This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Google redirect and more

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

No, I only have Internet Explorer. Should I download an alternative and see if it can download the Java file? Which one would you suggest?
1. Using Mozilla seemed to have solved the problem with the Java file.

2. JavaRA log:

JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Wed Jun 02 12:31:23 2010

Found and removed: C:\Program Files\Java\jre1.5.0_09

Found and removed: C:\Program Files\Java\jre1.6.0_05

Found and removed: C:\Program Files\Java\jre1.6.0_07

Found and removed: C:\Documents and Settings\Brandon Miles\Application Data\Sun\Java\jre1.6.0_14

Found and removed: Software\JavaSoft\Java2D\1.5.0_03

Found and removed: Software\JavaSoft\Java2D\1.5.0_06

Found and removed: Software\JavaSoft\Java2D\1.5.0_09

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\JavaPlugin.150_03

Found and removed: SOFTWARE\Classes\JavaPlugin.150_06

Found and removed: SOFTWARE\Classes\JavaPlugin.150_09

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Classes\JavaPlugin.160_05

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_05

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610005

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160050}

Found and removed: Software\Classes\JavaPlugin.160_05

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.6.0_05

Found and removed: Software\JavaSoft\Java2D\1.6.0_05

Found and removed: Software\JavaSoft\Java Runtime Environment\1.6.0_05

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.6.0_07

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.6.0_07

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D610007

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D610007

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0160070}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_09\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_05\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.6.0_07\bin\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\C:\Program Files\Common Files\Java\Update\Base Images\jre1.6.0.b105\patch-jre1.6.0_05.b13\

————————————

Finished reporting.



JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Wed Jun 02 13:00:19 2010

————————————

Finished reporting.



JavaRa 1.15 Removal Log.

Report follows after line.

————————————

The JavaRa removal process was started on Wed Jun 02 13:33:57 2010

Found and removed: C:\Documents and Settings\Brandon Miles\Application Data\Sun\Java\jre1.6.0_17

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

————————————

Finished reporting.

3. OTL log:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\Documents and Settings\Brandon Miles\Desktop\mbam-setup-1.46.exe moved successfully.
C:\Documents and Settings\NetworkService\Application Data\vqdlkr.dat moved successfully.
========== FILES ==========
C:\Documents and Settings\Brandon Miles\Shared\jaimee hammer cute girl has orgasm on webcam.mpg moved successfully.
C:\Program Files\Morpheus\morpheustoolbar.exe moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Brandon Miles
->Temp folder emptied: 7972639 bytes
->Temporary Internet Files folder emptied: 64738240 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 38932873 bytes
->Flash cache emptied: 4055 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Owner
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: RBM
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 664 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 32591424 bytes

Total Files Cleaned = 138.00 mb


[EMPTYFLASH]

User: Administrator

User: All Users

User: Brandon Miles
->Flash cache emptied: 0 bytes

User: Default User

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

User: Owner

User: RBM

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.5.2 log created on 06022010_133810

Files\Folders moved on Reboot…

Registry entries deleted on Reboot…

4. Security Check log:

Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 3
Internet Explorer 7 Out of date!
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
ESET Online Scanner v3
```````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
Malwarebytes' Anti-Malware
HijackThis 2.0.2
Java™ 6 Update 20
Adobe Flash Player
Adobe Reader 9
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.3)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
CA CA Internet Security Suite CA Anti-Virus ISafe.exe
CA CA Internet Security Suite CA Anti-Virus VetMsg.exe
CA CA Internet Security Suite CA Anti-Virus CAVRID.exe
CA CA Internet Security Suite CA Personal Firewall capfsem.exe
CA CA Internet Security Suite CA Personal Firewall capfasem.exe
````````````````````````````````
DNS Vulnerability Check:

Unknown. This method cannot test your vulnerability to DNS cache poisoning.

``````````End of Log````````````
Download Avenger by Swandog and unzip it to your Desktop.

Note: This program must be run from an account with Administrator privileges.

  • Open the Avenger folder and double click Avenger.exe to launch the program.
  • Copy the text in the code box below and Paste it into the Input script here: box.
Drivers to delete:
ghcpy
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.

  • Ensure the following:
    • Scan for Rootkits is checked.
    • Automatically disable any rootkits found is Unchecked.
  • Press the Execute key.
  • Avenger will now process the script you've pasted (this may involve more than one re-boot), when finished it will produce a log file.
  • Post the log back here please. (it can also be found at C:\avenger.txt)
Downloaded and ran Avenger. After the reboot, I got an error message saying the file was not found or I didn't have the proper permissions. The account I am using is an administrator account.
Registry Export
I need some more information on a key in your registry. Please do the following:
Press Start => Run, Copy/Paste the command below into the run dialog box and press Ok:

reg export "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ghcpy" "%userprofile%\desktop\look.txt"

You should see a new file on your Desktop named look.txt. Please double click on the file to open it, and then post the contents of look.txt in this thread.
Try this:

Start > Run > type in: cmd.exe

Copy/Paste following bolded text:

reg export "HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\ghcpy" "%userprofile%\desktop\look.txt"

Hit ENTER

Let me know what it says after hitting enter.
Okay. Can you do me a favor and attempt to run a scan with ComboFix and see if it lets you proceed with running a scan?
ComboFix was able to run (Windows restore was downloaded first). The log is below:

ComboFix 10-06-01.01 - Brandon Miles 06/02/2010 15:23:02.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.767.391 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Readme.txt
c:\windows\system\oeminfo.ini
C:\zip.exe

.
((((((((((((((((((((((((( Files Created from 2010-05-02 to 2010-06-02 )))))))))))))))))))))))))))))))
.

2010-06-02 18:17 . 2010-06-02 18:17 0 —-a-w- C:\backup.reg
2010-06-02 18:17 . 2010-06-02 18:17 574 —-a-w- C:\cleanup.bat
2010-06-02 17:16 . 2010-06-02 17:16 61440 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1366c09b-n\decora-sse.dll
2010-06-02 17:16 . 2010-06-02 17:16 503808 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-76076f38-n\msvcp71.dll
2010-06-02 17:16 . 2010-06-02 17:16 499712 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-76076f38-n\jmc.dll
2010-06-02 17:16 . 2010-06-02 17:16 348160 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-76076f38-n\msvcr71.dll
2010-06-02 17:16 . 2010-06-02 17:16 12800 —-a-w- c:\documents and settings\Brandon Miles\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-1366c09b-n\decora-d3d.dll
2010-06-02 17:15 . 2010-06-02 17:15 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-06-02 17:15 . 2010-06-02 17:15 ——– d—–w- c:\program files\Java
2010-06-02 16:54 . 2010-06-02 16:54 0 —-a-w- c:\windows\nsreg.dat
2010-06-02 16:54 . 2010-06-02 16:54 ——– d—–w- c:\documents and settings\Brandon Miles\Local Settings\Application Data\Mozilla
2010-06-02 07:08 . 2010-06-02 07:08 ——– d—–w- c:\program files\MSXML 4.0
2010-06-02 02:16 . 2010-06-02 02:16 ——– d—–w- c:\program files\ESET
2010-06-02 01:31 . 2010-06-02 01:31 ——– d—–w- c:\documents and settings\Brandon Miles\Application Data\Malwarebytes
2010-06-02 01:31 . 2010-04-29 19:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-02 01:31 . 2010-06-02 01:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-02 01:31 . 2010-06-02 01:31 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-02 01:31 . 2010-04-29 19:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-02 01:16 . 2010-06-02 01:16 ——– d—–w- C:\_OTL
2010-06-01 17:40 . 2010-06-01 17:40 388096 —-a-r- c:\documents and settings\Brandon Miles\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-06-01 14:31 . 2010-06-01 14:20 1541416 —-a-w- c:\documents and settings\All Users\Application Data\CA\Consumer\AV\tmp\vete_tmp.dll
2010-06-01 13:56 . 2010-06-01 14:20 739696 —-a-w- c:\windows\system32\drivers\vetefile.sys
2010-06-01 13:56 . 2010-06-01 14:20 133520 —-a-w- c:\windows\system32\drivers\veteboot.sys
2010-06-01 13:31 . 2010-06-01 13:56 32240 —-a-w- c:\windows\system32\drivers\vetmonnt.sys
2010-06-01 13:31 . 2010-06-01 13:56 26352 —-a-w- c:\windows\system32\drivers\vet-filt.sys
2010-06-01 13:31 . 2010-06-01 13:56 21488 —-a-w- c:\windows\system32\drivers\vetfddnt.sys
2010-06-01 13:31 . 2010-06-01 13:56 21104 —-a-w- c:\windows\system32\drivers\vet-rec.sys
2010-06-01 13:31 . 2007-08-20 17:37 75016 —-a-w- c:\windows\system32\isafprod.dll
2010-06-01 13:31 . 2007-08-20 17:37 99592 —-a-w- c:\windows\system32\isafeif.dll
2010-06-01 13:31 . 2007-08-20 17:26 79424 —-a-w- c:\windows\system32\vetredir.dll
2010-06-01 13:31 . 2010-06-01 13:31 ——– d—–w- c:\program files\Common Files\Scanner
2010-06-01 13:30 . 2010-06-01 13:56 ——– d—–w- c:\documents and settings\All Users\Application Data\CA
2010-06-01 13:30 . 2010-06-01 13:31 ——– d—–w- c:\program files\CA
2010-05-29 14:11 . 2010-05-29 14:11 1152 —-a-w- c:\windows\system32\windrv.sys
2010-05-29 14:10 . 2010-05-29 14:10 ——– d—–w- c:\documents and settings\Brandon Miles\Application Data\GetRightToGo
2010-05-29 12:36 . 2010-05-29 12:36 ——– d—–w- c:\program files\Trend Micro
2010-05-29 11:14 . 2010-05-29 11:14 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-05-28 16:42 . 2010-05-28 16:42 ——– d—–w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-05-28 14:12 . 2010-05-28 13:14 15880 —-a-w- c:\windows\system32\lsdelete.exe
2010-05-28 13:14 . 2010-02-04 15:53 64288 —-a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-28 13:14 . 2010-05-28 13:14 ——– dc—-w- c:\windows\system32\DRVSTORE
2010-05-28 13:14 . 2010-05-28 13:14 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-28 13:09 . 2010-02-04 15:53 2954656 -c–a-w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-05-28 13:08 . 2010-05-28 13:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-05-28 13:08 . 2010-05-28 13:09 ——– d—–w- c:\program files\Lavasoft
2010-05-28 12:22 . 2010-05-28 12:22 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Apple Computer
2010-05-27 18:42 . 2010-05-28 13:09 ——– dc-h–w- c:\documents and settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-27 13:27 . 2008-04-13 18:45 26368 -c–a-w- c:\windows\system32\dllcache\usbstor.sys
2010-05-27 10:25 . 2010-05-28 16:42 ——– d—–w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-05-27 10:25 . 2010-05-27 10:25 ——– d—–w- c:\program files\SDHelper (Spybot - Search & Destroy)

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2010-06-02 18:18 . 2010-06-02 01:21 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2010-06-02 18:18 . 2010-06-02 01:21 54726 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2010-06-02 17:38 . 2007-02-24 23:51 ——– d—–w- c:\program files\Morpheus
2010-06-02 17:17 . 2006-07-13 21:38 ——– d—–w- c:\program files\Common Files\Java
2010-06-01 21:12 . 2001-08-18 12:00 3328 —-a-w- c:\windows\system32\drivers\pciide.sys
2010-05-27 18:30 . 2004-12-12 18:05 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-05-27 16:22 . 2004-12-12 18:05 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-03-11 12:38 . 2004-01-08 20:23 832512 —-a-w- c:\windows\system32\wininet.dll
2010-03-11 12:38 . 2004-08-04 07:56 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:38 . 2001-08-18 12:00 17408 —-a-w- c:\windows\system32\corpol.dll
2010-03-09 11:09 . 2002-02-26 20:58 430080 —-a-w- c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LTWinModem1"="ltmsg.exe 9" [X]
"Dell|Alert"="c:\program files\Dell\Support\Alert\bin\DAMon.exe" [2002-04-03 282624]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-10 155648]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2010-06-01 14088]
"Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-17 28738]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2010-06-01 177392]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2010-06-01 230664]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2010-06-01 259312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2010-06-01 173296]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2010-06-01 1193200]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 17:30 79368 —-a-w- c:\windows\SYSTEM32\UmxWNP.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]
dwwionce REG_SZ

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R0 KmxStart;KmxStart;c:\windows\SYSTEM32\DRIVERS\KmxStart.sys [6/24/2008 7:08 PM 93712]
R0 Lbd;Lbd;c:\windows\SYSTEM32\DRIVERS\Lbd.sys [5/28/2010 9:14 AM 64288]
R1 KmxAgent;KmxAgent;c:\windows\SYSTEM32\DRIVERS\KmxAgent.sys [6/24/2008 7:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\SYSTEM32\DRIVERS\KmxFile.sys [6/24/2008 7:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\SYSTEM32\DRIVERS\KmxFw.sys [6/24/2008 7:08 PM 115216]
R2 KmxCF;KmxCF;c:\windows\SYSTEM32\DRIVERS\KmxCF.sys [6/24/2008 7:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\SYSTEM32\DRIVERS\KmxSbx.sys [6/24/2008 7:08 PM 66576]
R3 KmxCfg;KmxCfg;c:\windows\SYSTEM32\DRIVERS\KmxCfg.sys [6/24/2008 7:08 PM 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 9:10 PM 189704]
S3 Fadpu16E;Fadpu16E; [x]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 11:52 AM 1314704]
.
Contents of the 'Scheduled Tasks' folder

2010-06-01 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 13:14]

2010-06-01 c:\windows\Tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 01:10]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride =
LSP: c:\windows\system32\VetRedir.dll
Trusted Zone: microsoft.com\windowsupdate
FF - ProfilePath - c:\documents and settings\Brandon Miles\Application Data\Mozilla\Firefox\Profiles\p97coiir.default\
FF - plugin: c:\progra~1\Yahoo!\Common\npyaxmpb.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-klmdb.sys



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-02 15:33
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Dell|Alert = c:\program files\Dell\Support\Alert\bin\DAMon.exe?p?o?r?t?\?A?l?e?r?t?\?b?i?n?\?D?A?M?o?n?.?e?x?e???????????x:??????x???`???X??? ???????`???P????(?w'(?w????????????(???}??????w????????????0????$?w7(?w?o?wS??w???w????????????X*@?????????X????????%@?e?????

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-3646499915-954458941-1742551072-1008\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:ef,1f,49,b2,3e,27,67,73,fd,92,f4,7d,cf,b7,80,8d,19,25,86,ac,60,fd,54,
b3,c3,44,0b,47,f2,da,95,14,1f,60,3d,76,e1,41,29,cf,af,90,64,2c,35,01,fb,f8,\
"??"=hex:90,56,a4,4d,49,5d,3a,cb,4f,0e,1e,76,81,1c,49,38

[HKEY_USERS\S-1-5-21-3646499915-954458941-1742551072-1008\Software\SecuROM\License information*]
"datasecu"=hex:61,86,46,5e,5f,a3,00,8f,1d,10,87,35,1e,fa,99,95,47,90,fc,58,bb,
6d,69,75,dd,9b,1b,fe,70,3f,0b,6e,9f,d8,93,c4,b6,0b,1e,6c,11,9a,9d,0f,98,53,\
"rkeysecu"=hex:c3,94,60,b1,4d,bc,d6,c5,f7,57,81,90,6c,b0,8f,5e
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1216)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll

- - - - - - - > 'lsass.exe'(1416)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Completion time: 2010-06-02 15:40:43
ComboFix-quarantined-files.txt 2010-06-02 19:40

Pre-Run: 13,048,393,728 bytes free
Post-Run: 13,021,057,024 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn

- - End Of File - - FC6E0100C1BF070CDF5A9E3DBF4BCDD6
ComboFix Script
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

KillAll::
Registry::
[-HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\appcertdlls]

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
ComboFix made a restore point and started the scan, but then stalled. Should I re-run by dragging the CFScipt over the icon again?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI