This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Infection

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey my computer is infected again…please help

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:36:07 PM, on 2/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Application Data\584798d\SA5847.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://m.www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O1 - Hosts: ÿþ127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 74.125.45.100 4-open-davinci.com
O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com
O1 - Hosts: 74.125.45.100 privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com
O1 - Hosts: 74.125.45.100 getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com
O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com
O1 - Hosts: 74.125.45.100 www.getavplusnow.com
O1 - Hosts: 74.125.45.100 safebrowsing-cache.google.com
O1 - Hosts: 74.125.45.100 urs.microsoft.com
O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com
O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com
O1 - Hosts: 74.125.45.100 paysoftbillsolution.com
O1 - Hosts: 74.125.45.100 protected.maxisoftwaremart.com
O1 - Hosts: 94.228.209.243 www.google.com
O1 - Hosts: 94.228.209.243 google.com
O1 - Hosts: 94.228.209.243 google.com.au
O1 - Hosts: 94.228.209.243 www.google.com.au
O1 - Hosts: 94.228.209.243 google.be
O1 - Hosts: 94.228.209.243 www.google.be
O1 - Hosts: 94.228.209.243 google.com.br
O1 - Hosts: 94.228.209.243 www.google.com.br
O1 - Hosts: 94.228.209.243 google.ca
O1 - Hosts: 94.228.209.243 google.ch
O1 - Hosts: 94.228.209.243 www.google.ch
O1 - Hosts: 94.228.209.243 google.de
O1 - Hosts: 94.228.209.243 www.google.de
O1 - Hosts: 94.228.209.243 google.dk
O1 - Hosts: 94.228.209.243 www.google.dk
O1 - Hosts: 94.228.209.243 google.fr
O1 - Hosts: 94.228.209.243 www.google.fr
O1 - Hosts: 94.228.209.243 google.ie
O1 - Hosts: 94.228.209.243 www.google.ie
O1 - Hosts: 94.228.209.243 google.it
O1 - Hosts: 94.228.209.243 www.google.it
O1 - Hosts: 94.228.209.243 google.co.jp
O1 - Hosts: 94.228.209.243 www.google.co.jp
O1 - Hosts: 94.228.209.243 google.nl
O1 - Hosts: 94.228.209.243 www.google.nl
O1 - Hosts: 94.228.209.243 google.no
O1 - Hosts: 94.228.209.243 www.google.no
O1 - Hosts: 94.228.209.243 google.co.nz
O1 - Hosts: 94.228.209.243 www.google.co.nz
O1 - Hosts: 94.228.209.243 google.pl
O1 - Hosts: 94.228.209.243 www.google.pl
O1 - Hosts: 94.228.209.243 google.se
O1 - Hosts: 94.228.209.243 www.google.se
O1 - Hosts: 94.228.209.243 google.co.uk
O1 - Hosts: 94.228.209.243 www.google.co.uk
O1 - Hosts: 94.228.209.243 google.co.za
O1 - Hosts: 94.228.209.243 www.google.co.za
O1 - Hosts: 94.228.209.243 www.google-analytics.com
O1 - Hosts: 94.228.209.243 www.bing.com
O1 - Hosts: 94.228.209.243 search.yahoo.com
O1 - Hosts: 94.228.209.243 www.search.yahoo.com
O1 - Hosts: 94.228.209.243 uk.search.yahoo.com
O1 - Hosts: 94.228.209.243 ca.search.yahoo.com
O1 - Hosts: 94.228.209.243 de.search.yahoo.com
O1 - Hosts: 94.228.209.243 fr.search.yahoo.com
O1 - Hosts: 94.228.209.243 au.search.yahoo.com
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: WOT Helper - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: WOT - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Security Antivirus] "C:\Documents and Settings\All Users\Application Data\584798d\SA5847.exe" /s /d
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 11153 bytes
DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 18:20:47.39 on Mon 02/22/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.247 [GMT -6:00] AV: Security Antivirus *On-access scanning enabled* (Updated) {0522E8A1-CE2C-4743-909F-C9456608B937} AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: Security Antivirus *enabled* {901415E7-E41C-44E8-9E2D-CB60DBCBD26F} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\stsystra.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\eHome\ehmsas.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Skype\Phone\Skype.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\All Users\Application Data\584798d\SA5847.exe C:\Program Files\OpenOffice.org 3\program\soffice.exe C:\Program Files\OpenOffice.org 3\program\soffice.bin C:\Program Files\iPod\bin\iPodService.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Skype\Toolbars\Shared\SkypeNames.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\internet explorer\iexplore.exe C:\Documents and Settings\Shaughnessy\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://m.www.yahoo.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: WOT Helper: {c920e44a-7f78-4e64-bdd7-a57026e7feb7} - c:\program files\wot\WOT.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: WOT: {71576546-354d-41c9-aae8-31f2ec22bf0d} - c:\program files\wot\WOT.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [Skype] "c:\program files\skype\\phone\Skype.exe" /nosplash /minimized uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [Security Antivirus] "c:\documents and settings\all users\application data\584798d\SA5847.exe" /s /d mRun: [ehTray] c:\windows\ehome\ehtray.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [ATIPTA] "c:\program files\ati technologies\ati control panel\atiptaxx.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: c:\docume~1\shaugh~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE StartupFolder: c:\docume~1\shaugh~1\startm~1\programs\startup\openof~1.lnk - c:\program files\openoffice.org 3\program\quickstart.exe IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {5067A26B-1337-4436-8AFE-EE169C2DA79F} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Handler: wot - {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - c:\program files\wot\WOT.dll Notify: avgrsstarter - avgrsstx.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\shaugh~1\applic~1\mozilla\firefox\profiles\a1h6040u.default\ FF - prefs.js: browser.search.selectedEngine - search FF - plugin: c:\documents and settings\shaughnessy\local settings\application data\yahoo!\browserplus\2.4.21\plugins\npybrowserplus_2.4.21.dll FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.13\npGoogleOneClick8.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); ============= SERVICES / DRIVERS =============== R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-12 335240] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-12 27784] R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-12 108552] R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-7-12 908056] R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-12 297752] R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-8-23 38224] R3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\system32\drivers\SMCWGU.sys [2009-7-12 408064] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-9-20 133104] =============== Created Last 30 ================ 2010-02-21 14:19 –dsh— c:\docume~1\shaugh~1\applic~1\Security Antivirus 2010-02-21 14:19 –dsh— c:\docume~1\alluse~1\applic~1\SAAMCLMQDVV 2010-02-21 14:13 –dsh— c:\docume~1\alluse~1\applic~1\584798d 2010-01-31 18:23 8,704 ac—— c:\windows\system32\dllcache\kbdjpn.dll 2010-01-31 18:23 8,192 ac—— c:\windows\system32\dllcache\kbdkor.dll 2010-01-31 18:23 6,144 ac—— c:\windows\system32\dllcache\kbd101c.dll 2010-01-31 18:23 5,632 ac—— c:\windows\system32\dllcache\kbd103.dll 2010-01-31 18:23 8,704 a——- c:\windows\system32\kbdjpn.dll 2010-01-31 18:23 8,192 a——- c:\windows\system32\kbdkor.dll 2010-01-31 18:23 6,144 a——- c:\windows\system32\kbd101c.dll 2010-01-31 18:23 5,632 a——- c:\windows\system32\kbd103.dll 2010-01-31 18:23 6,144 ac—— c:\windows\system32\dllcache\kbd101b.dll 2010-01-31 18:23 6,144 a——- c:\windows\system32\kbd101b.dll 2010-01-31 18:23 6,144 ac—— c:\windows\system32\dllcache\kbd106.dll 2010-01-31 18:23 6,144 a——- c:\windows\system32\kbd106.dll ==================== Find3M ==================== 2010-01-06 18:15 97,970 a——- c:\windows\Publix Preschool Pals Uninstaller.exe 2009-12-31 10:50 353,792 a——- c:\windows\system32\drivers\srv.sys 2009-12-21 13:14 916,480 a——- c:\windows\system32\wininet.dll 2009-12-16 12:43 343,040 a——- c:\windows\system32\mspaint.exe 2009-12-14 01:08 33,280 a——- c:\windows\system32\csrsrv.dll 2009-12-08 13:26 2,145,280 ——– c:\windows\system32\ntoskrnl.exe 2009-12-08 12:43 2,023,936 ——– c:\windows\system32\ntkrnlpa.exe 2009-12-05 12:30 411,368 a——- c:\windows\system32\deploytk.dll 2009-11-27 11:11 1,291,776 a——- c:\windows\system32\quartz.dll 2009-11-27 11:11 17,920 a——- c:\windows\system32\msyuv.dll 2009-11-27 10:07 28,672 a——- c:\windows\system32\msvidc32.dll 2009-11-27 10:07 8,704 a——- c:\windows\system32\tsbyuv.dll 2009-11-27 10:07 84,992 a——- c:\windows\system32\avifil32.dll 2009-11-27 10:07 48,128 a——- c:\windows\system32\iyuv_32.dll 2009-11-27 10:07 11,264 a——- c:\windows\system32\msrle32.dll 2009-08-23 17:57 245,760 a–sh— c:\windows\system32\config\systemprofile\ietldcache\index.dat 2009-08-23 17:57 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009082320090824\index.dat ============= FINISH: 18:21:27.98 ===============
Manufacturer: Name: PCI Simple Communications Controller PNP Device ID: PCI\VEN_14F1&DEV_2F20&SUBSYS_200F14F1&REV_00\4&5855BE9&0&28F0 Service: ==== System Restore Points =================== RP175: 11/24/2009 5:34:40 PM - System Checkpoint RP176: 11/25/2009 3:00:16 AM - Software Distribution Service 3.0 RP177: 11/26/2009 3:45:01 AM - System Checkpoint RP178: 11/26/2009 9:17:55 AM - Avg8 Update RP179: 11/27/2009 3:29:44 PM - System Checkpoint RP180: 11/28/2009 4:37:24 PM - System Checkpoint RP181: 11/29/2009 5:25:24 PM - System Checkpoint RP182: 11/30/2009 6:49:01 PM - System Checkpoint RP183: 12/1/2009 7:27:39 PM - System Checkpoint RP184: 12/2/2009 8:00:27 PM - System Checkpoint RP185: 12/3/2009 8:19:20 PM - System Checkpoint RP186: 12/4/2009 11:49:56 PM - System Checkpoint RP187: 12/5/2009 12:30:20 PM - Installed Java™ 6 Update 17 RP188: 12/6/2009 12:59:57 PM - System Checkpoint RP189: 12/7/2009 1:37:03 PM - System Checkpoint RP190: 12/8/2009 7:53:06 PM - System Checkpoint RP191: 12/9/2009 9:13:39 AM - Avg8 Update RP192: 12/10/2009 7:43:27 AM - Software Distribution Service 3.0 RP193: 12/11/2009 8:02:52 AM - System Checkpoint RP194: 12/12/2009 10:51:32 AM - System Checkpoint RP195: 12/13/2009 9:55:15 AM - Avg8 Update RP196: 12/13/2009 9:56:10 AM - Avg8 Update RP197: 12/14/2009 10:19:06 AM - System Checkpoint RP198: 12/15/2009 11:25:09 AM - System Checkpoint RP199: 12/16/2009 2:57:50 PM - Installed OpenOffice.org 3.1 RP200: 12/17/2009 3:15:46 PM - System Checkpoint RP201: 12/18/2009 4:22:34 PM - System Checkpoint RP202: 12/19/2009 5:36:42 PM - System Checkpoint RP203: 12/20/2009 3:00:19 AM - Software Distribution Service 3.0 RP204: 12/21/2009 5:04:24 AM - System Checkpoint RP205: 12/21/2009 9:50:49 AM - Avg8 Update RP206: 12/22/2009 10:41:42 AM - System Checkpoint RP207: 12/23/2009 6:05:42 PM - System Checkpoint RP208: 12/24/2009 6:52:24 PM - System Checkpoint RP209: 12/25/2009 8:52:24 PM - System Checkpoint RP210: 12/26/2009 6:22:11 PM - Removed AVG Free 8.5 RP211: 12/26/2009 6:45:20 PM - Removed AVG Free 8.5 RP212: 12/27/2009 3:02:43 PM - OTL Restore Point RP213: 12/27/2009 8:17:02 PM - Installed WOT for Internet Explorer RP214: 12/28/2009 8:07:33 AM - Avg8 Update RP215: 12/29/2009 12:02:18 PM - System Checkpoint RP216: 12/30/2009 12:41:52 PM - System Checkpoint RP217: 12/31/2009 1:02:46 PM - System Checkpoint RP218: 1/2/2010 10:38:57 AM - System Checkpoint RP219: 1/3/2010 12:41:00 PM - System Checkpoint RP220: 1/4/2010 8:41:53 AM - Avg8 Update RP221: 1/5/2010 12:26:07 PM - System Checkpoint RP222: 1/6/2010 2:33:49 PM - System Checkpoint RP223: 1/7/2010 2:34:51 PM - System Checkpoint RP224: 1/8/2010 3:01:22 PM - System Checkpoint RP225: 1/9/2010 3:46:34 PM - System Checkpoint RP226: 1/11/2010 5:51:35 AM - System Checkpoint RP227: 1/12/2010 8:19:06 AM - System Checkpoint RP228: 1/13/2010 3:00:14 AM - Software Distribution Service 3.0 RP229: 1/14/2010 1:56:30 PM - System Checkpoint RP230: 1/15/2010 3:17:28 PM - System Checkpoint RP231: 1/17/2010 8:52:42 AM - System Checkpoint RP232: 1/18/2010 9:19:34 AM - System Checkpoint RP233: 1/19/2010 10:42:06 AM - System Checkpoint RP234: 1/20/2010 3:00:14 AM - Software Distribution Service 3.0 RP235: 1/21/2010 3:01:57 AM - System Checkpoint RP236: 1/22/2010 3:00:16 AM - Software Distribution Service 3.0 RP237: 1/23/2010 3:21:39 AM - System Checkpoint RP238: 1/24/2010 3:45:42 AM - System Checkpoint RP239: 1/25/2010 4:33:42 AM - System Checkpoint RP240: 1/26/2010 5:45:43 AM - System Checkpoint RP241: 1/27/2010 6:33:43 AM - System Checkpoint RP242: 1/28/2010 11:36:08 AM - System Checkpoint RP243: 1/29/2010 1:12:43 PM - System Checkpoint RP244: 1/30/2010 1:15:53 PM - System Checkpoint RP245: 2/2/2010 9:33:52 AM - Avg8 Update RP246: 2/3/2010 10:49:53 AM - System Checkpoint RP247: 2/4/2010 12:23:21 PM - System Checkpoint RP248: 2/5/2010 2:26:17 PM - System Checkpoint RP249: 2/6/2010 2:35:44 PM - System Checkpoint RP250: 2/7/2010 4:02:49 PM - System Checkpoint RP251: 2/8/2010 4:51:22 PM - System Checkpoint RP252: 2/9/2010 5:03:20 PM - System Checkpoint RP253: 2/10/2010 3:00:15 AM - Software Distribution Service 3.0 RP254: 2/11/2010 3:24:46 AM - System Checkpoint RP255: 2/12/2010 3:48:47 AM - System Checkpoint RP256: 2/13/2010 6:26:31 AM - System Checkpoint RP257: 2/14/2010 7:36:48 AM - System Checkpoint RP258: 2/15/2010 8:24:50 AM - System Checkpoint RP259: 2/16/2010 10:52:51 AM - System Checkpoint RP260: 2/17/2010 8:14:57 PM - System Checkpoint RP261: 2/18/2010 8:24:18 PM - System Checkpoint RP262: 2/19/2010 9:24:17 PM - System Checkpoint RP263: 2/20/2010 9:25:35 PM - System Checkpoint RP264: 2/21/2010 10:35:34 PM - System Checkpoint ==== Installed Programs ====================== Acrobat.com Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.3 Apple Application Support Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Control Panel ATI Display Driver AVG Free 8.5 AVS Update Manager 1.0 AVS Video Converter 6 AVS4YOU Software Navigator 1.3 BitTorrent Bonjour Citrix Presentation Server Client Compatibility Pack for the 2007 Office system EPSON Printer Software ERUNT 1.1j Google Chrome Google Earth Google Toolbar for Internet Explorer Google Update Helper High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) iTunes Java™ 6 Update 17 KeePass Password Safe 1.17 Malwarebytes' Anti-Malware Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft Office Excel Viewer 2003 Microsoft Office Word Viewer 2003 Microsoft Silverlight Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable MobileMe Control Panel Mozilla Firefox (3.5.2) OpenOffice.org 3.1 Publix Preschool Pals QuickTime Safari Security Update for Windows Internet Explorer 8 (KB971961) Security Update for Windows Internet Explorer 8 (KB972260) Security Update for Windows Internet Explorer 8 (KB974455) Security Update for Windows Internet Explorer 8 (KB976325) Security Update for Windows Internet Explorer 8 (KB978207) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969897) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) SigmaTel Audio Skype web features Skype™ 4.1 Update for Windows Internet Explorer 8 (KB972636) Update for Windows Internet Explorer 8 (KB976749) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) WebFldrs XP Windows Internet Explorer 8 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WOT for Internet Explorer Yahoo! BrowserPlus ==== Event Viewer Messages From Past Week ======== 2/21/2010 3:16:05 PM, error: Service Control Manager [7009] - Timeout (30000 milliseconds) waiting for the AVG Free8 WatchDog service to connect. 2/21/2010 3:16:05 PM, error: Service Control Manager [7001] - The AVG Free8 E-mail Scanner service depends on the AVG Free8 WatchDog service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 2/21/2010 3:16:05 PM, error: Service Control Manager [7000] - The AVG Free8 WatchDog service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 2/21/2010 2:20:02 PM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 2 time(s). 2/21/2010 2:13:55 PM, error: Service Control Manager [7031] - The AVG Free8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service. 2/21/2010 2:13:54 PM, error: Service Control Manager [7034] - The AVG Free8 E-mail Scanner service terminated unexpectedly. It has done this 1 time(s). 2/15/2010 10:47:55 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) ==== End Of File ===========================
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-02-22 20:06:27
Windows 5.1.2600 Service Pack 3
Running: m6fqe163.exe; Driver: C:\DOCUME~1\SHAUGH~1\LOCALS~1\Temp\pgldqpoc.sys


—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2156E9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9AD5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD189 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED964 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E2548CE C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E43AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E42E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E434C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E41B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2ED9C0 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[2988] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4717 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E2156E9 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2ED964 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E43AF C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E42E1 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E434C C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E41B2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E4214 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E4412 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\internet explorer\iexplore.exe[3724] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4276 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Program Files\internet explorer\iexplore.exe[2988] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW] [451F1ACB] C:\Program Files\internet explorer\xpshims.dll (Internet Explorer Compatibility Shims for XP/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
ComboFix 10-02-21.02 - Shaughnessy 02/22/2010 21:15:02.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.450 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Security Antivirus *On-access scanning enabled* (Updated) {0522E8A1-CE2C-4743-909F-C9456608B937}
FW: Security Antivirus *enabled* {901415E7-E41C-44E8-9E2D-CB60DBCBD26F}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Shaughnessy\Application Data\Security Antivirus
c:\documents and settings\Shaughnessy\Application Data\Security Antivirus\cookies.sqlite
c:\documents and settings\Shaughnessy\Application Data\Security Antivirus\Instructions.ini
c:\program files\Mozilla Firefox\searchplugins\search.xml

.
((((((((((((((((((((((((( Files Created from 2010-01-23 to 2010-02-23 )))))))))))))))))))))))))))))))
.

2010-02-21 20:19 . 2010-02-21 20:19 ——– d-sh–w- c:\documents and settings\All Users\Application Data\SAAMCLMQDVV
2010-02-21 20:19 . 2009-07-30 11:26 428024 —-a-w- c:\documents and settings\All Users\Application Data\584798d\sqlite3.dll
2010-02-21 20:19 . 2009-07-30 11:26 722424 —-a-w- c:\documents and settings\All Users\Application Data\584798d\mozcrt19.dll
2010-02-21 20:19 . 2010-02-21 20:19 2038784 —-a-w- c:\documents and settings\All Users\Application Data\584798d\SA5847.exe
2010-02-21 20:13 . 2010-02-21 20:20 ——– d-sh–w- c:\documents and settings\All Users\Application Data\584798d
2010-02-01 00:23 . 2001-08-18 04:36 8704 -c–a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-02-01 00:23 . 2001-08-18 04:36 8704 —-a-w- c:\windows\system32\kbdjpn.dll
2010-02-01 00:23 . 2001-08-18 04:36 8192 -c–a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-02-01 00:23 . 2001-08-18 04:36 8192 —-a-w- c:\windows\system32\kbdkor.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 —-a-w- c:\windows\system32\kbd101c.dll
2010-02-01 00:23 . 2001-08-17 20:55 5632 -c–a-w- c:\windows\system32\dllcache\kbd103.dll
2010-02-01 00:23 . 2001-08-17 20:55 5632 —-a-w- c:\windows\system32\kbd103.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 —-a-w- c:\windows\system32\kbd101b.dll
2010-02-01 00:23 . 2008-04-14 01:09 6144 -c–a-w- c:\windows\system32\dllcache\kbd106.dll
2010-02-01 00:23 . 2008-04-14 01:09 6144 —-a-w- c:\windows\system32\kbd106.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-23 03:20 . 2009-09-05 15:24 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\Skype
2010-02-22 23:54 . 2009-07-12 21:24 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-02-22 23:47 . 2009-12-05 22:09 ——– d—–w- c:\program files\PokerStars
2010-02-22 23:30 . 2009-09-05 15:27 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\skypePM
2010-01-30 04:21 . 2009-06-12 21:55 ——– d—–w- c:\program files\Google
2010-01-23 22:54 . 2009-06-20 15:44 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-23 16:17 . 2009-06-24 02:01 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\Apple Computer
2010-01-22 09:17 . 2009-08-01 15:04 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-07 00:15 . 2010-01-07 00:15 97970 —-a-w- c:\windows\Publix Preschool Pals Uninstaller.exe
2010-01-07 00:15 . 2010-01-07 00:14 ——– d—–w- c:\program files\Publix Preschool Pals
2009-12-31 16:50 . 2004-08-10 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 18:20 . 2009-12-30 18:19 ——– d—–w- c:\program files\iTunes
2009-12-30 18:20 . 2009-12-30 18:19 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-30 18:20 . 2009-12-30 18:20 ——– d—–w- c:\program files\iPod
2009-12-30 18:19 . 2009-06-24 01:59 ——– d—–w- c:\program files\Common Files\Apple
2009-12-30 18:17 . 2009-12-30 18:17 ——– d—–w- c:\program files\QuickTime
2009-12-30 18:09 . 2009-12-30 18:09 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-30 18:03 . 2009-07-18 18:30 ——– d—–w- c:\program files\Safari
2009-12-30 17:58 . 2009-12-30 17:58 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-29 16:42 . 2009-12-29 16:42 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\AVS4YOU
2009-12-29 16:42 . 2009-12-29 16:42 ——– d—–w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-12-29 16:42 . 2009-12-29 16:41 ——– d—–w- c:\program files\AVS4YOU
2009-12-29 16:42 . 2009-12-29 16:41 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-12-28 02:39 . 2009-07-12 21:27 21944 —-a-w- c:\documents and settings\Shaughnessy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-28 02:32 . 2009-12-28 02:32 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\KeePass
2009-12-28 02:31 . 2009-12-28 02:31 ——– d—–w- c:\program files\KeePass Password Safe
2009-12-28 02:19 . 2009-12-28 02:19 ——– d—–w- c:\program files\ERUNT
2009-12-28 02:17 . 2009-12-28 02:17 ——– d—–w- c:\program files\WOT
2009-12-27 07:11 . 2009-08-23 14:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-27 07:11 . 2009-12-27 07:11 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-26 14:08 . 2009-12-26 14:08 ——– d—–w- c:\program files\Trend Micro
2009-12-21 19:14 . 2004-08-10 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2009-12-16 21:04 . 2009-12-16 21:04 1 —-a-w- c:\documents and settings\Shaughnessy\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-16 18:43 . 2009-07-12 20:43 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-10 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2004-08-10 12:00 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 22:59 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-05 18:30 . 2009-12-05 18:30 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-05 18:30 . 2009-12-05 18:30 152576 —-a-w- c:\documents and settings\Shaughnessy\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-05 18:29 . 2009-12-05 18:28 79488 —-a-w- c:\documents and settings\Shaughnessy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-04 18:22 . 2004-08-10 12:00 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 22:14 . 2009-08-23 14:56 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 22:13 . 2009-08-23 14:56 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-27 17:11 . 2004-08-10 12:00 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2004-08-10 12:00 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-10 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-10 12:00 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-12 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]
"Security Antivirus"="c:\documents and settings\All Users\Application Data\584798d\SA5847.exe" [2010-02-21 2038784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-13 2043160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\Shaughnessy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 19:50 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\584798d\\SA5847.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/12/2009 3:24 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/12/2009 3:24 PM 108552]
R3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\system32\drivers\SMCWGU.sys [7/12/2009 2:57 PM 408064]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/12/2009 3:24 PM 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/12/2009 3:24 PM 297752]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/20/2009 9:08 AM 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [8/23/2009 8:56 AM 38224]
.
Contents of the 'Scheduled Tasks' folder

2010-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 15:08]

2010-02-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 15:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://m.www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Shaughnessy\Application Data\Mozilla\Firefox\Profiles\a1h6040u.default\
FF - plugin: c:\documents and settings\Shaughnessy\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-22 21:20
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-02-22 21:22:42
ComboFix-quarantined-files.txt 2010-02-23 03:22

Pre-Run: 226,616,922,112 bytes free
Post-Run: 226,970,402,816 bytes free

- - End Of File - - 1E36422B7DF87AC40D3C972DEC7196D3
Hi,

Please do the following:


  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/Infection_t110453.html

Collect::
c:\documents and settings\All Users\Application Data\584798d\sqlite3.dll
c:\documents and settings\All Users\Application Data\584798d\mozcrt19.dll
c:\documents and settings\All Users\Application Data\584798d\SA5847.exe

Folder::
c:\documents and settings\All Users\Application Data\584798d
c:\documents and settings\All Users\Application Data\SAAMCLMQDVV

SecCenter::
AV: Security Antivirus *On-access scanning enabled* (Updated) {0522E8A1-CE2C-4743-909F-C9456608B937}
FW: Security Antivirus *enabled* {901415E7-E41C-44E8-9E2D-CB60DBCBD26F}

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Security Antivirus"=-

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

**Note**
When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.


NEXT

  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.




NEXT



Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply


In your next reply please include
  • ComboFix Log
  • MBAM Log
  • Kaspersky report
ComboFix 10-02-23.03 - Shaughnessy 02/23/2010 19:20:53.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.494 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Shaughnessy\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

file zipped: c:\documents and settings\All Users\Application Data\584798d\mozcrt19.dll
file zipped: c:\documents and settings\All Users\Application Data\584798d\SA5847.exe
file zipped: c:\documents and settings\All Users\Application Data\584798d\sqlite3.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\584798d
c:\documents and settings\All Users\Application Data\584798d\37.mof
c:\documents and settings\All Users\Application Data\584798d\BackUp\ERUNT AutoBackup.lnk
c:\documents and settings\All Users\Application Data\584798d\BackUp\OpenOffice.org 3.1.lnk
c:\documents and settings\All Users\Application Data\584798d\mozcrt19.dll
c:\documents and settings\All Users\Application Data\584798d\SA5847.exe
c:\documents and settings\All Users\Application Data\584798d\SAV.ico
c:\documents and settings\All Users\Application Data\584798d\SAVSys\vd952342.bd
c:\documents and settings\All Users\Application Data\584798d\sqlite3.dll
c:\documents and settings\All Users\Application Data\SAAMCLMQDVV
c:\documents and settings\All Users\Application Data\SAAMCLMQDVV\SAHTVYRQTMV.cfg
c:\documents and settings\Shaughnessy\Application Data\Security Antivirus
c:\program files\Mozilla Firefox\searchplugins\search.xml

.
((((((((((((((((((((((((( Files Created from 2010-01-24 to 2010-02-24 )))))))))))))))))))))))))))))))
.

2010-02-01 00:23 . 2001-08-18 04:36 8704 -c–a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-02-01 00:23 . 2001-08-18 04:36 8704 —-a-w- c:\windows\system32\kbdjpn.dll
2010-02-01 00:23 . 2001-08-18 04:36 8192 -c–a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-02-01 00:23 . 2001-08-18 04:36 8192 —-a-w- c:\windows\system32\kbdkor.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 —-a-w- c:\windows\system32\kbd101c.dll
2010-02-01 00:23 . 2001-08-17 20:55 5632 -c–a-w- c:\windows\system32\dllcache\kbd103.dll
2010-02-01 00:23 . 2001-08-17 20:55 5632 —-a-w- c:\windows\system32\kbd103.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 -c–a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-02-01 00:23 . 2001-08-17 20:55 6144 —-a-w- c:\windows\system32\kbd101b.dll
2010-02-01 00:23 . 2008-04-14 01:09 6144 -c–a-w- c:\windows\system32\dllcache\kbd106.dll
2010-02-01 00:23 . 2008-04-14 01:09 6144 —-a-w- c:\windows\system32\kbd106.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-24 01:24 . 2009-09-05 15:24 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\Skype
2010-02-24 01:12 . 2009-09-05 15:27 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\skypePM
2010-02-22 23:54 . 2009-07-12 21:24 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-02-22 23:47 . 2009-12-05 22:09 ——– d—–w- c:\program files\PokerStars
2010-01-30 04:21 . 2009-06-12 21:55 ——– d—–w- c:\program files\Google
2010-01-23 22:54 . 2009-06-20 15:44 ——– d—–w- c:\program files\Common Files\Adobe
2010-01-23 16:17 . 2009-06-24 02:01 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\Apple Computer
2010-01-22 09:17 . 2009-08-01 15:04 ——– d—–w- c:\program files\Microsoft Silverlight
2010-01-07 00:15 . 2010-01-07 00:15 97970 —-a-w- c:\windows\Publix Preschool Pals Uninstaller.exe
2010-01-07 00:15 . 2010-01-07 00:14 ——– d—–w- c:\program files\Publix Preschool Pals
2009-12-31 16:50 . 2004-08-10 12:00 353792 —-a-w- c:\windows\system32\drivers\srv.sys
2009-12-30 18:20 . 2009-12-30 18:19 ——– d—–w- c:\program files\iTunes
2009-12-30 18:20 . 2009-12-30 18:19 ——– d—–w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-12-30 18:20 . 2009-12-30 18:20 ——– d—–w- c:\program files\iPod
2009-12-30 18:19 . 2009-06-24 01:59 ——– d—–w- c:\program files\Common Files\Apple
2009-12-30 18:17 . 2009-12-30 18:17 ——– d—–w- c:\program files\QuickTime
2009-12-30 18:09 . 2009-12-30 18:09 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-30 18:03 . 2009-07-18 18:30 ——– d—–w- c:\program files\Safari
2009-12-30 17:58 . 2009-12-30 17:58 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-12-29 16:42 . 2009-12-29 16:42 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\AVS4YOU
2009-12-29 16:42 . 2009-12-29 16:42 ——– d—–w- c:\documents and settings\All Users\Application Data\AVS4YOU
2009-12-29 16:42 . 2009-12-29 16:41 ——– d—–w- c:\program files\AVS4YOU
2009-12-29 16:42 . 2009-12-29 16:41 ——– d—–w- c:\program files\Common Files\AVSMedia
2009-12-28 02:39 . 2009-07-12 21:27 21944 —-a-w- c:\documents and settings\Shaughnessy\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-28 02:32 . 2009-12-28 02:32 ——– d—–w- c:\documents and settings\Shaughnessy\Application Data\KeePass
2009-12-28 02:31 . 2009-12-28 02:31 ——– d—–w- c:\program files\KeePass Password Safe
2009-12-28 02:19 . 2009-12-28 02:19 ——– d—–w- c:\program files\ERUNT
2009-12-28 02:17 . 2009-12-28 02:17 ——– d—–w- c:\program files\WOT
2009-12-27 07:11 . 2009-08-23 14:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-12-27 07:11 . 2009-12-27 07:11 4844296 —-a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-12-26 14:08 . 2009-12-26 14:08 ——– d—–w- c:\program files\Trend Micro
2009-12-21 19:14 . 2004-08-10 12:00 916480 ——w- c:\windows\system32\wininet.dll
2009-12-16 21:04 . 2009-12-16 21:04 1 —-a-w- c:\documents and settings\Shaughnessy\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-16 18:43 . 2009-07-12 20:43 343040 —-a-w- c:\windows\system32\mspaint.exe
2009-12-14 07:08 . 2004-08-10 12:00 33280 —-a-w- c:\windows\system32\csrsrv.dll
2009-12-08 19:26 . 2004-08-10 12:00 2145280 ——w- c:\windows\system32\ntoskrnl.exe
2009-12-08 18:43 . 2004-08-03 22:59 2023936 ——w- c:\windows\system32\ntkrnlpa.exe
2009-12-05 18:30 . 2009-12-05 18:30 411368 —-a-w- c:\windows\system32\deploytk.dll
2009-12-05 18:30 . 2009-12-05 18:30 152576 —-a-w- c:\documents and settings\Shaughnessy\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-12-05 18:29 . 2009-12-05 18:28 79488 —-a-w- c:\documents and settings\Shaughnessy\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2009-12-04 18:22 . 2004-08-10 12:00 455424 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-03 22:14 . 2009-08-23 14:56 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-03 22:13 . 2009-08-23 14:56 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-11-27 17:11 . 2004-08-10 12:00 1291776 —-a-w- c:\windows\system32\quartz.dll
2009-11-27 17:11 . 2004-08-04 00:56 17920 —-a-w- c:\windows\system32\msyuv.dll
2009-11-27 16:07 . 2004-08-10 12:00 28672 —-a-w- c:\windows\system32\msvidc32.dll
2009-11-27 16:07 . 2001-08-17 22:36 8704 —-a-w- c:\windows\system32\tsbyuv.dll
2009-11-27 16:07 . 2004-08-10 12:00 84992 —-a-w- c:\windows\system32\avifil32.dll
2009-11-27 16:07 . 2004-08-10 12:00 11264 —-a-w- c:\windows\system32\msrle32.dll
2009-11-27 16:07 . 2004-08-04 00:56 48128 —-a-w- c:\windows\system32\iyuv_32.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-02-23_03.20.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-02-24 01:10 . 2010-02-24 01:10 16384 c:\windows\Temp\Perflib_Perfdata_6d4.dat
+ 2010-02-24 01:11 . 2010-02-24 01:11 208896 c:\windows\ERDNT\AutoBackup\2-23-2010\Users\00000002\UsrClass.dat
+ 2010-02-24 01:11 . 2005-10-20 18:02 163328 c:\windows\ERDNT\AutoBackup\2-23-2010\ERDNT.EXE
+ 2010-02-24 01:11 . 2010-02-24 01:11 2826240 c:\windows\ERDNT\AutoBackup\2-23-2010\Users\00000001\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-12 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2009-10-09 25623336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2004-08-10 59392]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 339968]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2006-02-10 344064]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-12-13 2043160]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-08-13 177440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-05 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\Shaughnessy\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-28 19:50 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/12/2009 3:24 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/12/2009 3:24 PM 108552]
R3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\system32\drivers\SMCWGU.sys [7/12/2009 2:57 PM 408064]
S2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [7/12/2009 3:24 PM 908056]
S2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/12/2009 3:24 PM 297752]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/20/2009 9:08 AM 133104]
.
Contents of the 'Scheduled Tasks' folder

2010-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 15:08]

2010-02-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-20 15:08]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://m.www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Shaughnessy\Application Data\Mozilla\Firefox\Profiles\a1h6040u.default\
FF - plugin: c:\documents and settings\Shaughnessy\Local Settings\Application Data\Yahoo!\BrowserPlus\2.4.21\Plugins\npybrowserplus_2.4.21.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-23 19:24
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2010-02-23 19:26:28
ComboFix-quarantined-files.txt 2010-02-24 01:26
ComboFix2.txt 2010-02-23 03:22

Pre-Run: 226,970,882,048 bytes free
Post-Run: 226,928,353,280 bytes free

- - End Of File - - 017DA58BC52BD9B64633588B5E33BC13
Upload was successful
Malwarebytes' Anti-Malware 1.44 Database version: 3782 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 2/23/2010 7:36:06 PM mbam-log-2010-02-23 (19-36-06).txt Scan type: Quick Scan Objects scanned: 121573 Time elapsed: 4 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 5 Folders Infected: 0 Files Infected: 4 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_USERS\S-1-5-19\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=195&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=195&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-20\SOFTWARE\Classes\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=195&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=195&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\URL (Hijack.SearchPage) -> Bad: (http://findgala.com/?&uid=195&q={searchTerms}) Good: (http://www.Google.com/) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Shaughnessy\Desktop\Security Antivirus.lnk (Rogue.SecurityAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\Shaughnessy\Application Data\Microsoft\Internet Explorer\Quick Launch\Security Antivirus.lnk (Rogue.SecurityAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\Shaughnessy\Start Menu\Security Antivirus.lnk (Rogue.SecurityAntivirus) -> Quarantined and deleted successfully. C:\Documents and Settings\Shaughnessy\Start Menu\Programs\Security Antivirus.lnk (Rogue.SecurityAntivirus) -> Quarantined and deleted successfully.
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, February 23, 2010 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, February 24, 2010 01:19:45 Records in database: 3638138 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: A:\ C:\ D:\ Scan statistics: Objects scanned: 52537 Threats found: 2 Infected objects found: 4 Suspicious objects found: 0 Scan duration: 01:26:57 File name / Threat / Threats count C:\Qoobox\Quarantine\[4]-Submit_2010-02-23_19.20.42.zip Infected: Trojan-Ransom.Win32.DigiPog.ep 1 C:\System Volume Information\_restore{E2BBF59D-6916-4B59-AC9B-DCEDF82B6570}\RP209\A0025453.new Infected: Trojan.Win32.FraudPack.rdo 1 C:\System Volume Information\_restore{E2BBF59D-6916-4B59-AC9B-DCEDF82B6570}\RP211\A0026700.new Infected: Trojan.Win32.FraudPack.rdo 1 C:\System Volume Information\_restore{E2BBF59D-6916-4B59-AC9B-DCEDF82B6570}\RP265\A0033890.exe Infected: Trojan-Ransom.Win32.DigiPog.ep 1 Selected area has been scanned.
Hi.

The items found by Kaspersky are in old restore points and quarantine which we will be clearing up shortly,


Please do the following

[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 17can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.



NEXT


P2P - I see you have P2P software BitTorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information.
Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
Please see this topic for more information:
Perils of P2P File Sharing.
I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs.

NEXT

Please post a fresh DDS log and advise how the computer is running now and if there are any outstanding issues.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI