This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Trojan JS/IframeREF [Solved]

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have a dell laptop running XP pro and recently received an alert that the Trojan JS/IframeRef was found. Using microsoft security essentials, it was removed. A couple hours later I received the same alert and again removed it. It did this a few more times before it stopped finding the trojan alert. But since that time the computer run very, very, slowly. The are also a few programs that I tried to uninstall that I had difficulty removing. (File Type Assistant, Free File View, Browser Error Redirector). I'm not sure any of these have been removed I think I'm infected. Thank you in advance for any help or suggestions you may offer. Vd17
Hello and welcome to What the Tech.

My name is Michael and I will be helping you with your computer problems.

Be aware that I am currently in training, which means that my replies must first be approved by one of my teachers. This may cause a slight delay in my responses, but keep in mind that this process is only to ensure you are receiving advice of the utmost accuracy.

Please keep the following points in mind:
  • Malware research is often a time consuming process and sometimes multiple tools/methods will have to be employed before an infection is completely dealt with. Please be patient during the process of removal.
  • Read my instructions carefully before carrying them out. Also, consider printing out any instructions in case you lose your Internet connection.
  • If you have any questions, please ask before carrying out a fix. Clearing up any confusion beforehand will save time in the long run. That said, I will try to post instructions as clearly and concisely as possible.
  • Please reply to this thread. Do not start a new topic, and do not request help on other forums during the course of the cleaning process.
  • If you do not reply after three (3) days, your thread will be closed.
IMPORTANT NOTE: Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

I will be back as soon as possible with a response.
  • OTL

    Download OTL to your desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

[*]aswMBR


Please download aswMBR and save it to your desktop.

  • Double click aswMBR.exe to start the tool.
  • When prompted to download virus definitions, please do so.
  • Click Scan. Note: Do NOT attempt any Fix yet.
  • When the scan completes, click Save log, save it to your desktop and post it in your next reply.
  • There should also be another file that is created on your desktop named MBR.dat. Please right-click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
Hi Michael: Thank you in advance for helping me out. I downloaded the OTL and aswMBR as you instructed but when I run OTL Windows crashes. I get a screen dump with the message " A problem has been detected and Windows has been shut down to protect your computer." I rebooted and tried again. It happened three times in a row. I have attached a picture of the screen dump for your reference. Should I try booting up in "safe mode" and then run OTL? I'll wait for further instructions. Thanks - Vdicaprio
Hi Michael: below is the aswMBR log file - I have also attached the MBR.dat (zipped file): aswMBR version 0.9.9.1665 CopyrightΒ© 2011 AVAST Software Run date: 2012-04-12 14:11:11 —————————– 14:11:11.921 OS Version: Windows 5.1.2600 Service Pack 3 14:11:11.921 Number of processors: 2 586 0xF0D 14:11:11.921 ComputerName: JEFF UserName: Jeff 14:11:13.578 Initialize success 14:13:49.453 AVAST engine defs: 12041200 14:14:13.687 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 14:14:13.687 Disk 0 Vendor: ST916082 3.AD Size: 152627MB BusType: 3 14:14:13.718 Disk 0 MBR read successfully 14:14:13.718 Disk 0 MBR scan 14:14:13.875 Disk 0 TDL4@MBR code has been found 14:14:13.875 Disk 0 MBR hidden 14:14:13.906 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 14:14:13.968 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 142587 MB offset 80325 14:14:14.031 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 9993 MB offset 292109895 14:14:14.062 Disk 0 MBR [TDL4] **ROOTKIT** 14:14:14.078 Disk 0 trace - called modules: 14:14:14.078 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89a2349f]<< 14:14:14.093 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4b3030] 14:14:14.109 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000006d[0x8a4be9e0] 14:14:14.125 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> [0x8a49c030] 14:14:14.125 \Driver\iaStor[0x89a853f0] -> IRP_MJ_CREATE -> 0x89a2349f 14:14:14.859 AVAST engine scan C:\WINDOWS 14:14:23.718 AVAST engine scan C:\WINDOWS\system32 14:17:57.718 AVAST engine scan C:\WINDOWS\system32\drivers 14:18:15.796 AVAST engine scan C:\Documents and Settings\Jeff 14:24:08.843 AVAST engine scan C:\Documents and Settings\All Users 14:27:07.765 Scan finished successfully 14:27:44.546 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jeff\Desktop\MBR.dat" 14:27:44.578 The log file has been saved successfully to "C:\Documents and Settings\Jeff\Desktop\aswMBR.txt" thanks - I'll wait for further instructions.

Attachments:

Re-Run aswMBR

Click Scan

On completion of the scan

Click Fix

[external image: Posted Image]



Save the log as before and post in your next reply
Hi Michael: I ran the aswMBR scan again and did the fix as instructed. The log is shown below and the dat file is attached. aswMBR version 0.9.9.1665 CopyrightΒ© 2011 AVAST Software Run date: 2012-04-13 07:32:18 —————————– 07:32:18.500 OS Version: Windows 5.1.2600 Service Pack 3 07:32:18.500 Number of processors: 2 586 0xF0D 07:32:18.500 ComputerName: JEFF UserName: Jeff 07:32:29.062 Initialize success 07:33:06.703 AVAST engine defs: 12041200 07:33:11.687 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 07:33:11.687 Disk 0 Vendor: ST916082 3.AD Size: 152627MB BusType: 3 07:33:11.718 Disk 0 MBR read successfully 07:33:11.734 Disk 0 MBR scan 07:33:11.984 Disk 0 TDL4@MBR code has been found 07:33:11.984 Disk 0 MBR hidden 07:33:12.093 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 07:33:12.562 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 142587 MB offset 80325 07:33:12.765 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 9993 MB offset 292109895 07:33:12.812 Disk 0 MBR [TDL4] **ROOTKIT** 07:33:12.812 Disk 0 trace - called modules: 07:33:12.828 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89a8349f]<< 07:33:12.843 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8a4626c8] 07:33:12.843 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000006e[0x8a4ddb58] 07:33:12.859 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> [0x8a4b2030] 07:33:12.875 \Driver\iaStor[0x89af7e70] -> IRP_MJ_CREATE -> 0x89a8349f 07:33:18.156 AVAST engine scan C:\WINDOWS 07:33:48.125 AVAST engine scan C:\WINDOWS\system32 07:37:51.765 AVAST engine scan C:\WINDOWS\system32\drivers 07:38:11.109 AVAST engine scan C:\Documents and Settings\Jeff 07:48:50.468 AVAST engine scan C:\Documents and Settings\All Users 07:52:50.062 Scan finished successfully 07:57:14.203 Disk 0 MBR read successfully 07:57:14.593 Disk 0 TDL4@MBR code has been found 07:57:14.593 Disk 0 fixing MBR … 07:57:14.609 Disk 0 MBR restored successfully 07:57:14.609 Verifying disinfection 07:57:24.812 Infection fixed successfully - please reboot ASAP 07:57:53.718 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jeff\Desktop\MBR.dat" 07:57:53.734 The log file has been saved successfully to "C:\Documents and Settings\Jeff\Desktop\aswMBR-1.txt" Thanks

Attachments:

Let's run aswMBR again to make sure the infection is gone.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
Michael I ran aswMBR again the dat file is attached and the log is posted below. I did not click "fix" this time. It show anything in red this time but the line below "Service scanning" was tagged in yellow. One question - should I disable my antivirus software before running this? I havent been and while aswMBR was scanning a pop up from my Microsoft Security Essentials appeared saying it found a virus and to reboot the computer to complete the removal. I ignored the pop up. aswMBR version 0.9.9.1665 CopyrightΒ© 2011 AVAST Software Run date: 2012-04-13 15:12:31 —————————– 15:12:31.515 OS Version: Windows 5.1.2600 Service Pack 3 15:12:31.515 Number of processors: 2 586 0xF0D 15:12:31.515 ComputerName: JEFF UserName: Jeff 15:12:33.734 Initialize success 15:12:43.546 AVAST engine defs: 12041200 15:12:52.734 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 15:12:52.750 Disk 0 Vendor: ST916082 3.AD Size: 152627MB BusType: 3 15:12:52.781 Disk 0 MBR read successfully 15:12:52.781 Disk 0 MBR scan 15:12:52.843 Disk 0 unknown MBR code 15:12:52.843 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 15:12:52.890 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 142587 MB offset 80325 15:12:52.953 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 9993 MB offset 292109895 15:12:53.000 Disk 0 scanning sectors +312576705 15:12:53.125 Disk 0 scanning C:\WINDOWS\system32\drivers 15:13:09.562 Service scanning 15:13:27.703 Service MpKsl4e74a90b c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4E245602-07BC-4A49-80BE-F93DD291F844}\MpKsl4e74a90b.sys **LOCKED** 32 15:13:45.796 Modules scanning 15:13:54.234 Disk 0 trace - called modules: 15:13:54.281 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll iaStor.sys 15:13:54.296 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x89f2aab8] 15:13:54.312 3 CLASSPNP.SYS[ba0e8fd7] -> nt!IofCallDriver -> \Device\0000006d[0x8a4619e0] 15:13:54.328 5 ACPI.sys[b9f7f620] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a4d4030] 15:13:55.187 AVAST engine scan C:\WINDOWS 15:14:03.859 AVAST engine scan C:\WINDOWS\system32 15:17:34.609 AVAST engine scan C:\WINDOWS\system32\drivers 15:17:52.531 AVAST engine scan C:\Documents and Settings\Jeff 15:26:33.562 AVAST engine scan C:\Documents and Settings\All Users 15:30:52.031 Scan finished successfully 15:42:20.625 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Jeff\Desktop\MBR.dat" 15:42:20.640 The log file has been saved successfully to "C:\Documents and Settings\Jeff\Desktop\aswMBR.txt" thanks

Attachments:

The yellow file is related to Microsoft Security Essentials, so it should be left alone.

I'll mention when disabling your anti-virus is critical (like before running the following program), but in general it is good practice to temporarily disable it before running any kind of fix I instruct you to do. You were right to ignore the pop-up. :thumbup:

  • ComboFix


  • Download ComboFix from one of the following locations:

    Link 1
    Link 2

  • VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.
  • Double click on ComboFix.exe & follow the prompts.

  • As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
  • Should there be issues with internet afterward:

    In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

    In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.
Michael:

I ran combofix the log is posted below:

ComboFix 12-04-14.02 - Jeff 04/14/2012 10:46:16.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2540 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Application Data\TEMP\DFC5A2B2.TMP
c:\documents and settings\Jeff\Application Data\completescan
c:\documents and settings\Jeff\Application Data\install
c:\documents and settings\Jeff\dos2usb.tmp
c:\documents and settings\Jeff\g2mdlhlpx.exe
c:\documents and settings\Jeff\GoToAssistDownloadHelper.exe
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}\chrome.manifest
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}\chrome\content\overlay.xul
c:\documents and settings\Jeff\Local Settings\Application Data\{C0FC7898-C632-412D-A685-1BCDD118DFD0}\install.rdf
c:\documents and settings\Jeff\Local Settings\Application Data\assembly\tmp
c:\documents and settings\Jeff\WINDOWS
c:\windows\system32\regobj.dll
c:\windows\Tasks\At1.job
c:\windows\Tasks\At10.job
c:\windows\Tasks\At11.job
c:\windows\Tasks\At12.job
c:\windows\Tasks\At13.job
c:\windows\Tasks\At14.job
c:\windows\Tasks\At15.job
c:\windows\Tasks\At16.job
c:\windows\Tasks\At17.job
c:\windows\Tasks\At18.job
c:\windows\Tasks\At19.job
c:\windows\Tasks\At2.job
c:\windows\Tasks\At20.job
c:\windows\Tasks\At21.job
c:\windows\Tasks\At22.job
c:\windows\Tasks\At23.job
c:\windows\Tasks\At24.job
c:\windows\Tasks\At3.job
c:\windows\Tasks\At4.job
c:\windows\Tasks\At5.job
c:\windows\Tasks\At6.job
c:\windows\Tasks\At7.job
c:\windows\Tasks\At8.job
c:\windows\Tasks\At9.job
.
.
((((((((((((((((((((((((( Files Created from 2012-03-14 to 2012-04-14 )))))))))))))))))))))))))))))))
.
.
2012-04-13 16:08 . 2012-03-13 23:15 6582328 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{4E245602-07BC-4A49-80BE-F93DD291F844}\mpengine.dll
2012-04-13 12:29 . 2012-04-13 12:29 ——– d—–w- c:\documents and settings\Jeff\Local Settings\Application Data\PCHealth
2012-04-03 19:33 . 2012-04-03 19:33 418464 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-04 19:56 . 2010-08-26 12:41 22344 β€”-a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 19:33 . 2011-05-19 11:54 70304 β€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-13 23:15 . 2011-06-27 11:58 6582328 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-03-01 11:01 . 2008-04-25 16:16 916992 β€”-a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2008-04-25 16:16 43520 β€”-a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01 . 2008-04-25 16:16 1469440 β€”-a-w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-25 16:16 177664 β€”-a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-25 16:16 148480 β€”-a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-25 16:16 385024 β€”-a-w- c:\windows\system32\html.iec
2012-02-03 09:22 . 2008-04-25 16:16 1860096 β€”-a-w- c:\windows\system32\win32k.sys
2012-01-31 12:44 . 2011-06-25 15:02 237072 β€”β€”w- c:\windows\system32\MpSigStub.exe
2012-01-20 15:33 . 2012-01-20 15:33 255352 β€”-a-w- c:\windows\system32\awrdscdc.ax
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 21:31 1514152 β€”-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-02-21 159744]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-21 16855552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-30 2220032]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-9-4 7168]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\WINDOWS\\system32\\dkabcoms.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
.
R2 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe -service –> c:\windows\system32\DKabcoms.exe -service [?]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [9/4/2008 3:25 PM 48472]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [9/4/2008 3:25 PM 43480]
S1 bbyljlnw;bbyljlnw;\??\c:\windows\system32\drivers\bbyljlnw.sys –> c:\windows\system32\drivers\bbyljlnw.sys [?]
S1 bgtrgkhs;bgtrgkhs;\??\c:\windows\system32\drivers\bgtrgkhs.sys –> c:\windows\system32\drivers\bgtrgkhs.sys [?]
S1 clzpbvlb;clzpbvlb;\??\c:\windows\system32\drivers\clzpbvlb.sys –> c:\windows\system32\drivers\clzpbvlb.sys [?]
S1 cufczslm;cufczslm;\??\c:\windows\system32\drivers\cufczslm.sys –> c:\windows\system32\drivers\cufczslm.sys [?]
S1 eiuvmzcq;eiuvmzcq;\??\c:\windows\system32\drivers\eiuvmzcq.sys –> c:\windows\system32\drivers\eiuvmzcq.sys [?]
S1 erkjgnif;erkjgnif;\??\c:\windows\system32\drivers\erkjgnif.sys –> c:\windows\system32\drivers\erkjgnif.sys [?]
S1 fhttknqq;fhttknqq;\??\c:\windows\system32\drivers\fhttknqq.sys –> c:\windows\system32\drivers\fhttknqq.sys [?]
S1 fimufhfu;fimufhfu;\??\c:\windows\system32\drivers\fimufhfu.sys –> c:\windows\system32\drivers\fimufhfu.sys [?]
S1 futndtiw;futndtiw;\??\c:\windows\system32\drivers\futndtiw.sys –> c:\windows\system32\drivers\futndtiw.sys [?]
S1 gclurjnt;gclurjnt;\??\c:\windows\system32\drivers\gclurjnt.sys –> c:\windows\system32\drivers\gclurjnt.sys [?]
S1 hqaubcrq;hqaubcrq;\??\c:\windows\system32\drivers\hqaubcrq.sys –> c:\windows\system32\drivers\hqaubcrq.sys [?]
S1 hthncqvz;hthncqvz;\??\c:\windows\system32\drivers\hthncqvz.sys –> c:\windows\system32\drivers\hthncqvz.sys [?]
S1 hyenzaut;hyenzaut;\??\c:\windows\system32\drivers\hyenzaut.sys –> c:\windows\system32\drivers\hyenzaut.sys [?]
S1 jbiwfqbk;jbiwfqbk;\??\c:\windows\system32\drivers\jbiwfqbk.sys –> c:\windows\system32\drivers\jbiwfqbk.sys [?]
S1 jwwrvecv;jwwrvecv;\??\c:\windows\system32\drivers\jwwrvecv.sys –> c:\windows\system32\drivers\jwwrvecv.sys [?]
S1 kwuqfndo;kwuqfndo;\??\c:\windows\system32\drivers\kwuqfndo.sys –> c:\windows\system32\drivers\kwuqfndo.sys [?]
S1 laegbejf;laegbejf;\??\c:\windows\system32\drivers\laegbejf.sys –> c:\windows\system32\drivers\laegbejf.sys [?]
S1 mzspbfes;mzspbfes;\??\c:\windows\system32\drivers\mzspbfes.sys –> c:\windows\system32\drivers\mzspbfes.sys [?]
S1 njmqufaa;njmqufaa;\??\c:\windows\system32\drivers\njmqufaa.sys –> c:\windows\system32\drivers\njmqufaa.sys [?]
S1 nplalqix;nplalqix;\??\c:\windows\system32\drivers\nplalqix.sys –> c:\windows\system32\drivers\nplalqix.sys [?]
S1 ntkkulmb;ntkkulmb;\??\c:\windows\system32\drivers\ntkkulmb.sys –> c:\windows\system32\drivers\ntkkulmb.sys [?]
S1 ntrsrote;ntrsrote;\??\c:\windows\system32\drivers\ntrsrote.sys –> c:\windows\system32\drivers\ntrsrote.sys [?]
S1 obqyotvj;obqyotvj;\??\c:\windows\system32\drivers\obqyotvj.sys –> c:\windows\system32\drivers\obqyotvj.sys [?]
S1 ofbhwhoy;ofbhwhoy;\??\c:\windows\system32\drivers\ofbhwhoy.sys –> c:\windows\system32\drivers\ofbhwhoy.sys [?]
S1 ofeqbixu;ofeqbixu;\??\c:\windows\system32\drivers\ofeqbixu.sys –> c:\windows\system32\drivers\ofeqbixu.sys [?]
S1 pijyljkw;pijyljkw;\??\c:\windows\system32\drivers\pijyljkw.sys –> c:\windows\system32\drivers\pijyljkw.sys [?]
S1 piqtlxcr;piqtlxcr;\??\c:\windows\system32\drivers\piqtlxcr.sys –> c:\windows\system32\drivers\piqtlxcr.sys [?]
S1 rcuvekjg;rcuvekjg;\??\c:\windows\system32\drivers\rcuvekjg.sys –> c:\windows\system32\drivers\rcuvekjg.sys [?]
S1 rsngpasp;rsngpasp;\??\c:\windows\system32\drivers\rsngpasp.sys –> c:\windows\system32\drivers\rsngpasp.sys [?]
S1 sqsglmpd;sqsglmpd;\??\c:\windows\system32\drivers\sqsglmpd.sys –> c:\windows\system32\drivers\sqsglmpd.sys [?]
S1 tbpgyhib;tbpgyhib;\??\c:\windows\system32\drivers\tbpgyhib.sys –> c:\windows\system32\drivers\tbpgyhib.sys [?]
S1 tdctjwfr;tdctjwfr;\??\c:\windows\system32\drivers\tdctjwfr.sys –> c:\windows\system32\drivers\tdctjwfr.sys [?]
S1 tdnzoxvi;tdnzoxvi;\??\c:\windows\system32\drivers\tdnzoxvi.sys –> c:\windows\system32\drivers\tdnzoxvi.sys [?]
S1 twmxhavm;twmxhavm;\??\c:\windows\system32\drivers\twmxhavm.sys –> c:\windows\system32\drivers\twmxhavm.sys [?]
S1 udngpust;udngpust;\??\c:\windows\system32\drivers\udngpust.sys –> c:\windows\system32\drivers\udngpust.sys [?]
S1 ugkhxqdo;ugkhxqdo;\??\c:\windows\system32\drivers\ugkhxqdo.sys –> c:\windows\system32\drivers\ugkhxqdo.sys [?]
S1 uufpnfar;uufpnfar;\??\c:\windows\system32\drivers\uufpnfar.sys –> c:\windows\system32\drivers\uufpnfar.sys [?]
S1 vqvlilmx;vqvlilmx;\??\c:\windows\system32\drivers\vqvlilmx.sys –> c:\windows\system32\drivers\vqvlilmx.sys [?]
S1 vuxhotuy;vuxhotuy;\??\c:\windows\system32\drivers\vuxhotuy.sys –> c:\windows\system32\drivers\vuxhotuy.sys [?]
S1 waegznlf;waegznlf;\??\c:\windows\system32\drivers\waegznlf.sys –> c:\windows\system32\drivers\waegznlf.sys [?]
S1 xtvuejyq;xtvuejyq;\??\c:\windows\system32\drivers\xtvuejyq.sys –> c:\windows\system32\drivers\xtvuejyq.sys [?]
S1 ygeafpkf;ygeafpkf;\??\c:\windows\system32\drivers\ygeafpkf.sys –> c:\windows\system32\drivers\ygeafpkf.sys [?]
S1 zemqhyyk;zemqhyyk;\??\c:\windows\system32\drivers\zemqhyyk.sys –> c:\windows\system32\drivers\zemqhyyk.sys [?]
S2 elAPIsvc;elAPI - Service Server;c:\program files\DOS2USB\elsvc.exe [10/14/2010 5:08 PM 45056]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2011 4:58 PM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 3:33 PM 253600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2011 4:58 PM 136176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 β€”-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-13 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 19:33]
.
2012-04-14 c:\windows\Tasks\Free File Viewer Update Checker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2011-02-16 21:50]
.
2012-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 20:58]
.
2012-04-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 20:58]
.
2012-04-14 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2012-03-23 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2012-04-14 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 21:31]
.
2012-04-13 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=5080904
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: bxcleve.com\www
Trusted Zone: bxohio.com\www
Trusted Zone: private-planroom.com\subs
Trusted Zone: private-planroom.com\www
TCP: DhcpNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{1335B6E7-E3A1-4A35-B017-7332703EB27C}: NameServer = 166.102.165.11,207.91.5.20
DPF: {4A769165-055C-4566-ABBB-3EA82DD4F8AE} - hxxp://www.ipinviewer.com/binInstall/IVSLite.CAB
.
.
β€”β€”- File Associations β€”β€”-
.
.scr=DWGTrueViewScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
BHO-{C4B8BAB4-1667-11DF-A242-BA9455D89593} - c:\program files\simppulltoolbar\auxi\simppulltoolbAu.dll
BHO-{E4E6BF2A-1667-11DF-A01F-1F9655D89593} - (no file)
HKCU-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
HKLM-Run-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe
MSConfigStartUp-Pvolago - c:\windows\dpgmsavc.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-14 10:54
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”
.
- - - - - - - > 'winlogon.exe'(944)
c:\windows\System32\BCMLogon.dll
.
Completion time: 2012-04-14 10:55:30
ComboFix-quarantined-files.txt 2012-04-14 14:55
ComboFix2.txt 2010-11-08 13:59
.
Pre-Run: 124,507,447,296 bytes free
Post-Run: 126,002,028,544 bytes free
.
- - End Of File - - 956018A0EC30CEB80B9EA611D18536AC
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here.

Open notepad and copy/paste the text in the code box below into it (including the URL, excluding "CODE"):

http://forums.whatthetech.com/index.php?showtopic=122889

Collect::
c:\windows\system32\drivers\bbyljlnw.sys
c:\windows\system32\drivers\bgtrgkhs.sys
c:\windows\system32\drivers\clzpbvlb.sys
c:\windows\system32\drivers\cufczslm.sys
c:\windows\system32\drivers\eiuvmzcq.sys
c:\windows\system32\drivers\erkjgnif.sys
c:\windows\system32\drivers\fhttknqq.sys
c:\windows\system32\drivers\fimufhfu.sys
c:\windows\system32\drivers\futndtiw.sys 
c:\windows\system32\drivers\gclurjnt.sys
c:\windows\system32\drivers\hqaubcrq.sys
c:\windows\system32\drivers\hthncqvz.sys
c:\windows\system32\drivers\hyenzaut.sys
c:\windows\system32\drivers\jbiwfqbk.sys
c:\windows\system32\drivers\jwwrvecv.sys
c:\windows\system32\drivers\kwuqfndo.sys
c:\windows\system32\drivers\laegbejf.sys
c:\windows\system32\drivers\mzspbfes.sys
c:\windows\system32\drivers\njmqufaa.sys
c:\windows\system32\drivers\nplalqix.sys
c:\windows\system32\drivers\ntkkulmb.sys
c:\windows\system32\drivers\ntrsrote.sys
c:\windows\system32\drivers\obqyotvj.sys
c:\windows\system32\drivers\ofbhwhoy.sys
c:\windows\system32\drivers\ofeqbixu.sys
c:\windows\system32\drivers\pijyljkw.sys
c:\windows\system32\drivers\piqtlxcr.sys
c:\windows\system32\drivers\rcuvekjg.sys
c:\windows\system32\drivers\rsngpasp.sys
c:\windows\system32\drivers\sqsglmpd.sys
c:\windows\system32\drivers\tbpgyhib.sys
c:\windows\system32\drivers\tdctjwfr.sys
c:\windows\system32\drivers\tdnzoxvi.sys
c:\windows\system32\drivers\twmxhavm.sys
c:\windows\system32\drivers\udngpust.sys
c:\windows\system32\drivers\ugkhxqdo.sys
c:\windows\system32\drivers\uufpnfar.sys
c:\windows\system32\drivers\vqvlilmx.sys
c:\windows\system32\drivers\vuxhotuy.sys
c:\windows\system32\drivers\waegznlf.sys
c:\windows\system32\drivers\xtvuejyq.sys
c:\windows\system32\drivers\ygeafpkf.sys
c:\windows\system32\drivers\zemqhyyk.sys

Driver::
bbyljlnw
bgtrgkhs
clzpbvlb
cufczslm
eiuvmzcq
erkjgnif
fhttknqq
fimufhfu
futndtiw
gclurjnt
hqaubcrq
hthncqvz
hyenzaut
jbiwfqbk
jwwrvecv
kwuqfndo
laegbejf
mzspbfes
njmqufaa
nplalqix
ntkkulmb
ntrsrote
obqyotvj
ofbhwhoy
ofeqbixu
pijyljkw
piqtlxcr
rcuvekjg
rsngpasp
sqsglmpd
tbpgyhib
tdctjwfr
tdnzoxvi
twmxhavm
udngpust
ugkhxqdo
uufpnfar
vqvlilmx
vuxhotuy
waegznlf
xtvuejyq
ygeafpkf
zemqhyyk

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Referring to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you. Post that log in your next reply.

**Note**

When CF finishes running, the ComboFix log will open along with a message box–do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.
  • Ensure you are connected to the internet and click OK on the message box.
Hi Michael

Posted below is the lates ComboFix log:

ComboFix 12-04-14.02 - Jeff 04/15/2012 12:10:46.4.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3062.2531 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jeff\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
β€”β€”-\Service_bbyljlnw
β€”β€”-\Service_bgtrgkhs
β€”β€”-\Service_clzpbvlb
β€”β€”-\Service_cufczslm
β€”β€”-\Service_eiuvmzcq
β€”β€”-\Service_erkjgnif
β€”β€”-\Service_fhttknqq
β€”β€”-\Service_fimufhfu
β€”β€”-\Service_futndtiw
β€”β€”-\Service_gclurjnt
β€”β€”-\Service_hqaubcrq
β€”β€”-\Service_hthncqvz
β€”β€”-\Service_hyenzaut
β€”β€”-\Service_jbiwfqbk
β€”β€”-\Service_jwwrvecv
β€”β€”-\Service_kwuqfndo
β€”β€”-\Service_laegbejf
β€”β€”-\Service_mzspbfes
β€”β€”-\Service_njmqufaa
β€”β€”-\Service_nplalqix
β€”β€”-\Service_ntkkulmb
β€”β€”-\Service_ntrsrote
β€”β€”-\Service_obqyotvj
β€”β€”-\Service_ofbhwhoy
β€”β€”-\Service_ofeqbixu
β€”β€”-\Service_pijyljkw
β€”β€”-\Service_piqtlxcr
β€”β€”-\Service_rcuvekjg
β€”β€”-\Service_rsngpasp
β€”β€”-\Service_sqsglmpd
β€”β€”-\Service_tbpgyhib
β€”β€”-\Service_tdctjwfr
β€”β€”-\Service_tdnzoxvi
β€”β€”-\Service_twmxhavm
β€”β€”-\Service_udngpust
β€”β€”-\Service_ugkhxqdo
β€”β€”-\Service_uufpnfar
β€”β€”-\Service_vqvlilmx
β€”β€”-\Service_vuxhotuy
β€”β€”-\Service_waegznlf
β€”β€”-\Service_xtvuejyq
β€”β€”-\Service_ygeafpkf
β€”β€”-\Service_zemqhyyk
.
.
((((((((((((((((((((((((( Files Created from 2012-03-15 to 2012-04-15 )))))))))))))))))))))))))))))))
.
.
2012-04-15 16:17 . 2012-04-15 16:17 ——– dβ€”a-w- c:\documents and settings\All Users\Application Data\TEMP
2012-04-15 16:17 . 2012-04-15 16:17 9310 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXTBOX.JS
2012-04-15 16:17 . 2012-04-15 16:17 8646 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TILEBOX.JS
2012-04-15 16:17 . 2012-04-15 16:17 6429 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\UICORE.JS
2012-04-15 16:17 . 2012-04-15 16:17 63115 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\USERTILE.JS
2012-04-15 16:17 . 2012-04-15 16:17 5927 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\IdentityCRL\production\temp\wlidui_WLIDSVC\TEXT.JS
2012-04-14 15:02 . 2012-03-13 23:15 6582328 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8DE75DEF-BBB0-4C35-80C3-DF28ADD0743F}\mpengine.dll
2012-04-13 12:29 . 2012-04-13 12:29 ——– d—–w- c:\documents and settings\Jeff\Local Settings\Application Data\PCHealth
2012-04-03 19:33 . 2012-04-03 19:33 418464 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-04-04 19:56 . 2010-08-26 12:41 22344 β€”-a-w- c:\windows\system32\drivers\mbam.sys
2012-04-03 19:33 . 2012-04-03 19:33 418464 β€”-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-04-03 19:33 . 2011-05-19 11:54 70304 β€”-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-03-13 23:15 . 2012-04-14 15:02 6582328 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{8DE75DEF-BBB0-4C35-80C3-DF28ADD0743F}\mpengine.dll
2012-03-13 23:15 . 2011-06-27 11:58 6582328 β€”-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-03-01 11:01 . 2008-04-25 16:16 916992 β€”-a-w- c:\windows\system32\wininet.dll
2012-03-01 11:01 . 2008-04-25 16:16 43520 β€”-a-w- c:\windows\system32\licmgr10.dll
2012-03-01 11:01 . 2008-04-25 16:16 1469440 β€”-a-w- c:\windows\system32\inetcpl.cpl
2012-02-29 14:10 . 2008-04-25 16:16 177664 β€”-a-w- c:\windows\system32\wintrust.dll
2012-02-29 14:10 . 2008-04-25 16:16 148480 β€”-a-w- c:\windows\system32\imagehlp.dll
2012-02-29 12:17 . 2008-04-25 16:16 385024 β€”-a-w- c:\windows\system32\html.iec
2012-02-03 09:22 . 2008-04-25 16:16 1860096 β€”-a-w- c:\windows\system32\win32k.sys
2012-01-31 12:44 . 2011-06-25 15:02 237072 β€”β€”w- c:\windows\system32\MpSigStub.exe
2012-01-20 15:33 . 2012-01-20 15:33 255352 β€”-a-w- c:\windows\system32\awrdscdc.ax
.
.
((((((((((((((((((((((((((((( SnapShot@2012-04-14_14.54.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-15 16:16 . 2012-04-15 16:16 16384 c:\windows\Temp\Perflib_Perfdata_748.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{00000000-6E41-4FD3-8538-502F5495E5FC}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{00000000-6e41-4fd3-8538-502f5495e5fc}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
2012-01-03 21:31 1514152 β€”-a-w- c:\program files\Ask.com\GenericAskToolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2012-01-03 1514152]
.
[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]
[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]
[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"DellAutomatedPCTuneUp"="c:\program files\DellAutomatedPCTuneUp\PTAgnt.exe" [2007-10-11 465136]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-02-21 159744]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-21 16855552]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-22 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-22 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-22 137752]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-06-30 2220032]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2008-02-22 1245184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-02-26 128296]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"ApnUpdater"="c:\program files\Ask.com\Updater\Updater.exe" [2012-01-03 1391272]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - c:\windows\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2008-9-4 7168]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\WINDOWS\\system32\\dkabcoms.exe"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
.
R2 dkab_device;dkab_device;c:\windows\system32\DKabcoms.exe -service –> c:\windows\system32\DKabcoms.exe -service [?]
R2 elAPIsvc;elAPI - Service Server;c:\program files\DOS2USB\elsvc.exe [10/14/2010 5:08 PM 45056]
R3 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [9/4/2008 3:25 PM 48472]
R3 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [9/4/2008 3:25 PM 43480]
S?2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2011 4:58 PM 136176]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 3:33 PM 253600]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [10/18/2011 4:58 PM 136176]
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 08:32 128512 β€”-a-w- c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-14 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 19:33]
.
2012-04-15 c:\windows\Tasks\Free File Viewer Update Checker.job
- c:\program files\FreeFileViewer\FFVCheckForUpdates.exe [2011-02-16 21:50]
.
2012-04-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 20:58]
.
2012-04-14 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-10-18 20:58]
.
2012-04-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
2012-03-23 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2010-11-18 15:13]
.
2012-04-15 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
- c:\program files\Ask.com\UpdateTask.exe [2012-01-03 21:31]
.
2012-04-15 c:\windows\Tasks\SystemToolsDailyTest.job
- c:\program files\Dell Support Center\pcdrcui.exe [2010-11-18 15:13]
.
.
β€”β€”- Supplementary Scan β€”β€”-
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=5080904
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
Trusted Zone: bxcleve.com\www
Trusted Zone: bxohio.com\www
Trusted Zone: private-planroom.com\subs
Trusted Zone: private-planroom.com\www
TCP: DhcpNameServer = 192.168.254.254 192.168.254.254
TCP: Interfaces\{1335B6E7-E3A1-4A35-B017-7332703EB27C}: NameServer = 166.102.165.11,207.91.5.20
DPF: {4A769165-055C-4566-ABBB-3EA82DD4F8AE} - hxxp://www.ipinviewer.com/binInstall/IVSLite.CAB
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-04-15 12:18
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
β€”β€”β€”β€”β€”β€”β€” DLLs Loaded Under Running Processes β€”β€”β€”β€”β€”β€”β€”
.
- - - - - - - > 'winlogon.exe'(944)
c:\windows\System32\BCMLogon.dll
.
- - - - - - - > 'explorer.exe'(2700)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
β€”β€”β€”β€”β€”β€”β€”β€” Other Running Processes β€”β€”β€”β€”β€”β€”β€”β€”
.
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\windows\system32\DKabcoms.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxsrvc.exe
c:\program files\DellTPad\ApMsgFwd.exe
c:\program files\DellTPad\HidFind.exe
c:\program files\DellTPad\Apntex.exe
c:\program files\Dell Network Assistant\ezi_hnm2.exe
c:\windows\system32\imapi.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2012-04-15 12:19:32 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-15 16:19
ComboFix2.txt 2010-11-08 13:59
.
Pre-Run: 125,986,955,264 bytes free
Post-Run: 125,927,813,120 bytes free
.
- - End Of File - - A0A71552FFFE5DB7BC6019B988D23D56
I should let you know that Ask Toolbar modifies your browser. You can read more about it here. Would you like to keep it or remove it?

  • Malwarebytes' Anti-Malware

    It seems you already have MBAM installed. If not, you can download the installer here.

    • Once the program has loaded, click the Update tab and Check for Updates to get the latest version.
    • Click the Scanner tab, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When completed, a log will open in Notepad. This log is saved by MBAM and can be viewed by clicking the Logs tab.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
  • TFC

    Download TFC to your desktop

    • Close any open windows.
    • Double click the TFC icon to run the program
    • TFC will close all open programs itself in order to run.
    • Click the Start button to begin the process.
    • Allow TFC to run uninterrupted.
    • The program should not take long to finish its job.
    • Once it's finished it should automatically reboot your machine.
    • If it doesn't, manually reboot to ensure a complete clean.
  • ESET Online Scanner

    Please disable any real-time security programs such as your anti-virus before proceeding with this scan.

    • Open Internet Explorer.
    • Download ESET Online Scanner.
    • Put a checkmark in the checkbox next to YES, I accept the Terms of Use.
    • Click Start.
    • When prompted by your web browser, click Install.
    • Uncheck Remove found threats.
    • Check Scan archives.
    • Click Start and let the scanner finish downloading virus signatures. The scan will begin afterward.
    • When the scan completes, click List of found threats.
    • Click Export to text file… and save the file to your desktop.
    • Click Back.
    • Click Finish.
Please post the contents of the MBAM and ESET logs in your next reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI