This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

google redirect infection, tdsskiller and others won't open or run

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have tried to remove the virus with emsisoft, malwarebytes, and other similar antivirus and malware programs without success. Some sites have recommending TDSSkiller for rootkit problems (whatever they are). But when I download this, it won't run- it looks like it starts to, but then shuts down. I have also tried downloading TDSSkiller on another computer, assigning a different filename as has been suggested on other sites, and then transferring this renamed file to my computer, but it still won't open or run. Very frustrating! It seems like this malware stays one step ahead of attempts to remove it and interferes with the deployment of tools or operation of programs that might shut it down. I was able to again download and reinstall hijackthis so that it runs. The logfile is attached below. Any help would be appreciated as this has become a tremendous timesucker.

Attachments:

Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

Please download DDS by sUBs from one of the following links and save it to your desktop.
Please use copy / paste to post the scan results.

    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Here is what you requested. DDS (Ver_10-12-12.01) - NTFSx86 Run by [removed] at 22:55:03.62 on Sat 02/12/2011 Internet Explorer: 8.0.6001.18999 BrowserJavaVersion: 1.6.0_17 Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3535.1509 [GMT -5:00] AV: Security Suite *Enabled/Updated* {F5E52F41-190C-46f6-9FC3-55470285CC2B} SP: Spybot - Search and Destroy *Disabled/Outdated* {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} AV: Emsisoft Anti-Malware *Enabled/Updated* {607A6E45-BE50-AFD5-4F70-7EAAEC5B715D} AV: Sophos Anti-Virus *Enabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C} SP: Sophos Anti-Virus *Enabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791} SP: Emsisoft Anti-Malware *Enabled/Updated* {DB1B8FA1-986A-A05B-75C0-45D897DC3BE0} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Program Files\Emsisoft Anti-Malware\a2service.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\WLANExt.exe C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Flip Video\FlipShare\FlipShareService.exe C:\Program Files\Intel\AMT\LMS.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Windows\system32\svchost.exe -k regsvc C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe C:\Program Files\Sophos\Remote Management System\RouterNT.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxpers.exe C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\System32\WDBtnMgr.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Office Communicator\communicator.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\ctfmon.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Sophos\AutoUpdate\ALsvc.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Users\gbarron\Desktop\dds.pif C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://my.mercyhurst.edu/Pages/default.aspx uSearch Bar = Preserve uInternet Settings,ProxyServer = http=127.0.0.1:18810 uInternet Settings,ProxyOverride = BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe" /silentRetrials /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [EPSON NX410 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifca.exe /fu "c:\users\gbarron\appdata\local\temp\E_SA942.tmp" /EF "HKCU" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [ehSfAxdeCUNMnk.exe] c:\programdata\ehSfAxdeCUNMnk.exe uRun: [RgFqlXFJatY] c:\progra~2\RgFqlXFJatY.exe uRun: [ImxpkgNQo7ZcXknT] c:\progra~2\ImxpkgNQo7ZcXknT.exe uRun: [3qPbZBGJ] c:\progra~2\3qPbZBGJ.exe uRun: [bTl53SCxZd7Lh] c:\programdata\bTl53SCxZd7Lh.exe mRun: [picon] "c:\program files\common files\intel\privacy icon\PrivacyIconClient.exe" -startup mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2 mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [WD Button Manager] WDBtnMgr.exe mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Sophos AutoUpdate Monitor] c:\program files\sophos\autoupdate\almon.exe dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe" StartupFolder: c:\users\gbarron\appdata\roaming\micros~1\windows\startm~1\programs\startup\epsona~1.lnk - d:\common\epsonreg\EpsonReg.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\amazon~1.lnk - c:\program files\amazon\amazon unbox video\ADVWindowsClientSystemTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe uPolicies-system: ReportControllerMissing = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: MaxGPOScriptWait = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: mercyhurst.edu\campusmanager Trusted Zone: microsoft.com DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - file:///D:/LTOCX14N.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/authorware/awswaxd.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://cengage.webex.com/client/T27L/webex/ieatgpc1.cab Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\users\gbarron\appdata\roaming\mozilla\firefox\profiles\426dwsii.default\ FF - prefs.js: browser.startup.homepage - hxxp://lakernet.mercyhurst.edu/ FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\users\gbarron\appdata\roaming\mozilla\firefox\profiles\426dwsii.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-22 64160] R1 a2injectiondriver;a2injectiondriver;c:\program files\emsisoft anti-malware\a2dix86.sys [2011-2-2 41928] R1 a2util;a-squared Malware-IDS utility driver;c:\program files\emsisoft anti-malware\a2util32.sys [2011-2-2 11776] R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\drivers\savonaccess.sys [2011-2-4 122360] R2 a2AntiMalware;Emsisoft Anti-Malware 5.0 - Service;c:\program files\emsisoft anti-malware\a2service.exe [2011-2-2 2853904] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_2311653e\AEstSrv.exe [2009-2-17 77824] R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2008-6-3 386328] R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2008-11-11 808296] R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2008-11-11 20840] R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2008-8-18 453712] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456] R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2011-2-4 163056] R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2011-2-4 97520] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-2-18 1153368] R2 Sophos Agent;Sophos Agent;c:\program files\sophos\remote management system\ManagementAgentNT.exe [2011-2-4 282624] R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2010-9-30 230640] R2 Sophos Message Router;Sophos Message Router;c:\program files\sophos\remote management system\RouterNT.exe [2011-2-4 806912] R2 swi_service;Sophos Web Intelligence Service;c:\program files\sophos\sophos anti-virus\web intelligence\swi_service.exe [2011-2-4 1541360] R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2009-2-17 2058776] R3 a2acc;a2acc;c:\program files\emsisoft anti-malware\a2accx86.sys [2011-2-2 72808] R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [2009-2-17 12840] R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-11-11 32808] R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y6032.sys [2009-2-17 224384] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-2-17 112128] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-6-26 3662848] R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2008-11-26 133472] R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2008-12-26 279488] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate1c9e522293f8bdb;Google Update Service (gupdate1c9e522293f8bdb);c:\program files\google\update\GoogleUpdate.exe [2009-6-4 133104] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-2-18 21504] S3 PeerDistSvc;BranchCache;c:\windows\system32\svchost.exe -k PeerDist [2009-2-18 21504] S3 sdcfilter;sdcfilter;c:\windows\system32\drivers\sdcfilter.sys [2011-2-4 23928] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2011-2-4 22536] =============== Created Last 30 ================ 2011-02-11 19:02:06 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll 2011-02-11 19:02:06 57344 —-a-w- c:\program files\common files\system\msadc\msadcs.dll 2011-02-11 19:02:06 413696 —-a-w- c:\windows\system32\odbc32.dll 2011-02-11 19:02:06 253952 —-a-w- c:\program files\common files\system\ado\msadox.dll 2011-02-11 19:02:06 241664 —-a-w- c:\program files\common files\system\ado\msadomd.dll 2011-02-11 19:02:06 180224 —-a-w- c:\program files\common files\system\msadc\msadco.dll 2011-02-11 19:01:54 1203032 —-a-w- c:\windows\system32\ntdll.dll 2011-02-11 19:00:33 1169408 —-a-w- c:\windows\system32\sdclt.exe 2011-02-11 07:07:09 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{6d8e9be9-e6e0-4718-98fb-b0912cfb3c15}\mpengine.dll 2011-02-11 05:54:20 388096 —-a-r- c:\users\gbarron\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-11 05:54:18 ——– d—–w- c:\program files\Trend Micro 2011-02-04 20:12:57 131824 —-a-w- c:\windows\system32\sdccoinstaller.dll 2011-02-04 20:12:51 ——– d—–w- c:\progra~2\Sophos Web Intelligence 2011-02-04 20:12:12 ——– d—–w- c:\program files\common files\Cisco Systems 2011-02-04 20:12:09 28912 —-a-w- c:\windows\system32\SophosBootTasks.exe 2011-02-04 20:10:16 122360 —-a-w- c:\windows\system32\drivers\savonaccess.sys 2011-02-04 20:09:59 23928 —-a-w- c:\windows\system32\drivers\sdcfilter.sys 2011-02-04 20:09:48 22536 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys 2011-02-02 07:55:47 ——– d—–w- c:\program files\Emsisoft Anti-Malware 2011-01-29 07:19:47 ——– d—–w- c:\progra~2\aJpEdEg09000 2011-01-29 04:31:21 ——– d—–w- c:\users\gbarron\appdata\local\Sophos 2011-01-27 01:15:48 ——– d—–w- c:\users\gbarron\appdata\roaming\PeerNetworking 2011-01-24 23:28:13 82696 —-a-w- c:\windows\system32\lmdimon8.dll 2011-01-24 23:28:13 82168 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\lmdippr8.dll ==================== Find3M ==================== 2010-12-04 06:35:11 249856 ——w- c:\windows\Setup1.exe 2010-12-04 06:35:10 73216 —-a-w- c:\windows\ST6UNST.EXE 2010-12-04 06:25:05 286720 —-a-w- c:\windows\iun506.exe 2010-11-29 22:38:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- c:\windows\system32\QuickTime.qts 2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll 2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll 2008-03-16 12:30:52 216064 –sh–r- c:\windows\system32\nbDX.dll ============= FINISH: 23:03:08.53 ===============
uInternet Settings,ProxyServer = http=127.0.0.1:18810 <–That appears to be a proxy hijacker.


Please don't attach the scans / logs from these scans, use "copy/paste".

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

Note: Close all browsers before running ATF Cleaner: IE, FireFox, etc.

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Launch Notepad (Start>All Programs>Accessories), and copy/paste all the Quoted REGEDIT below to it. Don't forget to include REGEDIT4.
Save in: Desktop
File Name: fixme.reg
Save as Type: All files
Click: Save

REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
"ProxyServer"=-

Save this as fixme.reg Choose to save as *all files and place it on your desktop.
It should look like this: [external image: Posted Image]
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

Reboot and describe how your computer behaves at the moment.
I ran the file and rebooted. I don't notice any difference in performance; reboot uneventful. I'm still being directed elsewhere when i click on a google search link.
AV: Security Suite *Enabled/Updated* {F5E52F41-190C-46f6-9FC3-55470285CC2B}

AV: Emsisoft Anti-Malware *Enabled/Updated* {607A6E45-BE50-AFD5-4F70-7EAAEC5B715D}

AV: Sophos Anti-Virus *Enabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C}

You have 3 anti-virus programs running.


Never install more than one Antivirus and Firewall! Rather than giving you extra protection, it will decrease the reliability of it seriously!
The reason for this is that if both products have their automatic (Real-Time) protection switched on, your system may lock up due to both software products attempting to access the same file at the same time.
Also because more than one Antivirus and Firewall installed are not compatible with each other, it can cause system performance problems and a serious system slowdown.

Please do not delete anything unless instructed to.


1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove 2 of the 3 you have.

Reboot and let me know how it's running and post a new DDS scan results
Thanks -I didn't know that. I deleted emsisoft and security suite and kept sophos. Ran DDS and here are the files: DDS (Ver_10-12-12.01) - NTFSx86 Run by [removed] at 22:24:35.15 on Sun 02/13/2011 Internet Explorer: 8.0.6001.18999 BrowserJavaVersion: 1.6.0_17 Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3535.1948 [GMT -5:00] AV: Security Suite *Enabled/Updated* {F5E52F41-190C-46f6-9FC3-55470285CC2B} SP: Spybot - Search and Destroy *Disabled/Outdated* {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} AV: Sophos Anti-Virus *Enabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C} SP: Sophos Anti-Virus *Enabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\WLANExt.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Flip Video\FlipShare\FlipShareService.exe C:\Program Files\Intel\AMT\LMS.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Windows\system32\svchost.exe -k regsvc C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe C:\Program Files\Sophos\AutoUpdate\ALsvc.exe C:\Program Files\Sophos\Remote Management System\RouterNT.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Dell\Dell ControlPoint\DCPButtonSvc.exe C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\taskeng.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\igfxpers.exe C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\System32\WDBtnMgr.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Program Files\Microsoft Office Communicator\communicator.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe C:\Program Files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe C:\Windows\System32\mobsync.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\ctfmon.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\gbarron\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://my.mercyhurst.edu/Pages/default.aspx uSearch Bar = Preserve uInternet Settings,ProxyOverride = BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe" /silentRetrials /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [EPSON NX410 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifca.exe /fu "c:\users\gbarron\appdata\local\temp\E_SA942.tmp" /EF "HKCU" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [ehSfAxdeCUNMnk.exe] c:\programdata\ehSfAxdeCUNMnk.exe uRun: [RgFqlXFJatY] c:\progra~2\RgFqlXFJatY.exe uRun: [ImxpkgNQo7ZcXknT] c:\progra~2\ImxpkgNQo7ZcXknT.exe uRun: [3qPbZBGJ] c:\progra~2\3qPbZBGJ.exe uRun: [bTl53SCxZd7Lh] c:\programdata\bTl53SCxZd7Lh.exe mRun: [picon] "c:\program files\common files\intel\privacy icon\PrivacyIconClient.exe" -startup mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2 mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [WD Button Manager] WDBtnMgr.exe mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Sophos AutoUpdate Monitor] c:\program files\sophos\autoupdate\almon.exe dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe" StartupFolder: c:\users\gbarron\appdata\roaming\micros~1\windows\startm~1\programs\startup\epsona~1.lnk - d:\common\epsonreg\EpsonReg.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\amazon~1.lnk - c:\program files\amazon\amazon unbox video\ADVWindowsClientSystemTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe uPolicies-system: ReportControllerMissing = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: MaxGPOScriptWait = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: mercyhurst.edu\campusmanager Trusted Zone: microsoft.com DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - file:///D:/LTOCX14N.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/authorware/awswaxd.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://cengage.webex.com/client/T27L/webex/ieatgpc1.cab Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\users\gbarron\appdata\roaming\mozilla\firefox\profiles\426dwsii.default\ FF - prefs.js: browser.startup.homepage - hxxp://lakernet.mercyhurst.edu/ FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\users\gbarron\appdata\roaming\mozilla\firefox\profiles\426dwsii.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-22 64160] R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\drivers\savonaccess.sys [2011-2-4 122360] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_2311653e\AEstSrv.exe [2009-2-17 77824] R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2008-6-3 386328] R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2008-11-11 808296] R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2008-11-11 20840] R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2008-8-18 453712] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456] R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2011-2-4 163056] R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2011-2-4 97520] R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-2-18 1153368] R2 Sophos Agent;Sophos Agent;c:\program files\sophos\remote management system\ManagementAgentNT.exe [2011-2-4 282624] R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2010-9-30 230640] R2 Sophos Message Router;Sophos Message Router;c:\program files\sophos\remote management system\RouterNT.exe [2011-2-4 806912] R2 swi_service;Sophos Web Intelligence Service;c:\program files\sophos\sophos anti-virus\web intelligence\swi_service.exe [2011-2-4 1541360] R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2009-2-17 2058776] R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [2009-2-17 12840] R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-11-11 32808] R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y6032.sys [2009-2-17 224384] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-2-17 112128] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\NETw5v32.sys [2008-6-26 3662848] R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2008-11-26 133472] R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2008-12-26 279488] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate1c9e522293f8bdb;Google Update Service (gupdate1c9e522293f8bdb);c:\program files\google\update\GoogleUpdate.exe [2009-6-4 133104] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-2-18 21504] S3 PeerDistSvc;BranchCache;c:\windows\system32\svchost.exe -k PeerDist [2009-2-18 21504] S3 sdcfilter;sdcfilter;c:\windows\system32\drivers\sdcfilter.sys [2011-2-4 23928] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2011-2-4 22536] =============== Created Last 30 ================ 2011-02-11 19:02:06 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll 2011-02-11 19:02:06 57344 —-a-w- c:\program files\common files\system\msadc\msadcs.dll 2011-02-11 19:02:06 413696 —-a-w- c:\windows\system32\odbc32.dll 2011-02-11 19:02:06 253952 —-a-w- c:\program files\common files\system\ado\msadox.dll 2011-02-11 19:02:06 241664 —-a-w- c:\program files\common files\system\ado\msadomd.dll 2011-02-11 19:02:06 180224 —-a-w- c:\program files\common files\system\msadc\msadco.dll 2011-02-11 19:01:54 1203032 —-a-w- c:\windows\system32\ntdll.dll 2011-02-11 19:00:33 1169408 —-a-w- c:\windows\system32\sdclt.exe 2011-02-11 07:07:09 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{6d8e9be9-e6e0-4718-98fb-b0912cfb3c15}\mpengine.dll 2011-02-11 05:54:20 388096 —-a-r- c:\users\gbarron\appdata\roaming\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-11 05:54:18 ——– d—–w- c:\program files\Trend Micro 2011-02-04 20:12:57 131824 —-a-w- c:\windows\system32\sdccoinstaller.dll 2011-02-04 20:12:51 ——– d—–w- c:\progra~2\Sophos Web Intelligence 2011-02-04 20:12:12 ——– d—–w- c:\program files\common files\Cisco Systems 2011-02-04 20:12:09 28912 —-a-w- c:\windows\system32\SophosBootTasks.exe 2011-02-04 20:10:16 122360 —-a-w- c:\windows\system32\drivers\savonaccess.sys 2011-02-04 20:09:59 23928 —-a-w- c:\windows\system32\drivers\sdcfilter.sys 2011-02-04 20:09:48 22536 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys 2011-02-02 07:55:47 ——– d—–w- c:\program files\Emsisoft Anti-Malware 2011-01-30 19:57:00 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2011-01-30 19:57:00 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2011-01-29 07:19:47 ——– d—–w- c:\progra~2\aJpEdEg09000 2011-01-29 04:31:21 ——– d—–w- c:\users\gbarron\appdata\local\Sophos 2011-01-27 01:15:48 ——– d—–w- c:\users\gbarron\appdata\roaming\PeerNetworking 2011-01-24 23:28:13 82696 —-a-w- c:\windows\system32\lmdimon8.dll 2011-01-24 23:28:13 82168 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\lmdippr8.dll ==================== Find3M ==================== 2010-12-04 06:35:11 249856 ——w- c:\windows\Setup1.exe 2010-12-04 06:35:10 73216 —-a-w- c:\windows\ST6UNST.EXE 2010-12-04 06:25:05 286720 —-a-w- c:\windows\iun506.exe 2010-11-29 22:38:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- c:\windows\system32\QuickTime.qts 2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll 2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll 2008-03-16 12:30:52 216064 –sh–r- c:\windows\system32\nbDX.dll ============= FINISH: 22:31:50.41 ===============

Attachments:

  • [attachment removed: Attach__2_.zip]
uRun: [ehSfAxdeCUNMnk.exe] c:\programdata\ehSfAxdeCUNMnk.exe
uRun: [RgFqlXFJatY] c:\progra~2\RgFqlXFJatY.exe
uRun: [ImxpkgNQo7ZcXknT] c:\progra~2\ImxpkgNQo7ZcXknT.exe
uRun: [3qPbZBGJ] c:\progra~2\3qPbZBGJ.exe
uRun: [bTl53SCxZd7Lh] c:\programdata\bTl53SCxZd7Lh.exe

Those all look bad to me.

Download ComboFix from one of these locations:

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Well, that was an adventure. Many interesting things happened with combofix. I downloaded the file to my desktop, and tried to run it. The green bar showed up along with the spinning circle, which didn't appear continuously, but sporadically on and off as if it were trying to run, but couldn't. Finally, it just stalled. I clicked again and tried to run it. First, a window opened that told me I appeared to have a corrupt copy and suggested I download a new copy. Before I closed the window I got another one that said Sophos and Lavaware was still running and suggested I disable these. I deleted lavasoft files and turned Sophos active scanning off. Then I noticed a new log file on my desktop with the name CatchMe.log. The contents were as follows: File "C:\Windows\system32\drivers\volsnap.sys" added successfully Then I downloaded a new copy of combofix after I'd sent the first to the recyling bin. It seeemed to install successfully. Double clicked to run it, green bar appeared, followed shortly after by a blue screen with something about drivers; before I could try to make sense of it, the system rebooted by itself. Got a message saying that the system had recovered from an unexpected shutdown, with details as follows: Problem signature: Problem Event Name: BlueScreen OS Version: 6.0.6002.2.2.0.256.6 Locale ID: 1033 Additional information about the problem: BCCode: c5 BCP1: 00000000 BCP2: 00000002 BCP3: 00000001 BCP4: 8253682A OS Version: 6_0_6002 Service Pack: 2_0 Product: 256_1 Files that help describe the problem: C:\Windows\Minidump\Mini021611-02.dmp C:\Users\gbarron\AppData\Local\Temp\WER-728571-0.sysdata.xml C:\Users\gbarron\AppData\Local\Temp\WER674A.tmp.version.txt Again double clicked on combofix, with the same results-shortly after it starts, the bluescreen appears with the same message about drivers and a crash dump, and again, before I could read it completely, the system rebooted itself. Same recovery message; same details as above. I won't try combofix again until I hear from you.
Lets try a online scan first.

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control…Click here to install…". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Check Remove found threats and Scan potentially unwanted applications.
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Actually ran eset twice- I ran it as I fell asleep last night, and had a message in the am that it had crashed and restarted. Ran it again this morning- checked tha logs and while nothing was detected this morning , it had found some nasty stuff in the first scan and eliminated it. Here's the log: ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=2609f3ce712734498bbbd3b03e4afad5 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-18 07:54:38 # local_time=2011-02-18 02:54:38 (-0500, Eastern Standard Time) # country="United States" # lang=9 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5892 16776574 100 100 0 134617232 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=8449 16775165 50 97 0 110347164 0 0 # scanned=153088 # found=4 # cleaned=4 # scan_time=5948 C:\Users\gbarron\AppData\Local\Temp\jar_cache7547313991959423153.tmp multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\Users\gbarron\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\2d817510-494630b5 multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\Users\gbarron\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\962fb59-19dac17f a variant of Java/Exploit.CVE-2010-0844.A trojan (deleted - quarantined) 00000000000000000000000000000000 C C:\Users\gbarron\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6\766920c6-2ccad2cc multiple threats (deleted - quarantined) 00000000000000000000000000000000 C # version=7 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6419 # api_version=3.0.2 # EOSSerial=2609f3ce712734498bbbd3b03e4afad5 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-02-18 02:39:41 # local_time=2011-02-18 09:39:41 (-0500, Eastern Standard Time) # country="United States" # lang=9 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=5892 16776574 100 100 0 134642587 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # compatibility_mode=8449 16775165 50 97 0 110372519 0 0 # scanned=153435 # found=0 # cleaned=0 # scan_time=4895
Go here and follow the instructions to clear your Java Cache
http://www.java.com/en/download/help/plugin_cache.xml

Next:
Java updates:
http://www.java.com/en/download/manual.jsp

Next:

Delete the combofix you have on the desktop then do this:

Download Combofix from any of the links below but rename it to iexplore.exe before saving it to your desktop.

If need be, Download the tools needed to a flash drive or other USB device, and transfer them to the infected computer.

Note:
If combofix (iexplore.exe) won't run from the desktop, try running it from the USB device.



Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save iexplore.exe to your Desktop

Double click on the iexplore.exe ComboFix.exe & follow the prompts.
Be sure to download any updates.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.



  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
Ok- combofix downloaded as combofix and iexplorer.exe and saved to desktop. Sophos disabled. Attempted to execute Combofix, but kept getting rkill window with message that it was attempting to terminate known malware processes. Log on completion is below: This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Rkill was run on 02/21/2011 at 21:37:35. Operating System: Windows Vista â„¢ Business Processes terminated by Rkill or while it was running: C:\Windows\System32\InfDefaultInstall.exe Rkill completed on 02/21/2011 at 21:38:49. I would guess that rkill is reading Combofix as malware, and that I need to delete rkill?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI