This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Redirect

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks again for your help. There was no reboot on this one; I'll take that as a good sign. ComboFix 10-06-22.03 - Jeffrey Jones 06/23/2010 9:36.3.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.501 [GMT -5:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83} FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . —- Previous Run ——- . c:\windows\system32\ebec.sys . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . ——-\Legacy_ebec ——-\Service_ebec ((((((((((((((((((((((((( Files Created from 2010-05-23 to 2010-06-23 ))))))))))))))))))))))))))))))) . 2010-06-22 20:05 . 2010-06-22 20:05 ——– d—–w- c:\program files\iPod 2010-06-22 20:04 . 2010-06-22 20:06 ——– d—–w- c:\program files\iTunes 2010-06-22 19:58 . 2010-06-22 19:58 ——– d—–w- c:\windows\LastGood 2010-06-22 19:56 . 2010-06-22 19:56 ——– d—–w- c:\program files\Bonjour 2010-06-22 19:50 . 2010-06-22 19:50 72504 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe 2010-06-21 21:34 . 2010-06-21 21:34 ——– d—–w- c:\program files\Alwil Software 2010-06-21 21:34 . 2010-06-21 21:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software 2010-06-15 19:16 . 2010-06-15 19:16 63488 ——w- c:\documents and settings\Jeffrey Jones\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll 2010-06-15 19:16 . 2010-06-15 19:16 52224 ——w- c:\documents and settings\Jeffrey Jones\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-06-15 19:16 . 2010-06-15 19:16 117760 ——w- c:\documents and settings\Jeffrey Jones\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-06-15 19:16 . 2010-06-15 19:16 ——– d—–w- c:\documents and settings\Jeffrey Jones\Application Data\SUPERAntiSpyware.com 2010-06-10 14:18 . 2010-05-06 10:41 743424 ——w- c:\windows\system32\dllcache\iedvtool.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-06-23 13:06 . 2006-11-12 06:15 3216 —-a-w- c:\windows\system32\encobject.dat 2010-06-22 20:05 . 2007-07-17 03:14 ——– d—–w- c:\program files\Common Files\Apple 2010-06-21 02:10 . 2009-01-11 17:11 5427 —-a-w- c:\windows\system32\EGATHDRV.SYS 2010-06-15 16:22 . 2007-02-18 14:09 ——– d—–w- c:\program files\Spybot - Search & Destroy 2010-06-15 15:18 . 2007-02-18 14:10 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2010-06-09 23:29 . 2007-07-25 23:31 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-06-09 23:28 . 2006-11-03 10:54 ——– d—a-w- c:\program files\Microsoft Works 2010-06-09 23:21 . 2006-11-03 10:27 ——– d—a-w- c:\program files\Common Files\Wise Installation Wizard 2010-05-18 21:35 . 2010-05-18 21:35 91424 —-a-w- c:\windows\system32\dnssd.dll 2010-05-18 21:35 . 2010-05-18 21:35 107808 —-a-w- c:\windows\system32\dns-sd.exe 2010-05-06 10:41 . 2006-04-30 06:56 916480 ——w- c:\windows\system32\wininet.dll 2010-05-02 05:22 . 2006-04-30 06:55 1851264 ——w- c:\windows\system32\win32k.sys 2010-04-26 16:44 . 2009-03-12 13:42 ——– d—–w- c:\program files\McAfee.com 2010-04-26 16:44 . 2009-03-12 13:42 ——– d—–w- c:\program files\McAfee 2010-04-26 16:44 . 2009-03-05 14:53 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee 2010-04-20 05:30 . 2006-04-30 06:55 285696 ——w- c:\windows\system32\atmfd.dll 2009-12-31 01:07 . 2009-12-31 01:07 0 ——w- c:\program files\error.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-23 663552] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-03-17 47392] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 279912] "VX6000"="c:\windows\vVX6000.exe" [2007-04-10 996712] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-03-31 1179952] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ACNotify] [BU] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AwayNotify] 2006-08-16 17:07 49152 ——w- c:\program files\Lenovo\AwayTask\AwayNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\NavLogon] [BU] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus] 2006-04-26 03:20 40448 ——w- c:\windows\system32\psqlpwd.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2] 2005-07-05 14:45 28672 ——w- c:\windows\system32\notifyf2.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey] 2005-11-30 11:16 24576 ——w- c:\windows\system32\tphklock.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Notification Packages REG_MULTI_SZ scecli psqlpwd [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk backup=c:\windows\pss\Bluetooth.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk backup=c:\windows\pss\Service Manager.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk backup=c:\windows\pss\VPN Client.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACWLIcon] 2006-08-26 08:17 110592 ——w- c:\program files\ThinkPad\ConnectUtilities\ACWLIcon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2010-03-24 18:17 952768 ——w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] 2007-03-09 16:09 63712 ——w- c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2010-04-02 18:05 40368 ——w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AMSG] 2005-11-14 06:23 487424 ——w- c:\program files\ThinkVantage\AMSG\Amsg.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AT&T Communication Manager] 2008-02-08 19:24 33280 ——w- c:\program files\AT&T\Communication Manager\ATTCM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AwaySch] 2006-08-16 17:07 69632 ——w- c:\program files\Lenovo\AwayTask\AwaySch.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BLOG] 2006-05-25 16:13 208896 ——w- c:\progra~1\ThinkPad\UTILIT~1\BATLOGEX.DLL [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cssauth] 2006-07-15 02:13 2341632 ——w- c:\program files\Lenovo\Client Security Solution\cssauth.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-04-14 00:12 15360 ——w- c:\windows\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray] 2006-05-19 00:24 196696 ——w- c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA] 2006-02-02 13:20 122940 ——w- c:\windows\system32\DLA\DLACTRLW.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eFax 4.2] 2006-07-14 20:36 107008 ——w- c:\program files\eFax Messenger 4.2\J2GDllCmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EZEJMNAP] 2006-02-23 17:22 237568 ——w- c:\progra~1\ThinkPad\UTILIT~1\EZEJMNAP.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update] 2007-10-15 02:17 49152 ——w- c:\program files\HP\HP Software Update\hpwuSchd2.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpqSRMon] 2007-08-22 21:31 80896 ——w- c:\program files\HP\Digital Imaging\bin\HpqSRmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd] 2006-07-25 06:17 77824 ——w- c:\windows\system32\hkcmd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers] 2006-07-25 06:21 118784 ——w- c:\windows\system32\igfxpers.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray] 2006-07-25 06:21 94208 ——w- c:\windows\system32\igfxtray.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch] 2007-01-30 02:10 46632 ——w- c:\program files\ScanSoft\PaperPort\IndexSearch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup] 2004-07-28 00:50 221184 ——w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler] 2005-02-16 21:15 81920 ——w- c:\program files\Common Files\Installshield\UpdateService\issch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2010-06-15 21:33 141624 —-a-w- c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager] 2007-07-25 22:02 563984 ——w- c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon] 2007-07-25 22:06 2027792 ——w- c:\program files\Logitech\QuickCam\Quickcam.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LPManager] 2006-07-04 16:11 110592 ——w- c:\progra~1\THINKV~2\PrdCtr\LPMGR.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD] 2007-01-30 02:12 30248 ——w- c:\program files\ScanSoft\PaperPort\pptd40nt.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDService.exe] 2006-03-14 00:38 41472 ——r- c:\program files\Lenovo\SafeGuard PrivateDisk\pdservice.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRMGRTR] 2006-05-25 16:13 151552 ——w- c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2010-03-18 02:53 421888 ——w- c:\program files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX] 2005-05-06 23:06 716800 ——w- c:\program files\Analog Devices\SoundMAX\SMax4.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP] 2005-05-20 00:11 925696 ——w- c:\program files\Analog Devices\Core\smax4pnp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate] 2006-10-25 14:03 210472 ——w- c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2008-02-22 09:25 144784 ——w- c:\program files\Java\jre1.6.0_05\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2006-02-14 05:16 512000 ——w- c:\program files\Synaptics\SynTP\SynTPEnh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr] 2006-02-14 05:17 110592 ——w- c:\program files\Synaptics\SynTP\SynTPLpr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TP4EX] 2005-10-17 09:11 65536 ——w- c:\windows\system32\TP4EX.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPHOTKEY] 2006-07-25 01:19 94208 ——w- c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPKMAPHELPER] 2006-06-03 06:00 856064 ——w- c:\program files\ThinkPad\Utilities\TpKmapAp.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TpShocks] 2006-03-16 03:04 106496 ——w- c:\windows\system32\TpShocks.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TVT Scheduler Proxy] 2006-07-15 02:05 503808 ——w- c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG] 2006-10-19 02:05 204288 ——w- c:\program files\Windows Media Player\wmpnscfg.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Brother\\Brmfl07a\\FAXRX.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "54925:UDP"= 54925:UDP:Brother Network Scanner "5353:UDP"= 5353:UDP:Bonjour R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/14/2010 7:35 PM 82952] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [3/12/2009 8:46 AM 93320] R2 McMPFSvc;McAfee Personal Firewall;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/14/2010 7:34 PM 271480] R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/14/2010 7:34 PM 271480] R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/14/2010 7:35 PM 188136] R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/14/2010 7:35 PM 141792] R2 PrivateDisk;PrivateDisk;c:\program files\Lenovo\SafeGuard PrivateDisk\privatediskm.sys [3/13/2006 7:05 PM 58368] R2 smi2;smi2;c:\program files\SMI2\smi2.sys [7/14/2006 6:55 PM 3968] R2 smihlp;SMI helper driver;c:\program files\ThinkVantage Fingerprint Software\smihlp.sys [4/25/2006 10:00 PM 3456] R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [12/22/2007 4:16 PM 24652] R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/14/2010 7:35 PM 55456] R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/14/2010 7:35 PM 312584] R3 mfendiskmp;mfendiskmp;c:\windows\system32\drivers\mfendisk.sys [4/14/2010 7:35 PM 88480] S3 ATTRcAppSvc;AT&T RcAppSvc;c:\program files\AT&T\Communication Manager\RcAppSvc.exe [12/21/2007 10:42 AM 113176] S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/14/2010 7:35 PM 88480] S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/14/2010 7:35 PM 83496] S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [1/20/2010 12:15 AM 2385896] — Other Services/Drivers In Memory — *NewlyCreated* - BONJOUR_SERVICE *NewlyCreated* - IPOD_SERVICE *Deregistered* - mfeavfk01 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc . Contents of the 'Scheduled Tasks' folder 2010-06-22 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:34] 2009-12-31 c:\windows\Tasks\PMTask.job - c:\progra~1\ThinkPad\UTILIT~1\PWMIDTSK.EXE [2006-11-03 16:13] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.yahoo.com/ uInternet Connection Wizard,ShellNext = hxxp://consumer.diskeeper.com/purchase/purchase.asp?RID=943&APID=PPS0001039&PC=1&PE=2&PT=5&MajorVer=9&MinorVer=0&PBN=541&PMBN=0&LCID=1033 uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s LSP: bmnet.dll Trusted Zone: internet Trusted Zone: mcafee.com TCP: {FA86CE8D-916B-4D63-A9BC-46596BF439E0} = 172.22.4.5,192.168.1.16 . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_USERS\S-1-5-21-1656658061-583462979-3375965528-1006\Software\Microsoft\SystemCertificates\AddressBook*] @Allowed: (Read) (RestrictedCode) @Allowed: (Read) (RestrictedCode) [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe" [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" [HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters] "SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79, 00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\ . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(884) c:\windows\system32\tvt_gina.dll c:\program files\Lenovo\Client Security Solution\css_gina_plugin.dll c:\program files\Lenovo\Client Security Solution\css_wait_bar.dll c:\program files\Lenovo\Client Security Solution\cssuserdatadispatcher.dll c:\program files\Lenovo\Client Security Solution\csswait.dll c:\program files\Common Files\Lenovo\tvt_banner.dll c:\program files\Lenovo\Client Security Solution\cssdlgpwentry.dll c:\program files\Lenovo\Client Security Solution\dlganswerprompt.dll c:\program files\Lenovo\Client Security Solution\tvttsp.dll c:\program files\Lenovo\Client Security Solution\tcsrpc.dll c:\program files\Common Files\Lenovo\tvt_res.dll c:\windows\system32\bmnet.dll c:\program files\ThinkVantage Fingerprint Software\pscssint.dll c:\program files\ThinkVantage Fingerprint Software\infra.dll c:\program files\ThinkVantage Fingerprint Software\VTI.DLL c:\windows\system32\psqlpwd.dll c:\program files\ThinkVantage Fingerprint Software\homefus2.dll c:\windows\system32\biologon.dll c:\program files\ThinkVantage Fingerprint Software\homepass.dll c:\program files\ThinkVantage Fingerprint Software\bio.dll c:\program files\ThinkVantage Fingerprint Software\remote.dll c:\windows\system32\tphklock.dll c:\windows\system32\MSVCP71.dll c:\program files\Lenovo\AwayTask\AwayNotify.dll c:\windows\system32\PROCHLP.DLL c:\windows\system32\igfxdev.dll c:\windows\system32\notifyf2.dll c:\program files\ThinkVantage Fingerprint Software\crypto.dll - - - - - - - > 'lsass.exe'(964) c:\windows\system32\psqlpwd.dll c:\program files\ThinkVantage Fingerprint Software\infra.dll c:\program files\ThinkVantage Fingerprint Software\homefus2.dll c:\windows\system32\bmnet.dll - - - - - - - > 'explorer.exe'(5756) c:\windows\system32\WININET.dll c:\windows\system32\PROCHLP.DLL c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2010-06-23 09:50:44 ComboFix-quarantined-files.txt 2010-06-23 14:50 ComboFix2.txt 2010-06-22 17:46 Pre-Run: 25,094,180,864 bytes free Post-Run: 25,102,102,528 bytes free - - End Of File - - 193576A615292073FB5C063531B53544
Hi- It seems to be running much better and I'm not being redirected after a number of tests in google. You've been awesome, I very much appreciate it. I have a couple of other questions if I may (if we're done fixing the problem?) -Is there anything within the system that I need to reset (we had unchecked and checked various boxes in different menus as you searched for the problem). -What type of virus and spyware program(s) would you recommend. I currently use McAfee and it's horrible (I'm alerted constantly that my firewall is not on and I have to turn it back on). My spyware is Spybot. Thanks- Jeff

-What type of virus and spyware program(s) would you recommend. I currently use McAfee and it's horrible (I'm alerted constantly that my firewall is not on and I have to turn it back on). My spyware is Spybot.

I use Microsoft Security Essentials myself.

Is there anything within the system that I need to reset (we had unchecked and checked various boxes in different menus as you searched for the problem).

This should take care of that.

Good job :thumbup:

The following will implement some cleanup procedures as well as reset System Restore points:

  • Click START run
  • Now type ComboFix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.



To be on the safe side, I would also change all my passwords.



Here's my usual all clean post

Log looks good :D


  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
    5. Change the Download signed ActiveX controls to Prompt
    6. Change the Download unsigned ActiveX controls to Disable
    7. Change the Initialize and script ActiveX controls not marked as safe to Disable
    8. Change the Installation of desktop items to Prompt
    9. Change the Launching programs and files in an IFRAME to Prompt
    10. Change the Navigate sub-frames across different domains to Prompt
    11. When all these settings have been made, click on the OK button.
    12. If it prompts you as to whether or not you want to save the settings, press the Yes button.

  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week
    (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer.
    Without a firewall your computer is succeptible to being hacked and taken over.
    I am very serious about this and see it happen almost every day with my clients.
    Simply using a Firewall in its default configuration can lower your risk greatly.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
    This will ensure your computer has always the latest security updates available installed on your computer.
    If there are new updates to install, install them immediately, reboot your computer, and revisit the site
    until there are no more critical updates.

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly.
    Without regular updates you WILL NOT be protected when new malicious programs are released.

Only run one Anti-Virus and Firewall program.


I would suggest you read How to Prevent Malware:
This is awesome; I very much appreciate your help. I've done everything below (including switching to Microsoft Security Essentials). My computer is running like the day I got it. It makes me wonder how long I had that virus. I will be recommending your site to all of my colleagues as we are independent reps that work from our homes. Will also be donating. Thanks again for everything. Have a great day. Jeff

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI