This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Search engine redirect and Browser crashing

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I posted a few weeks ago but the thread was closed. Sorry about that, getting on the internet has been difficult to say the least. I am still experiencing -Search engine redirects -Malware "re-spawning" -Random browser crashes

Thanks!

Here are my results from DDS and GMER:


DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 18:44:58.96 on Fri 05/28/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.964 [GMT -7:00]

AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
svchost.exe
svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\PROGRA~1\COMMON~1\Stardock\SDMCP.exe
svchost.exe
C:\WINDOWS\Explorer.EXE
c:\program files\a-squared free\a2service.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgfws9.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Elantech\ktp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG9\avgui.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Documents and Settings\Operator\Desktop\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com
uURLSearchHooks: AVG Security Toolbar BHO: {a3bc75a2-1f87-4686-aa43-5347d756017c} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
TB: AVG Security Toolbar: {ccc7a320-b3ca-4199-b1a6-9f516dd69829} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -scheduler
uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [High Definition Audio Property Page Shortcut] HDAShCut.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [KTPWare] c:\program files\elantech\ktp.exe
mRun: [CHotkey] mHotkey.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [BlackBerryAutoUpdate] c:\program files\common files\research in motion\auto update\RIMAutoUpdate.exe /background
mRun: [IntelZeroConfig] "c:\program files\intel\wifi\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\common files\intel\wirelesscommon\iFrmewrk.exe" /tf Intel Wireless Tray
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [N360] "c:\program files\nortoninstaller\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360\a5e82d02\4.0.0.127\InstStub.exe" /RELAUNCH /RUNONCE /PRODID N360
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
IE: &D;&ownload; &with; BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000
IE: Send to &Bluetooth; Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - c:\program files\paltalk messenger\Paltalk.exe
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.4.1.27.dll/206
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1229243957436
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1229243947545
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - c:\program files\avg\avg9\toolbar\IEToolbar.dll
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxdev.dll
Notify: MCPClient - c:\progra~1\common~1\stardock\mcpstub.dll
Notify: WB - c:\program files\alienguise\fastload.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll
SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\operator\applic~1\mozilla\firefox\profiles\qzesgo25.default\
FF - component: c:\documents and settings\operator\application data\mozilla\firefox\profiles\qzesgo25.default\extensions\{b042753d-f57e-4e8e-a01b-7379a6d4cefb}\components\IBitCometExtension.dll
FF - component: c:\documents and settings\operator\application data\mozilla\firefox\profiles\qzesgo25.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\avg\avg9\toolbar\firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\operator\application data\mozilla\firefox\profiles\qzesgo25.default\extensions\{1bc9ba34-1eed-42ca-a505-6d2f1a935bbb}\plugins\npietab2.dll
FF - plugin: c:\documents and settings\operator\application data\mozilla\firefox\profiles\qzesgo25.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\documents and settings\operator\application data\mozilla\firefox\profiles\qzesgo25.default\extensions\[removed]\plugins\npcoolirisplugin.dll
FF - plugin: c:\documents and settings\operator\application data\mozilla\plugins\npcoolirisplugin.dll
FF - plugin: c:\progra~1\yahoo!\common\npyaxmpb.dll
FF - plugin: c:\program files\common files\research in motion\bbwebsllauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\microsoft\office live\npOLW.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [2010-5-26 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [2010-5-26 52872]
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2010-5-27 64288]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-5-26 216200]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-5-26 29512]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-5-26 242896]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 a2free;a-squared Free Service;c:\program files\a-squared free\a2service.exe [2007-8-11 1872320]
R2 avg9wd;AVG WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-5-26 308064]
R2 avgfws9;AVG Firewall;c:\program files\avg\avg9\avgfws9.exe [2010-5-26 2325816]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\avg\avg9\identity protection\agent\bin\AVGIDSAgent.exe [2010-5-26 5888008]
R2 bwcdrv;BUFFALO Wireless Configuration;c:\windows\system32\drivers\BWCDRV.SYS [2003-12-21 19840]
R2 WDDMService;WD SmartWare Drive Manager;c:\program files\western digital\wd smartware\wd drive manager\WDDMService.exe [2009-11-5 110592]
R2 wwEngineSvc;Window Washer Engine;c:\program files\webroot\washer\WasherSvc.exe [2007-8-28 388936]
R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [2010-5-26 30104]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSDriver.sys [2010-5-26 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSFilter.sys [2010-5-26 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\avg\avg9\identity protection\agent\driver\platform_xp\AVGIDSShim.sys [2010-5-26 26120]
S0 oramwp;oramwp;c:\windows\system32\drivers\oramwp.sys [2010-5-26 0]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-14 135664]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2010-2-4 1314704]
S2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files\western digital\wd smartware\front parlor\WDSmartWareBackgroundService.exe [2009-6-16 20480]
S3 AVG Security Toolbar Service;AVG Security Toolbar Service;c:\program files\avg\avg9\toolbar\ToolbarBroker.exe [2010-5-26 430152]
S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [2010-5-26 30104]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2010-3-14 11520]

=============== Created Last 30 ================

2010-05-29 01:33:35 0 dc—-w- c:\docume~1\operator\applic~1\AVG9
2010-05-27 07:52:46 64288 -c–a-w- c:\windows\system32\drivers\Lbd.sys
2010-05-27 07:52:40 95024 -c–a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-05-27 07:44:58 0 dc-h–w- c:\docume~1\alluse~1\applic~1\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-05-27 07:36:50 0 dc—-w- c:\program files\Trend Micro
2010-05-27 07:14:05 0 dc—-w- c:\docume~1\operator\applic~1\SUPERAntiSpyware.com
2010-05-27 07:14:05 0 dc—-w- c:\docume~1\alluse~1\applic~1\SUPERAntiSpyware.com
2010-05-27 07:13:57 0 dc—-w- c:\program files\SUPERAntiSpyware
2010-05-27 07:12:19 0 dc—-w- c:\docume~1\operator\applic~1\Malwarebytes
2010-05-27 07:12:00 38224 -c–a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-05-27 07:11:59 20952 -c–a-w- c:\windows\system32\drivers\mbam.sys
2010-05-27 07:11:59 0 dc—-w- c:\program files\Malwarebytes' Anti-Malware
2010-05-27 07:11:59 0 dc—-w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-05-27 01:46:42 664 -c–a-w- c:\windows\system32\d3d9caps.dat
2010-05-26 22:56:53 0 dc-h–w- C:\$AVG
2010-05-26 22:41:40 12464 -c–a-w- c:\windows\system32\avgrsstx.dll
2010-05-26 22:41:38 216200 -c–a-w- c:\windows\system32\drivers\avgldx86.sys
2010-05-26 22:41:09 0 dc—-w- c:\windows\system32\drivers\Avg
2010-05-26 22:41:04 0 dc—-w- c:\docume~1\alluse~1\applic~1\AVG Security Toolbar
2010-05-26 22:39:43 25096 -c–a-w- c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-26 22:39:42 52872 -c–a-w- c:\windows\system32\drivers\avgrkx86.sys
2010-05-26 22:39:40 242896 -c–a-w- c:\windows\system32\drivers\avgtdix.sys
2010-05-26 22:38:44 50968 -c–a-w- c:\windows\system32\avgfwdx.dll
2010-05-26 22:38:44 30104 -c–a-w- c:\windows\system32\drivers\avgfwdx.sys
2010-05-26 22:37:27 0 dc—-w- c:\program files\AVG
2010-05-26 22:37:02 0 dc—-w- c:\docume~1\alluse~1\applic~1\avg9
2010-05-26 22:27:33 0 dc—-w- c:\windows\4FC9DA9DF608454E8191D7EFFDCC5726.TMP
2010-05-26 22:27:32 0 dc—-w- c:\program files\common files\Wise Installation Wizard
2010-05-26 22:12:18 0 dc—-w- c:\docume~1\alluse~1\applic~1\NortonInstaller
2010-05-26 22:10:06 0 -c–a-w- c:\windows\system32\drivers\oramwp.sys
2010-05-18 00:06:02 73728 -c–a-w- c:\windows\system32\javacpl.cpl
2010-05-18 00:06:02 411368 -c–a-w- c:\windows\system32\deployJava1.dll
2010-05-02 00:51:35 0 dc—-w- c:\docume~1\alluse~1\applic~1\PCSettings

==================== Find3M ====================

2010-05-26 20:56:42 256 -c–a-w- c:\documents and settings\operator\pool.bin
2010-03-10 06:15:52 420352 -c–a-w- c:\windows\system32\vbscript.dll
2008-05-24 10:07:12 32768 -csha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008052420080525\index.dat
2007-08-29 08:20:23 15775008 -csha-w- c:\windows\system32\drivers\fidbox.dat
2007-08-29 08:20:24 331552 -csha-w- c:\windows\system32\drivers\fidbox2.dat

============= FINISH: 18:45:39.35 ===============



GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-30 21:33:53
Windows 5.1.2600 Service Pack 3
Running: qg4dmhoi.exe; Driver: C:\DOCUME~1\Operator\LOCALS~1\Temp\pwtdrpow.sys


—- System - GMER 1.0.15 —-

SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwCreateKey [0xBA91887E]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xBA98A670]
SSDT Lbd.sys (Boot Driver/Lavasoft AB) ZwSetValueKey [0xBA918BFE]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xA5005620]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xBA98A7C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xBA98A860]

—- Kernel code sections - GMER 1.0.15 —-

init C:\WINDOWS\system32\drivers\tifm21.sys entry point in "init" section [0xB8B5FEBF]

—- User code sections - GMER 1.0.15 —-

.text c:\program files\a-squared free\a2service.exe[1136] kernel32.dll!CreateThread + 1A 7C8106F1 4 Bytes CALL 00454E05 c:\program files\a-squared free\a2service.exe (a-squared Service/Emsi Software GmbH)
.text C:\WINDOWS\system32\SearchIndexer.exe[2212] kernel32.dll!WriteFile 7C810E27 7 Bytes JMP 00585C0C C:\WINDOWS\system32\MSSRCH.DLL (mssrch.dll/Microsoft Corporation)

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

—- EOF - GMER 1.0.15 —-

Attachments:

Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step



Download TDSSKiller and save it to your Desktop.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone
Ok, I did the above steps. The browser crashing seems to have gotten worse and there is a lot of internet lag. I am also getting these popup windows .


[external image: Posted Image]


Here is the log generated from GooredFix:

GooredFix by jpshortstuff (08.01.10.1)
Log created at 11:24 on 20/06/2010 (Operator)
Firefox version 3.6.3 (en-US)

========== GooredScan ==========


========== GooredLog ==========

C:\Program Files\Mozilla Firefox\extensions\
{972ce4c6-7e08-4474-a285-3208198ce6fd} [03:55 06/01/2007]
{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} [05:06 04/01/2010]
{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} [05:14 04/01/2010]
{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} [00:06 18/05/2010]

C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\extensions\
Access Privileges Test [04:19 11/04/2007]
[removed] [02:43 25/05/2010]
[removed] [00:14 16/12/2008]
[removed] [01:16 20/04/2010]
[removed] [09:48 07/01/2010]
{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}(2) [22:23 18/06/2009]
{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB} [05:26 25/05/2010]
{20a82645-c095-46ed-80e3-08825760534b} [00:35 02/05/2010]
{34c409b0-936e-11db-b606-0800200c9a66} [05:35 06/01/2007]
{44d0a1b4-9c90-4f86-ac92-8680b5d6549e} [18:25 10/10/2009]
{89506680-e3f4-484c-a2c0-ed711d481eda} [07:34 18/01/2010]
{B042753D-F57E-4e8e-A01B-7379A6D4CEFB} [21:54 26/05/2010]
{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}-trash [21:54 26/05/2010]
{B9C8BE50-7105-4ec6-8FB4-4935C0671648} [07:55 17/02/2010]
{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B} [02:43 25/05/2010]
{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} [20:44 11/05/2010]
{d3d70bca-2d54-425e-b02c-b7e2f4b07688} [09:53 12/07/2009]
{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389} [01:15 20/04/2010]

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [21:48 28/01/2009]
"[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [00:05 18/05/2010]
"{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [22:38 26/05/2010]
"avg@igeared"="C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared" [22:41 26/05/2010]

-=E.O.F=-
Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
That seems to have helped a lot! Thank you so much. After running CF my computer was rebooted and the search redirecting seems to have stopped. Firefox did freeze and crash a few times before I was finally able to get it open, but after I did, it's holding up pretty well. I restored my AVG resident shield and haven't gotten any popups yet! Here are my scan results from CF: ComboFix 10-06-20.03 - Operator 06/20/2010 18:29:32.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1267 [GMT -7:00] Running from: C:\Documents and Settings\[removed]\Desktop\Downloads\ComboFix.exe AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} FW: AVG Firewall *enabled* {8decf618-9569-4340-b34a-d78d28969b66} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\DOCUME~1\Operator\LOCALS~1\Temp\install_flash_player.exe C:\Documents and Settings\Operator\Local Settings\Application Data\Windows Server C:\Documents and Settings\Operator\Local Settings\Application Data\Windows Server\flags.ini C:\Documents and Settings\Operator\Local Settings\Application Data\Windows Server\uses32.dat C:\feed.txt c:\windows\system32\driVERs\oramwp.sys C:\WINDOWS\system32\hlp.dat Infected copy of C:\WINDOWS\system32\ws2_32.dll was found and disinfected Restored copy from - C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_oramwp ——-\Service_oramwp ((((((((((((((((((((((((( Files Created from 2010-05-21 to 2010-06-21 ))))))))))))))))))))))))))))))) . 2010-06-13 19:19:04 . 2010-05-06 10:41:48 743424 -c—-w- C:\WINDOWS\system32\dllcache\iedvtool.dll 2010-06-13 19:08:04 . 2010-06-13 19:12:03 ——– dc—-w- C:\Documents and Settings\LocalService\Local Settings\Application Data\Temp 2010-05-29 01:33:35 . 2010-05-29 01:33:36 ——– dc—-w- C:\Documents and Settings\Operator\Application Data\AVG9 2010-05-28 01:11:11 . 2010-05-28 01:11:11 ——– dcsh–w- C:\WINDOWS\system32\config\systemprofile\IETldCache 2010-05-27 07:52:46 . 2010-02-04 15:53:02 64288 -c–a-w- C:\WINDOWS\system32\drivers\Lbd.sys 2010-05-27 07:52:40 . 2010-05-27 07:52:36 95024 -c–a-w- C:\WINDOWS\system32\drivers\SBREDrv.sys 2010-05-27 07:44:58 . 2010-05-27 07:44:59 ——– dc-h–w- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6} 2010-05-27 07:44:33 . 2010-05-27 07:52:44 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\Lavasoft 2010-05-27 07:36:50 . 2010-05-27 07:36:50 ——– dc—-w- C:\Program Files\Trend Micro 2010-05-27 07:14:05 . 2010-05-27 07:14:05 ——– dc—-w- C:\Documents and Settings\Operator\Application Data\SUPERAntiSpyware.com 2010-05-27 07:14:05 . 2010-05-27 07:14:05 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2010-05-27 07:13:57 . 2010-06-13 19:13:55 ——– dc—-w- C:\Program Files\SUPERAntiSpyware 2010-05-27 07:12:19 . 2010-05-27 07:12:19 ——– dc—-w- C:\Documents and Settings\Operator\Application Data\Malwarebytes 2010-05-27 07:12:00 . 2010-04-29 22:39:38 38224 -c–a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2010-05-27 07:11:59 . 2010-05-27 07:12:05 ——– dc—-w- C:\Program Files\Malwarebytes' Anti-Malware 2010-05-27 07:11:59 . 2010-05-27 07:11:59 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2010-05-27 07:11:59 . 2010-04-29 22:39:26 20952 -c–a-w- C:\WINDOWS\system32\drivers\mbam.sys 2010-05-27 01:46:42 . 2010-05-27 04:19:16 664 -c–a-w- C:\WINDOWS\system32\d3d9caps.dat 2010-05-26 22:57:35 . 2010-05-26 22:57:35 ——– dc—-w- C:\Documents and Settings\Operator\Local Settings\Application Data\AVG Security Toolbar 2010-05-26 22:56:53 . 2010-05-26 22:56:53 ——– dc—-w- C:\$AVG 2010-05-26 22:41:40 . 2010-05-26 22:41:41 12464 -c–a-w- C:\WINDOWS\system32\avgrsstx.dll 2010-05-26 22:41:38 . 2010-05-26 22:41:38 216200 -c–a-w- C:\WINDOWS\system32\drivers\avgldx86.sys 2010-05-26 22:41:34 . 2010-06-13 19:19:09 29584 -c–a-w- C:\WINDOWS\system32\drivers\avgmfx86.sys 2010-05-26 22:41:09 . 2010-06-21 00:59:08 ——– dc—-w- C:\WINDOWS\system32\drivers\Avg 2010-05-26 22:41:04 . 2010-05-26 22:43:20 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar 2010-05-26 22:39:43 . 2010-05-26 22:39:43 25096 -c–a-w- C:\WINDOWS\system32\drivers\AVGIDSxx.sys 2010-05-26 22:39:42 . 2010-05-26 22:39:43 52872 -c–a-w- C:\WINDOWS\system32\drivers\avgrkx86.sys 2010-05-26 22:39:40 . 2010-06-13 19:19:10 242896 -c–a-w- C:\WINDOWS\system32\drivers\avgtdix.sys 2010-05-26 22:38:44 . 2010-05-26 22:38:45 30104 -c–a-w- C:\WINDOWS\system32\drivers\avgfwdx.sys 2010-05-26 22:38:44 . 2010-05-26 22:38:44 50968 -c–a-w- C:\WINDOWS\system32\avgfwdx.dll 2010-05-26 22:37:27 . 2010-05-26 22:37:27 ——– dc—-w- C:\Program Files\AVG 2010-05-26 22:37:02 . 2010-06-20 18:29:43 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\avg9 2010-05-26 22:27:33 . 2010-05-27 07:07:05 ——– dc—-w- C:\WINDOWS\4FC9DA9DF608454E8191D7EFFDCC5726.TMP 2010-05-26 22:27:32 . 2010-05-26 22:27:32 ——– dc—-w- C:\Program Files\Common Files\Wise Installation Wizard 2010-05-26 22:12:18 . 2010-05-26 22:12:18 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\NortonInstaller 2010-05-26 22:10:10 . 2010-05-27 07:21:44 ——– dc—-w- C:\Documents and Settings\Operator\Local Settings\Application Data\bedckrmih . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-20 18:16:05 . 2008-10-05 07:40:44 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\Google Updater 2010-06-20 18:14:43 . 2008-06-13 06:47:31 ——– dc—-w- C:\Program Files\Microsoft Silverlight 2010-06-13 20:26:03 . 2008-07-10 08:01:02 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2010-06-13 19:19:48 . 2010-06-13 19:19:48 29512 -c–a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgmfx86.sys 2010-06-13 19:19:48 . 2010-06-13 19:19:48 242896 -c–a-w- C:\Documents and Settings\All Users\Application Data\avg9\update\backup\avgtdix.sys 2010-05-29 01:36:52 . 2008-01-12 21:21:01 256 -c–a-w- C:\WINDOWS\system32\pool.bin 2010-05-28 21:36:59 . 2010-05-27 07:14:56 63488 -c–a-w- C:\Documents and Settings\Operator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2010-05-28 21:36:57 . 2010-05-27 07:14:54 117760 -c–a-w- C:\Documents and Settings\Operator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-05-28 21:35:42 . 2009-03-22 05:48:15 ——– dc—-w- C:\Program Files\Ultra Mobile 3GP Video Converter 2010-05-28 21:33:34 . 2007-01-09 04:20:31 ——– dc—-w- C:\Program Files\a-squared Free 2010-05-28 19:28:20 . 2007-08-28 08:19:34 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2010-05-28 19:16:05 . 2007-08-28 10:25:24 ——– dc—-w- C:\Program Files\CCleaner 2010-05-28 03:40:46 . 2010-05-28 03:40:46 503808 -c–a-w- C:\Documents and Settings\Operator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-149b80f4-n\msvcp71.dll 2010-05-28 03:40:46 . 2010-05-28 03:40:46 499712 -c–a-w- C:\Documents and Settings\Operator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-149b80f4-n\jmc.dll 2010-05-28 03:40:46 . 2010-05-28 03:40:46 348160 -c–a-w- C:\Documents and Settings\Operator\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-149b80f4-n\msvcr71.dll 2010-05-28 03:40:46 . 2010-05-28 03:40:46 12800 -c–a-w- C:\Documents and Settings\Operator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-22ac9bac-n\decora-d3d.dll 2010-05-28 03:40:45 . 2010-05-28 03:40:45 61440 -c–a-w- C:\Documents and Settings\Operator\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-22ac9bac-n\decora-sse.dll 2010-05-27 07:45:03 . 2007-01-06 18:22:48 ——– dc—-w- C:\Program Files\Lavasoft 2010-05-27 07:36:51 . 2010-05-27 07:36:51 388096 -c–a-r- C:\Documents and Settings\Operator\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe 2010-05-27 07:14:55 . 2010-05-27 07:14:55 52224 -c–a-w- C:\Documents and Settings\Operator\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-05-27 00:13:21 . 2007-04-27 04:23:46 ——– dc—-w- C:\Documents and Settings\Operator\Application Data\Media Player Classic 2010-05-26 21:55:18 . 2007-01-14 06:39:57 ——– dc—-w- C:\Program Files\BitComet 2010-05-26 21:03:31 . 2008-01-09 04:54:55 ——– dc–a-w- C:\Documents and Settings\All Users\Application Data\TEMP 2010-05-26 21:03:20 . 2007-01-06 18:20:28 ——– dc—-w- C:\Program Files\SpywareBlaster 2010-05-26 20:56:42 . 2007-12-18 09:57:28 256 -c–a-w- C:\Documents and Settings\Operator\pool.bin 2010-05-19 06:54:38 . 2010-05-19 06:54:38 26694 -c–a-r- C:\Documents and Settings\Operator\Application Data\Microsoft\Installer\{269ED390-8651-4935-AB18-34BDD12D81AB}\BlackBerry.exe 2010-05-19 03:32:08 . 2008-10-05 07:40:43 ——– dc—-w- C:\Program Files\Google 2010-05-18 00:18:03 . 2007-01-13 05:12:16 ——– dc—-w- C:\Program Files\Common Files\Java 2010-05-18 00:05:45 . 2010-05-18 00:06:02 411368 -c–a-w- C:\WINDOWS\system32\deployJava1.dll 2010-05-06 10:41:53 . 2004-08-04 12:00:00 916480 -c–a-w- C:\WINDOWS\system32\wininet.dll 2010-05-02 05:22:50 . 2004-08-04 12:00:00 1851264 -c–a-w- C:\WINDOWS\system32\win32k.sys 2010-05-02 01:20:51 . 2010-05-02 01:20:51 ——– dc—-w- C:\Program Files\Windows Sidebar 2010-05-02 00:57:02 . 2007-08-29 08:11:51 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\Symantec 2010-05-02 00:51:35 . 2010-05-02 00:51:35 ——– dc—-w- C:\Documents and Settings\All Users\Application Data\PCSettings 2010-04-21 00:21:13 . 2010-04-21 00:21:13 26694 -c–a-r- C:\Documents and Settings\Operator\Application Data\Microsoft\Installer\{64E51C99-7613-4E89-A462-C3A01FBE3C83}\BlackBerry.exe 2010-04-20 05:30:08 . 2004-08-04 12:00:00 285696 -c–a-w- C:\WINDOWS\system32\atmfd.dll 2010-04-06 02:38:11 . 2010-04-06 02:38:11 26694 -c–a-r- C:\Documents and Settings\Operator\Application Data\Microsoft\Installer\{DE907EE9-D3F8-41C2-B388-3529A482A75A}\BlackBerry.exe 2007-08-29 08:20:23 . 2007-08-07 03:55:05 15775008 -csha-w- C:\WINDOWS\system32\drivers\fidbox.dat 2007-08-29 08:20:24 . 2007-08-07 03:55:05 331552 -csha-w- C:\WINDOWS\system32\drivers\fidbox2.dat . ——- Sigcheck ——- [-] 2009-01-24 11:22:21 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\dllcache\tcpip.sys [-] 2009-01-24 11:22:21 . D24EA301E2B36C4E975FD216CA85D8E7 . 361600 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\system32\drivers\tcpip.sys [7] 2008-06-20 11:59:02 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625 (xpsp_sp3_qfe.080620-1309)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys [7] 2008-04-13 19:20:16 . 93EA8D04EC73A85DB02EB8805988F733 . 361344 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\tcpip.sys [-] 2007-10-30 17:20:55 . 90CAFF4B094573449A0872A0F919B178 . 360064 . . [5.1.2600.3244 (xpsp_sp2_gdr.071030-1259)] . . C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys [-] 2007-10-30 16:53:32 . 64798ECFA43D78C7178375FCDD16D8C8 . 360832 . . [5.1.2600.3244 (xpsp_sp2_qfe.071030-1255)] . . C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys [-] 2006-04-20 12:18:35 . B2220C618B42A2212A59D91EBD6FC4B4 . 360576 . . [5.1.2600.2892 (xpsp.060420-0256)] . . C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys [-] 2005-05-25 19:07:12 . 63FDFEA54EB53DE2D863EE454937CE1E . 359936 . . [5.1.2600.2685 (xpsp.050525-1029)] . . C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys [7] 2008-04-14 00:12:08 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ServicePackFiles\i386\user32.dll [-] 2008-04-14 00:12:08 . 48FDBBE0E55B15E1886FCF5D8563B19F . 578560 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\user32.dll [-] 2007-03-08 15:48:36 . 7AA4F6C00405DFC4B70ED4214E7D687B . 578048 . . [5.1.2600.3099 (xpsp_sp2_qfe.070308-0217)] . . C:\WINDOWS\$NtServicePackUninstall$\user32.dll [-] 2005-03-02 18:19:56 . 1800F293BCCC8EDE8A70E12B88D80036 . 577024 . . [5.1.2600.2622 (xpsp.050301-1521)] . . C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll [7] 2008-04-14 00:12:10 . 9789E95E1D88EEB4B922BF3EA7779C28 . 19968 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\ws2help.dll [-] 2008-04-14 00:12:10 . 6388CB57165A1496B75333BB7492CCA9 . 19968 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\ws2help.dll [7] 2004-08-04 12:00:00 . 9BEACB911CA61E5881102188AB7FB431 . 19968 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\$NtServicePackUninstall$\ws2help.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks] "{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 17:25:40 2117704] [HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll" [2010-04-19 17:25:40 2117704] [HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 17:14:36 206112] "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-06-13 19:13:56 2403568] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 00:12:16 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-02-07 00:39:00 94208] "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-02-07 00:36:00 77824] "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-02-07 00:40:00 118784] "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-08 00:07:16 61952] "RTHDCPL"="RTHDCPL.EXE" [2006-01-11 09:23:34 15961088] "KTPWare"="C:\Program Files\Elantech\ktp.exe" [2005-10-27 06:50:36 512000] "CHotkey"="mHotkey.exe" [2001-12-26 21:12:26 472576] "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 19:50:42 155648] "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-03 04:24:46 32768] "BlackBerryAutoUpdate"="C:\Program Files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-11 05:32:26 648536] "IntelZeroConfig"="C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe" [2009-05-21 20:49:36 1372160] "IntelWireless"="C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2009-05-21 20:06:22 1202448] "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 20:31:24 236016] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2009-11-11 07:08:18 417792] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2009-11-13 00:33:10 141600] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 05:42:51 36272] "Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 18:17:47 952768] "SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 18:43:18 248040] "AVG9_TRAY"="C:\PROGRA~1\AVG\AVG9\avgtray.exe" [2010-06-13 19:19:11 2065248] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 05:41:34 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 17:13:36 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21:41 548352 -c–a-w- C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2010-05-26 22:41:41 12464 -c–a-w- C:\WINDOWS\system32\avgrsstx.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MCPClient] 2005-01-31 22:13:38 49152 —-a-w- C:\PROGRA~1\COMMON~1\Stardock\MCPStub.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB] 2001-12-21 07:34:52 24576 —-a-w- C:\Program Files\AlienGUIse\fastload.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"= "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= "C:\\Program Files\\BitComet\\BitComet.exe"= "C:\\Program Files\\Skype\\Phone\\Skype.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\AVG\\AVG9\\avgam.exe"= "C:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"= "C:\\Program Files\\AVG\\AVG9\\avgupd.exe"= "C:\\Program Files\\AVG\\AVG9\\avgnsx.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "11348:TCP"= 11348:TCP:BitComet 11348 TCP "11348:UDP"= 11348:UDP:BitComet 11348 UDP "11897:TCP"= 11897:TCP:BitComet 11897 TCP "11897:UDP"= 11897:UDP:BitComet 11897 UDP R0 AVGIDSErHrxpx;AVG9IDSErHr;C:\WINDOWS\system32\drivers\AVGIDSxx.sys [5/26/2010 3:39:43 PM 25096] R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\drivers\avgrkx86.sys [5/26/2010 3:39:42 PM 52872] R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [5/27/2010 12:52:46 AM 64288] R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\drivers\avgldx86.sys [5/26/2010 3:41:38 PM 216200] R1 AvgTdiX;AVG Network Redirector;C:\WINDOWS\system32\drivers\avgtdix.sys [5/26/2010 3:39:40 PM 242896] R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25:48 AM 12872] R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41:30 AM 67656] R2 a2free;a-squared Free Service;C:\Program Files\a-squared Free\a2service.exe [8/11/2007 5:00:14 PM 1872320] R2 avg9wd;AVG WatchDog;C:\Program Files\AVG\AVG9\avgwdsvc.exe [5/26/2010 3:39:37 PM 308064] R2 avgfws9;AVG Firewall;C:\Program Files\AVG\AVG9\avgfws9.exe [5/26/2010 3:40:04 PM 2331544] R2 bwcdrv;BUFFALO Wireless Configuration;C:\WINDOWS\system32\drivers\BWCDRV.SYS [12/21/2003 1:21:00 AM 19840] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2/4/2010 8:52:57 AM 1314704] R2 WDDMService;WD SmartWare Drive Manager;C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [11/5/2009 8:44:16 AM 110592] R2 WDSmartWareBackgroundService;WD SmartWare Background Service;C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [6/16/2009 8:58:08 AM 20480] R2 wwEngineSvc;Window Washer Engine;C:\Program Files\Webroot\Washer\WasherSvc.exe [8/28/2007 12:57:44 AM 388936] R3 Avgfwdx;Avgfwdx;C:\WINDOWS\system32\drivers\avgfwdx.sys [5/26/2010 3:38:44 PM 30104] S2 gupdate;Google Update Service (gupdate);C:\Program Files\Google\Update\GoogleUpdate.exe [12/14/2009 1:27:53 AM 135664] S3 AVG Security Toolbar Service;AVG Security Toolbar Service;C:\Program Files\AVG\AVG9\Toolbar\ToolbarBroker.exe [5/26/2010 3:41:03 PM 430152] S3 Avgfwfd;AVG network filter service;C:\WINDOWS\system32\drivers\avgfwdx.sys [5/26/2010 3:38:44 PM 30104] S3 AVGIDSAgent;AVG9IDSAgent;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [5/26/2010 3:39:23 PM 5888008] S3 AVGIDSDriverxpx;AVG9IDSDriver;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [5/26/2010 3:39:28 PM 122376] S3 AVGIDSFilterxpx;AVG9IDSFilter;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [5/26/2010 3:39:27 PM 30216] S3 AVGIDSShimxpx;AVG9IDSShim;C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [5/26/2010 3:39:26 PM 26120] S3 WDC_SAM;WD SCSI Pass Thru driver;C:\WINDOWS\system32\drivers\wdcsam.sys [3/14/2010 6:16:23 PM 11520] . Contents of the 'Scheduled Tasks' folder 2010-06-21 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job - C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 15:52:58 . 2010-05-27 07:51:25] 2010-04-12 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34:12 . 2008-07-30 19:34:12] 2010-06-21 C:\WINDOWS\Tasks\Google Software Updater.job - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-05 07:40:43 . 2009-03-27 04:51:07] 2010-06-21 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-14 08:27:53 . 2009-12-14 08:27:49] 2010-06-21 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-14 08:27:53 . 2009-12-14 08:27:49] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com IE: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm Handler: avgsecuritytoolbar - {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll DPF: vzTCPConfig - hxxp://www2.verizon.net/help/fios_settings_POTT20009/include/vzTCPConfig.CAB DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab FF - ProfilePath - C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\ FF - component: C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}\components\IBitCometExtension.dll FF - component: C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\extensions\[removed]\components\coolirisstub.dll FF - component: C:\Program Files\AVG\AVG9\Firefox\components\avgssff.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll FF - component: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll FF - plugin: C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\extensions\{1BC9BA34-1EED-42ca-A505-6D2F1A935BBB}\plugins\npietab2.dll FF - plugin: C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: C:\Documents and Settings\Operator\Application Data\Mozilla\Firefox\Profiles\qzesgo25.default\extensions\[removed]\plugins\npcoolirisplugin.dll FF - plugin: C:\Documents and Settings\Operator\Application Data\Mozilla\plugins\npcoolirisplugin.dll FF - plugin: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll FF - plugin: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll FF - plugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: C:\Program Files\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: C:\Program Files\Microsoft\Office Live\npOLW.dll FF - plugin: C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ —- FIREFOX POLICIES —- C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); . - - - - ORPHANS REMOVED - - - - HKLM-Run-N360 - C:\Program Files\NortonInstaller\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360\A5E82D02\4.0.0.127\InstStub.exe
Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Ok, well I spoke a little too soon. After running CF yesterday I shut off my computer, but when I turned it back on to run MBAM it got stuck in a constant reboot cycle.

My system tries to start Windows but stops at the load screen, flashes (what looks like the BSoD) then starts over. I'm going to try starting in Safe Mode, but I'm not quite sure I can even get to there.

UPDATE: I can't start in Safe Mode, it tries, but gets stuck in the drivers screen and freezes. Help!
I need you to find your original Windows installation CD then follow the directions below:

1. Inset your Windows Install disc to boot from CD.
Note: if you cannot boot from the CD, go into your BIOS and set the computer to boot from CD first

2. Press any key on the keyboard when prompted.
3. Press R to load the Recovery Console.
4. Enter your password when prompted.
5. You must enter which Windows installation to log onto. Type 1 and press enter.
6. At the C:\Windows prompt, type the following bolded text, and press Enter:

cd ERDNT\Hiv-backup

7. At the next prompt, type the following bolded text, and press Enter:

batch erdnt.con

8. The erunt backups will begin copying.
9. At the next prompt, type the following bolded text, and press Enter:

exit

Windows will now begin loading.

When Windows has loaded up again, post me the contents of the Combofix log located at C:\Combofix.txt
Ok, I will need to look for the disc. It may take me a couple of days, so please don't think I've abandoned this thread. Thank you !
I did install the recovery console when I ran CF, but when I try to run it a screen pops up that says: "NTLDR is compressed. Press Ctrl+Alt+Del to restart" I did find the CD that came with my laptop and when I boot from CD it only gives me an option to install over my existing. Is there any way to save some files even if I do have to perform a fresh install?
Get into the Recovery Console, and see if NTLDR is compressed:

Type: dir \ntldr

If the "c" attribute is shown, enter the command:

Type: attrib -c \ntldr

Type: exit (reboot)

Note the spaces, they need to be there.
Yes, sorry. I have been trying and have not been able to get into the recovery console. It just keeps rebooting itself everytime I try. Is there any other way?

Yes, sorry. I have been trying and have not been able to get into the recovery console. It just keeps rebooting itself everytime I try. Is there any other way?

You'll need your Windows CD to boot from. Do you have that?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI