This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

google redirect infection, tdsskiller and others won't open or run

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This might seem like a ridiculous question, but do you know where it might be? I had it on my desktop, but it is no longer there. Obviously it's still operating from somewhere; I've searched, but nothing turns up.
Here is the DDS scan I ran today. DDS (Ver_10-12-12.01) - NTFSx86 Run by [removed] at 14:43:27.18 on Wed 02/23/2011 Internet Explorer: 8.0.6001.18999 BrowserJavaVersion: 1.6.0_24 Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3535.1705 [GMT -5:00] AV: Security Suite *Enabled/Updated* {F5E52F41-190C-46f6-9FC3-55470285CC2B} SP: Spybot - Search and Destroy *Disabled/Outdated* {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} AV: Sophos Anti-Virus *Disabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C} SP: Sophos Anti-Virus *Disabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\STacSV.exe C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe C:\Windows\system32\WLANExt.exe C:\Windows\system32\taskeng.exe C:\Windows\System32\spoolsv.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\rundll32.exe C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\aestsrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Intel\WiFi\bin\EvtEng.exe C:\Program Files\Flip Video\FlipShare\FlipShareService.exe C:\Program Files\Intel\AMT\LMS.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe C:\Windows\system32\svchost.exe -k regsvc C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe C:\Program Files\Sophos\Remote Management System\RouterNT.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Lavasoft\Ad-Aware\AAWWSC.exe C:\Program Files\Google\Update\GoogleUpdate.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Dell\Dell ControlPoint\Dell.ControlPoint.exe C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe C:\Program Files\Google\Quick Search Box\GoogleQuickSearchBox.exe C:\Program Files\IDT\WDM\sttray.exe C:\Windows\System32\WDBtnMgr.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Microsoft Office Communicator\communicator.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\ctfmon.exe C:\Windows\System32\mobsync.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\Explorer.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Sophos\AutoUpdate\ALsvc.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Users\gbarron\Desktop\dds.pif ============== Pseudo HJT Report =============== uStart Page = hxxp://my.mercyhurst.edu/Pages/default.aspx uSearch Bar = Preserve uInternet Settings,ProxyOverride = BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn\yt.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti- virus\SophosBHO.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll BHO: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.6.5805.1910\swg.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: Easy Photo Print: {9421dd08-935f-4701-a9ca-22df90ac4ea6} - c:\program files\epson software\easy photo print\EPTBL.dll TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn\yt.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll uRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe" /silentRetrials /background uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [EPSON NX410 Series] c:\windows\system32\spool\drivers\w32x86\3\e_fatifca.exe /fu "c:\users\gbarron\appdata\local\temp\E_SA942.tmp" /EF "HKCU" uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [ehSfAxdeCUNMnk.exe] c:\programdata\ehSfAxdeCUNMnk.exe uRun: [RgFqlXFJatY] c:\progra~2\RgFqlXFJatY.exe uRun: [ImxpkgNQo7ZcXknT] c:\progra~2\ImxpkgNQo7ZcXknT.exe uRun: [3qPbZBGJ] c:\progra~2\3qPbZBGJ.exe uRun: [bTl53SCxZd7Lh] c:\programdata\bTl53SCxZd7Lh.exe mRun: [picon] "c:\program files\common files\intel\privacy icon\PrivacyIconClient.exe" -startup mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [DellControlPoint] "c:\program files\dell\dell controlpoint\Dell.ControlPoint.exe" mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe mRun: [Dell Webcam Central] "c:\program files\dell webcam\dell webcam central\WebcamDell.exe" /mode2 mRun: [Google Quick Search Box] "c:\program files\google\quick search box\GoogleQuickSearchBox.exe" /autorun mRun: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe mRun: [WD Button Manager] WDBtnMgr.exe mRun: [LTCM Client] c:\program files\ltcm client\ltcmClient.exe /startup mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Sophos AutoUpdate Monitor] c:\program files\sophos\autoupdate\almon.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" dRun: [Communicator] "c:\program files\microsoft office communicator\Communicator.exe" StartupFolder: c:\users\gbarron\appdata\roaming\micros~1\windows\startm~1\programs\startup\epsona~1.lnk - d:\common\epsonreg\EpsonReg.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\amazon~1.lnk - c:\program files\amazon\amazon unbox video\ADVWindowsClientSystemTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellco~1.lnk - c:\program files\dell\dell controlpoint\system manager\DCPSysMgr.exe uPolicies-system: ReportControllerMissing = 1 (0x1) mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: MaxGPOScriptWait = 0 (0x0) IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12 \REFIEBAR.DLL IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll Trusted Zone: mercyhurst.edu\campusmanager Trusted Zone: microsoft.com DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - file:///D:/LTOCX14N.cab DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab DPF: {15B782AF-55D8-11D1-B477-006097098764} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/authorware/awswaxd.cab DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://cengage.webex.com/client/T27L/webex/ieatgpc1.cab Notify: igfxcui - igfxdev.dll AppInit_DLLs: c:\progra~1\sophos\sophos~1\SOPHOS~1.DLL Hosts: 127.0.0.1 www.spywareinfo.com ================= FIREFOX =================== FF - ProfilePath - c:\users\gbarron\appdata\roaming\mozilla\firefox\profiles\426dwsii.default\ FF - prefs.js: browser.startup.homepage - hxxp://lakernet.mercyhurst.edu/ FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.2.183.39\npGoogleOneClick8.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000- 0024-ABCDEFFEDCBA} FF - Extension: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08 -4474-a285-3208198ce6fd} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC -0016-0000-0011-ABCDEFFEDCBA} FF - Extension: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC -0016-0000-0013-ABCDEFFEDCBA} FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\DotNetAssistantExtension FF - Extension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\users\gbarron\appdata\roaming\mozilla\firefox\profiles\426dwsii.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} ============= SERVICES / DRIVERS =============== R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-6-22 64160] R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\drivers\savonaccess.sys [2011-2-4 122360] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\driverstore\filerepository\stwrt.inf_2311653e\AEstSrv.exe [2009 -2-17 77824] R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostControlService.exe [2008-11-11 808296] R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\broadcom corporation\broadcom ush host components\cv\bin\HostStorageService.exe [2008-11-11 20840] R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1029456] R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2011-2-4 163056] R2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2011-2-4 97520] R2 Sophos Agent;Sophos Agent;c:\program files\sophos\remote management system\ManagementAgentNT.exe [2011-2-4 282624] R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2010-9-30 230640] R2 Sophos Message Router;Sophos Message Router;c:\program files\sophos\remote management system\RouterNT.exe [2011-2-4 806912] R2 swi_service;Sophos Web Intelligence Service;c:\program files\sophos\sophos anti-virus\web intelligence\swi_service.exe [2011-2-4 1541360] R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\common files\intel\privacy icon\uns\UNS.exe [2009-2-17 2058776] R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\drivers\ccidflt.sys [2009-2-17 12840] R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\drivers\cvusbdrv.sys [2008-11-11 32808] R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\drivers\e1y6032.sys [2009-2-17 224384] R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2009-2-17 112128] R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32 \drivers\NETw5v32.sys [2008-6-26 3662848] R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\drivers\OA001Ufd.sys [2008-11-26 133472] R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\drivers\OA001Vid.sys [2008-12-26 279488] S2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\dell\dell controlpoint\DCPButtonSvc.exe [2008-6-3 386328] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319 \mscorsvw.exe [2010-3-18 130384] S2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\dell\dell controlpoint\system manager\DCPSysMgrSvc.exe [2008-8-18 453712] S2 gupdate1c9e522293f8bdb;Google Update Service (gupdate1c9e522293f8bdb);c:\program files\google\update\GoogleUpdate.exe [2009-6-4 133104] S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-2-18 1153368] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2009-2-18 21504] S3 PeerDistSvc;BranchCache;c:\windows\system32\svchost.exe -k PeerDist [2009-2-18 21504] S3 sdcfilter;sdcfilter;c:\windows\system32\drivers\sdcfilter.sys [2011-2-4 23928] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319 \wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2011-2-4 22536] =============== Created Last 30 ================ 2011-02-19 01:49:59 472808 —-a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll 2011-02-19 01:49:58 472808 —-a-w- c:\windows\system32\deployJava1.dll 2011-02-18 19:15:55 ——– d—–w- c:\progra~2\dKlKiGd06504 2011-02-18 06:12:51 ——– d—–w- c:\program files\ESET 2011-02-16 15:57:47 59904 –sha-r- c:\windows\system32\sl_anetr.dll 2011-02-16 05:02:14 ——– d—–w- C:\ComboFix 2011-02-15 14:27:01 5890896 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{d9b74aee-dfbb- 458e-8011-6f6b6569d8f6}\mpengine.dll 2011-02-11 19:02:06 708608 —-a-w- c:\program files\common files\system\ado\msado15.dll 2011-02-11 19:02:06 57344 —-a-w- c:\program files\common files\system\msadc\msadcs.dll 2011-02-11 19:02:06 413696 —-a-w- c:\windows\system32\odbc32.dll 2011-02-11 19:02:06 253952 —-a-w- c:\program files\common files\system\ado\msadox.dll 2011-02-11 19:02:06 241664 —-a-w- c:\program files\common files\system\ado\msadomd.dll 2011-02-11 19:02:06 180224 —-a-w- c:\program files\common files\system\msadc\msadco.dll 2011-02-11 19:01:54 1203032 —-a-w- c:\windows\system32\ntdll.dll 2011-02-11 19:00:33 1169408 —-a-w- c:\windows\system32\sdclt.exe 2011-02-11 05:54:20 388096 —-a-r- c:\users\gbarron\appdata\roaming\microsoft\installer\{45a66726-69bc-466b- a7a4-12fcba4883d7}\HiJackThis.exe 2011-02-11 05:54:18 ——– d—–w- c:\program files\Trend Micro 2011-02-04 20:12:57 131824 —-a-w- c:\windows\system32\sdccoinstaller.dll 2011-02-04 20:12:51 ——– d—–w- c:\progra~2\Sophos Web Intelligence 2011-02-04 20:12:12 ——– d—–w- c:\program files\common files\Cisco Systems 2011-02-04 20:12:09 28912 —-a-w- c:\windows\system32\SophosBootTasks.exe 2011-02-04 20:10:16 122360 —-a-w- c:\windows\system32\drivers\savonaccess.sys 2011-02-04 20:09:59 23928 —-a-w- c:\windows\system32\drivers\sdcfilter.sys 2011-02-04 20:09:48 22536 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys 2011-02-02 07:55:47 ——– d—–w- c:\program files\Emsisoft Anti-Malware 2011-01-30 19:57:00 103864 —-a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll 2011-01-30 19:57:00 103864 —-a-w- c:\program files\internet explorer\plugins\nppdf32.dll 2011-01-29 07:19:47 ——– d—–w- c:\progra~2\aJpEdEg09000 2011-01-29 04:31:21 ——– d—–w- c:\users\gbarron\appdata\local\Sophos 2011-01-27 01:15:48 ——– d—–w- c:\users\gbarron\appdata\roaming\PeerNetworking 2011-01-24 23:28:13 82696 —-a-w- c:\windows\system32\lmdimon8.dll 2011-01-24 23:28:13 82168 —-a-w- c:\windows\system32\spool\prtprocs\w32x86\lmdippr8.dll ==================== Find3M ==================== 2010-12-04 06:35:11 249856 ——w- c:\windows\Setup1.exe 2010-12-04 06:35:10 73216 —-a-w- c:\windows\ST6UNST.EXE 2010-12-04 06:25:05 286720 —-a-w- c:\windows\iun506.exe 2010-11-29 22:38:30 94208 —-a-w- c:\windows\system32\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- c:\windows\system32\QuickTime.qts 2006-05-03 09:06:54 163328 –sh–r- c:\windows\system32\flvDX.dll 2007-02-21 10:47:16 31232 –sh–r- c:\windows\system32\msfDX.dll 2008-03-16 12:30:52 216064 –sh–r- c:\windows\system32\nbDX.dll ============= FINISH: 14:50:50.52 ===============

Attachments:

  • [attachment removed: Attach223.zip]
AV: Security Suite *Enabled/Updated* {F5E52F41-190C-46f6-9FC3-55470285CC2B}
That is a Fake anti-virus program

1.Click Start > Settings > Control Panel.
2.Next, open Add/Remove Programs and remove if listed:
AV: Security Suite


Delete this folder
c:\progra~2\dKlKiGd06504

Delete these files
c:\programdata\ehSfAxdeCUNMnk.exe
c:\progra~2\RgFqlXFJatY.exe
c:\progra~2\ImxpkgNQo7ZcXknT.exe
c:\progra~2\3qPbZBGJ.exe
c:\programdata\bTl53SCxZd7Lh.exe

Now try Combofix
Thanks for sticking with this with me- I really appreciate this. I could not locate AV:Security Suite in the program folder. Tried searching, but no match found. I also could not locate this folder: c:\progra~2\dKlKiGd06504 or these files: c:\programdata\ehSfAxdeCUNMnk.exe c:\progra~2\ImxpkgNQo7ZcXknT.exe c:\progra~2\3qPbZBGJ.exe I did find these and deleted them: c:\programdata\bTl53SCxZd7Lh.exe c:\progra~2\RgFqlXFJatY.exe I'd appreciate any direction you could give me on how to locate Security Suite or the folder and files above. Thanks again!
They could be hidden

Vista Users

To enable the viewing of hidden and protected system files in Windows Vista please follow these steps:

Close all programs so that you are at your desktop.
Click on the Start button. This is the small round button with the Windows flag in the lower left corner.

Click on the Control Panel menu option.
When the control panel opens you can either be in Classic View or Control Panel Home view:

If you are in the Classic View do the following:
Double-click on the Folder Options icon.
Click on the View tab.


If you are in the Control Panel Home view do the following:

Click on the Appearance and Personalization link.
Click on Show Hidden Files or Folders.
Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
Remove the checkmark from the checkbox labeled Hide extensions for known file types.
Remove the checkmark from the checkbox labeled Hide protected operating system files.


Now see if you can find them
I found the folder dKIKI… and deleted it showing hidden folders/files. Still cannot locate the 3 other files with a manual or auto search.
Delete the combofix you have now on the desktop


Download Combofix from any of the links below but rename it to iexplore.exe before saving it to your desktop.

Link 1
Link 2 If using this link, Right Click and select Save As.


* IMPORTANT !!! Save iexplore.exe to your Desktop

Double click on the iexplore.exe ComboFix.exe & follow the prompts.
Be sure to download any updates.

  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt so we can continue cleaning the system.



  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs

  • Double click on ComboFix.exe & follow the prompts.

    Notes: Combofix will run without the Recovery Console installed. Skip the Recovery Console part if you're running Vista or Windows 7.

    Note: If you have SP3, use the SP2 package.
    If Vista or Windows 7, skip the Recovery Console part

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt using Copy / Paste in your next reply.


Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Give it atleast 20-30 minutes to finish if needed.

Please do not attach the scan results from Combofx. Use copy/paste.

Also please describe how your computer behaves at the moment.
OK-here's what I did and what happened:
First, deleted old desktop copy of Combofix and downloaded fresh one from link 1, renaming it iexplore.exe before saving it to desktop.
Deactivated Sophos and tried to start Combofix- got green status bar and then a blue screen message of a crash dump with Process_has_locked_files.
Restarted in safe mode.
Attempted to restart Combofix. This time got a security message that I had a corrupted copy of Combofix and should delete it. This was followed by a message from Combofix that Lavasoft was still running and I should disable it. I could not find Lavasoft in my programs, so I elected to run Combofix anyway. (I presume the first security message was bogus to stop me from running combofix?)
To my surprise, Combofix began to run through its stages, and after what seemed like a long wait, generated the following log:

ComboFix 11-02-28.03 - gbarron 02/28/2011 23:35:47.1.2 - x86 MINIMAL
Microsoft® Windows Vista™ Business 6.0.6002.2.1252.1.1033.18.3535.2898 [GMT -5:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Sophos Anti-Virus *Disabled/Updated* {479CCF92-4960-B3E0-7373-BF453B467D2C}
SP: Lavasoft Ad-Watch Live! *Enabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
SP: Sophos Anti-Virus *Disabled/Updated* {FCFD2E76-6F5A-BC6E-49C3-843740C13791}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\install.exe
c:\programdata\Microsoft\Network\Downloader\qmgr0.dat
c:\programdata\Microsoft\Network\Downloader\qmgr1.dat
c:\users\gbarron\AppData\Roaming\xssend2
c:\users\pcimage\AppData\Roaming\desktop.ini
c:\users\test\Desktop\Internet Explorer.lnk

—– BITS: Possible infected sites —–

hxxp://wus-vs:8530
.
((((((((((((((((((((((((( Files Created from 2011-02-01 to 2011-03-01 )))))))))))))))))))))))))))))))
.

2011-03-01 05:05 . 2011-03-01 05:07 ——– d—–w- c:\users\gbarron\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\test\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\mhurst99\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\lfrownfelter2\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\bhowell\AppData\Local\temp
2011-03-01 05:05 . 2011-03-01 05:05 ——– d—–w- c:\users\Administrator\AppData\Local\temp
2011-03-01 04:18 . 2011-03-01 04:22 ——– d—–w- C:\32788R22FWJFW
2011-02-19 01:51 . 2011-02-19 01:51 ——– d—–w- c:\program files\Common Files\Java
2011-02-19 01:49 . 2011-02-19 01:49 472808 —-a-w- c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
2011-02-19 01:49 . 2011-02-19 01:49 472808 —-a-w- c:\windows\system32\deployJava1.dll
2011-02-18 06:12 . 2011-02-18 06:12 ——– d—–w- c:\program files\ESET
2011-02-16 15:57 . 2011-02-16 15:57 59904 –sha-r- c:\windows\system32\sl_anetr.dll
2011-02-15 14:27 . 2011-01-13 09:41 5890896 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{D9B74AEE-DFBB-458E-8011-6F6B6569D8F6}\mpengine.dll
2011-02-11 19:02 . 2010-12-28 15:55 413696 —-a-w- c:\windows\system32\odbc32.dll
2011-02-11 19:02 . 2010-12-28 15:53 253952 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-02-11 19:02 . 2010-12-28 15:53 241664 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-02-11 19:02 . 2010-12-28 15:53 708608 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-02-11 19:02 . 2010-12-28 15:53 57344 —-a-w- c:\program files\Common Files\System\msadc\msadcs.dll
2011-02-11 19:02 . 2010-12-28 15:53 180224 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-02-11 19:01 . 2010-06-30 22:28 1203032 —-a-w- c:\windows\system32\ntdll.dll
2011-02-11 19:00 . 2010-12-14 14:49 1169408 —-a-w- c:\windows\system32\sdclt.exe
2011-02-11 05:54 . 2011-02-11 05:54 388096 —-a-r- c:\users\gbarron\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-11 05:54 . 2011-02-11 05:54 ——– d—–w- c:\program files\Trend Micro
2011-02-04 20:12 . 2011-02-04 20:10 131824 —-a-w- c:\windows\system32\sdccoinstaller.dll
2011-02-04 20:12 . 2011-02-04 20:12 ——– d—–w- c:\programdata\Sophos Web Intelligence
2011-02-04 20:12 . 2011-02-04 20:12 ——– d—–w- c:\program files\Common Files\Cisco Systems
2011-02-04 20:12 . 2011-02-04 20:09 28912 —-a-w- c:\windows\system32\SophosBootTasks.exe
2011-02-04 20:10 . 2011-02-04 20:10 122360 —-a-w- c:\windows\system32\drivers\savonaccess.sys
2011-02-04 20:09 . 2011-02-04 20:09 23928 —-a-w- c:\windows\system32\drivers\sdcfilter.sys
2011-02-04 20:09 . 2011-02-04 20:09 22536 —-a-w- c:\windows\system32\drivers\SophosBootDriver.sys
2011-02-02 07:55 . 2011-02-13 21:46 ——– d—–w- c:\program files\Emsisoft Anti-Malware
2011-01-30 19:57 . 2011-01-30 19:57 103864 —-a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-01-30 19:57 . 2011-01-30 19:57 103864 —-a-w- c:\program files\Internet Explorer\Plugins\nppdf32.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 23:09 . 2010-03-26 12:01 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 23:08 . 2010-03-26 12:01 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-12-04 06:35 . 2009-06-15 19:21 249856 ——w- c:\windows\Setup1.exe
2010-12-04 06:35 . 2009-06-15 19:21 73216 —-a-w- c:\windows\ST6UNST.EXE
2010-12-04 06:25 . 2010-12-04 06:25 286720 —-a-w- c:\windows\iun506.exe
2006-05-03 09:06 163328 –sh–r- c:\windows\System32\flvDX.dll
2007-02-21 10:47 31232 –sh–r- c:\windows\System32\msfDX.dll
2008-03-16 12:30 216064 –sh–r- c:\windows\System32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-07-23 5803368]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-06-04 39408]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"picon"="c:\program files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe" [2008-06-19 367128]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-08-08 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-08-08 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-08-08 145944]
"DellControlPoint"="c:\program files\Dell\Dell ControlPoint\Dell.ControlPoint.exe" [2008-05-30 593920]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-10-17 442536]
"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-06-04 68592]
"WD Button Manager"="WDBtnMgr.exe" [2010-01-15 364544]
"LTCM Client"="c:\program files\LTCM Client\ltcmClient.exe" [2008-12-24 1540288]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Sophos AutoUpdate Monitor"="c:\program files\Sophos\AutoUpdate\almon.exe" [2010-09-30 439536]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Communicator"="c:\program files\Microsoft Office Communicator\Communicator.exe" [2007-07-23 5803368]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Amazon Unbox.lnk - c:\program files\Amazon\Amazon Unbox Video\ADVWindowsClientSystemTray.exe [2010-9-13 97384]
Dell ControlPoint System Manager.lnk - c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgr.exe [2008-8-18 1186896]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"MaxGPOScriptWait"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"ReportControllerMissing"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Sophos\SOPHOS~1\sophos_detoured.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1422877143-578114725-926709054-12956\Scripts\Logon\0\0]
"Script"=logonedited.vbs

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1422877143-578114725-926709054-28461\Scripts\Logon\0\0]
"Script"=usercommconfig.bat

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\S-1-5-21-1422877143-578114725-926709054-28461\Scripts\Logon\1\0]
"Script"=logonedited.vbs

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
2010-03-03 16:35 524632 —-a-w- c:\program files\Lavasoft\Ad-Aware\AAWTray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2011-01-31 08:44 35760 —-a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-12-13 22:16 421160 —-a-w- c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 22:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

R0 pegcbrhq;pegcbrhq; [x]
R1 SAVOnAccess;SAVOnAccess;c:\windows\system32\DRIVERS\savonaccess.sys [2011-02-04 122360]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_2311653e\aestsrv.exe [2008-06-27 77824]
R2 buttonsvc32;Dell ControlPoint Button Service;c:\program files\Dell\Dell ControlPoint\DCPButtonSvc.exe [2008-06-03 386328]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 Credential Vault Host Control Service;Credential Vault Host Control Service;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe [2008-11-11 808296]
R2 Credential Vault Host Storage;Credential Vault Host Storage;c:\program files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe [2008-11-11 20840]
R2 dcpsysmgrsvc;Dell ControlPoint System Manager;c:\program files\Dell\Dell ControlPoint\System Manager\DCPSysMgrSvc.exe [2008-08-18 453712]
R2 gupdate1c9e522293f8bdb;Google Update Service (gupdate1c9e522293f8bdb);c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 133104]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [2011-02-04 163056]
R2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [2011-02-04 97520]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
R2 swi_service;Sophos Web Intelligence Service;c:\program files\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2011-02-04 1541360]
R2 UNS;Intel® Active Management Technology User Notification Service;c:\program files\Common Files\Intel\Privacy Icon\UNS\UNS.exe [2008-06-19 2058776]
R3 CCIDFILTER;Broadcom Smart Card Reader Filter Driver;c:\windows\system32\DRIVERS\ccidflt.SYS [2008-11-11 12840]
R3 cvusbdrv;Broadcom USH CV;c:\windows\system32\Drivers\cvusbdrv.sys [2008-11-11 32808]
R3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y6032.sys [2008-04-04 224384]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [2008-06-30 112128]
R3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2008-06-26 3662848]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\system32\DRIVERS\OA001Ufd.sys [2008-11-26 133472]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\system32\DRIVERS\OA001Vid.sys [2008-12-26 279488]
R3 PeerDistSvc;BranchCache;c:\windows\System32\svchost.exe [2008-01-19 21504]
R3 sdcfilter;sdcfilter;c:\windows\system32\DRIVERS\sdcfilter.sys [2011-02-04 23928]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R4 SophosBootDriver;SophosBootDriver;c:\windows\system32\DRIVERS\SophosBootDriver.sys [2011-02-04 22536]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-06-22 64160]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-03-03 1029456]


— Other Services/Drivers In Memory —

*NewlyCreated* - ECACHE

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
PeerDist REG_MULTI_SZ PeerDistSvc
.
Contents of the 'Scheduled Tasks' folder

2010-03-26 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 16:35]

2011-02-28 c:\windows\Tasks\Daily-12pm.job
- c:\program files\Sophos\Sophos Anti-Virus\BackgroundScanClient.exe [2011-02-04 20:09]

2010-03-26 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.1.0.14\DriverRobot.exe [2009-10-23 21:51]

2010-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 14:38]

2010-10-18 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-06-04 14:38]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://my.mercyhurst.edu/Pages/default.aspx
uInternet Settings,ProxyOverride =
Trusted Zone: mercyhurst.edu\campusmanager
Trusted Zone: microsoft.com
DPF: {00140000-B1BA-11CE-ABC6-F5B2E79D9E3F} - file:///D:/LTOCX14N.cab
FF - ProfilePath -
.
- - - - ORPHANS REMOVED - - - -

Toolbar-Locked - (no file)
HKCU-Run-ehSfAxdeCUNMnk.exe - c:\programdata\ehSfAxdeCUNMnk.exe
HKCU-Run-RgFqlXFJatY - c:\progra~2\RgFqlXFJatY.exe
HKCU-Run-ImxpkgNQo7ZcXknT - c:\progra~2\ImxpkgNQo7ZcXknT.exe
HKCU-Run-3qPbZBGJ - c:\progra~2\3qPbZBGJ.exe
HKCU-Run-bTl53SCxZd7Lh - c:\programdata\bTl53SCxZd7Lh.exe
HKLM-Run-SysTrayApp - %ProgramFiles%\IDT\WDM\sttray.exe
HKLM-RunOnce- - (no file)
AddRemove-Copy Utility - c:\program files\EPSON\Copy Utility\Uninst.isu
AddRemove-PF 2450 PHOTO Guide - c:\program files\EPSON\2450 PHOTO\DeIsL1.isu



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-01 00:07
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sophos Message Router]
"ImagePath"="\"c:\program files\Sophos\Remote Management System\RouterNT.exe\" -service -name Router -ORBListenEndpoints iiop://:8193/ssl_port=8194"
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2011-03-01 00:24:30
ComboFix-quarantined-files.txt 2011-03-01 05:24

Pre-Run: 19,978,457,088 bytes free
Post-Run: 20,229,402,624 bytes free

- - End Of File - - 3422DF2096B5D2140480992C1BE200A6
Please go to http://www.virustotal.com/, click on Browse, and upload the following file for analysis:

c:\windows\system32\sl_anetr.dll

Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.


If virustotal is too busy you can try these.

http://virusscan.jotti.org

http://www.kaspersky.com/scanforvirus.html
Initially would not allow me to upload-received message that I did not have permission to open file and that i should contact file owner. Right clicked on properties and assigned myself full control under the security tab. This worked-uploaded to Kasspersky first as virustotal was busy. Kasspersky gave it a clean bill of health. Then uploaded it to virustotal with the following analysis:
VT Community Sign in ▼ My account ▼ Sign out Signing out… Languages ▼

VirusTotal's website has changed, we need new translations, do you feel like helping the community?
[removed]
Sign in to VT CommunitySafety ratings and user comments (disinfection, in-the-wild locations, reverse engineering reports, etc.) on malware and URLs, free and easy.
email
password
Keep me logged in
Sign in Signing in, please wait…
Login failed, please try again
Forgot your password? Create an account

Edit my profile
View my profile
Inbox

Virustotal is a service that analyzes suspicious files and URLs and facilitates the quick detection of viruses, worms, trojans, and all kinds of malware detected by antivirus engines. More information…

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: sl_anetr.dll
Submission date: 2011-03-02 03:59:57 (UTC)
Current status: queued queued analysing finished


Result: 12/ 42 (28.6%)
VT Community

not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.03.02.00 2011.03.01 -
AntiVir 7.11.4.24 2011.03.01 TR/Vundo.Gen
Antiy-AVL 2.0.3.7 2011.03.01 -
Avast 4.8.1351.0 2011.02.23 Win32:MalOb-EI
Avast5 5.0.677.0 2011.02.23 Win32:MalOb-EI
AVG 10.0.0.1190 2011.03.01 -
BitDefender 7.2 2011.03.02 Gen:Variant.Vundo.5
CAT-QuickHeal 11.00 2011.03.01 -
ClamAV 0.96.4.0 2011.03.01 -
Commtouch 5.2.11.5 2011.03.02 -
Comodo 7846 2011.03.02 -
DrWeb 5.0.2.03300 2011.03.02 -
Emsisoft 5.1.0.2 2011.03.02 Gen.Variant.Vundo!IK
eSafe 7.0.17.0 2011.03.01 -
eTrust-Vet 36.1.8191 2011.03.01 -
F-Prot 4.6.2.117 2011.02.28 -
F-Secure 9.0.16160.0 2011.03.02 Gen:Variant.Vundo.5
Fortinet 4.2.254.0 2011.03.02 -
GData 21 2011.03.02 Gen:Variant.Vundo.5
Ikarus T3.1.1.97.0 2011.03.02 Gen.Variant.Vundo
Jiangmin 13.0.900 2011.03.01 -
K7AntiVirus 9.91.3990 2011.03.01 -
Kaspersky 7.0.0.125 2011.03.02 -
McAfee 5.400.0.1158 2011.03.02 -
McAfee-GW-Edition 2010.1C 2011.03.01 -
Microsoft 1.6603 2011.03.01 -
NOD32 5918 2011.03.01 Win32/Adware.Virtumonde.NHD
Norman 6.07.03 2011.03.01 -
nProtect 2011-02-10.01 2011.02.15 Gen:Variant.Vundo.5
Panda 10.0.3.5 2011.03.01 Suspicious file
PCTools 7.0.3.5 2011.03.01 -
Prevx 3.0 2011.03.02 Medium Risk Malware
Rising 23.47.01.06 2011.03.01 -
Sophos 4.61.0 2011.03.02 -
SUPERAntiSpyware 4.40.0.1006 2011.03.02 -
Symantec 20101.3.0.103 2011.03.02 -
TheHacker 6.7.0.1.142 2011.03.01 -
TrendMicro 9.200.0.1012 2011.03.02 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.02 -
VIPRE 8580 2011.03.02 -
ViRobot 2011.3.2.4334 2011.03.02 -
VirusBuster 13.6.229.0 2011.03.01 -
Additional informationShow all
MD5 : 0082d7a97a224ed09ea72cf14991a228
SHA1 : ff68e0dd6ae4764640c57d068c3da7cba6897935
SHA256: 47fa7e5ea3f5475513ee3009dfeed99d065f30553258c59a3c55035fa4f606cd
ssdeep: 1536:NDTfyitD0PuX49B5zr170H2w1ZeGXSMIAC:NPfycD0WXsB5VQWIKr
File size : 59904 bytes
First seen: 2011-03-02 03:59:57
Last seen : 2011-03-02 03:59:57
TrID:
Win64 Executable Generic (80.9%)
Win32 Executable Generic (8.0%)
Win32 Dynamic Link Library (generic) (7.1%)
Generic Win/DOS Executable (1.8%)
DOS Executable Generic (1.8%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Microsoft_ Windows_ Operating System
description..: WDM Tee/Communication Transform Filter
original name: mstee.sys
internal name: mstee.sys
file version.: 6.1.7000.0 (winmain_win7beta.081212-1400)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned

PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x444E
timedatestamp….: 0x4959EA03 (Tue Dec 30 09:29:39 2008)
machinetype……: 0x14c (I386)

[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x3662, 0x3800, 6.39, a2cc7175ac0b907a3703140b1a256696
.rdata, 0x5000, 0x90CE, 0x9200, 5.44, 85e913475e7804cc1b0bb64360b4858b
.data, 0xF000, 0x8E0C, 0x1000, 0.51, 4f1b225bf082359a2d62c75e34979481
.rsrc, 0x18000, 0x410, 0x600, 2.48, e0b54e0c26478b2fb1d32563098993a5
.reloc, 0x19000, 0x474, 0x600, 4.47, 6e521f365ded85716ba48023a7bc30f7

[[ 4 import(s) ]]
KERNEL32.dll: HeapAlloc, HeapCreate, HeapFree, GetProcAddress, LoadLibraryW, TerminateProcess, GetCurrentProcess, SetUnhandledExceptionFilter, LocalFree, FormatMessageW, GlobalFree, GlobalSize, GlobalReAlloc, lstrcpyW, lstrcpynW, GetFileAttributesW, lstrlenW, EnterCriticalSection, LeaveCriticalSection, lstrcmpiW, GetCommandLineA, GlobalAlloc, GetModuleHandleW, VirtualProtect
USER32.dll: DestroyWindow, ShowWindow, SetWindowLongW, DrawTextW, CharNextW, SetCursor, IsWindow, GetWindowLongW, CharUpperBuffW, CharLowerW, LoadStringW, LoadIconW, EnableWindow, SendMessageW, SetWindowTextW, GetParent, RedrawWindow, DefWindowProcW, GetDlgItem
GDI32.dll: SetTextColor, GetTextExtentPointW, ExtTextOutW
MSVCR71.dll: _onexit, malloc, _initterm, free, _except_handler3, __CppXcptFilter, __dllonexit, _adjust_fdiv

Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…73430008FBA52C4
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 16384
CompanyName: Microsoft Corporation
EntryPoint: 0x444e
FileDescription: WDM Tee/Communication Transform Filter
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 58 kB
FileSubtype: 7
FileType: Win32 DLL
FileVersion: 6.1.7000.0 (winmain_win7beta.081212-1400)
FileVersionNumber: 6.1.7000.0
ImageVersion: 6.1
InitializedDataSize: 86016
InternalName: mstee.sys
LanguageCode: Neutral
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 9.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Driver
OriginalFilename: mstee.sys
PEType: PE32
ProductName: Microsoft Windows Operating System
ProductVersion: 6.1.7000.0
ProductVersionNumber: 6.1.7000.0
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2008:12:30 10:29:39+01:00
UninitializedDataSize: 0

Symantec reputation:Suspicious.Insight


VT Community

0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
VirusTotal Team
Add your comment… Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?

You can add basic styles to your comments using the following accepted bbcode tags:

text – bold
text – italics
text – underline
text – strikethrough
text
– preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.

Goodware Malware Spam attachment/link
P2P download Propagating via IM Network worm
Drive-by-download



Anonymous limit exceeded: anonymous users can only make one comment per file or URL, either sign in or register in order to continue making reviews on this item. Note that anonymous user discrimination is based on IP addresses, hence, it may be possible that another user behind your same proxy or NAT connection already made a review.

Preview commentEdit comment Post comment Posting comment…
Comment successfully posted







ATTENTION: VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
VirusTotal © Hispasec Sistemas - Blog

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI