This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Web Browser Constantly Re-directs - I have included my Hijackthis log

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I got the following logs this evening…



ComboFix log:


ComboFix 10-06-03.01 - Owner 06/04/2010 23:04:18.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1278.838 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\desiree.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\windows\system32\tmp.tmp"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\tmp.tmp

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_UQPFFVGKYUDXFE
——-\Service_uqpffvgkyudxfe


((((((((((((((((((((((((( Files Created from 2010-05-05 to 2010-06-05 )))))))))))))))))))))))))))))))
.

2010-06-02 13:04 . 2010-06-02 13:04 29512 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys
2010-06-02 13:04 . 2010-06-02 13:04 242896 —-a-w- c:\documents and settings\All Users\Application Data\avg9\update\backup\avgtdix.sys
2010-05-29 04:32 . 2009-10-23 14:27 3555328 -c—-w- c:\windows\system32\dllcache\moviemk.exe
2010-05-18 18:21 . 2010-05-18 18:21 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-05-18 18:21 . 2010-05-18 18:21 ——– d—–w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-05 03:05 . 2010-01-28 15:56 0 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\prvlcl.dat
2010-06-02 13:04 . 2010-01-28 15:20 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys
2010-06-02 13:04 . 2010-01-28 15:19 29584 —-a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-06-01 03:33 . 2009-12-01 16:59 19808 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-29 03:35 . 2010-05-18 06:12 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-28 02:02 . 2009-12-01 05:09 95360 —-a-w- c:\windows\system32\drivers\atapi.sys
2010-05-18 14:12 . 2010-05-18 05:01 ——– d—–w- c:\program files\Google
2010-05-18 06:16 . 2010-05-18 06:12 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-18 05:58 . 2010-02-01 15:25 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-05-18 01:16 . 2010-01-28 15:19 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-05-17 17:37 . 2010-05-16 22:07 112 —-a-w- c:\documents and settings\All Users\Application Data\xm8848Hu.dat
2010-05-13 01:01 . 2010-01-24 21:43 664 —-a-w- c:\windows\system32\d3d9caps.dat
2010-03-24 18:17 . 2010-03-24 08:04 952768 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 —-a-w- c:\documents and settings\All Users\Application Data\Adobe\Reader\9.2\ARM\17553\AcrobatUpdater.exe
2010-03-15 14:45 . 2010-03-15 14:45 12464 —-a-w- c:\windows\system32\avgrsstx.dll
2010-03-15 14:43 . 2010-01-28 15:19 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys
2010-03-10 06:15 . 2003-07-16 20:49 420352 —-a-w- c:\windows\system32\vbscript.dll
2009-12-01 05:42 . 2009-12-01 05:42 800544 —-a-w- c:\program files\JavaSetup6u17-rv.exe
2009-12-01 05:17 . 2009-12-01 05:17 8084968 —-a-w- c:\program files\Firefox Setup 3.5.5.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-05-29_04.30.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-02 15:24 . 2010-04-21 13:28 46080 c:\windows\system32\tzchange.exe
- 2009-12-02 15:24 . 2009-10-28 15:07 46080 c:\windows\system32\tzchange.exe
+ 2001-08-17 22:36 . 2009-11-27 17:33 17920 c:\windows\system32\msyuv.dll
+ 2003-07-16 20:36 . 2009-11-27 16:37 28672 c:\windows\system32\msvidc32.dll
+ 2003-07-16 20:36 . 2009-11-27 16:37 11264 c:\windows\system32\msrle32.dll
- 2003-07-16 20:36 . 2004-08-04 07:56 11264 c:\windows\system32\msrle32.dll
+ 2009-03-08 09:31 . 2010-02-25 06:24 55296 c:\windows\system32\msfeedsbs.dll
- 2009-03-08 09:31 . 2009-03-08 09:31 55296 c:\windows\system32\msfeedsbs.dll
+ 2003-07-16 20:31 . 2010-02-25 06:24 25600 c:\windows\system32\jsproxy.dll
- 2003-07-16 20:31 . 2009-03-08 09:33 25600 c:\windows\system32\jsproxy.dll
+ 2001-08-17 22:36 . 2009-11-27 16:37 48128 c:\windows\system32\iyuv_32.dll
+ 2009-12-01 17:10 . 2010-02-25 06:24 12800 c:\windows\system32\dllcache\xpshims.dll
- 2009-12-01 17:10 . 2009-12-21 19:14 12800 c:\windows\system32\dllcache\xpshims.dll
+ 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\system32\dllcache\msyuv.dll
+ 2003-07-16 20:36 . 2009-11-27 16:37 28672 c:\windows\system32\dllcache\msvidc32.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 11264 c:\windows\system32\dllcache\msrle32.dll
- 2009-12-01 17:10 . 2009-12-21 19:14 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-12-01 17:10 . 2010-02-25 06:24 55296 c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-03-08 09:33 . 2010-02-25 06:24 25600 c:\windows\system32\dllcache\jsproxy.dll
- 2009-03-08 09:33 . 2009-03-08 09:33 25600 c:\windows\system32\dllcache\jsproxy.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\system32\dllcache\iyuv_32.dll
+ 2009-12-14 07:35 . 2009-12-14 07:35 33280 c:\windows\system32\dllcache\csrsrv.dll
+ 2010-01-13 14:10 . 2010-01-13 14:10 85504 c:\windows\system32\dllcache\cabview.dll
- 2009-06-10 14:21 . 2009-06-10 14:21 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2009-06-10 14:21 . 2009-11-27 16:37 84992 c:\windows\system32\dllcache\avifil32.dll
+ 2003-07-16 20:26 . 2009-12-14 07:35 33280 c:\windows\system32\csrsrv.dll
+ 2003-07-16 20:25 . 2010-01-13 14:10 85504 c:\windows\system32\cabview.dll
+ 2003-07-16 20:24 . 2009-11-27 16:37 84992 c:\windows\system32\avifil32.dll
- 2003-07-16 20:24 . 2009-06-10 14:21 84992 c:\windows\system32\avifil32.dll
- 2009-12-02 15:07 . 2009-12-28 05:24 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 23040 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 27136 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 11264 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 12288 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-05-31 01:07 . 2009-03-08 09:33 12288 c:\windows\ie8updates\KB980182-IE8\xpshims.dll
+ 2010-05-31 01:07 . 2009-03-08 09:31 55296 c:\windows\ie8updates\KB980182-IE8\msfeedsbs.dll
+ 2010-05-31 01:07 . 2009-03-08 09:33 25600 c:\windows\ie8updates\KB980182-IE8\jsproxy.dll
+ 2010-05-31 01:04 . 2008-07-08 13:02 17272 c:\windows\ie8updates\KB971961-IE8\spmsg.dll
+ 2010-05-31 01:04 . 2008-07-08 13:02 26488 c:\windows\ie8updates\KB971961-IE8\spcustom.dll
+ 2009-11-27 17:33 . 2009-11-27 17:33 17920 c:\windows\Driver Cache\i386\msyuv.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 48128 c:\windows\Driver Cache\i386\iyuv_32.dll
+ 2001-08-17 22:36 . 2009-11-27 16:37 8704 c:\windows\system32\tsbyuv.dll
+ 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\system32\dllcache\tsbyuv.dll
+ 2009-12-02 15:07 . 2010-05-31 01:27 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 4096 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-11-27 16:37 . 2009-11-27 16:37 8704 c:\windows\Driver Cache\i386\tsbyuv.dll
+ 2003-07-16 20:51 . 2009-12-24 07:05 177664 c:\windows\system32\wintrust.dll
+ 2006-06-23 17:33 . 2010-02-25 06:24 916480 c:\windows\system32\wininet.dll
- 2005-09-01 01:49 . 2009-01-07 23:20 474112 c:\windows\system32\shlwapi.dll
+ 2005-09-01 01:49 . 2009-12-08 08:59 474112 c:\windows\system32\shlwapi.dll
+ 2003-07-16 20:40 . 2010-02-25 06:24 206848 c:\windows\system32\occache.dll
+ 2003-07-16 20:36 . 2010-02-25 06:24 611840 c:\windows\system32\mstime.dll
- 2003-07-16 20:36 . 2009-03-08 09:32 611840 c:\windows\system32\mstime.dll
+ 2009-03-08 09:32 . 2010-02-25 06:24 594432 c:\windows\system32\msfeeds.dll
- 2009-03-08 09:32 . 2009-03-08 09:32 594432 c:\windows\system32\msfeeds.dll
- 2006-05-18 05:58 . 2009-03-08 09:33 726528 c:\windows\system32\jscript.dll
+ 2006-05-18 05:58 . 2009-12-09 05:53 726528 c:\windows\system32\jscript.dll
+ 2006-02-24 21:24 . 2010-02-25 06:24 184320 c:\windows\system32\iepeers.dll
+ 2003-07-16 20:30 . 2010-02-25 06:24 387584 c:\windows\system32\iedkcs32.dll
+ 2003-07-16 20:30 . 2010-02-24 09:54 173056 c:\windows\system32\ie4uinit.exe
- 2003-07-16 20:30 . 2009-03-08 09:32 173056 c:\windows\system32\ie4uinit.exe
+ 2003-07-16 20:47 . 2010-02-11 12:01 226880 c:\windows\system32\drivers\tcpip6.sys
+ 2003-07-16 20:46 . 2009-12-31 16:14 352640 c:\windows\system32\drivers\srv.sys
+ 2003-07-16 20:34 . 2010-02-24 12:31 454016 c:\windows\system32\drivers\mrxsmb.sys
+ 2009-12-24 07:05 . 2009-12-24 07:05 177664 c:\windows\system32\dllcache\wintrust.dll
+ 2009-03-08 09:34 . 2010-02-25 06:24 916480 c:\windows\system32\dllcache\wininet.dll
- 2009-03-08 09:33 . 2009-03-08 09:33 420352 c:\windows\system32\dllcache\vbscript.dll
+ 2009-03-08 09:33 . 2010-03-10 06:15 420352 c:\windows\system32\dllcache\vbscript.dll
+ 2006-08-16 09:37 . 2010-02-11 12:01 226880 c:\windows\system32\dllcache\tcpip6.sys
+ 2006-08-14 10:34 . 2009-12-31 16:14 352640 c:\windows\system32\dllcache\srv.sys
- 2009-01-07 23:20 . 2009-01-07 23:20 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2009-01-07 23:20 . 2009-12-08 08:59 474112 c:\windows\system32\dllcache\shlwapi.dll
+ 2009-03-08 09:34 . 2010-02-25 06:24 206848 c:\windows\system32\dllcache\occache.dll
- 2009-03-08 09:32 . 2009-03-08 09:32 611840 c:\windows\system32\dllcache\mstime.dll
+ 2009-03-08 09:32 . 2010-02-25 06:24 611840 c:\windows\system32\dllcache\mstime.dll
- 2009-12-01 17:10 . 2009-12-21 19:14 594432 c:\windows\system32\dllcache\msfeeds.dll
+ 2009-12-01 17:10 . 2010-02-25 06:24 594432 c:\windows\system32\dllcache\msfeeds.dll
+ 2006-05-05 09:41 . 2010-02-24 12:31 454016 c:\windows\system32\dllcache\mrxsmb.sys
- 2003-07-16 20:31 . 2009-03-08 09:33 726528 c:\windows\system32\dllcache\jscript.dll
+ 2003-07-16 20:31 . 2009-12-09 05:53 726528 c:\windows\system32\dllcache\jscript.dll
+ 2009-12-01 17:10 . 2010-02-25 06:24 247808 c:\windows\system32\dllcache\ieproxy.dll
+ 2009-03-08 09:31 . 2010-02-25 06:24 184320 c:\windows\system32\dllcache\iepeers.dll
+ 2009-03-08 19:09 . 2010-02-25 06:24 387584 c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 09:32 . 2010-02-24 09:54 173056 c:\windows\system32\dllcache\ie4uinit.exe
- 2009-03-08 09:32 . 2009-03-08 09:32 173056 c:\windows\system32\dllcache\ie4uinit.exe
+ 2006-08-16 11:58 . 2010-02-12 04:47 100864 c:\windows\system32\dllcache\6to4svc.dll
+ 2006-08-16 12:14 . 2010-02-12 04:47 100864 c:\windows\system32\6to4svc.dll
- 2009-12-02 15:07 . 2009-12-28 05:24 409600 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 409600 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 286720 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 286720 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 249856 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 249856 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 794624 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 794624 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-12-02 15:07 . 2010-05-31 01:27 135168 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2009-12-02 15:07 . 2009-12-28 05:24 135168 c:\windows\Installer\{91120409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2010-05-31 01:07 . 2009-03-08 09:33 420352 c:\windows\ie8updates\KB981332-IE8\vbscript.dll
+ 2010-05-31 01:07 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB981332-IE8\spuninst\updspapi.dll
+ 2010-05-31 01:07 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB981332-IE8\spuninst\spuninst.exe
+ 2010-05-31 01:06 . 2009-03-08 09:34 914944 c:\windows\ie8updates\KB980182-IE8\wininet.dll
+ 2010-05-31 01:07 . 2009-05-26 11:40 382840 c:\windows\ie8updates\KB980182-IE8\spuninst\updspapi.dll
+ 2010-05-31 01:07 . 2009-05-26 11:40 231288 c:\windows\ie8updates\KB980182-IE8\spuninst\spuninst.exe
+ 2010-05-31 01:06 . 2009-03-08 09:34 109568 c:\windows\ie8updates\KB980182-IE8\occache.dll
+ 2010-05-31 01:06 . 2009-03-08 09:32 611840 c:\windows\ie8updates\KB980182-IE8\mstime.dll
+ 2010-05-31 01:07 . 2009-03-08 09:32 594432 c:\windows\ie8updates\KB980182-IE8\msfeeds.dll
+ 2010-05-31 01:07 . 2009-03-08 09:33 246784 c:\windows\ie8updates\KB980182-IE8\ieproxy.dll
+ 2010-05-31 01:07 . 2009-03-08 09:31 183808 c:\windows\ie8updates\KB980182-IE8\iepeers.dll
+ 2010-05-31 01:07 . 2009-03-08 19:09 391536 c:\windows\ie8updates\KB980182-IE8\iedkcs32.dll
+ 2010-05-31 01:07 . 2009-03-08 09:32 173056 c:\windows\ie8updates\KB980182-IE8\ie4uinit.exe
+ 2010-05-31 01:18 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB976662-IE8\spuninst\updspapi.dll
+ 2010-05-31 01:18 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB976662-IE8\spuninst\spuninst.exe
+ 2010-05-31 01:18 . 2009-06-22 06:44 726528 c:\windows\ie8updates\KB976662-IE8\jscript.dll
+ 2010-05-31 01:04 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\updspapi.dll
+ 2010-05-31 01:04 . 2008-07-08 13:02 755576 c:\windows\ie8updates\KB971961-IE8\update.exe
+ 2010-05-31 01:04 . 2008-07-08 13:02 382840 c:\windows\ie8updates\KB971961-IE8\spuninst\updspapi.dll
+ 2010-05-31 01:04 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst\spuninst.exe
+ 2010-05-31 01:04 . 2008-07-08 13:02 231288 c:\windows\ie8updates\KB971961-IE8\spuninst.exe
+ 2010-05-31 01:04 . 2009-03-08 09:33 726528 c:\windows\ie8updates\KB971961-IE8\jscript.dll
+ 2004-10-28 01:14 . 2010-02-24 12:31 454016 c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2004-08-04 07:56 . 2010-02-16 12:27 4734976 c:\windows\system32\wmp.dll
+ 2006-08-31 02:42 . 2010-02-25 06:24 1209344 c:\windows\system32\urlmon.dll
+ 2003-07-16 20:42 . 2009-11-27 17:33 1291264 c:\windows\system32\quartz.dll
+ 2003-07-16 20:39 . 2010-02-16 13:19 2181376 c:\windows\system32\ntoskrnl.exe
+ 2002-08-29 01:04 . 2010-02-16 12:39 2058368 c:\windows\system32\ntkrnlpa.exe
+ 2006-06-30 16:28 . 2010-02-25 06:24 5944832 c:\windows\system32\mshtml.dll
+ 2009-03-08 09:32 . 2010-02-25 06:24 1985536 c:\windows\system32\iertutil.dll
+ 2009-11-30 21:49 . 2010-06-01 01:08 1411512 c:\windows\system32\FNTCACHE.DAT
+ 2009-07-13 08:18 . 2010-02-16 12:27 4734976 c:\windows\system32\dllcache\wmp.dll
+ 2009-03-08 09:34 . 2010-02-25 06:24 1209344 c:\windows\system32\dllcache\urlmon.dll
+ 2009-06-03 19:27 . 2009-11-27 17:33 1291264 c:\windows\system32\dllcache\quartz.dll
+ 2009-12-02 15:56 . 2010-02-16 13:19 2181376 c:\windows\system32\dllcache\ntoskrnl.exe
+ 2009-12-02 15:56 . 2010-02-16 12:39 2016768 c:\windows\system32\dllcache\ntkrpamp.exe
+ 2009-12-02 15:56 . 2010-02-16 12:39 2058368 c:\windows\system32\dllcache\ntkrnlpa.exe
+ 2009-12-02 15:56 . 2010-02-16 13:17 2137088 c:\windows\system32\dllcache\ntkrnlmp.exe
+ 2009-03-08 09:41 . 2010-02-25 06:24 5944832 c:\windows\system32\dllcache\mshtml.dll
- 2009-12-01 17:10 . 2009-12-21 19:14 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2009-12-01 17:10 . 2010-02-25 06:24 1985536 c:\windows\system32\dllcache\iertutil.dll
+ 2009-10-16 23:07 . 2009-10-16 23:07 6115328 c:\windows\Installer\d1032c.msp
+ 2010-04-21 22:46 . 2010-04-21 22:46 5522432 c:\windows\Installer\d1031a.msp
+ 2010-01-27 22:53 . 2010-01-27 22:53 6820864 c:\windows\Installer\d10308.msp
+ 2010-01-19 23:29 . 2010-01-19 23:29 5050368 c:\windows\Installer\d102f6.msp
+ 2007-04-19 19:49 . 2007-04-19 19:49 1661280 c:\windows\Installer\$PatchCache$\Managed\9040211900063D11C8EF10054038389C\11.0.8173\PPTVIEW.EXE
+ 2010-05-31 01:06 . 2009-03-08 09:34 1206784 c:\windows\ie8updates\KB980182-IE8\urlmon.dll
+ 2010-05-31 01:06 . 2009-03-08 09:41 5937152 c:\windows\ie8updates\KB980182-IE8\mshtml.dll
+ 2010-05-31 01:07 . 2009-03-08 09:32 1985024 c:\windows\ie8updates\KB980182-IE8\iertutil.dll
+ 2005-03-02 00:59 . 2010-02-16 13:19 2181376 c:\windows\Driver Cache\i386\ntoskrnl.exe
+ 2005-03-02 00:34 . 2010-02-16 12:39 2016768 c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2005-03-02 00:34 . 2010-02-16 12:39 2058368 c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2005-03-02 00:57 . 2010-02-16 13:17 2137088 c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2009-12-01 15:06 . 2010-04-30 16:51 32058312 c:\windows\system32\MRT.exe
+ 2009-03-08 09:39 . 2010-02-25 16:54 11070976 c:\windows\system32\ieframe.dll
+ 2009-12-01 17:10 . 2010-02-25 16:54 11070976 c:\windows\system32\dllcache\ieframe.dll
+ 2010-05-31 01:07 . 2009-03-08 09:39 11063808 c:\windows\ie8updates\KB980182-IE8\ieframe.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2010-04-19 15:25 2117704 —-a-w- c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 2117704]

[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\System32\igfxtray.exe" [2005-10-19 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2005-10-19 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"FlashPlayerUpdate"="c:\windows\system32\Macromed\Flash\FlashUtil10c.exe" [2009-07-18 257440]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-03-15 14:45 12464 —-a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [1/28/2010 10:19 AM 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [1/28/2010 10:20 AM 242896]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [3/15/2010 9:45 AM 308064]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: microsoft.com\*.update
Trusted Zone: windowsupdate.com\download
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\209kmn1w.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: keyword.URL - hxxp://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-tb-web_us&p=
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-04 23:11
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0e,73,84,f8,55,01,40,bd,79,5c,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,b2,0e,73,84,f8,55,01,40,bd,79,5c,\
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2580)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-06-04 23:14:53 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-05 04:14
ComboFix2.txt 2010-05-29 04:35

Pre-Run: 475,611,578,368 bytes free
Post-Run: 475,520,798,720 bytes free

- - End Of File - - 50A584B3A6703EA7C29C35B6E15ADAEC




GooredFix log:


GooredFix by jpshortstuff (08.01.10.1)
Log created at 23:25 on 04/06/2010 (Owner)
Firefox version 3.5.9 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [05:18 01/12/2009]
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [05:43 01/12/2009]

C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\209kmn1w.default\extensions\
{73a6fe31-595d-460b-a920-fcc0f8843232} [17:25 28/01/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [15:19 28/01/2010]
"avg@igeared"="C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared" [18:12 22/05/2010]

-=E.O.F=-





TDSSKiller log:


23:26:27:296 0340 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48
23:26:27:296 0340 ================================================================================
23:26:27:296 0340 SystemInfo:

23:26:27:296 0340 OS Version: 5.1.2600 ServicePack: 2.0
23:26:27:296 0340 Product type: Workstation
23:26:27:296 0340 ComputerName: WILSON
23:26:27:296 0340 UserName: Owner
23:26:27:296 0340 Windows directory: C:\WINDOWS
23:26:27:296 0340 Processor architecture: Intel x86
23:26:27:296 0340 Number of processors: 1
23:26:27:296 0340 Page size: 0x1000
23:26:27:312 0340 Boot type: Normal boot
23:26:27:312 0340 ================================================================================
23:26:27:656 0340 Initialize success
23:26:27:656 0340
23:26:27:656 0340 Scanning Services …
23:26:28:000 0340 Raw services enum returned 290 services
23:26:28:015 0340
23:26:28:015 0340 Scanning Drivers …
23:26:28:609 0340 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
23:26:28:671 0340 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
23:26:28:718 0340 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
23:26:28:765 0340 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
23:26:28:796 0340 AFD (55e6e1c51b6d30e54335750955453702) C:\WINDOWS\System32\drivers\afd.sys
23:26:28:968 0340 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
23:26:28:984 0340 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
23:26:29:046 0340 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
23:26:29:062 0340 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
23:26:29:093 0340 AvgLdx86 (9c0a7e6d3cb9a8a7ad4e4575d9a42e94) C:\WINDOWS\System32\Drivers\avgldx86.sys
23:26:29:125 0340 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\WINDOWS\System32\Drivers\avgmfx86.sys
23:26:29:156 0340 AvgTdiX (6e11bbc8dc5af836adc9c5f682fa3186) C:\WINDOWS\System32\Drivers\avgtdix.sys
23:26:29:218 0340 bcm4sbxp (b60f57b4d9cdbc663cc03eb8af7ec34e) C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys
23:26:29:265 0340 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
23:26:29:312 0340 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
23:26:29:375 0340 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
23:26:29:406 0340 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
23:26:29:421 0340 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
23:26:29:515 0340 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
23:26:29:562 0340 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
23:26:29:609 0340 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
23:26:29:640 0340 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
23:26:29:687 0340 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
23:26:29:718 0340 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
23:26:29:734 0340 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
23:26:29:765 0340 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
23:26:29:781 0340 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
23:26:29:796 0340 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
23:26:29:828 0340 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
23:26:29:843 0340 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
23:26:29:875 0340 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
23:26:29:890 0340 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
23:26:29:921 0340 hidusb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
23:26:29:984 0340 HPZid412 (d03d10f7ded688fecf50f8fbf1ea9b8a) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
23:26:30:000 0340 HPZipr12 (89f41658929393487b6b7d13c8528ce3) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
23:26:30:015 0340 HPZius12 (abcb05ccdbf03000354b9553820e39f8) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
23:26:30:078 0340 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
23:26:30:140 0340 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
23:26:30:218 0340 ialm (44b7d5a4f2bd9fe21aea0bb0bace38c4) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
23:26:30:250 0340 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
23:26:30:359 0340 IntelC51 (7509c548400f4c9e0211e3f6e66abbe6) C:\WINDOWS\system32\DRIVERS\IntelC51.sys
23:26:30:406 0340 IntelC52 (9584ffdd41d37f2c239681d0dac2513e) C:\WINDOWS\system32\DRIVERS\IntelC52.sys
23:26:30:437 0340 IntelC53 (de2686c0e012e6ae24acd6e79eb7ff5d) C:\WINDOWS\system32\DRIVERS\IntelC53.sys
23:26:30:468 0340 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\system32\DRIVERS\intelide.sys
23:26:30:500 0340 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
23:26:30:546 0340 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
23:26:30:593 0340 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
23:26:30:625 0340 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
23:26:30:656 0340 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
23:26:30:703 0340 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
23:26:30:734 0340 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
23:26:30:765 0340 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
23:26:30:781 0340 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
23:26:30:828 0340 klmd23 (67e1faa88fb397b3d56909d7e04f4dd3) C:\WINDOWS\system32\drivers\klmd.sys
23:26:30:921 0340 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
23:26:30:968 0340 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
23:26:31:031 0340 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
23:26:31:062 0340 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
23:26:31:109 0340 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys
23:26:31:140 0340 mohfilt (59b8b11ff70728eec60e72131c58b716) C:\WINDOWS\system32\DRIVERS\mohfilt.sys
23:26:31:171 0340 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
23:26:31:203 0340 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
23:26:31:234 0340 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
23:26:31:265 0340 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
23:26:31:312 0340 MRxSmb (fb6c89bb3ce282b08bdb1e3c179e1c39) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
23:26:31:359 0340 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
23:26:31:390 0340 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
23:26:31:421 0340 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
23:26:31:453 0340 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
23:26:31:484 0340 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
23:26:31:500 0340 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
23:26:31:531 0340 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
23:26:31:562 0340 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
23:26:31:593 0340 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
23:26:31:625 0340 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
23:26:31:640 0340 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
23:26:31:656 0340 NetBIOS (3a2aca8fc1d7786902ca434998d7ceb4) C:\WINDOWS\system32\DRIVERS\netbios.sys
23:26:31:687 0340 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
23:26:31:734 0340 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
23:26:31:781 0340 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
23:26:31:812 0340 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
23:26:31:843 0340 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
23:26:31:875 0340 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
23:26:31:890 0340 OMCI (cec7e2c6c1fa00c7ab2f5434f848ae51) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
23:26:31:953 0340 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
23:26:31:984 0340 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
23:26:32:015 0340 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
23:26:32:031 0340 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
23:26:32:062 0340 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
23:26:32:109 0340 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
23:26:32:203 0340 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
23:26:32:218 0340 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys
23:26:32:250 0340 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
23:26:32:265 0340 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
23:26:32:359 0340 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
23:26:32:406 0340 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
23:26:32:421 0340 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
23:26:32:453 0340 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
23:26:32:468 0340 Rdbss (03b965b1ca47f6ef60eb5e51cb50e0af) C:\WINDOWS\system32\DRIVERS\rdbss.sys
23:26:32:500 0340 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
23:26:32:546 0340 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
23:26:32:593 0340 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
23:26:32:625 0340 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
23:26:32:656 0340 serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
23:26:32:687 0340 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
23:26:32:703 0340 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
23:26:32:750 0340 smwdm (99a9e1ef62f955c82a5001ac94b4b77b) C:\WINDOWS\system32\drivers\smwdm.sys
23:26:32:843 0340 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
23:26:32:859 0340 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\system32\DRIVERS\sr.sys
23:26:32:906 0340 Srv (7a4f147cc6b133f905f6e65e2f8669fb) C:\WINDOWS\system32\DRIVERS\srv.sys
23:26:32:937 0340 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
23:26:32:953 0340 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
23:26:33:046 0340 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
23:26:33:078 0340 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
23:26:33:109 0340 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
23:26:33:140 0340 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
23:26:33:156 0340 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
23:26:33:203 0340 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
23:26:33:265 0340 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
23:26:33:312 0340 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
23:26:33:359 0340 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
23:26:33:375 0340 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
23:26:33:406 0340 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
23:26:33:437 0340 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:26:33:468 0340 usbstor (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
23:26:33:484 0340 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
23:26:33:515 0340 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
23:26:33:562 0340 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
23:26:33:593 0340 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
23:26:33:640 0340 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
23:26:33:703 0340 {6080A529-897E-4629-A488-ABA0C29B635E} (61002db7b6efb5711685b9d79b8e8ce6) C:\WINDOWS\system32\drivers\ialmsbw.sys
23:26:33:734 0340 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (35ce2baa708ea038ab72359de87bab87) C:\WINDOWS\system32\drivers\ialmkchw.sys
23:26:33:734 0340
23:26:33:734 0340 Completed
23:26:33:734 0340
23:26:33:734 0340 Results:
23:26:33:734 0340 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
23:26:33:750 0340 File objects infected / cured / cured on reboot: 0 / 0 / 0
23:26:33:750 0340
23:26:33:750 0340 KLMD(ARK) unloaded successfully
Hello Desiree

Thank you for the logs. Please work your way through the following steps:


  • Clean out your temporary files


    • Please download ATF Cleaner by Atribune by clicking here and save the file (called ATF-Cleaner.exe) to your desktop.
    • Run the program by double clicking the ATF-Cleaner.exe icon located on your desktop.
    • Check the boxes to the left of the following:

    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Java Cache

    • The rest are optional. If you want to remove everything check the "Select All" box.
    • Click on "Empty Selected" to begin cleaning.
    • Once the "Done Cleaning" message appears, click OK.
    • If you use Firefox, Click on the Firefox tab and repeat the above process.
    • When you have finished cleaning, click on the "Exit" button in the main menu.

  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform full scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please update your Java


    • To update your Java, Click on "Start" then on "Control Panel" and then on the Java icon (looks like a coffee cup).
    • In the window that opens, click on the "Update" tab, and then on "Update Now".
    • Your Java should begin to update. Please follow any prompts that you receive.


    Please provide the MBAM log in your next reply.

    Also, please describe how your machine is behaving now. Are you still experiencing problems?
Hi - I cleaned out my temporary files (including Firefox, I did the steps again for that too.) I also ran MBAM, and below is the log for that (it did find some infected objects and deleted them). I also have Java updated now. As to my computer's performance - so far I've seen a huge improvement. I can browse the sites I need to without any redirects, that's in Firefox AND Internet Explorer. Also, so far, my machine has NOT been running slow. So it looks like everything you've helped me with has made a difference in it's performance while on the internet AND while working in programs in general. MBAM log: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4175 Windows 5.1.2600 Service Pack 2 Internet Explorer 8.0.6001.18702 6/7/2010 11:17:32 AM mbam-log-2010-06-07 (11-17-32).txt Scan type: Full scan (C:\|) Objects scanned: 190066 Time elapsed: 48 minute(s), 32 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 6 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\0FGAVxDX.exe.vir (Backdoor.Sinowal) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\system32\dnhiozxybgjuwe.dll.vir (Adware.BHO) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\system32\tpithphlaqely.exe.vir (Adware.AdRotator) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2241BAC8-F343-4AE6-81CF-D5D6FF003AAE}\RP84\A0156893.exe (Backdoor.Sinowal) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{2241BAC8-F343-4AE6-81CF-D5D6FF003AAE}\RP84\A0156895.exe (Adware.AdRotator) -> Quarantined and deleted successfully.
Hello Desiree

Thank you for the logs.

so far I've seen a huge improvement

Thats great news, but we still have some work to do. The MBAM log reported evidence of some Backdoor infections on your system (which have now been removed).


  • IMPORTANT!!!


    • It is very likely that the malware we are dealing with has password stealing capabilities. For this reason you are STRONGLY ADVISED to disconnect the infected computer from the internet and from any networked computers until it can be cleaned. If you have networked compters, these must be checked, as they may also be infected.
    • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft. It may also be prudent to ask your banks to freeze/disable online access to your accounts until you are certain that your computer is free of the infecting malware.


    • It is ESSENTIAL that you use a CLEAN (uninfected) computer to change ALL of your passwords for the online services (banking etc) that you use. DO NOT USE THE INFECTED COMPUTER TO CHANGE YOUR PASSWORDS OR TO PERFORM ANY FINANCIAL TRANSACTIONS, as doing so will give the attacker access to the new password that you create.


    The following procedure will remove the files that ComboFix has quarantined and flush your infected restore points:

  • Please Uninstall Combofix

    • Click on "Start" and then on "Run".
    • Now type combofix /uninstall in the run box and click "OK". Please note the space between the "x" and the "/Uninstall", it needs to be there.

  • MBAM


    • Please update MBAM, scan your system again and post the log that is created (if anything malicious is found have MBAM remove it as you did before).

…STRONGLY ADVISED to disconnect the infected computer from the internet and from any networked computers until it can be cleaned. If you have networked compters, these must be checked, as they may also be infected.


I think my other computer is not directly connected to the infected one; and the other computer is the main one connected to my dsl modem, whereas the infected computer gains internet access through a router. I'm not sure if these two computers are really networked together then, however, I will run a check on the system there as well. Which program do I need to run to check that one out? i.e: MBAM, AVG, any of the others I have used on the infected one thus far? Just want to make sure before I go on to do that. Thanks!
Hello Desiree

I'm not sure if these two computers are really networked together

Does your other computer show any of the symptoms that were displayed by the infected one?

If the other computer does not appear to have any problems, go ahead and run MBAM on it.

However, if the other computer displays symptoms similar to the infected one, come back and let me know BEFORE you run anything.


I think my other computer is not directly connected to the infected one

Do you use USB flash drives (memory sticks)? If the answers is yes, please consider the following:


  • Please download Flash Disinfector


  • Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
  • Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
  • The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
  • Wait until Flash disinfector has finished scanning and then exit the program.
  • Reboot your computer.

Please uninstall ComboFix and run MBAM again on the infected machine and post the log created (Instructions in post #19).

If your other machine displays symptoms of infection, or if MBAM finds anything bad on it, let me know and I will help you clean the second machine once we have dealt with the first one :)
Hi, Thanks for the instructions, I will do the steps.

Does your other computer show any of the symptoms that were displayed by the infected one?

If the other computer does not appear to have any problems, go ahead and run MBAM on it.


The other computer does not display any symptoms like the infected machine, so I will just run MBAM on it. However, I DO use a flash drive between the two machines. So, I will run Flash Disinfector on it… Do I need to run this program on both computers or on just one or the other? Just checking first. :)
Hello Desiree

Do I need to run this program on both computers

It would do no harm to have it present on both machines, that way you could run it on your flash drives regardless of which machine you were using :)

Please uninstall ComboFix and run MBAM again on the infected machine and post the log created (Instructions in post #19).

If your other machine displays symptoms of infection, or if MBAM finds anything bad on it, let me know and I will help you clean the second machine once we have dealt with the first one


I am running MBAM on my other machine to see what it shows me. Will post that log in the next reply.
I also will use Flash Disinfector on both machines after that as well. Thanks!
Here is the latest MBAM log for the infected computer that I ran after I uninstalled Combofix…

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4188

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

6/11/2010 12:15:36 AM
mbam-log-2010-06-11 (00-15-36).txt

Scan type: Full scan (C:\|)
Objects scanned: 181550
Time elapsed: 41 minute(s), 15 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hello Desiree

That looks much better. We will run an Online Scan as a final check - just to see if anything has been missed.


  • Please perform the following scan:


  • This is a very deep scan that can take many hours. In some instances you may need to let it run overnight. Please be patient.


  • It is recommended that you disable your onboard antivirus program and antispyware programs while performing scans to eliminate software conflicts and to speed up scan time.
  • DO NOT surf the net while your resident protection is disabled!
  • Once the scan is finished remember to re-enable your resident antivirus protection along with whatever antispyware applications you use.


  • Please perform a Kaspersky Online Scan of your computer by clicking here or here.


  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run (at times it may appear to stall).
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.

  • Once the scan is complete, click on View scan report. To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
  • If you need help performing the above steps, an animated tutorial can be found here.

In your next reply please provide the Kaspersky Online Scan log and a new OTL log
Due to inactivity, this topic has been closed. If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI