This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

search engine redirect

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Every time I go on google or yahoo to search for something another search engine pops up when i click on a link. I have McAfee and its not picking up anything. I've also tried Malwarebytes and that isn't helping any either. If anybody has any ideas I could use the help. Thanks



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:14:09 PM, on 7/21/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Sheena\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=aspire_r1600
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=aspire_r1600
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=aspire_r1600
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O1 - Hosts: 89.149.210.113 www.google.com
O1 - Hosts: 89.149.210.113 us.
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [EarthLink Installer] " /C
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Download All using 4shared Desktop - C:\Program Files\4shared Desktop\down_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
O16 - DPF: {20722C4E-9050-45C8-8D1A-816C4A06AD90} (Photo Upload Plugin Class) - http://www.cvsphoto.com/upload/activex/v3_…veX_Control.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 11182 bytes
Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:


Copy and paste these lines in Notepad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop. Double click to run.
*** note: Win Vista and Win 7 need to right click and choose to "run as Administrator" .. the computer will reboot itself.

After reboot"

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Its running a little slow and the windows media player isnt working and when I try to uninstall my Mcafee so i can install AVG it will not let me

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 4:43:03 PM, on 7/22/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17055)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\DivX\DivX Update\DivXUpdate.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Sheena\My Documents\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=aspire_r1600
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=aspire_r1600
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…;m=aspire_r1600
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [EgisTecLiveUpdate] "C:\Program Files\EgisTec Egis Software Update\EgisUpdate.exe"
O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CarboniteSetupLite] "C:\Program Files\Carbonite\CarbonitePreinstaller.exe" /preinstalled
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RemoteControl8] "C:\Program Files\CyberLink\PowerDVD8\PDVD8Serv.exe"
O4 - HKLM\..\Run: [PDVD8LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD8\Language\Language.exe"
O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
O4 - HKLM\..\Run: [EarthLink Installer] " /C
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Download All using 4shared Desktop - C:\Program Files\4shared Desktop\down_all.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20722C4E-9050-45C8-8D1A-816C4A06AD90} (Photo Upload Plugin Class) - http://www.cvsphoto.com/upload/activex/v3_…veX_Control.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe (file missing)
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

–
End of file - 10707 bytes
Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
ComboFix 10-07-22.01 - Sheena 07/22/2010 18:21:29.1.2 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.895.629 [GMT -4:00] Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat c:\documents and settings\Sheena\Application Data\.# c:\documents and settings\Sheena\Application Data\.#\MBX@1238@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@1238@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@1238@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@1B0@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@1B0@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@1B0@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@654@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@654@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@654@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@824@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@824@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@824@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@864@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@864@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@864@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@88C@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@88C@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@88C@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@ACC@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@ACC@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@ACC@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@B2C@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@B2C@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@B2C@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@C0C@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@C0C@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@C0C@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@D74@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@D74@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@D74@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@EC@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@EC@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@EC@394200.### c:\documents and settings\Sheena\Application Data\.#\MBX@FB4@3941A0.### c:\documents and settings\Sheena\Application Data\.#\MBX@FB4@3941D0.### c:\documents and settings\Sheena\Application Data\.#\MBX@FB4@394200.### c:\windows\Downloaded Program Files\popcaploader.dll c:\windows\Downloaded Program Files\popcaploader.inf —– BITS: Possible infected sites —– hxxp://ads1.msads.net . ((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 ))))))))))))))))))))))))))))))) . 2010-07-20 23:50 . 2010-07-20 23:52 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp 2010-07-20 23:49 . 2010-07-20 23:49 ——– d—–w- c:\windows\system32\wbem\Repository 2010-07-20 23:49 . 2010-07-20 23:49 ——– d—–w- c:\program files\McAfee.com 2010-07-20 23:46 . 2009-08-13 01:33 ——– d—–w- c:\documents and settings\Administrator\Local Settings\Application Data\EgisTec 2010-07-17 01:05 . 2010-07-17 01:05 ——– d—–w- C:\$AVG 2010-07-17 00:11 . 2010-07-17 00:11 12536 —-a-w- c:\windows\system32\avgrsstx(2).dll 2010-07-17 00:11 . 2010-07-20 21:39 ——– d—–w- c:\windows\system32\drivers\Avg(2) 2010-07-17 00:05 . 2010-07-20 23:49 ——– d—–w- c:\program files\AVG(2) 2010-07-17 00:04 . 2010-07-21 23:02 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9 2010-07-06 22:27 . 2010-07-06 22:27 ——– d—–w- c:\documents and settings\Sheena\Local Settings\Application Data\xvyblaiwu . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-22 21:23 . 2009-08-13 01:44 ——– d—–w- c:\program files\Acer GameZone 2010-07-20 23:56 . 2010-06-01 18:35 ——– d—–w- c:\program files\LimeWire 2010-07-20 23:48 . 2010-07-20 23:48 ——– d—–w- c:\program files\McAfee 2010-07-20 23:48 . 2010-07-20 23:48 ——– d—–w- c:\program files\Common Files\McAfee 2010-07-17 00:25 . 2009-08-13 01:33 ——– d—–w- c:\documents and settings\All Users\Application Data\McAfee 2010-07-16 23:10 . 2010-05-25 22:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater 2010-06-14 14:31 . 2009-08-13 00:58 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe 2010-06-08 22:42 . 2009-08-13 01:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help 2010-06-01 21:23 . 2010-06-01 18:49 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink 2010-06-01 18:49 . 2010-06-01 18:49 ——– d—–w- c:\documents and settings\Sheena\Application Data\CyberLink 2010-05-25 22:45 . 2009-08-13 01:21 ——– d—–w- c:\program files\Google 2010-05-23 16:49 . 2010-05-23 16:49 348160 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6dc5bc19-n\msvcr71.dll 2010-05-23 16:49 . 2010-05-23 16:49 503808 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6dc5bc19-n\msvcp71.dll 2010-05-23 16:49 . 2010-05-23 16:49 61440 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-14603739-n\decora-sse.dll 2010-05-23 16:49 . 2010-05-23 16:49 499712 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6dc5bc19-n\jmc.dll 2010-05-23 16:49 . 2010-05-23 16:49 12800 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-14603739-n\decora-d3d.dll 2010-05-23 00:04 . 2010-05-23 00:05 411368 —-a-w- c:\windows\system32\deploytk.dll 2010-05-16 23:51 . 2010-03-20 19:26 60664 —-a-w- c:\documents and settings\Sheena\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-05-04 17:20 . 2009-08-13 01:44 832512 —-a-w- c:\windows\system32\wininet.dll 2010-05-04 17:20 . 2009-08-13 01:44 78336 —-a-w- c:\windows\system32\ieencode.dll 2010-05-04 17:20 . 2009-08-13 01:44 17408 —-a-w- c:\windows\system32\corpol.dll 2010-05-02 05:22 . 2009-08-13 01:44 1851264 —-a-w- c:\windows\system32\win32k.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2009-05-15 06:02 120104 —-a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-20 68856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "nwiz"="nwiz.exe" [2009-05-24 1657376] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-24 86016] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-24 13758464] "RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-11 30192] "EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-05-14 199464] "mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-05-15 345384] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672] "CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2008-10-03 294544] "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952] "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392] "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168] "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168] "RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432] "PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-02-11 1218008] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\drivers\mwlPSDFilter.sys [12/4/2008 9:34 PM 17840] R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\drivers\mwlPSDNserv.sys [12/4/2008 9:34 PM 15280] R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\drivers\mwlPSDVDisk.sys [12/4/2008 9:34 PM 58800] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [8/12/2009 9:40 PM 93320] R2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe [5/15/2009 2:03 AM 305448] R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [8/12/2009 9:45 PM 46752] S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/13/2010 4:54 PM 135664] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [8/12/2009 9:13 PM 1684736] S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/12/2009 9:21 PM 30192] . Contents of the 'Scheduled Tasks' folder 2010-07-22 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-20 22:34] 2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 20:54] 2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 20:54] . . ——- Supplementary Scan ——- . uStart Page = hxxp://www.google.com/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0310&m=aspire_r1600 IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_2EC7709873947E87.dll/cmsidewiki.html DPF: {20722C4E-9050-45C8-8D1A-816C4A06AD90} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_6/PhotoCenter_ActiveX_Control.cab . - - - - ORPHANS REMOVED - - - - HKLM-Run-EarthLink Installer - (no file) ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'winlogon.exe'(464) c:\windows\system32\WININET.dll - - - - - - - > 'lsass.exe'(524) c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(3052) c:\windows\system32\WININET.dll c:\program files\EgisTec\MyWinLocker 3\x86\psdprotect.dll c:\program files\EgisTec\MyWinLocker 3\x86\sysenv.dll c:\program files\EgisTec\MyWinLocker 3\x86\XmlLite.dll c:\windows\system32\ieframe.dll . ———————— Other Running Processes ———————— . c:\windows\system32\nvsvc32.exe c:\program files\Java\jre6\bin\jqs.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\mcafee\mna\mcnasvc.exe c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe c:\program files\McAfee\MPF\MPFSrv.exe c:\program files\McAfee\MSK\MskSrver.exe c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe c:\progra~1\mcafee.com\agent\mcagent.exe c:\windows\system32\wscntfy.exe c:\windows\RTHDCPL.EXE c:\program files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe . ************************************************************************** . Completion time: 2010-07-22 18:37:38 - machine was rebooted ComboFix-quarantined-files.txt 2010-07-22 22:37 Pre-Run: 128,397,848,576 bytes free Post-Run: 128,546,009,088 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect - - End Of File - - CBF2F33004256BA64BCD49803A614F1C
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\program files\McAfee.com\Agent\mcagent.exe
c:\Program Files\Common Files\McAfee\MNA\McNASvc.exe

Folder::
c:\documents and settings\Sheena\Local Settings\Application Data\xvyblaiwu
c:\program files\McAfee
c:\program files\Common Files\McAfee
c:\documents and settings\All Users\Application Data\McAfee
c:\program files\McAfee.com\Agent

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Some sites or still being redirected

ComboFix 10-07-22.01 - Sheena 07/22/2010 21:07:35.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.895.660 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Sheena\Desktop\CFScript.txt

FILE ::
"c:\program files\Common Files\McAfee\MNA\McNASvc.exe"
"c:\program files\McAfee.com\Agent\mcagent.exe"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Application Data\McAfee
c:\documents and settings\All Users\Application Data\McAfee\HackerWatch\data\HwLocal.xdb
c:\documents and settings\All Users\Application Data\McAfee\HackerWatch\data\HwShared.xdb
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\Install001.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\Common\Install\log.ini
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MasterInstaller\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McInst\rmoldfile.inf000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McMSCIns\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\McProxy\mcproxy\mcproxy000.log
c:\documents and settings\All Users\Application Data\McAfee\MCLOGS\MISP\Install\Install000.log
c:\documents and settings\All Users\Application Data\McAfee\MSC\Cache\McSubDB.Bak
c:\documents and settings\All Users\Application Data\McAfee\MSC\Logs\settings.dat
c:\documents and settings\All Users\Application Data\McAfee\MSC\mcini.ini
c:\documents and settings\All Users\Application Data\McAfee\MSC\McSubDB.Dat
c:\documents and settings\Sheena\Local Settings\Application Data\xvyblaiwu
c:\program files\Common Files\McAfee
c:\program files\Common Files\McAfee\Core\mccore.inf
c:\program files\Common Files\McAfee\Core\mccoreps.dll
c:\program files\Common Files\McAfee\Core\McEvtBrk.dll
c:\program files\Common Files\McAfee\Core\mchost.exe
c:\program files\Common Files\McAfee\FWDriver\fwdrv.inf
c:\program files\Common Files\McAfee\FWDriver\fwdrvins.exe
c:\program files\Common Files\McAfee\FWDriver\fwdrvver.dll
c:\program files\Common Files\McAfee\FWDriver\mpfp.cat
c:\program files\Common Files\McAfee\FWDriver\mpfp.sys
c:\program files\Common Files\McAfee\FWDriver\Vista\fwdrvex.inf
c:\program files\Common Files\McAfee\HackerWatch\HWAPI.dll
c:\program files\Common Files\McAfee\HackerWatch\hwapi.inf
c:\program files\Common Files\McAfee\HackerWatch\hwupdchk.exe
c:\program files\Common Files\McAfee\McProxy\McProxy.exe
c:\program files\Common Files\McAfee\McProxy\McProxy.inf
c:\program files\Common Files\McAfee\McProxy\Proxyver.dll
c:\program files\Common Files\McAfee\McProxy\rmoldfile.inf
c:\program files\Common Files\McAfee\McSvcHost\McSHIns.dll
c:\program files\Common Files\McAfee\McSvcHost\McSvcHost.inf
c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe
c:\program files\Common Files\McAfee\McSvcHost\McSvHVer.dll
c:\program files\Common Files\McAfee\MNA\McAltHPS.dll
c:\program files\Common Files\McAfee\MNA\McAltHst.exe
c:\program files\Common Files\McAfee\MNA\McNaIns.dll
c:\program files\Common Files\McAfee\MNA\McNAReg.dll
c:\program files\Common Files\McAfee\MNA\McNARgPS.dll
c:\program files\Common Files\McAfee\MNA\McNASvc.dll
c:\program files\Common Files\McAfee\MNA\McNASvPS.dll
c:\program files\Common Files\McAfee\MNA\McNAVer.dll
c:\program files\Common Files\McAfee\MNA\McTrstPS.dll
c:\program files\Common Files\McAfee\MNA\mna32.inf
c:\program files\McAfee
c:\program files\McAfee.com\Agent
c:\program files\McAfee.com\Agent\mcscentr.adf
c:\program files\McAfee\MSC\1033\instLD.inf
c:\program files\McAfee\MSC\1033\msclcres.inf
c:\program files\McAfee\MSC\1033\mscpstLD.inf
c:\program files\McAfee\MSC\mscdfoem.inf
c:\program files\McAfee\MSC\mscLD.inf
c:\program files\McAfee\MSC\mscLI.inf
c:\program files\McAfee\MSC\mscuicfg.dat
c:\program files\McAfee\MSC\MSFix.inf
c:\program files\McAfee\MSC\override.inf
c:\program files\McAfee\MSC\subst.inf
c:\program files\McAfee\MSC\subst2.inf
c:\program files\McAfee\Temp\qxz164\actwizui.inf
c:\program files\McAfee\Temp\qxz164\av.inf
c:\program files\McAfee\Temp\qxz164\avap.inf
c:\program files\McAfee\Temp\qxz164\cfwids.cat
c:\program files\McAfee\Temp\qxz164\cfwids.inf
c:\program files\McAfee\Temp\qxz164\cfwids.sys
c:\program files\McAfee\Temp\qxz164\DAInstall.exe
c:\program files\McAfee\Temp\qxz164\extra.rul
c:\program files\McAfee\Temp\qxz164\Fix519818.exe
c:\program files\McAfee\Temp\qxz164\ftl.dll
c:\program files\McAfee\Temp\qxz164\fw.inf
c:\program files\McAfee\Temp\qxz164\HWAPI.dll
c:\program files\McAfee\Temp\qxz164\hwapi.inf
c:\program files\McAfee\Temp\qxz164\HwLocal.xdb
c:\program files\McAfee\Temp\qxz164\HWUpdChk.exe
c:\program files\McAfee\Temp\qxz164\InstProg.dll
c:\program files\McAfee\Temp\qxz164\langmap.dat
c:\program files\McAfee\Temp\qxz164\LangSel.dll
c:\program files\McAfee\Temp\qxz164\lockdown.dll
c:\program files\McAfee\Temp\qxz164\mcactui.dll
c:\program files\McAfee\Temp\qxz164\mcactui.inf
c:\program files\McAfee\Temp\qxz164\mcactwiz.dll
c:\program files\McAfee\Temp\qxz164\mcactwiz.inf
c:\program files\McAfee\Temp\qxz164\mcactwiz_ld.dll
c:\program files\McAfee\Temp\qxz164\mcafee.html
c:\program files\McAfee\Temp\qxz164\mcagent.exe
c:\program files\McAfee\Temp\qxz164\mcagntps.dll
c:\program files\McAfee\Temp\qxz164\mcawlang.inf
c:\program files\McAfee\Temp\qxz164\mcbrwsr2.dll
c:\program files\McAfee\Temp\qxz164\mccore.inf
c:\program files\McAfee\Temp\qxz164\McCorePS.dll
c:\program files\McAfee\Temp\qxz164\McDBMgr.dll
c:\program files\McAfee\Temp\qxz164\McDisc.dll
c:\program files\McAfee\Temp\qxz164\McDiscPS.dll
c:\program files\McAfee\Temp\qxz164\McDspWrp.dll
c:\program files\McAfee\Temp\qxz164\mcdspwrp.inf
c:\program files\McAfee\Temp\qxz164\McEvtBrk.dll
c:\program files\McAfee\Temp\qxz164\McGsShm.dll
c:\program files\McAfee\Temp\qxz164\McHNShim.dll
c:\program files\McAfee\Temp\qxz164\McHNShPS.dll
c:\program files\McAfee\Temp\qxz164\mchost.exe
c:\program files\McAfee\Temp\qxz164\mcinfo.exe
c:\program files\McAfee\Temp\qxz164\McIPTShm.dll
c:\program files\McAfee\Temp\qxz164\mclangmap.inf
c:\program files\McAfee\Temp\qxz164\McLib.lib
c:\program files\McAfee\Temp\qxz164\McLogShm.dll
c:\program files\McAfee\Temp\qxz164\mcltvers.ini
c:\program files\McAfee\Temp\qxz164\mclwapi.dll
c:\program files\McAfee\Temp\qxz164\McMISPPS.dll
c:\program files\McAfee\Temp\qxz164\mcmispps.inf
c:\program files\McAfee\Temp\qxz164\McMPFEvt.dll
c:\program files\McAfee\Temp\qxz164\mcmscins.dll
c:\program files\McAfee\Temp\qxz164\McMscShm.dll
c:\program files\McAfee\Temp\qxz164\mcmscsub.dll
c:\program files\McAfee\Temp\qxz164\McMscVer.dll
c:\program files\McAfee\Temp\qxz164\McNdAtpg.dll
c:\program files\McAfee\Temp\qxz164\McNDLor.dll
c:\program files\McAfee\Temp\qxz164\McNDSv.dll
c:\program files\McAfee\Temp\qxz164\McNDSVPS.dll
c:\program files\McAfee\Temp\qxz164\McNMAtpg.dll
c:\program files\McAfee\Temp\qxz164\McNmcIns.dll
c:\program files\McAfee\Temp\qxz164\McNmcLoR.dll
c:\program files\McAfee\Temp\qxz164\McNMCShell.exe
c:\program files\McAfee\Temp\qxz164\McNmcSPS.dll
c:\program files\McAfee\Temp\qxz164\McNmcSrv.dll
c:\program files\McAfee\Temp\qxz164\McNmcVer.dll
c:\program files\McAfee\Temp\qxz164\mcoemmgr.exe
c:\program files\McAfee\Temp\qxz164\mcoemmgr.inf
c:\program files\McAfee\Temp\qxz164\mcoemres.dll
c:\program files\McAfee\Temp\qxz164\mcoemres.inf
c:\program files\McAfee\Temp\qxz164\mcprlalt.dll
c:\program files\McAfee\Temp\qxz164\mcprlres.dll
c:\program files\McAfee\Temp\qxz164\McProxy.dll
c:\program files\McAfee\Temp\qxz164\McProxy.inf
c:\program files\McAfee\Temp\qxz164\McPrsShm.dll
c:\program files\McAfee\Temp\qxz164\McRegObj.dll
c:\program files\McAfee\Temp\qxz164\McRTMui.dll
c:\program files\McAfee\Temp\qxz164\mcscindx.dat
c:\program files\McAfee\Temp\qxz164\mcscrhlp.dll
c:\program files\McAfee\Temp\qxz164\McShield.dll
c:\program files\McAfee\Temp\qxz164\mcshield.exe
c:\program files\McAfee\Temp\qxz164\McSmpUI.dll
c:\program files\McAfee\Temp\qxz164\McSmtFWk.exe
c:\program files\McAfee\Temp\qxz164\mcsmtmsg.inf
c:\program files\McAfee\Temp\qxz164\McSmtStr.dll
c:\program files\McAfee\Temp\qxz164\McSmtTsk.dll
c:\program files\McAfee\Temp\qxz164\mcsubmgr.dll
c:\program files\McAfee\Temp\qxz164\mcsvrcnt.exe
c:\program files\McAfee\Temp\qxz164\mcsync.exe
c:\program files\McAfee\Temp\qxz164\mcuc.inf
c:\program files\McAfee\Temp\qxz164\McUiCfg.dll
c:\program files\McAfee\Temp\qxz164\McUICnt.exe
c:\program files\McAfee\Temp\qxz164\mcuihost.exe
c:\program files\McAfee\Temp\qxz164\mcuinshm.dll
c:\program files\McAfee\Temp\qxz164\mcuninst.exe
c:\program files\McAfee\Temp\qxz164\mcupdate.exe
c:\program files\McAfee\Temp\qxz164\McUpdMgr.exe
c:\program files\McAfee\Temp\qxz164\McUpdShm.dll
c:\program files\McAfee\Temp\qxz164\mcutil.dll
c:\program files\McAfee\Temp\qxz164\mcutil2.dll
c:\program files\McAfee\Temp\qxz164\mfeapfa.dll
c:\program files\McAfee\Temp\qxz164\mfeapfk.cat
c:\program files\McAfee\Temp\qxz164\mfeapfk.inf
c:\program files\McAfee\Temp\qxz164\mfeapfk.sys
c:\program files\McAfee\Temp\qxz164\mfeavfa.dll
c:\program files\McAfee\Temp\qxz164\mfeavfk.cat
c:\program files\McAfee\Temp\qxz164\mfeavfk.inf
c:\program files\McAfee\Temp\qxz164\mfeavfk.sys
c:\program files\McAfee\Temp\qxz164\mfebopa.dll
c:\program files\McAfee\Temp\qxz164\mfebopk.cat
c:\program files\McAfee\Temp\qxz164\mfebopk.inf
c:\program files\McAfee\Temp\qxz164\mfebopk.sys
c:\program files\McAfee\Temp\qxz164\mfeclnk.cat
c:\program files\McAfee\Temp\qxz164\mfeclnk.inf
c:\program files\McAfee\Temp\qxz164\mfeclnk.sys
c:\program files\McAfee\Temp\qxz164\mfefire.exe
c:\program files\McAfee\Temp\qxz164\mfefirek.cat
c:\program files\McAfee\Temp\qxz164\mfefirek.inf
c:\program files\McAfee\Temp\qxz164\mfefirek.sys
c:\program files\McAfee\Temp\qxz164\mfefwctl.dll
c:\program files\McAfee\Temp\qxz164\mfehida.dll
c:\program files\McAfee\Temp\qxz164\mfehidin.exe
c:\program files\McAfee\Temp\qxz164\mfehidk.cat
c:\program files\McAfee\Temp\qxz164\mfehidk.inf
c:\program files\McAfee\Temp\qxz164\mfehidk.sys
c:\program files\McAfee\Temp\qxz164\mfehidk_messages.dll
c:\program files\McAfee\Temp\qxz164\mfendisk.cat
c:\program files\McAfee\Temp\qxz164\mfendisk.inf
c:\program files\McAfee\Temp\qxz164\mfendisk.sys
c:\program files\McAfee\Temp\qxz164\mfendisk_m.cat
c:\program files\McAfee\Temp\qxz164\mfendisk_m.inf
c:\program files\McAfee\Temp\qxz164\mfenlfk.cat
c:\program files\McAfee\Temp\qxz164\mfenlfk.inf
c:\program files\McAfee\Temp\qxz164\mfenlfk.sys
c:\program files\McAfee\Temp\qxz164\mferkda.dll
c:\program files\McAfee\Temp\qxz164\mferkdet.cat
c:\program files\McAfee\Temp\qxz164\mferkdet.inf
c:\program files\McAfee\Temp\qxz164\mferkdet.sys
c:\program files\McAfee\Temp\qxz164\mfetdi2k.cat
c:\program files\McAfee\Temp\qxz164\mfetdi2k.inf
c:\program files\McAfee\Temp\qxz164\mfetdi2k.sys
c:\program files\McAfee\Temp\qxz164\mfevtpa.dll
c:\program files\McAfee\Temp\qxz164\mfevtps.exe
c:\program files\McAfee\Temp\qxz164\mfewfpk.cat
c:\program files\McAfee\Temp\qxz164\mfewfpk.inf
c:\program files\McAfee\Temp\qxz164\mfewfpk.sys
c:\program files\McAfee\Temp\qxz164\misplf.dll
c:\program files\McAfee\Temp\qxz164\mispreg.exe
c:\program files\McAfee\Temp\qxz164\msc\mscLI.inf
c:\program files\McAfee\Temp\qxz164\msccmn.inf
c:\program files\McAfee\Temp\qxz164\msccust.inf
c:\program files\McAfee\Temp\qxz164\mscinres.dll
c:\program files\McAfee\Temp\qxz164\mscjsres.dll
c:\program files\McAfee\Temp\qxz164\msclgmis.inf
c:\program files\McAfee\Temp\qxz164\mscmisc.inf
c:\program files\McAfee\Temp\qxz164\mscoobe.inf
c:\program files\McAfee\Temp\qxz164\mscprmgr.inf
c:\program files\McAfee\Temp\qxz164\mscpstLI.inf
c:\program files\McAfee\Temp\qxz164\mscreg.inf
c:\program files\McAfee\Temp\qxz164\mscrem.inf
c:\program files\McAfee\Temp\qxz164\mscres.inf
c:\program files\McAfee\Temp\qxz164\mscshll.inf
c:\program files\McAfee\Temp\qxz164\mscsvc.inf
c:\program files\McAfee\Temp\qxz164\mscuild.dll
c:\program files\McAfee\Temp\qxz164\mscuimgr.inf
c:\program files\McAfee\Temp\qxz164\mscupd.inf
c:\program files\McAfee\Temp\qxz164\mytilus3.dll
c:\program files\McAfee\Temp\qxz164\mytilus3_server.dll
c:\program files\McAfee\Temp\qxz164\mytilus3_worker.dll
c:\program files\McAfee\Temp\qxz164\naevent.dll
c:\program files\McAfee\Temp\qxz164\NaiEvent.dll
c:\program files\McAfee\Temp\qxz164\NMCJsRes.dll
c:\program files\McAfee\Temp\qxz164\nmcLI32.inf
c:\program files\McAfee\Temp\qxz164\nmcLI32_CD.inf
c:\program files\McAfee\Temp\qxz164\oemui.dll
c:\program files\McAfee\Temp\qxz164\oemui.inf
c:\program files\McAfee\Temp\qxz164\oemuild.dll
c:\program files\McAfee\Temp\qxz164\oemuild.inf
c:\program files\McAfee\Temp\qxz164\Proxyver.dll
c:\program files\McAfee\Temp\qxz164\rmoldfile.inf
c:\program files\McAfee\Temp\qxz164\RprtShm.dll
c:\program files\McAfee\Temp\qxz164\scriptff.dll
c:\program files\McAfee\Temp\qxz164\scriptsn.dll
c:\program files\McAfee\Temp\qxz164\sqlite3.dll
c:\program files\McAfee\Temp\qxz164\strings.bin
c:\program files\McAfee\Temp\qxz164\TskTCShm.dll
c:\program files\McAfee\Temp\qxz164\vscan.bof
c:\program files\McAfee\Temp\qxz164\vscore.inf
c:\program files\McAfee\Temp\qxz164\vscore.xml
c:\program files\McAfee\Temp\qxz164\vscore_fresh.inf
c:\program files\McAfee\Temp\qxz164\vscore_pre.inf
c:\program files\McAfee\Temp\qxz164\vscore_update.inf
c:\program files\McAfee\Temp\qxz164\VSCVer.dll
c:\program files\McAfee\Temp\qxz164\x64\mcactui.dll
c:\program files\McAfee\Temp\qxz164\x64\mcactwiz.dll
c:\program files\McAfee\Temp\qxz164\x64\mcactwiz_ld.dll
c:\program files\McAfee\Temp\qxz164\x64\mcoemmgr.exe
c:\program files\McAfee\Temp\qxz16A\mscLD.inf
c:\program files\McAfee\Temp\qxz16B\mclgtmpl.inf
c:\program files\McAfee\Temp\qxz176\override.inf

.
((((((((((((((((((((((((( Files Created from 2010-06-23 to 2010-07-23 )))))))))))))))))))))))))))))))
.

2010-07-22 23:40 . 2010-07-23 01:21 ——– d—–w- c:\program files\McAfee.com
2010-07-20 23:50 . 2010-07-20 23:52 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Temp
2010-07-20 23:49 . 2010-07-20 23:49 ——– d—–w- c:\windows\system32\wbem\Repository
2010-07-17 01:05 . 2010-07-17 01:05 ——– d—–w- C:\$AVG
2010-07-17 00:11 . 2010-07-17 00:11 12536 —-a-w- c:\windows\system32\avgrsstx(2).dll
2010-07-17 00:11 . 2010-07-20 21:39 ——– d—–w- c:\windows\system32\drivers\Avg(2)
2010-07-17 00:05 . 2010-07-20 23:49 ——– d—–w- c:\program files\AVG(2)
2010-07-17 00:04 . 2010-07-22 23:12 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-22 21:23 . 2009-08-13 01:44 ——– d—–w- c:\program files\Acer GameZone
2010-07-20 23:56 . 2010-06-01 18:35 ——– d—–w- c:\program files\LimeWire
2010-07-16 23:10 . 2010-05-25 22:34 ——– d—–w- c:\documents and settings\All Users\Application Data\Google Updater
2010-06-14 14:31 . 2009-08-13 00:58 744448 —-a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-08 22:42 . 2009-08-13 01:14 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-06-01 21:23 . 2010-06-01 18:49 ——– d—–w- c:\documents and settings\All Users\Application Data\CyberLink
2010-06-01 18:49 . 2010-06-01 18:49 ——– d—–w- c:\documents and settings\Sheena\Application Data\CyberLink
2010-06-01 00:32 . 2010-06-01 00:32 95568 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2010-06-01 00:32 . 2010-06-01 00:32 385880 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2010-05-25 22:45 . 2009-08-13 01:21 ——– d—–w- c:\program files\Google
2010-05-23 16:49 . 2010-05-23 16:49 348160 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6dc5bc19-n\msvcr71.dll
2010-05-23 16:49 . 2010-05-23 16:49 503808 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6dc5bc19-n\msvcp71.dll
2010-05-23 16:49 . 2010-05-23 16:49 61440 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-14603739-n\decora-sse.dll
2010-05-23 16:49 . 2010-05-23 16:49 499712 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-6dc5bc19-n\jmc.dll
2010-05-23 16:49 . 2010-05-23 16:49 12800 —-a-w- c:\documents and settings\Sheena\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-14603739-n\decora-d3d.dll
2010-05-23 00:04 . 2010-05-23 00:05 411368 —-a-w- c:\windows\system32\deploytk.dll
2010-05-16 23:51 . 2010-03-20 19:26 60664 —-a-w- c:\documents and settings\Sheena\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-04 17:20 . 2009-08-13 01:44 832512 —-a-w- c:\windows\system32\wininet.dll
2010-05-04 17:20 . 2009-08-13 01:44 78336 —-a-w- c:\windows\system32\ieencode.dll
2010-05-04 17:20 . 2009-08-13 01:44 17408 —-a-w- c:\windows\system32\corpol.dll
2010-05-02 05:22 . 2009-08-13 01:44 1851264 —-a-w- c:\windows\system32\win32k.sys
.

((((((((((((((((((((((((((((( SnapShot@2010-07-22_22.33.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-07-23 01:05 . 2010-07-23 01:05 16384 c:\windows\Temp\Perflib_Perfdata_7f8.dat
+ 2009-08-13 01:44 . 2010-07-23 01:09 67984 c:\windows\system32\perfc009.dat
- 2009-08-13 01:44 . 2010-07-22 22:24 67984 c:\windows\system32\perfc009.dat
+ 2009-08-13 01:44 . 2010-07-23 01:09 433698 c:\windows\system32\perfh009.dat
- 2009-08-13 01:44 . 2010-07-22 22:24 433698 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2009-05-15 06:02 120104 —-a-w- c:\program files\EgisTec\MyWinLocker 3\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-03-20 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2009-05-24 1657376]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-05-24 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-05-24 13758464]
"RTHDCPL"="RTHDCPL.EXE" [2009-05-21 17881600]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2010-06-11 30192]
"EgisTecLiveUpdate"="c:\program files\EgisTec Egis Software Update\EgisUpdate.exe" [2009-05-14 199464]
"mwlDaemon"="c:\program files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe" [2009-05-15 345384]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2008-10-03 294544]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-14 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2008-04-14 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-14 455168]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-10-17 91432]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-04-12 1135912]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=

R1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\drivers\mwlPSDFilter.sys [12/4/2008 9:34 PM 17840]
R1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\drivers\mwlPSDNserv.sys [12/4/2008 9:34 PM 15280]
R1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\drivers\mwlPSDVDisk.sys [12/4/2008 9:34 PM 58800]
R2 MWLService;MyWinLocker Service;c:\program files\EgisTec\MyWinLocker 3\x86\MWLService.exe [5/15/2009 2:03 AM 305448]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [8/12/2009 9:45 PM 46752]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [4/13/2010 4:54 PM 135664]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [8/12/2009 9:13 PM 1684736]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [8/12/2009 9:21 PM 30192]
.
Contents of the 'Scheduled Tasks' folder

2010-07-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2010-03-20 22:34]

2010-07-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 20:54]

2010-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-04-13 20:54]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=0&o=xph&d=0310&m=aspire_r1600
IE: &Download All using 4shared Desktop - c:\program files\4shared Desktop\down_all.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
DPF: {20722C4E-9050-45C8-8D1A-816C4A06AD90} - hxxp://www.cvsphoto.com/upload/activex/v3_0_0_6/PhotoCenter_ActiveX_Control.cab
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-mcmscsvc



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-22 21:22
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe catchme.sys CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x84A4CB4C]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf754bf28
\Driver\ACPI -> ACPI.sys @ 0xf735ecb8
\Driver\atapi -> atapi.sys @ 0xf72fe852
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->NDIS: NVIDIA nForce 10/100/1000 Mbps Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xf7143bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7150a21
SendHandler -> NDIS.sys @ 0xf712e87b
user & kernel MBR OK

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(472)
c:\windows\system32\WININET.dll

- - - - - - - > 'lsass.exe'(532)
c:\windows\system32\WININET.dll
.
Completion time: 2010-07-22 21:25:46
ComboFix-quarantined-files.txt 2010-07-23 01:25
ComboFix2.txt 2010-07-22 22:37

Pre-Run: 128,014,733,312 bytes free
Post-Run: 128,393,621,504 bytes free

- - End Of File - - D58A189596565C272943F90DDD96BBD3
Please Download MBRCheck.exe to your desktop
XP users > double click on MBRCheck.exe to run it
Vista and Windows 7 users > right click on MBRCheck.exe and select Run as Please download MBRCheck.exe to your desktop.

  • Double click to run it
  • It will prompt you with some text
  • Left click on title bar (where program name and path is written)
  • From menu chose Edit -> Select All
  • Now just click Enter key on keyboard to copy selected text
  • Now paste that text here for me.
MBRCheck, version 1.1.1 © 2010, AD \\.\C: –> \\.\PhysicalDrive0 Size Device Name MBR Status ——————————————– 149 GB \\.\PhysicalDrive0 Windows 2008 MBR code detected Done! Press ENTER to exit…
That looks good.

Still trying to figure out the redirects.

You might want to print these instructions out.



Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step



Download TDSSKiller and save it to your Desktop.
Once completed it will create a log in your C:\ drive called TDSSKiller_*** (*** denotes version & date)
  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone
please post the contents of that log TDSSKiller and GooredFix log.
GooredFix by jpshortstuff (03.07.10.1) Log created at 15:22 on 24/07/2010 (Sheena) Firefox version [Unable to determine] ========== GooredScan ========== ========== GooredLog ========== C:\Program Files\Mozilla Firefox\extensions\ (none) [HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions] "{20a82645-c095-46ed-80e3-08825760534b}"="c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\" [00:43 18/04/2010] "[removed]"="C:\Program Files\Java\jre6\lib\deploy\jqs\ff" [00:04 23/05/2010] -=E.O.F=- 15:23:29:328 3284 TDSS rootkit removing tool 2.3.2.2 Jun 30 2010 17:23:49 15:23:29:328 3284 ================================================================================ 15:23:29:328 3284 SystemInfo: 15:23:29:328 3284 OS Version: 5.1.2600 ServicePack: 3.0 15:23:29:328 3284 Product type: Workstation 15:23:29:328 3284 ComputerName: ACER-42041E6643 15:23:29:328 3284 UserName: Sheena 15:23:29:328 3284 Windows directory: C:\WINDOWS 15:23:29:328 3284 System windows directory: C:\WINDOWS 15:23:29:328 3284 Processor architecture: Intel x86 15:23:29:328 3284 Number of processors: 2 15:23:29:328 3284 Page size: 0x1000 15:23:29:328 3284 Boot type: Normal boot 15:23:29:328 3284 ================================================================================ 15:23:29:906 3284 Initialize success 15:23:29:906 3284 15:23:29:906 3284 Scanning Services … 15:23:30:187 3284 Raw services enum returned 324 services 15:23:30:203 3284 15:23:30:203 3284 Scanning Drivers … 15:23:30:718 3284 abp480n5 (6abb91494fe6c59089b9336452ab2ea3) C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS 15:23:30:781 3284 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys 15:23:30:812 3284 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys 15:23:30:968 3284 adpu160m (9a11864873da202c996558b2106b0bbc) C:\WINDOWS\system32\DRIVERS\adpu160m.sys 15:23:31:015 3284 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 15:23:31:093 3284 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys 15:23:31:234 3284 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys 15:23:31:265 3284 agpCPQ (03a7e0922acfe1b07d5db2eeb0773063) C:\WINDOWS\system32\DRIVERS\agpCPQ.sys 15:23:31:296 3284 Aha154x (c23ea9b5f46c7f7910db3eab648ff013) C:\WINDOWS\system32\DRIVERS\aha154x.sys 15:23:31:359 3284 aic78u2 (19dd0fb48b0c18892f70e2e7d61a1529) C:\WINDOWS\system32\DRIVERS\aic78u2.sys 15:23:31:500 3284 aic78xx (b7fe594a7468aa0132deb03fb8e34326) C:\WINDOWS\system32\DRIVERS\aic78xx.sys 15:23:31:531 3284 AliIde (1140ab9938809700b46bb88e46d72a96) C:\WINDOWS\system32\DRIVERS\aliide.sys 15:23:31:578 3284 alim1541 (cb08aed0de2dd889a8a820cd8082d83c) C:\WINDOWS\system32\DRIVERS\alim1541.sys 15:23:31:687 3284 Ambfilt (f6af59d6eee5e1c304f7f73706ad11d8) C:\WINDOWS\system32\drivers\Ambfilt.sys 15:23:31:875 3284 amdagp (95b4fb835e28aa1336ceeb07fd5b9398) C:\WINDOWS\system32\DRIVERS\amdagp.sys 15:23:31:921 3284 amsint (79f5add8d24bd6893f2903a3e2f3fad6) C:\WINDOWS\system32\DRIVERS\amsint.sys 15:23:31:953 3284 asc (62d318e9a0c8fc9b780008e724283707) C:\WINDOWS\system32\DRIVERS\asc.sys 15:23:32:000 3284 asc3350p (69eb0cc7714b32896ccbfd5edcbea447) C:\WINDOWS\system32\DRIVERS\asc3350p.sys 15:23:32:140 3284 asc3550 (5d8de112aa0254b907861e9e9c31d597) C:\WINDOWS\system32\DRIVERS\asc3550.sys 15:23:32:187 3284 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 15:23:32:265 3284 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 15:23:32:312 3284 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 15:23:32:453 3284 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 15:23:32:500 3284 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 15:23:32:703 3284 cbidf (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\DRIVERS\cbidf2k.sys 15:23:32:812 3284 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 15:23:32:859 3284 cd20xrnt (f3ec03299634490e97bbce94cd2954c7) C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys 15:23:32:921 3284 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 15:23:32:968 3284 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 15:23:32:984 3284 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\drivers\Cdrom.sys 15:23:33:109 3284 CmdIde (e5dcb56c533014ecbc556a8357c929d5) C:\WINDOWS\system32\DRIVERS\cmdide.sys 15:23:33:156 3284 Cpqarray (3ee529119eed34cd212a215e8c40d4b6) C:\WINDOWS\system32\DRIVERS\cpqarray.sys 15:23:33:234 3284 dac2w2k (e550e7418984b65a78299d248f0a7f36) C:\WINDOWS\system32\DRIVERS\dac2w2k.sys 15:23:33:312 3284 dac960nt (683789caa3864eb46125ae86ff677d34) C:\WINDOWS\system32\DRIVERS\dac960nt.sys 15:23:33:453 3284 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 15:23:33:546 3284 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys 15:23:33:703 3284 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys 15:23:33:750 3284 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 15:23:33:781 3284 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 15:23:33:828 3284 dpti2o (40f3b93b4e5b0126f2f5c0a7a5e22660) C:\WINDOWS\system32\DRIVERS\dpti2o.sys 15:23:33:953 3284 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 15:23:34:000 3284 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 15:23:34:062 3284 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 15:23:34:078 3284 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys 15:23:34:093 3284 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 15:23:34:171 3284 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 15:23:34:328 3284 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 15:23:34:390 3284 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 15:23:34:421 3284 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 15:23:34:484 3284 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 15:23:34:593 3284 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys 15:23:34:656 3284 hpn (b028377dea0546a5fcfba928a8aefae0) C:\WINDOWS\system32\DRIVERS\hpn.sys 15:23:34:718 3284 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 15:23:34:875 3284 i2omgmt (9368670bd426ebea5e8b18a62416ec28) C:\WINDOWS\system32\drivers\i2omgmt.sys 15:23:34:953 3284 i2omp (f10863bf1ccc290babd1a09188ae49e0) C:\WINDOWS\system32\DRIVERS\i2omp.sys 15:23:35:015 3284 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\drivers\Imapi.sys 15:23:35:156 3284 ini910u (4a40e045faee58631fd8d91afc620719) C:\WINDOWS\system32\DRIVERS\ini910u.sys 15:23:35:531 3284 IntcAzAudAddService (0cacdcbbc8e6f11e2865c47bfc509848) C:\WINDOWS\system32\drivers\RtkHDAud.sys 15:23:35:734 3284 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys 15:23:35:781 3284 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys 15:23:35:828 3284 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 15:23:35:859 3284 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 15:23:35:984 3284 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 15:23:36:015 3284 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 15:23:36:109 3284 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 15:23:36:156 3284 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 15:23:36:281 3284 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys 15:23:36:328 3284 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 15:23:36:343 3284 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys 15:23:36:390 3284 klmd23 (316353165feba3d0538eaa9c2f60c5b7) C:\WINDOWS\system32\drivers\klmd.sys 15:23:36:531 3284 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 15:23:36:609 3284 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 15:23:36:671 3284 mfeapfk (b77e959e1c50d3e3a9d9ef423be62e09) C:\WINDOWS\system32\drivers\mfeapfk.sys 15:23:36:796 3284 mfehidk (e7ecf7872bf8f2897ae5a696d908c2f7) C:\WINDOWS\system32\drivers\mfehidk.sys 15:23:36:968 3284 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 15:23:37:015 3284 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys 15:23:37:093 3284 Monfilt (9fa7207d1b1adead88ae8eed9cdbbaa5) C:\WINDOWS\system32\drivers\Monfilt.sys 15:23:37:265 3284 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys 15:23:37:296 3284 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys 15:23:37:359 3284 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 15:23:37:421 3284 MPFP (136157e79849b9e5316ba4008d6075a8) C:\WINDOWS\system32\Drivers\Mpfp.sys 15:23:37:546 3284 mraid35x (3f4bb95e5a44f3be34824e8e7caf0737) C:\WINDOWS\system32\DRIVERS\mraid35x.sys 15:23:37:562 3284 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 15:23:37:656 3284 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 15:23:37:718 3284 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 15:23:37:843 3284 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 15:23:37:875 3284 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 15:23:37:906 3284 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 15:23:37:953 3284 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 15:23:37:968 3284 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys 15:23:38:031 3284 mwlPSDFilter (a4a79414483ecf56eb1664a709b4d9a5) C:\WINDOWS\system32\DRIVERS\mwlPSDFilter.sys 15:23:38:140 3284 mwlPSDNServ (2b535201b7ebf06653099c318066e036) C:\WINDOWS\system32\DRIVERS\mwlPSDNServ.sys 15:23:38:171 3284 mwlPSDVDisk (8edba480be33b8b3f6bbb7a4ecb21454) C:\WINDOWS\system32\DRIVERS\mwlPSDVDisk.sys 15:23:38:218 3284 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 15:23:38:250 3284 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 15:23:38:265 3284 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 15:23:38:375 3284 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 15:23:38:437 3284 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys 15:23:38:484 3284 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 15:23:38:562 3284 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 15:23:38:718 3284 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 15:23:38:781 3284 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 15:23:38:953 3284 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 15:23:39:281 3284 nv (e2faccaa3d194245acda43c531460b71) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys 15:23:39:671 3284 NVENETFD (7d275ecda4628318912f6c945d5cf963) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys 15:23:39:734 3284 nvgts (75e2e77c5497f34e60491d27bf03f1cb) C:\WINDOWS\system32\drivers\nvgts.sys 15:23:39:781 3284 NVHDA (422bbe63a70950440e1db5fe7a9557a7) C:\WINDOWS\system32\drivers\nvhda32.sys 15:23:39:796 3284 nvnetbus (b64aacefad2be5bff5353fe681253c67) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys 15:23:39:906 3284 nvsmu (2a085aec3ab2b1211611d2a7b9e22456) C:\WINDOWS\system32\DRIVERS\nvsmu.sys 15:23:39:953 3284 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 15:23:39:968 3284 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 15:23:40:031 3284 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\drivers\Parport.sys 15:23:40:046 3284 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 15:23:40:156 3284 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys 15:23:40:218 3284 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys 15:23:40:265 3284 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys 15:23:40:296 3284 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys 15:23:40:468 3284 perc2 (6c14b9c19ba84f73d3a86dba11133101) C:\WINDOWS\system32\DRIVERS\perc2.sys 15:23:40:500 3284 perc2hib (f50f7c27f131afe7beba13e14a3b9416) C:\WINDOWS\system32\DRIVERS\perc2hib.sys 15:23:40:546 3284 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 15:23:40:640 3284 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 15:23:40:656 3284 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 15:23:40:703 3284 ql1080 (0a63fb54039eb5662433caba3b26dba7) C:\WINDOWS\system32\DRIVERS\ql1080.sys 15:23:40:750 3284 Ql10wnt (6503449e1d43a0ff0201ad5cb1b8c706) C:\WINDOWS\system32\DRIVERS\ql10wnt.sys 15:23:40:843 3284 ql12160 (156ed0ef20c15114ca097a34a30d8a01) C:\WINDOWS\system32\DRIVERS\ql12160.sys 15:23:40:906 3284 ql1240 (70f016bebde6d29e864c1230a07cc5e6) C:\WINDOWS\system32\DRIVERS\ql1240.sys 15:23:41:031 3284 ql1280 (907f0aeea6bc451011611e732bd31fcf) C:\WINDOWS\system32\DRIVERS\ql1280.sys 15:23:41:062 3284 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 15:23:41:125 3284 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 15:23:41:140 3284 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 15:23:41:156 3284 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 15:23:41:234 3284 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 15:23:41:359 3284 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 15:23:41:421 3284 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 15:23:41:484 3284 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys 15:23:41:500 3284 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 15:23:41:609 3284 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\drivers\Serial.sys 15:23:41:640 3284 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 15:23:41:718 3284 sisagp (6b33d0ebd30db32e27d1d78fe946a754) C:\WINDOWS\system32\DRIVERS\sisagp.sys 15:23:41:750 3284 Sparrow (83c0f71f86d3bdaf915685f3d568b20e) C:\WINDOWS\system32\DRIVERS\sparrow.sys 15:23:41:796 3284 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 15:23:41:953 3284 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys 15:23:42:015 3284 Srv (89220b427890aa1dffd1a02648ae51c3) C:\WINDOWS\system32\DRIVERS\srv.sys 15:23:42:171 3284 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 15:23:42:234 3284 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 15:23:42:281 3284 symc810 (1ff3217614018630d0a6758630fc698c) C:\WINDOWS\system32\DRIVERS\symc810.sys 15:23:42:312 3284 symc8xx (070e001d95cf725186ef8b20335f933c) C:\WINDOWS\system32\DRIVERS\symc8xx.sys 15:23:42:437 3284 sym_hi (80ac1c4abbe2df3b738bf15517a51f2c) C:\WINDOWS\system32\DRIVERS\sym_hi.sys 15:23:42:500 3284 sym_u3 (bf4fab949a382a8e105f46ebb4937058) C:\WINDOWS\system32\DRIVERS\sym_u3.sys 15:23:42:562 3284 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 15:23:42:671 3284 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 15:23:42:796 3284 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 15:23:42:843 3284 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 15:23:42:890 3284 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 15:23:42:937 3284 TosIde (f2790f6af01321b172aa62f8e1e187d9) C:\WINDOWS\system32\DRIVERS\toside.sys 15:23:42:968 3284 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 15:23:43:093 3284 ultra (1b698a51cd528d8da4ffaed66dfc51b9) C:\WINDOWS\system32\DRIVERS\ultra.sys 15:23:43:140 3284 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 15:23:43:265 3284 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 15:23:43:281 3284 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 15:23:43:296 3284 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 15:23:43:312 3284 usbohci (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys 15:23:43:359 3284 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 15:23:43:421 3284 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 15:23:43:562 3284 viaagp (754292ce5848b3738281b4f3607eaef4) C:\WINDOWS\system32\DRIVERS\viaagp.sys 15:23:43:593 3284 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 15:23:43:640 3284 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys 15:23:43:671 3284 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 15:23:43:703 3284 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 15:23:43:843 3284 WmiAcpi (c42584fd66ce9e17403aebca199f7bdb) C:\WINDOWS\system32\DRIVERS\wmiacpi.sys 15:23:43:875 3284 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys 15:23:43:875 3284 15:23:43:875 3284 Completed 15:23:43:875 3284 15:23:43:875 3284 Results: 15:23:43:875 3284 Registry objects infected / cured / cured on reboot: 0 / 0 / 0 15:23:43:875 3284 File objects infected / cured / cured on reboot: 0 / 0 / 0 15:23:43:875 3284 15:23:43:890 3284 KLMD(ARK) unloaded successfully

No so far Google Chrome and IE are working

So only FF.


To empty the cache in firefox
1. click on tools > options
2. click on the Privacy button on the left side of the window
3. click the "Clear All" button to clear all cached items or select individual items to clear by clicking on individual "Clear" buttons (History, Saved Information, Saved Passwords, Download Manager History, Cookies, Cache)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI