This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect in IE and Firefox

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello!
I'm having trouble with Google redirect in IE8 and Firefox.

I've run McAfee, SpyBot, and Ad-Aware which have found and fixed minor things but haven't fixed this.

I also downloaded and ran GooRedFix. Ran fine, problem still exists.

I've also been through the steps here: http://forums.whatthetech.com/you_Infected_t106388.html

But, the system restore program errored on me (I have the error info if you want it). I used Windows to create a restore point instead of SysRestorePoint.

Also, running GMER didn't go well. Both times I tried it, I got a blue screen and then the machine shut itself off and restarted. So I have no GMER log.

************
MBAM log:
************

Malwarebytes' Anti-Malware 1.44
Database version: 3866
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18882

3/14/2010 11:40:35 AM
mbam-log-2010-03-14 (11-40-35).txt

Scan type: Quick Scan
Objects scanned: 119209
Time elapsed: 5 minute(s), 13 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

************
DDS Log:
************

DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 12:12:07.54 on Sun 03/14/2010
Internet Explorer: 8.0.6001.18882
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1844 [GMT -4:00]

SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\AUDIODG.EXE
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\agrsmsvc.exe
C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
C:\WINDOWS\System32\bgsvcgen.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Windows\system32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\chatsupport.palm.com\bin\tgsrvc.exe
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\WUDFHost.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
C:\WINDOWS\zHotkey.exe
C:\WINDOWS\ModPS2Key.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\sttray.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Panasonic\VideoCamSuite\VideoCamSuiteAutoStart.exe
C:\Program Files\WinTV\Ir.exe
C:\Program Files\Palm\Hotsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Intel\IntelDH\CCU\CCU_Engine.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\Users\Chad\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://rr.com/
mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5408
mDefault_Page_URL = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5408
uInternet Settings,ProxyOverride = ;localhost
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
mSearchAssistant = hxxp://www.gateway.com/g/sidepanel.html?Ch=Retail&Br=GTW&Loc=ENG_US&Sys=DTP&M=GT5408
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: McAfee Phishing Filter: {27b4851a-3207-45a2-b947-be8afe6163ab} - c:\progra~1\mcafee\msk\mskapbho.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\mcafee\virusscan\scriptsn.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
BHO: McAfee SiteAdvisor BHO: {b164e929-a1b6-4a06-b104-2cd0e90a88ff} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\google\BAE.dll
TB: McAfee SiteAdvisor Toolbar: {0ebbbe48-bad4-4b4c-8e5a-516abecae064} - c:\progra~1\mcafee\sitead~1\mcieplg.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [CCUTRAYICON] c:\program files\intel\inteldh\ccu\CCU_TrayIcon.exe
mRun: [NMSSupport] "c:\program files\common files\intel\inteldh\nms\support\IntelHCTAgent.exe" /startup
mRun: [CHotkey] zHotkey.exe
mRun: [ShowWnd] ShowWnd.exe
mRun: [ModPS2] ModPS2Key.exe
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [mcagent_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [LogitechCommunicationsManager] "c:\program files\common files\logishrd\lcommgr\Communications_Helper.exe"
mRun: [LogitechQuickCamRibbon] "c:\program files\logitech\quickcam\Quickcam.exe" /hide
mRun: [googletalk] c:\program files\google\google talk\googletalk.exe /autostart
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [CanonSolutionMenu] c:\program files\canon\solutionmenu\CNSLMAIN.exe /logon
mRun: [CanonMyPrinter] c:\program files\canon\myprinter\BJMyPrt.exe /logon
mRun: [SSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot
mRun: [OpwareSE4] "c:\program files\scansoft\omnipagese4\OpwareSE4.exe"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [HotSync] "c:\program files\palmsource\desktop\HotSync.exe" -AllUsers
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SigmatelSysTrayApp] sttray.exe
StartupFolder: c:\users\chad\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\autoru~1.lnk - c:\program files\panasonic\videocamsuite\VideoCamSuiteAutoStart.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\autost~1.lnk - c:\program files\wintv\Ir.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hotsyn~1.lnk - c:\program files\palm\Hotsync.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\mcafee~1.lnk - c:\program files\mcafee security scan\1.0.150\SSScheduler.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\progra~1\mcafee\sitead~1\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~1\GOEC62~1.DLL

================= FIREFOX ===================

FF - ProfilePath - c:\users\chad\appdata\roaming\mozilla\firefox\profiles\tmcw1gkb.default\
FF - component: c:\program files\mcafee\siteadvisor\components\McFFPlg.dll
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.hideGoButton", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver={moz:version}&");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features=TrustRank&client={moz:client}&appver={moz:version}&");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?");

============= SERVICES / DRIVERS ===============

R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-3-13 64288]
R2 DQLWinService;DQLWinService;c:\program files\common files\intel\inteldh\nms\adpplugins\DQLWinService.exe [2006-10-29 208896]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1229232]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\mcafee\siteadvisor\McSACore.exe [2008-10-4 93320]
R2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\system32\drivers\nmsgopro.sys [2006-9-27 28672]
R2 nmsunidr;UniDriver for NMS;c:\windows\system32\drivers\nmsunidr.sys [2006-10-19 7424]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-3-14 1153368]
R2 tgsrvc_chatsupport.palm.com;SupportSoft Repair Service (chatsupport.palm.com);c:\program files\chatsupport.palm.com\bin\tgsrvc.exe [2008-1-11 148768]
R2 wlidsvc;Windows Live ID Sign-in Assistant;c:\program files\common files\microsoft shared\windows live\WLIDSVC.EXE [2009-3-30 1533808]
R3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2009-3-19 391168]
R3 IntelDH;IntelDH Driver;c:\windows\system32\drivers\IntelDH.sys [2007-7-30 5504]
S1 AuviBDA;Auvitek HDTV BDA Tuner/Demod/Capture;c:\windows\system32\drivers\AuviBDA.sys [2007-12-10 465664]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-29 135664]
S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-9-10 21504]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2007-7-30 30192]
S3 HauppaugeTVServer;HauppaugeTVServer;c:\progra~1\wintv\HCWTVS~1.EXE [2007-12-17 815104]
S3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8XX.sys [2006-1-25 472644]
S3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\drivers\NETw2v32.sys [2006-11-2 2589184]

=============== Created Last 30 ================

2010-03-14 11:59 239,008,747 a——- c:\windows\MEMORY.DMP
2010-03-14 11:23 –d—– c:\users\chad\appdata\roaming\Malwarebytes
2010-03-14 11:23 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-14 11:23 19,160 a——- c:\windows\system32\drivers\mbam.sys
2010-03-14 11:23 –d—– c:\programdata\Malwarebytes
2010-03-14 11:23 –d—– c:\program files\Malwarebytes' Anti-Malware
2010-03-14 11:23 –d—– c:\progra~2\Malwarebytes
2010-03-14 00:00 –d—– c:\programdata\Spybot - Search & Destroy
2010-03-14 00:00 –d—– c:\program files\Spybot - Search & Destroy
2010-03-14 00:00 –d—– c:\progra~2\Spybot - Search & Destroy
2010-03-13 18:57 15,880 a——- c:\windows\system32\lsdelete.exe
2010-03-13 18:42 64,288 a——- c:\windows\system32\drivers\Lbd.sys
2010-03-13 18:42 95,024 a——- c:\windows\system32\drivers\SBREDrv.sys
2010-03-13 18:39 -cd-h— c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-03-13 18:39 -cd-h— c:\progra~2\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-03-13 18:39 –d—– c:\programdata\Lavasoft
2010-03-13 18:39 –d—– c:\program files\Lavasoft
2010-03-13 09:13 24,064 a——- c:\windows\system32\nshhttp.dll
2010-03-13 09:13 411,648 a——- c:\windows\system32\drivers\http.sys
2010-03-13 09:13 30,720 a——- c:\windows\system32\httpapi.dll
2010-02-28 09:38 –d—– c:\program files\Windows Portable Devices
2010-02-28 09:37 0 a—h— c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2010-02-28 09:31 81,920 a——- c:\windows\system32\wpdbusenum.dll
2010-02-28 09:29 555,520 a——- c:\windows\system32\UIAutomationCore.dll
2010-02-28 09:29 234,496 a——- c:\windows\system32\oleacc.dll
2010-02-28 09:29 4,096 a——- c:\windows\system32\oleaccrc.dll
2010-02-27 09:17 1,696,256 a——- c:\windows\system32\gameux.dll
2010-02-27 09:17 28,672 a——- c:\windows\system32\Apphlpdm.dll
2010-02-27 09:17 4,240,384 a——- c:\windows\system32\GameUXLegacyGDFs.dll
2010-02-27 01:48 –d—– c:\windows\system32\eu-ES
2010-02-27 01:48 –d—– c:\windows\system32\ca-ES
2010-02-27 01:47 –d—– c:\windows\system32\vi-VN
2010-02-26 22:03 –d—– c:\windows\system32\EventProviders
2010-02-24 08:22 2,048 a——- c:\windows\system32\tzres.dll
2010-02-24 08:22 526,336 a——- c:\windows\system32\RMActivate_isv.exe
2010-02-24 08:22 518,144 a——- c:\windows\system32\RMActivate.exe
2010-02-24 08:22 471,552 a——- c:\windows\system32\secproc_isv.dll
2010-02-24 08:22 471,552 a——- c:\windows\system32\secproc.dll
2010-02-24 08:22 347,136 a——- c:\windows\system32\RMActivate_ssp.exe
2010-02-24 08:22 346,624 a——- c:\windows\system32\RMActivate_ssp_isv.exe
2010-02-24 08:22 332,288 a——- c:\windows\system32\msdrm.dll
2010-02-24 08:22 152,576 a——- c:\windows\system32\secproc_ssp_isv.dll
2010-02-24 08:22 152,064 a——- c:\windows\system32\secproc_ssp.dll

==================== Find3M ====================

2010-03-06 12:04 21,560 a——- c:\windows\system32\drivers\atapi.sys
2010-02-28 09:38 665,600 a——- c:\windows\inf\drvindex.dat
2010-02-28 09:38 143,360 a——- c:\windows\inf\infstrng.dat
2010-02-28 09:38 86,016 a——- c:\windows\inf\infstor.dat
2010-02-28 09:38 51,200 a——- c:\windows\inf\infpub.dat
2010-01-06 11:38 173,056 a——- c:\windows\apppatch\AcXtrnal.dll
2010-01-06 11:38 2,159,616 a——- c:\windows\apppatch\AcGenral.dll
2010-01-06 11:38 542,720 a——- c:\windows\apppatch\AcLayers.dll
2010-01-06 11:38 458,752 a——- c:\windows\apppatch\AcSpecfc.dll
2010-01-02 02:38 916,480 a——- c:\windows\system32\wininet.dll
2010-01-02 02:32 109,056 a——- c:\windows\system32\iesysprep.dll
2010-01-02 02:32 71,680 a——- c:\windows\system32\iesetup.dll
2010-01-02 00:57 133,632 a——- c:\windows\system32\ieUnatt.exe
2008-09-11 12:47 174 a–sh— c:\program files\desktop.ini
2008-06-23 21:23 486 a——- c:\users\chad\appdata\roaming\wklnhst.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat
2006-11-02 08:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat
2006-11-02 08:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat
2006-11-02 05:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat
2006-11-02 05:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat

============= FINISH: 12:15:31.12 ===============



Thanks for any help you can provide.
Hello ChadA and welcome to WhatTheTech. I’ll be happy to look over your log and help you with your issues. It will be very helpful if you follow these guidelines:
  • Malware removal is a sometimes lengthy and tedious process. Please stick with the thread until I’ve given you the “All clear.” Absence of symptoms does not mean your machine is clean!
  • Please do not run any scans or install/uninstall any applications without being directed to do so.
  • Please follow my instructions carefully and in the order they are posted.
  • Any underlined text in my posts indicates a clickable link.
  • You should print any instructions I give you for ease of use and reference.
  • If you have any questions at all, please stop and ask before proceeding.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.This may cause a delay, but I will do my best to keep it as short as possible.

I will post back as soon as possible with instructions.
ChadA,

🖼Click to load external image (Posted Image) Please try to run GMER again. Make sure you have all of your security software disabled and all other windows closed. Also uncheck the box beside "files" as well.

If that doesn't work, please try to run it in the safe mode:

Follow these steps to reboot your computer into the Safe Mode:
  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode menu item
  • Press Enter.
🖼Click to load external image (Posted Image) Download and run HAMeb_check.exe save it to your desktop.

Click on the icon to run it, when complete it will open a log for you, please post the content of the log in your next reply.

Note: The log is temporary - it will not be saved when closed, so please be sure to copy the content so that you can paste it into your next reply before you close the log

🖼Click to load external image (Posted Image) If you have the Attach.txt file from your DDS run, please include it in your next post. If you do not have it, please run DDS again and post the Attach.txt file that is produced.

Please include the following in your next post:
  • GMER log
  • HAMeb_check log
  • Attach.txt log from DDS
RP,
Thanks for the help. I was able to get GMER to run in safe mode (finally). That log is below. Also, I've attached my attach.txt from DDS.

I downloaded HAMeb_check and tried to run it but got the message "This tool is not compatible with your system."

**************
GMER log
**************

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-15 11:46:33
Windows 6.0.6002 Service Pack 2
Running: ohriytys.exe; Driver: C:\Users\Chad\AppData\Local\Temp\kwddqpob.sys


—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\Windows\system32\drivers\atapi.sys entry point in ".rsrc" section [0x829B1014]

—- User code sections - GMER 1.0.15 —-

.text C:\Windows\system32\svchost.exe[812] ntdll.dll!NtProtectVirtualMemory 77894D34 5 Bytes JMP 0020000A
.text C:\Windows\system32\svchost.exe[812] ntdll.dll!NtWriteVirtualMemory 77895674 5 Bytes JMP 0021000A
.text C:\Windows\system32\svchost.exe[812] ntdll.dll!KiUserExceptionDispatcher 77895DC8 5 Bytes JMP 001F000A
.text C:\Windows\system32\svchost.exe[812] ole32.dll!CoCreateInstance 77739EA6 5 Bytes JMP 0033000A
.text C:\Windows\system32\svchost.exe[812] USER32.dll!GetCursorPos 76FF0B88 5 Bytes JMP 0034000A
.text C:\Windows\Explorer.EXE[1040] ntdll.dll!NtProtectVirtualMemory 77894D34 5 Bytes JMP 0021000A
.text C:\Windows\Explorer.EXE[1040] ntdll.dll!NtWriteVirtualMemory 77895674 5 Bytes JMP 0037000A
.text C:\Windows\Explorer.EXE[1040] ntdll.dll!KiUserExceptionDispatcher 77895DC8 5 Bytes JMP 0020000A

—- User IAT/EAT - GMER 1.0.15 —-

IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown] [74437817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage] [7448A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI] [7443BB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode] [7442F695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup] [744375E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC] [7442E7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM] [74468395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream] [7443DA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight] [7442FFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth] [7442FF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage] [744271CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM] [744BCAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile] [7445C8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics] [7442D968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree] [74426853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc] [7442687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
IAT C:\Windows\Explorer.EXE[1040] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode] [74432AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396
ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 85324B4C

—- Files - GMER 1.0.15 —-

File C:\Windows\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

Attachments:

ChadA,

🖼Click to load external image (Posted Image) Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Right click on ComboFix.exe & choose "Run as administrator", then follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please include the following in your next post:
  • ComboFix log
I've done as instructed. The log text is below. Something to note: Combofix said it detected root kit activity and rebooted the machine. On reboot, it displayed it had completed Stage 1 and 2. Then 2 McAfee windows appeared and said something about detecting and quarantining a file. I had disabled McAfee, but it restarted in the reboot. Combofix ran the rest of its process with no trouble as far as I could tell (though it did say something about not being able to find a file called whitedir…) *** Comboxfix log *** ComboFix 10-03-15.04 - Chad 03/15/2010 23:15:12.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.2214 [GMT -4:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Resident AV is active . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-3282302405-4175071610-2365169027-500 c:\windows\COUPON~1.OCX c:\windows\CouponPrinter.ocx Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected Restored copy from - Kitty ate it :P . ((((((((((((((((((((((((( Files Created from 2010-02-16 to 2010-03-16 ))))))))))))))))))))))))))))))) . 2010-03-15 13:40 . 2010-03-15 15:38 ——– d—–w- c:\users\Chad\AppData\Local\Adobe 2010-03-14 15:23 . 2010-03-14 15:23 ——– d—–w- c:\users\Chad\AppData\Roaming\Malwarebytes 2010-03-14 15:23 . 2010-01-07 20:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-14 15:23 . 2010-03-14 15:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-03-14 15:23 . 2010-03-14 15:23 ——– d—–w- c:\programdata\Malwarebytes 2010-03-14 15:23 . 2010-01-07 20:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-03-14 15:14 . 2010-03-14 15:15 ——– d—–w- c:\program files\ERUNT 2010-03-14 04:00 . 2010-03-14 04:34 ——– d—–w- c:\programdata\Spybot - Search & Destroy 2010-03-14 04:00 . 2010-03-14 04:05 ——– d—–w- c:\program files\Spybot - Search & Destroy 2010-03-13 22:57 . 2010-03-13 22:42 15880 —-a-w- c:\windows\system32\lsdelete.exe 2010-03-13 22:42 . 2010-03-13 22:42 ——– dc—-w- c:\windows\system32\DRVSTORE 2010-03-13 22:42 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys 2010-03-13 22:42 . 2010-03-13 22:42 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2010-03-13 22:39 . 2010-03-13 22:39 ——– dc-h–w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6} 2010-03-13 22:39 . 2010-03-13 22:42 ——– d—–w- c:\programdata\Lavasoft 2010-03-13 22:39 . 2010-03-13 22:39 ——– d—–w- c:\program files\Lavasoft 2010-03-13 13:13 . 2010-02-20 23:06 24064 —-a-w- c:\windows\system32\nshhttp.dll 2010-03-13 13:13 . 2010-02-20 23:05 30720 —-a-w- c:\windows\system32\httpapi.dll 2010-03-13 13:13 . 2010-02-20 20:53 411648 —-a-w- c:\windows\system32\drivers\http.sys 2010-02-28 13:38 . 2010-02-28 13:38 ——– d—–w- c:\program files\Windows Portable Devices 2010-02-28 13:31 . 2009-10-01 01:02 30208 —-a-w- c:\windows\system32\WPDShextAutoplay.exe 2010-02-28 13:31 . 2009-10-01 01:02 31232 —-a-w- c:\windows\system32\BthMtpContextHandler.dll 2010-02-28 13:31 . 2009-10-01 01:01 81920 —-a-w- c:\windows\system32\wpdbusenum.dll 2010-02-28 13:31 . 2009-10-01 01:01 60928 —-a-w- c:\windows\system32\PortableDeviceConnectApi.dll 2010-02-28 13:31 . 2009-10-01 01:02 2537472 —-a-w- c:\windows\system32\wpdshext.dll 2010-02-28 13:31 . 2009-10-01 01:02 334848 —-a-w- c:\windows\system32\PortableDeviceApi.dll 2010-02-28 13:31 . 2009-10-01 01:02 87552 —-a-w- c:\windows\system32\WPDShServiceObj.dll 2010-02-28 13:31 . 2009-10-01 01:01 546816 —-a-w- c:\windows\system32\wpd_ci.dll 2010-02-28 13:31 . 2009-10-01 01:01 160256 —-a-w- c:\windows\system32\PortableDeviceTypes.dll 2010-02-28 13:31 . 2009-10-01 01:01 196608 —-a-w- c:\windows\system32\PortableDeviceWMDRM.dll 2010-02-28 13:31 . 2009-10-01 01:01 100864 —-a-w- c:\windows\system32\PortableDeviceClassExtension.dll 2010-02-28 13:31 . 2009-10-01 01:01 350208 —-a-w- c:\windows\system32\WPDSp.dll 2010-02-28 13:29 . 2009-10-08 21:08 555520 —-a-w- c:\windows\system32\UIAutomationCore.dll 2010-02-28 13:29 . 2009-10-08 21:08 234496 —-a-w- c:\windows\system32\oleacc.dll 2010-02-28 13:29 . 2009-10-08 21:07 4096 —-a-w- c:\windows\system32\oleaccrc.dll 2010-02-27 13:17 . 2010-01-06 15:39 1696256 —-a-w- c:\windows\system32\gameux.dll 2010-02-27 13:17 . 2010-01-06 15:38 28672 —-a-w- c:\windows\system32\Apphlpdm.dll 2010-02-27 13:17 . 2010-01-06 13:30 4240384 —-a-w- c:\windows\system32\GameUXLegacyGDFs.dll 2010-02-27 05:48 . 2010-02-27 05:49 ——– d—–w- c:\windows\system32\ca-ES 2010-02-27 05:48 . 2010-02-27 05:49 ——– d—–w- c:\windows\system32\eu-ES 2010-02-27 05:47 . 2010-02-27 05:49 ——– d—–w- c:\windows\system32\vi-VN 2010-02-27 02:03 . 2010-02-27 02:03 ——– d—–w- c:\windows\system32\EventProviders 2010-02-24 12:22 . 2010-01-23 09:26 2048 —-a-w- c:\windows\system32\tzres.dll 2010-02-24 12:22 . 2010-01-25 12:00 471552 —-a-w- c:\windows\system32\secproc_isv.dll 2010-02-24 12:22 . 2010-01-25 12:00 471552 —-a-w- c:\windows\system32\secproc.dll 2010-02-24 12:22 . 2010-01-25 08:21 526336 —-a-w- c:\windows\system32\RMActivate_isv.exe 2010-02-24 12:22 . 2010-01-25 08:21 518144 —-a-w- c:\windows\system32\RMActivate.exe 2010-02-24 12:22 . 2010-01-25 08:21 347136 —-a-w- c:\windows\system32\RMActivate_ssp.exe 2010-02-24 12:22 . 2010-01-25 12:00 152576 —-a-w- c:\windows\system32\secproc_ssp_isv.dll 2010-02-24 12:22 . 2010-01-25 12:00 152064 —-a-w- c:\windows\system32\secproc_ssp.dll 2010-02-24 12:22 . 2010-01-25 11:58 332288 —-a-w- c:\windows\system32\msdrm.dll 2010-02-24 12:22 . 2010-01-25 08:21 346624 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-13 22:41 . 2010-03-13 22:41 17480 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\EmailScannerBridge.dll 2010-03-13 22:41 . 2010-03-13 22:41 961984 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\CEAPI.dll 2010-03-13 22:41 . 2010-03-13 22:41 835312 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe 2010-03-13 22:41 . 2010-03-13 22:41 842992 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe 2010-03-13 22:41 . 2010-03-13 22:41 1593320 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\Ad-Aware.exe 2010-03-13 22:41 . 2010-03-13 22:41 815184 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWTray.exe 2010-03-13 22:41 . 2010-03-13 22:41 1229232 —-a-w- c:\programdata\Lavasoft\Ad-Aware\Update\AAWService.exe 2010-03-13 13:36 . 2006-11-02 11:18 ——– d—–w- c:\program files\Windows Mail 2010-03-13 13:18 . 2007-07-30 15:34 ——– d—–w- c:\programdata\Microsoft Help 2010-03-10 21:33 . 2007-12-05 02:54 ——– d—–w- c:\program files\WinTV 2010-03-06 20:21 . 2008-07-15 19:43 ——– d—–w- c:\program files\Coupons 2010-03-06 16:04 . 2009-08-01 00:59 21560 —-a-w- c:\windows\system32\drivers\atapi.sys 2010-02-28 14:17 . 2010-02-28 14:17 690952 —-a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2010-02-28 13:38 . 2006-11-02 10:25 665600 —-a-w- c:\windows\inf\drvindex.dat 2010-02-28 13:37 . 2010-02-28 13:37 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf 2010-02-27 05:50 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Calendar 2010-02-27 05:49 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Sidebar 2010-02-27 05:49 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Journal 2010-02-27 05:49 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Collaboration 2010-02-27 05:49 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Photo Gallery 2010-02-27 05:49 . 2006-11-02 12:37 ——– d—–w- c:\program files\Windows Defender 2010-02-25 13:07 . 2007-12-05 02:24 132480 —-a-w- c:\users\Chad\AppData\Local\GDIPFONTCACHEV1.DAT 2010-02-04 15:53 . 2010-03-13 22:39 2954656 -c–a-w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe 2010-01-29 13:05 . 2007-07-30 15:37 ——– d—–w- c:\program files\Google 2010-01-22 12:23 . 2009-10-09 23:11 ——– d—–w- c:\program files\Microsoft Silverlight 2010-01-08 16:26 . 2010-01-08 16:26 86016 —-a-w- c:\programdata\NOS\Adobe_Downloads\arh.exe 2010-01-06 15:38 . 2010-02-27 13:17 173056 —-a-w- c:\windows\AppPatch\AcXtrnal.dll 2010-01-06 15:38 . 2010-02-27 13:17 542720 —-a-w- c:\windows\AppPatch\AcLayers.dll 2010-01-06 15:38 . 2010-02-27 13:17 458752 —-a-w- c:\windows\AppPatch\AcSpecfc.dll 2010-01-06 15:38 . 2010-02-27 13:17 2159616 —-a-w- c:\windows\AppPatch\AcGenral.dll 2010-01-02 06:38 . 2010-02-27 01:52 916480 —-a-w- c:\windows\system32\wininet.dll 2010-01-02 06:32 . 2010-02-27 01:52 71680 —-a-w- c:\windows\system32\iesetup.dll 2010-01-02 06:32 . 2010-02-27 01:52 109056 —-a-w- c:\windows\system32\iesysprep.dll 2010-01-02 04:57 . 2010-02-27 01:52 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2009-12-17 01:09 . 2008-08-09 15:22 119808 —-a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2010-01-15 12:28 . 2008-01-11 06:56 67688 —-a-w- c:\program files\mozilla firefox\components\jar50.dll 2010-01-15 12:28 . 2008-01-11 06:56 54368 —-a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2010-01-15 12:28 . 2008-01-11 06:56 34944 —-a-w- c:\program files\mozilla firefox\components\myspell.dll 2010-01-15 12:28 . 2008-01-11 06:56 46712 —-a-w- c:\program files\mozilla firefox\components\spellchk.dll 2010-01-15 12:28 . 2008-01-11 06:56 172136 —-a-w- c:\program files\mozilla firefox\components\xpinstal.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "CCUTRAYICON"="c:\program files\Intel\IntelDH\CCU\CCU_TrayIcon.exe" [2006-11-18 182744] "NMSSupport"="c:\program files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" [2006-09-26 423424] "CHotkey"="zHotkey.exe" [2006-11-07 547840] "ShowWnd"="ShowWnd.exe" [2005-01-27 36864] "ModPS2"="ModPS2Key.exe" [2006-11-07 53248] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-12-17 30192] "IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2007-02-05 849280] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-10-29 1218008] "LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984] "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696] "CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-15 644696] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-04 1603152] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472] "OpwareSE4"="c:\program files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 79400] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-12-12 98304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-12-12 106496] "Persistence"="c:\windows\system32\igfxpers.exe" [2006-12-12 81920] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288] "SigmatelSysTrayApp"="sttray.exe" [2006-11-02 303104] c:\users\Chad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Adobe Gamma Loader.exe.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-8 108544] Auto run of VideoCam Suite 1.0.lnk - c:\program files\Panasonic\VideoCamSuite\VideoCamSuiteAutoStart.exe [2008-4-14 161160] AutoStart IR.lnk - c:\program files\WinTV\Ir.exe [2007-12-17 106551] HotSync Manager.lnk - c:\program files\Palm\Hotsync.exe [2008-1-3 1392640] McAfee Security Scan.lnk - c:\program files\McAfee Security Scan\1.0.150\SSScheduler.exe [2009-7-27 199184] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /r \??\k:\0autocheck autochk *\0lsdelete [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys] @="FSFilter System Recovery" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk backup=c:\windows\pss\Logitech Desktop Messenger.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigFix] 2006-11-16 23:04 2348584 —-a-w- c:\program files\BigFix\bigfix.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM] 2008-03-09 20:08 20480 —-a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(B):38,3c,28,3f,ad,b7,ca,01 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3282302405-4175071610-2365169027-1001] "EnableNotifications"=dword:00000001 "EnableNotificationsRef"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3282302405-4175071610-2365169027-500] "EnableNotificationsRef"=dword:00000002 R1 AuviBDA;Auvitek HDTV BDA Tuner/Demod/Capture;c:\windows\system32\DRIVERS\AuviBDA.sys [2007-02-28 465664] R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 135664] R3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2009-12-17 30192] R3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;c:\windows\system32\drivers\HCWBT8XX.sys [2006-01-25 472644] R3 NETw2v32;Intel® PRO/Wireless 2200BG Network Connection Driver for Windows Vista;c:\windows\system32\DRIVERS\NETw2v32.sys [2006-11-02 2589184] S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-02-04 64288] S2 DQLWinService;DQLWinService;c:\program files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2006-10-29 208896] S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-13 1229232] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-12-08 93320] S2 nmsgopro;GoProto Protocol Driver for NMS;c:\windows\system32\DRIVERS\nmsgopro.sys [2006-09-27 28672] S2 nmsunidr;UniDriver for NMS;c:\windows\system32\DRIVERS\nmsunidr.sys [2006-10-19 7424] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368] S2 tgsrvc_chatsupport.palm.com;SupportSoft Repair Service (chatsupport.palm.com);c:\program files\chatsupport.palm.com\bin\tgsrvc.exe [2008-01-11 148768] S3 hcw18bda;Hauppauge WinTV 418 Driver;c:\windows\system32\drivers\hcw18bda.sys [2009-03-20 391168] S3 IntelDH;IntelDH Driver;c:\windows\system32\Drivers\IntelDH.sys [2007-07-30 5504] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder 2010-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 13:05] 2010-03-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 13:05] 2009-12-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 16:22] 2010-01-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2009-10-21 16:22] . . ——- Supplementary Scan ——- . uStart Page = hxxp://rr.com/ mStart Page = hxxp://www.gateway.com/g/startpage.html?Ch=Retail&Br;=GTW&Loc;=ENG_US&Sys;=DTP&M;=GT5408 uInternet Settings,ProxyOverride = ;localhost uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p;=%s IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html FF - ProfilePath - c:\users\Chad\AppData\Roaming\Mozilla\Firefox\Profiles\tmcw1gkb.default\ FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.allow_platform_file_picker", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://branding/content/searchconfig.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://branding/content/searchconfig.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("signon.prefillForms", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.enabled", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.remoteLookups", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.updateURL", "http://sb.google.com/safebrowsing/update?client={moz:client}&appver;={moz:version}&"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.lookupURL", "http://sb.google.com/safebrowsing/lookup?sourceid=firefox-antiphish&features;=TrustRank&client;={moz:client}&appver;={moz:version}&"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.safebrowsing.provider.0.reportURL", "http://sb.google.com/safebrowsing/report?"); . - - - - ORPHANS REMOVED - - - - HKLM-Run-HotSync - c:\program files\PalmSource\Desktop\HotSync.exe SafeBoot-dmboot.sys SafeBoot-dmio.sys SafeBoot-dmload.sys SafeBoot-dmadmin SafeBoot-dmserver SafeBoot-SRService MSConfigStartUp-BlazeServoTool - c:\program files\BlazeVideo\BlazeDTV 2.5\MediaDetector.exe MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe AddRemove-LSI Soft Modem - c:\windows\agrsmdel ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(19516) c:\progra~1\mcafee\SITEAD~1\saHook.dll c:\program files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll . ———————— Other Running Processes ———————— . c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe c:\windows\system32\AUDIODG.EXE c:\windows\system32\agrsmsvc.exe c:\program files\Intel\IntelDH\CCU\AlertService.exe c:\windows\System32\bgsvcgen.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\progra~1\McAfee\VIRUSS~1\mcshield.exe c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe c:\program files\McAfee\MSK\MskSrver.exe c:\windows\system32\rundll32.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe c:\program files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe c:\windows\system32\WUDFHost.exe c:\program files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe c:\program files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\windows\system32\wbem\unsecapp.exe c:\progra~1\mcafee.com\agent\mcagent.exe c:\program files\Windows Media Player\wmplayer.exe c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\windows\servicing\TrustedInstaller.exe c:\program files\Windows Media Player\wmpnetwk.exe . ************************************************************************** . Completion time: 2010-03-15 23:35:44 - machine was rebooted ComboFix-quarantined-files.txt 2010-03-16 03:35 Pre-Run: 230,782,750,720 bytes free Post-Run: 230,709,161,984 bytes free - - End Of File - - 4795843194EC098CDA4970C4DB22C396
ChadA,

That looks better; are you still being redirected? Please run this scan for me next:

🖼Click to load external image (Posted Image) Using Internet Explorer or Firefox, visit Kaspersky Online Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.

2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan. Click HERE to see how to disable the most common antivirus programs.
3. Click Run at the Security prompt.

The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, adware, dialers, and other riskware
    • Archives
    • E-mail databases
  • Click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View report… at the bottom.
  • Click the Save report… button.

    [external image: Posted Image]

  • Change the Files of type dropdown box to Text file (.txt) and name the file KasReport.txt to save the file to your desktop so that you may post it in your next reply

Please include the following in your next post:
  • Kaspersky log
  • How is your computer running / anymore redirects?
It doesn't seem to be redirecting anymore. I ran Kaspersky and it found 1 item. Log below: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Tuesday, March 16, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Tuesday, March 16, 2010 08:32:27 Records in database: 3812583 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan statistics: Objects scanned: 150392 Threats found: 1 Infected objects found: 1 Suspicious objects found: 0 Scan duration: 02:00:18 File name / Threat / Threats count C:\Users\Chad\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JYV7V6JG\index[2].htm Infected: Packed.JS.Agent.cc 1 Selected area has been scanned.
ChadA,

Let's take care of that one Kaspersky detection, then your logs look clean:

🖼Click to load external image (Posted Image) Open notepad and then copy and paste the contents of the code box below into it. Go to File > save as and name the file “fixes.bat” (WITH the quotation marks) and save it to your desktop.

@echo off
del "C:\Users\Chad\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\JYV7V6JG\index[2].htm"
del /Q %0

Double-click on the fixes.bat file to execute it.
Reboot.

Next, you have some important cleanup and housekeeping to tend to:

🖼Click to load external image (Posted Image) Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
  • Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 18. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Select the Windows platform from the dropdown menu.
  • Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java™ 6) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java version.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
  • After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
    • On the General tab, under Temporary Internet Files, click the Settings button.
    • Next, click on the Delete Files button
    • There are two options in the window to clear the cache - Leave BOTH Checked
      Applications and AppletsTrace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.
🖼Click to load external image (Posted Image) Your Adobe reader needs to be updated. Please visit Adobe's site and grab the newest version.

Go HERE to scan for any other out of date and/or vulnerable applications on your computer and follow the instructions given for updating them.

🖼Click to load external image (Posted Image) Uninstall ComboFix
  • Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens:
    Combofix /Uninstall
🖼Click to load external image (Posted Image)

🖼Click to load external image (Posted Image) Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
🖼Click to load external image (Posted Image) Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
  • Manually delete any remaining logs or tools from our fixes
🖼Click to load external image (Posted Image) Finally, I'd like to make a couple of suggestions to help you stay clean in the future:
  • Restart any anti-malware programs that we disabled while we were cleaning your machine.
  • Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
  • Consider running in a limited user account. See this post for more information.
  • Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Please post once more so I know you are all set and I can close this thread. Good luck and stay safe!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI