This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

More Google Redirects

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

sorry i missed your post earlier. i have just got home and fired up the machine. redirects are still happenning. yahoo and bing redirct my clicks as well as google.
Resetting Router

Let’s try to reset the router to its default configuration.
  • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
  • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • If you don’t know the router's default password, you can look it up. HERE
  • You also need to reconfigure any security settings you had in place prior to the reset.
  • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.

Note: After resetting your router, it is important to set a non-default password, and if possible, username, on the router. This will assist in eliminating the possibility of the router being hijacked again.
i have another question before I do that…….. earlier today i was at the office. that is where I ran ComboFix and all the stuff yesterday. and that would have nothing to do with my home router. does that make any difference?? and can i use the control panel to reset the router to default settings or should I do it via the hardware as you say above? Thanks, Rob

i have another question before I do that……..


earlier today i was at the office. that is where I ran ComboFix and all the stuff yesterday. and that would have nothing to do with my home router.

does that make any difference??


and can i use the control panel to reset the router to default settings or should I do it via the hardware as you say above?

Thanks,
Rob

If you were being redirected at the office and not connected to your router at home, than your router could be OK.



Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

c:\windows\system32\abdc.sys


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If virscan.org is too busy you can try these.

http://virscan.org/

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html

i dont have that file so it responds with "File is empty (0 bytes)!"

It shows in your combofix scan.
2010-06-13 21:48 . 2010-06-13 21:48 80896 —-a-w- c:\windows\system32\abdc.sys
R1 abdc;abdc;c:\windows\system32\abdc.sys [6/13/2010 3:48 PM 80896]

Let me go through the CF scan and I'll post back.
I DO HAVE THE FILE. I was in system andbnot system32 when i posted. sorry about that. I do have it and I am trying to scan it but it STILL says ZERO BYTES.
i also just tried the kipersky link and it wont run either. kipersky did nothing as well.
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/More_Google_Redirects_t112617.html
Collect::
c:\windows\system32\abdc.sys

File::
c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS 
d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys
d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS
c:\windows\Tasks\At1.job

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Here is the ComboFix log:

ComboFix 10-06-17.03 - robert.p.powell 06/18/2010 18:27:52.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3016.2152 [GMT -6:00]
Running from: d:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: d:\documents and settings\robert.p.powell\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C}
FW: ISS Proventia 9.0.226.0 *enabled* {1B42F604-2FE3-485B-BA3D-B55276659D1F}

FILE ::
"c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe"
"c:\windows\Tasks\At1.job"
"d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS"
"d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS"
"d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys"

file zipped: c:\windows\system32\abdc.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
c:\windows\system32\abdc.sys
c:\windows\Tasks\At1.job

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_abdc
——-\Service_abdc


((((((((((((((((((((((((( Files Created from 2010-05-19 to 2010-06-19 )))))))))))))))))))))))))))))))
.

2010-06-16 21:17 . 2010-06-16 21:17 ——– d—–w- c:\program files\Trend Micro
2010-06-16 15:25 . 2010-06-16 15:25 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\SUPERAntiSpyware.com
2010-06-16 15:25 . 2010-06-16 15:25 ——– d—–w- d:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-16 13:51 . 2010-03-05 14:37 65536 ——w- c:\windows\system32\dllcache\asycfilt.dll
2010-06-15 22:08 . 2010-04-29 21:39 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-15 22:08 . 2010-04-29 21:39 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-06-15 21:05 . 2010-06-15 21:05 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\Malwarebytes
2010-06-15 21:04 . 2010-06-16 13:56 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 21:04 . 2010-06-15 21:04 ——– d—–w- d:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-08 14:59 . 2010-06-08 14:59 ——– d—–w- c:\program files\examotion

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-19 00:37 . 2006-09-14 04:54 ——– d—–w- c:\program files\Symantec AntiVirus
2010-06-16 19:10 . 2008-10-29 11:25 ——– d—–w- d:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-16 14:19 . 2009-10-23 15:18 ——– d—–w- c:\program files\Microsoft ActiveSync
2010-06-04 16:43 . 2006-09-14 04:38 ——– d—–w- c:\program files\Firm Applications
2010-05-14 22:21 . 2010-02-17 14:42 373800 —-a-w- d:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-05-09 13:55 . 2009-10-22 21:39 ——– d—–w- d:\documents and settings\robert.p.powell\Application Data\Accenture
2010-05-04 17:20 . 2006-09-12 22:49 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2006-09-12 22:50 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2006-09-12 22:49 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-03 23:38 . 2009-10-21 09:10 60368 —-a-w- d:\documents and settings\robert.p.powell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-07-18 16:48 . 2009-10-21 09:17 45056 —-a-w- c:\program files\Common Files\Period20.dll
2008-07-18 16:48 . 2009-10-21 09:17 24576 —-a-w- c:\program files\Common Files\Artes32X.dll
2008-07-18 16:48 . 2009-10-21 09:17 24576 —-a-w- c:\program files\Common Files\ACTripsLog.dll
2006-09-12 22:21 . 2006-09-13 22:47 319 —-a-w- c:\program files\VersionMarker.dat
.

((((((((((((((((((((((((((((( SnapShot@2010-06-18_03.11.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-06-19 00:37 . 2010-06-19 00:37 16384 c:\windows\Temp\Perflib_Perfdata_1cc.dat
+ 2006-09-12 22:50 . 2010-06-18 23:32 85666 c:\windows\system32\perfc009.dat
- 2006-09-12 22:50 . 2010-06-17 23:56 85666 c:\windows\system32\perfc009.dat
+ 2006-09-12 23:18 . 2010-06-18 18:31 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-09-12 23:18 . 2010-06-17 18:14 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2006-09-12 23:18 . 2010-06-17 18:14 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2006-09-12 23:18 . 2010-06-18 18:31 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2006-09-12 23:18 . 2010-06-17 18:14 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-06-18 18:31 . 2010-06-18 18:31 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2006-09-12 22:50 . 2010-06-18 23:32 479392 c:\windows\system32\perfh009.dat
- 2006-09-12 22:50 . 2010-06-17 23:56 479392 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MPlayer"="c:\windows\system32\MPlayer.vbs" [2009-03-26 4035]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-10-31 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-10-31 178712]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-10-31 150040]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-05-09 360448]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-03 1323008]
"TPHOTKEY"="c:\program files\Lenovo\HOTKEY\TPOSDSVC.exe" [2008-09-30 68976]
"AMDD"="c:\program files\Accenture\AMDD\AMDD.exe" [2010-03-11 115200]
"Communicator"="c:\program files\Microsoft Office Communicator\communicator.exe" [2009-10-21 5073744]
"Accenture Connection"="c:\program files\Accenture Connection\9341989\Program\Accenture Connection.exe" [2009-10-23 28711]
"Pointsec Tray"="c:\program files\Pointsec\Pointsec for PC\P95Tray.exe" [2008-04-12 666176]
"SchedulingAgent_nDG"="c:\program files\ManageSoft\Schedule Agent\ndschedag.exe" [2009-08-08 1439040]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 29696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-19 2221352]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-18 149280]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2006-06-13 127036]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2010-04-29 437584]

d:\documents and settings\robert.p.powell\Start Menu\Programs\Startup\
Picture Motion Browser Media Check Tool.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2010-2-18 385024]

d:\documents and settings\All Users\Start Menu\Programs\Startup\
Accenture Connection.lnk - c:\program files\Accenture Connection\9341989\Program\Accenture Connection.exe [2009-10-23 28711]
Bluetooth.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2008-8-18 604776]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2009-10-21 50688]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-11-12 450560]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2009-11-12 581632]
Proventia Desktop Agent.lnk - c:\program files\ISS\Proventia Desktop\blackice.exe [2009-10-21 2179072]
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"LogonType"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2006-09-06 09:07 34344 —-a-w- c:\program files\Lenovo\HOTKEY\notifyf2.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2008-08-08 11:44 28672 —-a-w- c:\program files\Lenovo\HOTKEY\tphklock.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2005-09-01 03:27 1658592 —-a-w- c:\program files\Messenger\Msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Accenture Connection\\9341989\\Program\\Accenture Connection.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Microsoft Office Communicator\\communicator.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

R0 prot_2k;prot_2k;c:\windows\system32\drivers\prot_2k.sys [4/12/2008 2:21 PM 221632]
R1 lenovo.smi;Lenovo System Interface Driver;c:\windows\system32\drivers\smiif32.sys [8/27/2009 1:18 PM 13480]
R2 BackWeb Plug-in - 9341989;Accenture Connection;c:\program files\Accenture Connection\9341989\Program\ServiceWrapper-9341989.exe [10/23/2009 8:44 AM 28711]
R2 BlackICE;BlackICE;c:\program files\ISS\Proventia Desktop\blackd.exe [10/21/2009 3:12 AM 2081034]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [6/15/2010 4:08 PM 304464]
R2 mgssecsvc;ManageSoft Security Service;c:\program files\ManageSoft\Security Agent\mgssecsvc.exe [8/8/2009 1:51 AM 1095168]
R2 ndGlobalLauncher;ManageSoft installation agent;c:\program files\ManageSoft\Launcher\ndserv.exe [8/8/2009 2:29 AM 2899264]
R2 ndinit;ManageSoft managed device;c:\program files\ManageSoft\Schedule Agent\ndinit.exe [8/8/2009 2:29 AM 730944]
R2 Pointsec;Pointsec;c:\windows\system32\Prot_srv.exe [4/12/2008 2:22 PM 367168]
R2 Pointsec_start;Pointsec Service Start;c:\windows\system32\pstartSr.exe [4/12/2008 2:22 PM 145984]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [10/21/2009 3:00 AM 2058776]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y5132.sys [8/27/2009 1:07 PM 239760]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [5/27/2010 4:03 PM 102448]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [6/15/2010 4:08 PM 20952]
R4 black;black;c:\windows\system32\drivers\Blackcat.sys [10/21/2009 3:12 AM 205938]
S1 SASDIFSV;SASDIFSV;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.sys [?]
S2 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\drivers\ipsecw2k.sys [11/6/2009 3:40 PM 114016]
S3 Cdmsvos;Cdmsvos; [x]
S3 IgniteService;IgniteService;c:\program files\IgniteCDS\IgniteService.exe [10/20/2009 1:31 PM 86016]
S3 MakoNT;MakoNT;c:\windows\system32\drivers\isskboep.sys [10/21/2009 3:12 AM 80512]
S3 rap;rap;c:\windows\system32\drivers\RapDrv.sys [10/21/2009 3:12 AM 50163]
S3 SASENUM;SASENUM;\??\d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS –> d:\docume~1\ROBERT~1.POW\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]
S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 9:48 PM 116664]
S3 VPatch;ISS Buffer Overflow Exploit Prevention;c:\program files\ISS\Proventia Desktop\vpatch.exe [10/21/2009 3:12 AM 405770]
S4 mgsdl;ManageSoft Peer-to-Peer Download Service;c:\program files\ManageSoft\Launcher\mgsdl.exe [8/8/2009 1:30 AM 1401344]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{EEBF9CA6-567B-41cd-B5F6-EF2C7FEF37B5}]
2010-05-04 17:20 124928 —-a-w- c:\windows\system32\advpack.dll
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = ;localhost
IE: {{c95fe080-8f5d-11d2-a20b-00aa003c157a}
Trusted Zone: accenture.com
Trusted Zone: accenture.com
Handler: bwfile-9341989 - {358D3935-0C33-4169-9598-63FAF077328B} - c:\program files\Accenture Connection\9341989\Program\GAPlugProtocol-9341989.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {0D0950E6-046D-437A-8985-369BE10C7E2A} - hxxps://iauthor.accenture.com/iAuthor/ASP/IALogOut.CAB
DPF: {4A3CBDDD-C4DC-4C38-B44F-704DAEF628AE} - hxxps://sync.accenture.com/projectserver/objects/pjclient.cab
DPF: {61CE1CA1-6577-49B6-AE2C-43007A942429} - hxxps://webcast.accenture.com/v2/WebcastLog/WebcastInfo.CAB
DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} - hxxps://secure.logmeinrescue-enterprise.com/Customer/x86/RescueDownloader.cab
DPF: {AF9A1421-E128-4D5F-A37E-039F305867B9} - hxxps://sync.accenture.com/projectserver/objects/1033/pjcintl.cab
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-18 18:38
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(1372)
c:\windows\system32\pssogina.dll
c:\program files\Lenovo\HOTKEY\tphklock.dll

- - - - - - - > 'explorer.exe'(5468)
c:\windows\system32\WININET.dll
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\btmmhook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Juniper Networks\Common Files\dsNcService.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Nero\Nero8\Nero BackItUp\NBService.exe
c:\program files\ManageSoft\Schedule Agent\ndtask.exe
c:\windows\system32\IoctlSvc.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\SearchIndexer.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\program files\iPass\iPassConnect\iPassPeriodicUpdateApp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\Synaptics\SynTP\SynTPLpr.exe
c:\program files\Lenovo\HOTKEY\TPONSCR.exe
c:\program files\Lenovo\Zoom\TpScrex.exe
c:\program files\ManageSoft\Schedule Agent\ndtask.exe
c:\program files\Microsoft ActiveSync\wcescomm.exe
c:\progra~1\MICROS~4\rapimgr.exe
c:\program files\Logitech\SetPoint\KHALMNPR.EXE
c:\progra~1\ThinkPad\BLUETO~1\BTSTAC~1.EXE
.
**************************************************************************
.
Completion time: 2010-06-18 18:42:28 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-19 00:42
ComboFix2.txt 2010-06-18 15:33
ComboFix3.txt 2010-06-18 03:13

Pre-Run: 32,796,790,784 bytes free
Post-Run: 32,630,558,720 bytes free

- - End Of File - - 7483AFE15A2DE04AEEE6675BC39C210E
i have tried numerous links. closed the browser then reopen. tried a bunch of google then yahoo. not one redirect. can i try reboot??

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI