This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Chrome Browser Redirect

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When using google or other search engines as well as some of my favorites I'm randomly being redirected to a link that appears as facebook.com/(original site linke) but appears as a myspace page. Attached below is my hijack this log and my OTL Logs:
***********************************************

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:38:46 AM, on 7/16/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Users\S3ymour\AppData\Local\Google\Update\GoogleUpdate.exe
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
C:\Program Files (x86)\AVG\AVG9\avgtray.exe
C:\Program Files (x86)\TheStubware\TheStubware.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\S3ymour\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?

LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common

Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)

\AVG\AVG9\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot -

Search & Destroy\SDHelper.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)

\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [HDAudDeck] "C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe" -r
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Monitor] "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~2\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [TheStubware] "C:\Program Files (x86)\TheStubware\TheStubware.exe" -Startup
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Google Update] "C:\Users\S3ymour\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [Silverlight] "C:\Users\S3ymour\AppData\Roaming\Silverlight.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL

SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-21-717218054-4078819399-4181070963-501\..\Run: [Sidebar] C:\Program Files\Windows

Sidebar\sidebar.exe /autoRun (User 'Guest')
O4 - S-1-5-21-717218054-4078819399-4181070963-501 Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)

\OpenOffice.org 3\program\quickstart.exe (User 'Guest')
O4 - S-1-5-21-717218054-4078819399-4181070963-501 User Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)

\OpenOffice.org 3\program\quickstart.exe (User 'Guest')
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search &

Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -

C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -

http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} -

C:\Windows\system32\browseui.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file

missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: WebEx Service Host for Support Center (atashost) - WebEx Communications, Inc. - C:\Windows\SysWOW64

\atashost.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9

\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\AVG9

\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LeapFrog Connect Device Service - LeapFrog Enterprises, Inc. - C:\Program Files (x86)

\LeapFrog\LeapFrog Connect\CommandService.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe

(file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32

\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe

(file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file

missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)

\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file

missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe

(file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe

(file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common

Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32

\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file

missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file

missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32

\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program

Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 8796 bytes
*******************************************************************
OTL logfile created on: 7/16/2010 10:40:38 AM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\S3ymour\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 459.50 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: S3YMOUR-PC
Current User Name: S3ymour
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/07/16 10:40:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\S3ymour\Downloads\OTL.exe
PRC - [2010/07/16 10:27:38 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\S3ymour\Downloads\HiJackThis.exe
PRC - [2010/07/15 18:43:33 | 000,723,296 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe
PRC - [2010/07/15 18:43:15 | 002,065,760 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgtray.exe
PRC - [2010/07/15 18:42:54 | 000,921,440 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgemc.exe
PRC - [2010/07/15 18:42:45 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe
PRC - [2010/06/28 22:27:23 | 000,945,720 | —- | M] (Google Inc.) – C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe
PRC - [2010/05/08 10:17:47 | 001,238,352 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\steam.exe
PRC - [2010/04/11 16:34:30 | 000,781,312 | —- | M] (TheStubware.com) – C:\Program Files (x86)\TheStubware\TheStubware.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2010/01/11 15:21:52 | 000,490,216 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
PRC - [2009/11/10 10:14:38 | 000,443,728 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2009/11/10 09:28:06 | 001,131,808 | —- | M] (LeapFrog Enterprises, Inc.) – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2009/03/06 12:59:12 | 000,020,376 | —- | M] (WebEx Communications, Inc.) – C:\Windows\SysWOW64\atashost.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | RHS- | M] (Safer Networking Limited) – C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe


========== Modules (SafeList) ==========

MOD - [2010/07/16 10:40:25 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\S3ymour\Downloads\OTL.exe
MOD - [2008/01/20 22:50:01 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\msscript.ocx
MOD - [2008/01/20 22:48:06 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/06/14 23:12:12 | 000,203,264 | —- | M] () [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/07/15 18:42:54 | 000,921,440 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgemc.exe – (avg9emc)
SRV - [2010/07/15 18:42:45 | 000,308,136 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe – (avg9wd)
SRV - [2010/03/26 17:43:04 | 000,332,720 | —- | M] (Valve Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2010/03/18 14:27:14 | 001,020,768 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe – (WPFFontCache_v0400)
SRV - [2010/03/18 14:27:14 | 000,138,576 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_64)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/11/10 09:28:06 | 001,131,808 | —- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] – C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe – (LeapFrog Connect Device Service)
SRV - [2009/03/06 12:59:12 | 000,020,376 | —- | M] (WebEx Communications, Inc.) [Auto | Running] – C:\Windows\SysWOW64\atashost.exe – (atashost)
SRV - [2009/01/26 15:31:10 | 001,153,368 | —- | M] (Safer Networking Ltd.) [Auto | Running] – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe – (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV:64bit: - File not found [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\ipinip.sys – (IpInIp)
DRV:64bit: - File not found [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\ActiveMonitor.SYS – (ActiveMonitor)
DRV:64bit: - [2010/07/15 18:44:31 | 000,317,520 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\avgtdia.sys – (AvgTdiA)
DRV:64bit: - [2010/07/15 18:44:25 | 000,269,904 | —- | M] () [Kernel | System | Running] – C:\Windows\SysNative\Drivers\avgldx64.sys – (AvgLdx64)
DRV:64bit: - [2010/07/15 18:44:23 | 000,035,536 | —- | M] () [File_System | System | Running] – C:\Windows\SysNative\Drivers\avgmfx64.sys – (AvgMfx64)
DRV:64bit: - [2009/11/10 09:27:06 | 000,024,576 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\FlyUsb.sys – (FlyUsb)
DRV:64bit: - [2009/06/14 23:48:02 | 006,031,872 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/06/04 08:20:48 | 000,113,168 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2009/05/05 01:30:28 | 000,016,440 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\DRIVERS\AtiPcie.sys – (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2009/04/28 14:26:52 | 001,152,000 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\viahduaa.sys – (VIAHdAudAddService)
DRV:64bit: - [2008/12/12 02:41:44 | 000,188,416 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\Rtlh64.sys – (RTL8169)
DRV:64bit: - [2008/01/20 22:47:28 | 000,046,080 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2008/01/20 22:46:57 | 000,022,528 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\WSDPrint.sys – (WSDPrintDevice)
DRV:64bit: - [2008/01/20 22:46:53 | 001,523,712 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTDPV6.SYS – (VST64_DPV)
DRV:64bit: - [2008/01/20 22:46:53 | 000,724,480 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTCNXT6.SYS – (winachsf)
DRV:64bit: - [2008/01/20 22:46:53 | 000,392,704 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\VSTBS26.SYS – (VST64HWBS2)
DRV:64bit: - [2006/09/18 17:36:24 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\Wbem\ntfs.mof – (Ntfs)
DRV - [2010/04/10 17:05:56 | 000,009,728 | —- | M] (TheStubware.com) [Kernel | Boot | Stopped] – C:\Windows\SysWow64\drivers\TheStubwareDriver.SYS – (TheStubwareDriver)
DRV - [2010/04/10 17:01:56 | 000,044,032 | —- | M] (TheStubware.com) [Kernel | System | Stopped] – C:\Windows\SysWOW64\drivers\ActiveMonitor.SYS – (ActiveMonitor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2006/09/18 17:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TheStubware] C:\Program Files (x86)\TheStubware\TheStubware.exe (TheStubware.com)
O4 - HKCU..\Run: [Silverlight] C:\Users\S3ymour\AppData\Roaming\Silverlight.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O4 - Startup: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 [removed] [removed]
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\S3ymour\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/15 19:19:19 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/07/15 19:12:38 | 000,044,032 | —- | C] (TheStubware.com) – C:\Windows\SysWow64\drivers\ActiveMonitor.SYS
[2010/07/15 19:12:38 | 000,009,728 | —- | C] (TheStubware.com) – C:\Windows\SysWow64\drivers\TheStubwareDriver.SYS
[2010/07/15 19:12:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\TheStubware
[2010/07/15 19:09:57 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/07/15 19:09:51 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/07/15 19:09:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/07/15 19:09:40 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSSTDFMT.DLL
[2010/07/15 19:09:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\SpywareBlaster
[2010/07/15 18:53:49 | 000,000,000 | —D | C] – C:\Users\S3ymour\AppData\Roaming\QuickScan
[2010/07/15 18:44:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\Avg
[2010/07/15 18:41:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/07/15 18:40:42 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/06/25 03:01:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2010/06/23 13:28:34 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2010/06/23 13:28:34 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSNP.ax
[2010/06/23 13:28:31 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2010/06/23 13:28:31 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2010/06/23 13:28:31 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2010/06/23 13:28:18 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2010/06/23 13:28:18 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2010/06/23 13:28:18 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2010/06/23 13:28:18 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2010/06/23 08:45:04 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Apphlpdm.dll
[2010/06/23 08:45:03 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\SysWow64\GameUXLegacyGDFs.dll

========== Files - Modified Within 30 Days ==========

[2010/07/16 10:40:53 | 002,097,152 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT
[2010/07/16 10:35:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 10:35:18 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 10:30:34 | 000,000,734 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts.new
[2010/07/16 10:13:59 | 000,000,916 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-717218054-4078819399-4181070963-1000UA.job
[2010/07/16 10:13:08 | 000,524,288 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/07/16 10:13:08 | 000,065,536 | -HS- | M] () – C:\Users\S3ymour\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/07/16 09:37:33 | 062,044,352 | —- | M] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/16 08:02:16 | 001,987,940 | -H– | M] () – C:\Users\S3ymour\AppData\Local\IconCache.db
[2010/07/16 01:14:00 | 000,000,864 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-717218054-4078819399-4181070963-1000Core.job
[2010/07/16 01:13:01 | 000,000,939 | —- | M] () – C:\Windows\SysNative\nt.bat
[2010/07/15 19:37:56 | 001,033,616 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/07/15 19:37:56 | 000,250,638 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/07/15 19:37:56 | 000,005,534 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/07/15 19:31:34 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/15 19:31:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/15 19:12:39 | 000,000,882 | —- | M] () – C:\Users\S3ymour\Desktop\TheStubware.lnk
[2010/07/15 19:10:11 | 000,001,121 | —- | M] () – C:\Users\S3ymour\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/15 19:09:44 | 000,000,842 | —- | M] () – C:\Users\S3ymour\Desktop\SpywareBlaster.lnk
[2010/07/15 18:44:33 | 000,013,048 | —- | M] () – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 18:44:33 | 000,001,689 | —- | M] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/07/15 18:44:31 | 000,317,520 | —- | M] () – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 18:44:25 | 000,269,904 | —- | M] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/15 18:44:23 | 000,035,536 | —- | M] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/15 18:44:22 | 000,113,461 | —- | M] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/13 20:45:27 | 000,119,239 | —- | M] () – C:\Users\S3ymour\Documents\Verizon Wireless - Pay Bill Confirmation.pdf
[2010/07/07 22:03:06 | 000,000,680 | —- | M] () – C:\Users\S3ymour\AppData\Local\d3d9caps.dat
[2010/06/29 19:26:22 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/25 11:32:24 | 000,074,716 | —- | M] () – C:\Users\S3ymour\Documents\Volkswagen Credit – One-time Payment Confirmation.pdf
[2010/06/21 18:00:20 | 000,019,981 | —- | M] () – C:\Users\S3ymour\Documents\rubber band trick.odt

========== Files Created - No Company Name ==========

[2010/07/15 19:12:39 | 000,000,882 | —- | C] () – C:\Users\S3ymour\Desktop\TheStubware.lnk
[2010/07/15 19:10:11 | 000,001,121 | —- | C] () – C:\Users\S3ymour\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2010/07/15 19:09:44 | 000,000,842 | —- | C] () – C:\Users\S3ymour\Desktop\SpywareBlaster.lnk
[2010/07/15 18:44:33 | 000,001,689 | —- | C] () – C:\Users\Public\Desktop\AVG Free 9.0.lnk
[2010/07/15 18:44:31 | 000,013,048 | —- | C] () – C:\Windows\SysNative\avgrssta.dll
[2010/07/15 18:44:30 | 000,317,520 | —- | C] () – C:\Windows\SysNative\drivers\avgtdia.sys
[2010/07/15 18:44:24 | 000,269,904 | —- | C] () – C:\Windows\SysNative\drivers\avgldx64.sys
[2010/07/15 18:44:22 | 062,044,352 | —- | C] () – C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/07/15 18:44:22 | 000,113,461 | —- | C] () – C:\Windows\SysNative\drivers\Avg\iavichjw.avm
[2010/07/15 18:44:22 | 000,035,536 | —- | C] () – C:\Windows\SysNative\drivers\avgmfx64.sys
[2010/07/04 19:28:02 | 000,143,360 | —- | C] () – C:\Windows\STARTME.exe
[2010/07/04 19:28:02 | 000,143,360 | —- | C] () – C:\STARTME.exe
[2010/06/29 19:26:22 | 000,001,917 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/06/25 11:32:22 | 000,074,716 | —- | C] () – C:\Users\S3ymour\Documents\Volkswagen Credit – One-time Payment Confirmation.pdf
[2010/06/23 13:28:34 | 000,227,328 | —- | C] () – C:\Windows\SysNative\mpg2splt.ax
[2010/06/23 13:28:34 | 000,101,376 | —- | C] () – C:\Windows\SysNative\MSNP.ax
[2010/06/23 13:28:31 | 000,558,592 | —- | C] () – C:\Windows\SysNative\EncDec.dll
[2010/06/23 13:28:31 | 000,375,808 | —- | C] () – C:\Windows\SysNative\psisdecd.dll
[2010/06/23 13:28:31 | 000,289,792 | —- | C] () – C:\Windows\SysNative\psisrndr.ax
[2010/06/23 13:28:18 | 001,942,856 | —- | C] () – C:\Windows\SysNative\dfshim.dll
[2010/06/23 13:28:18 | 000,444,752 | —- | C] () – C:\Windows\SysNative\mscoree.dll
[2010/06/23 13:28:18 | 000,320,352 | —- | C] () – C:\Windows\SysNative\PresentationHost.exe
[2010/06/23 13:28:18 | 000,109,912 | —- | C] () – C:\Windows\SysNative\PresentationHostProxy.dll
[2010/06/23 13:28:18 | 000,048,960 | —- | C] () – C:\Windows\SysNative\netfxperf.dll
[2010/06/23 08:45:04 | 000,032,256 | —- | C] () – C:\Windows\SysNative\Apphlpdm.dll
[2010/06/23 08:45:03 | 004,240,384 | —- | C] () – C:\Windows\SysNative\GameUXLegacyGDFs.dll
[2010/06/21 18:00:17 | 000,019,981 | —- | C] () – C:\Users\S3ymour\Documents\rubber band trick.odt
[2010/05/03 19:19:31 | 000,000,110 | —- | C] () – C:\Windows\{7E7D778E-121D-4BBD-BA29-FAA81B9FBD8C}_WiseFW.ini
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2008/01/20 22:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 22:49:49 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
< End of report >
**********************************
OTL Extras logfile created on: 7/16/2010 10:40:38 AM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\S3ymour\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 459.50 Gb Free Space | 77.08% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: S3YMOUR-PC
Current User Name: S3ymour
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – C:\Users\S3ymour\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" File not found
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" ()
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l ()
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02B91901-B752-4616-9D9E-D7E18A825922}" = rport=10243 | protocol=6 | dir=out | app=system |
"{071E94FF-0FB4-44ED-B528-6FDB88AC6DDC}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{09C4C23B-69D8-458F-96B2-EE1841D72673}" = rport=445 | protocol=6 | dir=out | app=system |
"{108D355C-696F-4D5C-A75B-9F9ECF5F5A3E}" = lport=2869 | protocol=6 | dir=in | app=system |
"{142C709F-8705-4B37-BFBB-6E90DFBAB9EA}" = rport=137 | protocol=17 | dir=out | app=system |
"{35CEB676-0E5B-4ABA-AEDB-B3713A4F35ED}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{3A4C7909-3742-40A6-9755-A66C197ADD75}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{40AF35A7-40D9-4BA4-95E5-64E44AB465E7}" = lport=445 | protocol=6 | dir=in | app=system |
"{44A0D924-2FD5-4A39-A72A-E3010AA36A15}" = lport=138 | protocol=17 | dir=in | app=system |
"{4B642F71-AC4B-404C-8529-1BE0A19F3FC1}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4E0DF76F-6630-4146-83F3-CEC2A92856E7}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{57431551-B353-498B-A15E-4395C2495618}" = lport=139 | protocol=6 | dir=in | app=system |
"{5DBD489B-B578-4FEE-8E7F-A867CE0C3FB0}" = rport=139 | protocol=6 | dir=out | app=system |
"{6A23914F-183D-471F-94C5-8464A821267B}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{835E3590-4680-41AC-8DCF-82079054231A}" = rport=138 | protocol=17 | dir=out | app=system |
"{8620EF64-1D29-475A-AA63-9449321C0E61}" = lport=10243 | protocol=6 | dir=in | app=system |
"{A61984F4-86BC-4E20-97AF-538AFBCF521E}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D7481A5E-3859-4C43-B693-2D24016C4EF4}" = lport=137 | protocol=17 | dir=in | app=system |
"{F7A9A007-6B8A-4332-9785-3B8907CD9C21}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{017D7D89-99F0-462C-AF63-6BD87E5272E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{0289DCE7-5711-4B4F-9994-0941726FD56E}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{059F2FE0-86F1-417F-BF7E-4443EB04CA74}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{07BCD401-0932-409F-9493-9673F4346535}" = dir=in | app=c:\program files (x86)\avg\avg9\avgnsa.exe |
"{0F6FA451-2F2F-48DD-BA2E-08567D1E58A7}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{1ACBBC3C-6895-4F9E-A0FE-1A59AAB53A61}" = dir=in | app=c:\program files (x86)\avg\avg9\avgupd.exe |
"{290EC4F2-0826-45DD-91C5-E5986404B10E}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3711A8D6-B302-4854-A766-137B3F85F198}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{46690E88-CC63-45EA-9A48-2858716D188A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{47048B4E-7960-4A30-A707-3037CA518CFA}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{51BBC386-2724-42EF-ADDF-6EF0F7486B2F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{5C65390F-3907-444F-A40F-2FCF80CBDC16}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{630D8919-EB5B-484C-93EB-8193A2A8A5F4}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{73912051-FF87-4E44-91DB-7150FE30B796}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7595F797-A7AB-478C-87AD-DEA6A878AD4B}" = protocol=6 | dir=out | app=system |
"{76256F75-2511-46E2-96E3-9B365B8EA7A5}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7D06721B-6648-49A1-BF5B-48E6C8A0D244}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{91BB38F7-E22A-44D9-ADFE-1B3B2EE55323}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{9AB4F3D2-155C-465A-A960-F88C21B6FACC}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{AEC5E466-7B9F-4F5C-A6E7-22C5EFD19E7A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{B39FCD9E-CAE6-4F20-A0ED-824759AD4BFF}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{BE652749-511D-4790-80B9-39148BD94FA3}" = dir=in | app=c:\program files (x86)\avg\avg9\avgemc.exe |
"{C9AAF35E-D240-409B-93CF-46EBB52460F6}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D94706D8-E3D6-4240-8049-83DA785D1640}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |
"{DF7584B8-C18B-430D-820B-0D49A01FDA59}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E0978ACD-E440-4D9B-8133-3A5E5A4F9244}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EDEAC8E2-5ED6-4AC5-AB99-5A2EA0567F08}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EF30D827-2637-4BFE-AC4A-83E5B1A0BF5A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{F20C5155-1981-4D05-9957-C5C73E88C0DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1D7F8784-001D-38D6-DCC6-5174D250C811}" = ATI Catalyst Install Manager
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6E2FA73-B2A7-8223-98EC-685E2E8F6CE0}" = ccc-utility64
"781745E87AFF80C0C1388CFF79D19ECAB2E9BB47" = Windows Driver Package - LeapFrog (FlyUsb) USB (11/05/2008 1.1.1.0)
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0A169B94-4AF2-AD4B-1265-E1074A347418}" = Catalyst Control Center Core Implementation
"{0F15BB9F-7E5E-A355-FA8E-C2164726E577}" = CCC Help Portuguese
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 18
"{277832E3-0A34-C91C-D344-2FED4C847397}" = CCC Help German
"{279355E6-EE94-A7A5-F6B5-2903748443AE}" = Catalyst Control Center Graphics Full New
"{290AC453-D1F4-F73B-F01C-0018BC10B62B}" = ccc-core-static
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{39A3C9DD-457C-5BF1-4B2D-A76927264B26}" = CCC Help Dutch
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AA3D64E-9EC3-4B0F-AB91-5885AC55641F}" = Microsoft Games for Windows - LIVE
"{4E868D3D-6EEB-4273-926C-2287236B5B79}" = 3DVIA player 5.0
"{5AC4AE26-732F-40DE-CC6C-A4BFC2142BF8}" = CCC Help English
"{665B3CA4-DAB1-D27E-6727-0BEF6593E882}" = CCC Help Greek
"{674AD787-B463-ED3E-CCA8-4F49A9C1785D}" = Catalyst Control Center Localization All
"{6ADD0603-16EF-400D-9F9E-486432835002}" = OpenOffice.org 3.2
"{7009600B-85C8-5D83-1101-6446540F1897}" = Catalyst Control Center Graphics Previews Common
"{7305AE01-CD11-18B5-DC5F-B1A2960935C3}" = CCC Help Polish
"{7E15C4B8-85FC-4539-94F2-8280C0B213A3}" = LeapFrog Tag Plugin
"{7E7D778E-121D-4BBD-BA29-FAA81B9FBD8C}" = LeapFrog Connect
"{7FCC4EDC-6EE2-4309-ABD7-85F2667A7B90}" = WebEx Support Manager for Internet Explorer
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83BBF5E6-004F-1DBA-EC29-1033B675831B}" = CCC Help Thai
"{8508FB72-89A3-41FD-DE33-9EEBFB298947}" = CCC Help Italian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{97835E04-BA21-6878-768F-1B84EA2ADAC1}" = CCC Help Norwegian
"{A192CA8A-5259-ECD5-1564-AB715B722432}" = CCC Help Japanese
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B31327DF-2B59-F072-8B44-79CDE915D75E}" = CCC Help Danish
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B41423C9-C260-F8C8-39DD-541400ECF367}" = CCC Help French
"{C6CBE669-DDCA-DB7F-236D-18B20BEFF1B5}" = CCC Help Chinese Traditional
"{CA7D81F8-5661-3D97-F6B0-5E0993511A5D}" = CCC Help Finnish
"{D069C7EF-001B-5378-9F71-F005DE42E255}" = Catalyst Control Center Graphics Light
"{D2A7D7D8-1E27-8464-6666-44B6FB83B3FC}" = CCC Help Czech
"{D86DE1ED-9BF1-6101-6D08-2D762B28D8C8}" = CCC Help Korean
"{E1A8F958-D748-63DD-F2D2-82BE71B0F905}" = CCC Help Hungarian
"{E40A74A2-D821-2442-CCA3-75C54964D525}" = Catalyst Control Center Graphics Full Existing
"{E43ACD6B-0E7E-4F4C-0BA8-999FCB5FC5B9}" = CCC Help Chinese Standard
"{E481DB0E-52F2-4EE0-9BDA-9EE173FA6EA2}" = Catalyst Control Center - Branding
"{E9684BDD-32A6-550C-6456-0A4209EB4F3A}" = CCC Help Russian
"{F05F2DB5-4300-C318-4560-08CD9E35F512}" = CCC Help Spanish
"{F1D038D6-6229-AA2E-A8D1-43EED2CBF0BD}" = CCC Help Swedish
"{F322850C-6CCB-FC54-D36D-0F4E1CC90CBF}" = Skins
"{F527F14E-B80A-5BE7-DC85-8BF2D172067F}" = CCC Help Turkish
"{FF4F3E30-6638-6A16-2A68-139F6C613233}" = Catalyst Control Center Graphics Previews Vista
"{FFB07785-9FC3-334F-A54F-AC8D5B471EAE}" = Catalyst Control Center InstallProxy
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AVG9Uninstall" = AVG Free 9.0
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"SpywareBlaster_is1" = SpywareBlaster 4.3
"Steam App 15620" = Warhammer 40,000: Dawn of War II
"TagPlugin" = Use the entry named LeapFrog Connect to uninstall (LeapFrog Tag Plugin)
"TheStubware 1.7.8_is1" = TheStubware 1.7.8
"UPCShell" = LeapFrog Connect
"VLC media player" = VLC media player 1.0.1

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/19/2010 8:36:20 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 12bc Start Time: 01cb100e879e8e88 Termination Time: 22

Error - 6/19/2010 8:42:09 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 8a8 Start Time: 01cb1010ac242838 Termination Time: 21

Error - 6/23/2010 1:46:12 PM | Computer Name = S3ymour-PC | Source = WinMgmt | ID = 10
Description =

Error - 6/23/2010 1:51:09 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3012
Description =

Error - 6/23/2010 1:51:09 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3011
Description =

Error - 6/25/2010 3:04:28 AM | Computer Name = S3ymour-PC | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 6/29/2010 8:39:45 PM | Computer Name = S3ymour-PC | Source = WinMgmt | ID = 10
Description =

Error - 6/29/2010 8:42:26 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3012
Description =

Error - 6/29/2010 8:42:26 PM | Computer Name = S3ymour-PC | Source = LoadPerf | ID = 3011
Description =

Error - 6/30/2010 1:24:42 PM | Computer Name = S3ymour-PC | Source = Application Hang | ID = 1002
Description = The program chrome.exe version 0.0.0.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 6d0 Start Time: 01cb187845c9c3c0 Termination Time: 5

[ System Events ]
Error - 6/19/2010 9:04:58 AM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =

Error - 6/19/2010 9:06:11 AM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10016
Description =

Error - 6/23/2010 1:44:59 PM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =

Error - 6/23/2010 1:46:23 PM | Computer Name = S3ymour-PC | Source = Print | ID = 54
Description = Document https://services.actstudent.org/OA_HTML/act…cdAdmTicket.jsp
failed to print and was deleted because of corruption in the spooled file. The
associated driver is: HP DeskJet 970Cxi. Try printing the document again.

Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10005
Description =

Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 6/29/2010 7:26:20 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 6/29/2010 8:38:08 PM | Computer Name = S3ymour-PC | Source = HTTP | ID = 15016
Description =

Error - 6/29/2010 8:39:32 PM | Computer Name = S3ymour-PC | Source = DCOM | ID = 10016
Description =

Error - 6/30/2010 1:17:48 PM | Computer Name = S3ymour-PC | Source = Service Control Manager | ID = 7011
Description =


< End of report >
*****************************************

Thanks for the help!
Posted Image


Click: Start > All Programs> Accessories
Open Notepad, click on Format and uncheck Word Wrap.


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

XP Users

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.



Please do not delete anything unless instructed to.


We've been seeing some Java infections lately.
Go here and follow the instructions to clear your Java Cache


Next:

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • [external image: Posted Image]
  • Then click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.


Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste".
Well according to the scan log no malware was detected. See below: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4321 Windows 6.0.6001 Service Pack 1 Internet Explorer 8.0.6001.18928 7/17/2010 9:40:09 AM mbam-log-2010-07-17 (09-40-09).txt Scan type: Quick scan Objects scanned: 131942 Time elapsed: 3 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step



Download TDSSKiller and save it to your Desktop.
Once completed it will create a log in your C:\ drive called TDSSKiller_*** (*** denotes version & date)
  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone
please post the contents of that log TDSSKiller and GooredFix log.
No more link hijacks happening now. Here are the log posts: GooredFix by jpshortstuff (03.07.10.1) Log created at 12:28 on 17/07/2010 (S3ymour) Firefox version [Unable to determine] ========== GooredScan ========== ========== GooredLog ========== C:\Program Files (x86)\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [07:01 27/03/2010] -=E.O.F=- ************************************* Unable to run TDSSKiller, the utility doesn't support 64 bit operating systems - attached screen shot of the error it gave;

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI