This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

More Google Redirects

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sometimes I click links from a Google search and they redirect me to other sites. a few times today i ended up on 'monstermarketplace.com I went to safe mode and did a norton full scan. it found stuff. i then reboot and safe mode; scan again shows clean. redirects still happening, maybe not as ofteen. almost always the first time I use google after opening a browser. I attached the norton export of the scan that found stuff. it shows a lot of the finding were in a java folder. TIA, ROB _______________________________________ DDS SCAN___________ _______________________ DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 20:16:05.57 on Mon 06/14/2010 Internet Explorer: 7.0.5730.13 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3016.2003 [GMT -6:00] AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: ISS Proventia 9.0.226.0 *enabled* {1B42F604-2FE3-485B-BA3D-B55276659D1F} ============== Running Processes =============== C:\WINDOWS\system32\ibmpmsvc.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Accenture Connection\9341989\Program\ServiceWrapper-9341989.exe C:\Program Files\ISS\Proventia Desktop\blackd.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Juniper Networks\Common Files\dsNcService.exe C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\ManageSoft\Security Agent\mgssecsvc.exe C:\Program Files\ManageSoft\Launcher\ndserv.exe C:\Program Files\ManageSoft\Schedule Agent\ndinit.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe C:\WINDOWS\system32\IoctlSvc.exe C:\WINDOWS\system32\Prot_srv.exe C:\WINDOWS\system32\pstartSr.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe C:\Program Files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe C:\WINDOWS\Explorer.EXE C:\Program Files\ManageSoft\Schedule Agent\ndtask.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe C:\Program Files\Accenture\AMDD\AMDD.exe C:\Program Files\Microsoft Office Communicator\communicator.exe C:\Program Files\Accenture Connection\9341989\Program\Accenture Connection.exe C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Pointsec\Pointsec for PC\P95Tray.exe C:\Program Files\Lenovo\Zoom\TpScrex.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe C:\Program Files\Microsoft ActiveSync\wcescomm.exe C:\PROGRA~1\MICROS~4\rapimgr.exe C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Logitech\SetPoint\KEM.exe C:\Program Files\ISS\Proventia Desktop\blackice.exe C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\PROGRA~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Symantec AntiVirus\VPC32.exe C:\Program Files\Microsoft Office\Office12\EXCEL.EXE D:\Documents and Settings\robert.p.powell\Desktop\dds.scr ============== Pseudo HJT Report =============== uWindow Title = Windows Internet Explorer provided by Accenture uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = localhost; BHO: HelperObject Class: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 7\SnagItBHO.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: ManageSoft Web Application Tracker: {30a22ec9-42d0-4d46-a2f7-7516419f943d} - c:\progra~1\manage~1\usagea~1\mgsiebho.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: SnagIt: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 7\SnagItIEAddin.dll TB: {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No File TB: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MPlayer] c:\windows\system32\MPlayer.vbs uRun: [LDM] c:\program files\logitech\desktop messenger\8876480\program\BackWeb-8876480.exe uRun: [H/PC Connection Agent] "c:\program files\microsoft activesync\wcescomm.exe" mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [vptray] c:\progra~1\symant~1\VPTray.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [picon] "c:\program files\common files\intel\privacy icon\PrivacyIconClient.exe" -startup mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [TPHOTKEY] c:\program files\lenovo\hotkey\TPOSDSVC.exe mRun: [AMDD] c:\program files\accenture\amdd\AMDD.exe mRun: [Communicator] "c:\program files\microsoft office communicator\communicator.exe" /fromrunkey mRun: [ACSTP] e:\local\other\locpost62\icollect\acstp_install.exe mRun: [Accenture Connection] "c:\program files\accenture connection\9341989\program\Accenture Connection.exe" -startup mRun: [Pointsec Tray] c:\program files\pointsec\pointsec for pc\P95Tray.exe mRun: [SchedulingAgent_nDG] "c:\program files\managesoft\schedule agent\ndschedag.exe" -o RunNDStartup=True -o Startup=True mRun: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe mRun: [NBKeyScan] "c:\program files\nero\nero8\nero backitup\NBKeyScan.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [DLA] c:\windows\system32\dla\DLACTRLW.EXE mRun: [Total PC Defender] c:\program files\total pc defender\Total PC Defender.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" StartupFolder: d:\docume~1\robert~1.pow\startm~1\programs\startup\pictur~1.lnk - c:\program files\sony\sony picture utility\pmbcore\SPUVolumeWatcher.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\accent~1.lnk - c:\program files\accenture connection\9341989\program\Accenture Connection.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\thinkpad\bluetooth software\BTTray.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\logite~2.lnk - c:\program files\logitech\desktop messenger\8876480\program\LDMConf.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\logite~1.lnk - c:\program files\logitech\setpoint\KEM.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\proven~1.lnk - c:\program files\iss\proventia desktop\blackice.exe StartupFolder: d:\docume~1\alluse~1\startm~1\programs\startup\window~1.lnk - c:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: NoWelcomeScreen = 1 (0x1) mPolicies-system: LogonType = 0 (0x0) IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\thinkpad\bluetooth software\btsendto_ie.htm IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll IE: {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - c:\progra~1\micros~4\INetRepl.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL Trusted Zone: accenture.com Trusted Zone: accenture.com DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab DPF: {0D0950E6-046D-437A-8985-369BE10C7E2A} - hxxps://iauthor.accenture.com/iAuthor/ASP/IALogOut.CAB DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} - hxxps://iauthor.accenture.com/iAuthor/ASP/Reporting/ScriptX.cab DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxps://sync.accenture.com/projectserver/objects/pjclient.cab DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} - hxxps://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue-enterprise.com/Customer/x86/RescueDownloader.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269724662777 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {8BBDC81D-81B3-49EE-87E8-47B7A707FAE8} - hxxps://www2.gotomeeting.com/default/applets/g2mdlax.cab DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxps://sync.accenture.com/projectserver/objects/1033/pjcintl.cab DPF: {BF17C411-9ADA-4C73-B12C-BD814BDE187F} - hxxps://mylearning.accenture.com/accenture/core/common/ScheduleServices/ScheduleServices.cab DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_01-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} - hxxps://amr1-extranet.accenture.com/dana-cached/setup/JuniperSetupSP1.cab Handler: bwfile-9341989 - {358D3935-0C33-4169-9598-63FAF077328B} - c:\program files\accenture connection\9341989\program\GAPlugProtocol-9341989.dll Notify: igfxcui - igfxdev.dll Notify: NavLogon - c:\windows\system32\NavLogon.dll Notify: tpfnf2 - c:\program files\lenovo\hotkey\notifyf2.dll Notify: tphotkey - c:\program files\lenovo\hotkey\tphklock.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll ============= SERVICES / DRIVERS =============== R0 prot_2k;prot_2k;c:\windows\system32\drivers\prot_2k.sys [2008-4-12 221632] R1 abdc;abdc;c:\windows\system32\abdc.sys [2010-6-13 80896] R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [2009-8-27 13480] R1 SAVRT;SAVRT;c:\program files\symantec antivirus\savrt.sys [2006-9-6 337592] R1 SAVRTPEL;SAVRTPEL;c:\program files\symantec antivirus\Savrtpel.sys [2006-9-6 54968] R2 BackWeb Plug-in - 9341989;Accenture Connection;c:\program files\accenture connection\9341989\program\ServiceWrapper-9341989.exe [2009-10-23 28711] R2 BlackICE;BlackICE;c:\program files\iss\proventia desktop\blackd.exe [2009-10-21 2081034] R2 ccEvtMgr;Symantec Event Manager;c:\program files\common files\symantec shared\ccEvtMgr.exe [2007-5-29 192104] R2 ccSetMgr;Symantec Settings Manager;c:\program files\common files\symantec shared\ccSetMgr.exe [2007-5-29 169576] R2 mgssecsvc;ManageSoft Security Service;c:\program files\managesoft\security agent\mgssecsvc.exe [2009-8-8 1095168] R2 ndGlobalLauncher;ManageSoft installation agent;c:\program files\managesoft\launcher\ndserv.exe [2009-8-8 2899264] R2 ndinit;ManageSoft managed device;c:\program files\managesoft\schedule agent\ndinit.exe [2009-8-8 730944] R2 Pointsec;Pointsec;c:\windows\system32\Prot_srv.exe [2008-4-12 367168] R2 Pointsec_start;Pointsec Service Start;c:\windows\system32\pstartSr.exe [2008-4-12 145984] R2 Symantec AntiVirus;Symantec AntiVirus;c:\program files\symantec antivirus\Rtvscan.exe [2007-10-7 1822648] R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2009-10-21 2058776] R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [2009-8-27 239760] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-5-27 102448] R3 NAVENG;NAVENG;c:\progra~1\common~1\symant~1\virusd~1\20100614.003\naveng.sys [2010-6-14 85552] R3 NAVEX15;NAVEX15;c:\progra~1\common~1\symant~1\virusd~1\20100614.003\navex15.sys [2010-6-14 1347504] R4 black;black;c:\windows\system32\drivers\Blackcat.sys [2009-10-21 205938] S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [2009-11-6 114016] S3 Cdmsvos;Cdmsvos; [x] S3 IgniteService;IgniteService;c:\program files\ignitecds\IgniteService.exe [2009-10-20 86016] S3 MakoNT;MakoNT;c:\windows\system32\drivers\isskboep.sys [2009-10-21 80512] S3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [2009-10-21 50163] S3 SavRoam;SAVRoam;c:\program files\symantec antivirus\SavRoam.exe [2007-10-7 116664] S3 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\iss\proventia desktop\vpatch.exe [2009-10-21 405770] S4 mgsdl;ManageSoft Peer-to-Peer Download Service;c:\program files\managesoft\launcher\mgsdl.exe [2009-8-8 1401344] =============== Created Last 30 ================ 2010-06-13 15:48 80,896 a——- c:\windows\system32\abdc.sys 2010-06-08 08:59 –d—– c:\program files\examotion ==================== Find3M ==================== 2010-05-04 22:50 3,600,384 a——- c:\windows\system32\dllcache\mshtml.dll 2010-04-16 07:24 70,656 a——- c:\windows\system32\dllcache\ie4uinit.exe 2010-04-16 07:24 13,824 ——– c:\windows\system32\dllcache\ieudinit.exe 2010-04-16 05:43 634,656 a——- c:\windows\system32\dllcache\iexplore.exe 2010-04-16 05:43 161,792 a——- c:\windows\system32\dllcache\ieakui.dll 2008-07-18 10:48 45,056 a——- c:\program files\common files\Period20.dll 2008-07-18 10:48 24,576 a——- c:\program files\common files\Artes32X.dll 2008-07-18 10:48 24,576 a——- c:\program files\common files\ACTripsLog.dll 2007-07-26 20:02 305,688 a——- c:\windows\inf\IaStor.sys 2006-09-12 16:21 319 a——- c:\program files\VersionMarker.dat 2009-10-24 17:07 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009102420091025\index.dat ============= FINISH: 20:16:38.03 ===============

Attachments:

Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step



Download TDSSKiller and save it to your Desktop.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone
I dont have firefox installed. IE7on XP SP3. Regardless, I followed the steps. The results look promising. So far, about 20 different links without any redirects. Testing will continue. Do I need to update Java Virtual Machine or something. That appears to be where the issue comes from? Goored log: ________________________ GooredFix by jpshortstuff (08.01.10.1) Log created at 10:21 on 15/06/2010 (robert.p.powell) Firefox version [Unable to determine] ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "[removed]"="C:\Program Files\ManageSoft\Usage Agent\mgsusageagent\" [15:07 23/10/2009] "{20a82645-c095-46ed-80e3-08825760534b}"="C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [23:18 24/10/2009] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [05:53 18/12/2009] -=E.O.F=- ___________________________________________ TDSS Log: 10:24:03:546 7928 TDSS rootkit removing tool 2.3.2.0 May 31 2010 10:39:48 10:24:03:546 7928 ================================================================================ 10:24:03:546 7928 SystemInfo: 10:24:03:546 7928 OS Version: 5.1.2600 ServicePack: 3.0 10:24:03:546 7928 Product type: Workstation 10:24:03:546 7928 ComputerName: ACN7440R8DZFV4 10:24:03:546 7928 UserName: robert.p.powell 10:24:03:546 7928 Windows directory: C:\WINDOWS 10:24:03:546 7928 Processor architecture: Intel x86 10:24:03:546 7928 Number of processors: 2 10:24:03:546 7928 Page size: 0x1000 10:24:03:546 7928 Boot type: Normal boot 10:24:03:546 7928 ================================================================================ 10:24:03:765 7928 Initialize success 10:24:03:765 7928 10:24:03:765 7928 Scanning Services … 10:24:03:890 7928 Raw services enum returned 430 services 10:24:03:921 7928 10:24:03:921 7928 Scanning Drivers … 10:24:03:968 7928 10:24:03:968 7928 Completed 10:24:03:968 7928 10:24:03:968 7928 Results: 10:24:03:984 7928 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 10:24:03:984 7928 File objects infected / cured / cured on reboot: 0 / 0 / 0 10:24:03:984 7928 10:24:03:984 7928 KLMD(ARK) unloaded successfully ____________________________________________________
We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
1. cleared Java cache.
2. Ran ATF Cleaner.
3 reboot
4 install malwarebyte antimalware
5. perform quick scan

6. 3 times scan stuck on C:\Program Files\Microsoft ActiveSync\wcescomm.exe

first 2, i had to do a hard stop and restart. third time I got the blue screen of death.


—– result Malwarebytes scan NOT PERFORMED yet.

ideas?



my computer appears to be running ok. google has nt redirected me in about 40 searches and clicks.
this evening, i tried to google that wcescomm.exe just for something to test. three links in a row were redirected. I can see 'redirecting' right in the tab when its hapeening. should I rename that exe so I can finish the malwarebytes????
I cannot get a scan to complete with Malwarebytes. Common denominator seems to be 15 seconds. I never get past that time. I have renamed 4 files that it chokes on. the latest is ctfmon.exe in system32 folder. i rename it, it creates a new exe. SO I am stuck here………… is there a different scanner or something else I can try??????? THX ROB
Don't rename any of your Windows programs like ctfmon.exe. Those are critical operating files.



Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.If Vista or Windows 7, skip the Recovery Console part
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
i corrected all the renamed files. I have NOT done any of the above yet. last night EVERY search is redirecting. and now I cannot even go back to google. the redirect overpowers the back button. and it happens on EVERY SEARCH. I was able to run the malwarebytes in safe mode; here is the log. Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4201 Windows 5.1.2600 Service Pack 3 (Safe Mode) Internet Explorer 7.0.5730.13 6/16/2010 10:00:56 AM mbam-log-2010-06-16 (10-00-56).txt Scan type: Quick scan Objects scanned: 152618 Time elapsed: 13 minute(s), 54 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 1 Registry Data Items Infected: 3 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\total pc defender (Rogue.TotalPCDefender) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ____________________________________________________ do I now pick up with the above post???
i ran combofix. it asked if i wanted to update it I CHOSE NO ???

anyway, here is the log:

ComboFix 10-06-16.02 - robert.p.powell 06/17/2010 21:03:20.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3016.2204 [GMT -6:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: ISS Proventia [removed] *enabled* {1B42F604-2FE3-485B-BA3D-B55276659D1F}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\winsusrm.dll
c:\windows\system32\winsusrx.dll

.
((((((((((((((((((((((((( Files Created from 2010-05-18 to 2010-06-18 )))))))))))))))))))))))))))))))
.

2010-06-16 21:17 . 2010-06-16 21:17 ——– d—–w- c:\program files\Trend Micro
2010-06-16 15:25 . 2010-06-16 15:25 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\SUPERAntiSpyware.com
2010-06-16 15:25 . 2010-06-16 15:25 ——– d—–w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-16 13:51 . 2010-03-05 14:37 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-15 22:08 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-15 22:08 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-15 21:05 . 2010-06-15 21:05 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\Malwarebytes
2010-06-15 21:04 . 2010-06-16 13:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 21:04 . 2010-06-15 21:04 ——– d—–w- d:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-13 21:48 . 2010-06-13 21:48 80896 —-a-w- c:\windows\system32\abdc.sys
2010-06-08 14:59 . 2010-06-08 14:59 ——– d—–w- c:\program files\examotion

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-18 03:12 . 2006-09-14 04:54 ——– d—–w- c:\program files\Symantec AntiVirus
2010-06-16 19:10 . 2008-10-29 11:25 ——– d—–w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-16 14:19 . 2009-10-23 15:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-06-04 16:43 . 2006-09-14 04:38 ——– d—–w- c:\program files\Firm Applications
2010-05-14 22:21 . 2010-02-17 14:42 373800 —-a-w- d:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-05-09 13:55 . 2009-10-22 21:39 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\Accenture
2010-05-04 17:20 . 2006-09-12 22:49 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2006-09-12 22:50 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2006-09-12 22:49 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-03 23:38 . 2009-10-21 09:10 60368 —-a-w- d:\documents and settings\robert.p.powell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-11 21:10 . 2010-04-11 21:10 86016 —-a-w- d:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe
2008-07-18 16:48 . 2009-10-21 09:17 45056 —-a-w- c:\program files\Common Files\Period20.dll
2008-07-18 16:48 . 2009-10-21 09:17 24576 —-a-w- c:\program files\Common Files\Artes32X.dll
2008-07-18 16:48 . 2009-10-21 09:17 24576 —-a-w- c:\program files\Common Files\ACTripsLog.dll
2006-09-12 22:21 . 2006-09-13 22:47 319 —-a-w- c:\program files\VersionMarker.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MPlayer"="c:\windows\system32\MPlayer.vbs" [2009-03-26 4035]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2009-11-12 20480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-31 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-31 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-31 150040]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-05-09 360448]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
"AMDD"="c:\program files\Accenture\AMDD\AMDD.exe" [2010-03-11 115200]
"Communicator"="c:\program files\Microsoft Office Communicator\communicator.exe" [2009-10-21 5073744]
"Accenture Connection"="c:\program files\Accenture Connection\9341989\Program\Accenture Connection.exe" [2009-10-23 28711]
"Pointsec Tray"="c:\program files\Pointsec\Pointsec for PC\P95Tray.exe" [2008-04-12 666176]
"SchedulingAgent_nDG"="c:\program files\ManageSoft\Schedule Agent\ndschedag.exe" [2009-08-08 1439040]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 29696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-19 2221352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-18 149280]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

d:\documents and settings\robert.p.powell\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-2-18 385024]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Accenture Connection.lnk - c:\program files\Accenture Connection\9341989\Program\Accenture Connection.exe [2009-10-23 28711]
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2008-8-18 604776]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-10-21 50688]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-11-12 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2009-11-12 581632]
Proventia Desktop Agent.lnk - c:\program files\ISS\Proventia Desktop\blackice.exe [2009-10-21 2179072]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 09:07 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-08-08 11:44 28672 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2005-09-01 03:27 1658592 —-a-w- c:\program files\Messenger\Msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Accenture Connection\\9341989\\Program\\Accenture Connection.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 prot_2k;prot_2k;c:\windows\system32\drivers\prot_2k.sys [4/12/2008 2:21 PM 221632]
R1 abdc;abdc;c:\windows\system32\abdc.sys [6/13/2010 3:48 PM 80896]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [8/27/2009 1:18 PM 13480]
R1 SASDIFSV;SASDIFSV;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
R1 SASKUTIL;SASKUTIL;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys [?]
R2 BlackICE;BlackICE;c:\program files\ISS\Proventia Desktop\blackd.exe [10/21/2009 3:12 AM 2081034]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/15/2010 4:08 PM 304464]
R2 mgssecsvc;ManageSoft Security Service;c:\program files\ManageSoft\Security Agent\mgssecsvc.exe [8/8/2009 1:51 AM 1095168]
R2 ndGlobalLauncher;ManageSoft installation agent;c:\program files\ManageSoft\Launcher\ndserv.exe [8/8/2009 2:29 AM 2899264]
R2 ndinit;ManageSoft managed device;c:\program files\ManageSoft\Schedule Agent\ndinit.exe [8/8/2009 2:29 AM 730944]
R2 Pointsec;Pointsec;c:\windows\system32\Prot_srv.exe [4/12/2008 2:22 PM 367168]
R2 Pointsec_start;Pointsec Service Start;c:\windows\system32\pstartSr.exe [4/12/2008 2:22 PM 145984]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [10/21/2009 3:00 AM 2058776]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [8/27/2009 1:07 PM 239760]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/27/2010 4:03 PM 102448]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/15/2010 4:08 PM 20952]
R4 black;black;c:\windows\system32\drivers\Blackcat.sys [10/21/2009 3:12 AM 205938]
S2 BackWeb Plug-in - 9341989;Accenture Connection;c:\program files\Accenture Connection\9341989\Program\ServiceWrapper-9341989.exe [10/23/2009 8:44 AM 28711]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [11/6/2009 3:40 PM 114016]
S3 Cdmsvos;Cdmsvos; [x]
S3 IgniteService;IgniteService;c:\program files\IgniteCDS\IgniteService.exe [10/20/2009 1:31 PM 86016]
S3 MakoNT;MakoNT;c:\windows\system32\drivers\isskboep.sys [10/21/2009 3:12 AM 80512]
S3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [10/21/2009 3:12 AM 50163]
S3 SASENUM;SASENUM;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 9:48 PM 116664]
S3 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\ISS\Proventia Desktop\vpatch.exe [10/21/2009 3:12 AM 405770]
S4 mgsdl;ManageSoft Peer-to-Peer Download Service;c:\program files\ManageSoft\Launcher\mgsdl.exe [8/8/2009 1:30 AM 1401344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
2010-05-04 17:20 124928 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-06-16 c:\windows\Tasks\At1.job
- c:\program files\ACMT\ACMT.exe [2006-09-14 03:29]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = ;localhost
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: accenture.com
Trusted Zone: accenture.com
Handler: bwfile-9341989 - {358D3935-0C33-4169-9598-63FAF077328B} - c:\program files\Accenture Connection\9341989\Program\GAPlugProtocol-9341989.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0D0950E6-046D-437A-8985-369BE10C7E2A} - hxxps://iauthor.accenture.com/iAuthor/ASP/IALogOut.CAB
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxps://sync.accenture.com/projectserver/objects/pjclient.cab
DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} - hxxps://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue-enterprise.com/Customer/x86/RescueDownloader.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxps://sync.accenture.com/projectserver/objects/1033/pjcintl.cab
.
- - - - ORPHANS REMOVED - - - -

WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKLM-Run-ACSTP - e:\local\OTHER\LOCPOST62\icollect\acstp_install.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
AddRemove-Accenture Bank Branch Simulator - d:\data\Showcase_\Accenture_Learning_CDC_Showcase\thinkingworld\Accenture Bank Branch Simulator\uninstaller.exe
AddRemove-KB913433 - c:\windows\system32\MacroMed\Flash\genuinst.exe
AddRemove-WZCLINE - c:\program files\WinZip\winzip32
AddRemove-{54B36F04-841A-499F-A144-51EA0078A90B} - c:\program files\ManageSoft\Launcher\ndlaunch -o InstallProfile=Public -d ManageSoft cmtrack Inventory Agent Plugin



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-17 21:11
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1380)
c:\windows\system32\pssogina.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
c:\windows\system32\igfxdev.dll
c:\program files\Lenovo\HOTKEY\notifyf2.dll
.
Completion time: 2010-06-17 21:13:41
ComboFix-quarantined-files.txt 2010-06-18 03:13

Pre-Run: 32,754,094,080 bytes free
Post-Run: 32,787,701,760 bytes free

- - End Of File - - 28300C34753807AF092E94AA6FDD8668
and the redirects still happen. i rebooted. it seems lke it happens a few times then it stops for a few clicks then it comes back to every click.
Ok. I ran it agian just now and allowed the update.

Here is the log:

_________________________

ComboFix 10-06-17.02 - robert.p.powell 06/18/2010 9:24.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3016.2150 [GMT -6:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: ISS Proventia [removed] *enabled* {1B42F604-2FE3-485B-BA3D-B55276659D1F}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\win.com

.
((((((((((((((((((((((((( Files Created from 2010-05-18 to 2010-06-18 )))))))))))))))))))))))))))))))
.

2010-06-16 21:17 . 2010-06-16 21:17 ——– d—–w- c:\program files\Trend Micro
2010-06-16 15:25 . 2010-06-16 15:25 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\SUPERAntiSpyware.com
2010-06-16 15:25 . 2010-06-16 15:25 ——– d—–w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-16 13:51 . 2010-03-05 14:37 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-15 22:08 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-15 22:08 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-15 21:05 . 2010-06-15 21:05 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\Malwarebytes
2010-06-15 21:04 . 2010-06-16 13:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 21:04 . 2010-06-15 21:04 ——– d—–w- d:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-13 21:48 . 2010-06-13 21:48 80896 —-a-w- c:\windows\system32\abdc.sys
2010-06-08 14:59 . 2010-06-08 14:59 ——– d—–w- c:\program files\examotion

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-18 15:20 . 2006-09-14 04:54 ——– d—–w- c:\program files\Symantec AntiVirus
2010-06-16 19:10 . 2008-10-29 11:25 ——– d—–w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-16 14:19 . 2009-10-23 15:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-06-04 16:43 . 2006-09-14 04:38 ——– d—–w- c:\program files\Firm Applications
2010-05-14 22:21 . 2010-02-17 14:42 373800 —-a-w- d:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-05-09 13:55 . 2009-10-22 21:39 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\Accenture
2010-05-04 17:20 . 2006-09-12 22:49 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2006-09-12 22:50 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2006-09-12 22:49 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-03 23:38 . 2009-10-21 09:10 60368 —-a-w- d:\documents and settings\robert.p.powell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-07-18 16:48 . 2009-10-21 09:17 45056 —-a-w- c:\program files\Common Files\Period20.dll
2008-07-18 16:48 . 2009-10-21 09:17 24576 —-a-w- c:\program files\Common Files\Artes32X.dll
2008-07-18 16:48 . 2009-10-21 09:17 24576 —-a-w- c:\program files\Common Files\ACTripsLog.dll
2006-09-12 22:21 . 2006-09-13 22:47 319 —-a-w- c:\program files\VersionMarker.dat
.

((((((((((((((((((((((((((((( SnapShot@2010-06-18_03.11.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-18 14:50 . 2010-06-18 14:50 16384 c:\windows\Temp\Perflib_Perfdata_158.dat
+ 2006-09-12 22:50 . 2010-06-18 14:54 85666 c:\windows\system32\perfc009.dat
- 2006-09-12 22:50 . 2010-06-17 23:56 85666 c:\windows\system32\perfc009.dat
+ 2006-09-12 22:50 . 2010-06-18 14:54 479392 c:\windows\system32\perfh009.dat
- 2006-09-12 22:50 . 2010-06-17 23:56 479392 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MPlayer"="c:\windows\system32\MPlayer.vbs" [2009-03-26 4035]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2009-11-12 20480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-31 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-31 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-31 150040]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-05-09 360448]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
"AMDD"="c:\program files\Accenture\AMDD\AMDD.exe" [2010-03-11 115200]
"Communicator"="c:\program files\Microsoft Office Communicator\communicator.exe" [2009-10-21 5073744]
"Accenture Connection"="c:\program files\Accenture Connection\9341989\Program\Accenture Connection.exe" [2009-10-23 28711]
"Pointsec Tray"="c:\program files\Pointsec\Pointsec for PC\P95Tray.exe" [2008-04-12 666176]
"SchedulingAgent_nDG"="c:\program files\ManageSoft\Schedule Agent\ndschedag.exe" [2009-08-08 1439040]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 29696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-19 2221352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-18 149280]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

d:\documents and settings\robert.p.powell\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-2-18 385024]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Accenture Connection.lnk - c:\program files\Accenture Connection\9341989\Program\Accenture Connection.exe [2009-10-23 28711]
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2008-8-18 604776]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-10-21 50688]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-11-12 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2009-11-12 581632]
Proventia Desktop Agent.lnk - c:\program files\ISS\Proventia Desktop\blackice.exe [2009-10-21 2179072]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 09:07 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-08-08 11:44 28672 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2005-09-01 03:27 1658592 —-a-w- c:\program files\Messenger\Msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Accenture Connection\\9341989\\Program\\Accenture Connection.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 prot_2k;prot_2k;c:\windows\system32\drivers\prot_2k.sys [4/12/2008 2:21 PM 221632]
R1 abdc;abdc;c:\windows\system32\abdc.sys [6/13/2010 3:48 PM 80896]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [8/27/2009 1:18 PM 13480]
R2 BlackICE;BlackICE;c:\program files\ISS\Proventia Desktop\blackd.exe [10/21/2009 3:12 AM 2081034]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/15/2010 4:08 PM 304464]
R2 mgssecsvc;ManageSoft Security Service;c:\program files\ManageSoft\Security Agent\mgssecsvc.exe [8/8/2009 1:51 AM 1095168]
R2 ndGlobalLauncher;ManageSoft installation agent;c:\program files\ManageSoft\Launcher\ndserv.exe [8/8/2009 2:29 AM 2899264]
R2 ndinit;ManageSoft managed device;c:\program files\ManageSoft\Schedule Agent\ndinit.exe [8/8/2009 2:29 AM 730944]
R2 Pointsec;Pointsec;c:\windows\system32\Prot_srv.exe [4/12/2008 2:22 PM 367168]
R2 Pointsec_start;Pointsec Service Start;c:\windows\system32\pstartSr.exe [4/12/2008 2:22 PM 145984]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [10/21/2009 3:00 AM 2058776]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [8/27/2009 1:07 PM 239760]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/27/2010 4:03 PM 102448]
R3 MakoNT;MakoNT;c:\windows\system32\drivers\isskboep.sys [10/21/2009 3:12 AM 80512]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/15/2010 4:08 PM 20952]
R3 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\ISS\Proventia Desktop\vpatch.exe [10/21/2009 3:12 AM 405770]
R4 black;black;c:\windows\system32\drivers\Blackcat.sys [10/21/2009 3:12 AM 205938]
S1 SASDIFSV;SASDIFSV;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys [?]
S2 BackWeb Plug-in - 9341989;Accenture Connection;c:\program files\Accenture Connection\9341989\Program\ServiceWrapper-9341989.exe [10/23/2009 8:44 AM 28711]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [11/6/2009 3:40 PM 114016]
S3 Cdmsvos;Cdmsvos; [x]
S3 IgniteService;IgniteService;c:\program files\IgniteCDS\IgniteService.exe [10/20/2009 1:31 PM 86016]
S3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [10/21/2009 3:12 AM 50163]
S3 SASENUM;SASENUM;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 9:48 PM 116664]
S4 mgsdl;ManageSoft Peer-to-Peer Download Service;c:\program files\ManageSoft\Launcher\mgsdl.exe [8/8/2009 1:30 AM 1401344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
2010-05-04 17:20 124928 —-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-06-16 c:\windows\Tasks\At1.job
- c:\program files\ACMT\ACMT.exe [2006-09-14 03:29]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = ;localhost
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: accenture.com
Trusted Zone: accenture.com
Handler: bwfile-9341989 - {358D3935-0C33-4169-9598-63FAF077328B} - c:\program files\Accenture Connection\9341989\Program\GAPlugProtocol-9341989.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0D0950E6-046D-437A-8985-369BE10C7E2A} - hxxps://iauthor.accenture.com/iAuthor/ASP/IALogOut.CAB
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxps://sync.accenture.com/projectserver/objects/pjclient.cab
DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} - hxxps://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue-enterprise.com/Customer/x86/RescueDownloader.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxps://sync.accenture.com/projectserver/objects/1033/pjcintl.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-18 09:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1380)
c:\windows\system32\pssogina.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll
.
Completion time: 2010-06-18 09:33:30
ComboFix-quarantined-files.txt 2010-06-18 15:33
ComboFix2.txt 2010-06-18 03:13

Pre-Run: 32,809,689,088 bytes free
Post-Run: 32,770,359,296 bytes free

- - End Of File - - 95BBA1A80F947E729B5AC4561778E874

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI