This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Redirect

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I am having trouble with both IE and FireFox being intermitantly redirected to addresses like pursuit2u.net. I have run malwarebytes and superantispyware and removed everything that it found with no success. I have attache dthe DDS Log below. Thanks for your help! re DDS (Ver_09-06-26.01) - NTFSx86 Run by [removed] at 19:47:51.14 on Sun 07/04/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2015.1413 [GMT -7:00] ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Intuit\Entitlement Client\v3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\LogMeIn\x86\RaMaint.exe C:\Program Files\LogMeIn\x86\LogMeIn.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe C:\WINDOWS\System32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\LogMeIn\x86\LogMeInSystray.exe C:\Program Files\LogMeIn\x86\LMIGuardian.exe C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program Files\Linksys\WUSB600N\WUSB600N.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== mSearchURL = hxxp://www.Google.com/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\wirele~1.lnk - c:\program files\linksys\wusb600n\WUSB600N.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab TCP: {3E0FF98E-6ECC-4350-B4DC-8316C251E0EB} = 208.67.222.222,208.67.220.220 Handler: qbpos - {662E7FAE-5C17-491C-AD9D-98C1F66CC6A0} - c:\windows\system32\QBPOSProtocol.dll Notify: LMIinit - LMIinit.dll ================= FIREFOX =================== FF - ProfilePath - FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false); c:\program files\mozilla firefox\greprefs\all.js - pref("media.cache_size", 51200); c:\program files\mozilla firefox\greprefs\all.js - pref("media.ogg.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.wave.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("media.autoplay.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess"); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.dpi", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", "-1"); c:\program files\mozilla firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true); c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072); c:\program files\mozilla firefox\greprefs\all.js - pref("geo.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35"); // now unused c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.delay", 50); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R1 bebd;bebd;c:\windows\system32\bebd.sys [2010-5-1 74240] R2 Intuit Entitlement Service v3;Intuit Entitlement Service v3;c:\program files\common files\intuit\entitlement client\v3\server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [2008-1-30 24576] R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2010-1-27 12856] R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2010-7-3 47640] R2 QBPOSDBServiceV6;QBPOS Database Manager v6;c:\program files\intuit\quickbooks point of sale 6.0\databaseserver\QBPOSDBServiceV6.exe [2010-3-15 1479504] R2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\intuit\quickb~1\qbdbmgrn.exe -hvquickbooksdb17 –> c:\progra~1\intuit\quickb~1\QBDBMgrN.exe -hvQuickBooksDB17 [?] S0 8ee83ed6bacf0746bc28c33d75f3dda4;8ee83ed6bacf0746bc28c33d75f3dda4;c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys –> c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys [?] S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\nick\locals~1\temp\sas_selfextract\sasdifsv.sys –> c:\docume~1\nick\locals~1\temp\sas_selfextract\SASDIFSV.SYS [?] S1 SASKUTIL;SASKUTIL;\??\c:\program files\superantispyware\saskutil.sys –> c:\program files\superantispyware\SASKUTIL.sys [?] S3 DUBE100;D-Link DUB-E100 USB 2.0 to Fast Ethernet Adapter;c:\windows\system32\drivers\DUBE100.sys [2007-9-7 11935] S3 getPlusHelper;getPlus® Helper;c:\windows\system32\svchost.exe -k getPlusHelper [2003-3-31 14336] S3 rootrepeal;rootrepeal;\??\c:\windows\system32\drivers\rootrepeal.sys –> c:\windows\system32\drivers\rootrepeal.sys [?] S3 rt2870;Linksys 802.11n USB Wireless LAN Card Driver;c:\windows\system32\drivers\rt2870.sys [2007-12-14 551680] S3 SASENUM;SASENUM;\??\c:\docume~1\nick\locals~1\temp\sas_selfextract\sasenum.sys –> c:\docume~1\nick\locals~1\temp\sas_selfextract\SASENUM.SYS [?] S4 LMIRfsClientNP;LMIRfsClientNP; [x] =============== Created Last 30 ================ 2010-07-04 19:11 –d—– c:\docume~1\admini~1\applic~1\SUPERAntiSpyware.com 2010-07-04 19:09 –dsh— c:\documents and settings\administrator\IECompatCache 2010-07-04 19:08 –dsh— c:\documents and settings\administrator\PrivacIE 2010-07-04 19:03 –dsh— c:\documents and settings\administrator\IETldCache 2010-07-04 19:03 –d—– c:\documents and settings\Administrator 2010-07-04 18:17 95,024 a——- c:\windows\system32\drivers\SBREDrv.sys 2010-07-04 18:14 –d—– c:\program files\Lavasoft 2010-07-04 18:04 –d—– c:\program files\common files\PC Tools 2010-07-04 16:22 221,568 ——– c:\windows\system32\MpSigStub.exe 2010-07-04 15:31 411,368 a——- c:\windows\system32\deployJava1.dll 2010-07-04 15:31 73,728 a——- c:\windows\system32\javacpl.cpl 2010-07-04 14:40 54,156 a—h— c:\windows\QTFont.qfn 2010-07-04 14:40 1,409 a——- c:\windows\QTFont.for 2010-07-04 14:34 –d—– c:\program files\Trend Micro 2010-07-03 23:36 a-dshr– C:\cmdcons 2010-07-03 23:34 77,312 a——- c:\windows\MBR.exe 2010-07-03 23:34 256,512 a——- c:\windows\PEV.exe 2010-07-03 23:34 161,792 a——- c:\windows\SWREG.exe 2010-07-03 23:34 98,816 a——- c:\windows\sed.exe 2010-07-03 21:00 –d—– c:\docume~1\alluse~1\applic~1\LogMeIn 2010-07-03 20:59 29,568 a——- c:\windows\system32\LMIport.dll 2010-07-03 20:59 83,360 a——- c:\windows\system32\LMIRfsClientNP.dll 2010-07-03 20:59 47,640 a——- c:\windows\system32\drivers\LMIRfsDriver.sys 2010-07-03 20:59 87,424 a——- c:\windows\system32\LMIinit.dll 2010-07-03 20:59 1,024 a——- C:\.rnd 2010-07-03 20:59 –d—– c:\program files\LogMeIn 2010-06-29 10:27 –d—– c:\program files\Dell 2010-06-29 10:27 –d—– c:\windows\system32\Dell 2010-06-16 20:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-06-16 20:23 –d—– c:\windows\LMI8.tmp 2010-06-16 18:43 –d—– c:\windows\LMI2006.tmp 2010-06-16 18:20 –d—– c:\windows\LMI1EE3.tmp 2010-06-10 15:46 743,424 -c—— c:\windows\system32\dllcache\iedvtool.dll ==================== Find3M ==================== 2010-07-04 19:02 1,536 a——- c:\windows\system32\TrueSoft.dat 2010-05-06 03:41 916,480 a——- c:\windows\system32\wininet.dll 2010-05-01 22:22 1,851,264 a——- c:\windows\system32\win32k.sys 2010-05-01 10:11 74,240 ——– c:\windows\system32\bebd.sys 2010-04-19 22:30 285,696 a——- c:\windows\system32\atmfd.dll 2009-03-31 18:29 32,768 a–sh— c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009033120090401\index.dat ============= FINISH: 19:48:51.51 ===============
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.



Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step



Download TDSSKiller and save it to your Desktop.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone
please post the contents of that log TDSSKiller and GooredFix log.
After running and rebooting, the redirects are still occurring. Here are the logs: GooredFix by jpshortstuff (03.07.10.1) Log created at 07:54 on 05/07/2010 (Nick) Firefox version 3.6.6 (en-US) ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ {972ce4c6-7e08-4474-a285-3208198ce6fd} [22:38 04/07/2010] C:\Documents and Settings\Nick\Application Data\Mozilla\Firefox\Profiles\ermrq6jv.default\extensions\ {20a82645-c095-46ed-80e3-08825760534b} [23:08 04/07/2010] [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [20:57 04/09/2009] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [22:31 04/07/2010] "{3f963a5b-e555-4543-90e2-c3908898db71}"="C:\Program Files\AVG\AVG9\Firefox" [04:55 05/07/2010] "avg@igeared"="C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared" [04:57 05/07/2010] -=E.O.F=- 07:55:28:171 3980 TDSS rootkit removing tool 2.3.2.2 Jun 30 2010 17:23:49 07:55:28:171 3980 ================================================================================ 07:55:28:171 3980 SystemInfo: 07:55:28:171 3980 OS Version: 5.1.2600 ServicePack: 3.0 07:55:28:171 3980 Product type: Workstation 07:55:28:171 3980 ComputerName: VWC1 07:55:28:171 3980 UserName: Nick 07:55:28:171 3980 Windows directory: C:\WINDOWS 07:55:28:171 3980 System windows directory: C:\WINDOWS 07:55:28:171 3980 Processor architecture: Intel x86 07:55:28:171 3980 Number of processors: 1 07:55:28:171 3980 Page size: 0x1000 07:55:28:171 3980 Boot type: Normal boot 07:55:28:171 3980 ================================================================================ 07:55:28:437 3980 Initialize success 07:55:28:437 3980 07:55:28:437 3980 Scanning Services … 07:55:28:921 3980 Raw services enum returned 345 services 07:55:28:937 3980 07:55:28:937 3980 Scanning Drivers … 07:55:30:609 3980 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 07:55:30:718 3980 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 07:55:30:921 3980 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 07:55:31:046 3980 AegisP (15e655baa989444f56787ef558823643) C:\WINDOWS\system32\DRIVERS\AegisP.sys 07:55:31:187 3980 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 07:55:31:578 3980 AmdK7 (8fce268cdbdd83b23419d1f35f42c7b1) C:\WINDOWS\system32\DRIVERS\amdk7.sys 07:55:31:953 3980 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 07:55:32:062 3980 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 07:55:32:218 3980 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 07:55:32:328 3980 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 07:55:32:437 3980 AvgLdx86 (b8c187439d27aba430dd69fdcf1fa657) C:\WINDOWS\system32\Drivers\avgldx86.sys 07:55:32:578 3980 AvgMfx86 (53b3f979930a786a614d29cafe99f645) C:\WINDOWS\system32\Drivers\avgmfx86.sys 07:55:32:703 3980 AvgTdiX (22e3b793c3e61720f03d3a22351af410) C:\WINDOWS\system32\Drivers\avgtdix.sys 07:55:32:812 3980 bebd (9c29a3fe1cafe859239735c6f20223f1) C:\WINDOWS\system32\bebd.sys 07:55:32:812 3980 Suspicious file (NoAccess): C:\WINDOWS\system32\bebd.sys. md5: 9c29a3fe1cafe859239735c6f20223f1 07:55:32:968 3980 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 07:55:33:234 3980 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 07:55:33:765 3980 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 07:55:34:015 3980 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 07:55:34:140 3980 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 07:55:34:406 3980 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 07:55:34:562 3980 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 07:55:34:687 3980 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 07:55:34:750 3980 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 07:55:34:828 3980 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 07:55:34:953 3980 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 07:55:35:046 3980 DUBE100 (d94fbb47d33c61541e86972ba540626a) C:\WINDOWS\system32\DRIVERS\DUBE100.sys 07:55:35:140 3980 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 07:55:35:234 3980 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys 07:55:35:328 3980 FETND5BV (cfc4cc73c903152a23e1db28eaba1f03) C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys 07:55:35:453 3980 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys 07:55:35:578 3980 FETNDISB (b0f11e97b051e7dcca40b0453f985636) C:\WINDOWS\system32\DRIVERS\fetnd5b.sys 07:55:35:703 3980 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 07:55:35:812 3980 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys 07:55:35:937 3980 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys 07:55:36:062 3980 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 07:55:36:187 3980 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 07:55:36:265 3980 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 07:55:36:375 3980 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 07:55:36:562 3980 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 07:55:36:859 3980 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 07:55:36:968 3980 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 07:55:37:203 3980 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys 07:55:37:312 3980 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 07:55:37:437 3980 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 07:55:37:562 3980 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 07:55:37:703 3980 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 07:55:37:796 3980 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 07:55:37:921 3980 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 07:55:38:031 3980 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 07:55:38:140 3980 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 07:55:38:250 3980 klmd23 (316353165feba3d0538eaa9c2f60c5b7) C:\WINDOWS\system32\drivers\klmd.sys 07:55:38:437 3980 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 07:55:38:562 3980 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 07:55:38:796 3980 LMIInfo (4f69faaabb7db0d43e327c0b6aab40fc) C:\Program Files\LogMeIn\x86\RaInfo.sys 07:55:38:921 3980 lmimirr (4477689e2d8ae6b78ba34c9af4cc1ed1) C:\WINDOWS\system32\DRIVERS\lmimirr.sys 07:55:39:093 3980 LMIRfsDriver (3faa563ddf853320f90259d455a01d79) C:\WINDOWS\system32\drivers\LMIRfsDriver.sys 07:55:39:187 3980 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 07:55:39:296 3980 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 07:55:39:390 3980 MODEMCSA (1992e0d143b09653ab0f9c5e04b0fd65) C:\WINDOWS\system32\drivers\MODEMCSA.sys 07:55:39:484 3980 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 07:55:39:625 3980 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 07:55:39:703 3980 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 07:55:39:875 3980 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 07:55:40:015 3980 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 07:55:40:093 3980 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 07:55:40:187 3980 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 07:55:40:281 3980 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 07:55:40:375 3980 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 07:55:40:468 3980 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 07:55:40:578 3980 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 07:55:40:734 3980 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 07:55:40:875 3980 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 07:55:41:000 3980 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 07:55:41:109 3980 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 07:55:41:234 3980 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 07:55:41:375 3980 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 07:55:41:515 3980 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 07:55:41:609 3980 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 07:55:41:765 3980 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 07:55:41:953 3980 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 07:55:42:093 3980 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 07:55:42:234 3980 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 07:55:42:375 3980 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys 07:55:42:500 3980 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 07:55:42:609 3980 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 07:55:42:734 3980 PCASp50 (1961590aa191b6b7dcf18a6a693af7b8) C:\WINDOWS\system32\Drivers\PCASp50.sys 07:55:42:890 3980 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 07:55:43:109 3980 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 07:55:43:703 3980 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 07:55:43:843 3980 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 07:55:44:000 3980 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 07:55:44:156 3980 Ptserial (4c67e55571d720402c87a9483083174d) C:\WINDOWS\system32\DRIVERS\ptserial.sys 07:55:44:531 3980 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 07:55:44:640 3980 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 07:55:44:765 3980 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 07:55:44:890 3980 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 07:55:45:000 3980 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 07:55:45:062 3980 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 07:55:45:156 3980 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 07:55:45:265 3980 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 07:55:45:406 3980 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys 07:55:45:562 3980 rt2870 (b10c0cea067240b6741cc7862f63d2fd) C:\WINDOWS\system32\DRIVERS\rt2870.sys 07:55:45:750 3980 S3Psddr (f5c5903c601a193e659485cd8258fcb3) C:\WINDOWS\system32\DRIVERS\s3gnbm.sys 07:55:46:062 3980 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 07:55:46:203 3980 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys 07:55:46:343 3980 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys 07:55:46:437 3980 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 07:55:46:656 3980 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 07:55:46:796 3980 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 07:55:46:937 3980 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys 07:55:47:109 3980 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 07:55:47:234 3980 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 07:55:47:562 3980 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 07:55:47:687 3980 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 07:55:47:859 3980 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 07:55:47:984 3980 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 07:55:48:093 3980 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 07:55:48:187 3980 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 07:55:48:421 3980 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 07:55:48:593 3980 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 07:55:48:734 3980 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 07:55:48:875 3980 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 07:55:49:000 3980 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 07:55:49:140 3980 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 07:55:49:296 3980 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 07:55:49:453 3980 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 07:55:49:593 3980 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 07:55:49:656 3980 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 07:55:49:718 3980 viaagp1 (4b039bbd037b01f5db5a144c837f283a) C:\WINDOWS\system32\DRIVERS\viaagp1.sys 07:55:49:781 3980 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 07:55:49:890 3980 VIAudio (8fe5fd4c124808b30720b84fd07051c2) C:\WINDOWS\system32\drivers\viaudios.sys 07:55:50:062 3980 Vmodem (a630c3b4b1f8ebe85a6c70128135b388) C:\WINDOWS\system32\DRIVERS\vmodem.sys 07:55:50:265 3980 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 07:55:50:437 3980 Vpctcom (8dffba3f522ea796d2e015fc137b4ce0) C:\WINDOWS\system32\DRIVERS\vpctcom.sys 07:55:50:625 3980 Vvoice (f10cdd635fbc729372736a6ec0b0b30c) C:\WINDOWS\system32\DRIVERS\vvoice.sys 07:55:50:765 3980 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 07:55:50:968 3980 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 07:55:51:078 3980 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 07:55:51:093 3980 07:55:51:093 3980 Completed 07:55:51:093 3980 07:55:51:093 3980 Results: 07:55:51:093 3980 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 07:55:51:093 3980 File objects infected / cured / cured on reboot: 0 / 0 / 0 07:55:51:093 3980 07:55:51:093 3980 KLMD(ARK) unloaded successfully
DO NOT use any TOOLS such as Combofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.



Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.




Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Next:


Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
The browser is still redirecting after these steps have been completed. Here is the combofix log.


ComboFix 10-07-04.04 - Nick 07/05/2010 8:33.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2015.1512 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2010-06-05 to 2010-07-05 )))))))))))))))))))))))))))))))
.

2010-07-05 07:30 . 2010-07-05 07:30 74 —ha-w- C:\aaw7boot.cmd
2010-07-05 05:02 . 2010-07-05 15:19 0 —-a-w- c:\documents and settings\Nick\Local Settings\Application Data\prvlcl.dat
2010-07-05 04:53 . 2010-07-05 04:53 ——– d—–w- c:\program files\AVG
2010-07-05 04:44 . 2010-07-05 04:44 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\Temp
2010-07-05 02:03 . 2010-07-05 02:17 ——– d—–w- c:\documents and settings\Administrator
2010-07-05 01:57 . 2010-07-05 01:57 ——– d—–w- c:\documents and settings\Nick\Application Data\Registry Mechanic
2010-07-05 01:17 . 2010-07-05 01:17 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-07-05 01:14 . 2010-07-05 14:50 ——– d—–w- c:\program files\Lavasoft
2010-07-04 23:22 . 2010-05-21 21:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-07-04 22:38 . 2010-07-04 22:38 0 —-a-w- c:\windows\nsreg.dat
2010-07-04 22:38 . 2010-07-04 22:38 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\Mozilla
2010-07-04 22:31 . 2010-07-04 22:31 ——– d—–w- c:\program files\Common Files\Java
2010-07-04 22:31 . 2010-07-04 22:31 503808 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\msvcp71.dll
2010-07-04 22:31 . 2010-07-04 22:31 499712 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\jmc.dll
2010-07-04 22:31 . 2010-07-04 22:31 348160 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\msvcr71.dll
2010-07-04 22:31 . 2010-07-04 22:31 61440 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-17a24c77-n\decora-sse.dll
2010-07-04 22:31 . 2010-07-04 22:31 12800 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-17a24c77-n\decora-d3d.dll
2010-07-04 22:31 . 2010-07-04 22:31 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-04 21:34 . 2010-07-04 21:34 ——– d—–w- c:\program files\Trend Micro
2010-07-04 04:26 . 2010-07-05 15:25 ——– d—–w- c:\documents and settings\LogMeInRemoteUser\Local Settings\Application Data\Microsoft
2010-07-04 04:00 . 2010-07-04 04:00 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\LogMeIn
2010-07-04 04:00 . 2010-07-04 04:00 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2010-07-04 03:59 . 2010-06-02 23:06 53632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-07-04 03:59 . 2010-06-02 23:06 29568 —-a-w- c:\windows\system32\LMIport.dll
2010-07-04 03:59 . 2010-06-02 23:06 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-07-04 03:59 . 2010-01-27 19:22 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2010-07-04 03:59 . 2010-06-02 23:06 87424 —-a-w- c:\windows\system32\LMIinit.dll
2010-07-04 03:59 . 2010-07-05 07:00 ——– d—–w- c:\program files\LogMeIn
2010-06-29 17:27 . 2010-06-29 17:27 ——– d—–w- c:\program files\Dell
2010-06-29 17:27 . 2010-06-29 17:27 ——– d—–w- c:\windows\system32\Dell
2010-06-17 06:07 . 2010-06-17 06:07 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\LogMeIn Rescue Unattended
2010-06-17 03:43 . 2010-06-17 03:43 ——– d—–w- c:\documents and settings\Nick\Application Data\Malwarebytes
2010-06-17 03:42 . 2010-06-17 03:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-17 03:23 . 2010-06-17 03:23 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2010-06-17 03:23 . 2010-06-17 15:02 ——– d—–w- c:\windows\LMI8.tmp
2010-06-17 01:43 . 2010-07-04 21:27 ——– d—–w- c:\windows\LMI2006.tmp
2010-06-17 01:20 . 2010-06-17 01:20 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\ICS
2010-06-17 01:20 . 2010-06-17 06:06 ——– d—–w- c:\windows\LMI1EE3.tmp
2010-06-10 22:46 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 17:07 . 2010-06-08 17:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-05 15:28 . 2004-06-04 21:30 1536 —-a-w- c:\windows\system32\TrueSoft.dat
2010-07-05 14:50 . 2008-04-20 02:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-05 02:18 . 2008-11-11 00:05 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-05 02:18 . 2008-11-11 00:05 ——– d—–w- c:\program files\NOS
2010-07-05 02:17 . 2009-01-16 20:41 ——– d—–w- c:\program files\RealArcade
2010-07-05 02:17 . 2004-12-15 18:41 ——– d—–w- c:\program files\Common Files\Real
2010-07-05 02:16 . 2009-01-16 19:19 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-05 02:16 . 2004-08-25 22:21 ——– d—–w- c:\program files\Yahoo!
2010-07-05 00:50 . 2004-06-07 20:29 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-05 00:48 . 2004-06-07 20:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-04 22:46 . 2004-06-07 20:20 ——– d—–w- c:\program files\Symantec
2010-07-04 22:44 . 2004-06-07 20:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-07-04 22:44 . 2004-06-07 20:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-07-04 22:31 . 2004-08-20 22:34 ——– d—–w- c:\program files\Java
2010-07-04 05:42 . 2007-05-18 23:08 ——– d—–w- c:\program files\Coupons
2010-07-04 04:05 . 2004-08-21 18:59 ——– d—–w- c:\program files\Google
2010-07-04 04:03 . 2008-04-21 06:12 ——– d—–w- c:\documents and settings\Nick\Application Data\Yahoo!
2010-07-02 23:03 . 2009-09-04 21:42 ——– d—–w- c:\program files\Dl_cats
2010-06-29 17:40 . 2010-04-21 17:31 439816 —-a-w- c:\documents and settings\Nick\Application Data\Real\Update\setup3.10\setup.exe
2010-06-22 17:09 . 2007-07-03 00:07 2694 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2007\qbbackup.sys
2010-06-17 01:28 . 2008-04-21 02:43 ——– d—–w- c:\documents and settings\Nick\Application Data\SUPERAntiSpyware.com
2010-06-12 01:42 . 2004-08-06 19:38 ——– d—–w- c:\program files\Opera
2010-06-04 17:03 . 2009-11-02 20:05 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-27 22:34 . 2010-05-27 22:34 ——– d—–w- c:\documents and settings\Nick\Application Data\YoudaGames
2010-05-06 10:41 . 2004-02-07 01:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2003-03-31 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 17:11 . 2010-05-01 17:11 74240 ——w- c:\windows\system32\bebd.sys
2010-04-20 05:30 . 2003-03-31 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-07-04_23.04.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-29 15:05 . 2008-07-29 15:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 80896 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfcm90ud.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 80896 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfcm90d.dll
+ 2010-07-05 15:27 . 2010-07-05 15:27 16384 c:\windows\Temp\Perflib_Perfdata_6ac.dat
+ 2010-07-05 05:36 . 2010-07-05 05:36 29926 c:\windows\Installer\{338F08AB-C262-42C7-B000-34DE1A475273}\_6FEFF9B68218417F98F549.exe
+ 2008-07-29 15:05 . 2008-07-29 15:05 875520 c:\windows\WinSxS\x86_Microsoft.VC90.DebugCRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_f863c71f\msvcp90d.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 312832 c:\windows\WinSxS\x86_Microsoft.VC90.DebugCRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_f863c71f\msvcm90d.dll
+ 2009-07-12 07:02 . 2009-07-12 07:02 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-07-12 07:02 . 2009-07-12 07:02 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-07-12 07:05 . 2009-07-12 07:05 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2003-03-31 12:00 . 2008-04-14 00:12 142336 c:\windows\system32\dllcache\nwprovau.dll
+ 2010-01-04 20:39 . 2010-07-05 05:42 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
- 2010-01-04 20:39 . 2010-07-04 21:33 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-07-05 01:14 . 2010-07-05 01:14 236032 c:\windows\Installer\cf517.msi
+ 2010-07-05 05:36 . 2010-07-05 05:36 167424 c:\windows\Installer\1bdbeb.msi
+ 2008-07-29 15:05 . 2008-07-29 15:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 5982720 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfc90ud.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 5937144 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfc90d.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 1180672 c:\windows\WinSxS\x86_Microsoft.VC90.DebugCRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_f863c71f\msvcr90d.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-05 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-05-27 77824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"VTPreset"="VTPreset.exe" [2004-02-25 45056]
"DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-10 69632]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2005-04-22 290816]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

c:\documents and settings\Nick\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]
Wireless Network Monitor.lnk - c:\program files\Linksys\WUSB600N\WUSB600N.exe [2008-1-9 6922240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-02 23:06 87424 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
2003-08-14 13:29 561152 ——w- c:\program files\Common Files\Verizon Online\SFP\vzSFPWin.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 bebd;bebd;c:\windows\system32\bebd.sys [5/1/2010 10:11 AM 74240]
R2 Intuit Entitlement Service v3;Intuit Entitlement Service v3;c:\program files\Common Files\Intuit\Entitlement Client\v3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [1/30/2008 3:12 PM 24576]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
R2 QBPOSDBServiceV6;QBPOS Database Manager v6;c:\program files\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBPOSDBServiceV6.exe [3/15/2010 10:06 AM 1479504]
R2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 –> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
S0 8ee83ed6bacf0746bc28c33d75f3dda4;8ee83ed6bacf0746bc28c33d75f3dda4;c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys –> c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 DUBE100;D-Link DUB-E100 USB 2.0 to Fast Ethernet Adapter;c:\windows\system32\drivers\DUBE100.sys [9/7/2007 9:37 AM 11935]
S3 SASENUM;SASENUM;\??\c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS –> c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-261903793-682003330-1003Core.job
- c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-05 04:44]

2010-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-261903793-682003330-1003UA.job
- c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-05 04:44]

2010-07-04 c:\windows\Tasks\User_Feed_Synchronization-{7851FF64-2E9D-428E-90DE-24BDA072DC78}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 12:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.Google.com/
uStart Page = hxxp://www.yahoo.com/
uSearchAssistant = hxxp://www.Google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchURL = hxxp://www.Google.com/
TCP: {3E0FF98E-6ECC-4350-B4DC-8316C251E0EB} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\ermrq6jv.default\
FF - plugin: c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
HKCU-Run-RegistryMechanic - c:\program files\Registry Mechanic\RegMech.exe
HKLM-Run-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-05 08:40
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1409082233-261903793-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\LMIinit.dll

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'explorer.exe'(2132)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2010-07-05 08:43:33
ComboFix-quarantined-files.txt 2010-07-05 15:43
ComboFix2.txt 2010-07-04 23:07

Pre-Run: 4,126,052,352 bytes free
Post-Run: 4,112,084,992 bytes free

- - End Of File - - F7DE50635863310428DF17BF54394E5A
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Hello, I am still being redirected. Here is the log:

ComboFix 10-07-04.04 - Nick 07/05/2010 9:33.4.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2015.1513 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt

FILE ::
"c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys"
.

((((((((((((((((((((((((( Files Created from 2010-06-05 to 2010-07-05 )))))))))))))))))))))))))))))))
.

2010-07-05 07:30 . 2010-07-05 07:30 74 —ha-w- C:\aaw7boot.cmd
2010-07-05 05:02 . 2010-07-05 15:19 0 —-a-w- c:\documents and settings\Nick\Local Settings\Application Data\prvlcl.dat
2010-07-05 04:53 . 2010-07-05 04:53 ——– d—–w- c:\program files\AVG
2010-07-05 04:44 . 2010-07-05 04:44 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\Temp
2010-07-05 02:03 . 2010-07-05 02:17 ——– d—–w- c:\documents and settings\Administrator
2010-07-05 01:57 . 2010-07-05 01:57 ——– d—–w- c:\documents and settings\Nick\Application Data\Registry Mechanic
2010-07-05 01:17 . 2010-07-05 01:17 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-07-05 01:14 . 2010-07-05 16:11 ——– d—–w- c:\program files\Lavasoft
2010-07-04 23:22 . 2010-05-21 21:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-07-04 22:38 . 2010-07-04 22:38 0 —-a-w- c:\windows\nsreg.dat
2010-07-04 22:38 . 2010-07-04 22:38 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\Mozilla
2010-07-04 22:31 . 2010-07-04 22:31 ——– d—–w- c:\program files\Common Files\Java
2010-07-04 22:31 . 2010-07-04 22:31 503808 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\msvcp71.dll
2010-07-04 22:31 . 2010-07-04 22:31 499712 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\jmc.dll
2010-07-04 22:31 . 2010-07-04 22:31 348160 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\msvcr71.dll
2010-07-04 22:31 . 2010-07-04 22:31 61440 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-17a24c77-n\decora-sse.dll
2010-07-04 22:31 . 2010-07-04 22:31 12800 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-17a24c77-n\decora-d3d.dll
2010-07-04 22:31 . 2010-07-04 22:31 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-04 21:34 . 2010-07-04 21:34 ——– d—–w- c:\program files\Trend Micro
2010-07-04 04:26 . 2010-07-05 15:25 ——– d—–w- c:\documents and settings\LogMeInRemoteUser\Local Settings\Application Data\Microsoft
2010-07-04 04:00 . 2010-07-04 04:00 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\LogMeIn
2010-07-04 04:00 . 2010-07-04 04:00 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2010-07-04 03:59 . 2010-06-02 23:06 53632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-07-04 03:59 . 2010-06-02 23:06 29568 —-a-w- c:\windows\system32\LMIport.dll
2010-07-04 03:59 . 2010-06-02 23:06 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-07-04 03:59 . 2010-01-27 19:22 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2010-07-04 03:59 . 2010-06-02 23:06 87424 —-a-w- c:\windows\system32\LMIinit.dll
2010-07-04 03:59 . 2010-07-05 07:00 ——– d—–w- c:\program files\LogMeIn
2010-06-29 17:27 . 2010-06-29 17:27 ——– d—–w- c:\program files\Dell
2010-06-29 17:27 . 2010-06-29 17:27 ——– d—–w- c:\windows\system32\Dell
2010-06-17 06:07 . 2010-06-17 06:07 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\LogMeIn Rescue Unattended
2010-06-17 03:43 . 2010-06-17 03:43 ——– d—–w- c:\documents and settings\Nick\Application Data\Malwarebytes
2010-06-17 03:42 . 2010-06-17 03:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-17 03:23 . 2010-06-17 03:23 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2010-06-17 03:23 . 2010-06-17 15:02 ——– d—–w- c:\windows\LMI8.tmp
2010-06-17 01:43 . 2010-07-04 21:27 ——– d—–w- c:\windows\LMI2006.tmp
2010-06-17 01:20 . 2010-06-17 01:20 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\ICS
2010-06-17 01:20 . 2010-06-17 06:06 ——– d—–w- c:\windows\LMI1EE3.tmp
2010-06-10 22:46 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 17:07 . 2010-06-08 17:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-05 16:05 . 2007-07-03 00:07 2694 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2007\qbbackup.sys
2010-07-05 15:28 . 2004-06-04 21:30 1536 —-a-w- c:\windows\system32\TrueSoft.dat
2010-07-05 14:50 . 2008-04-20 02:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-05 02:18 . 2008-11-11 00:05 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-05 02:18 . 2008-11-11 00:05 ——– d—–w- c:\program files\NOS
2010-07-05 02:17 . 2009-01-16 20:41 ——– d—–w- c:\program files\RealArcade
2010-07-05 02:17 . 2004-12-15 18:41 ——– d—–w- c:\program files\Common Files\Real
2010-07-05 02:16 . 2009-01-16 19:19 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-05 02:16 . 2004-08-25 22:21 ——– d—–w- c:\program files\Yahoo!
2010-07-05 00:50 . 2004-06-07 20:29 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-05 00:48 . 2004-06-07 20:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-04 22:46 . 2004-06-07 20:20 ——– d—–w- c:\program files\Symantec
2010-07-04 22:44 . 2004-06-07 20:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-07-04 22:44 . 2004-06-07 20:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-07-04 22:31 . 2004-08-20 22:34 ——– d—–w- c:\program files\Java
2010-07-04 05:42 . 2007-05-18 23:08 ——– d—–w- c:\program files\Coupons
2010-07-04 04:05 . 2004-08-21 18:59 ——– d—–w- c:\program files\Google
2010-07-04 04:03 . 2008-04-21 06:12 ——– d—–w- c:\documents and settings\Nick\Application Data\Yahoo!
2010-07-02 23:03 . 2009-09-04 21:42 ——– d—–w- c:\program files\Dl_cats
2010-06-29 17:40 . 2010-04-21 17:31 439816 —-a-w- c:\documents and settings\Nick\Application Data\Real\Update\setup3.10\setup.exe
2010-06-17 01:28 . 2008-04-21 02:43 ——– d—–w- c:\documents and settings\Nick\Application Data\SUPERAntiSpyware.com
2010-06-12 01:42 . 2004-08-06 19:38 ——– d—–w- c:\program files\Opera
2010-06-04 17:03 . 2009-11-02 20:05 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-27 22:34 . 2010-05-27 22:34 ——– d—–w- c:\documents and settings\Nick\Application Data\YoudaGames
2010-05-06 10:41 . 2004-02-07 01:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2003-03-31 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-05-01 17:11 . 2010-05-01 17:11 74240 ——w- c:\windows\system32\bebd.sys
2010-04-20 05:30 . 2003-03-31 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((( SnapShot@2010-07-04_23.04.31 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-07-29 15:05 . 2008-07-29 15:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 80896 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfcm90ud.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 80896 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfcm90d.dll
+ 2010-07-05 15:27 . 2010-07-05 15:27 16384 c:\windows\Temp\Perflib_Perfdata_6ac.dat
+ 2008-07-29 15:05 . 2008-07-29 15:05 875520 c:\windows\WinSxS\x86_Microsoft.VC90.DebugCRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_f863c71f\msvcp90d.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 312832 c:\windows\WinSxS\x86_Microsoft.VC90.DebugCRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_f863c71f\msvcm90d.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2003-03-31 12:00 . 2008-04-14 00:12 142336 c:\windows\system32\dllcache\nwprovau.dll
- 2010-01-04 20:39 . 2010-07-04 21:33 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-01-04 20:39 . 2010-07-05 05:42 245760 c:\windows\system32\config\systemprofile\IETldCache\index.dat
+ 2010-07-05 01:14 . 2010-07-05 01:14 236032 c:\windows\Installer\cf517.msi
+ 2008-07-29 15:05 . 2008-07-29 15:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 5982720 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfc90ud.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 5937144 c:\windows\WinSxS\x86_Microsoft.VC90.DebugMFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_c94a3a24\mfc90d.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 1180672 c:\windows\WinSxS\x86_Microsoft.VC90.DebugCRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_f863c71f\msvcr90d.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-07-05 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-05-27 77824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"VTPreset"="VTPreset.exe" [2004-02-25 45056]
"DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-10 69632]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2005-04-22 290816]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

c:\documents and settings\Nick\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]
Wireless Network Monitor.lnk - c:\program files\Linksys\WUSB600N\WUSB600N.exe [2008-1-9 6922240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-02 23:06 87424 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
2003-08-14 13:29 561152 ——w- c:\program files\Common Files\Verizon Online\SFP\vzSFPWin.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R1 bebd;bebd;c:\windows\system32\bebd.sys [5/1/2010 10:11 AM 74240]
R2 Intuit Entitlement Service v3;Intuit Entitlement Service v3;c:\program files\Common Files\Intuit\Entitlement Client\v3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [1/30/2008 3:12 PM 24576]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
R2 QBPOSDBServiceV6;QBPOS Database Manager v6;c:\program files\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBPOSDBServiceV6.exe [3/15/2010 10:06 AM 1479504]
R2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 –> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
S0 8ee83ed6bacf0746bc28c33d75f3dda4;8ee83ed6bacf0746bc28c33d75f3dda4;c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys –> c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 DUBE100;D-Link DUB-E100 USB 2.0 to Fast Ethernet Adapter;c:\windows\system32\drivers\DUBE100.sys [9/7/2007 9:37 AM 11935]
S3 SASENUM;SASENUM;\??\c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS –> c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-261903793-682003330-1003Core.job
- c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-05 04:44]

2010-07-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1409082233-261903793-682003330-1003UA.job
- c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-07-05 04:44]

2010-07-05 c:\windows\Tasks\User_Feed_Synchronization-{7851FF64-2E9D-428E-90DE-24BDA072DC78}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 12:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.Google.com/
uStart Page = hxxp://www.yahoo.com/
uSearchAssistant = hxxp://www.Google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchURL = hxxp://www.Google.com/
TCP: {3E0FF98E-6ECC-4350-B4DC-8316C251E0EB} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\ermrq6jv.default\
FF - plugin: c:\documents and settings\Nick\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-05 09:36
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1409082233-261903793-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\LMIinit.dll

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'explorer.exe'(2800)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\LMIRfsClientNP.dll
.
Completion time: 2010-07-05 09:39:01
ComboFix-quarantined-files.txt 2010-07-05 16:38
ComboFix2.txt 2010-07-05 15:43
ComboFix3.txt 2010-07-04 23:07

Pre-Run: 4,236,365,824 bytes free
Post-Run: 4,227,989,504 bytes free

- - End Of File - - 2573B38FEBDA6749C0C144D5D4584EE4
Please go to http://virusscan.jotti.org, click on Browse, and upload the following file for analysis:

c:\windows\system32\bebd.sys


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If virscan.org is too busy you can try these.

http://virscan.org/

http://www.kaspersky.com/scanforvirus.html


http://www.virustotal.com/en/indexf.html
We need to get a copy of that file.

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

http://forums.whatthetech.com/index.php?showtopic=112989
File::

Collect::
c:\windows\system32\bebd.sys

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Here you go:

ComboFix 10-07-04.04 - Nick 07/05/2010 10:03:33.5.1 - x86 NETWORK
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2015.1740 [GMT -7:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Nick\Desktop\CFScript.txt

file zipped: c:\windows\system32\bebd.sys
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\bebd.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_bebd
——-\Service_bebd


((((((((((((((((((((((((( Files Created from 2010-06-05 to 2010-07-05 )))))))))))))))))))))))))))))))
.

2010-07-05 07:30 . 2010-07-05 07:30 74 —ha-w- C:\aaw7boot.cmd
2010-07-05 05:02 . 2010-07-05 15:19 0 —-a-w- c:\documents and settings\Nick\Local Settings\Application Data\prvlcl.dat
2010-07-05 04:53 . 2010-07-05 04:53 ——– d—–w- c:\program files\AVG
2010-07-05 04:44 . 2010-07-05 04:44 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\Temp
2010-07-05 02:03 . 2010-07-05 02:17 ——– d—–w- c:\documents and settings\Administrator
2010-07-05 01:57 . 2010-07-05 01:57 ——– d—–w- c:\documents and settings\Nick\Application Data\Registry Mechanic
2010-07-05 01:17 . 2010-07-05 01:17 95024 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-07-05 01:14 . 2010-07-05 16:11 ——– d—–w- c:\program files\Lavasoft
2010-07-04 23:22 . 2010-05-21 21:14 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-07-04 22:38 . 2010-07-04 22:38 0 —-a-w- c:\windows\nsreg.dat
2010-07-04 22:38 . 2010-07-04 22:38 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\Mozilla
2010-07-04 22:31 . 2010-07-04 22:31 ——– d—–w- c:\program files\Common Files\Java
2010-07-04 22:31 . 2010-07-04 22:31 503808 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\msvcp71.dll
2010-07-04 22:31 . 2010-07-04 22:31 499712 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\jmc.dll
2010-07-04 22:31 . 2010-07-04 22:31 348160 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6cccd44f-n\msvcr71.dll
2010-07-04 22:31 . 2010-07-04 22:31 61440 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-17a24c77-n\decora-sse.dll
2010-07-04 22:31 . 2010-07-04 22:31 12800 —-a-w- c:\documents and settings\Nick\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-17a24c77-n\decora-d3d.dll
2010-07-04 22:31 . 2010-07-04 22:31 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-04 21:34 . 2010-07-04 21:34 ——– d—–w- c:\program files\Trend Micro
2010-07-04 04:26 . 2010-07-05 15:25 ——– d—–w- c:\documents and settings\LogMeInRemoteUser\Local Settings\Application Data\Microsoft
2010-07-04 04:00 . 2010-07-04 04:00 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\LogMeIn
2010-07-04 04:00 . 2010-07-04 04:00 ——– d—–w- c:\documents and settings\All Users\Application Data\LogMeIn
2010-07-04 03:59 . 2010-06-02 23:06 53632 —-a-w- c:\windows\system32\Spool\prtprocs\w32x86\LMIproc.dll
2010-07-04 03:59 . 2010-06-02 23:06 29568 —-a-w- c:\windows\system32\LMIport.dll
2010-07-04 03:59 . 2010-06-02 23:06 83360 —-a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-07-04 03:59 . 2010-01-27 19:22 47640 —-a-w- c:\windows\system32\drivers\LMIRfsDriver.sys
2010-07-04 03:59 . 2010-06-02 23:06 87424 —-a-w- c:\windows\system32\LMIinit.dll
2010-07-04 03:59 . 2010-07-05 07:00 ——– d—–w- c:\program files\LogMeIn
2010-06-29 17:27 . 2010-06-29 17:27 ——– d—–w- c:\program files\Dell
2010-06-29 17:27 . 2010-06-29 17:27 ——– d—–w- c:\windows\system32\Dell
2010-06-17 06:07 . 2010-06-17 06:07 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\LogMeIn Rescue Unattended
2010-06-17 03:43 . 2010-06-17 03:43 ——– d—–w- c:\documents and settings\Nick\Application Data\Malwarebytes
2010-06-17 03:42 . 2010-06-17 03:42 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-17 03:23 . 2010-06-17 03:23 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ICS
2010-06-17 03:23 . 2010-06-17 15:02 ——– d—–w- c:\windows\LMI8.tmp
2010-06-17 01:43 . 2010-07-04 21:27 ——– d—–w- c:\windows\LMI2006.tmp
2010-06-17 01:20 . 2010-06-17 01:20 ——– d—–w- c:\documents and settings\Nick\Local Settings\Application Data\ICS
2010-06-17 01:20 . 2010-06-17 06:06 ——– d—–w- c:\windows\LMI1EE3.tmp
2010-06-10 22:46 . 2010-05-06 10:41 743424 -c—-w- c:\windows\system32\dllcache\iedvtool.dll
2010-06-08 17:07 . 2010-06-08 17:07 ——– d—–w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-05 17:11 . 2004-06-04 21:30 1536 —-a-w- c:\windows\system32\TrueSoft.dat
2010-07-05 16:05 . 2007-07-03 00:07 2694 —-a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2007\qbbackup.sys
2010-07-05 14:50 . 2008-04-20 02:40 ——– d—–w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-07-05 02:18 . 2008-11-11 00:05 ——– d—–w- c:\documents and settings\All Users\Application Data\NOS
2010-07-05 02:18 . 2008-11-11 00:05 ——– d—–w- c:\program files\NOS
2010-07-05 02:17 . 2009-01-16 20:41 ——– d—–w- c:\program files\RealArcade
2010-07-05 02:17 . 2004-12-15 18:41 ——– d—–w- c:\program files\Common Files\Real
2010-07-05 02:16 . 2009-01-16 19:19 ——– d—a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-05 02:16 . 2004-08-25 22:21 ——– d—–w- c:\program files\Yahoo!
2010-07-05 00:50 . 2004-06-07 20:29 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-07-05 00:48 . 2004-06-07 20:29 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-04 22:46 . 2004-06-07 20:20 ——– d—–w- c:\program files\Symantec
2010-07-04 22:44 . 2004-06-07 20:20 ——– d—–w- c:\program files\Common Files\Symantec Shared
2010-07-04 22:44 . 2004-06-07 20:20 ——– d—–w- c:\documents and settings\All Users\Application Data\Symantec
2010-07-04 22:31 . 2004-08-20 22:34 ——– d—–w- c:\program files\Java
2010-07-04 05:42 . 2007-05-18 23:08 ——– d—–w- c:\program files\Coupons
2010-07-04 04:05 . 2004-08-21 18:59 ——– d—–w- c:\program files\Google
2010-07-04 04:03 . 2008-04-21 06:12 ——– d—–w- c:\documents and settings\Nick\Application Data\Yahoo!
2010-07-02 23:03 . 2009-09-04 21:42 ——– d—–w- c:\program files\Dl_cats
2010-06-29 17:40 . 2010-04-21 17:31 439816 —-a-w- c:\documents and settings\Nick\Application Data\Real\Update\setup3.10\setup.exe
2010-06-17 01:28 . 2008-04-21 02:43 ——– d—–w- c:\documents and settings\Nick\Application Data\SUPERAntiSpyware.com
2010-06-12 01:42 . 2004-08-06 19:38 ——– d—–w- c:\program files\Opera
2010-06-04 17:03 . 2009-11-02 20:05 ——– d—–w- c:\program files\Microsoft Silverlight
2010-05-27 22:34 . 2010-05-27 22:34 ——– d—–w- c:\documents and settings\Nick\Application Data\YoudaGames
2010-05-06 10:41 . 2004-02-07 01:05 916480 —-a-w- c:\windows\system32\wininet.dll
2010-05-02 05:22 . 2003-03-31 12:00 1851264 —-a-w- c:\windows\system32\win32k.sys
2010-04-20 05:30 . 2003-03-31 12:00 285696 —-a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2010-01-27 63048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-05-27 77824]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"VTPreset"="VTPreset.exe" [2004-02-25 45056]
"DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-10 69632]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2005-04-22 290816]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]

c:\documents and settings\Nick\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]
Wireless Network Monitor.lnk - c:\program files\Linksys\WUSB600N\WUSB600N.exe [2008-1-9 6922240]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-02 23:06 87424 —-a-w- c:\windows\system32\LMIinit.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SFP]
2003-08-14 13:29 561152 ——w- c:\program files\Common Files\Verizon Online\SFP\vzSFPWin.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=

R2 Intuit Entitlement Service v3;Intuit Entitlement Service v3;c:\program files\Common Files\Intuit\Entitlement Client\v3\Server\Intuit.Spc.Map.EntitlementClient.Server.Service.exe [1/30/2008 3:12 PM 24576]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [1/27/2010 12:22 PM 12856]
R2 QBPOSDBServiceV6;QBPOS Database Manager v6;c:\program files\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBPOSDBServiceV6.exe [3/15/2010 10:06 AM 1479504]
R2 QuickBooksDB17;QuickBooksDB17;c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 –> c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe -hvQuickBooksDB17 [?]
S0 8ee83ed6bacf0746bc28c33d75f3dda4;8ee83ed6bacf0746bc28c33d75f3dda4;c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys –> c:\windows\system32\8ee83ed6bacf0746bc28c33d75f3dda4.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS –> c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys –> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]
S3 DUBE100;D-Link DUB-E100 USB 2.0 to Fast Ethernet Adapter;c:\windows\system32\drivers\DUBE100.sys [9/7/2007 9:37 AM 11935]
S3 SASENUM;SASENUM;\??\c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS –> c:\docume~1\Nick\LOCALS~1\Temp\SAS_SelfExtract\SASENUM.SYS [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder

2010-07-05 c:\windows\Tasks\User_Feed_Synchronization-{7851FF64-2E9D-428E-90DE-24BDA072DC78}.job
- c:\windows\system32\msfeedssync.exe [2007-08-14 12:31]
.
.
——- Supplementary Scan ——-
.
uSearchMigratedDefaultURL = hxxp://www.Google.com/
uStart Page = hxxp://www.yahoo.com/
uSearchAssistant = hxxp://www.Google.com/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchURL = hxxp://www.Google.com/
TCP: {3E0FF98E-6ECC-4350-B4DC-8316C251E0EB} = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\documents and settings\Nick\Application Data\Mozilla\Firefox\Profiles\ermrq6jv.default\
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-05 10:13
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-1409082233-261903793-682003330-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(640)
c:\windows\system32\LMIinit.dll

- - - - - - - > 'lsass.exe'(696)
c:\windows\system32\LMIRfsClientNP.dll

- - - - - - - > 'explorer.exe'(484)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\progra~1\Intuit\QUICKB~1\QBDBMgrN.exe
c:\program files\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBDBMgrN.exe
c:\program files\Intuit\QuickBooks Point of Sale 6.0\DatabaseServer\QBDBMgrN.exe
c:\windows\system32\wscntfy.exe
c:\program files\Dell Photo AIO Printer 922\dlbtbmon.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
.
**************************************************************************
.
Completion time: 2010-07-05 10:19:29 - machine was rebooted
ComboFix-quarantined-files.txt 2010-07-05 17:19
ComboFix2.txt 2010-07-05 16:39
ComboFix3.txt 2010-07-05 15:43
ComboFix4.txt 2010-07-04 23:07

Pre-Run: 4,231,192,576 bytes free
Post-Run: 4,215,324,672 bytes free

- - End Of File - - CC7A8CB2B02E78E8A05864AF719C8F76
You still being redirected?

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take quite a long time to download.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Haven't had the opportunity to run Kaspersky scan. The system seems to be working great now. No issues with redirects. Thanks for the help, I really appreciate it. I will be sending over a donation shortly.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI