This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HiJackThis Log - Please Help

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can somebody please help me find the culprit?
*****************************************************************
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:36:27 AM, on 01/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\Toshiba\Tvs\TvsTray.exe
C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Lexmark 7100 Series\lxbxmon.exe
C:\Program Files\Lexmark 7100 Series\ezprint.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\lxbxcoms.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MICROS~2\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.6.5612.1312\swg.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [Tvs] C:\Program Files\Toshiba\Tvs\TvsTray.exe
O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [LXBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [lxbxmon.exe] "C:\Program Files\Lexmark 7100 Series\lxbxmon.exe"
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ebozaqib] rundll32.exe "C:\WINDOWS\egiqaxac.dll",Startup
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - S-1-5-18 Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')
O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200707…ex/qtplugin.cab
O16 - DPF: {050A3800-6C03-48A5-A6D7-14CCF18A700D} (v4 silent install) - https://homebase.prestigehomes.ca/Citrix/Me…te/v4icachk.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - https://homebase.prestigehomes.ca/Citrix/Me…ca32/wficat.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1208265820317
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - - (no file)
O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbxcoms.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
Hi

Please do the following:

  • Open HiJackThis
  • Click on Do a system scan only
  • Check the boxes next to ONLY the entries listed below (if still present):


O4 - HKLM\..\Run: [Ebozaqib] rundll32.exe "C:\WINDOWS\egiqaxac.dll",Startup
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwssvc.exe

  • Close all windows except Hijackthis and click Fix Checked
  • Click Yes when prompted
  • Close HijackThis.


NEXT



Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • if an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.



NEXT



Please download DDS from either of these links

LINK 1
LINK 2

and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.pif to run the tool.
  • When done, two DDS.txt's will open.
  • Save both reports to your desktop.
—————————————————
Please include the contents of the following in your next reply:

DDS.txt
Attach.txt.



NEXT


Download GMER Rootkit Scanner from here to your desktop. It will be a randomly named executable.
  • Double click the exe file.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO, then use the following settings for a more complete scan.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are unchecked
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Thanks CatByte!!! Hope you can help me! Here is my MBRCheck txt file ********************************* MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 3 (build 2600) Logical Drives Mask: 0x0000000c Kernel Drivers (total 155): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EE000 \WINDOWS\system32\hal.dll 0xF7AD6000 \WINDOWS\system32\KDCOM.DLL 0xF79E6000 \WINDOWS\system32\BOOTVID.dll 0xF7587000 ACPI.sys 0xF7AD8000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF7576000 pci.sys 0xF75D6000 isapnp.sys 0xF75E6000 ohci1394.sys 0xF75F6000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF79EA000 compbatt.sys 0xF79EE000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xF7B9E000 pciide.sys 0xF7856000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7ADA000 intelide.sys 0xF7558000 pcmcia.sys 0xF7606000 MountMgr.sys 0xF7539000 ftdisk.sys 0xF79F2000 ACPIEC.sys 0xF7B9F000 \WINDOWS\system32\DRIVERS\OPRGHDLR.SYS 0xF785E000 PartMgr.sys 0xF7616000 VolSnap.sys 0xF7521000 atapi.sys 0xF7626000 disk.sys 0xF7636000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF7501000 fltmgr.sys 0xF74EF000 sr.sys 0xF74D9000 DRVMCDB.SYS 0xF7866000 PxHelp20.sys 0xF74C2000 KSecDD.sys 0xF7435000 Ntfs.sys 0xF7408000 NDIS.sys 0xF73EE000 Mup.sys 0xF7666000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF7676000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF7AC6000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0xB9E23000 \SystemRoot\system32\DRIVERS\ialmnt5.sys 0xB9E0F000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xB9DE7000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xB9DAC000 \SystemRoot\system32\DRIVERS\yk51x86.sys 0xF7916000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0xB9D88000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF791E000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xB9A65000 \SystemRoot\system32\DRIVERS\w29n51.sys 0xF7686000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7926000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xB9A36000 \SystemRoot\system32\DRIVERS\SynTP.sys 0xF7B12000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF792E000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7696000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF7936000 \SystemRoot\system32\drivers\iviaspi.sys 0xF7ACE000 \SystemRoot\system32\drivers\pfc.sys 0xF7B14000 \SystemRoot\System32\Drivers\DLACDBHM.SYS 0xF76A6000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF76B6000 \SystemRoot\system32\DRIVERS\redbook.sys 0xB9A13000 \SystemRoot\system32\DRIVERS\ks.sys 0xB99D6000 \SystemRoot\system32\DRIVERS\iwca.sys 0xF7BFF000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF77C6000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xBA7E0000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xB99BF000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF77D6000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF77E6000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF79CE000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xB99AE000 \SystemRoot\system32\DRIVERS\psched.sys 0xF77F6000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF79D6000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF79DE000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF7806000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7B28000 \SystemRoot\system32\DRIVERS\swenum.sys 0xB9950000 \SystemRoot\system32\DRIVERS\update.sys 0xBA7D8000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF7B2A000 \SystemRoot\system32\DRIVERS\NBSMI.sys 0xF7816000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xA93F1000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xA93CD000 \SystemRoot\system32\drivers\portcls.sys 0xF7846000 \SystemRoot\system32\drivers\drmk.sys 0xF76C6000 \SystemRoot\system32\DRIVERS\Tvs.sys 0xF7886000 \SystemRoot\system32\DRIVERS\tsxt_kern_i386.sys 0xF7896000 \SystemRoot\system32\DRIVERS\wowhd_kern_i386.sys 0xF76D6000 \SystemRoot\system32\DRIVERS\csiidecoder_kern_i386.sys 0xA92BA000 \SystemRoot\system32\DRIVERS\AGRSM.sys 0xF789E000 \SystemRoot\System32\Drivers\Modem.SYS 0xF76F6000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7B60000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7D1C000 \SystemRoot\System32\Drivers\Null.SYS 0xF7B62000 \SystemRoot\System32\Drivers\Beep.SYS 0xF78C6000 \SystemRoot\System32\Drivers\DLARTL_N.SYS 0xF78CE000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF78D6000 \SystemRoot\System32\drivers\vga.sys 0xF7B64000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7B66000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xA9259000 \SystemRoot\System32\Drivers\meiudf.sys 0xA9248000 \SystemRoot\System32\Drivers\Udfs.SYS 0xF78DE000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF78E6000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF7ACA000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xA9235000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xA91DC000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xA91B4000 \SystemRoot\system32\DRIVERS\netbt.sys 0xBA7F4000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xA9192000 \SystemRoot\System32\drivers\afd.sys 0xF7716000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF78EE000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0xA9167000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xA90CF000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF7706000 \SystemRoot\System32\Drivers\Fips.SYS 0xA90A9000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF7726000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF7746000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xA8FE7000 \SystemRoot\system32\DRIVERS\avipbb.sys 0xF7B6A000 \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys 0xA8FCF000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7B6C000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF7A96000 \SystemRoot\System32\drivers\Dxapi.sys 0xF78FE000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C03000 \SystemRoot\System32\drivers\dxgthk.sys 0xF7906000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0xF7A9A000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF7776000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF790E000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xF7A9E000 \SystemRoot\System32\Drivers\BrScnUsb.sys 0xA92B6000 \SystemRoot\System32\Drivers\BrUsbSer.sys 0xA8F96000 \SystemRoot\System32\Drivers\BrSerIf.sys 0xA92AE000 \SystemRoot\system32\DRIVERS\mouhid.sys 0xBF020000 \SystemRoot\System32\ialmdnt5.dll 0xBF012000 \SystemRoot\System32\ialmrnt5.dll 0xBF042000 \SystemRoot\System32\ialmdev5.DLL 0xBF073000 \SystemRoot\System32\ialmdd5.DLL 0xBFFA0000 \SystemRoot\System32\ATMFD.DLL 0xA8E41000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0xA9099000 \SystemRoot\System32\Drivers\DRVNDDM.SYS 0xF7C27000 \SystemRoot\System32\DLA\DLADResN.SYS 0xA8E2B000 \SystemRoot\System32\DLA\DLAIFS_M.SYS 0xA8F6E000 \SystemRoot\System32\DLA\DLAOPIOM.SYS 0xF7B8E000 \SystemRoot\System32\DLA\DLAPoolM.SYS 0xF795E000 \SystemRoot\System32\DLA\DLABOIOM.SYS 0xA8E14000 \SystemRoot\System32\DLA\DLAUDFAM.SYS 0xA8DFE000 \SystemRoot\System32\DLA\DLAUDF_M.SYS 0xA8E7E000 \SystemRoot\system32\DRIVERS\AegisP.sys 0xA8E7A000 \SystemRoot\system32\DRIVERS\s24trans.sys 0xA8DD6000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xA8DD2000 \SystemRoot\system32\DRIVERS\netdevio.sys 0xA8B51000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xA89F8000 \SystemRoot\System32\Drivers\HTTP.sys 0xA88D9000 \SystemRoot\system32\DRIVERS\srv.sys 0xF7946000 \??\C:\WINDOWS\system32\drivers\symlcbrd.sys 0xA848C000 \SystemRoot\system32\drivers\wdmaud.sys 0xA8C06000 \SystemRoot\system32\drivers\sysaudio.sys 0xA6F72000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xBF151000 \SystemRoot\System32\spool\DRIVERS\W32X86\2\ppbint.dll 0xA6B4A000 \SystemRoot\system32\drivers\kmixer.sys 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 63): 0 System Idle Process 4 System 876 C:\WINDOWS\system32\smss.exe 980 csrss.exe 1004 C:\WINDOWS\system32\winlogon.exe 1048 C:\WINDOWS\system32\services.exe 1060 C:\WINDOWS\system32\lsass.exe 1260 C:\WINDOWS\system32\svchost.exe 1328 svchost.exe 1468 C:\WINDOWS\system32\svchost.exe 1504 C:\Program Files\Intel\Wireless\Bin\EvtEng.exe 1628 C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe 1740 svchost.exe 1944 svchost.exe 232 C:\WINDOWS\system32\spoolsv.exe 532 C:\Program Files\Avira\AntiVir Desktop\sched.exe 800 C:\WINDOWS\system32\rundll32.exe 820 svchost.exe 1376 C:\Program Files\Avira\AntiVir Desktop\avguard.exe 1396 C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe 1532 C:\WINDOWS\system32\DVDRAMSV.exe 1800 C:\Program Files\Java\jre6\bin\jqs.exe 1840 C:\Program Files\Avira\AntiVir Desktop\avshadow.exe 1872 C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe 116 C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe 1172 C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 500 C:\WINDOWS\system32\svchost.exe 584 C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe 1460 C:\Program Files\Canon\CAL\CALMAIN.exe 2476 C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe 2656 C:\WINDOWS\explorer.exe 2792 C:\Program Files\Intel\Wireless\Bin\1XConfig.exe 3080 C:\Program Files\Avira\AntiVir Desktop\avmailc.exe 3136 C:\Program Files\Avira\AntiVir Desktop\avwebgrd.exe 3784 alg.exe 3888 C:\WINDOWS\agrsmmsg.exe 3996 C:\WINDOWS\RTHDCPL.exe 184 C:\WINDOWS\system32\ctfmon.exe 2064 C:\Program Files\Toshiba\TOSHIBA Zooming Utility\SmoothView.exe 2076 C:\Program Files\Toshiba\Tvs\TvsTray.exe 2088 C:\Program Files\Toshiba\TOSHIBA Applet\THotkey.exe 2108 C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe 756 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 2172 C:\Program Files\Synaptics\SynTP\Toshiba.exe 2248 C:\WINDOWS\system32\TPSMain.exe 2632 C:\Program Files\Brother\ControlCenter2\brctrcen.exe 2648 C:\WINDOWS\system32\TPSBattM.exe 2512 C:\Program Files\Lexmark 7100 Series\lxbxmon.exE 4088 C:\Program Files\Lexmark 7100 Series\ezprint.exe 252 C:\Program Files\Avira\AntiVir Desktop\avgnt.exe 1516 C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe 1720 C:\WINDOWS\system32\ctfmon.exe 2620 C:\Program Files\Windows Live\Messenger\msnmsgr.exe 2824 C:\WINDOWS\system32\svchost.exe 2308 C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 2976 C:\WINDOWS\system32\lxbxcoms.exe 4072 C:\WINDOWS\system32\wscntfy.exe 4084 C:\WINDOWS\system32\dllhost.exe 120 msdtc.exe 4020 C:\Program Files\Internet Explorer\iexplore.exe 1808 C:\Program Files\Internet Explorer\iexplore.exe 948 C:\Program Files\Internet Explorer\iexplore.exe 3248 C:\Documents and Settings\Marcel A Cote\Local Settings\Temporary Internet Files\Content.IE5\QS9SND8K\MBRCheck[1].exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) PhysicalDrive0 Model Number: HTS541080G9SA00, Rev: MB4OC60D Size Device Name MBR Status ——————————————– 74 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: 31D100779DE502702C374F7C15687B56FCFD5528 Done!
Hi Again, Here's the DDS contents with the Attach file attached. ******************************************* DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 10:27:35.34 on 01/10/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_21 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1015.498 [GMT -3:00] AV: AntiVir Desktop *On-access scanning disabled* (Updated) {C19476D9-52BC-4E93-8AF3-CCF59F7AE8FE} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir Desktop\sched.exe C:\WINDOWS\system32\rundll32.exe svchost.exe C:\Program Files\Avira\AntiVir Desktop\avguard.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Avira\AntiVir Desktop\avshadow.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe C:\Program Files\Canon\CAL\CALMAIN.exe C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe C:\Program Files\Avira\AntiVir Desktop\avmailc.exe C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe C:\Program Files\Toshiba\Tvs\TvsTray.exe C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Synaptics\SynTP\Toshiba.exe C:\WINDOWS\system32\TPSMain.exe C:\Program Files\Brother\ControlCenter2\brctrcen.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\Lexmark 7100 Series\lxbxmon.exe C:\Program Files\Lexmark 7100 Series\ezprint.exe C:\Program Files\Avira\AntiVir Desktop\avgnt.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\lxbxcoms.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\dllhost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Marcel A Cote\Desktop\dds.com ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.ca/ mSearchAssistant = hxxp://www.google.com/ie mURLSearchHooks: N/A: {00a6faf6-072e-44cf-8957-5838f569a31d} - c:\program files\mywebsearch\bar\2.bin\MWSSRCAS.DLL BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5612.1312\swg.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File TB: Ask Toolbar: {3041d03e-fd4b-44e0-b742-2d9b88305f98} - c:\program files\askbardis\bar\bin\askBar.dll TB: My Web Search: {07b18ea9-a523-4961-b6bb-170de4475cca} - c:\program files\mywebsearch\bar\2.bin\MWSBAR.DLL TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll uRun: [TOSCDSPD] c:\program files\toshiba\toscdspd\toscdspd.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MsnMsgr] "c:\program files\windows live\messenger\MsnMsgr.Exe" /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" mRun: [AGRSMMSG] AGRSMMSG.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Alcmtr] ALCMTR.EXE mRun: [SmoothView] c:\program files\toshiba\toshiba zooming utility\SmoothView.exe mRun: [Tvs] c:\program files\toshiba\tvs\TvsTray.exe mRun: [THotkey] c:\program files\toshiba\toshiba applet\thotkey.exe mRun: [IntelZeroConfig] c:\program files\intel\wireless\bin\ZCfgSvc.exe mRun: [IntelWireless] c:\program files\intel\wireless\bin\ifrmewrk.exe /tf Intel PROSet/Wireless mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [TPSMain] TPSMain.exe mRun: [LXBXCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\LXBXtime.dll,_RunDLLEntry@16 mRun: [SetDefPrt] c:\program files\brother\brmfl04g\BrStDvPt.exe mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun mRun: [lxbxmon.exe] "c:\program files\lexmark 7100 series\lxbxmon.exe" mRun: [FaxCenterServer4_in_1] "c:\program files\lexmark 7100 series\fm3032.exe" /s mRun: [EzPrint] "c:\program files\lexmark 7100 series\ezprint.exe" mRun: [avgnt] "c:\program files\avira\antivir desktop\avgnt.exe" /min mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [Ebozaqib] rundll32.exe "c:\windows\egiqaxac.dll",Startup dRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE LSP: c:\program files\avira\antivir desktop\avsda.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20070711/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {050A3800-6C03-48A5-A6D7-14CCF18A700D} - hxxps://homebase.prestigehomes.ca/Citrix/MetaFrame/site/v4icachk.cab DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} - hxxps://homebase.prestigehomes.ca/Citrix/MetaFrame/ICAWEB_common/en/ica32/wficat.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1208265820317 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Name-Space Handler: ftp\* - {419A0123-4312-1122-A0C0-434FDA6DA542} - c:\program files\coreftp\pftpns.dll Notify: igfxcui - igfxdev.dll Notify: IntelWireless - c:\program files\intel\wireless\bin\LgNotify.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\marcel~1\applic~1\mozilla\firefox\profiles\9l4jbxsr.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - MyWebSearch FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp? id=ZUfox000&fl=0&ptb=ZMRTyiZD8Ep9c4G6cj_YZw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor= FF - component: c:\documents and settings\marcel a cote\application data\mozilla\firefox\profiles\9l4jbxsr.default\extensions\{3112ca9c-de6d-4884-a869- 9855de68056c}\components\frozen.dll FF - plugin: c:\program files\google\update\1.2.183.29\npGoogleOneClick8.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mywebsearch\bar\firefox\NPMYWEBS.DLL FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: XULRunner: {6F15A4C8-1030-45DB-B180-AA846EC15DE6} - c:\documents and settings\marcel a cote\local settings\application data\{6F15A4C8- 1030-45DB-B180-AA846EC15DE6} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} —- FIREFOX POLICIES —- pref(dom.disable_open_during_load, true); ============= SERVICES / DRIVERS =============== R1 avgio;avgio;c:\program files\avira\antivir desktop\avgio.sys [2010-6-22 11608] R2 AntiVirMailService;Avira AntiVir MailGuard;c:\program files\avira\antivir desktop\avmailc.exe [2010-6-22 337064] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\avira\antivir desktop\sched.exe [2010-6-22 135336] R2 AntiVirService;Avira AntiVir Guard;c:\program files\avira\antivir desktop\avguard.exe [2010-6-22 267432] R2 AntiVirWebService;Avira AntiVir WebGuard;c:\program files\avira\antivir desktop\avwebgrd.exe [2010-6-22 405672] R2 avgntflt;avgntflt;c:\windows\system32\drivers\avgntflt.sys [2010-6-22 60936] S1 podmenadrv;podmenadrv; [x] S2 aawservice;Ad-Aware 2007 Service; [x] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-4-22 135664] S2 MyWebSearchService;My Web Search Service;c:\progra~1\mywebs~1\bar\2.bin\mwssvc.exe [2010-1-23 28762] S2 podmena;podmena;c:\windows\system32\svchost.exe -k podmena [2005-11-24 14336] S2 SSIPDDP;SSIPDDP Parallel port device driver; [x] =============== Created Last 30 ================ 2010-10-01 12:24:12 120 —-a-w- c:\windows\Dcoxuvel.dat 2010-09-30 14:20:18 0 d—–w- c:\windows\system32\NtmsData 2010-09-30 01:28:37 0 —-a-w- c:\windows\Pvacunirumecahal.bin 2010-09-30 01:26:45 227 —-a-w- c:\windows\system32\winset.ini 2010-09-30 01:26:39 67072 –sha-r- c:\windows\system32\vdmdbgt.dll 2010-09-30 00:57:36 0 d—–w- C:\Adobe_Photoshop_CS3 2010-09-26 13:07:30 0 d—–w- c:\docume~1\marcel~1\applic~1\FrostWire 2010-09-26 13:07:10 0 d—–w- c:\program files\FrostWire 2010-09-26 13:06:53 73728 —-a-w- c:\windows\system32\javacpl.cpl 2010-09-26 13:06:53 423656 —-a-w- c:\windows\system32\deployJava1.dll 2010-09-13 14:55:02 0 d—–w- c:\documents and settings\marcel a cote\IGC 2010-09-13 14:54:01 0 d—–w- c:\program files\IGC ==================== Find3M ==================== 2010-08-17 13:17:06 58880 —-a-w- c:\windows\system32\spoolsv.exe 2010-07-22 15:49:15 590848 —-a-w- c:\windows\system32\rpcrt4.dll 2010-07-22 05:57:20 5120 —-a-w- c:\windows\system32\xpsp4res.dll 2009-10-16 14:36:16 56 –sh–r- c:\windows\system32\641A3D4AE2.sys 2009-10-16 14:36:16 1786 –sha-w- c:\windows\system32\KGyGaAvL.sys 2008-10-17 12:50:34 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008101720081018 \index.dat 2009-06-10 18:54:55 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009061020090611 \index.dat ============= FINISH: 10:28:35.14 ===============

Attachments:

If you are having trouble running GMER, please try running it in safe mode or just with the "sections" and the "C:\" drive checked.

If you are still having trouble running it, try this scanner instead:

Scan With RootKitUnHooker


  • Please Download Rootkit Unhooker and save it to your desktop.
  • Now double-click on RKUnhookerLE.exe to run it.
  • Click the Report tab, then click Scan.
  • Check (Tick) Drivers and Stealth
  • Uncheck the rest. then click OK
  • When prompted to Select Disks for Scan, make sure C:\ is checked and click OK
  • Wait till the scanner has finished and then click File > Save Report.
  • Save the report somewhere where you can find it. Click Close.
  • Copy the entire contents of the report and paste it in your next reply.

Note** you may get the following warning, just click OK and continue.

"Rootkit Unhooker has detected a parasite inside itself!

It is recommended to remove parasite, okay?"
Hi,

Please do the following:

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
Hi

Please do the following:

  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
  • They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy')

http://forums.whatthetech.com/index.php?showtopic=114836&view=findpost&p=686200

Collect::
c:\windows\Dcoxuvel.dat
c:\windows\system32\vdmdbgt.dll

File::
c:\windows\Pvacunirumecahal.bin

FireFox::
FF - ProfilePath - c:\documents and settings\Marcel A Cote\Application Data\Mozilla\Firefox\Profiles\9l4jbxsr.default\
FF - prefs.js: browser.search.selectedEngine - MyWebSearch
FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZUfox000&fl=0&ptb=ZMRTyiZD8Ep9c4G6cj_YZw&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=kwd&searchfor=

Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste')

Save this file to your desktop, Save this as "CFScript"


Here's how to do that:

1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …

[external image: Posted Image]
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you.
  • Copy and paste the contents of the log in your next reply.

CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.


NEXT


Please download Malwarebytes' Anti-Malware
  • Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



NEXT


Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI