This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet searches redirected

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Let me start by saying I am sorry for what is sure to be a confusing explaination of what is going on with my computer, but I am not very smart about computers. I appriciate any help you may be able to offer.

My problem is when I do a Google or Yahoo search and click on a link from the list it returns I get redirected to wrong page. When I hit the "Back" button it does not let me leave the wrong website. If I highlight, copy and paste the web address from the Google or Yahoo search list into the web address box I can get to the correct site. It seems to be the link and not the address that is the problem. Since I don't know about computers i searched Yahoo Answers and they suggested I download the Highjack program, run it and save the file for you guys to look at. I did NOT "fix" anything, just saved the text file to my desktop.

Not sure if it is helpful to know but I use Webroot Anti-Virus, Avast Anti-visrus and ZoneAlert as my computer security. I was using Firefox but the redirecting got so bad and it kept freezing and crashing that I started using Internet Explorer. I perfer Firefox but would be willing to change to whatever browser you feel would be better.

If you need any other information please let me know. Thank you again for working with someone who is clueless about these things.

I see there is an option to attach files (i.e. the highjack results) but I believe I read in the posting instructions that I am supposed to paste my results in the actual post. If this is incorrect I can attach the .txt file.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:36:04 PM, on 9/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\EeePC\ACPI\AsTray.exe
C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe
C:\Program Files\EeePC\ACPI\AsEPCMon.exe
C:\Program Files\Elantech\ETDCtrl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\Alwil Software\Avast5\avastUI.exe
C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\5CQMT2S7\HiJackThis[1].exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: (no name) - MRI_DISABLED - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [RTHDCPL] "RTHDCPL.EXE"
O4 - HKLM\..\Run: [IgfxTray] "C:\WINDOWS\system32\igfxtray.exe"
O4 - HKLM\..\Run: [HotKeysCmds] "C:\WINDOWS\system32\hkcmd.exe"
O4 - HKLM\..\Run: [Persistence] "C:\WINDOWS\system32\igfxpers.exe"
O4 - HKLM\..\Run: [AsusTray] "C:\Program Files\EeePC\ACPI\AsTray.exe"
O4 - HKLM\..\Run: [AsusACPIServer] "C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe"
O4 - HKLM\..\Run: [AsusEPCMonitor] "C:\Program Files\EeePC\ACPI\AsEPCMon.exe"
O4 - HKLM\..\Run: [ETDWare] "C:\Program Files\Elantech\ETDCtrl.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] "C:\WINDOWS\system32\ctfmon.exe"
O4 - HKUS\S-1-5-18\..\Run: [userinit] C:\WINDOWS\system32\sdra64.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [userinit] C:\WINDOWS\system32\sdra64.exe (User 'Default user')
O4 - Global Startup: SuperHybridEngine.lnk = ?
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6770.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1261312389765
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1261312381515
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe

–
End of file - 9434 bytes
Hi

Please do the following:



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Here are the results of the three things you requested I do. Thank you. 1) MBR Check Results MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 113): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806D0000 \WINDOWS\system32\hal.dll 0xF7A88000 \WINDOWS\system32\KDCOM.DLL 0xF7998000 \WINDOWS\system32\BOOTVID.dll 0xF7459000 ACPI.sys 0xF7A8A000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7448000 pci.sys 0xF7588000 isapnp.sys 0xF7598000 sshrmd.sys 0xF75A8000 ssfs0bbc.sys 0xF741A000 ssidrv.sys 0xF73ED000 \WINDOWS\system32\DRIVERS\NDIS.SYS 0xF7808000 \WINDOWS\system32\DRIVERS\TDI.SYS 0xF799C000 compbatt.sys 0xF79A0000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xF7B50000 PCIIde.sys 0xF7810000 \WINDOWS\System32\Drivers\PCIIDEX.SYS 0xF7A8C000 intelide.sys 0xF75B8000 MountMgr.sys 0xF73CE000 ftdisk.sys 0xF79A4000 ACPIEC.sys 0xF7B51000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xF7818000 PartMgr.sys 0xF75C8000 VolSnap.sys 0xF73B6000 atapi.sys 0xF75D8000 disk.sys 0xF75E8000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7396000 fltMgr.sys 0xF7384000 sr.sys 0xF736D000 KSecDD.sys 0xF72E0000 Ntfs.sys 0xF72C6000 Mup.sys 0xF7698000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF715D000 \SystemRoot\system32\DRIVERS\igxpmp32.sys 0xF7149000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF7121000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF76A8000 \SystemRoot\system32\DRIVERS\l1e51x86.sys 0xF709B000 \SystemRoot\system32\DRIVERS\ar5211.sys 0xF7870000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xF7077000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF7878000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF76B8000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7880000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF76C8000 \SystemRoot\system32\DRIVERS\ETD.sys 0xF7888000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7A2C000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0xF7A30000 \SystemRoot\system32\DRIVERS\ASUSACPI.sys 0xF7C45000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF76D8000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7A34000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF7060000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF76E8000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF76F8000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF704F000 \SystemRoot\system32\DRIVERS\psched.sys 0xF7708000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF7890000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7898000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF7718000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7A92000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF702C000 \SystemRoot\system32\DRIVERS\ks.sys 0xF6FCE000 \SystemRoot\system32\DRIVERS\update.sys 0xF7A40000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7728000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF7748000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7A94000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xAA30F000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xAA2EB000 \SystemRoot\system32\drivers\portcls.sys 0xF7758000 \SystemRoot\system32\drivers\drmk.sys 0xF7A98000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7BB0000 \SystemRoot\System32\Drivers\Null.SYS 0xF7A9A000 \SystemRoot\System32\Drivers\Beep.SYS 0xF78B8000 \SystemRoot\System32\drivers\vga.sys 0xF7A9C000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7A9E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF78C0000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78C8000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7292000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xAA250000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xAA1F7000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xAA1A9000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF77A8000 \SystemRoot\System32\Drivers\aswTdi.SYS 0xAA181000 \SystemRoot\system32\DRIVERS\netbt.sys 0xAA100000 \SystemRoot\System32\vsdatant.sys 0xAA0DE000 \SystemRoot\System32\drivers\afd.sys 0xF77C8000 \SystemRoot\system32\DRIVERS\netbios.sys 0xAA0B3000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xAA043000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF77F8000 \SystemRoot\System32\Drivers\Fips.SYS 0xAA01C000 \SystemRoot\System32\Drivers\aswSP.SYS 0xF7910000 \SystemRoot\System32\Drivers\Aavmker4.SYS 0xF6F9E000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xBF800000 \SystemRoot\System32\win32k.sys 0xAA1EF000 \SystemRoot\System32\drivers\Dxapi.sys 0xF7960000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C09000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF024000 \SystemRoot\System32\igxpgd32.dll 0xBF012000 \SystemRoot\System32\igxprd32.dll 0xBF04D000 \SystemRoot\System32\igxpdv32.DLL 0xBF1AE000 \SystemRoot\System32\igxpdx32.DLL 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xA9C19000 \SystemRoot\System32\Drivers\aswFsBlk.SYS 0xA9B4D000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xF7858000 \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys 0xA97BE000 \SystemRoot\System32\Drivers\aswMon2.SYS 0xA9551000 \SystemRoot\system32\drivers\wdmaud.sys 0xA971E000 \SystemRoot\system32\drivers\sysaudio.sys 0xA9344000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA924D000 \SystemRoot\system32\DRIVERS\srv.sys 0xF7978000 \SystemRoot\System32\Drivers\aswRdr.SYS 0xA8EC4000 \SystemRoot\System32\Drivers\HTTP.sys 0xA7AEF000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 45): 0 System Idle Process 4 System 424 C:\WINDOWS\system32\smss.exe 712 csrss.exe 736 C:\WINDOWS\system32\winlogon.exe 784 C:\WINDOWS\system32\services.exe 796 C:\WINDOWS\system32\lsass.exe 960 C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe 980 C:\WINDOWS\system32\svchost.exe 1068 svchost.exe 1112 C:\WINDOWS\system32\svchost.exe 1224 svchost.exe 1416 svchost.exe 1460 C:\WINDOWS\explorer.exe 1540 C:\WINDOWS\system32\ZoneLabs\vsmon.exe 468 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe 544 C:\Program Files\Alwil Software\Avast5\AvastSvc.exe 1292 C:\WINDOWS\system32\spoolsv.exe 1520 svchost.exe 1644 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1664 C:\Program Files\Bonjour\mDNSResponder.exe 1040 C:\Program Files\Java\jre6\bin\jqs.exe 2264 C:\WINDOWS\system32\svchost.exe 2388 C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe 3764 C:\WINDOWS\system32\hkcmd.exe 3780 C:\Program Files\EeePC\ACPI\AsTray.exe 3800 C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe 3808 C:\Program Files\EeePC\ACPI\AsEPCMon.exe 3832 C:\Program Files\Elantech\ETDCTRL.EXE 3880 C:\WINDOWS\system32\igfxsrvc.exe 3892 C:\Program Files\iTunes\iTunesHelper.exe 3928 C:\Program Files\Common Files\Java\Java Update\jusched.exe 3968 C:\WINDOWS\system32\igfxext.exe 3992 C:\Program Files\Alwil Software\Avast5\AvastUI.exe 324 C:\WINDOWS\system32\ctfmon.exe 1760 C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe 2860 C:\Program Files\iPod\bin\iPodService.exe 3504 C:\Program Files\CheckPoint\ZAForceField\ForceField.exe 160 C:\Program Files\Internet Explorer\iexplore.exe 992 C:\Program Files\Internet Explorer\iexplore.exe 3728 C:\WINDOWS\system32\svchost.exe 1868 C:\Program Files\Internet Explorer\iexplore.exe 1064 C:\Program Files\Internet Explorer\iexplore.exe 188 C:\WINDOWS\system32\wscntfy.exe 224 C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\9M70PDO0\MBRCheck[1].exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x0000000f`00bc3400 (NTFS) PhysicalDrive0 Model Number: ST9120817AS, Rev: 3.AAA Size Device Name MBR Status ——————————————– 111 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 Done! 2) DDS Results – The "Attach" file has been zipped and attached to this reply. DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 10:38:42.20 on Sat 09/18/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.334 [GMT -4:00] AV: Webroot AntiVirus with Spy Sweeper *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597} AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe C:\Program Files\EeePC\ACPI\AsTray.exe C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe C:\Program Files\EeePC\ACPI\AsEPCMon.exe C:\Program Files\Elantech\ETDCtrl.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\WINDOWS\system32\igfxext.exe C:\Program Files\Alwil Software\Avast5\avastUI.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\DC5CGM6Z\dds[1].com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local uURLSearchHooks: H - No File mWinlogon: Userinit=userinit.exe, BHO: MRI_DISABLED - No File BHO: Skype add-on (mastermind) - No File BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe" mRun: [RTHDCPL] "RTHDCPL.EXE" mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" mRun: [Persistence] "c:\windows\system32\igfxpers.exe" mRun: [AsusTray] "c:\program files\eeepc\acpi\AsTray.exe" mRun: [AsusACPIServer] "c:\program files\eeepc\acpi\AsAcpiSvr.exe" mRun: [AsusEPCMonitor] "c:\program files\eeepc\acpi\AsEPCMon.exe" mRun: [ETDWare] "c:\program files\elantech\ETDCtrl.exe" mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden" mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray dRun: [userinit] c:\windows\system32\sdra64.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261312389765 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261312381515 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\ypm182qo.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://m.www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q= FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll FF - component: c:\program files\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: XULRunner: {14DA921F-039E-4108-A01D-79FC2DAEAF84} - c:\documents and settings\owner\local settings\application data\{14da921f-039e-4108-a01d-79fc2daeaf84}\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); ============= SERVICES / DRIVERS =============== R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-11-6 29808] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-9-12 165584] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-9-3 532224] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-9-12 17744] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-12 40384] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2010-5-26 26352] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2010-5-26 493032] R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240] R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2009-12-20 1201640] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-12 136176] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-12 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-12 40384] =============== Created Last 30 ================ 2010-09-16 23:37:16 0 dc-h–w- c:\windows\ie8 2010-09-13 01:47:54 38848 —-a-w- c:\windows\avastSS.scr 2010-09-13 01:47:45 0 d—–w- c:\docume~1\alluse~1\applic~1\Alwil Software 2010-09-03 21:55:25 0 d—–w- c:\docume~1\owner\applic~1\CheckPoint 2010-09-03 21:48:40 0 d—–w- c:\program files\ZoneAlarm 2010-09-03 21:48:24 0 d—–w- c:\program files\CheckPoint 2010-09-03 21:48:21 4212 —ha-w- c:\windows\system32\zllictbl.dat 2010-09-03 21:47:50 1238528 —-a-w- c:\windows\system32\zpeng25.dll 2010-09-03 21:47:43 0 d—–w- c:\windows\system32\ZoneLabs 2010-09-03 21:47:32 421442 —-a-w- c:\windows\system32\vsconfig.xml 2010-09-03 21:47:30 0 d—–w- c:\program files\Zone Labs 2010-09-03 21:46:54 0 d—–w- c:\windows\Internet Logs 2010-08-24 22:31:54 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-08-24 22:31:53 411368 —-a-w- c:\windows\system32\deployJava1.dll ==================== Find3M ==================== 2010-09-13 16:34:16 3922 —-a-w- c:\docume~1\owner\applic~1\wklnhst.dat 2008-05-07 08:34:00 15523560 —-a-w- c:\program files\U1 Setup.exe ============= FINISH: 10:41:39.60 =============== 3) GMER Rootkit Scanner Results – file attached
One or more of the identified infections is a backdoor trojan/rootkit.

This type of infection allows hackers to remotely control your computer, steal critical system information and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?




Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Yes, I do most of my banking online. Thank you for the ID theft information. I will be sure to change my passwords on a clean computer and contact my bank about this. Below are the results of the ComboFix scan.



ComboFix 10-09-17.04 - Owner 09/18/2010 21:42:54.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.675 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Webroot AntiVirus with Spy Sweeper *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\Thumbs.db

Infected copy of c:\windows\system32\drivers\tcpip.sys was found and disinfected
Restored copy from - Kitty had a snack :P
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_usnjsvc


((((((((((((((((((((((((( Files Created from 2010-08-19 to 2010-09-19 )))))))))))))))))))))))))))))))
.

2010-09-16 23:37 . 2010-09-16 23:39 ——– dc-h–w- c:\windows\ie8
2010-09-15 01:37 . 2010-09-15 01:40 ——– d—–w- c:\program files\QuickTime
2010-09-13 01:53 . 2010-09-13 01:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-09-13 01:49 . 2010-09-16 21:53 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2010-09-13 01:49 . 2010-09-13 01:49 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-09-13 01:48 . 2010-09-13 01:52 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Google
2010-09-13 01:48 . 2010-09-13 01:50 ——– d—–w- c:\program files\Google
2010-09-13 01:48 . 2010-09-07 14:47 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-13 01:48 . 2010-09-07 14:52 165584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-13 01:48 . 2010-09-07 14:47 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-13 01:48 . 2010-09-07 14:52 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-13 01:48 . 2010-09-07 14:47 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-13 01:48 . 2010-09-07 14:47 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-13 01:48 . 2010-09-07 14:46 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-13 01:47 . 2010-09-07 15:12 38848 —-a-w- c:\windows\avastSS.scr
2010-09-13 01:47 . 2010-09-07 15:11 167592 —-a-w- c:\windows\system32\aswBoot.exe
2010-09-13 01:47 . 2010-09-13 01:47 ——– d—–w- c:\program files\Alwil Software
2010-09-13 01:47 . 2010-09-13 01:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-09-11 05:11 . 2010-09-11 05:11 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-09-11 01:44 . 2010-09-11 01:44 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-09-03 21:47 . 2010-09-03 21:47 ——– d—–w- c:\program files\Zone Labs
2010-09-03 21:46 . 2010-09-19 01:59 ——– d—–w- c:\windows\Internet Logs
2010-08-24 22:33 . 2010-08-24 22:33 ——– d—–w- c:\windows\Sun
2010-08-24 22:32 . 2010-08-24 22:32 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-66f0c5bb-n\msvcp71.dll
2010-08-24 22:32 . 2010-08-24 22:32 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-66f0c5bb-n\jmc.dll
2010-08-24 22:32 . 2010-08-24 22:32 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-66f0c5bb-n\msvcr71.dll
2010-08-24 22:32 . 2010-08-24 22:32 ——– d—–w- c:\program files\Common Files\Java
2010-08-24 22:32 . 2010-08-24 22:32 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4d2c44e4-n\decora-d3d.dll
2010-08-24 22:32 . 2010-08-24 22:32 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4d2c44e4-n\decora-sse.dll
2010-08-24 22:31 . 2010-08-24 22:30 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-24 22:30 . 2010-08-24 22:30 ——– d—–w- c:\program files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-13 16:34 . 2010-01-03 21:18 3922 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-09-12 16:51 . 2010-07-28 23:27 ——– d—–w- c:\program files\Windows Live Safety Center
2010-09-03 21:55 . 2010-09-03 21:55 ——– d—–w- c:\documents and settings\Owner\Application Data\CheckPoint
2010-09-03 21:48 . 2010-09-03 21:48 ——– d—–w- c:\program files\ZoneAlarm
2010-09-03 21:48 . 2010-09-03 21:48 ——– d—–w- c:\program files\CheckPoint
2010-09-03 21:48 . 2010-09-03 21:48 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-09-03 21:21 . 2010-08-03 21:39 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-09-01 23:56 . 2010-09-03 21:53 52224 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
2010-09-01 23:56 . 2010-09-03 21:53 101376 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
2010-08-15 15:22 . 2009-12-23 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-03 21:40 . 2010-08-03 21:40 ——– d—–w- c:\program files\AVG
2010-07-29 22:37 . 2010-07-29 22:34 ——– d—–w- c:\program files\iTunes
2010-07-29 22:34 . 2010-07-29 22:34 ——– d—–w- c:\program files\iPod
2010-07-29 22:34 . 2009-12-24 21:23 ——– d—–w- c:\program files\Common Files\Apple
2010-07-29 22:12 . 2010-07-29 22:12 ——– d—–w- c:\program files\Bonjour
2010-07-29 22:09 . 2010-07-29 22:09 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-29 22:06 . 2010-07-18 16:15 ——– d—–w- c:\program files\Safari
2010-07-29 21:59 . 2010-07-29 21:59 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-26 01:16 . 2010-07-26 01:16 38184 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-26 01:15 . 2010-07-25 23:12 120 —-a-w- c:\windows\Fjupijohapuhidon.dat
2010-07-26 00:22 . 2010-02-10 22:30 ——– d—–w- c:\program files\Celebrity Toolbar
2010-07-25 23:12 . 2010-07-25 23:12 0 —-a-w- c:\windows\Sxarakecofezipah.bin
2010-07-18 16:12 . 2010-07-18 16:12 71992 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-07-03 20:36 . 2010-07-03 20:17 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-23 17:51 . 2010-09-03 21:47 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 17:51 . 2010-09-03 21:48 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 17:51 . 2010-09-03 21:48 69120 —-a-w- c:\windows\system32\zlcomm.dll
2008-05-07 08:34 . 2008-08-08 18:09 15523560 —-a-w- c:\program files\U1 Setup.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 104984]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 121368]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 100888]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-07-23 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-07-23 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2009-11-06 6515784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-8-8 303104]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 23:51 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 —-a-w- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 15:34 5724184 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [11/6/2009 1:00 PM 29808]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9/12/2010 9:48 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/12/2010 9:48 PM 17744]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [12/20/2009 10:15 AM 1201640]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/12/2010 9:48 PM 136176]
.
Contents of the 'Scheduled Tasks' folder

2010-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-09-19 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]

2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 01:48]

2010-09-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 01:48]

2010-07-26 c:\windows\Tasks\wrSpySweeper_L8B53FAC4F3A84C4CB2ACC7A95894A522.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-12-20 20:20]

2010-07-26 c:\windows\Tasks\wrSpySweeper_L8B53FAC4F3A84C4CB2ACC7A95894A522.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-12-20 20:20]

2010-09-18 c:\windows\Tasks\wrSpySweeper_LC55EE9AC83A2407EB2C9B6C9EC8E655B.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-12-20 20:20]

2010-09-18 c:\windows\Tasks\wrSpySweeper_LC55EE9AC83A2407EB2C9B6C9EC8E655B.job
- c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe [2009-12-20 20:20]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: &Windows; Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://m.www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q;=
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF - HiddenExtension: XULRunner: {14DA921F-039E-4108-A01D-79FC2DAEAF84} - c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
.
- - - - ORPHANS REMOVED - - - -

URLSearchHooks-{66f2e20d-0da8-4c11-a9c8-dd8477b88acd} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-18 22:01
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(752)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(808)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'explorer.exe'(1364)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
———————— Other Running Processes ————————
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Webroot\WebrootSecurity\SpySweeper.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Alwil Software\Avast5\setup\avast.setup
c:\program files\Webroot\WebrootSecurity\SSU.EXE
.
**************************************************************************
.
Completion time: 2010-09-18 22:08:04 - machine was rebooted
ComboFix-quarantined-files.txt 2010-09-19 02:07

Pre-Run: 48,016,465,920 bytes free
Post-Run: 48,350,486,528 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - 6ABABF062F5BE37AFC13C7C5C21BDF76
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=114622&view=findpost&p=683538

Collect::
c:\windows\Fjupijohapuhidon.dat
c:\windows\system32\sdra64.exe

File::
c:\windows\Sxarakecofezipah.bin

FireFox::
FF - HiddenExtension: XULRunner: {14DA921F-039E-4108-A01D-79FC2DAEAF84} - c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\

DDS::
BHO: MRI_DISABLED
BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} 
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT



You have two antivirus programs installed:


AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Webroot AntiVirus with Spy Sweeper *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}


Having more than one antivirus can cause conflicts, system slowdowns and crashes, I suggest removing one of them.



NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Run an on-line scan with Kaspersky

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
Below are the results of the CFScript.txt into ComboFix.exe and the Malwarebytes' . Attached is a Word document of a screen shot of the Kaspersky scan. I could not save the report because there was nothing detected in the scan.



ComboFix 10-09-17.04 - Owner 09/19/2010 1:22.2.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.202 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: Webroot AntiVirus with Spy Sweeper *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597}
FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

FILE ::
"c:\windows\Sxarakecofezipah.bin"

file zipped: c:\windows\Fjupijohapuhidon.dat
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\\install.rdf
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\chrome.manifest
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\chrome\content\_cfg.js
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\chrome\content\overlay.xul
c:\documents and settings\Owner\Local Settings\Application Data\{14DA921F-039E-4108-A01D-79FC2DAEAF84}\install.rdf
c:\windows\Fjupijohapuhidon.dat
c:\windows\Sxarakecofezipah.bin

.
((((((((((((((((((((((((( Files Created from 2010-08-19 to 2010-09-19 )))))))))))))))))))))))))))))))
.

2010-09-19 03:17 . 2010-09-19 03:17 ——– d—–w- c:\windows\LastGood
2010-09-16 23:37 . 2010-09-16 23:39 ——– dc-h–w- c:\windows\ie8
2010-09-15 01:37 . 2010-09-15 01:40 ——– d—–w- c:\program files\QuickTime
2010-09-13 01:53 . 2010-09-13 01:53 ——– d—–w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2010-09-13 01:49 . 2010-09-16 21:53 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Temp
2010-09-13 01:49 . 2010-09-13 01:49 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2010-09-13 01:48 . 2010-09-13 01:52 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\Google
2010-09-13 01:48 . 2010-09-13 01:50 ——– d—–w- c:\program files\Google
2010-09-13 01:48 . 2010-09-07 14:47 17744 —-a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-13 01:48 . 2010-09-07 14:52 165584 —-a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-13 01:48 . 2010-09-07 14:47 23376 —-a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-13 01:48 . 2010-09-07 14:52 46672 —-a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-13 01:48 . 2010-09-07 14:47 100176 —-a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-13 01:48 . 2010-09-07 14:47 94544 —-a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-13 01:48 . 2010-09-07 14:46 28880 —-a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-13 01:47 . 2010-09-07 15:12 38848 —-a-w- c:\windows\avastSS.scr
2010-09-13 01:47 . 2010-09-07 15:11 167592 —-a-w- c:\windows\system32\aswBoot.exe
2010-09-13 01:47 . 2010-09-13 01:47 ——– d—–w- c:\program files\Alwil Software
2010-09-13 01:47 . 2010-09-13 01:47 ——– d—–w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-09-11 05:11 . 2010-09-11 05:11 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe
2010-09-11 01:44 . 2010-09-11 01:44 ——– d-sh–w- c:\documents and settings\LocalService\IETldCache
2010-09-03 21:47 . 2010-09-03 21:47 ——– d—–w- c:\program files\Zone Labs
2010-09-03 21:46 . 2010-09-19 05:32 ——– d—–w- c:\windows\Internet Logs
2010-08-24 22:33 . 2010-08-24 22:33 ——– d—–w- c:\windows\Sun
2010-08-24 22:32 . 2010-08-24 22:32 503808 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-66f0c5bb-n\msvcp71.dll
2010-08-24 22:32 . 2010-08-24 22:32 499712 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-66f0c5bb-n\jmc.dll
2010-08-24 22:32 . 2010-08-24 22:32 348160 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-66f0c5bb-n\msvcr71.dll
2010-08-24 22:32 . 2010-08-24 22:32 ——– d—–w- c:\program files\Common Files\Java
2010-08-24 22:32 . 2010-08-24 22:32 12800 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4d2c44e4-n\decora-d3d.dll
2010-08-24 22:32 . 2010-08-24 22:32 61440 —-a-w- c:\documents and settings\Owner\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-4d2c44e4-n\decora-sse.dll
2010-08-24 22:31 . 2010-08-24 22:30 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-08-24 22:30 . 2010-08-24 22:30 ——– d—–w- c:\program files\Java

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-19 03:20 . 2010-07-28 23:27 ——– d—–w- c:\program files\Windows Live Safety Center
2010-09-13 16:34 . 2010-01-03 21:18 3922 —-a-w- c:\documents and settings\Owner\Application Data\wklnhst.dat
2010-09-03 21:55 . 2010-09-03 21:55 ——– d—–w- c:\documents and settings\Owner\Application Data\CheckPoint
2010-09-03 21:48 . 2010-09-03 21:48 ——– d—–w- c:\program files\ZoneAlarm
2010-09-03 21:48 . 2010-09-03 21:48 ——– d—–w- c:\program files\CheckPoint
2010-09-03 21:48 . 2010-09-03 21:48 4212 —ha-w- c:\windows\system32\zllictbl.dat
2010-09-03 21:21 . 2010-08-03 21:39 ——– d—–w- c:\documents and settings\All Users\Application Data\avg9
2010-09-01 23:56 . 2010-09-03 21:53 52224 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
2010-09-01 23:56 . 2010-09-03 21:53 101376 —-a-w- c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
2010-08-15 15:22 . 2009-12-23 02:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-03 21:40 . 2010-08-03 21:40 ——– d—–w- c:\program files\AVG
2010-07-29 22:37 . 2010-07-29 22:34 ——– d—–w- c:\program files\iTunes
2010-07-29 22:34 . 2010-07-29 22:34 ——– d—–w- c:\program files\iPod
2010-07-29 22:34 . 2009-12-24 21:23 ——– d—–w- c:\program files\Common Files\Apple
2010-07-29 22:12 . 2010-07-29 22:12 ——– d—–w- c:\program files\Bonjour
2010-07-29 22:09 . 2010-07-29 22:09 73000 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-29 22:06 . 2010-07-18 16:15 ——– d—–w- c:\program files\Safari
2010-07-29 21:59 . 2010-07-29 21:59 72488 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.17.8\SetupAdmin.exe
2010-07-26 01:16 . 2010-07-26 01:16 38184 —-a-w- c:\documents and settings\Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-07-26 00:22 . 2010-02-10 22:30 ——– d—–w- c:\program files\Celebrity Toolbar
2010-07-18 16:12 . 2010-07-18 16:12 71992 —-a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.33.16.0\SetupAdmin.exe
2010-07-03 20:36 . 2010-07-03 20:17 57344 —-a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-06-23 17:51 . 2010-09-03 21:47 1238528 —-a-w- c:\windows\system32\zpeng25.dll
2010-06-23 17:51 . 2010-09-03 21:48 103936 —-a-w- c:\windows\system32\zlcommdb.dll
2010-06-23 17:51 . 2010-09-03 21:48 69120 —-a-w- c:\windows\system32\zlcomm.dll
2008-05-07 08:34 . 2008-08-08 18:09 15523560 —-a-w- c:\program files\U1 Setup.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-09-19_01.59.24 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-19 02:00 . 2010-09-19 02:00 16384 c:\windows\Temp\Perflib_Perfdata_874.dat
+ 2008-08-07 21:23 . 2010-09-19 02:03 71462 c:\windows\system32\perfc009.dat
- 2008-08-07 21:23 . 2010-09-19 01:46 71462 c:\windows\system32\perfc009.dat
+ 2008-09-12 16:08 . 2010-09-19 01:58 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-12 16:08 . 2010-09-19 01:24 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-12 16:08 . 2010-09-19 01:24 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-09-12 16:08 . 2010-09-19 01:58 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-09-12 16:08 . 2010-09-19 01:24 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-09-12 16:08 . 2010-09-19 01:58 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-08-07 21:23 . 2010-09-19 02:03 441692 c:\windows\system32\perfh009.dat
- 2008-08-07 21:23 . 2010-09-19 01:46 441692 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 104984]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 121368]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 100888]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-07-23 98304]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-07-23 479232]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-07-13 47904]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-07-21 141608]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2010-06-23 1043968]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2010-05-26 730600]
"avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-09-07 2838912]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-08-10 421888]
"SpySweeper"="c:\program files\Webroot\WebrootSecurity\SpySweeperUI.exe" [2009-11-06 6515784]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-8-8 303104]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WebrootSpySweeperService]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WRConsumerService]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-10-10 23:51 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2008-06-19 08:20 57344 —-a-w- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2007-10-18 15:34 5724184 —-a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [11/6/2009 1:00 PM 29808]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [9/12/2010 9:48 PM 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [9/12/2010 9:48 PM 17744]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [5/26/2010 9:35 AM 26352]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [5/26/2010 9:35 AM 493032]
R2 WRConsumerService;Webroot Client Service;c:\program files\Webroot\WebrootSecurity\WRConsumerService.exe [12/20/2009 10:15 AM 1201640]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [9/12/2010 9:48 PM 136176]
.
Contents of the 'Scheduled Tasks' folder

2010-02-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]

2010-09-19 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 15:20]

2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 01:48]

2010-09-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-13 01:48]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://m.www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q=
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll
FF - component: c:\program files\CheckPoint\ZAForceField\TrustChecker\components\TrustCheckerMozillaPlugin.dll
FF - plugin: c:\program files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

—- FIREFOX POLICIES —-
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-19 01:32
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(752)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll

- - - - - - - > 'lsass.exe'(808)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
Completion time: 2010-09-19 01:36:20
ComboFix-quarantined-files.txt 2010-09-19 05:36
ComboFix2.txt 2010-09-19 02:08

Pre-Run: 48,481,058,816 bytes free
Post-Run: 48,523,190,272 bytes free

- - End Of File - - 697A3C07AE9DC936FC8D666C071ED4A4
Upload was successful


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4650

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

9/19/2010 1:57:21 AM
mbam-log-2010-09-19 (01-57-21).txt

Scan type: Quick scan
Objects scanned: 131763
Time elapsed: 8 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 10
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{3446af26-b8d7-199b-4cfc-6fd764ca5c9f} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{494e6cec-7483-a4ee-0938-895519a84bc7} (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{c48635ad-d6b5-3ee4-aaa2-540d5a173658} (Backdoor.Bot) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Hi

Please do the following:


Visit ADOBEand download the latest version of Acrobat Reader (version 9.3)
Having the latest updates ensures there are no security vulnerabilities in your system.



NEXT


[external image: Posted Image] Your Java is out of date.
Java™ 6 Update 20 can be updated from the Java control panel Start > Control Panel (Classic View) > Java (looks like a coffee cup) > Update Tab > Update Now.
An update should begin; > follow the prompts.


Clear Sun Jave cache

Go into the Control Panel and double-click the Java Icon. (looks like a coffee cup) If you do not see the icon, look to your left and click 'Switch to Classic View'.
  • On the General tab, under Temporary Internet Files, click the Settings button.
  • Next, click on the Delete Files button
  • There are two options in the window to clear the cache - Leave BOTH Checked
    • Applications and Applets
      Trace and Log Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Window
  • Click OK to leave the Java Control Panel.



NEXT


Please post a fresh DDS Log and advise how your computer is running now and if there are any outstanding issues.
I have done several Google and Yahoo searches and all the links returned are working!!! As far as I can tell everything seems to be running well. Below are the results of the DDS scan. The "attach" file is attached in a zip file. DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 16:36:23.95 on Sun 09/19/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.294 [GMT -4:00] AV: Webroot AntiVirus with Spy Sweeper *On-access scanning disabled* (Updated) {77E10C7F-2CCA-4187-9394-BDBC267AD597} AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} FW: ZoneAlarm Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe C:\Program Files\EeePC\ACPI\AsTray.exe C:\Program Files\EeePC\ACPI\AsAcpiSvr.exe C:\Program Files\EeePC\ACPI\AsEPCMon.exe C:\Program Files\Elantech\ETDCtrl.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\igfxsrvc.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Alwil Software\Avast5\avastUI.exe C:\WINDOWS\system32\igfxext.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\CheckPoint\ZAForceField\ForceField.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\WINDOWS\system32\msiexec.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wscntfy.exe C:\Documents and Settings\Owner\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.yahoo.com/ uInternet Settings,ProxyOverride = *.local BHO: MRI_DISABLED - No File BHO: Skype add-on (mastermind) - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No File BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Toolbar Helper: {bdbd1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll BHO: 1 (0x1) - No File BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: Windows Live Toolbar: {bdad1dad-c946-4a17-adc1-64b5b4ff55d0} - c:\program files\windows live toolbar\msntb.dll uRun: [ctfmon.exe] "c:\windows\system32\ctfmon.exe" uRunOnce: [JavaInstallRetry] "c:\documents and settings\owner\application data\sun\java\JRERunOnce.exe" RUNONCE=1 SPONSORS=0 mRun: [RTHDCPL] "RTHDCPL.EXE" mRun: [IgfxTray] "c:\windows\system32\igfxtray.exe" mRun: [HotKeysCmds] "c:\windows\system32\hkcmd.exe" mRun: [Persistence] "c:\windows\system32\igfxpers.exe" mRun: [AsusTray] "c:\program files\eeepc\acpi\AsTray.exe" mRun: [AsusACPIServer] "c:\program files\eeepc\acpi\AsAcpiSvr.exe" mRun: [AsusEPCMonitor] "c:\program files\eeepc\acpi\AsEPCMon.exe" mRun: [ETDWare] "c:\program files\elantech\ETDCtrl.exe" mRun: [AppleSyncNotifier] "c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe" mRun: [ISW] "c:\program files\checkpoint\zaforcefield\ForceField.exe" /icon="hidden" mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [SpySweeper] "c:\program files\webroot\webrootsecurity\SpySweeperUI.exe" /startintray mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\superh~1.lnk - c:\program files\asus\eeepc\super hybrid engine\SuperHybridEngine.exe IE: &Windows Live Search - c:\program files\windows live toolbar\msntb.dll/search.htm IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~4\office12\ONBttnIE.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office12\REFIEBAR.DLL DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1261312389765 DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1261312381515 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL Notify: igfxcui - igfxdev.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\ypm182qo.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://m.www.yahoo.com/ FF - prefs.js: keyword.URL - hxxp://search.myheritage.com/?orig=ds&q= FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\FFExternalAlert.dll FF - component: c:\documents and settings\owner\application data\mozilla\firefox\profiles\ypm182qo.default\extensions\{66f2e20d-0da8-4c11-a9c8-dd8477b88acd}\components\RadioWMPCore.dll FF - component: c:\program files\checkpoint\zaforcefield\trustchecker\components\TrustCheckerMozillaPlugin.dll FF - plugin: c:\program files\checkpoint\zaforcefield\trustchecker\bin\npFFApi.dll FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbaam7a8h", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true); c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); ============= SERVICES / DRIVERS =============== R0 ssfs0bbc;ssfs0bbc;c:\windows\system32\drivers\ssfs0bbc.sys [2009-11-6 29808] R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-9-12 165584] R1 vsdatant;vsdatant;c:\windows\system32\vsdatant.sys [2010-9-3 532224] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-9-12 17744] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-12 40384] R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\checkpoint\zaforcefield\ISWKL.sys [2010-5-26 26352] R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\checkpoint\zaforcefield\ISWSVC.exe [2010-5-26 493032] R2 vsmon;TrueVector Internet Monitor;c:\windows\system32\zonelabs\vsmon.exe -service –> c:\windows\system32\zonelabs\vsmon.exe -service [?] R2 WebrootSpySweeperService;Webroot Spy Sweeper Engine;c:\program files\webroot\webrootsecurity\SpySweeper.exe [2009-11-6 4048240] R2 WRConsumerService;Webroot Client Service;c:\program files\webroot\webrootsecurity\WRConsumerService.exe [2009-12-20 1201640] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-9-12 136176] S3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-12 40384] S3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-9-12 40384] =============== Created Last 30 ================ 2010-09-19 05:47:08 0 d—–w- c:\docume~1\owner\applic~1\Malwarebytes 2010-09-19 05:46:58 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-09-19 05:46:57 0 d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-09-19 05:46:56 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-09-19 05:46:56 0 d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-09-19 01:34:24 0 d-sha-r- C:\cmdcons 2010-09-19 01:30:53 98816 —-a-w- c:\windows\sed.exe 2010-09-19 01:30:53 77312 —-a-w- c:\windows\MBR.exe 2010-09-19 01:30:53 256512 —-a-w- c:\windows\PEV.exe 2010-09-19 01:30:53 161792 —-a-w- c:\windows\SWREG.exe 2010-09-16 23:37:16 0 dc-h–w- c:\windows\ie8 2010-09-13 01:47:54 38848 —-a-w- c:\windows\avastSS.scr 2010-09-13 01:47:45 0 d—–w- c:\docume~1\alluse~1\applic~1\Alwil Software 2010-09-03 21:55:25 0 d—–w- c:\docume~1\owner\applic~1\CheckPoint 2010-09-03 21:48:40 0 d—–w- c:\program files\ZoneAlarm 2010-09-03 21:48:24 0 d—–w- c:\program files\CheckPoint 2010-09-03 21:48:21 4212 —ha-w- c:\windows\system32\zllictbl.dat 2010-09-03 21:47:50 1238528 —-a-w- c:\windows\system32\zpeng25.dll 2010-09-03 21:47:43 0 d—–w- c:\windows\system32\ZoneLabs 2010-09-03 21:47:32 421442 —-a-w- c:\windows\system32\vsconfig.xml 2010-09-03 21:47:30 0 d—–w- c:\program files\Zone Labs 2010-09-03 21:46:54 0 d—–w- c:\windows\Internet Logs 2010-08-24 22:31:54 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-08-24 22:31:53 423656 —-a-w- c:\windows\system32\deployJava1.dll ==================== Find3M ==================== 2010-09-13 16:34:16 3922 —-a-w- c:\docume~1\owner\applic~1\wklnhst.dat 2010-08-17 13:17:06 58880 —-a-w- c:\windows\system32\spoolsv.exe 2010-07-22 15:49:15 590848 —-a-w- c:\windows\system32\rpcrt4.dll 2010-07-22 05:57:20 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2010-06-30 12:31:35 149504 —-a-w- c:\windows\system32\schannel.dll 2010-06-24 12:22:03 916480 —-a-w- c:\windows\system32\wininet.dll 2010-06-23 13:44:04 1851904 —-a-w- c:\windows\system32\win32k.sys 2008-05-07 08:34:00 15523560 —-a-w- c:\program files\U1 Setup.exe ============= FINISH: 16:37:35.98 ===============

Attachments:

Hi

Just some housekeeping to do now,

Please do the following:

You can delete the MBRCheck, DDS and GMER logs and programs from your desktop.


NEXT


Follow these steps to uninstall Combofix

  • Make sure your security programs are totally disabled.
  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

If there are any logs/tools remaining > right click and delete them.


NEXT


Below I have included a number of recommendations for how to protect your computer against malware infections.

  • It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
    Strong passwords: How to create and use them
    Then consider a password keeper, to keep all your passwords safe.

  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • Download TFC to your desktop
    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run,
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish it's job
    • Once its finished it should automatically reboot your machine,
    • if it doesn't, manually reboot to ensure a complete clean
    It's normal after running TFC cleaner that the PC will be slower to boot the first time.

  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
    • Green to go
    • Yellow for caution
    • Red to stop
    WOT has an addon available for both Firefox and IE

  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • In light of your recent issue, I'm sure you'd like to avoid any future infections. Please take a look at these well written articles:
    Think Prevention.
    PC Safety and Security–What Do I Need?.


**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.


Thank you for your patience, and performing all of the procedures requested.

Please respond one last time so we can consider the thread resolved and close it, thank-you.
I have followed all your recommendations and am now reading all the prevention documents you listed. I can't thank you enough for helping me resolve my computer problems. THANK YOU!!!!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI