This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Searchqu.com/406 hijacking Firefox

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I confess it, I did download iLiVid video software and have been cursed with the searchqu.com browser hijack ever since. Some other curious symptoms, over the same 2-week period: - MalwareBytes AntiMalware has been unable to run its updating protocol; - My Thunderbird Profiles directory is not editable - Clicking on Google/NortonSafe search results gets hijacked to various vendor sites rather than the requested search result. I spent about 20 days (part time!) working with the AntiMalware tech support to try to fix these two issues. Eventually we agreed to close the ticket and I should re-install Windows. I meanwhile read that whatthetech is more familiar with the searchqu.com infection, and I see you are using some different tools than the MBAM tech. So if it's all right I would like to try your tech support in hopes to avoid scrubbing the machine and re-installing all my apps. OK? here is the DDS.txt log contents: . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 8.0.6001.18702 Run by [removed] at 19:43:34 on 2011-10-28 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.289 [GMT -4:00] . AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8} FW: Norton 360 *Disabled* . ============== Running Processes =============== . C:\WINDOWS\system32\svchost.exe -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\SUPERAntiSpyware\SASCORE.EXE C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\PROGRA~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\PKWARE\PKZIPM\9.00.0010\PKTray.exe C:\Documents and Settings\User\Application Data\Dropbox\bin\Dropbox.exe C:\Program Files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe C:\Program Files\Mozilla Firefox\plugin-container.exe C:\WINDOWS\system32\wscntfy.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://www.yahoo.com/ BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\5.1.0.29\ips\IPSBHO.DLL BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\5.1.0.29\coIEPlg.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [CTSyncU.exe] "c:\program files\creative\sync manager unicode\CTSyncU.exe" uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [DiskeeperSystray] "c:\program files\diskeeper corporation\diskeeper\DkIcon.exe" mRun: [nwiz] nwiz.exe /install mRun: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe mRun: [ControlCenter3] c:\program files\brother\controlcenter3\brctrcen.exe /autorun mRun: [BrStsMon00] c:\program files\browny02\brother\BrStMonW.exe /AUTORUN mRun: [Acrobat Assistant 8.0] "c:\program files\adobe\acrobat 8.0\acrobat\Acrotray.exe" mRun: [DATAMNGR] c:\progra~1\search~1\search~1\DATAMN~1.EXE mRun: [Malwarebytes' Anti-Malware] "c:\program files\malwarebytes' anti-malware\mbamgui.exe" /starttray StartupFolder: c:\docume~1\user\startm~1\programs\startup\dropbox.lnk - c:\documents and settings\user\application data\dropbox\bin\Dropbox.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pkzipa~1.lnk - c:\program files\pkware\pkzipm\9.00.0010\PKTray.exe IE: Append to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~2\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} - hxxp://acs.pandasoftware.com/activescan/cabs/as2stubie.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} - hxxp://driveragent.com/files/driveragent.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{62B01DCB-0F6D-4468-98F0-E1C04CEDAE56} : DhcpNameServer = 192.168.1.1 Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\3p0gzzlb.default\ FF - prefs.js: keyword.URL - hxxp://www.hpmirror.com FF - plugin: c:\program files\microsoft silverlight\4.0.60831.0\npctrlui.dll . ============= SERVICES / DRIVERS =============== . R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2011-10-18 28552] R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0501000.01d\SymDS.sys [2011-6-9 340088] R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0501000.01d\SymEFA.sys [2011-6-9 744568] R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\bashdefs\20111014.001\BHDrvx86.sys [2011-10-14 818808] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664] R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-10-19 98392] R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0501000.01d\Ironx86.sys [2011-6-9 136312] R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608] R2 MBAMService;MBAMService;c:\program files\malwarebytes' anti-malware\mbamservice.exe [2011-10-15 366152] R2 N360;Norton 360;c:\program files\norton 360\engine\5.1.0.29\ccSvcHst.exe [2011-6-9 130008] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2011-10-22 105592] R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\ipsdefs\20111026.030\IDSXpx86.sys [2011-10-26 356280] R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-10-15 22216] R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\virusdefs\20111028.002\NAVENG.SYS [2011-10-28 86136] R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_5.1.0.29\definitions\virusdefs\20111028.002\NAVEX15.SYS [2011-10-28 1576312] S1 ShldDrv;Panda File Shield Driver;c:\windows\system32\drivers\shldrv51.sys –> c:\windows\system32\drivers\ShlDrv51.sys [?] S2 PavProc;Panda Process Protection Driver;\??\c:\windows\system32\drivers\pavproc.sys –> c:\windows\system32\drivers\PavProc.sys [?] S2 PavPrSrv;Panda Process Protection Service;"c:\program files\common files\panda software\pavshld\pavprsrv.exe" –> c:\program files\common files\panda software\pavshld\pavprsrv.exe [?] S3 2812992B;2812992B;c:\windows\system32\2812992b.exe –> c:\windows\system32\2812992B.exe [?] S3 71418283;71418283;c:\windows\system32\71418283.exe –> c:\windows\system32\71418283.exe [?] S3 84563EAA;84563EAA;c:\windows\system32\84563eaa.exe –> c:\windows\system32\84563EAA.exe [?] S3 BrYNSvc;BrYNSvc;c:\program files\browny02\BrYNSvc.exe [2011-6-29 245760] S3 Com4QLBEx;Com4QLBEx;c:\program files\hewlett-packard\hp quick launch buttons\Com4QLBEx.exe [2011-6-1 227896] S3 DrvAgent32;DrvAgent32;\??\c:\windows\system32\drivers\drvagent32.sys –> c:\windows\system32\drivers\DrvAgent32.sys [?] S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [2011-6-1 588032] UnknownUnknown BlackBox;BlackBox; [x] . =============== Created Last 30 ================ . 2011-10-20 03:15:39 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys 2011-10-20 03:15:39 27984 —-a-w- c:\windows\system32\sbbd.exe 2011-10-18 12:34:36 28552 —-a-w- c:\windows\system32\drivers\pavboot.sys 2011-10-18 12:34:16 ——– d—–w- c:\program files\Panda Security 2011-10-18 12:00:22 ——– d—–w- c:\program files\MozBackup 2011-10-18 02:33:27 753664 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iKernel.dll 2011-10-18 02:33:27 69714 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\ctor.dll 2011-10-18 02:33:27 5632 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\DotNetInstaller.exe 2011-10-18 02:33:27 274432 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iscript.dll 2011-10-18 02:33:27 184320 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iuser.dll 2011-10-18 02:33:25 331908 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\setup.dll 2011-10-18 02:33:25 200836 —-a-w- c:\program files\common files\installshield\professional\runtime\11\00\intel32\iGdi.dll 2011-10-16 16:23:37 ——– d—–w- c:\program files\ESET 2011-10-16 02:17:35 ——– d—–w- c:\documents and settings\user\application data\Malwarebytes 2011-10-16 02:17:27 ——– d—–w- c:\documents and settings\all users\application data\Malwarebytes 2011-10-16 02:17:24 22216 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-10-16 02:17:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2011-10-14 19:03:24 ——– d-sha-r- C:\cmdcons 2011-10-14 19:01:28 518144 —-a-w- c:\windows\SWREG.exe 2011-10-14 19:01:28 256000 —-a-w- c:\windows\PEV.exe 2011-10-14 19:01:28 208896 —-a-w- c:\windows\MBR.exe 2011-10-14 19:01:27 98816 —-a-w- c:\windows\sed.exe 2011-10-13 07:07:45 ——– d—–w- C:\fa473302f039f3817773a7 2011-10-12 18:35:05 ——– d—–w- c:\documents and settings\user\local settings\application data\WMTools Downloaded Files 2011-10-05 02:30:19 ——– d—–w- c:\documents and settings\user\application data\SUPERAntiSpyware.com 2011-10-05 02:29:08 ——– d—–w- c:\program files\SUPERAntiSpyware 2011-10-05 02:29:08 ——– d—–w- c:\documents and settings\all users\application data\SUPERAntiSpyware.com . ==================== Find3M ==================== . 2011-09-26 15:41:20 611328 —-a-w- c:\windows\system32\uiautomationcore.dll 2011-09-26 15:41:20 220160 —-a-w- c:\windows\system32\oleacc.dll 2011-09-26 15:41:14 20480 —-a-w- c:\windows\system32\oleaccrc.dll 2011-09-24 15:28:00 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2011-09-09 09:12:13 599040 —-a-w- c:\windows\system32\crypt32.dll 2011-09-06 13:20:51 1858944 —-a-w- c:\windows\system32\win32k.sys 2011-08-22 23:48:55 916480 —-a-w- c:\windows\system32\wininet.dll 2011-08-22 23:48:54 43520 ——w- c:\windows\system32\licmgr10.dll 2011-08-22 23:48:54 1469440 ——w- c:\windows\system32\inetcpl.cpl 2011-08-22 11:56:39 385024 ——w- c:\windows\system32\html.iec 2011-08-17 13:49:54 138496 —-a-w- c:\windows\system32\drivers\afd.sys . ============= FINISH: 19:44:17.75 ===============
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.


Having said that….Let's get going!! :thumbup:
———-
Hi,

I see that you have run ComboFix on your system already? Do you happen to still have the log from the last time it was ran? It could be found at C:\ComboFix.txt. If you still have it could you post that into your next reply please? :)
—————–

GMER

Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
.
———-

In your next reply please post the ComboFix log (if you have it) and the log created by GMER.
Thank you Jeff!
Let me summarize the steps taken over the last couple of weeks:
DDS
Trace_route
ComboFix
TDSS Killer
ESET Online Scan
VipreRecovery
Dr.Web Cure-It CD
GMER
I saved the logs from pretty much all of these. Some found things & fixed them; others did not but the hijacking continues.

Here is my ComboFix log: Should I send the old GMER document, or re-execute that?

ComboFix 11-10-14.03 - User 10/14/2011 15:04:48.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.991.341 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton 360 *Disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\User\Recent\xyzsoftware.url
c:\windows\system32\d3d9caps.dat
.
.
((((((((((((((((((((((((( Files Created from 2011-09-14 to 2011-10-14 )))))))))))))))))))))))))))))))
.
.
2011-10-14 15:26 . 2011-10-14 15:26 ——– d—–w- c:\documents and settings\Administrator
2011-10-13 07:07 . 2011-10-13 07:07 ——– d—–w- C:\fa473302f039f3817773a7
2011-10-12 18:35 . 2011-10-12 18:35 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\WMTools Downloaded Files
2011-10-05 02:30 . 2011-10-05 02:30 ——– d—–w- c:\documents and settings\User\Application Data\SUPERAntiSpyware.com
2011-10-05 02:29 . 2011-10-05 02:30 ——– d—–w- c:\program files\SUPERAntiSpyware
2011-10-05 02:29 . 2011-10-05 02:29 ——– d—–w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2011-10-04 17:24 . 2011-10-04 17:24 ——– d—–w- c:\documents and settings\User\Application Data\Malwarebytes
2011-10-04 17:22 . 2011-10-04 17:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-10-04 17:22 . 2011-10-04 17:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-10-04 17:22 . 2011-08-31 21:00 22216 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-09-27 20:11 . 2011-09-27 20:11 ——– d—–w- c:\documents and settings\User\AppData
2011-09-27 15:43 . 2011-09-27 15:43 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\Ilivid Player
2011-09-27 15:41 . 2011-09-27 15:41 ——– d—–w- c:\program files\SearchCore for Browsers
2011-09-27 15:40 . 2011-09-27 15:40 ——– d—–w- c:\documents and settings\User\Local Settings\Application Data\PackageAware
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-26 15:41 . 2008-07-29 23:59 611328 —-a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2006-02-28 12:00 220160 —-a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2006-02-28 12:00 20480 —-a-w- c:\windows\system32\oleaccrc.dll
2011-09-24 15:28 . 2011-06-01 20:46 404640 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-09 09:12 . 2006-02-28 12:00 599040 —-a-w- c:\windows\system32\crypt32.dll
2011-09-06 13:20 . 2006-02-28 12:00 1858944 —-a-w- c:\windows\system32\win32k.sys
2011-08-22 23:48 . 2006-02-28 12:00 916480 —-a-w- c:\windows\system32\wininet.dll
2011-08-22 23:48 . 2006-02-28 12:00 43520 ——w- c:\windows\system32\licmgr10.dll
2011-08-22 23:48 . 2006-02-28 12:00 1469440 ——w- c:\windows\system32\inetcpl.cpl
2011-08-22 11:56 . 2006-02-28 12:00 385024 ——w- c:\windows\system32\html.iec
2011-08-17 13:49 . 2006-02-28 12:00 138496 —-a-w- c:\windows\system32\drivers\afd.sys
2011-10-05 15:53 . 2011-08-19 21:41 134104 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\User\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\User\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\User\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12 94208 —-a-w- c:\documents and settings\User\Application Data\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 700416]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-09-14 4611456]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-21 7581696]
"DiskeeperSystray"="c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2005-11-22 221184]
"nwiz"="nwiz.exe" [2006-07-21 1519616]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2011-03-31 2221352]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-11 624248]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 449608]
.
c:\documents and settings\User\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\User\Application Data\Dropbox\bin\Dropbox.exe [2011-9-1 24183152]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
PKZIP Attachments Status.lnk - c:\program files\PKWARE\PKZIPM\9.00.0010\PKTray.exe [2011-9-5 169552]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2011-05-04 17:54 551296 —-a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 09:42 15360 —-a-w- c:\windows\system32\ctfmon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
2005-11-22 21:38 221184 —-a-w- c:\program files\Diskeeper Corporation\Diskeeper\DkIcon.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
2006-07-27 18:44 61952 —-a-w- c:\windows\system32\CHDAudPropShortcut.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-07-21 00:58 7581696 —-a-w- c:\windows\system32\nvcpl.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-07-21 00:58 86016 —-a-w- c:\windows\system32\nvmctray.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-07-21 00:58 1519616 —-a-w- c:\windows\system32\nwiz.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl.exe]
2010-02-25 19:19 323640 —-a-w- c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-10-31 23:42 32768 —-a-w- c:\program files\PowerDVD\PDVDServ.exe
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\User\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"54925:UDP"= 54925:UDP:BrotherNetwork Scanner
.
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0501000.01D\SymDS.sys [6/9/2011 11:41 AM 340088]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0501000.01D\SymEFA.sys [6/9/2011 11:41 AM 744568]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110929.001\BHDrvx86.sys [9/29/2011 5:35 PM 816760]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 12:27 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 5:55 PM 67664]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0501000.01D\Ironx86.sys [6/9/2011 11:41 AM 136312]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 7:38 PM 116608]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [10/4/2011 1:22 PM 366152]
R2 N360;Norton 360;c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe [6/9/2011 11:41 AM 130008]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [7/29/2011 10:27 AM 105592]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20111013.030\IDSXpx86.sys [10/13/2011 8:39 PM 356280]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [10/4/2011 1:22 PM 22216]
S3 BrYNSvc;BrYNSvc;c:\program files\Browny02\BrYNSvc.exe [6/29/2011 10:24 AM 245760]
S3 Com4QLBEx;Com4QLBEx;c:\program files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [6/1/2011 4:31 PM 227896]
S3 DrvAgent32;DrvAgent32;\??\c:\windows\system32\Drivers\DrvAgent32.sys –> c:\windows\system32\Drivers\DrvAgent32.sys [?]
S3 MBAMSwissArmy;MBAMSwissArmy;\??\c:\windows\system32\drivers\mbamswissarmy.sys –> c:\windows\system32\drivers\mbamswissarmy.sys [?]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\drivers\RTL8192su.sys [6/1/2011 4:03 PM 588032]
.
Contents of the 'Scheduled Tasks' folder
.
2011-10-12 c:\windows\Tasks\prismSevenDays.job
- c:\program files\NCH Software\Prism\prism.exe [2011-10-12 19:00]
.
2011-10-12 c:\windows\Tasks\prismShakeIcon.job
- c:\program files\NCH Software\Prism\prism.exe [2011-10-12 19:00]
.
2011-09-23 c:\windows\Tasks\wavepadShakeIcon.job
- c:\program files\NCH Software\WavePad\wavepad.exe [2011-09-11 02:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.yahoo.com/
IE: Append to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\User\Application Data\Mozilla\Firefox\Profiles\3p0gzzlb.default\
FF - prefs.js: browser.search.selectedEngine - Norton Safe Search
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-10 - (no file)
Notify-NavLogon - (no file)
MSConfigStartUp-Adobe ARM - c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-10-14 15:13
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
Windows 5.1.2600
.
CreateFile("\\.\PHYSICALDRIVE0"): The process cannot access the file because it is being used by another process.
device: opened successfully
user: error reading MBR
kernel: MBR read successfully
user != kernel MBR !!!
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\5.1.0.29\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\5.1.0.29\diMaster.dll\" /prefetch:1"
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'winlogon.exe'(864)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
.
- - - - - - - > 'explorer.exe'(3244)
c:\windows\system32\WININET.dll
c:\windows\system32\nview.dll
c:\documents and settings\User\Application Data\Dropbox\bin\DropboxExt.14.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
———————— Other Running Processes ————————
.
c:\program files\Diskeeper Corporation\Diskeeper\DkService.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\progra~1\SEARCH~1\SEARCH~1\DATAMN~1.EXE
c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Completion time: 2011-10-14 15:19:43 - machine was rebooted
ComboFix-quarantined-files.txt 2011-10-14 19:19
.
Pre-Run: 125,087,514,624 bytes free
Post-Run: 125,200,654,336 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
.
- - End Of File - - DEFA2A1124B39EBB0C49529B789430CF
Hi yolozone,

After you get GMER ran and the log posted please do the following:

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
This is the GMER log (from Tuesday this week). Let me know if I misunderstood & should run it fresh.




GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-10-25 20:20:23
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\00000078 WDC_WD1600BEVS-00RST0 rev.04.01G04
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\kxddyfod.sys


—- System - GMER 1.0.15 —-

SSDT 864F7A58 ZwAlertResumeThread
SSDT 864F8198 ZwAlertThread
SSDT 864F71B0 ZwAllocateVirtualMemory
SSDT 864DE6A0 ZwAssignProcessToJobObject
SSDT 86655B30 ZwConnectPort
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwCreateKey [0xECDA5710]
SSDT 8647D168 ZwCreateMutant
SSDT 86429160 ZwCreateSymbolicLinkObject
SSDT 865754D0 ZwCreateThread
SSDT 864E0790 ZwDebugActiveProcess
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteKey [0xECDA5990]
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xECDA5EF0]
SSDT 8652EB58 ZwDuplicateObject
SSDT 864C9580 ZwFreeVirtualMemory
SSDT 864F3318 ZwImpersonateAnonymousToken
SSDT 864F7980 ZwImpersonateThread
SSDT 8662FA68 ZwLoadDriver
SSDT 85F8C7F0 ZwMapViewOfSection
SSDT 864F21D0 ZwOpenEvent
SSDT 8654D008 ZwOpenProcess
SSDT 8651E3F0 ZwOpenProcessToken
SSDT 864EC208 ZwOpenSection
SSDT 86547498 ZwOpenThread
SSDT 863BA118 ZwProtectVirtualMemory
SSDT 864F8270 ZwResumeThread
SSDT 8600B718 ZwSetContextThread
SSDT 86709A88 ZwSetInformationProcess
SSDT 864E3178 ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xECDA6140]
SSDT 864EC540 ZwSuspendProcess
SSDT 864F9FD0 ZwSuspendThread
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xECCAE640]
SSDT 86504CE8 ZwTerminateThread
SSDT 8650ABC8 ZwUnmapViewOfSection
SSDT 864D9200 ZwWriteVirtualMemory

—- Kernel code sections - GMER 1.0.15 —-

? SYMDS.SYS The system cannot find the file specified. !
? SYMEFA.SYS The system cannot find the file specified. !
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6152360, 0x2255BD, 0xE8000020]

—- Devices - GMER 1.0.15 —-

Device Ntfs.sys (NT File System Driver/Microsoft Corporation)

AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 Wdf01000.sys (Kernel Mode Driver Framework Runtime/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)

Device mrxsmb.sys (Windows NT SMB Minirdr/Microsoft Corporation)
Device Cdfs.SYS (CD-ROM File System Driver/Microsoft Corporation)

—- EOF - GMER 1.0.15 —-
. . . . . and here is the log file from ASWmbr . . . . . thanks again Jeff aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-28 21:06:21 —————————– 21:06:21.437 OS Version: Windows 5.1.2600 Service Pack 3 21:06:21.437 Number of processors: 2 586 0x4802 21:06:21.437 ComputerName: LPTP-44A16EDC57 UserName: User 21:06:30.031 Initialize success 21:09:50.687 AVAST engine defs: 11102802 21:15:59.359 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000079 21:15:59.359 Disk 0 Vendor: WDC_WD1600BEVS-00RST0 04.01G04 Size: 152627MB BusType: 3 21:15:59.421 Disk 0 MBR read successfully 21:15:59.421 Disk 0 MBR scan 21:15:59.500 Disk 0 Windows XP default MBR code 21:15:59.515 Disk 0 scanning sectors +312560640 21:15:59.593 Disk 0 scanning C:\WINDOWS\system32\drivers 21:16:16.578 Service scanning 21:16:18.984 Modules scanning 21:16:27.359 Disk 0 trace - called modules: 21:16:27.375 21:16:27.703 AVAST engine scan C:\WINDOWS 21:16:37.546 AVAST engine scan C:\WINDOWS\system32 21:18:37.390 AVAST engine scan C:\WINDOWS\system32\drivers 21:18:53.125 AVAST engine scan C:\Documents and Settings\User 21:30:15.156 AVAST engine scan C:\Documents and Settings\All Users 21:32:05.750 Scan finished successfully 21:34:29.062 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\User\Desktop\MBR.dat" 21:34:29.093 The log file has been saved successfully to "C:\Documents and Settings\User\Desktop\185503-aswMBR.txt"
Hi yolozone,

Please go ahead and delete the ComboFix icon from your desktop using right-click > delete. Once you have done that please download a fresh copy of ComboFix from either
Link 1 or
Link 2.
—————-

When you ran DDS there should have been a log named Attach.txt. If you still have that could you post that as well? Thanks. :)
ATTACH.txt file: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 5/31/2011 7:07:06 PM System Uptime: 10/25/2011 11:36:14 PM (68 hours ago) . Motherboard: Quanta | | 30B7 Processor: AMD Turion™ 64 X2 Mobile Technology TL-50 | Socket S1 | 1607/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 149 GiB total, 111.433 GiB free. D: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP77: 8/5/2011 11:45:07 AM - System Checkpoint RP78: 8/6/2011 12:29:39 PM - System Checkpoint RP79: 8/9/2011 6:20:36 PM - System Checkpoint RP80: 8/10/2011 6:20:51 PM - System Checkpoint RP81: 8/11/2011 3:00:16 AM - Software Distribution Service 3.0 RP82: 8/12/2011 3:30:25 AM - System Checkpoint RP83: 8/13/2011 4:30:28 AM - System Checkpoint RP84: 8/14/2011 1:47:07 PM - System Checkpoint RP85: 8/15/2011 3:23:42 PM - System Checkpoint RP86: 8/16/2011 4:48:59 PM - System Checkpoint RP87: 8/17/2011 5:39:25 PM - System Checkpoint RP88: 8/18/2011 6:02:37 PM - System Checkpoint RP89: 8/19/2011 7:20:58 PM - System Checkpoint RP90: 8/20/2011 7:38:18 PM - System Checkpoint RP91: 8/21/2011 8:06:42 PM - System Checkpoint RP92: 8/22/2011 10:27:03 PM - System Checkpoint RP93: 8/24/2011 12:28:49 AM - System Checkpoint RP94: 8/24/2011 3:00:14 AM - Software Distribution Service 3.0 RP95: 8/25/2011 3:21:03 AM - System Checkpoint RP96: 8/26/2011 3:38:45 AM - System Checkpoint RP97: 8/27/2011 4:07:34 AM - System Checkpoint RP98: 8/28/2011 8:16:52 PM - System Checkpoint RP99: 8/29/2011 8:53:40 PM - System Checkpoint RP100: 8/30/2011 11:21:40 PM - System Checkpoint RP101: 8/31/2011 11:34:58 PM - Removed Nero 9 4.4.9.0 RP102: 9/1/2011 11:36:57 PM - System Checkpoint RP103: 9/3/2011 12:24:32 AM - System Checkpoint RP104: 9/4/2011 12:46:20 AM - System Checkpoint RP105: 9/5/2011 12:58:09 AM - System Checkpoint RP106: 9/5/2011 8:38:39 PM - Installed PKZIP for Windows 9.00.0010 RP107: 9/6/2011 10:26:06 PM - System Checkpoint RP108: 9/7/2011 3:00:15 AM - Software Distribution Service 3.0 RP109: 9/8/2011 3:56:19 AM - System Checkpoint RP110: 9/9/2011 4:56:19 AM - System Checkpoint RP111: 9/10/2011 5:56:19 AM - System Checkpoint RP112: 9/11/2011 6:56:17 AM - System Checkpoint RP113: 9/12/2011 7:56:18 AM - System Checkpoint RP114: 9/13/2011 7:57:33 AM - System Checkpoint RP115: 9/14/2011 9:02:12 AM - System Checkpoint RP116: 9/15/2011 3:00:46 AM - Software Distribution Service 3.0 RP117: 9/16/2011 3:26:28 AM - System Checkpoint RP118: 9/17/2011 10:27:39 AM - System Checkpoint RP119: 9/18/2011 4:29:32 PM - System Checkpoint RP120: 9/19/2011 6:45:08 PM - System Checkpoint RP121: 9/20/2011 7:13:24 PM - System Checkpoint RP122: 9/21/2011 8:13:26 PM - System Checkpoint RP123: 9/22/2011 8:35:08 PM - System Checkpoint RP124: 9/23/2011 9:32:16 PM - System Checkpoint RP125: 9/24/2011 9:51:47 PM - System Checkpoint RP126: 9/25/2011 10:20:42 PM - System Checkpoint RP127: 9/26/2011 10:28:12 PM - System Checkpoint RP128: 9/27/2011 12:01:32 PM - Installed SWF Image Creator RP129: 9/27/2011 12:25:51 PM - Removed SWF Image Creator RP130: 9/28/2011 2:44:41 AM - Software Distribution Service 3.0 RP131: 9/29/2011 3:38:17 AM - System Checkpoint RP132: 9/30/2011 4:38:15 AM - System Checkpoint RP133: 10/1/2011 5:38:15 AM - System Checkpoint RP134: 10/2/2011 6:38:17 AM - System Checkpoint RP135: 10/3/2011 9:32:43 AM - System Checkpoint RP136: 10/4/2011 9:54:44 AM - System Checkpoint RP137: 10/5/2011 12:49:53 PM - System Checkpoint RP138: 10/6/2011 1:49:29 PM - System Checkpoint RP139: 10/12/2011 4:57:47 PM - System Checkpoint RP140: 10/13/2011 3:00:36 AM - Software Distribution Service 3.0 RP141: 10/13/2011 3:11:48 AM - Software Distribution Service 3.0 RP142: 10/14/2011 3:39:36 AM - System Checkpoint RP143: 10/15/2011 4:16:11 AM - System Checkpoint RP144: 10/17/2011 1:41:38 AM - System Checkpoint RP145: 10/18/2011 2:26:23 AM - System Checkpoint RP146: 10/19/2011 3:26:24 AM - System Checkpoint RP147: 10/20/2011 4:18:22 AM - System Checkpoint RP148: 10/21/2011 5:12:10 AM - System Checkpoint RP149: 10/22/2011 6:12:11 AM - System Checkpoint RP150: 10/23/2011 7:07:54 AM - System Checkpoint RP151: 10/24/2011 8:09:05 AM - System Checkpoint RP152: 10/25/2011 10:04:58 AM - System Checkpoint RP153: 10/26/2011 10:09:40 AM - System Checkpoint RP154: 10/27/2011 1:21:18 PM - System Checkpoint RP155: 10/28/2011 1:42:39 PM - System Checkpoint . ==== Installed Programs ====================== . Adobe Acrobat 8 Professional Adobe Acrobat 8.1.3 Professional Adobe AIR Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Broadcom 802.11 Wireless LAN Adapter Brother MFL-Pro Suite MFC-J410W CDex extraction audio Conexant HD Audio Creative Removable Disk Manager Creative System Information Creative ZEN V Series (R2) Diskeeper Professional Edition Dropbox ESET Online Scanner v3 HDAUDIO Soft Data Fax Modem with SmartCP Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows XP (KB2443685) Hotfix for Windows XP (KB2570791) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) HP Quick Launch Buttons ImagXpress LiveUpdate 2.6 (Symantec Corporation) Malwarebytes' Anti-Malware version 1.51.2.1300 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Kernel-Mode Driver Framework Feature Pack 1.5 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office File Validation Add-In Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable MozBackup 1.5.1 Mozilla Firefox 7.0.1 (x86 en-US) Mozilla Thunderbird (7.0.1) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) MSXML 6.0 Parser (KB925673) neroxml NOOK for PC Norton 360 Notepad++ NVIDIA Drivers Panda ActiveScan 2.0 PhotoFiltre PKZIP for Windows 9.00.0010 PowerDVD Prism Video File Converter QLBCASL SearchCore for Browsers Security Update for 2007 Microsoft Office System (KB2288621) Security Update for 2007 Microsoft Office System (KB2288931) Security Update for 2007 Microsoft Office System (KB2345043) Security Update for 2007 Microsoft Office System (KB2553074) Security Update for 2007 Microsoft Office System (KB2553089) Security Update for 2007 Microsoft Office System (KB2553090) Security Update for 2007 Microsoft Office System (KB2584063) Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office Access 2007 (KB979440) Security Update for Microsoft Office Excel 2007 (KB2553073) Security Update for Microsoft Office Groove 2007 (KB2552997) Security Update for Microsoft Office InfoPath 2007 (KB2510061) Security Update for Microsoft Office InfoPath 2007 (KB979441) Security Update for Microsoft Office PowerPoint 2007 (KB2535818) Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623) Security Update for Microsoft Office Publisher 2007 (KB2284697) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB2344993) Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2497640) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2530548) Security Update for Windows Internet Explorer 8 (KB2544521) Security Update for Windows Internet Explorer 8 (KB2559049) Security Update for Windows Internet Explorer 8 (KB2586448) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows XP (KB2079403) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2121546) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2360937) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2412687) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2476490) Security Update for Windows XP (KB2476687) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2497640) Security Update for Windows XP (KB2503658) Security Update for Windows XP (KB2503665) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2506223) Security Update for Windows XP (KB2507618) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508272) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2511455) Security Update for Windows XP (KB2524375) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2536276) Security Update for Windows XP (KB2544893) Security Update for Windows XP (KB2555917) Security Update for Windows XP (KB2562937) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2567053) Security Update for Windows XP (KB2567680) Security Update for Windows XP (KB2570222) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975562) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978601) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB980436) Security Update for Windows XP (KB981322) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) SUPERAntiSpyware Synaptics Pointing Device Driver Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 System (KB2539530) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office Outlook 2007 (KB2583910) Update for Outlook 2007 Junk Email Filter (KB2596560) Update for Windows Internet Explorer 8 (KB2447568) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2541763) Update for Windows XP (KB2607712) Update for Windows XP (KB2616676) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VLC media player 1.1.11 WavePad Sound Editor WebFldrs XP Windows Genuine Advantage Notifications (KB905474) Windows Internet Explorer 8 Windows Media Format Runtime Windows Presentation Foundation Windows XP Service Pack 3 XML Paper Specification Shared Components Pack 1.0 . ==== Event Viewer Messages From Past Week ======== . 10/26/2011 8:29:10 AM, error: Service Control Manager [7000] - The 2812992B service failed to start due to the following error: The system cannot find the file specified. 10/26/2011 8:20:20 AM, error: Service Control Manager [7000] - The 84563EAA service failed to start due to the following error: The system cannot find the file specified. 10/25/2011 10:30:58 PM, error: Service Control Manager [7034] - The 71418283 service terminated unexpectedly. It has done this 1 time(s). 10/23/2011 5:42:38 AM, error: MRxSmb [8003] - The master browser has received a server announcement from the computer DAVID-E4E0FFA5A that believes that it is the master browser for the domain on transport NetBT_Tcpip_{62B01DCB-0F6. The master browser is stopping or an election is being forced. 10/23/2011 12:04:24 AM, error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: ShldDrv 10/23/2011 12:04:21 AM, error: Service Control Manager [7000] - The Panda Process Protection Service service failed to start due to the following error: The system cannot find the path specified. 10/23/2011 12:04:21 AM, error: Service Control Manager [7000] - The Panda Process Protection Driver service failed to start due to the following error: The system cannot find the file specified. 10/21/2011 9:02:11 AM, error: NetBT [4319] - A duplicate name has been detected on the TCP network. The IP address of the machine that sent the message is in the data. Use nbtstat -n in a command window to see which name is in the Conflict state. . ==== End Of File ===========================
Hi yolozone,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    KillAll::
    
    DDS::
    mRun: [DATAMNGR] c:\progra~1\search~1\search~1\DATAMN~1.EXE
    
    File::
    c:\windows\system32\2812992b.exe
    c:\windows\system32\71418283.exe
    c:\windows\system32\84563eaa.exe
    
    Firefox::
    FF - ProfilePath - c:\documents and settings\user\application data\mozilla\firefox\profiles\3p0gzzlb.default\
    FF - prefs.js: keyword.URL - hxxp://www.hpmirror.com
    
    Driver::
    2812992B
    71418283
    84563EAA
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
Jeff - I am experiencing some . . . anomalous . . . behavior in Combo Fix. Last night I downloaded C.F. from (Link 2). Today I applied CFScript.txt to the program. I was informed that "C.F. has expired. Should it run in Reduced Effectiveness mode?" To this I said No, and fetched a fresh copy from (Link 1). Re-applied CFScript.txt to the C.F. icon. The DOS prompt window gave me the ten minute message: "Scanning for infection files. . . should be ten minutes but badly infected machines can easily double." That was about 90 minutes ago. How long should I give it before cancelling & re-execute the script? I don't *think* I mouse clicked on the DOS window but with the optical touchpad who can say? Come to think, I did use the mouse to move the entire prompt-window a couple of inches, just to check if my processor was hanging. But even that was after it had run for 50+ minutes. Remember too I can forward the log that ComboFIx generated on Tuesday of this week. Thank you for your help!
Hi yolozone, Go ahead and delete that copy of combofix and grab a fresh copy again. Then use the same cfscript.txt that we already created and run it again. This time to click on anything or do anything because this can stall the program.
Hi yolozone,

No let's try something else. :)

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI