This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Firefox Browser Closes, Google Search Results Redirected

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My Firefox browser keeps shutting down. When I click on a google search result I am redirected to another site. Help…. DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 12:39:43.12 on 28/05/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.340 [GMT -3:00] AV: AVG Anti-Virus *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\VTTimer.exe C:\WINDOWS\system32\S3trayp.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Java\jre6\bin\jusched.exe svchost.exe C:\WINDOWS\Samsung\PanelMgr\SSMMgr.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Ideal POS System 4.0\IPSPrinterServer.exe C:\Program Files\Ideal POS System 4.0\IPSServerMonitor.exe C:\Program Files\CyberLink\Shared Files\RichVideo.exe C:\PROGRA~1\AVG\AVG8\avgam.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Java\jre6\bin\jucheck.exe C:\Program Files\Ideal POS System 4.0\IPSServer.exe C:\Documents and Settings\ADMIN\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "c:\program files\common files\ahead\lib\NMBgMonitor.exe" uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe mRun: [VTTimer] VTTimer.exe mRun: [S3Trayp] S3trayp.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe" mRun: [LanguageShortcut] "c:\program files\cyberlink\powerdvd\language\Language.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [Samsung PanelMgr] c:\windows\samsung\panelmgr\SSMMgr.exe /autorun mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ipspri~1.lnk - c:\program files\ideal pos system 4.0\IPSPrinterServer.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ipsser~1.lnk - c:\program files\ideal pos system 4.0\IPSServerMonitor.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC} - c:\program files\java\jre6\bin\jp2iexp.dll IE: {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1231960271921 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll Notify: avgrsstarter - avgrsstx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\admin\applic~1\mozilla\firefox\profiles\22817fzi.default\ FF - prefs.js: browser.search.selectedEngine - Search the Web FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?ourmark=3&ei=utf-8&fr=freecause-caamcl&type=60399&p= FF - component: c:\documents and settings\admin\application data\mozilla\firefox\profiles\22817fzi.default\extensions\{091dc955-8128-4a3d-bd56-88e400cc28c6}\components\Engine.dll FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2009-5-23 12552] R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-5-23 335240] R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-5-23 27784] R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-5-23 108552] R2 avg8wd;AVG8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-28 297752] R3 Rockey_USB;Feitian ROCKEY4 USB Service;c:\windows\system32\drivers\Rockey4USB.sys [2008-2-5 12928] R3 S3GIGP;S3GIGP;c:\windows\system32\drivers\S3gIGPm.sys [2007-12-3 714240] S0 opaaz;opaaz; [x] S1 3ce96ef6;3ce96ef6;c:\windows\system32\drivers\3ce96ef6.sys –> c:\windows\system32\drivers\3ce96ef6.sys [?] S2 krckj;Windows Network;c:\windows\system32\svchost.exe -k netsvcs [2006-2-28 14336] S2 SSPORT;SSPORT;\??\c:\windows\system32\drivers\ssport.sys –> c:\windows\system32\drivers\SSPORT.sys [?] S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys –> d:\NTGLM7X.sys [?] =============== Created Last 30 ================ 2010-05-27 17:34 9,325,999 a——- C:\IPS100527.zip 2010-05-25 17:50 9,292,674 a——- C:\IPS100525.zip 2010-05-22 17:31 9,280,261 a——- C:\IPS100522.zip 2010-05-20 17:42 9,262,289 a——- C:\IPS100520.zip 2010-05-19 17:26 9,253,310 a——- C:\IPS100519.zip 2010-05-18 17:51 9,240,267 a——- C:\IPS100518.zip 2010-05-15 17:02 9,231,381 a——- C:\IPS100515.zip 2010-05-14 17:59 9,228,807 a——- C:\IPS100514.zip 2010-05-08 17:02 9,152,940 a——- C:\IPS100508.zip 2010-05-07 17:34 9,141,918 a——- C:\IPS100507.zip 2010-05-06 17:31 9,136,907 a——- C:\IPS100506.zip 2010-05-05 17:52 9,116,317 a——- C:\IPS100505.zip 2010-05-04 18:03 9,115,849 a——- C:\IPS100504.zip 2010-05-01 16:57 9,104,023 a——- C:\IPS100501.zip 2010-04-30 17:32 9,093,988 a——- C:\IPS100430.zip 2010-04-29 17:31 9,094,268 a——- C:\IPS100429.zip 2010-04-28 17:47 9,089,742 a——- C:\IPS100428.zip ==================== Find3M ==================== 2010-04-27 17:50 9,048,563 a——- C:\IPS100427.zip 2010-04-24 17:07 9,052,769 a——- C:\IPS100424.zip 2010-04-23 17:45 9,045,536 a——- C:\IPS100423.zip 2010-04-22 17:32 9,028,432 a——- C:\IPS100422.zip 2010-04-21 17:29 9,017,929 a——- C:\IPS100421.zip 2010-04-20 17:35 8,985,024 a——- C:\IPS100420.zip 2010-04-10 16:57 8,878,834 a——- C:\IPS100410.zip 2010-04-09 17:52 8,872,176 a——- C:\IPS100409.zip 2010-04-08 17:31 8,873,134 a——- C:\IPS100408.zip 2010-04-07 17:32 8,868,742 a——- C:\IPS100407.zip 2010-04-06 17:35 8,850,658 a——- C:\IPS100406.zip 2010-04-03 16:59 8,852,542 a——- C:\IPS100403.zip 2010-04-01 17:32 8,847,567 a——- C:\IPS100401.zip 2010-03-31 17:29 8,842,014 a——- C:\IPS100331.zip 2010-03-30 17:30 8,834,607 a——- C:\IPS100330.zip 2010-03-27 16:57 8,816,188 a——- C:\IPS100327.zip 2010-03-26 17:41 8,810,629 a——- C:\IPS100326.zip 2010-03-25 17:29 8,809,237 a——- C:\IPS100325.zip 2010-03-24 17:27 8,797,780 a——- C:\IPS100324.zip 2010-03-23 17:30 8,791,832 a——- C:\IPS100323.zip 2010-03-20 16:57 8,791,748 a——- C:\IPS100320.zip 2010-03-19 17:29 8,789,693 a——- C:\IPS100319.zip 2010-03-18 17:33 8,779,761 a——- C:\IPS100318.zip 2010-03-17 17:31 8,768,191 a——- C:\IPS100317.zip 2010-03-16 17:50 8,752,853 a——- C:\IPS100316.zip 2009-06-03 16:52 76,648 a——- c:\docume~1\admin\applic~1\GDIPFONTCACHEV1.DAT 2009-05-21 13:44 11,938 a——- c:\docume~1\admin\applic~1\wklnhst.dat 2009-01-14 12:02 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009011420090115\index.dat ============= FINISH: 12:41:01.75 ===============

Attachments:

Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Hello kileyray,please do the following


Temporarily disable spybot teatimer
SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

      [external image: Posted Image]
      Click the image to enlarge it
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
      • IAT/EAT
      • Drives/Partition other than Systemdrive (typically C:\)
      • Show All (don't miss this one)
    • Then click the Scan button & wait for it to finish.
    • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
    • Save it where you can easily find it, such as your desktop, and attach it in your reply.

    **Caution**
    Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


    If GMER won't run try with devices unchecked.If still no go try in safe mode.
Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2


[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save Combo-Fix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on Combo-Fix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
Thank you for your prompt reply. Combo fix log is below.


ComboFix 10-05-31.03 - ADMIN 01/06/2010 10:21:04.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.600 [GMT -3:00]
Running from: E:\Combo-Fix.exe
AV: AVG Anti-Virus *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Thumbs.db

Infected copy of c:\windows\system32\drivers\ipsec.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((( Files Created from 2010-05-01 to 2010-06-01 )))))))))))))))))))))))))))))))
.

2010-05-27 20:34 . 2010-05-27 20:34 9325999 —-a-w- C:\IPS100527.zip
2010-05-27 18:11 . 2010-05-27 18:11 ——– d—–w- c:\documents and settings\HelpAssistant\UserData
2010-05-27 18:10 . 2010-05-27 18:10 ——– d—–w- c:\documents and settings\HelpAssistant\InstallAnywhere
2010-05-27 14:35 . 2010-05-27 14:35 503808 —-a-w- c:\documents and settings\ADMIN\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-42aa716a-n\msvcp71.dll
2010-05-27 14:35 . 2010-05-27 14:35 499712 —-a-w- c:\documents and settings\ADMIN\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-42aa716a-n\jmc.dll
2010-05-27 14:35 . 2010-05-27 14:35 348160 —-a-w- c:\documents and settings\ADMIN\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-42aa716a-n\msvcr71.dll
2010-05-25 20:50 . 2010-05-25 20:50 9292674 —-a-w- C:\IPS100525.zip
2010-05-22 20:31 . 2010-05-22 20:31 9280261 —-a-w- C:\IPS100522.zip
2010-05-20 20:42 . 2010-05-20 20:42 9262289 —-a-w- C:\IPS100520.zip
2010-05-19 20:26 . 2010-05-19 20:26 9253310 —-a-w- C:\IPS100519.zip
2010-05-18 20:51 . 2010-05-18 20:51 9240267 —-a-w- C:\IPS100518.zip
2010-05-15 20:02 . 2010-05-15 20:03 9231381 —-a-w- C:\IPS100515.zip
2010-05-14 20:59 . 2010-05-14 20:59 9228807 —-a-w- C:\IPS100514.zip
2010-05-08 20:02 . 2010-05-08 20:02 9152940 —-a-w- C:\IPS100508.zip
2010-05-07 20:34 . 2010-05-07 20:34 9141918 —-a-w- C:\IPS100507.zip
2010-05-06 20:31 . 2010-05-06 20:31 9136907 —-a-w- C:\IPS100506.zip
2010-05-05 20:52 . 2010-05-05 20:52 9116317 —-a-w- C:\IPS100505.zip
2010-05-04 21:03 . 2010-05-04 21:03 9115849 —-a-w- C:\IPS100504.zip

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-01 13:15 . 2008-02-05 18:32 ——– d—–w- c:\program files\Ideal POS System 4.0
2010-06-01 12:47 . 2009-09-04 19:37 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-05-28 11:53 . 2009-09-04 19:43 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-05-28 11:30 . 2009-09-04 19:35 ——– d—–w- c:\program files\SpywareBlaster
2010-05-27 13:03 . 2009-05-23 15:55 ——– d—–w- c:\documents and settings\All Users\Application Data\avg8
2010-05-14 12:44 . 2008-02-05 18:24 ——– d—–w- c:\documents and settings\ADMIN\Application Data\U3
2010-05-01 19:57 . 2010-05-01 19:57 9104023 —-a-w- C:\IPS100501.zip
2010-04-30 20:32 . 2010-04-30 20:32 9093988 —-a-w- C:\IPS100430.zip
2010-04-29 20:31 . 2010-04-29 20:31 9094268 —-a-w- C:\IPS100429.zip
2010-04-28 20:47 . 2010-04-28 20:47 9089742 —-a-w- C:\IPS100428.zip
2010-04-27 20:50 . 2010-04-27 20:50 9048563 —-a-w- C:\IPS100427.zip
2010-04-24 20:07 . 2010-04-24 20:07 9052769 —-a-w- C:\IPS100424.zip
2010-04-23 20:45 . 2010-04-23 20:45 9045536 —-a-w- C:\IPS100423.zip
2010-04-22 20:32 . 2010-04-22 20:32 9028432 —-a-w- C:\IPS100422.zip
2010-04-21 20:29 . 2010-04-21 20:29 9017929 —-a-w- C:\IPS100421.zip
2010-04-20 20:35 . 2010-04-20 20:35 8985024 —-a-w- C:\IPS100420.zip
2010-04-13 15:19 . 2008-02-05 21:49 ——– d—–w- c:\program files\DesignPro
2010-04-10 19:57 . 2010-04-10 16:07 8878834 —-a-w- C:\IPS100410.zip
2010-04-09 20:52 . 2010-04-09 20:52 8872176 —-a-w- C:\IPS100409.zip
2010-04-09 20:19 . 2010-04-09 20:19 ——– d—–w- c:\program files\IKEA HomePlanner
2010-04-09 20:18 . 2010-04-09 20:18 ——– d—–w- c:\program files\Common Files\Wise Installation Wizard
2010-04-08 20:31 . 2010-04-08 20:31 8873134 —-a-w- C:\IPS100408.zip
2010-04-07 20:32 . 2010-04-07 20:32 8868742 —-a-w- C:\IPS100407.zip
2010-04-06 20:35 . 2010-04-06 20:35 8850658 —-a-w- C:\IPS100406.zip
2010-04-03 19:59 . 2010-04-03 19:59 8852542 —-a-w- C:\IPS100403.zip
2010-04-01 20:32 . 2010-04-01 20:32 8847567 —-a-w- C:\IPS100401.zip
2010-03-31 20:29 . 2010-03-31 20:29 8842014 —-a-w- C:\IPS100331.zip
2010-03-30 20:30 . 2010-03-30 20:30 8834607 —-a-w- C:\IPS100330.zip
2010-03-29 23:07 . 2010-04-09 18:46 65536 —-a-w- c:\documents and settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\22817fzi.default\extensions\{091dc955-8128-4a3d-bd56-88e400cc28c6}\components\Engine.dll
2010-03-27 19:57 . 2010-03-27 19:57 8816188 —-a-w- C:\IPS100327.zip
2010-03-26 20:41 . 2010-03-26 20:41 8810629 —-a-w- C:\IPS100326.zip
2010-03-25 20:29 . 2010-03-25 20:29 8809237 —-a-w- C:\IPS100325.zip
2010-03-24 20:27 . 2010-03-24 20:27 8797780 —-a-w- C:\IPS100324.zip
2010-03-23 20:30 . 2010-03-23 20:30 8791832 —-a-w- C:\IPS100323.zip
2010-03-20 19:57 . 2010-03-20 19:57 8791748 —-a-w- C:\IPS100320.zip
2010-03-19 20:29 . 2010-03-19 20:29 8789693 —-a-w- C:\IPS100319.zip
2010-03-18 20:33 . 2010-03-18 20:33 8779761 —-a-w- C:\IPS100318.zip
2010-03-17 20:31 . 2010-03-17 20:31 8768191 —-a-w- C:\IPS100317.zip
2010-03-16 20:50 . 2010-03-16 20:50 8752853 —-a-w- C:\IPS100316.zip
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2006-09-21 53248]
"S3Trayp"="S3trayp.exe" [2007-06-11 176128]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 16384000]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-18 2046816]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-05-28 148888]
"Samsung PanelMgr"="c:\windows\Samsung\PanelMgr\SSMMgr.exe" [2008-08-08 524288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
IPS Print Server.lnk - c:\program files\Ideal POS System 4.0\IPSPrinterServer.exe [2007-9-14 262144]
IPS Server Monitor.lnk - c:\program files\Ideal POS System 4.0\IPSServerMonitor.exe [2007-9-18 73728]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-07-28 11:28 11952 —-a-w- c:\windows\system32\avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ideal POS System 4.0\\IPSPrinterServer.exe"=
"c:\\Program Files\\Ideal POS System 4.0\\IPS.exe"=
"c:\\Program Files\\Ideal POS System 4.0\\IPSServer.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list]
"65533:TCP"= 65533:TCP:Services
"52344:TCP"= 52344:TCP:Services
"5187:TCP"= 5187:TCP:Services
"8874:TCP"= 8874:TCP:Services
"3389:TCP"= 3389:TCP:Remote Desktop
"5084:TCP"= 5084:TCP:Services
"8668:TCP"= 8668:TCP:Services

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [23/05/2009 12:55 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23/05/2009 12:55 335240]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23/05/2009 12:55 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [28/07/2009 08:27 297752]
R3 Rockey_USB;Feitian ROCKEY4 USB Service;c:\windows\system32\drivers\Rockey4USB.sys [05/02/2008 15:32 12928]
S0 opaaz;opaaz; [x]
S1 3ce96ef6;3ce96ef6;c:\windows\system32\drivers\3ce96ef6.sys –> c:\windows\system32\drivers\3ce96ef6.sys [?]
S2 krckj;Windows Network;c:\windows\system32\svchost.exe -k netsvcs [28/02/2006 09:00 14336]
S2 SSPORT;SSPORT;\??\c:\windows\system32\Drivers\SSPORT.sys –> c:\windows\system32\Drivers\SSPORT.sys [?]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys –> d:\NTGLM7X.sys [?]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
krckj
.
Contents of the 'Scheduled Tasks' folder

2009-12-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.ca/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\22817fzi.default\
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: keyword.URL - hxxp://ca.search.yahoo.com/search?ourmark=3&ei=utf-8&fr=freecause-caamcl&type=60399&p=
FF - component: c:\documents and settings\ADMIN\Application Data\Mozilla\Firefox\Profiles\22817fzi.default\extensions\{091dc955-8128-4a3d-bd56-88e400cc28c6}\components\Engine.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-01 10:25
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x86177C38]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf74e7f28
\Driver\ACPI -> ACPI.sys @ 0xf745acb8
\Driver\atapi -> 0x86177c38
IoDeviceObjectType -> DeleteProcedure -> ntoskrnl.exe @ 0x805e6686
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntoskrnl.exe @ 0x805e6686
ParseProcedure -> ntoskrnl.exe @ 0x8057b6b1
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x85b8a610
PacketIndicateHandler -> NDIS.sys @ 0xf7305a21
SendHandler -> NDIS.sys @ 0xf72e387b
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\krckj]
"ServiceDll"="c:\windows\system32\dowzm.dll"
.
Completion time: 2010-06-01 10:26:46
ComboFix-quarantined-files.txt 2010-06-01 13:26

Pre-Run: 146,931,249,152 bytes free
Post-Run: 147,042,598,912 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

- - End Of File - - F49B4B4F711707E2DDB15EBD29646E4A
Hi,you have Malwarebytes installed,please update and run a quick scan.Post the log please.

Next

Download and run HAMeb_check.exe
Post the contents of the resulting log.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4161

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

01/06/2010 17:30:01
mbam-log-2010-06-01 (17-30-01).txt

Scan type: Quick scan
Objects scanned: 153002
Time elapsed: 4 minute(s), 37 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\HelpAssistant\Local Settings\Temp\arwsnxmoec.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Local Settings\Temp\wrscmxaeno.tmp (Trojan.Tracur) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\9PEZY11V\kkemu[1].htm (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\HelpAssistant\Local Settings\Temporary Internet Files\Content.IE5\CMT49IXS\hypwhc[1].htm (Trojan.Downloader) -> Quarantined and deleted successfully.



Hameb Check


C:\Documents and Settings\ADMIN\Desktop\HAMeb_check.exe
01/06/2010 at 17:40:19.84

Account active Yes
Local Group Memberships *Administrators

~~ Checking profile list ~~

S-1-5-21-1152304892-403636839-1274598579-1004
%SystemDrive%\Documents and Settings\HelpAssistant

~~ Checking for HelpAssistant directories ~~

HelpAssistant

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x85C1C308]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x85c1c308
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x85af9610
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.

~~ Checking for termsrv32.dll ~~

termsrv32.dll present!


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %SystemRoot%\System32\termsrv32.dll

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\GloballyOpenPorts\List]
"65533:TCP"=65533:TCP:*:Enabled:Services
"52344:TCP"=52344:TCP:*:Enabled:Services
"5187:TCP"=5187:TCP:*:Enabled:Services
"8874:TCP"=8874:TCP:*:Enabled:Services
"3389:TCP"=3389:TCP:*:Enabled:Remote Desktop
"5084:TCP"=5084:TCP:*:Enabled:Services
"8668:TCP"=8668:TCP:*:Enabled:Services
"9489:TCP"=9489:TCP:*:Enabled:Services
"9490:TCP"=9490:TCP:*:Enabled:Services

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"65533:TCP"=65533:TCP:*:Enabled:Services
"52344:TCP"=52344:TCP:*:Enabled:Services
"5187:TCP"=5187:TCP:*:Enabled:Services
"8874:TCP"=8874:TCP:*:Enabled:Services
"3389:TCP"=3389:TCP:*:Enabled:Remote Desktop
"5084:TCP"=5084:TCP:*:Enabled:Services
"8668:TCP"=8668:TCP:*:Enabled:Services
"9489:TCP"=9489:TCP:*:Enabled:Services
"9490:TCP"=9490:TCP:*:Enabled:Services


~~ EOF ~~
Please download HelpAsst_mebroot_fix.exe and save it to your desktop.
Close out all other open programs and windows.
Double click the file to run it and follow any prompts.
If the tool detects an mbr infection, please allow it to run mbr -f and shutdown your computer.
Upon restarting, please wait about 5 minutes, click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !
When it completes, a log will open.
Please post the contents of that log.


*In the event the tool does not detect an mbr infection and completes, click Start>Run and type the following bolded command, then hit Enter.

mbr -f

Now, please do the Start>Run>mbr -f command a second time.
Now shut down the computer (do not restart, but shut it down), wait a few minutes then start it back up.
Give it about 5 minutes, then click Start>Run and type the following bolded command, then hit Enter.

helpasst -mbrt

Make sure you leave a space between helpasst and -mbrt !
When it completes, a log will open.
Please post the contents of that log.

**Important note to Dell users - fixing the mbr may prevent access the the Dell Restore Utility, which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced. If you are unwilling to take such a risk, you should not allow the tool to execute mbr -f nor execute the command manually, and you will either need to restore your computer to a factory state or allow your computer to remain having an infected mbr (the latter not recommended).
C:\Documents and Settings\ADMIN\Desktop\HelpAsst_mebroot_fix.exe
01/06/2010 at 18:26:54.65

HelpAssistant account is Active ~ attempting to de-activate

Account active Yes
Local Group Memberships *Administrators

HelpAssistant successfully set Inactive

~~ Checking for termsrv32.dll ~~

termsrv32.dll present! ~ attempting to remove
Remove on reboot: C:\WINDOWS\system32\termsrv32.dll

~~ Checking firewall ports ~~

backing up DomainProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"5187:TCP"=-
"8874:TCP"=-
"3389:TCP"=-
"5084:TCP"=-
"8668:TCP"=-
"9489:TCP"=-
"9490:TCP"=-

backing up StandardProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"5187:TCP"=-
"8874:TCP"=-
"3389:TCP"=-
"5084:TCP"=-
"8668:TCP"=-
"9489:TCP"=-
"9490:TCP"=-

~~ Checking profile list ~~

HelpAssistant profile found in registry ~ backing up and removing S-1-5-21-1152304892-403636839-1274598579-1004
HelpAssistant profile directory exists at C:\Documents and Settings\HelpAssistant ~ attempting to remove
~ All C:\Documents and Settings\HelpAssistant files successfully removed ~

~~ Checking mbr ~~

mbr infection detected! ~ running mbr -f

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x85c1c308
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x85af9610
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
original MBR restored successfully !

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x85c1c308
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x85af9610
Warning: possible MBR rootkit infection !
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
Use "Recovery Console" command "fixmbr" to clear infection !

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 01/06/2010 at 18:46:20.89

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

none found

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~
Hello kileyray,please do the following

Click Start>Run and type helpasst -folder then hit Enter.
The tool will run and prompt for confirmation to remove any HelpAssistant folders found.
If prompted, restart your computer.
When complete, click Start>Run and type helpasst -mbrt then hit Enter.
Post the new log that opens when it finishes.
C:\Documents and Settings\ADMIN\Desktop\HelpAsst_mebroot_fix.exe
01/06/2010 at 18:26:54.65

HelpAssistant account is Active ~ attempting to de-activate

Account active Yes
Local Group Memberships *Administrators

HelpAssistant successfully set Inactive

~~ Checking for termsrv32.dll ~~

termsrv32.dll present! ~ attempting to remove
Remove on reboot: C:\WINDOWS\system32\termsrv32.dll

~~ Checking firewall ports ~~

backing up DomainProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"5187:TCP"=-
"8874:TCP"=-
"3389:TCP"=-
"5084:TCP"=-
"8668:TCP"=-
"9489:TCP"=-
"9490:TCP"=-

backing up StandardProfile\GloballyOpenPorts\List registry key
closing rogue ports

HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\globallyopenports\list
"65533:TCP"=-
"52344:TCP"=-
"5187:TCP"=-
"8874:TCP"=-
"3389:TCP"=-
"5084:TCP"=-
"8668:TCP"=-
"9489:TCP"=-
"9490:TCP"=-

~~ Checking profile list ~~

HelpAssistant profile found in registry ~ backing up and removing S-1-5-21-1152304892-403636839-1274598579-1004
HelpAssistant profile directory exists at C:\Documents and Settings\HelpAssistant ~ attempting to remove
~ All C:\Documents and Settings\HelpAssistant files successfully removed ~

~~ Checking mbr ~~

mbr infection detected! ~ running mbr -f

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x85c1c308
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x85af9610
Warning: possible MBR rootkit infection !
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
MBR rootkit infection detected ! Use: "mbr.exe -f" to fix.
original MBR restored successfully !

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\atapi -> 0x85c1c308
NDIS: VIA Rhine II Fast Ethernet Adapter -> SendCompleteHandler -> 0x85af9610
Warning: possible MBR rootkit infection !
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
Use "Recovery Console" command "fixmbr" to clear infection !

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 01/06/2010 at 18:46:20.89

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

none found

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Folder removal routine ~ 02/06/2010 at 8:23:43.51

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found

~~ Checking for HelpAssistant directories ~~

none found

~~ EOF ~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 02/06/2010 at 8:24:53.59

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Folder removal routine ~ 02/06/2010 at 9:35:11.03

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found

~~ Checking for HelpAssistant directories ~~

none found

~~ EOF ~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 02/06/2010 at 9:35:35.28

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

none found

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~
Please do the following:


Go to Start > Run > copy/paste the bolded text into the open run box > hit OK

helpasst -cleanup

then reboot.


Browse for a bit (10-15 min)

Advise, if you are getting redirected, and note how your computer is running, then do the following:


Go to Start > run > copy/paste the bolded text into the open run box > hit OK


helpasst -mbrt



When completed a log should pop open for you - please post the resulting log in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Status check on 04/06/2010 at 9:00:03.21

Account active No
Local Group Memberships

~~ Checking mbr ~~

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
copy of MBR has been found in sector 0x012A18AC1
malicious code @ sector 0x012A18AC4 !
PE file found in sector at 0x012A18ADA !

~~ Checking for termsrv32.dll ~~

termsrv32.dll not found


HKEY_LOCAL_MACHINE\system\currentcontrolset\services\termservice\parameters
ServiceDll REG_EXPAND_SZ %systemroot%\System32\termsrv.dll

~~ Checking profile list ~~

No HelpAssistant profile in registry

~~ Checking for HelpAssistant directories ~~

none found

~~ Checking firewall ports ~~

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\domainprofile\GloballyOpenPorts\List]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]


~~ EOF ~~
Hi,how is it running now.Are you still getting redirected

Please scan the following files


  • Please visit Virus Total by clicking here.
  • Click the Browse button and search for the following file: c:\windows\system32\drivers\3ce96ef6.sys
  • Click Open.
  • Then click Send File.
  • Please be patient while the file is scanned.
  • If Virus Total tells you that the file has already been scanned, click "reanalyse now".

  • Once the scan results appear, copy and paste them into Notepad and repeat the procedure for the following file(s):

  • c:\windows\system32\dowzm.dll
  • Please provide the results from the scans in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI