This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google Redirect, Websites not loading

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was experiencing google redirects. I ran spybot, avast, ad aware, malwarebytes, and hitman pro. This seemed to get rid of the redirect but I am unable to load some sites and others I have to refresh multiple times before I get to the site. :pullhair:

Defogger did not find anything. I am adding the DDS and GMER logs below. Thank you for your help.


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:23:51.12 on Wed 04/14/2010
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.176 [GMT -4:00]

AV: avast! Antivirus *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Owner\Application Data\Smilebox\SmileboxTray.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uSearch Bar =
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei;=utf-8&fr;=b1ie7
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = localhost
BHO: Yahoo! Companion BHO: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_5_7_0.dll
BHO: {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - No File
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: UrlHelper Class: {6d023ebf-70b8-45a6-9ed5-556515fa0fe4} - c:\program files\bearshare applications\bearshare mediabar\BearShareIEHelper.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.1.1309.3572\swg.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
BHO: {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - No File
TB: Yahoo! Companion: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\ycomp5_5_7_0.dll
TB: BearShare MediaBar: {d3dee18f-db64-4beb-9ff1-e1f0a5033e4a} - c:\program files\bearshare applications\bearshare mediabar\BSMediaBar.dll
TB: {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No File
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
uRun: [Sonic RecordNow!]
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [SmileboxTray] "c:\documents and settings\owner\application data\smilebox\SmileboxTray.exe"
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockwave 11\SwHelper_1150596.exe -Update -1150596 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)" -"http://games.yahoo.com/daily-games/wordsense"
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.0\apps\apdproxy.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"
mRun: [avast5] c:\progra~1\alwils~1\avast5\avastUI.exe /nogui
mRun: [HitmanPro35] "c:\program files\hitman pro 3.5\HitmanPro35[1].exe" /scan:boot
StartupFolder: c:\docume~1\owner\startm~1\programs\startup\cyber-~1.lnk - c:\program files\sony\sony picture utility\volumewatcher\SPUVolumeWatcher.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
Trusted Zone: united.com\www
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/stg_drm.ocx
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.11/uploader2.cab
DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} - hxxps://webdl.symantec.com/activex/symdlmgr.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} - file:///C:/Program%20Files/Elf%20Bowling%207%2017%20-%20The%20Last%20Insult/Images/armhelper.ocx
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://demo.webex.com/client/T25L/support/ieatgpc.cab
Notify: igfxcui - igfxsrvc.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

============= SERVICES / DRIVERS ===============

R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-6-24 93712]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-4-13 64288]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-3-19 162768]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-6-24 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-6-24 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-6-24 115216]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-3-19 19024]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-19 40384]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-6-24 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-6-24 66576]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1265264]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-19 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-3-19 40384]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-6-24 88816]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-6 135664]
S2 UmxAgent;HIPS Event Manager;"c:\program files\ca\sharedcomponents\hipsengine\umxagent.exe" –> c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [?]
S2 UmxCfg;HIPS Configuration Interpreter;"c:\program files\ca\sharedcomponents\hipsengine\umxcfg.exe" –> c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [?]
S2 UmxPol;HIPS Policy Manager;"c:\program files\ca\sharedcomponents\hipsengine\umxpol.exe" –> c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [?]

=============== Created Last 30 ================

2010-04-15 02:20:55 0 —-a-w- c:\documents and settings\owner\defogger_reenable
2010-04-14 01:53:18 0 d—–w- c:\program files\Windows Installer Clean Up
2010-04-14 01:53:09 0 d—–w- c:\program files\MSECACHE
2010-04-14 00:20:41 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-04-13 22:35:43 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-13 22:35:35 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-13 22:33:57 0 dc-h–w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-13 22:33:15 0 d—–w- c:\program files\Lavasoft
2010-04-13 21:09:32 0 d-sh–w- c:\documents and settings\owner\IECompatCache
2010-04-13 21:07:15 0 d-sh–w- c:\documents and settings\owner\PrivacIE
2010-04-13 21:07:00 0 d—–w- c:\docume~1\owner\applic~1\Windows Search
2010-04-13 21:03:00 0 d-sh–w- c:\documents and settings\owner\IETldCache
2010-04-13 20:52:26 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-13 20:52:21 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-13 20:52:12 0 d—–w- c:\windows\ie8updates
2010-04-13 20:51:44 64000 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-04-13 20:47:20 0 dc-h–w- c:\windows\ie8
2010-04-13 20:41:10 0 d—–w- c:\docume~1\owner\applic~1\Windows Desktop Search
2010-04-13 20:40:39 0 d—–w- c:\windows\system32\GroupPolicy
2010-04-13 20:40:39 0 d—–w- c:\program files\Windows Desktop Search
2010-04-13 20:39:49 98304 -c—-w- c:\windows\system32\dllcache\nlhtml.dll
2010-04-13 20:39:49 29696 -c—-w- c:\windows\system32\dllcache\mimefilt.dll
2010-04-13 20:39:49 192000 -c—-w- c:\windows\system32\dllcache\offfilt.dll
2010-04-13 19:47:04 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-04-13 19:22:17 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-13 19:21:53 0 d—–w- c:\program files\Hitman Pro 3.5
2010-04-13 19:21:53 0 d—–w- c:\docume~1\alluse~1\applic~1\Hitman Pro
2010-04-01 02:22:04 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-01 02:22:04 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-03-29 16:50:15 0 d—–w- c:\program files\Spybot - Search & Destroy
2010-03-29 16:50:15 0 d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2010-03-28 17:52:39 54016 —-a-w- c:\windows\system32\drivers\avcdyu.sys
2010-03-26 13:59:42 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-26 13:59:40 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-26 13:59:39 0 d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-24 22:12:58 0 d—–w- c:\program files\CCleaner
2010-03-22 22:56:02 3255 —-a-w- c:\windows\system32\wbem\Outlook_01caca12d8541d76.mof
2010-03-20 13:22:32 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-19 16:51:13 0 d—–w- c:\docume~1\alluse~1\applic~1\Alwil Software

==================== Find3M ====================

2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-04-15 02:06:52 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-04-15 02:06:52 280390 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-03-10 06:15:52 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-02-25 06:24:37 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11:07 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 13:10:28 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25:04 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 04:33:11 100864 —-a-w- c:\windows\system32\6to4svc.dll
2008-09-22 01:32:37 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008092120080922\index.dat

============= FINISH: 22:24:44.40 ===============

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-15 05:24:50
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Owner\LOCALS~1\Temp\axeyakod.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xEE878C08]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateKey [0xEE70F6EA]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwCreateSection [0xEEB39FD2]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwCreateSymbolicLinkObject [0xEE71040B]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteKey [0xEE879078]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xEE878FA2]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xEE87869A]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwMakeTemporaryObject [0xEE71075C]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenKey [0xEE70F64E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xEE8785DA]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwOpenSection [0xEE710130]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xEE87863E]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xEE878CBE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRenameKey [0xEE879146]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xEE878C7E]
SSDT \SystemRoot\System32\DRIVERS\kmxagent.sys (HIPS Agent Driver/CA) ZwSetInformationProcess [0xEEB39662]
SSDT \SystemRoot\System32\DRIVERS\KmxSbx.sys (HIPS Registry, Spawning and Devices Guard driver/CA) ZwSetSystemInformation [0xEE710538]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xEE878DFE]

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0xEE88550A]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwLoadDriver [0xEE885468]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObInsertObject
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Kernel code sections - GMER 1.0.15 —-

.text ntoskrnl.exe!_abnormal_termination + F0 804E275C 4 Bytes JMP 08EE70F6
PAGE ntoskrnl.exe!ObInsertObject 8056503A 5 Bytes JMP EE88297E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwCreateProcessEx 8057FE4C 7 Bytes JMP EE88550E \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ObMakeTemporaryObject 8059F8CA 5 Bytes JMP EE8814AA \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)
PAGE ntoskrnl.exe!ZwLoadDriver 805A3B73 7 Bytes JMP EE88546C \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software)

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\SearchIndexer.exe[2032] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 3E3E49A5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 3E3E49D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2392] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!DialogBoxParamW 7E4247AB 5 Bytes JMP 3E215505 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!SetWindowsHookExW 7E42820F 5 Bytes JMP 3E2E9A75 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!CallNextHookEx 7E42B3C6 5 Bytes JMP 3E2DD101 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!SetWindowLongA 7E42C29D 5 Bytes JMP 3E3E49A5 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!SetWindowLongW 7E42C2BB 5 Bytes JMP 3E3E49D6 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!CreateWindowExW 7E42D0A3 5 Bytes JMP 3E2EDAC4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!UnhookWindowsHookEx 7E42D5F3 5 Bytes JMP 3E25466E C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!DialogBoxIndirectParamW 7E432072 5 Bytes JMP 3E3E473F C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!MessageBoxIndirectA 7E43A082 5 Bytes JMP 3E3E4671 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!DialogBoxParamA 7E43B144 5 Bytes JMP 3E3E46DC C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!MessageBoxExW 7E450838 5 Bytes JMP 3E3E4542 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!MessageBoxExA 7E45085C 5 Bytes JMP 3E3E45A4 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!DialogBoxIndirectParamA 7E456D7D 5 Bytes JMP 3E3E47A2 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] USER32.dll!MessageBoxIndirectW 7E4664D5 5 Bytes JMP 3E3E4606 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 3E2EDB20 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
.text C:\Program Files\Internet Explorer\iexplore.exe[2564] ole32.dll!OleLoadFromStream 77529C85 5 Bytes JMP 3E3E4AA7 C:\WINDOWS\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs aswSP.SYS (avast! self protection module/ALWIL Software)

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \FileSystem\Ntfs \Ntfs kmxagent.sys (HIPS Agent Driver/CA)
AttachedDevice \FileSystem\Ntfs \Ntfs KmxFile.sys (HIPS File Guard driver/CA)

Device \Driver\Tcpip \Device\Ip kmxfw.sys (HIPS Firewall Driver/CA)

AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\Tcp kmxfw.sys (HIPS Firewall Driver/CA)

AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Modem \Device\00000056 kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\Tcpip \Device\Udp kmxfw.sys (HIPS Firewall Driver/CA)

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\RawIp kmxfw.sys (HIPS Firewall Driver/CA)

AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\Tcpip \Device\IPMULTICAST kmxfw.sys (HIPS Firewall Driver/CA)
Device \Driver\AFD \Device\Afd KmxCF.sys (HIPS Content Filter Driver/CA)
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- EOF - GMER 1.0.15 —-

Attachments:

[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Thanks for getting back to me. I am attaching the Combofix text. After running I have been unable to get back into whatthetech.com. I had to copy to a flash drive and send from another computer. Go9ogle comes up but the various links (images, mail, news, etc) do not show but the link can be seen at the bottom when a move the cursor over where I know they reside.

Here is the text.

ComboFix 10-04-17.07 - Owner 04/18/2010 11:56:50.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.766.223 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

((((((((((((((((((((((((( Files Created from 2010-03-18 to 2010-04-18 )))))))))))))))))))))))))))))))
.

2010-04-17 21:59 . 2010-04-17 21:59 ——– d—–w- c:\program files\iPod
2010-04-17 21:59 . 2010-04-17 22:00 ——– d—–w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-17 21:49 . 2010-04-17 21:50 ——– d—–w- c:\program files\QuickTime
2010-04-17 21:44 . 2010-04-17 21:44 ——– d—–w- c:\program files\Bonjour
2010-04-17 21:34 . 2010-04-17 21:35 ——– d—–w- c:\program files\Safari
2010-04-14 10:58 . 2010-04-14 10:58 ——– d-sh–w- c:\documents and settings\Administrator\IETldCache
2010-04-14 01:53 . 2010-04-14 01:53 ——– d—–w- c:\program files\Windows Installer Clean Up
2010-04-14 01:53 . 2010-04-14 01:53 ——– d—–w- c:\program files\MSECACHE
2010-04-14 00:20 . 2010-04-13 22:35 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-04-13 22:35 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-13 22:35 . 2010-04-13 22:35 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-04-13 22:33 . 2010-04-13 22:34 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-13 22:33 . 2010-04-13 22:35 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-04-13 22:33 . 2010-04-13 22:34 ——– d—–w- c:\program files\Lavasoft
2010-04-13 21:27 . 2010-04-13 21:27 ——– d—–w- c:\program files\ERUNT
2010-04-13 21:09 . 2010-04-13 21:09 ——– d-sh–w- c:\documents and settings\Owner\IECompatCache
2010-04-13 21:07 . 2010-04-13 21:07 ——– d-sh–w- c:\documents and settings\Owner\PrivacIE
2010-04-13 21:07 . 2010-04-13 21:07 ——– d—–w- c:\documents and settings\Owner\Application Data\Windows Search
2010-04-13 21:05 . 2010-04-13 21:05 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-04-13 21:03 . 2010-04-13 21:03 ——– d-sh–w- c:\documents and settings\Owner\IETldCache
2010-04-13 20:52 . 2010-02-25 06:24 12800 -c—-w- c:\windows\system32\dllcache\xpshims.dll
2010-04-13 20:52 . 2010-02-25 06:24 247808 -c—-w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-13 20:52 . 2010-04-13 21:13 ——– d—–w- c:\windows\ie8updates
2010-04-13 20:51 . 2010-02-16 04:50 64000 -c—-w- c:\windows\system32\dllcache\iecompat.dll
2010-04-13 20:47 . 2010-04-13 20:51 ——– dc-h–w- c:\windows\ie8
2010-04-13 20:42 . 2010-04-13 21:02 ——– d—–w- c:\program files\Microsoft Silverlight
2010-04-13 20:41 . 2010-04-13 20:41 ——– d—–w- c:\documents and settings\Owner\Application Data\Windows Desktop Search
2010-04-13 20:40 . 2010-04-13 21:15 ——– d—–w- c:\program files\Windows Desktop Search
2010-04-13 20:40 . 2010-04-13 20:40 ——– d—–w- c:\windows\system32\GroupPolicy
2010-04-13 20:39 . 2008-03-07 17:02 98304 -c—-w- c:\windows\system32\dllcache\nlhtml.dll
2010-04-13 20:39 . 2008-03-07 17:02 29696 -c—-w- c:\windows\system32\dllcache\mimefilt.dll
2010-04-13 20:39 . 2008-03-07 17:02 192000 -c—-w- c:\windows\system32\dllcache\offfilt.dll
2010-04-13 19:47 . 2010-04-13 19:47 12872 —-a-w- c:\windows\system32\bootdelete.exe
2010-04-13 19:22 . 2010-04-18 03:15 15944 —-a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-04-13 19:21 . 2010-04-13 20:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Hitman Pro
2010-04-13 19:21 . 2010-04-13 19:21 ——– d—–w- c:\program files\Hitman Pro 3.5
2010-04-01 02:22 . 2010-04-15 02:04 96512 -c–a-w- c:\windows\system32\dllcache\atapi.sys
2010-04-01 02:22 . 2010-04-15 02:04 96512 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-03-29 16:50 . 2010-04-14 22:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-03-29 16:50 . 2010-03-29 16:57 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-28 18:46 . 2010-03-28 18:46 ——– d—–w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2010-03-28 17:52 . 2010-03-28 17:52 54016 —-a-w- c:\windows\system32\drivers\avcdyu.sys
2010-03-26 13:59 . 2010-01-07 20:07 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-26 13:59 . 2010-01-07 20:07 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-03-26 13:59 . 2010-03-26 13:59 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-03-24 22:12 . 2010-04-13 21:31 ——– d—–w- c:\program files\CCleaner
2010-03-20 13:22 . 2009-10-23 15:28 3558912 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-03-19 16:51 . 2010-04-14 16:35 162768 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-19 16:51 . 2010-04-14 16:31 19024 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-19 16:51 . 2010-04-14 16:31 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-19 16:51 . 2010-04-14 16:35 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-19 16:51 . 2010-04-14 16:31 100432 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-19 16:51 . 2010-04-14 16:31 94800 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-19 16:51 . 2010-04-14 16:30 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-03-19 16:51 . 2010-04-14 16:47 38848 —-a-w- c:\windows\system32\avastSS.scr
2010-03-19 16:51 . 2010-04-14 16:47 153184 —-a-w- c:\windows\system32\aswBoot.exe
2010-03-19 16:51 . 2010-03-19 16:51 ——– d—–w- c:\program files\Alwil Software
2010-03-19 16:51 . 2010-03-19 16:51 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-04-18 15:38 . 2008-05-13 21:56 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-04-18 15:38 . 2008-05-13 21:56 280390 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-04-18 03:31 . 2008-05-12 19:50 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-04-18 03:15 . 2007-04-08 02:41 ——– d—–w- c:\documents and settings\Owner\Application Data\Apple Computer
2010-04-17 22:00 . 2007-05-15 04:12 ——– d—–w- c:\program files\iTunes
2010-04-17 21:59 . 2009-07-26 00:25 ——– d—–w- c:\program files\Common Files\Apple
2010-04-17 21:37 . 2010-04-17 21:37 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-17 21:28 . 2010-04-17 21:28 79144 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.22.7\SetupAdmin.exe
2010-04-14 03:12 . 2005-04-28 14:09 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-04-14 01:53 . 2010-04-14 01:53 3584 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}\Icon386ED4E3.exe
2010-04-13 20:41 . 2009-07-31 17:09 ——– d—–w- c:\program files\Microsoft
2010-03-20 16:10 . 2008-05-03 00:20 ——– d—–w- c:\program files\Incomplete
2010-03-20 16:10 . 2008-05-03 00:08 ——– d—–w- c:\program files\FrostWire
2010-03-20 02:41 . 2009-02-26 01:33 ——– d—–w- c:\documents and settings\Owner\Application Data\Smilebox
2010-03-19 17:26 . 2010-03-19 17:26 0 —-a-w- c:\documents and settings\Owner\Application Data\Adobe\Acrobat\7.0\Updater\DLMUninst_001.exe
2010-03-19 17:26 . 2005-05-05 13:39 ——– d—–w- c:\documents and settings\Owner\Application Data\AdobeUM
2010-03-19 17:15 . 2008-05-10 15:40 ——– d—–w- c:\documents and settings\All Users\Application Data\CA
2010-03-19 16:41 . 2009-03-12 16:27 ——– d—–w- c:\documents and settings\Owner\Application Data\SUPERAntiSpyware.com
2010-03-19 16:41 . 2009-03-12 16:27 ——– d—–w- c:\program files\SUPERAntiSpyware
2010-03-11 16:46 . 2010-02-13 14:34 ——– d—–w- c:\documents and settings\Owner\Application Data\Facebook
2010-03-10 06:15 . 2003-07-16 20:49 420352 —-a-w- c:\windows\system32\vbscript.dll
2010-03-09 19:15 . 2009-01-29 09:11 287368 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxTray.exe
2010-02-26 06:41 . 2010-02-26 06:41 5582848 —-a-w- c:\documents and settings\Owner\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-02-25 06:24 . 2003-07-16 20:51 916480 —-a-w- c:\windows\system32\wininet.dll
2010-02-24 13:11 . 2003-07-16 20:34 455680 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 22:05 . 2009-01-29 12:11 397960 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxStarter.exe
2010-02-17 22:05 . 2009-01-29 11:48 168584 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxBrowserEngine.dll
2010-02-17 22:05 . 2009-01-29 08:48 217736 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxDvd.exe
2010-02-17 21:50 . 2010-02-17 21:50 1602184 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxClient.exe
2010-02-17 21:10 . 2010-02-17 21:10 344712 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxDvdEngine.dll
2010-02-17 21:10 . 2010-02-17 21:10 135816 —-a-w- c:\documents and settings\Owner\Application Data\Smilebox\SmileboxUpdater.exe
2010-02-17 13:10 . 2003-07-16 20:39 2189952 —-a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 13:25 . 2002-08-29 01:04 2066816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-13 14:34 . 2010-02-13 14:34 50354 —-a-w- c:\documents and settings\Owner\Application Data\Facebook\uninstall.exe
2010-02-12 15:46 . 2010-02-12 15:46 91424 —-a-w- c:\windows\system32\dnssd.dll
2010-02-12 15:46 . 2010-02-12 15:46 107808 —-a-w- c:\windows\system32\dns-sd.exe
2010-02-12 04:33 . 2003-07-16 20:23 100864 —-a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2003-07-16 20:47 226880 —-a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-04 15:53 . 2010-04-13 22:33 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-02-01 22:04 . 2010-02-01 22:04 847040 —-a-w- c:\documents and settings\Owner\Application Data\Facebook\axfbootloader.dll
2010-02-01 22:04 . 2010-02-01 22:04 5578752 —-a-w- c:\documents and settings\Owner\Application Data\Facebook\npfbplugin_1_0_1.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D023EBF-70B8-45A6-9ED5-556515FA0FE4}]
2008-04-08 10:16 398776 —-a-w- c:\program files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmileboxTray"="c:\documents and settings\Owner\Application Data\Smilebox\SmileboxTray.exe" [2010-03-09 287368]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150596.exe" [2009-04-29 468408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-10-19 126976]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-07 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-04-14 2790472]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
Cyber-shot Viewer Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-1-21 155648]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2008-7-7 282624]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk
backup=c:\windows\pss\Kodak EasyShare software.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-06-07 03:46 57344 —-a-w- c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCMSMMSG]
2003-08-29 08:59 122880 —-a-w- c:\windows\BCMSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ——w- c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-18 01:53 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2006-10-19 01:05 204288 ——w- c:\program files\Windows Media Player\wmpnscfg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"comHost"=3 (0x3)
"CaCCProvSP"=3 (0x3)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [6/24/2008 7:08 PM 93712]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/13/2010 6:35 PM 64288]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [3/19/2010 12:51 PM 162768]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [6/24/2008 7:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [6/24/2008 7:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [6/24/2008 7:08 PM 115216]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [3/19/2010 12:51 PM 19024]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [6/24/2008 7:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [6/24/2008 7:08 PM 66576]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1265264]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [6/24/2008 7:08 PM 88816]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/6/2010 9:05 PM 135664]
S2 UmxAgent;HIPS Event Manager;"c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" –> c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [?]
S2 UmxCfg;HIPS Configuration Interpreter;"c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" –> c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [?]
S2 UmxPol;HIPS Policy Manager;"c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe" –> c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [?]
.
Contents of the 'Scheduled Tasks' folder

2010-04-18 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 22:35]

2010-04-17 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-04-18 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-12 19:29]

2010-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-07 01:05]

2010-04-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-07 01:05]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = localhost;*.local
Trusted Zone: united.com\www
DPF: {3D3B42C2-11BF-4732-A304-A01384B70D68} - hxxp://picasaweb.google.com/s/v/56.11/uploader2.cab
.
- - - - ORPHANS REMOVED - - - -

BHO-{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - (no file)
HKCU-Run-Sonic RecordNow! - (no file)
SafeBoot-svcWRSSSDK
MSConfigStartUp-cctray - c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe
MSConfigStartUp-mmtask - c:\program files\MusicMatch\MusicMatch Jukebox\mmtask.exe
MSConfigStartUp-MMTray - c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
MSConfigStartUp-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-18 12:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(432)
c:\windows\system32\WININET.dll
c:\program files\Windows Desktop Search\deskbar.dll
c:\program files\Windows Desktop Search\en-us\dbres.dll.mui
c:\program files\Windows Desktop Search\dbres.dll
c:\program files\Windows Desktop Search\wordwheel.dll
c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui
c:\program files\Windows Desktop Search\msnlExtRes.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2010-04-18 12:12:44
ComboFix-quarantined-files.txt 2010-04-18 16:12

Pre-Run: 36,770,836,480 bytes free
Post-Run: 37,010,731,008 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect

- - End Of File - - F77353569A13EFD643436A3AE0B9AC41
I have the same problem trying to get to the website. Whether I go straight to the thread or just to the forum it won't connect and just says waiting for http:…. Refresh is not pulling it in. Google also still is not showing the links. However, Avast automatically updated it's virus definitions.
I ran the program and it restarted the pc. I cleared cookies and history and I am still getting the same results. Google still does not show the links and other sites continue to say waiting for the site. Some sights, such as fodors will display the top banner but nothing else and it will show that it is still waiting for the page to load.
Uninstall Internet Explorer 8 to return to Internet Explorer 7 on Windows XP Click "Start," and then click "Control Panel." Click "Add or Remove Programs." Check "Show Updates" at the top of the dialog box. Scroll down the list and highlight the version of Internet Explorer 8 that you are running, and then click "Change/Remove." Remove IE 8
I am back on IE 7 and still seeing the problems. I am looking at the updates and I see one for Excel on 3/21 which is about the time that I started having the issues. It had unreadable characters in the description. I removed it and rebooted to see if that would have any effect. That didn't so anything either.
Nope, just updated Excel again. I tried a cold boot and still no effect. I noticed on other thing. When I wen back to IE7 the tabs went back to chowing the tab welcome instead of my home page (google). So I changed this and applied before I cold booted and still was not set when I opened a tab, Subsequent changing of the settings, close out and reload of IE still did not go to home page when a new tab is created.
No, I am able to set home page to google. What I meant was that when you open a new tab in IE you get the "You Opened a New Tab" page. You can change the settings in Internet Options to open your home page (in my case Google) when you open a new tab. Well I set that and that is also not working. I get the New Tab page. I still have the other issues where Google.com does not show the links (mail, images, etc) and websites will not load. Some will after I refresh a couple of times but WTT and some others will not load and just say waiting for the page.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI