF89CA3} [20:33 04/12/2009] {77b819fa-95ad-4f2c-ac7c-486b356188a9} [04:28 24/12/2009] {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} [15:49 24/12/2009] {a8dd47cf-239f-48c4-8379-e6b4cbafdcfa} [00:04 13/01/2009] {b9db16a4-6edc-47ec-a1f4-b86292ed211d} [20:33 04/12/2009] {b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2) [04:28 24/12/2009] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [12:52 08/01/2010] {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} [05:17 24/12/2009] {FBF6D7FB-F305-4445-BB3D-FEF66579A033} [23:31 03/01/2010] {FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3} [05:17 24/12/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [16:12 04/12/2009] -=E.O.F=-
Strange that the redirections have gone, because GooredFix didn't actually delete anything. You have a malicious extension which is causing the redirects.

We can still use GooredFix to remove the extension. Please open notepad. Copy and paste the following bolded line into the notepad window:
C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}
Save this file to your Desktop, call it something like script.txt (it doesn't matter what you call it).

Drag the file you saved onto the GooredFix icon. This will launch GooredFix, click Yes when it asks you to scan, and post the log when it pops up.
Yeah, I couldnt get it to do it again after running your original recommendation. Obviously has spotty occurrences. Anyway here is the next log: GooredFix by jpshortstuff (02.01.10.1) Log created at 13:49 on 08/01/2010 (New Gigabyte) Firefox version 3.5.6 (en-US) ========== Script ========== Deleting "C:\Program Files (x86)\Mozilla Firefox\extensions\{8CE11043-9A15-4207-A565-0C94C42D590D}" -> Success! ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ [removed] [04:08 24/12/2009] {972ce4c6-7e08-4474-a285-3208198ce6fd} [05:16 24/12/2009] C:\Users\New Gigabyte\Application Data\Mozilla\Firefox\Profiles\aa8l98t3.default\extensions\ [removed] [05:16 24/12/2009] [removed] [15:55 04/12/2009] [removed] [05:17 24/12/2009] [removed] [21:24 03/01/2010] [removed] [00:04 13/01/2009] [removed] [12:52 08/01/2010] [removed] [04:28 24/12/2009] yetanothersmoothscrolling@kataho [05:17 24/12/2009] {03B08592-E5B4-45ff-A0BE-C1D975458688} [05:17 24/12/2009] {0545b830-f0aa-4d7e-8820-50a4629a56fe} [05:17 24/12/2009] {0cdfdd5e-eea6-45ff-b035-81243cf02efb} [00:04 13/01/2009] {0e477422-b71d-11db-8314-0800200c9a66} [00:04 13/01/2009] {20a82645-c095-46ed-80e3-08825760534b} [13:55 23/12/2009] {4BBDD651-70CF-4821-84F8-2B918CF89CA3} [20:33 04/12/2009] {77b819fa-95ad-4f2c-ac7c-486b356188a9} [04:28 24/12/2009] {9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e} [15:49 24/12/2009] {a8dd47cf-239f-48c4-8379-e6b4cbafdcfa} [00:04 13/01/2009] {b9db16a4-6edc-47ec-a1f4-b86292ed211d} [20:33 04/12/2009] {b9db16a4-6edc-47ec-a1f4-b86292ed211d}(2) [04:28 24/12/2009] {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [12:52 08/01/2010] {d40f5e7b-d2cf-4856-b441-cc613eeffbe3} [05:17 24/12/2009] {FBF6D7FB-F305-4445-BB3D-FEF66579A033} [23:31 03/01/2010] {FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3} [05:17 24/12/2009] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [16:12 04/12/2009] ———- Old Logs ———- GooredFix[18.06.03_08-01-2010].txt -=E.O.F=-
:thumbup:

If you wouldn't mind, I would like a sample of this from your machine. I want to know why GooredFix ignored it the first time round, and update GooredFix to get it automatically. If you wouldn't mind, please do the following steps (which will only take a minute).

Right-click GooredFix Backups on your Desktop, and select Send To -> Compressed (zipped) Folder. This will create a file on your Desktop called GooredFix Backups.zip. Please go to this page and upload the file for me:
http://www.bleepingcomputer.com/submit-mal….php?channel=72
It would be much appreciated.

Afterwards, you can delete the GooredFix Backups and the .zip we made, as well as GooredFix.exe. If you are having no more problems, we can wrap this topic up.

Cheers.
Upload done. And thank you very much for the help which was invaluable. Ill let you know if I have any more problems. Have a great 2010!
Thanks for the upload. Turns out you had a new variant of the infection, that's why it wasn't picked up. Updating GooredFix now to add this variant to the definitions - thanks again!
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI