This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browswer Hijack searchqu.com/405 - again [Solved]

31 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry, I am hijacked, again. I guess I will just stop downloading from savevid.com :( It seems it's my Firefox browser more than anything. If I click on MSIE, I don't get this but if I click on Firefox, the browser is hXXp://.searchqu.com/405 and my computer has been drastically slowed down on the net. Thanks
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———-

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
    Vista and Windows 7 users right click the icon and choose "Run as administrator".
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post both of the logs created by DDS and the log created by aswMBR.exe. :)
Hi CoolCat,

If you would, in your future replies please just copy and paste the logs. It makes it easier for me to read them. Thanks. :)
————

Please download MBRCheck.exe to your desktop.
  • Be sure to disable your security programs
  • Double click on the file to run it (Vista and Windows 7 users will have to confirm the UAC prompt)
  • A window will open on your desktop
  • If an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
  • If nothing unusual is found just press Enter
  • A .txt file named MBRCheck_mm.dd.yy_hh.mm.ss should appear on your desktop.
  • Please post the contents of that file.
Yep, sure enough, if showed an N. Here's the text. Thanks! MBRCheck, version 1.2.3 © 2010, AD Command-line: Windows Version: Windows Vista Home Premium Edition Windows Information: Service Pack 2 (build 6002), 64-bit Base Board Manufacturer: Acer BIOS Manufacturer: Acer System Manufacturer: Acer System Product Name: Aspire 6930 Logical Drives Mask: 0x0000002c Kernel Drivers (total 157): 0x02606000 \SystemRoot\system32\ntoskrnl.exe 0x02B1E000 \SystemRoot\system32\hal.dll 0x0060B000 \SystemRoot\system32\kdcom.dll 0x00615000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x00650000 \SystemRoot\system32\PSHED.dll 0x00664000 \SystemRoot\system32\CLFS.SYS 0x006C1000 \SystemRoot\system32\CI.dll 0x0080A000 \SystemRoot\system32\drivers\Wdf01000.sys 0x008E4000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x008F2000 \SystemRoot\system32\drivers\acpi.sys 0x00948000 \SystemRoot\system32\drivers\WMILIB.SYS 0x00951000 \SystemRoot\system32\drivers\msisadrv.sys 0x0095B000 \SystemRoot\system32\drivers\pci.sys 0x0098B000 \SystemRoot\System32\drivers\partmgr.sys 0x009A0000 \SystemRoot\system32\DRIVERS\compbatt.sys 0x009A4000 \SystemRoot\system32\DRIVERS\BATTC.SYS 0x009B0000 \SystemRoot\system32\drivers\volmgr.sys 0x00773000 \SystemRoot\System32\drivers\volmgrx.sys 0x009C4000 \SystemRoot\System32\drivers\mountmgr.sys 0x009D7000 \SystemRoot\System32\Drivers\UBHelper.sys 0x00A0D000 \SystemRoot\system32\DRIVERS\iaStor.sys 0x00B27000 \SystemRoot\system32\drivers\atapi.sys 0x00B2F000 \SystemRoot\system32\drivers\ataport.SYS 0x00B53000 \SystemRoot\system32\drivers\fltmgr.sys 0x00B9A000 \SystemRoot\system32\drivers\fileinfo.sys 0x00BAE000 \SystemRoot\system32\DRIVERS\psdfilter.sys 0x00C08000 \SystemRoot\System32\Drivers\ksecdd.sys 0x00E0B000 \SystemRoot\system32\drivers\ndis.sys 0x00C8F000 \SystemRoot\system32\drivers\msrpc.sys 0x00CDF000 \SystemRoot\system32\drivers\NETIO.SYS 0x01001000 \SystemRoot\System32\drivers\tcpip.sys 0x01176000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x01202000 \SystemRoot\System32\Drivers\Ntfs.sys 0x01382000 \SystemRoot\system32\drivers\volsnap.sys 0x013C6000 \SystemRoot\System32\Drivers\spldr.sys 0x013CE000 \SystemRoot\System32\Drivers\mup.sys 0x011A2000 \SystemRoot\System32\drivers\ecache.sys 0x013E0000 \SystemRoot\system32\drivers\disk.sys 0x011CE000 \SystemRoot\system32\drivers\CLASSPNP.SYS 0x013F4000 \SystemRoot\system32\drivers\crcdisk.sys 0x02525000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x02532000 \SystemRoot\system32\DRIVERS\tunmp.sys 0x0253B000 \SystemRoot\system32\DRIVERS\CmBatt.sys 0x02540000 \SystemRoot\system32\DRIVERS\wmiacpi.sys 0x02604000 \SystemRoot\system32\DRIVERS\igdkmd64.sys 0x03027000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x0310A000 \SystemRoot\System32\drivers\watchdog.sys 0x0311A000 \SystemRoot\system32\DRIVERS\usbuhci.sys 0x03126000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0x0316C000 \SystemRoot\system32\DRIVERS\usbehci.sys 0x0320D000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0x03405000 \SystemRoot\system32\DRIVERS\NETw5v64.sys 0x03897000 \SystemRoot\system32\DRIVERS\L1E60x64.sys 0x038AA000 \SystemRoot\system32\DRIVERS\winbondcir.sys 0x038C2000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0x038D8000 \SystemRoot\SysWOW64\Drivers\DKbFltr.sys 0x038E4000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0x038F2000 \SystemRoot\system32\DRIVERS\SynTP.sys 0x03948000 \SystemRoot\system32\DRIVERS\USBD.SYS 0x0394A000 \SystemRoot\system32\DRIVERS\mouclass.sys 0x03956000 \SystemRoot\system32\DRIVERS\cdrom.sys 0x03972000 \SystemRoot\system32\Drivers\NTIDrvr.sys 0x0397A000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x0398D000 \SystemRoot\system32\DRIVERS\msiscsi.sys 0x032FA000 \SystemRoot\system32\DRIVERS\storport.sys 0x039C5000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x039D2000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x03357000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x03363000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x03394000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x033A4000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x033C2000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x033DA000 \SystemRoot\system32\DRIVERS\wanatw64.sys 0x033E6000 \SystemRoot\system32\DRIVERS\termdd.sys 0x039F5000 \SystemRoot\system32\DRIVERS\swenum.sys 0x0317D000 \SystemRoot\system32\DRIVERS\ks.sys 0x031B1000 \SystemRoot\system32\DRIVERS\circlass.sys 0x03200000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0x031C2000 \SystemRoot\system32\DRIVERS\umbus.sys 0x02549000 \SystemRoot\system32\DRIVERS\usbhub.sys 0x031D2000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x0420C000 \SystemRoot\system32\drivers\RTKVHD64.sys 0x04379000 \SystemRoot\system32\drivers\portcls.sys 0x043B4000 \SystemRoot\system32\drivers\drmk.sys 0x043D7000 \SystemRoot\system32\drivers\ksthunk.sys 0x02591000 \SystemRoot\system32\DRIVERS\CAXHWAZL.sys 0x04406000 \SystemRoot\system32\DRIVERS\CAX_DPV.sys 0x04609000 \SystemRoot\system32\DRIVERS\CAX_CNXT.sys 0x046D4000 \SystemRoot\system32\drivers\modem.sys 0x046E3000 \SystemRoot\system32\drivers\IntcHdmi.sys 0x04708000 \SystemRoot\system32\drivers\RTSTOR64.SYS 0x0471E000 \SystemRoot\system32\DRIVERS\usbccgp.sys 0x0473A000 \SystemRoot\system32\DRIVERS\hidir.sys 0x04745000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0x04757000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0x0475F000 \SystemRoot\System32\Drivers\usbvideo.sys 0x04789000 \SystemRoot\system32\DRIVERS\hidusb.sys 0x04792000 \SystemRoot\system32\DRIVERS\kbdhid.sys 0x0479C000 \SystemRoot\system32\DRIVERS\mouhid.sys 0x047A7000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0x047B1000 \SystemRoot\System32\Drivers\Null.SYS 0x047BA000 \SystemRoot\System32\drivers\vga.sys 0x047C8000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x047ED000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x047F6000 \SystemRoot\system32\drivers\rdpencdd.sys 0x0457A000 \SystemRoot\System32\Drivers\Msfs.SYS 0x04585000 \SystemRoot\System32\Drivers\Npfs.SYS 0x04600000 \SystemRoot\System32\DRIVERS\rasacd.sys 0x04596000 \SystemRoot\system32\DRIVERS\tdx.sys 0x045B3000 \SystemRoot\system32\DRIVERS\smb.sys 0x00D38000 \SystemRoot\System32\DRIVERS\netbt.sys 0x00D7C000 \SystemRoot\system32\drivers\afd.sys 0x045CE000 \SystemRoot\system32\DRIVERS\pacer.sys 0x045EC000 \SystemRoot\system32\DRIVERS\netbios.sys 0x043DD000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x0740D000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x0745A000 \SystemRoot\system32\drivers\nsiproxy.sys 0x07466000 \SystemRoot\System32\Drivers\dfsc.sys 0x07483000 \SystemRoot\system32\DRIVERS\avkmgr.sys 0x0748D000 \SystemRoot\system32\DRIVERS\avipbb.sys 0x074B3000 \SystemRoot\System32\Drivers\crashdmp.sys 0x074C1000 \SystemRoot\System32\Drivers\dump_iaStor.sys 0x00000000 \SystemRoot\System32\win32k.sys 0x075DB000 \SystemRoot\System32\drivers\Dxapi.sys 0x075E7000 \SystemRoot\system32\DRIVERS\monitor.sys 0x00480000 \SystemRoot\System32\TSDDD.dll 0x00640000 \SystemRoot\System32\cdd.dll 0x02400000 \SystemRoot\system32\drivers\luafv.sys 0x02422000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0x02442000 \SystemRoot\system32\drivers\spsys.sys 0x024DC000 \SystemRoot\system32\DRIVERS\ipfltdrv.sys 0x031E6000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x00BB7000 \SystemRoot\system32\DRIVERS\nwifi.sys 0x07400000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0x024F7000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x18209000 \SystemRoot\system32\drivers\HTTP.sys 0x182AC000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x182D5000 \SystemRoot\system32\DRIVERS\bowser.sys 0x182F3000 \SystemRoot\System32\drivers\mpsdrv.sys 0x1830D000 \SystemRoot\system32\drivers\mrxdav.sys 0x18334000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x1835D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x183A6000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x183C5000 \SystemRoot\System32\DRIVERS\srv2.sys 0x17E0C000 \SystemRoot\System32\DRIVERS\srv.sys 0x17E9F000 \??\C:\Windows\SysWOW64\drivers\int15_64.sys 0x17EB7000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0x17EBC000 \SystemRoot\system32\drivers\peauth.sys 0x17F72000 \SystemRoot\system32\DRIVERS\PSDNServ.sys 0x17F7B000 \SystemRoot\system32\DRIVERS\PSDVdisk.sys 0x17F8E000 \SystemRoot\System32\Drivers\secdrv.SYS 0x17F99000 \SystemRoot\System32\drivers\tcpipreg.sys 0x17FA9000 \SystemRoot\system32\DRIVERS\xaudio64.sys 0x17FB1000 \??\C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl 0x00FCE000 \SystemRoot\system32\DRIVERS\ipnat.sys 0x17FD6000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x77870000 \Windows\System32\ntdll.dll Processes (total 89): 0 System Idle Process 4 System 480 C:\Windows\System32\smss.exe 612 csrss.exe 648 C:\Windows\System32\wininit.exe 668 csrss.exe 704 C:\Windows\System32\services.exe 716 C:\Windows\System32\lsass.exe 724 C:\Windows\System32\lsm.exe 828 C:\Windows\System32\winlogon.exe 908 C:\Windows\System32\svchost.exe 976 C:\Windows\System32\svchost.exe 336 C:\Windows\System32\svchost.exe 424 C:\Windows\System32\svchost.exe 584 C:\Windows\System32\svchost.exe 664 C:\Windows\System32\audiodg.exe 960 C:\Windows\System32\SLsvc.exe 748 C:\Windows\System32\svchost.exe 1288 C:\Windows\System32\svchost.exe 1488 C:\Windows\System32\spoolsv.exe 1512 C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 1532 C:\Windows\System32\svchost.exe 1752 C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 1780 C:\Program Files (x86)\Common Files\aol\acs\AOLacsd.exe 1812 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe 1840 C:\Program Files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe 1880 C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 1908 C:\Program Files\Acer\Empowering Technology\Service\ETService.exe 1992 C:\Program Files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe 2036 C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 1472 C:\ACER\Mobility Center\MobilityService.exe 1724 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 2064 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 2104 C:\Windows\System32\svchost.exe 2148 C:\Program Files (x86)\Cyberlink\Shared files\RichVideo.exe 2216 C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE 2248 C:\Windows\System32\svchost.exe 2288 C:\Windows\System32\svchost.exe 2384 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 2456 C:\Windows\System32\SearchIndexer.exe 2500 C:\Windows\System32\drivers\XAudio64.exe 2512 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE 2552 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe 2840 C:\Windows\System32\taskeng.exe 2992 C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe 1748 C:\Windows\System32\alg.exe 2280 WmiPrvSE.exe 3860 C:\Windows\System32\svchost.exe 3332 C:\Windows\System32\taskeng.exe 1968 C:\Windows\System32\dwm.exe 3476 C:\Windows\explorer.exe 3832 C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe 3896 C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe 3908 C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSLoader.exe 3948 C:\Windows\RAVCpl64.exe 3084 C:\Windows\PLFSetI.exe 4080 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 4072 C:\Windows\System32\hkcmd.exe 4068 C:\Windows\System32\igfxpers.exe 2392 C:\Program Files\Zune\ZuneLauncher.exe 4016 C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe 3768 C:\Windows\System32\igfxsrvc.exe 3484 C:\Windows\System32\wbem\unsecapp.exe 1208 C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe 3284 C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe 2796 C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe 3180 C:\Users\Ratopia\AppData\Local\temp\RtkBtMnt.exe 1080 C:\Program Files (x86)\Launch Manager\QtZgAcer.EXE 3568 C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe 3464 C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe 3260 C:\Program Files (x86)\Common Files\aol\1242688622\ee\aolsoftware.exe 3136 C:\Program Files (x86)\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe 3744 C:\Program Files (x86)\PCPitstop\Info Center\InfoCenter.exe 3848 C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe 3392 C:\Program Files (x86)\Windows Savevid Toolbar\Datamngr\datamngrUI.exe 3976 C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe 4208 C:\Windows\System32\igfxext.exe 4448 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 3428 C:\Program Files (x86)\AOL 9.1\waol.exe 3824 C:\Program Files (x86)\AOL 9.1\shellmon.exe 3572 C:\Program Files (x86)\Common Files\aol\1242688622\ee\anotify.exe 4748 C:\Program Files (x86)\Common Files\AOL\Topspeed\3.0\aoltpsd3.exe 4880 C:\Program Files (x86)\Mozilla Firefox\firefox.exe 2668 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe 552 C:\Windows\System32\SearchProtocolHost.exe 4552 C:\Windows\System32\SearchFilterHost.exe 4640 dllhost.exe 4536 dllhost.exe 1112 C:\Users\Ratopia\Desktop\MBRCheck.exe \\.\C: –> \\.\PhysicalDrive0 at offset 0x00000003`00100000 (NTFS) \\.\D: –> \\.\PhysicalDrive0 at offset 0x00000026`c2e00000 (NTFS) PhysicalDrive0 Model Number: HitachiHTS543232L9A300, Rev: FB4OC40C Size Device Name MBR Status ——————————————– 298 GB \\.\PhysicalDrive0 Unknown MBR code SHA1: 1BD01CAC429595C1D0CBBF8C10C0B8BA957B5116 Found non-standard or infected MBR. Enter 'Y' and hit ENTER for more options, or 'N' to exit: Done!
Hi CoolCat,

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
———-
Here is the log. Thank you! ComboFix 12-01-29.01 - Ratopia 01/28/2012 23:16:16.1.2 - x64 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4024.1011 [GMT -6:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Ratopia\AppData\Local\temp\RtkBtMnt.exe . . ((((((((((((((((((((((((( Files Created from 2011-12-28 to 2012-01-29 ))))))))))))))))))))))))))))))) . . 2012-01-24 07:25 . 2011-11-17 06:53 515968 —-a-w- c:\windows\system32\drivers\ksecdd.sys 2012-01-24 07:25 . 2011-11-16 16:42 347136 —-a-w- c:\windows\system32\schannel.dll 2012-01-24 07:25 . 2011-11-16 16:23 278528 —-a-w- c:\windows\SysWow64\schannel.dll 2012-01-24 07:25 . 2011-11-16 16:43 442368 —-a-w- c:\windows\system32\winhttp.dll 2012-01-24 07:25 . 2011-11-16 16:42 94720 —-a-w- c:\windows\system32\secur32.dll 2012-01-24 07:25 . 2011-11-16 16:41 1689600 —-a-w- c:\windows\system32\lsasrv.dll 2012-01-24 07:25 . 2011-11-16 16:24 77312 —-a-w- c:\windows\SysWow64\secur32.dll 2012-01-24 07:25 . 2011-11-16 16:23 377344 —-a-w- c:\windows\SysWow64\winhttp.dll 2012-01-24 07:25 . 2011-11-16 14:34 11264 —-a-w- c:\windows\system32\lsass.exe 2012-01-22 07:13 . 2012-01-22 07:13 ——– d—–w- c:\users\Ratopia\AppData\Local\Apple Computer 2012-01-20 21:33 . 2012-01-20 21:33 ——– d—–w- c:\users\Ratopia\AppData\Local\Acer Arcade Deluxe 2012-01-17 01:36 . 2012-01-17 01:36 ——– d—–w- c:\program files (x86)\Windows Savevid Toolbar 2012-01-17 01:35 . 2012-01-17 01:35 ——– dc-h–w- c:\programdata\{C4A867AE-B15C-4B7F-AD27-7F8C13A57518} 2012-01-17 01:35 . 2012-01-17 01:35 ——– d—–w- c:\program files (x86)\SavevidPlug-in 2012-01-10 21:45 . 2011-12-01 15:29 2409784 —-a-w- c:\program files\Windows Mail\OESpamFilter.dat 2012-01-10 21:45 . 2011-12-01 15:21 2409784 —-a-w- c:\program files (x86)\Windows Mail\OESpamFilter.dat 2012-01-10 21:45 . 2011-10-25 16:13 1570816 —-a-w- c:\windows\system32\quartz.dll 2012-01-10 21:45 . 2011-10-25 16:13 352256 —-a-w- c:\windows\system32\qdvd.dll 2012-01-10 21:45 . 2011-10-25 15:58 1314816 —-a-w- c:\windows\SysWow64\quartz.dll 2012-01-10 21:45 . 2011-10-25 15:58 497152 —-a-w- c:\windows\SysWow64\qdvd.dll 2012-01-10 21:44 . 2011-11-18 20:55 1585152 —-a-w- c:\windows\system32\ntdll.dll 2012-01-10 21:44 . 2011-11-18 20:55 1167984 —-a-w- c:\windows\SysWow64\ntdll.dll 2012-01-10 21:44 . 2011-11-25 16:25 451072 —-a-w- c:\windows\system32\winsrv.dll 2012-01-10 21:44 . 2011-10-14 17:31 211968 —-a-w- c:\windows\system32\winmm.dll 2012-01-10 21:44 . 2011-10-14 17:27 48128 —-a-w- c:\windows\system32\mcicda.dll 2012-01-10 21:44 . 2011-10-14 17:27 28672 —-a-w- c:\windows\system32\mciwave.dll 2012-01-10 21:44 . 2011-10-14 17:27 28160 —-a-w- c:\windows\system32\mciseq.dll 2012-01-10 21:44 . 2011-10-14 16:03 189952 —-a-w- c:\windows\SysWow64\winmm.dll 2012-01-10 21:44 . 2011-10-14 16:00 23552 —-a-w- c:\windows\SysWow64\mciseq.dll 2012-01-10 21:44 . 2011-11-18 18:07 76800 —-a-w- c:\windows\system32\packager.dll 2012-01-10 21:44 . 2011-11-18 17:47 66560 —-a-w- c:\windows\SysWow64\packager.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-01-17 01:19 . 2010-06-28 21:17 472808 —-a-w- c:\windows\SysWow64\deployJava1.dll 2012-01-06 07:21 . 2009-06-14 23:20 323584 —-a-w- c:\windows\SysWow64\AUDIOGENIE2.DLL 2011-12-27 14:25 . 2011-05-15 23:58 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-12-15 13:59 . 2010-06-04 07:04 525544 —-a-w- c:\windows\system32\deployJava1.dll 2011-12-10 21:24 . 2009-05-26 22:53 23152 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-12-09 08:36 . 2011-11-21 08:18 130760 —-a-w- c:\windows\system32\drivers\avipbb.sys 2011-11-23 13:57 . 2011-12-15 06:21 2764800 —-a-w- c:\windows\system32\win32k.sys 2011-11-08 14:58 . 2011-12-15 06:21 2048 —-a-w- c:\windows\system32\tzres.dll 2011-11-08 14:42 . 2011-12-15 06:21 2048 —-a-w- c:\windows\SysWow64\tzres.dll 2011-11-04 15:20 . 2011-12-15 06:21 1383424 —-a-w- c:\windows\system32\mshtml.tlb 2011-11-04 14:54 . 2011-12-15 06:21 1383424 —-a-w- c:\windows\SysWow64\mshtml.tlb . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\Wow6432Node\~\Browser Helper Objects\{23cd218f-af09-443f-bbb1-adb89fd5986d}] 2011-12-24 20:36 88976 —-a-w- c:\progra~2\WI0498~1\Datamngr\ToolBar\savevidX.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{23cd218f-af09-443f-bbb1-adb89fd5986d}"= "c:\progra~2\WI0498~1\Datamngr\ToolBar\savevidX.dll" [2011-12-24 88976] . [HKEY_CLASSES_ROOT\clsid\{23cd218f-af09-443f-bbb1-adb89fd5986d}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:52 121392 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-08 68856] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "eAudio"="c:\program files\Acer\Empowering Technology\eAudio\eAudio.exe" [2008-09-12 781824] "BkupTray"="c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe" [2008-04-26 28672] "LManager"="c:\progra~2\LAUNCH~1\QtZgAcer.EXE" [2008-06-04 817672] "ArcadeDeluxeAgent"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe" [2008-07-24 147456] "CLMLServer"="c:\program files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe" [2008-07-24 167936] "Acer Assist Launcher"="c:\program files (x86)\Acer\Acer Assist\launcher.exe" [2007-11-19 1261568] "Acer Product Registration"="c:\program files (x86)\Acer\Acer Registration\ACE1.exe" [2007-11-26 3387392] "HostManager"="c:\program files (x86)\Common Files\AOL\1242688622\ee\AOLSoftware.exe" [2008-06-24 41824] "MaxMenuMgr"="c:\program files (x86)\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-09-26 185640] "Microsoft Default Manager"="c:\program files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888] "Adobe Reader Speed Launcher"="c:\program files (x86)\Reader\Reader_sl.exe" [2011-06-08 37296] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Info Center"="c:\program files (x86)\PCPitstop\Info Center\InfoCenter.exe" [2011-08-03 24216] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2011-09-23 258512] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\WI0498~1\Datamngr\datamngr.dll c:\progra~2\WI0498~1\Datamngr\IEBHO.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . — Other Services/Drivers In Memory — . *NewlyCreated* - WS2IFSL . Contents of the 'Scheduled Tasks' folder . 2012-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . 2012-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-07-15 19:46] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9D717F81-9148-4f12-8568-69135F087DB0}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2008-07-30 01:53 50736 —-a-w- c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-07-20 182808] "ePower_DMC"="c:\program files\Acer\Empowering Technology\ePower\ePower_DMC.exe" [2008-08-01 481792] "eDataSecurity Loader"="c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe" [2008-07-30 561200] "RtHDVCpl"="RAVCpl64.exe" [2008-09-18 6495264] "Skytel"="Skytel.exe" [2008-09-18 1833504] "PLFSetI"="c:\windows\PLFSetI.exe" [2007-10-23 200704] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-04-25 1237288] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-12 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-12 417304] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2011-08-05 163552] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\progra~2\WI0498~1\Datamngr\x64\datamngr.dll c:\progra~2\WI0498~1\Datamngr\x64\IEBHO.dll c:\progra~2\WI0498~1\Datamngr\x64\IEBHO.dll . ——- Supplementary Scan ——- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com/ mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930 mLocal Page = %SystemRoot%\system32\blank.htm uInternet Settings,ProxyOverride = IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html IE: Save video on Savevid.com - c:\program files (x86)\SavevidPlug-in\redirect.htm TCP: DhcpNameServer = [removed] [removed] DPF: {94E5218F-9737-4FC2-8457-567B1FF23DC0} - hxxp://utilities.pcpitstop.com/Nirvana/controls/DiskMD3Ctrl.dll DPF: {A553720A-BFED-4EA4-A71F-7EFCA690A1F7} - hxxp://utilities.pcpitstop.com/Nirvana/controls/pcpitstopAntiVirus.dll CLSID: {603d3801-bd81-11d0-a3a5-00c04fd706ec} - %SystemRoot%\SysWow64\browseui.dll FF - ProfilePath - c:\users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p= FF - prefs.js: browser.search.selectedEngine - Search Results FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/405 FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=405&sr=0&q= FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b} FF - Ext: SavevidToolbar: {23cd218f-af09-443f-bbb1-adb89fd5986d} - %profile%\extensions\{23cd218f-af09-443f-bbb1-adb89fd5986d} . - - - - ORPHANS REMOVED - - - - . Toolbar-10 - (no file) Toolbar-10 - (no file) WebBrowser-{FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - (no file) AddRemove-Yahoo! Mail - c:\windows\system32\regsvr32 AddRemove-YInstHelper - c:\windows\system32\regsvr32 . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}] "ImagePath"="\??\c:\program files (x86)\Acer Arcade Deluxe\PlayMovie\000.fcl" . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}] @Denied: (A 2) (Everyone) . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0] @="Shockwave Flash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}] @Denied: (A 2) (Everyone) @="" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0] @="FlashBroker" . [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes] "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59, 00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ———————— Other Running Processes ———————— . c:\program files (x86)\Avira\AntiVir Desktop\sched.exe c:\program files (x86)\Avira\AntiVir Desktop\avguard.exe c:\program files (x86)\Common Files\AOL\ACS\AOLAcsd.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe c:\program files (x86)\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe c:\program files (x86)\Seagate\SeagateManager\Sync\FreeAgentService.exe c:\program files (x86)\Common Files\LightScribe\LSSrvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe c:\program files (x86)\Cyberlink\Shared files\RichVideo.exe c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files (x86)\Launch Manager\QtZgAcer.EXE c:\program files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe c:\program files (x86)\Windows Savevid Toolbar\Datamngr\datamngrUI.exe . ************************************************************************** . Completion time: 2012-01-28 23:35:29 - machine was rebooted ComboFix-quarantined-files.txt 2012-01-29 05:35 . Pre-Run: 73,098,604,544 bytes free Post-Run: 73,106,714,624 bytes free . - - End Of File - - 7876B8550D0C97B1082F3320A3DE10B4
Hi CoolCat,

Browser is still hijacked, though…

We haven't done any cleaning yet. Let me look over your ComboFix log and I will return as soon as I can. :thumbup: I have a busy day today getting ready to put the house up for sale so I may need some time.

Hi CoolCat,

Browser is still hijacked, though…

We haven't done any cleaning yet. Let me look over your ComboFix log and I will return as soon as I can. :thumbup: I have a busy day today getting ready to put the house up for sale so I may need some time.

No problem. Good luck! :-)
Hi CoolCat,

  • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:
    ClearJavaCache::
    
    DDS::
    mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0409&s=2&o=vp64&d=1208&m=aspire_6930
    uURLSearchHooks: H - No File
    mURLSearchHooks: H - No File
    BHO: Savevid Toolbar: {23cd218f-af09-443f-bbb1-adb89fd5986d} - C:\PROGRA~2\WI0498~1\Datamngr\ToolBar\savevidX.dll
    BHO: DataMngr: {9d717f81-9148-4f12-8568-69135f087db0} - C:\PROGRA~2\WI0498~1\Datamngr\BROWSE~1.DLL
    TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - C:\Program Files (x86)\AOL Toolbar\aoltb.dll
    TB: Savevid Toolbar: {23cd218f-af09-443f-bbb1-adb89fd5986d} - C:\PROGRA~2\WI0498~1\Datamngr\ToolBar\savevidX.dll
    TB: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
    TB: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
    mRun: [DATAMNGR] C:\PROGRA~2\WI0498~1\Datamngr\DATAMN~1.EXE
    BHO-X64:	 0x1 - No File
    BHO-X64:	 AcroIEHelperStub - No File
    BHO-X64: Savevid Toolbar: {23cd218f-af09-443f-bbb1-adb89fd5986d} - C:\PROGRA~2\WI0498~1\Datamngr\ToolBar\savevidX.dll
    BHO-X64:	 Savevid Toolbar - No File
    BHO-X64: DataMngr: {9D717F81-9148-4f12-8568-69135F087DB0} - C:\PROGRA~2\WI0498~1\Datamngr\BROWSE~1.DLL
    TB-X64: Savevid Toolbar: {23cd218f-af09-443f-bbb1-adb89fd5986d} - C:\PROGRA~2\WI0498~1\Datamngr\ToolBar\savevidX.dll
    TB-X64: {FD2FD708-1F6F-4B68-B141-C5778F0C19BB} - No File
    TB-X64: {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - No File
    mRun-x64: [DATAMNGR] C:\PROGRA~2\WI0498~1\Datamngr\DATAMN~1.EXE
    
    Firefox::
    FF - ProfilePath - C:\Users\Ratopia\AppData\Roaming\Mozilla\Firefox\Profiles\yas9n9so.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
    FF - prefs.js: browser.search.selectedEngine - Search Results
    FF - prefs.js: browser.startup.homepage - hxxp://www.searchqu.com/405
    FF - prefs.js: keyword.URL - hxxp://dts.search-results.com/sr?src=ffb&appid=0&systemid=405&sr=0&q=
    FF - component: C:\Program Files (x86)\Windows Savevid Toolbar\Datamngr\FirefoxExtension\components\DataMngrHlpFF3.dll
    FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    
    RegLock::
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    
    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
    "{23cd218f-af09-443f-bbb1-adb89fd5986d}"=-
  • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

    [external image: Posted Image]
  • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
  • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
  • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
———-
I did as instructed above, then got an error message asking if I was trying to run CFScript. and if so, CFScript. appears to be misspelt. Then the whole program closed.
Hi CoolCat,

Thanks for letting me know about the error message.

I'd like for you to move ComboFix.exe and the CFScritpt.txt off of the Desktop and place them in C:\.

Once you have C:\ComboFix.exe and C:\CFSctipt.txt, try running ComboFix and let me know what happens and post the log if you get one.
Hi CoolCat,

Let's try this….boot into Safe Mode and attempt to run ComboFix using the CFScript.txt again.

Reboot Your System in Safe Mode

  • Restart the computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
  • Use the arrow keys to select the Safe mode with Networking menu item
  • Press Enter.

After ComboFix has run please post the log that is made or let me know what problems you have. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI