This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

"Adware" infected laptop

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

I haven't seen that before.

Delete the copy of combofix you have. Download a new copy from the links given earlier.

Rename the file to jgh.exe before you download it. Try running it in normal windows with the right click.
That seemed to work

ComboFix 10-12-28.02 - Kiki Wiki 12/28/2010 21:23:24.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.2448 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\jgh.exe
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: IObit Security 360 *Disabled/Updated* {FAE2835A-B90A-9E7A-85DA-82DBDA7C1E3A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\users\Kiki Wiki\isofix.exe
c:\users\Kiki Wiki\raw2wav.exe

.
((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-29 )))))))))))))))))))))))))))))))
.

2010-12-29 04:32 . 2010-12-29 04:32 ——– d—–w- c:\users\Kiki Wiki\AppData\Local\temp
2010-12-29 04:32 . 2010-12-29 04:32 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-12-29 04:32 . 2010-12-29 04:32 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-12-29 02:49 . 2010-12-29 04:18 ——– d—–w- C:\ComboFix
2010-12-28 02:52 . 2010-12-28 02:52 ——– d—–w- C:\_OTL
2010-12-26 04:52 . 2010-12-26 04:52 ——– d—–w- c:\program files\CCleaner
2010-12-26 03:48 . 2010-12-26 03:50 56400 —-a-w- c:\windows\system32\drivers\tmrkb.sys
2010-12-26 03:48 . 2010-12-26 03:50 190032 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2010-12-25 17:09 . 2010-12-25 17:09 ——– d—–w- c:\users\Kiki Wiki\AppData\Local\Apps
2010-12-24 22:20 . 2010-12-27 00:03 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-12-24 22:20 . 2010-12-24 22:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-12-24 18:31 . 2010-12-24 18:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-12-24 18:27 . 2010-12-24 18:27 ——– d—–w- c:\users\Kiki Wiki\AppData\Local\Sunbelt Software
2010-12-24 18:26 . 2010-12-24 18:31 ——– d—–w- c:\programdata\Lavasoft
2010-12-24 18:26 . 2010-12-24 18:26 ——– d—–w- c:\program files\Lavasoft
2010-12-23 16:48 . 2010-12-23 16:48 241664 —-a-w- c:\windows\Wbegua.exe
2010-12-23 16:48 . 2010-12-23 16:48 61440 –sha-r- c:\windows\system32\rasgcwh.dll
2010-12-22 03:47 . 2010-11-10 04:33 6273872 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{776D7CC6-4B5C-4C22-AC26-3D1887B4B614}\mpengine.dll
2010-12-16 20:10 . 2010-12-22 17:08 ——– d—–w- c:\programdata\regid.1986-12.com.adobe
2010-12-16 20:02 . 2010-12-16 20:02 ——– d—–w- c:\program files\Adobe Media Player
2010-12-16 18:45 . 2010-12-16 19:45 1228400 —-a-w- c:\users\Kiki Wiki\Photoshop_12_LS1.exe
2010-12-16 18:41 . 2010-12-29 04:11 ——– d—–w- c:\program files\Common Files\Akamai
2010-12-14 22:03 . 2010-10-12 13:41 66048 —-a-w- c:\program files\Windows Mail\wabmig.exe
2010-12-14 22:03 . 2010-10-12 13:41 515584 —-a-w- c:\program files\Windows Mail\wab.exe
2010-12-14 22:03 . 2010-10-12 15:53 33280 —-a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-14 22:03 . 2010-10-28 13:20 2048 —-a-w- c:\windows\system32\tzres.dll
2010-12-14 22:00 . 2010-11-04 18:55 352768 —-a-w- c:\windows\system32\taskschd.dll
2010-12-14 22:00 . 2010-11-04 18:55 601600 —-a-w- c:\windows\system32\schedsvc.dll
2010-12-14 22:00 . 2010-11-04 18:56 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-14 22:00 . 2010-11-04 18:55 270336 —-a-w- c:\windows\system32\taskcomp.dll
2010-12-14 22:00 . 2010-11-04 16:34 171520 —-a-w- c:\windows\system32\taskeng.exe
2010-12-14 21:59 . 2010-10-18 13:31 2038272 —-a-w- c:\windows\system32\win32k.sys
2010-12-14 21:59 . 2010-11-03 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-04 04:53 . 2010-12-04 04:53 ——– d—–w- c:\program files\MSN Toolbar
2010-11-30 00:38 . 2010-11-30 00:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 00:38 . 2010-11-30 00:38 69632 —-a-w- c:\windows\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 22:41 . 2010-11-18 22:32 319456 —-a-w- c:\windows\DIFxAPI.dll
2010-11-03 02:29 . 2010-11-18 22:41 1084008 —-a-w- c:\windows\system32\RTSndMgr.cpl
2010-11-03 02:29 . 2010-11-18 22:41 3228712 —-a-w- c:\windows\system32\drivers\RTKVHDA.sys
2010-11-03 02:29 . 2010-11-18 22:41 1889896 —-a-w- c:\windows\system32\RtkPgExt.dll
2010-11-03 02:29 . 2010-11-18 22:41 68200 —-a-w- c:\windows\system32\RtkCoInst.dll
2010-11-03 02:28 . 2010-11-18 22:41 461416 —-a-w- c:\windows\system32\RtkApoApi.dll
2010-11-03 02:28 . 2010-11-18 22:41 3633256 —-a-w- c:\windows\system32\RtkAPO.dll
2010-11-03 02:28 . 2010-11-18 22:41 561256 —-a-w- c:\windows\system32\RCoRes.dat
2010-11-03 02:28 . 2010-11-18 22:41 406120 —-a-w- c:\windows\system32\DTSVoiceClarityDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 962664 —-a-w- c:\windows\system32\DTSS2HeadphoneDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 429160 —-a-w- c:\windows\system32\DTSSymmetryDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 291432 —-a-w- c:\windows\system32\DTSNeoPCDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 1132648 —-a-w- c:\windows\system32\DTSS2SpeakerDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 224360 —-a-w- c:\windows\system32\DTSLimiterDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 107112 —-a-w- c:\windows\system32\DTSLFXAPO.dll
2010-11-03 02:28 . 2010-11-18 22:41 107112 —-a-w- c:\windows\system32\DTSGFXAPO.dll
2010-11-03 02:28 . 2010-11-18 22:41 106600 —-a-w- c:\windows\system32\DTSGFXAPONS.dll
2010-11-03 02:27 . 2010-11-18 22:41 901224 —-a-w- c:\windows\system32\DTSBoostDLL.dll
2010-11-03 02:27 . 2010-11-18 22:41 448616 —-a-w- c:\windows\system32\DTSBassEnhancementDLL.dll
2010-11-03 02:27 . 2010-11-18 22:41 236648 —-a-w- c:\windows\system32\DTSGainCompensatorDLL.dll
2010-10-28 17:46 . 2010-11-18 22:41 1251944 —-a-w- c:\windows\RtlExUpd.dll
2010-10-26 20:02 . 2010-11-18 22:41 1558432 —-a-w- c:\windows\system32\FMAPO.dll
2010-10-26 16:15 . 2010-11-18 22:41 94352 —-a-w- c:\windows\system32\R4EEL32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 59536 —-a-w- c:\windows\system32\R4EEG32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 339600 —-a-w- c:\windows\system32\R4EED32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 1703568 —-a-w- c:\windows\system32\R4EEP32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 78992 —-a-w- c:\windows\system32\R4EEA32A.dll
2010-10-19 17:41 . 2009-10-02 21:50 222080 ——w- c:\windows\system32\MpSigStub.exe
2010-10-04 23:12 . 2010-11-18 22:41 1725784 —-a-w- c:\windows\system32\WavesGUILib.dll
2010-10-04 23:12 . 2010-11-18 22:41 1336664 —-a-w- c:\windows\system32\MaxxAudioRealtek.dll
2010-10-03 20:45 . 2010-11-18 22:41 259928 —-a-w- c:\windows\system32\MaxxAudioAPO30.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-03 9808488]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WG111T Smart Wizard.lnk - c:\program files\NETGEAR\WG111T\wlan111t.exe [2007-10-1 884840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 06:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 11:47 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-09-22 07:28 47904 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bing Bar]
2010-10-11 23:12 273672 —-a-w- c:\program files\MSN Toolbar\Platform\6.3.2348.0\mswinext.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-14 00:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lingoes]
2009-10-09 07:50 2203648 —-a-w- c:\program files\Lingoes\Translator2\Lingoes.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 18:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-05-23 3518368]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TipCtrl;TipCtrl;c:\program files\uTIPu\TipCtrl.exe [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2009-08-27 16168]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 XDva277;XDva277;c:\windows\system32\XDva277.sys [x]
R3 XDva285;XDva285;c:\windows\system32\XDva285.sys [x]
R3 XDva296;XDva296;c:\windows\system32\XDva296.sys [x]
R4 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-12 312152]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-03-31 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-03 691696]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2010-09-17 370008]
S1 aswSP;avast! Self Protection; [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-12-09 20392]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-09-06 51792]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-11-24 4497704]
S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-11-24 113448]
S3 dfmirage;dfmirage;c:\windows\system32\DRIVERS\dfmirage.sys [2008-03-26 34128]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2010-12-29 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-12-25 23:19]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
DPF: {0B386B45-B2CF-4525-82FE-D3489C2D26C9} - hxxp://www.latale.com/Launcher/ActozWebLauncher.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
FF - ProfilePath - c:\users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: YoYo Games InstantPlay: [removed] - %profile%\extensions\[removed]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: FireShot: {0b457cAA-602d-484a-8fe7-c1d894a011ba} - %profile%\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: general.useragent.extra.brc - BRI/1
.
.
——- File Associations ——-
.
JSEFile=NOTEPAD.EXE %1
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
MSConfigStartUp-BitTorrent DNA - c:\users\Kiki Wiki\Program Files\DNA\btdna.exe
MSConfigStartUp-JP595IR86O - c:\users\KIKIWI~1\AppData\Local\Temp\Wzd.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-28 21:32
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
QuickTime Task = "c:\program files\QuickTime\QTTask.exe" -atboottime???????3?"c:\program files\QuickTime\QTTask.exe" -a

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8e,0a,cb,c4,7f,04,7a,44,ae,84,f4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,8e,0a,cb,c4,7f,04,7a,44,ae,84,f4,\

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2010-12-28 21:36:19
ComboFix-quarantined-files.txt 2010-12-29 04:36

Pre-Run: 61,799,940,096 bytes free
Post-Run: 61,722,337,280 bytes free

- - End Of File - - 0E81F4932A1D969AF4F99BF1034822B3
Hi

How's the computer?

Next

Please open OTL by right clicking and clicking "Run as Administrator"

  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, click the None button near the top (it may looked greyed out)
  • In the window under Custom Scans/Fixes copy and paste the following


    /md5start
    Wbegua.exe
    rasgcwh.dll
    XDva277.sys
    XDva285.sys
    XDva296.sys
    /md5stop


  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window, OTL.Txt. Please post this log.
Still getting google redirects. I haven't been on long enough to see if the other problems are still there.

OTL logfile created on: 12/28/2010 10:37:16 PM - Run 3
OTL by OldTimer - Version 3.2.18.0 Folder = C:\Users\Kiki Wiki\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18999)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 68.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 147.58 Gb Total Space | 57.55 Gb Free Space | 38.99% Space Free | Partition Type: NTFS

Computer Name: KIKIWIKI-PC | User Name: Kiki Wiki | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

========== Custom Scans ==========


< >


< MD5 for: RASGCWH.DLL >
[2010/12/23 09:48:38 | 000,061,440 | RHS- | M] () Unable to obtain MD5 – C:\Windows\System32\rasgcwh.dll

< MD5 for: WBEGUA.EXE >
[2010/12/23 09:48:38 | 000,241,664 | —- | M] (Windows ® Codename Longhorn DDK provider) MD5=9B9FD4C4D7B79DF2B3EE4CF9CE4E4A8B – C:\Windows\Wbegua.exe

< End of report >
Hi Somethingsimple,

Redirect in all browsers or just FireFox?

We will be using Combofix again but will run it differently.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the all of the text in the code box below into the Notepad, (including the URL). Do Not copy the word CODE

http://forums.whatthetech.com/index.php?showtopic=116254&st=15

Collect::
C:\Windows\System32\rasgcwh.dll
C:\Windows\Wbegua.exe

RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]

Driver::
XDva277 
XDva285
XDva296

In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.

Please post the combofix log.
IE is affacted also.
The upload failed,where do I "manually" submit it?

ComboFix 10-12-28.02 - Kiki Wiki 12/28/2010 23:17:43.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3453.2395 [GMT -7:00]
Running from: c:\users\[removed]\Desktop\jgh.exe
Command switches used :: c:\users\Kiki Wiki\Desktop\CFScript.txt
AV: avast! Antivirus *Disabled/Outdated* {C37D8F93-0602-E43C-40AA-47DAD597F308}
SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: IObit Security 360 *Disabled/Updated* {FAE2835A-B90A-9E7A-85DA-82DBDA7C1E3A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

file zipped: c:\windows\System32\rasgcwh.dll
file zipped: c:\windows\Wbegua.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\System32\rasgcwh.dll
c:\windows\Wbegua.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_XDVA277
——-\Legacy_XDVA285
——-\Legacy_XDVA296
——-\Service_XDva277
——-\Service_XDva285
——-\Service_XDva296


((((((((((((((((((((((((( Files Created from 2010-11-28 to 2010-12-29 )))))))))))))))))))))))))))))))
.

2010-12-29 06:26 . 2010-12-29 06:33 ——– d—–w- c:\users\Kiki Wiki\AppData\Local\temp
2010-12-29 06:26 . 2010-12-29 06:26 ——– d—–w- c:\users\Guest\AppData\Local\temp
2010-12-29 06:26 . 2010-12-29 06:26 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-12-29 02:49 . 2010-12-29 04:18 ——– d—–w- C:\ComboFix
2010-12-28 02:52 . 2010-12-28 02:52 ——– d—–w- C:\_OTL
2010-12-26 04:52 . 2010-12-26 04:52 ——– d—–w- c:\program files\CCleaner
2010-12-26 03:48 . 2010-12-26 03:50 56400 —-a-w- c:\windows\system32\drivers\tmrkb.sys
2010-12-26 03:48 . 2010-12-26 03:50 190032 —-a-w- c:\windows\system32\drivers\tmcomm.sys
2010-12-25 17:09 . 2010-12-25 17:09 ——– d—–w- c:\users\Kiki Wiki\AppData\Local\Apps
2010-12-24 22:20 . 2010-12-27 00:03 ——– d—–w- c:\programdata\Spybot - Search & Destroy
2010-12-24 22:20 . 2010-12-24 22:23 ——– d—–w- c:\program files\Spybot - Search & Destroy
2010-12-24 18:31 . 2010-12-24 18:31 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-12-24 18:27 . 2010-12-24 18:27 ——– d—–w- c:\users\Kiki Wiki\AppData\Local\Sunbelt Software
2010-12-24 18:26 . 2010-12-24 18:31 ——– d—–w- c:\programdata\Lavasoft
2010-12-24 18:26 . 2010-12-24 18:26 ——– d—–w- c:\program files\Lavasoft
2010-12-22 03:47 . 2010-11-10 04:33 6273872 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{776D7CC6-4B5C-4C22-AC26-3D1887B4B614}\mpengine.dll
2010-12-16 20:10 . 2010-12-22 17:08 ——– d—–w- c:\programdata\regid.1986-12.com.adobe
2010-12-16 20:02 . 2010-12-16 20:02 ——– d—–w- c:\program files\Adobe Media Player
2010-12-16 18:45 . 2010-12-16 19:45 1228400 —-a-w- c:\users\Kiki Wiki\Photoshop_12_LS1.exe
2010-12-16 18:41 . 2010-12-29 06:27 ——– d—–w- c:\program files\Common Files\Akamai
2010-12-14 22:03 . 2010-10-12 13:41 66048 —-a-w- c:\program files\Windows Mail\wabmig.exe
2010-12-14 22:03 . 2010-10-12 13:41 515584 —-a-w- c:\program files\Windows Mail\wab.exe
2010-12-14 22:03 . 2010-10-12 15:53 33280 —-a-w- c:\program files\Windows Mail\wabfind.dll
2010-12-14 22:03 . 2010-10-28 13:20 2048 —-a-w- c:\windows\system32\tzres.dll
2010-12-14 22:00 . 2010-11-04 18:55 352768 —-a-w- c:\windows\system32\taskschd.dll
2010-12-14 22:00 . 2010-11-04 18:55 601600 —-a-w- c:\windows\system32\schedsvc.dll
2010-12-14 22:00 . 2010-11-04 18:56 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll
2010-12-14 22:00 . 2010-11-04 18:55 270336 —-a-w- c:\windows\system32\taskcomp.dll
2010-12-14 22:00 . 2010-11-04 16:34 171520 —-a-w- c:\windows\system32\taskeng.exe
2010-12-14 21:59 . 2010-10-18 13:31 2038272 —-a-w- c:\windows\system32\win32k.sys
2010-12-14 21:59 . 2010-11-03 10:51 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat
2010-12-04 04:53 . 2010-12-04 04:53 ——– d—–w- c:\program files\MSN Toolbar
2010-11-30 00:38 . 2010-11-30 00:38 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-30 00:38 . 2010-11-30 00:38 69632 —-a-w- c:\windows\system32\QuickTime.qts

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-18 22:41 . 2010-11-18 22:32 319456 —-a-w- c:\windows\DIFxAPI.dll
2010-11-03 02:29 . 2010-11-18 22:41 1084008 —-a-w- c:\windows\system32\RTSndMgr.cpl
2010-11-03 02:29 . 2010-11-18 22:41 3228712 —-a-w- c:\windows\system32\drivers\RTKVHDA.sys
2010-11-03 02:29 . 2010-11-18 22:41 1889896 —-a-w- c:\windows\system32\RtkPgExt.dll
2010-11-03 02:29 . 2010-11-18 22:41 68200 —-a-w- c:\windows\system32\RtkCoInst.dll
2010-11-03 02:28 . 2010-11-18 22:41 461416 —-a-w- c:\windows\system32\RtkApoApi.dll
2010-11-03 02:28 . 2010-11-18 22:41 3633256 —-a-w- c:\windows\system32\RtkAPO.dll
2010-11-03 02:28 . 2010-11-18 22:41 561256 —-a-w- c:\windows\system32\RCoRes.dat
2010-11-03 02:28 . 2010-11-18 22:41 406120 —-a-w- c:\windows\system32\DTSVoiceClarityDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 962664 —-a-w- c:\windows\system32\DTSS2HeadphoneDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 429160 —-a-w- c:\windows\system32\DTSSymmetryDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 291432 —-a-w- c:\windows\system32\DTSNeoPCDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 1132648 —-a-w- c:\windows\system32\DTSS2SpeakerDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 224360 —-a-w- c:\windows\system32\DTSLimiterDLL.dll
2010-11-03 02:28 . 2010-11-18 22:41 107112 —-a-w- c:\windows\system32\DTSLFXAPO.dll
2010-11-03 02:28 . 2010-11-18 22:41 107112 —-a-w- c:\windows\system32\DTSGFXAPO.dll
2010-11-03 02:28 . 2010-11-18 22:41 106600 —-a-w- c:\windows\system32\DTSGFXAPONS.dll
2010-11-03 02:27 . 2010-11-18 22:41 901224 —-a-w- c:\windows\system32\DTSBoostDLL.dll
2010-11-03 02:27 . 2010-11-18 22:41 448616 —-a-w- c:\windows\system32\DTSBassEnhancementDLL.dll
2010-11-03 02:27 . 2010-11-18 22:41 236648 —-a-w- c:\windows\system32\DTSGainCompensatorDLL.dll
2010-10-28 17:46 . 2010-11-18 22:41 1251944 —-a-w- c:\windows\RtlExUpd.dll
2010-10-26 20:02 . 2010-11-18 22:41 1558432 —-a-w- c:\windows\system32\FMAPO.dll
2010-10-26 16:15 . 2010-11-18 22:41 94352 —-a-w- c:\windows\system32\R4EEL32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 59536 —-a-w- c:\windows\system32\R4EEG32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 339600 —-a-w- c:\windows\system32\R4EED32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 1703568 —-a-w- c:\windows\system32\R4EEP32A.dll
2010-10-26 16:15 . 2010-11-18 22:41 78992 —-a-w- c:\windows\system32\R4EEA32A.dll
2010-10-19 17:41 . 2009-10-02 21:50 222080 ——w- c:\windows\system32\MpSigStub.exe
2010-10-04 23:12 . 2010-11-18 22:41 1725784 —-a-w- c:\windows\system32\WavesGUILib.dll
2010-10-04 23:12 . 2010-11-18 22:41 1336664 —-a-w- c:\windows\system32\MaxxAudioRealtek.dll
2010-10-03 20:45 . 2010-11-18 22:41 259928 —-a-w- c:\windows\system32\MaxxAudioAPO30.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-20 1451304]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2010-11-03 9808488]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2010-05-10 439568]
"AdobeAAMUpdater-1.0"="c:\program files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="c:\program files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-30 421888]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
NETGEAR WG111T Smart Wizard.lnk - c:\program files\NETGEAR\WG111T\wlan111t.exe [2007-10-1 884840]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-09-21 06:07 932288 —-a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-09-23 11:47 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
2010-09-22 07:28 47904 —-a-w- c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bing Bar]
2010-10-11 23:12 273672 —-a-w- c:\program files\MSN Toolbar\Platform\6.3.2348.0\mswinext.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 —-a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-14 00:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lingoes]
2009-10-09 07:50 2203648 —-a-w- c:\program files\Lingoes\Translator2\Lingoes.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2010-05-14 18:44 248552 —-a-w- c:\program files\Common Files\Java\Java Update\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001

R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R3 Lavasoft Kernexplorer;Lavasoft helper driver;c:\program files\Lavasoft\Ad-Aware\KernExplorer.sys [x]
R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2010-05-23 3518368]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TipCtrl;TipCtrl;c:\program files\uTIPu\TipCtrl.exe [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2009-08-27 16168]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 IS360service;IS360service;c:\program files\IObit\IObit Security 360\IS360srv.exe [2010-06-12 312152]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-03-31 47128]
R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-30 239336]
R4 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-03 691696]
R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2010-09-17 370008]
S1 aswSP;avast! Self Protection; [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\elrawdsk.sys [2008-12-09 20392]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-19 21504]
S2 aswFsBlk;aswFsBlk; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-09-06 51792]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-11-24 4497704]
S2 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-11-24 113448]
S3 dfmirage;dfmirage;c:\windows\system32\DRIVERS\dfmirage.sys [2008-03-26 34128]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder

2010-12-29 c:\windows\Tasks\AWC Startup.job
- c:\program files\IObit\Advanced SystemCare 3\AWC.exe [2010-12-25 23:19]
.
.
——- Supplementary Scan ——-
.
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubedownload.htm
IE: Free YouTube to Mp3 Converter - c:\users\Kiki Wiki\AppData\Roaming\DVDVideoSoftIEHelpers\youtubetomp3.htm
IE: Save YouTube Video as MP3 - c:\program files\Common Files\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
DPF: {0B386B45-B2CF-4525-82FE-D3489C2D26C9} - hxxp://www.latale.com/Launcher/ActozWebLauncher.cab
DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
FF - ProfilePath - c:\users\Kiki Wiki\AppData\Roaming\Mozilla\Firefox\Profiles\ibtx2mq3.default\
FF - prefs.js: browser.search.selectedEngine - Bing
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: YoYo Games InstantPlay: [removed] - %profile%\extensions\[removed]
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: FireShot: {0b457cAA-602d-484a-8fe7-c1d894a011ba} - %profile%\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}
FF - Ext: DVDVideoSoft Menu: {ACAA314B-EEBA-48e4-AD47-84E31C44796C} - %profile%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - user.js: browser.cache.memory.capacity - 65536
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.interrupt.parsing - true
FF - user.js: content.max.tokenizing.time - 2250000
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 750000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 750000
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 0
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
FF - user.js: general.useragent.extra.brc - BRI/1
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-12-28 23:34
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
QuickTime Task = "c:\program files\QuickTime\QTTask.exe" -atboottime???????3?"c:\program files\QuickTime\QTTask.exe" -a

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Akamai]
"ServiceDll"="C:/Program Files/Common Files/Akamai/netsession_win_aeec0f0.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
———————— Other Running Processes ————————
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\agrsmsvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\SYSTEM32\WISPTIS.EXE
c:\program files\Common Files\microsoft shared\ink\TabTip.exe
c:\program files\WTouch\WTouchUser.exe
c:\windows\system32\WTablet\Pen_TabletUser.exe
c:\program files\IObit\Game Booster\GameBox.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\program files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
.
**************************************************************************
.
Completion time: 2010-12-28 23:38:11 - machine was rebooted
ComboFix-quarantined-files.txt 2010-12-29 06:38
ComboFix2.txt 2010-12-29 04:36

Pre-Run: 61,767,143,424 bytes free
Post-Run: 61,359,624,192 bytes free

- - End Of File - - 691601FF2BF54B0A9ED6A07C8871D418
Hi Somethingsimple,

Let's flush the DNS cache and see if it helps.

  • Now go to Start > All programs > Accessories
  • Right click Run and click "Run as Adminstrator"
  • type: cmd
  • Press OK or Hit Enter.
  • At the command prompt, type or copy/paste: ipconfig /flushdns (note the space between ..g /f it needs to be there)
  • Hit Enter.
  • You will get a confirmation that the flush was successful.
  • Close the command box.

Try google again. Any other of the issues remaining?

Are you using a router? If so are any other computers effecting with the redirects?


To manualy submit a file.

Please visit this site and follow the instructions for uploading the file.

In the top box please copy and paste the following bold text

http://forums.whatthetech.com/index.php?showtopic=116254&st=15&gopid=702573&#entry702573

Use the browse button to navigate to the following file

C:\Qoobox\Quarantine\[4]-[removed]
The x's represent time and date. Yours' will be similar to Submit_2010-12-29@00:25.zip

Leave the bottom box blank.


Thanks
I cannot use run as an administrator,but the redirecting seems to have stopped. I just got a window asking me for permission to run something from Java,I didn't know what the file was so I canceled it,and I tried screenshoting the window but it failed. I'll try using my laptop normally tomorrow and see if anything else pops up,Thank you so much! Question: Can I run my security programs now? EDIT: File sent,also,I dragged the run command onto my desktop,is there anyway that I can put it back?
Hi Somethingsimple,

EDIT: File sent,also,I dragged the run command onto my desktop,is there anyway that I can put it back?

Did you copy it there or move it? Try right clicking the desktop and see if you are given the option to undo the copy or move.

A couple of more scans to do before your renable your programs.

Download and save to your desktop Malwarebytes Anti-Malware

Right Click mbam-setup.exe and click "Runas Administrator" to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.



As a Vista use you will need to run your browser with Administrator right in order to use this scanner
  • Right click your browser icon and chose "Run as Administrator" to run it
  • Do not browse anywhere else with this browser
  • Once the scan is complete and the results saved, close that instance of the browser
  • Open a new browser the usual way and post the log here.
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.

Please post back with
  • MBAM log
  • ESET log
Remember to renable your programs when done.
Dragging it to start put it back. Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Database version: 5416 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.18999 12/29/2010 8:43:05 AM mbam-log-2010-12-29 (08-43-05).txt Scan type: Quick scan Objects scanned: 153684 Time elapsed: 7 minute(s), 42 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 1 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\JP595IR86O (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\bak_Application (Hijacker.Application) -> Value: bak_Application -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations\Application (Hijacker.Application) -> Bad: (http://www.helpmeopen.com/?n=app&ext=%s) Good: (http://shell.windows.com/fileassoc/%04x/xml/redir.asp?Ext=%s) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) C:\Qoobox\Quarantine\C\Windows\System32\rasgcwh.dll.vir a variant of Win32/Kryptik.JHE trojan C:\Users\Kiki Wiki\Downloads\MsgPlusLive-482.exe a variant of Win32/Adware.CiDHelp application C:\Users\Kiki Wiki\Downloads\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application C:\Users\Kiki Wiki\Downloads\MsgPlusLive-490.exe a variant of Win32/MessengerPlus application C:\Users\Kiki Wiki\owner\Downloads\MsgPlusLive-479.exe a variant of Win32/Adware.CiDHelp application C:\Users\Kiki Wiki\owner\Downloads\MsgPlusLive-480.exe a variant of Win32/MessengerPlus application C:\_OTL\MovedFiles\12272010_195259\C_Users\Kiki Wiki\AppData\Local\Temp\Wzd.exe a variant of Win32/Kryptik.JDQ trojan
Hi Somethingsimple,

Dragging it to start put it back.

Good job. :thumbup:

C:\Users\Kiki Wiki\Downloads\MsgPlusLive-482.exe a variant of Win32/Adware.CiDHelp application
C:\Users\Kiki Wiki\Downloads\MsgPlusLive-483.exe a variant of Win32/Adware.CiDHelp application
C:\Users\Kiki Wiki\Downloads\MsgPlusLive-490.exe a variant of Win32/MessengerPlus application
C:\Users\Kiki Wiki\owner\Downloads\MsgPlusLive-479.exe a variant of Win32/Adware.CiDHelp application
C:\Users\Kiki Wiki\owner\Downloads\MsgPlusLive-480.exe a variant of Win32/MessengerPlus application

These are all adware related to this program, Messenger Plus! Live, it's not malicious but if you don't use the program I suggest you uninstall it.

The other detections are files we have already quarantined and will be removed when we clean up the tools.

How's the computer? If everything's ok we'll clean up the tools after you post back.
Everything seems to be going better. No popups,no random sounds,google isn't redirecting,etc! I DO use Messenger Plus for scripting + it's drawing ability,but if it is adware I will remove it. (Those items will be removed after I uninstall messenger plus,right? Or will I have to scan again just in case?)
Hi Somethingsimple,

Generally it only ESET that detects those files as adware. It didn't detect the whole program just the files located in this folder C:\Users\Kiki Wiki\Downloads . Remove the files from that location and you should be fine.

Here's a sample of one of the files as scanned at VirusTotal. You will note that Messenger Plus! has cleaned up their act somewhat in the last while. It is now consider an "Optional" uninstall.

Safe. Messenger Plus! stopped bundling the old sponsor package. The new community toolbar is powered by Conduit (http://www.conduit.com/privacy/) and verified safe by TRUSTe (http://clicktoverify.truste.com/pvr.php?page=validate&url=www.conduit.com&sealid=101) and McAfee (https://www.mcafeesecure.com/RatingVerify?ref=www.conduit.com), as well as still completely optional as always.

http://www.virustotal.com/file-scan/report…e58c-1288802423


No need for an additional scan.
Hi Somethingsimple,

I see Avast is reported out of date. Make sure it's up to date
  • right click the "a" icon
  • highlight updates
  • click engine and virus definitions
Make sure to renable the self protection module.


If no other problems, we can clean up our tools. Keep Defogger, we will use it shortly.


From your desktop, please delete
  • any notepads/logs that we created
  • GMER (s3jb5ryb.exe)

Eset online can be removed via add/remove programs if you wish.

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep it updated and use it regularly as an on demand scanner.


To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

You can delete Defogger now.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

You have 3 resident antispyware programs, 4 if you re-enable Teatimer.

SP: avast! Antivirus *Disabled/Outdated* {781C6E77-2038-EBB2-7A1A-7CA8AE10B9B5}
SP: IObit Security 360 *Disabled/Updated* {FAE2835A-B90A-9E7A-85DA-82DBDA7C1E3A}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

I don't think you need them all running at once. One of them is bundled with your antivirus program, Avast, the others are stand alone.


* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware)


You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.



-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879

We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI