This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

New browser pop ups are driving me crazy

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has been infected with several viruses over the past few months. I think I have managed to rid myself of most of them, however, I am still getting new internet browswr windows popping up uncontrollably. I have tried to run AVG, ESET, Spykiller and a few other programs, but nothing is picking it up. Please help! I have included my latest Hijack This log. Thank you in advance for any advice you might have.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:29:16 PM, on 6/6/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Google\Update\1.3.21.57\GoogleCrashHandler.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoHelper_en.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/?pc=Z006&form=ZGAPHP
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: PhotoPos Pro Toolbar - {A057A204-BACC-4D26-9F9D-3BEFCFBE6E86} - C:\PROGRA~1\PHOTOP~3\PHOTOP~1.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O3 - Toolbar: PhotoPos Pro Toolbar - {A057A204-BACC-4D26-9F9D-3BEFCFBE6E86} - C:\PROGRA~1\PHOTOP~3\PHOTOP~1.DLL
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DropBoxUtility] "C:\Program Files\DropBox\DropBox\DropBox.exe" /s
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realone player\update\realsched.exe" -osboot
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [SelectRebates] C:\Program Files\SelectRebates\SelectRebates.exe
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\ApcMain.exe -m
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [PlaxoUpdate] C:\Documents and Settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoHelper_en.exe -a
O4 - HKCU\..\Run: [PlaxoSysTray] C:\Documents and Settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoSysTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: RemindU - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: RemindU - {2863ACA1-9AA0-4432-8CFE-88C12B3B2E5E} - file://C:\Program Files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm (HKCU)
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 10242 bytes
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Having said that….Let's get going!! :thumbup:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise, this will be a team effort.
This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Vista and Windows 7 users:

These tools MUST be run from the executable. (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.
Hi jtt331,

I notice that you have both ESET Antivirus and AVG on your system. Which antivirus program are you actively using? Is your subscription to ESET current and available for use?

Please RUN HijackThis.

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis.
    • Place a check mark beside each one of the following items:
      O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
      O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -
      O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} -
      O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
    • Now with all the items selected, and all windows closed except for HJT, delete them by clicking the FIX checked button. Close the HijackThis window.
    ———-

    Please download DDS by sUBs from one of the following links and save it to your desktop.
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it


In your next reply please post both logs created by DDS and the log created by aswMBR as well as letting me know about the antivirus programs I asked about in the beginning. :)
HI Jeff, thank you for responding to my post. I am not home much, so it may take some time to reply to your posts and I apologize for that. I just wanted to put that up front in case some time goes by in between posts. I am going to try and do what you suggested tonight, but may not get a chance to. As soon as I can, I will post all the logs you requested. Right now, I am currently running ESET but have not de-activated AVG. Should I do so? Thanks again for your help.
Okay, I think I have everything you need. Here are the logs…..Thanks again!!!


DDS (Ver_2011-06-03.01) - NTFSx86
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_15
Run by [removed] at 16:20:00 on 2011-06-08
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.961 [GMT -4:00]
.
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Antivirus AntiSpyware 2011 *Enabled/Updated* {9BF7A7D0-DE0B-4C41-A909-8A0E9C6235AB}
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
FW: Antivirus AntiSpyware 2011 *Enabled*
.
============== Running Processes ===============
.
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Netropa\Multimedia Keyboard\nhksrv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Google\Update\1.3.21.57\GoogleCrashHandler.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\System32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Documents and Settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoHelper_en.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Microsoft Office\Office\EXCEL.EXE
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Mozilla Firefox\firefox.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.bing.com/?pc=Z006&form=ZGAPHP
uSearch Page = hxxp://www.google.com
uDefault_Search_URL = hxxp://search.msn.com
uSearch Bar = hxxp://www.google.com/ie
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mURLSearchHooks: N/A: {d73f49b6-b51b-4d32-a3b7-bd04b8342f53} -
mWinlogon: SFCDisable=4 (0x4)
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: PhotoPos Pro Toolbar: {a057a204-bacc-4d26-9f9d-3befcfbe6e86} - c:\progra~1\photop~3\PHOTOP~1.DLL
BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: PhotoPos Pro Toolbar: {a057a204-bacc-4d26-9f9d-3befcfbe6e86} - c:\progra~1\photop~3\PHOTOP~1.DLL
TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll
TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn3\yt.dll
TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} -
TB: &Crawler lišta: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} -
TB: Morpheus Toolbar: {3f3714a9-89a4-46be-8af3-d0c9d1fb03f9} -
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} -
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: ShopAtHome.com Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [updateMgr] "c:\program files\adobe\acrobat 7.0\reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m
uRun: [Messenger (Yahoo!)] "c:\program files\yahoo!\messenger\YahooMessenger.exe" -quiet
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [PlaxoUpdate] c:\documents and settings\owner\local settings\application data\plaxo\3.26.0.13\PlaxoHelper_en.exe -a
uRun: [PlaxoSysTray] c:\documents and settings\owner\local settings\application data\plaxo\3.26.0.13\PlaxoSysTray.exe
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [DropBoxUtility] "c:\program files\dropbox\dropbox\DropBox.exe" /s
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [TkBellExe] "c:\program files\real\realone player\update\realsched.exe" -osboot
mRun: []
mRun: [ApnUpdater] "c:\program files\ask.com\updater\Updater.exe"
mRun: [SelectRebates] c:\program files\selectrebates\SelectRebates.exe
mRun: [egui] "c:\program files\eset\eset nod32 antivirus\egui.exe" /hide /waitservice
dRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adobeg~1.lnk - c:\program files\common files\adobe\calibration\Adobe Gamma Loader.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpimag~1.lnk - c:\program files\hp\digital imaging\bin\hpqthb08.exe
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-us\local\search.html
IE: &Search
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search
IE: RemindU - file://c:\program files\upromise_remindu\sy1050\tp1050\scri1050a.htm
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922}
IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
DPF: DirectAnimation Java Classes - file://c:\windows\java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_15-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{8315BAF3-DA66-4871-8FC7-BC99CCFB021A} : DhcpNameServer = 192.168.1.1
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: avgrsstarter - avgrsstx.dll
Notify: igfxcui - igfxsrvc.dll
Notify: PCANotify - PCANotify.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\documents and settings\owner\application data\mozilla\firefox\profiles\6oljsjfq.jen\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=PSI&o=15116&locale=en_US&apn_uid=71267C36-3737-4C69-9F5B-09CA2DA85FF0&apn_ptnrs=L6&apn_sauid=21534966-0C9D-40F4-B73A-00D0006E6084&apn_dtid=&q=
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordext.dll
FF - component: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\firefox\ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
FF - plugin: c:\documents and settings\owner\application data\move networks\plugins\npqmp071505000010.dll
FF - plugin: c:\documents and settings\owner\application data\move networks\plugins\npqmp071706000001.dll
FF - plugin: c:\program files\canon\zoombrowser ex\program\NPCIG.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol400.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPcol500.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NPMorpBr.dll
FF - plugin: c:\program files\mozilla firefox\plugins\NpPopup.dll
FF - plugin: c:\program files\real\realone player\netscape6\nppl3260.dll
FF - plugin: c:\program files\real\realone player\netscape6\nprjplug.dll
FF - plugin: c:\program files\real\realone player\netscape6\nprpjplug.dll
FF - plugin: c:\ramson\google\picasa3\npPicasa2.dll
FF - plugin: c:\ramson\google\picasa3\npPicasa3.dll
.
—- FIREFOX POLICIES —-
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
============= SERVICES / DRIVERS ===============
.
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-1-4 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-1-4 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-1-4 108552]
R1 AW_HOST;AW_HOST;c:\windows\system32\drivers\AW_HOST5.sys [2002-2-11 33496]
R1 awlegacy;awlegacy;c:\windows\system32\drivers\AWLEGACY.SYS [2000-9-11 10816]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [2010-12-21 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2010-12-21 94872]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [2005-1-29 6656]
R2 aawservice;Ad-Aware 2007 Service;c:\program files\lavasoft\ad-aware 2007\aawservice.exe [2007-7-6 561152]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\avg\avg8\avgemc.exe [2009-1-4 908056]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-1-4 297752]
R2 ekrn;ESET Service;c:\program files\eset\eset nod32 antivirus\ekrn.exe [2011-1-12 810144]
R2 McAfeeFramework;McAfee Framework Service;c:\program files\network associates\common framework\FrameworkService.exe [2003-9-5 106586]
R2 nhksrv;Netropa NHK Server;c:\program files\netropa\multimedia keyboard\nhksrv.exe [2005-1-29 28672]
S0 dsmghm;dsmghm;c:\windows\system32\drivers\xlmrbnhp.sys –> c:\windows\system32\drivers\xlmrbnhp.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-22 135664]
S2 srvF28;srvF28;c:\windows\system32\svchost.exe -k netsvcs [2002-9-3 14336]
S3 Ad-Watch Connect Filter;Ad-Watch Connect Kernel Filter;c:\windows\system32\drivers\NSDriver.sys [2007-6-4 9344]
S3 awhost32;pcAnywhere Host Service;c:\program files\symantec\pcanywhere\AWHOST32.EXE [2002-2-15 114749]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-12-22 135664]
.
=============== File Associations ===============
.
.txt=
.
=============== Created Last 30 ================
.
2011-06-06 20:47:19 388096 —-a-r- c:\documents and settings\owner\application data\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-05-24 10:53:59 229376 —-a-r- c:\windows\system32\hpovst08.dll
2011-05-24 10:53:58 581632 —-a-r- c:\windows\system32\hpotscl.dll
2011-05-22 19:58:45 ——– d—–w- c:\documents and settings\owner\local settings\application data\ESET
2011-05-22 18:23:22 ——– d—–w- c:\program files\ESET
2011-05-22 18:10:09 54016 —-a-w- c:\windows\system32\drivers\auqwgxcl.sys
2011-05-18 18:26:40 ——– d-sh–w- C:\found.000
2011-05-11 19:26:42 781272 —-a-w- c:\program files\mozilla firefox\mozsqlite3.dll
2011-05-11 19:26:41 1874904 —-a-w- c:\program files\mozilla firefox\mozjs.dll
2011-05-11 19:26:40 15832 —-a-w- c:\program files\mozilla firefox\mozalloc.dll
2011-05-11 19:26:39 89048 —-a-w- c:\program files\mozilla firefox\libEGL.dll
2011-05-11 19:26:39 465880 —-a-w- c:\program files\mozilla firefox\libGLESv2.dll
2011-05-11 19:26:38 1892184 —-a-w- c:\program files\mozilla firefox\d3dx9_42.dll
2011-05-11 19:26:38 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
2011-05-11 19:26:37 1974616 —-a-w- c:\program files\mozilla firefox\D3DCompiler_42.dll
.
==================== Find3M ====================
.
.
=================== ROOTKIT ====================
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600 Disk: WDC_WD400BB-75DEA0 rev.05.03E05 -> Harddisk0\DR0 -> \Device\Ide\IdePort0 P0T0L0-3
.
device: opened successfully
user: MBR read successfully
.
Disk trace:
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8AFE3439]<<
_asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x8afe97d0]; MOV EAX, [0x8afe984c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
1 nt!IofCallDriver[0x804E37D5] -> \Device\Harddisk0\DR0[0x8B01AAB8]
3 CLASSPNP[0xF7637FD7] -> nt!IofCallDriver[0x804E37D5] -> [0x8AF4D860]
\Driver\atapi[0x8B043BD8] -> IRP_MJ_CREATE -> 0x8AFE3439
kernel: MBR read successfully
_asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; STI ; PUSH AX; POP ES; PUSH AX; POP DS; CLD ; MOV SI, 0x7c1b; MOV DI, 0x61b; PUSH AX; PUSH DI; MOV CX, 0x1e5; REP MOVSB ; RETF ; MOV BP, 0x7be; MOV CL, 0x4; CMP [BP+0x0], CH; JL 0x2e; JNZ 0x3a; }
detected disk devices:
\Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskWDC_WD400BB-75DEA0______________________05.03E05#4457572d414d3144393739303633_034_0_0_0_0#{5
3f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
detected hooks:
\Driver\atapi DriverStartIo -> 0x8AFE327F
user & kernel MBR OK
Warning: possible TDL3 rootkit infection !
.
============= FINISH: 16:23:18.64 ===============



aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-08 16:25:11
—————————–
16:25:11.500 OS Version: Windows 5.1.2600 Service Pack 3
16:25:11.500 Number of processors: 1 586 0x207
16:25:11.500 ComputerName: HOME-6OMCXJZ23I UserName: Owner
16:25:12.359 Initialize success
16:25:17.390 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
16:25:17.390 Disk 0 Vendor: WDC_WD400BB-75DEA0 05.03E05 Size: 38146MB BusType: 3
16:25:17.390 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskWDC_WD400BB-75DEA0______________________05.03E05#4457572d414d3144393739303633_034_0_0_0_0#{5
3f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
16:25:17.390 Device \Driver\atapi -> DriverStartIo 8afe327f
16:25:19.406 Disk 0 MBR read successfully
16:25:19.406 Disk 0 MBR scan
16:25:19.406 Disk 0 TDL4@MBR code has been found
16:25:19.406 Disk 0 Windows XP default MBR code found via API
16:25:19.406 Disk 0 MBR hidden
16:25:19.406 Disk 0 MBR [TDL4] **ROOTKIT**
16:25:19.406 Disk 0 trace - called modules:
16:25:19.421 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8afe3439]<<
16:25:19.421 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b01aab8]
16:25:19.421 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> [0x8af4d860]
16:25:19.421 \Driver\atapi[0x8b043bd8] -> IRP_MJ_CREATE -> 0x8afe3439
16:25:19.421 Scan finished successfully
16:25:42.078 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
16:25:42.078 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"

Attachments:

Hi jtt331,

Please go ahead now and uninstall AVG from your system. You can use the AVG uninstall tool found here to help you out with that. :) Just double-click the icon and follow the prompts to completely remove AVG.
———-

I would like for you now to please attach the following file to your next reply before running any of the following tools > C:\Documents and Settings\Owner\Desktop\MBR.dat
———

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click VirusTotal

copy and paste the following into the upload a file box (one at a time if more than one file is listed)

c:\windows\system32\drivers\auqwgxcl.sys
c:\windows\system32\drivers\xlmrbnhp.sys


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.
———-

Re-Run aswMBR

Click Scan

On completion of the scan

Click the FixButton

[external image: Posted Image]

Reboot your computer when prompted.

Save the log as before and post in your next reply.
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
———-

In your next reply please post the logs created by Virus Total, aswMBR.exe and ComboFix.
I have attached the mbr.dat file you requested. I'm not quite sure how to get the log from virustool so this may not be quite what your are looking for, but here is what I got for the first file you requested. I could not find the second file. Let me know if I need to do something different. I will hold off on the rest until I hear from you. Thanks. 9 VT Community user(s) with a total of 10237 reputation credit(s) say(s) this sample is goodware. 4 VT Community user(s) with a total of 3321 reputation credit(s) say(s) this sample is malware. File name: auqwgxcl.sys Submission date: 2011-06-09 20:16:50 (UTC) Current status: finished Result: 2/ 42 (4.8%) VT Community goodware Safety score: 75.5% Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.06.10.00 2011.06.09 - AntiVir 7.11.9.132 2011.06.09 - Antiy-AVL 2.0.3.7 2011.06.09 - Avast 4.8.1351.0 2011.06.09 - Avast5 5.0.677.0 2011.06.09 - AVG 10.0.0.1190 2011.06.09 - BitDefender 7.2 2011.06.09 - CAT-QuickHeal 11.00 2011.06.09 - ClamAV 0.97.0.0 2011.06.09 BC.Heuristics.Rootkit.B-11.MV Commtouch 5.3.2.6 2011.06.09 - Comodo 9009 2011.06.09 - DrWeb 5.0.2.03300 2011.06.09 - eSafe 7.0.17.0 2011.06.09 Win32.TrojanHorse eTrust-Vet 36.1.8378 2011.06.09 - F-Prot 4.6.2.117 2011.06.09 - F-Secure 9.0.16440.0 2011.06.09 - Fortinet 4.2.257.0 2011.06.09 - GData 22 2011.06.09 - Ikarus T3.1.1.104.0 2011.06.09 - Jiangmin 13.0.900 2011.06.09 - K7AntiVirus 9.105.4792 2011.06.09 - Kaspersky 9.0.0.837 2011.06.09 - McAfee 5.400.0.1158 2011.06.09 - McAfee-GW-Edition 2010.1D 2011.06.09 - Microsoft 1.6903 2011.06.09 - NOD32 6194 2011.06.09 - Norman 6.07.10 2011.06.09 - nProtect 2011-06-09.01 2011.06.09 - Panda 10.0.3.5 2011.06.09 - PCTools 7.0.3.5 2011.06.09 - Prevx 3.0 2011.06.09 - Rising 23.61.02.11 2011.06.09 - Sophos 4.66.0 2011.06.09 - SUPERAntiSpyware 4.40.0.1006 2011.06.09 - Symantec 20111.1.0.186 2011.06.09 - TheHacker 6.7.0.1.227 2011.06.09 - TrendMicro 9.200.0.1012 2011.06.09 - TrendMicro-HouseCall 9.200.0.1012 2011.06.09 - VBA32 3.12.16.1 2011.06.09 - VIPRE 9536 2011.06.09 - ViRobot 2011.6.9.4502 2011.06.09 - VirusBuster 14.0.74.0 2011.06.09 - Additional information MD5 : e6d35f3aa51a65eb35c1f2340154a25e SHA1 : aabbd57e20d2e7041f9e7abce6cfd8a53c366537 SHA256: 3da4f51682e7d42c5569f1fb1adc6295182962e36f748219e1d0c8f2389ba516 ssdeep: 768:Bosx0q2ph6P2Jpz8ftoSUiJP7hYTCMrhwYKUzY4q:j076P2Jpz8ftBUMPaCMrhwY File size : 54016 bytes First seen: 2009-09-18 00:44:25 Last seen : 2011-06-09 20:16:50 TrID: Clipper DOS Executable (33.3%) Generic Win/DOS Executable (33.0%) DOS Executable Generic (33.0%) VXD Driver (0.5%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%) sigcheck: publisher….: n/a copyright….: n/a product……: n/a description..: n/a original name: n/a internal name: n/a file version.: n/a comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0xC505 timedatestamp….: 0x4A9EE5B5 (Wed Sep 02 21:37:57 2009) machinetype……: 0x14c (I386) [[ 5 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x480, 0xBD9F, 0xBE00, 5.83, 9474f39576a0e15bdbaa2ea3355f0a4a .rdata, 0xC280, 0x126, 0x180, 3.78, 375b710d9f213cfced30e9fdb29567e1 .data, 0xC400, 0xC0, 0x100, 0.33, 786971ca2b109729eda604b44d6c72ad INIT, 0xC500, 0x3C8, 0x400, 5.20, eea49a93a73afb6afc178455582133c6 .reloc, 0xC900, 0x9EC, 0xA00, 6.62, bddd5a40c508bfc84ec87de5f8e6a5d3 [[ 1 import(s) ]] ntoskrnl.exe: ZwWriteFile, RtlUpcaseUnicodeChar, ZwClose, ZwCreateFile, RtlInitUnicodeString, _wcsicmp, ZwQueryValueKey, ZwOpenKey, ZwDeleteKey, swprintf, ZwEnumerateKey, ExFreePoolWithTag, DbgPrint, ExAllocatePool, RtlPrefixUnicodeString, memcpy, RtlDeleteRegistryValue, ZwSetValueKey, RtlWriteRegistryValue, ZwEnumerateValueKey, ZwSetInformationFile, ZwQueryInformationFile, ZwQueryDirectoryFile, ZwOpenFile, KeTickCount, KeBugCheck, MmGetSystemRoutineAddress, ZwFlushKey, PsTerminateSystemThread, KeSetPriorityThread, KeGetCurrentThread, RtlCheckRegistryKey, KeDelayExecutionThread, ZwReadFile, PsCreateSystemThread, PsGetVersion, KeBugCheckEx
Hi jtt331, That was just what I was wanting. Good Job!! :thumbup: Please continue with the instructions I had previously given and don't forget to post the logs created into your next reply.
Hi Jeff,
Here are the other two logs your requested. Looking forward to your response. Thank you.

Jen

aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-08 16:25:11
—————————–
16:25:11.500 OS Version: Windows 5.1.2600 Service Pack 3
16:25:11.500 Number of processors: 1 586 0x207
16:25:11.500 ComputerName: HOME-6OMCXJZ23I UserName: Owner
16:25:12.359 Initialize success
16:25:17.390 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdePort0
16:25:17.390 Disk 0 Vendor: WDC_WD400BB-75DEA0 05.03E05 Size: 38146MB BusType: 3
16:25:17.390 Device \Device\Ide\IdeDeviceP0T0L0-3 -> \??\IDE#DiskWDC_WD400BB-75DEA0______________________05.03E05#4457572d414d3144393739303633_034_0_0_0_0#{5
3f56307-b6bf-11d0-94f2-00a0c91efb8b} not found
16:25:17.390 Device \Driver\atapi -> DriverStartIo 8afe327f
16:25:19.406 Disk 0 MBR read successfully
16:25:19.406 Disk 0 MBR scan
16:25:19.406 Disk 0 TDL4@MBR code has been found
16:25:19.406 Disk 0 Windows XP default MBR code found via API
16:25:19.406 Disk 0 MBR hidden
16:25:19.406 Disk 0 MBR [TDL4] **ROOTKIT**
16:25:19.406 Disk 0 trace - called modules:
16:25:19.421 ntoskrnl.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8afe3439]<<
16:25:19.421 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b01aab8]
16:25:19.421 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> [0x8af4d860]
16:25:19.421 \Driver\atapi[0x8b043bd8] -> IRP_MJ_CREATE -> 0x8afe3439
16:25:19.421 Scan finished successfully
16:25:42.078 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
16:25:42.078 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"


aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-10 16:54:34
—————————–
16:54:34.453 OS Version: Windows 5.1.2600 Service Pack 3
16:54:34.453 Number of processors: 1 586 0x207
16:54:34.453 ComputerName: HOME-6OMCXJZ23I UserName: Owner
16:54:35.062 Initialize success
16:55:04.156 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
16:55:04.156 Disk 0 Vendor: WDC_WD400BB-75DEA0 05.03E05 Size: 38146MB BusType: 3
16:55:06.171 Disk 0 MBR read successfully
16:55:06.171 Disk 0 MBR scan
16:55:06.171 Disk 0 Windows XP default MBR code
16:55:08.171 Disk 0 scanning sectors +78108030
16:55:08.187 Disk 0 scanning C:\WINDOWS\system32\drivers
16:55:27.359 Service scanning
16:55:28.718 Disk 0 trace - called modules:
16:55:28.718 ntoskrnl.exe CLASSPNP.SYS disk.sys atapi.sys hal.dll pciide.sys PCIIDEX.SYS
16:55:28.718 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8afecab8]
16:55:28.718 3 CLASSPNP.SYS[f7637fd7] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x8aff9d98]
16:55:28.718 Scan finished successfully
16:55:55.750 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Owner\Desktop\MBR.dat"
16:55:55.750 The log file has been saved successfully to "C:\Documents and Settings\Owner\Desktop\aswMBR.txt"




ComboFix 11-06-09.04 - Owner 06/10/2011 16:07:20.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2046.1504 [GMT -4:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *Disabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ESET NOD32 Antivirus 4.2 *Disabled/Updated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Owner\Recent\Thumbs.db
c:\documents and settings\Owner\WINDOWS
c:\program files\Mozilla Firefox\plugins\NPMorpBr.dll
c:\program files\Search Toolbar
c:\program files\Search Toolbar\icon.ico
c:\program files\Search Toolbar\SearchToolbarUninstall.exe
c:\program files\Search Toolbar\SearchToolbarUpdater.exe
c:\program files\SelectRebates
c:\program files\SelectRebates\FFToolbar\chrome.manifest
c:\program files\SelectRebates\FFToolbar\chrome\sahtoolbar.jar
c:\program files\SelectRebates\FFToolbar\defaults\preferences\sahtoolbar.js
c:\program files\SelectRebates\FFToolbar\install.rdf
c:\program files\SelectRebates\SahImages\alert.png
c:\program files\SelectRebates\SahImages\check.png
c:\program files\SelectRebates\SahImages\close.png
c:\program files\SelectRebates\SelectAlerts.dat
c:\program files\SelectRebates\SelectRebates .exe
c:\program files\SelectRebates\SelectRebates.ini
c:\program files\SelectRebates\SelectRebatesA.dat
c:\program files\SelectRebates\SelectRebatesApi.exe
c:\program files\SelectRebates\SelectRebatesB.dat
c:\program files\SelectRebates\SelectRebatesBT.dat
c:\program files\SelectRebates\SelectRebatesDownload.exe
c:\program files\SelectRebates\SelectRebatesH.dat
c:\program files\SelectRebates\SelectRebatesUninstall.exe
c:\program files\SelectRebates\SRebates.dll
c:\program files\SelectRebates\SRFF3.dll
c:\program files\SelectRebates\Toolbar\AddtoList.bmp
c:\program files\SelectRebates\Toolbar\basis.xml
c:\program files\SelectRebates\Toolbar\Basis.xml.dym
c:\program files\SelectRebates\Toolbar\Blank.bmp
c:\program files\SelectRebates\Toolbar\CashBack.bmp
c:\program files\SelectRebates\Toolbar\Coupons.bmp
c:\program files\SelectRebates\Toolbar\GroceryCoupon.bmp
c:\program files\SelectRebates\Toolbar\i_magnifying.bmp
c:\program files\SelectRebates\Toolbar\icons.bmp
c:\program files\SelectRebates\Toolbar\logo.bmp
c:\program files\SelectRebates\Toolbar\logo_24.bmp
c:\program files\SelectRebates\Toolbar\logo_HotSpots.bmp
c:\program files\SelectRebates\Toolbar\ReviewSite.bmp
c:\program files\SelectRebates\Toolbar\RightControls.dym
c:\program files\SelectRebates\Toolbar\sahtb-alert.bmp
c:\program files\SelectRebates\Toolbar\sahtb-go.bmp
c:\program files\SelectRebates\Toolbar\sahtb-grocerycoupons.bmp
c:\program files\SelectRebates\Toolbar\sahtb-icons.bmp
c:\program files\SelectRebates\Toolbar\sahtb-restaurant.bmp
c:\program files\SelectRebates\Toolbar\sahtb-wishlist.bmp
c:\program files\SelectRebates\Toolbar\Scissors.bmp
C:\Thumbs.db
c:\windows\command
c:\windows\command\EXTRACT.PIF
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Legacy_RPCPATCH
——-\Legacy_RPCTFTPD
——-\Legacy_SVCPROC
.
.
((((((((((((((((((((((((( Files Created from 2011-05-10 to 2011-06-10 )))))))))))))))))))))))))))))))
.
.
2011-06-10 20:23 . 2011-06-10 20:23 ——– d—–w- c:\windows\LastGood
2011-06-09 20:15 . 2011-06-09 20:15 ——– d—–w- c:\program files\VirusTotalUploader2
2011-06-06 20:47 . 2011-06-06 20:47 388096 —-a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-05-24 10:53 . 2004-12-14 16:07 229376 —-a-r- c:\windows\system32\hpovst08.dll
2011-05-24 10:53 . 2004-12-14 16:07 581632 —-a-r- c:\windows\system32\hpotscl.dll
2011-05-22 19:58 . 2011-05-22 19:58 ——– d—–w- c:\documents and settings\Owner\Local Settings\Application Data\ESET
2011-05-22 18:30 . 2011-05-22 18:30 ——– d—–w- c:\documents and settings\LocalService\Local Settings\Application Data\ESET
2011-05-22 18:23 . 2011-05-22 18:23 ——– d—–w- c:\program files\ESET
2011-05-22 18:23 . 2011-05-22 18:23 ——– d—–w- c:\documents and settings\All Users\Application Data\ESET
2011-05-22 18:10 . 2011-05-22 18:10 54016 —-a-w- c:\windows\system32\drivers\auqwgxcl.sys
2011-05-22 17:23 . 2011-05-22 18:03 ——– d—–w- c:\documents and settings\Administrator
2011-05-21 01:02 . 2011-05-21 01:03 ——– d—–w- c:\documents and settings\John\Local Settings\Application Data\AskToolbar
2011-05-18 18:26 . 2011-05-18 18:26 ——– d—–w- C:\found.000
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-05-11 19:26 . 2011-05-11 19:26 142296 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
c:\program files\DropBox\DropBox\DropBox .exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-9F9D-3BEFCFBE6E86}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2011-05-17 17:29 1490312 —-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2011-05-17 1490312]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"Performance Center"="c:\program files\Ascentive\Performance Center\ApcMain.exe" [2009-01-23 3231744]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-08 68856]
"PlaxoUpdate"="c:\documents and settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoHelper_en.exe" [2011-04-29 834952]
"PlaxoSysTray"="c:\documents and settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\PlaxoSysTray.exe" [2011-04-29 15752]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"DropBoxUtility"="c:\program files\DropBox\DropBox\DropBox.exe" [N/A]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [N/A]
"TkBellExe"="c:\program files\real\realone player\update\realsched.exe" [N/A]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2011-05-17 395144]
"SelectRebates"="c:\program files\SelectRebates\SelectRebates.exe" [N/A]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2011-01-12 2219184]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2008-12-2 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-4 258048]
HP Image Zone Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-4 53248]
Kodak EasyShare software.lnk - c:\program files\KODAK\Kodak EasyShare software\bin\EasyShare.exe [2004-8-11 757760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PCANotify]
2002-02-15 14:51 24638 —-a-w- c:\windows\system32\PCANotify.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\srvF28]
@="service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaws.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [12/21/2010 3:04 PM 115008]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [12/21/2010 1:47 PM 94872]
R1 msikbd2k;Multimedia Keyboard Filter Driver;c:\windows\system32\drivers\Msikbd2k.sys [1/29/2005 2:34 PM 6656]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [1/12/2011 4:41 PM 810144]
R2 nhksrv;Netropa NHK Server;c:\program files\Netropa\Multimedia Keyboard\nhksrv.exe [1/29/2005 2:34 PM 28672]
S0 dsmghm;dsmghm;c:\windows\system32\drivers\xlmrbnhp.sys –> c:\windows\system32\drivers\xlmrbnhp.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [12/22/2009 10:03 PM 135664]
S2 srvF28;srvF28;c:\windows\system32\svchost.exe -k netsvcs [9/3/2002 1:05 PM 14336]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [12/22/2009 10:03 PM 135664]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - WUAUSERV
.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
srvF28
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 15:50]
.
2011-06-10 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2006-12-11 05:38]
.
2011-06-10 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-23 02:03]
.
2011-06-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-23 02:03]
.
2011-06-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-1343024091-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-1085031214-1343024091-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-05 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-18.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-1343024091-839522115-1003.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-09 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-1085031214-1343024091-839522115-1006.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2010-11-05 16:33]
.
2011-06-10 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-06-09 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2010-05-19 23:20]
.
2011-06-09 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2011-05-17 17:29]
.
2011-06-09 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-08-12 16:24]
.
2011-06-03 c:\windows\Tasks\WebReg officejet 6200 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2004-11-05 20:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.bing.com/?pc=Z006&form=ZGAPHP
uDefault_Search_URL = hxxp://search.msn.com
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Crawler Search
IE: RemindU - file://c:\program files\Upromise_RemindU\Sy1050\Tp1050\scri1050a.htm
TCP: DhcpNameServer = 192.168.1.1
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\6oljsjfq.Jen\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Ask.com
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://websearch.ask.com/redirect?client=ff&src=kw&tb=PSI&o=15116&locale=en_US&apn_uid=71267C36-3737-4C69-9F5B-09CA2DA85FF0&apn_ptnrs=L6&apn_sauid=21534966-0C9D-40F4-B73A-00D0006E6084&apn_dtid=&q=
FF - user.js: network.cookie.cookieBehavior - 0
FF - user.js: privacy.clearOnShutdown.cookies - false
FF - user.js: security.warn_viewing_mixed - false
FF - user.js: security.warn_viewing_mixed.show_once - false
FF - user.js: security.warn_submit_insecure - false
FF - user.js: security.warn_submit_insecure.show_once - false
.
.
——- File Associations ——-
.
.txt=
.
- - - - ORPHANS REMOVED - - - -
.
Notify-avgrsstarter - avgrsstx.dll
AddRemove-Blue's 123 Time Activities - c:\hegames\Blues123\Uninst.isu
AddRemove-Little Bear Preschool Thinking Adventures - c:\program files\Creative Wonders\Little Bear Preschool Thinking Adventures\Uninst.isu
AddRemove-Minibug - c:\progra~1\AWS\WEATHE~1\Install\MiniBug.exe
AddRemove-Mr. Potato Head's Activity Pack - c:\mrpotato\DeIsL1.isu
AddRemove-VeggieMysteryIslandDKey - c:\program files\BigIdea\The Mystery of Veggie Island\DeIsL1.isu
AddRemove-Yahoo! Anti-Spy - c:\progra~1\Yahoo!\common\unypsr.exe
AddRemove-Yahoo! Companion - c:\progra~1\Yahoo!\Common\UNYT_W~1.EXE
AddRemove-Yahoo! Messenger - c:\progra~1\Yahoo!\MESSEN~1\UNWISE.EXE
AddRemove-Yahoo! Search Defender - c:\progra~1\Yahoo!\SEARCH~1\UNINST~1.EXE
AddRemove-Yahoo! Software Update - c:\progra~1\Yahoo!\SOFTWA~1\UNINST~1.EXE
AddRemove-Yahoo! Toolbar - c:\progra~1\Yahoo!\Common\UNYT_W~1.EXE
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-10 16:27
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet006\Services\srvF28]
"servicedll"="\\?\globalroot\Device\HarddiskVolume1\WINDOWS\TEMP\srvF28.tmp"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'explorer.exe'(3976)
c:\windows\system32\WININET.dll
c:\documents and settings\Owner\Local Settings\Application Data\Plaxo\3.26.0.13\plx_hook.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\dcfssvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\drivers\KodakCCS.exe
c:\program files\Network Associates\Common Framework\FrameworkService.exe
c:\windows\System32\HPZipm12.exe
c:\program files\Google\Update\1.3.21.57\GoogleCrashHandler.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\NETWOR~1\COMMON~1\naPrdMgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Completion time: 2011-06-10 16:38:10 - machine was rebooted
ComboFix-quarantined-files.txt 2011-06-10 20:37
.
Pre-Run: 10,379,530,240 bytes free
Post-Run: 15,516,286,976 bytes free
.
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /NoExecute=OptIn
.
Current=6 Default=6 Failed=5 LastKnownGood=7 Sets=1,2,3,4,5,6,7
- - End Of File - - DF0102AB1731FC7DD9A4A98E16E27946
Hi jtt331,

I need some information on some unidentified files. We will use Virustotal Please submit these files for analysis

To submit a file to virustotal, please click VirusTotal


copy and paste the following into the upload a file box (one at a time if more than one file is listed)

c:\program files\DropBox\DropBox\DropBox .exe
c:\program files\DropBox\DropBox\DropBox.exe


scroll down a bit and click "send file", wait for the results and post them in your next reply.

Please note that sometimes the scans take a few minutes. Please ensure that the scan has completed and the results are complete before submitting the next sample. Also please make sure each result is clearly identified as to which sample they belong to.

Please post the logs created by Virus Total into your next reply. :)
Here is the log from Virustotal. File name: DropBox .exe Submission date: 2011-06-12 15:08:17 (UTC) Current status: finished Result: 0/ 42 (0.0%) VT Community not reviewed Safety score: - Compact Print results Antivirus Version Last Update Result AhnLab-V3 2011.06.12.02 2011.06.12 - AntiVir 7.11.9.159 2011.06.11 - Antiy-AVL 2.0.3.7 2011.06.12 - Avast 4.8.1351.0 2011.06.12 - Avast5 5.0.677.0 2011.06.12 - AVG 10.0.0.1190 2011.06.12 - BitDefender 7.2 2011.06.12 - CAT-QuickHeal 11.00 2011.06.12 - ClamAV 0.97.0.0 2011.06.12 - Commtouch 5.3.2.6 2011.06.11 - Comodo 9042 2011.06.12 - DrWeb 5.0.2.03300 2011.06.12 - Emsisoft 5.1.0.8 2011.06.12 - eSafe 7.0.17.0 2011.06.09 - eTrust-Vet 36.1.8380 2011.06.10 - F-Prot 4.6.2.117 2011.06.11 - Fortinet 4.2.257.0 2011.06.11 - GData 22 2011.06.12 - Ikarus T3.1.1.104.0 2011.06.12 - Jiangmin 13.0.900 2011.06.12 - K7AntiVirus 9.106.4798 2011.06.10 - Kaspersky 9.0.0.837 2011.06.12 - McAfee 5.400.0.1158 2011.06.12 - McAfee-GW-Edition 2010.1D 2011.06.12 - Microsoft 1.6903 2011.06.12 - NOD32 6200 2011.06.12 - Norman 6.07.10 2011.06.12 - nProtect 2011-06-12.01 2011.06.12 - Panda 10.0.3.5 2011.06.12 - PCTools 7.0.3.5 2011.06.10 - Prevx 3.0 2011.06.12 - Rising 23.61.04.07 2011.06.10 - Sophos 4.66.0 2011.06.12 - SUPERAntiSpyware 4.40.0.1006 2011.06.11 - Symantec 20111.1.0.186 2011.06.12 - TheHacker 6.7.0.1.228 2011.06.11 - TrendMicro 9.200.0.1012 2011.06.12 - TrendMicro-HouseCall 9.200.0.1012 2011.06.12 - VBA32 3.12.16.1 2011.06.10 - VIPRE 9561 2011.06.12 - ViRobot 2011.6.11.4507 2011.06.12 - VirusBuster 14.0.76.0 2011.06.11 - Additional information MD5 : 30d3aeee9a127c6051cc65d12183fb8e SHA1 : e00780ed617abf82bcf6cec43946e6fcf51ca8b0 SHA256: c78611e923688f732e34fc2c520725ecb776be91214cd66333d27f0f89f3f91f ssdeep: 6144:i5LtTAdwLnxtfPfkPr/uBnLhnC1XB21tnNvL09/lWaq61:x6LnLOr6nC1XB2NL0L File size : 253952 bytes First seen: 2011-06-12 15:08:17 Last seen : 2011-06-12 15:08:17 TrID: Win32 Executable MS Visual C++ (generic) (53.1%) Windows Screen Saver (18.4%) Win32 Executable Generic (12.0%) Win32 Dynamic Link Library (generic) (10.6%) Generic Win/DOS Executable (2.8%) sigcheck: publisher….: DropShots copyright….: Copyright © 2005 product……: DropBox description..: DropBox Desktop Client original name: DropBox.EXE internal name: DropBox file version.: 5, 7, 0, 0 comments…..: n/a signers……: - signing date.: - verified…..: Unsigned PEInfo: PE structure information [[ basic data ]] entrypointaddress: 0x239F6 timedatestamp….: 0x46C3EB07 (Thu Aug 16 06:13:27 2007) machinetype……: 0x14c (I386) [[ 4 section(s) ]] name, viradd, virsiz, rawdsiz, ntropy, md5 .text, 0x1000, 0x24FC0, 0x25000, 6.11, b6134cc80f6253245656a1333317702f .rdata, 0x26000, 0xE2EA, 0xF000, 5.30, 4c34475aba5fbff8a99210d0b7242bfe .data, 0x35000, 0x20E4, 0x1000, 1.63, 8221b2a38bf2f6b34fbdb10a0a7b68af .rsrc, 0x38000, 0x7408, 0x8000, 5.63, a46db5fd37d8c117e7aa20c6936f6a67 [[ 18 import(s) ]] WINMM.dll: PlaySoundA gdiplus.dll: GdipCreateBitmapFromFile, GdipGetPropertyItemSize, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromScan0, GdipGetImageEncodersSize, GdipGetImageEncoders, GdipGetImageHeight, GdipGetImageWidth, GdipSaveImageToFile, GdipCloneImage, GdipDisposeImage, GdipLoadImageFromFileICM, GdipLoadImageFromFile, GdipAlloc, GdipFree, GdipDrawImageRectRectI, GdipDrawImageRectI, GdipSetInterpolationMode, GdipDeleteGraphics, GdipCreateFromHDC, GdiplusShutdown, GdiplusStartup, GdipGetPropertyItem, GdipGetImageGraphicsContext VERSION.dll: GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA MSVCR70.dll: __setusermatherr, _initterm, __getmainargs, _amsg_exit, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit, _onexit, __dllonexit, __1type_info@@UAE@XZ, floor, _mbschr, _mbslwr, isdigit, fprintf, ceil, atol, fopen, fclose, abs, _except_handler3, _mbscmp, _mbspbrk, _mbsicoll, _ismbcspace, _mbsinc, sscanf, _mktime64, _localtime64, _time64, atoi, _mbsicmp, memset, __p___argc, __p___argv, _mbsrchr, _adjust_fdiv, ___U@YAPAXI@Z, ___V@YAXPAX@Z, wcscmp, strtoul, strcmp, _strnicmp, strncpy, calloc, __2@YAPAXI@Z, sprintf, strcat, _CxxThrowException, __0exception@@QAE@ABV0@@Z, vsprintf, _vscprintf, memmove, memcpy, _mbsupr, _stat, __1exception@@UAE@XZ, __3@YAXPAX@Z, __0exception@@QAE@XZ, _vsnwprintf, _vsnprintf, wcscpy, __CxxFrameHandler, malloc, free, wcslen, strlen, _setmbcp, _stricmp, __p__commode, __p__fmode, __set_app_type, _terminate@@YAXXZ, _mbsstr, _controlfp, strcpy MFC70.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, - KERNEL32.dll: QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, GetVersionExA, GetStartupInfoA, InterlockedDecrement, InterlockedIncrement, GetProcAddress, GetLocalTime, OutputDebugStringA, GetSystemDirectoryA, CopyFileA, TerminateProcess, DeleteFileA, lstrcpyA, lstrcatA, WinExec, LocalFree, WaitForMultipleObjects, PeekNamedPipe, CreateProcessA, TerminateThread, CreatePipe, GetCurrentProcess, DuplicateHandle, CreateThread, SetLastError, GetTempPathA, Sleep, GetModuleFileNameA, ResetEvent, GetTickCount, GetCurrentThreadId, SetEvent, CancelWaitableTimer, CreateEventA, CreateWaitableTimerA, GetSystemTime, SetWaitableTimer, SystemTimeToFileTime, CreateMutexA, OpenProcess, WaitForSingleObject, IsDBCSLeadByteEx, ReadFile, SetFilePointer, GetFileSize, CreateFileA, CloseHandle, LoadResource, LockResource, SizeofResource, FindResourceA, lstrlenA, lstrcmpiA, MultiByteToWideChar, GetThreadLocale, GetLocaleInfoA, GetACP, WideCharToMultiByte, GetModuleHandleA, GetLastError, InterlockedExchange USER32.dll: FillRect, SetWindowLongA, GetSysColor, GetDC, ScreenToClient, LoadMenuA, GetMenuItemID, DeleteMenu, DrawIcon, SubtractRect, PtInRect, GetMenu, GetMenuItemCount, GetSubMenu, GetCursorPos, SetMenuDefaultItem, SetWindowsHookExA, TrackPopupMenuEx, GetClassNameA, CallNextHookEx, UnhookWindowsHookEx, LoadIconA, SetForegroundWindow, GetLastActivePopup, IsIconic, PostMessageA, GetWindowThreadProcessId, GetWindowDC, ReleaseDC, SetWindowRgn, GetDlgItem, SetWindowPos, LoadImageA, CopyImage, FindWindowA, SetTimer, GetSystemMetrics, GetClassInfoA, GetParent, InvalidateRect, UpdateWindow, ClientToScreen, GetClientRect, GetWindowRect, SetCursor, LoadCursorA, SendMessageA, EnableWindow, KillTimer GDI32.dll: CreateFontIndirectA, BitBlt, CreateCompatibleDC, GetObjectA, DeleteObject, Rectangle, CreateSolidBrush, CreatePen, CreateCompatibleBitmap, GetStockObject, GetDIBits, CombineRgn, GetRgnBox, CreateRectRgn, SelectObject, DeleteDC MSIMG32.dll: AlphaBlend ADVAPI32.dll: RegSetValueExA, RegOpenKeyExA, RegQueryValueExA, RegDeleteValueA, RegCreateKeyExA, RegQueryValueA, RegCloseKey SHELL32.dll: DragQueryFileA, DragAcceptFiles, Shell_NotifyIconA, SHAppBarMessage, ShellExecuteA, DragFinish COMCTL32.dll: _TrackMouseEvent SHLWAPI.dll: PathFindExtensionA ole32.dll: OleInitialize, OleUninitialize, OleRun, CoInitialize, CoUninitialize, CoInitializeEx, CoTaskMemFree, CoCreateGuid, CoCreateInstance OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, - urlmon.dll: URLDownloadToFileA, FindMimeFromData MSVCP70.dll: _c_str@_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QBEPBDXZ, __0_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@ABV01@@Z, __1_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@XZ, __0_$basic_string@DU_$char_traits@D@std@@V_$allocator@D@2@@std@@QAE@PBD@Z WININET.dll: InternetCanonicalizeUrlA, InternetReadFile, InternetOpenUrlA, InternetSetOptionA, HttpEndRequestA, InternetWriteFile, HttpSendRequestExA, HttpAddRequestHeadersA, HttpOpenRequestA, InternetConnectA, InternetCloseHandle, InternetOpenA, InternetCheckConnectionA, InternetGetCookieA ExifTool: file metadata CharacterSet: Unicode CodeSize: 151552 CompanyName: DropShots EntryPoint: 0x239f6 FileDescription: DropBox Desktop Client FileFlagsMask: 0x003f FileOS: Win32 FileSize: 248 kB FileSubtype: 0 FileType: Win32 EXE FileVersion: 5, 7, 0, 0 FileVersionNumber: 5.7.0.0 ImageVersion: 0.0 InitializedDataSize: 106496 InternalName: DropBox LanguageCode: English (U.S.) LegalCopyright: Copyright © 2005 LinkerVersion: 7.0 MIMEType: application/octet-stream MachineType: Intel 386 or later, and compatibles OSVersion: 4.0 ObjectFileType: Executable application OriginalFilename: DropBox.EXE PEType: PE32 ProductName: DropBox ProductVersion: 5, 7, 0, 0 ProductVersionNumber: 5.7.0.0 Subsystem: Windows GUI SubsystemVersion: 4.0 TimeStamp: 2007:08:16 08:13:27+02:00 UninitializedDataSize: 0
Hi jtt331,

Thank you for running the file c:\program files\DropBox\DropBox\DropBox .exe but I do not see where you ran c:\program files\DropBox\DropBox\DropBox.exe? If you notice in the first file you ran there is a space between Dropbox and .exe but in the second file there is no space. I need that file submitted to VirusTotal as well. :)
Hi Jeff. I can't seem to find the other file. If I go to c:\program files\DropBox\DropBox there is only one dropbox file in there and it is the one with the space. There are no other files to choose from. And if I type the file into virustotal it says file not found. Not sure what I am missing. Can you advise? Thanks!!
Hi jtt331,

Please do the following:

Click start > run, type cmd and click ok.

In the command box copy and paste the following and hit enter

ren "c:\program files\DropBox\DropBox\DropBox. exe" DropBox.exe

———-

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

DDS::
BHO: PhotoPos Pro Toolbar: {a057a204-bacc-4d26-9f9d-3befcfbe6e86} - c:\progra~1\photop~3\PHOTOP~1.DLL
TB: PhotoPos Pro Toolbar: {a057a204-bacc-4d26-9f9d-3befcfbe6e86} - c:\progra~1\photop~3\PHOTOP~1.DLL
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} -
TB: &Crawler lišta: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} -
TB: Morpheus Toolbar: {3f3714a9-89a4-46be-8af3-d0c9d1fb03f9} -
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} -
TB: {9D425283-D487-4337-BAB6-AB8354A81457} - No File
TB: ShopAtHome.com Toolbar: {98279c38-de4b-4bcf-93c9-8ec26069d6f4} -
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
mRun: [SelectRebates] c:\program files\selectrebates\SelectRebates.exe
IE: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-us\local\search.html
IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922}
uRun: [Performance Center] c:\program files\ascentive\performance center\ApcMain.exe -m

Driver::
srvF28
dsmghm

NetSvc::
srvF28


Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI