This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect - Please help [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Having increasing problems with the Google redirect virus. I have scanned with Hijack This and the results are as follows.



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:24:03 PM, on 10/18/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\McAfee Security Scan\2.1.121\SSScheduler.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Gwill\Desktop\HiJackThis.exe

O16 - DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} (UltraHVCamX Class) - http://hnshelby.dyndns.org/UltraHVCamX.cab
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} (WMI Class) - https://support.dell.com/systemprofiler/SysProExe.CAB
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Unknown owner - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.1.121\McCHSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - Unknown owner - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 4173 bytes



Any help would be greatly appreciated.
Thanks, Greg

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, Greg

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.
Hello there,

Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.com
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
===================================================

Please download aswMBR.exe and save it to your desktop.
  • Double click aswMBR.exe to start the tool. (Vista/Windows 7 users - right click to run as administrator)
  • Allow it to update where necessary
  • Click Scan

  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
===================================================

Download TDSSKiller.exe and save it to your desktop

Execute TDSSKiller.exe by doubleclicking on it.
Press Start Scan
If Malicious objects are found, do NOT select Cure. Change the action to Skip, and save the log.
Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.log.txt

===================================================

On your next reply please post :
DDS log
aswMBR log
TDSSKiller log

Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Conspire, Sorry for the delay. I could not get TDSKiller to open. Here is the other information you had requested. Thanks, Greg SDDS (Ver_2012-10-19.01) - NTFS_x86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2 Run by [removed] at 9:07:39 on 2012-10-20 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.696 [GMT -4:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\atiesrxx.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\System32\rundll32.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\taskeng.exe C:\Program Files\Dell Support Center\uaclauncher.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Live\Mail\wlmail.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxps://www.google.com/ uWindow Title = Internet Explorer provided by Dell uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3071116 uURLSearchHooks: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Apple] rundll32.exe c:\users\gwill\appdata\local\apple\reegpadn.dll,DllUnregisterServer mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ECenter] c:\dell\e-center\EULALauncher.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre7\bin\jp2iexp.dll LSP: mswsock.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} - hxxp://hnshelby.dyndns.org/UltraHVCamX.cab DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.2.1 TCP: Interfaces\{E393E313-4DFC-443B-8446-CC200B06B290} : DHCPNameServer = 192.168.2.1 LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg . ============= SERVICES / DRIVERS =============== . R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-4-20 176128] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-21 21504] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-4-20 7772160] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-4-20 243712] S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-3 250808] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664] S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2012-8-17 22640] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-6-21 16896] . =============== Created Last 30 ================ . 2012-10-05 17:38:19 ——– d—–w- C:\TDSSKiller_Quarantine 2012-10-04 23:46:12 ——– d-sh–w- c:\windows\system32\%APPDATA% 2012-10-04 00:18:32 ——– d—–w- c:\program files\VideoLAN 2012-10-02 21:27:14 6980552 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{88fdc249-a26d-4bef-94ec-b96dbf067953}\mpengine.dll . ==================== Find3M ==================== . 2012-10-11 01:28:36 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-11 01:28:36 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-05 17:40:20 66560 —-a-w- c:\windows\system32\drivers\smb.sys 2012-09-19 23:22:01 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-09-19 23:21:52 821736 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-09-19 23:21:52 746984 —-a-w- c:\windows\system32\deployJava1.dll 2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb . ============= FINISH: 9:08:58.53 =============== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-10-20 10:01:42 —————————– 10:01:42.572 OS Version: Windows 6.0.6002 Service Pack 2 10:01:42.572 Number of processors: 2 586 0x6B02 10:01:42.588 ComputerName: GWILL-DESKTOP UserName: Gwill 10:02:02.228 Initialize success 10:02:19.310 AVAST engine defs: 12102000 10:02:32.929 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000004d 10:02:32.929 Disk 0 Vendor: SAMSUNG_ CR10 Size: 476940MB BusType: 6 10:02:32.944 Disk 0 MBR read successfully 10:02:32.944 Disk 0 MBR scan 10:02:32.960 Disk 0 Windows VISTA default MBR code 10:02:32.960 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 47 MB offset 63 10:02:32.991 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 98304 10:02:33.007 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 466651 MB offset 21069824 10:02:33.022 Disk 0 scanning sectors +976771072 10:02:33.163 Disk 0 scanning C:\Windows\system32\drivers 10:02:46.033 Service scanning 10:03:07.467 Modules scanning 10:03:18.543 Disk 0 trace - called modules: 10:03:18.574 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys nvstor32.sys ndis.sys nvmfdx32.sys 10:03:18.574 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85a164d8] 10:03:18.590 3 CLASSPNP.SYS[885a58b3] -> nt!IofCallDriver -> [0x84a744f8] 10:03:18.590 5 acpi.sys[82a0b6bc] -> nt!IofCallDriver -> \Device\0000004d[0x84a6f4a0] 10:03:19.588 AVAST engine scan C:\Windows 10:03:28.902 AVAST engine scan C:\Windows\system32 10:06:25.821 File: C:\Windows\assembly\GAC\Desktop.ini **INFECTED** Win32:Sirefef-PL [Rtk] 10:07:48.462 AVAST engine scan C:\Windows\system32\drivers 10:08:10.961 AVAST engine scan C:\Users\Gwill 10:08:11.342 File: C:\Users\Gwill\AppData\Local\Apple\reegpadn.dll **INFECTED** Win32:Tracur-IJ [Trj] 10:11:01.361 Disk 0 MBR has been saved successfully to "C:\Users\Gwill\Desktop\MBR.dat" 10:11:01.371 The log file has been saved successfully to "C:\Users\Gwill\Desktop\aswMBR.txt"
Hello Greg,

Please read through these instructions to familiarize yourself with what to expect when this tool runs

Refer to the ComboFix User's Guide


Download ComboFix from one of these locations:

Link 1
Link 2



* IMPORTANT- Save ComboFix.exe to your Desktop

====================================================


Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs


====================================================


Double click on combofix.exe & follow the prompts.


When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply for further review.
conspire,
I ran Combofix and these are the results.

ComboFix 12-10-19.01 - Gwill 10/20/2012 13:00:18.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1235 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\$recycle.bin\S-1-5-18\$e4547d5306294d448f43a6a348142b53\@
c:\$recycle.bin\S-1-5-18\$e4547d5306294d448f43a6a348142b53\n
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\n
c:\programdata\0tbpw.pad
c:\programdata\PCDr\6032\AddOnDownloaded\af728edb-0984-4c06-9a4b-0878bcfa9a26.dll
c:\windows\$NtUninstallKB29984$
c:\windows\$NtUninstallKB29984$\1503472829\L\00000004.@
c:\windows\$NtUninstallKB29984$\1503472829\L\201d3dde
c:\windows\$NtUninstallKB29984$\1503472829\L\qnbwvoto
c:\windows\assembly\GAC\Desktop.ini
D:\install.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-20 to 2012-10-20 )))))))))))))))))))))))))))))))
.
.
2012-10-05 17:38 . 2012-10-05 17:38 ——– d—–w- C:\TDSSKiller_Quarantine
2012-10-04 23:46 . 2012-10-04 23:46 ——– d-sh–w- c:\windows\system32\%APPDATA%
2012-10-04 00:19 . 2012-10-20 12:44 ——– d—–w- c:\users\Gwill\AppData\Roaming\vlc
2012-10-04 00:18 . 2012-10-04 00:18 ——– d—–w- c:\program files\VideoLAN
2012-10-02 21:27 . 2012-08-30 08:17 6980552 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{88FDC249-A26D-4BEF-94EC-B96DBF067953}\mpengine.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-11 01:28 . 2012-04-03 19:42 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 01:28 . 2011-06-01 17:10 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-05 17:40 . 2010-10-09 13:30 66560 —-a-w- c:\windows\system32\drivers\smb.sys
2012-09-19 23:22 . 2012-09-19 23:22 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-19 23:21 . 2012-06-04 02:09 821736 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-09-19 23:21 . 2010-08-14 12:38 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-24 06:51 . 2012-09-22 11:02 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:47 . 2012-09-22 11:02 420864 —-a-w- c:\windows\system32\vbscript.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Apple"="c:\users\Gwill\AppData\Local\Apple\reegpadn.dll" [2012-09-08 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-23 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-23 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-23 81920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-03-27 421736]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-11-15 50688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 01:28]
.
2012-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 23:36]
.
2012-10-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 23:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://www.google.com/
TCP: DhcpNameServer = 192.168.2.1
DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} - hxxp://hnshelby.dyndns.org/UltraHVCamX.cab
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - (no file)
Toolbar-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
SafeBoot-87162842.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-20 13:10
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Apple = rundll32.exe c:\users\Gwill\AppData\Local\Apple\reegpadn.dll,DllUnregisterServer?3456789
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(3256)
c:\users\Gwill\AppData\Local\Apple\reegpadn.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\RtHDVCpl.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\System32\rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Completion time: 2012-10-20 13:14:54 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-20 17:14
.
Pre-Run: 10,335,608,832 bytes free
Post-Run: 10,242,097,152 bytes free
.
- - End Of File - - 960DD0658BDEE9CEA08A2DF5AAA32631
Ran TDSSKiller, it did not find anything. I still have an issue with using links from e-mail. Every time I click on one it tries to open in an "InPrivate" window which is just a blank page. I have to close that window and copy & past the links into my browser. This occurred at the same time as the redirect issue.
That is for sure, the infection is still showing in the log.

Download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

On the System Recovery Options menu you will get the following options:Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt

[*]Select Command Prompt

[*]In the command window type in notepad and press Enter.

[*]The notepad opens. Under File menu select Open.

[*]Select "Computer" and find your flash drive letter and close the notepad.

[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter

Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.

[*]When the tool opens click Yes to disclaimer.

[*]Press Scan button.

[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.

Conspire, Here are the results. Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 21-10-2012 Ran by [removed] at 21-10-2012 09:16:14 Running from I:\ Windows Vista ™ Home Premium (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\…\Run: [RtHDVCpl] RtHDVCpl.exe [x] HKLM\…\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start [81920 2005-02-16] (InstallShield Software Corporation) HKLM\…\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [61440 2008-01-21] (Advanced Micro Devices, Inc.) HKLM\…\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [39792 2008-10-14] (Adobe Systems Incorporated) HKLM\…\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart [86016 2007-09-22] (NVIDIA Corporation) HKLM\…\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup [8429568 2007-09-22] (NVIDIA Corporation) HKLM\…\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit [81920 2007-09-22] (NVIDIA Corporation) HKLM\…\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59280 2012-08-27] (Apple Inc.) HKLM\…\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" [252848 2012-07-03] (Sun Microsystems, Inc.) HKLM\…\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup [221184 2006-10-03] (Macrovision Corporation) HKLM\…\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe [17920 2007-05-24] ( ) HKLM\…\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" [421776 2012-09-09] (Apple Inc.) HKU\Default\…\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [460784 2007-03-15] (Gteko Ltd.) HKU\Default User\…\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup [460784 2007-03-15] (Gteko Ltd.) HKU\Gwill\…\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-18] (Microsoft Corporation) HKU\Gwill\…\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-18] (Microsoft Corporation) HKU\Gwill\…\Run: [Apple] rundll32.exe C:\Users\Gwill\AppData\Local\Apple\reegpadn.dll,DllUnregisterServer [354304 2012-09-07] () Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Startup: C:\Users\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software ) ==================== Services (Whitelisted) =================== 2 AERTFilters; C:\Windows\System32\AERTSrv.exe [77824 2007-12-05] (Andrea Electronics Corporation) 3 DSBrokerService; "C:\Program Files\DellSupport\brkrsvc.exe" [70656 2007-03-19] () 3 WLSetupSvc; "C:\Program Files\Windows Live\installer\WLSetupSvc.exe" [266240 2007-10-25] (Microsoft Corporation) 2 aawservice; "C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe" [x] 2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter [x] ==================== Drivers (Whitelisted) ==================== 4 blbdrive; C:\Windows\system32\drivers\blbdrive.sys [x] 3 catchme; \??\C:\Users\Gwill\AppData\Local\Temp\catchme.sys [x] 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys [x] 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys [x] 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys [x] 3 PCDSRVC{E9D79540-57D5953E-06020200}_0; \??\c:\program files\dell support center\pcdsrvc.pkms [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2012-10-21 09:16 - 2012-10-21 09:16 - 00000000 ____D C:\FRST 2012-10-20 10:14 - 2012-10-20 10:16 - 00000000 ___SD C:\ComboFix 2012-10-20 10:10 - 2012-10-20 10:10 - 00001666 ____A C:\Users\Public\Desktop\iTunes.lnk 2012-10-20 10:09 - 2012-10-20 10:09 - 00000000 ____D C:\Program Files\iPod 2012-10-20 10:09 - 2012-08-21 09:01 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys 2012-10-20 10:08 - 2012-10-20 10:09 - 00000000 ____D C:\Users\All Users\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-10-20 10:08 - 2012-10-20 10:09 - 00000000 ____D C:\Program Files\iTunes 2012-10-20 10:04 - 2012-10-20 10:04 - 00000000 ____D C:\Program Files\Bonjour 2012-10-20 09:47 - 2012-10-20 09:47 - 02213464 ____A (Kaspersky Lab ZAO) C:\Users\Gwill\Desktop\tdsskiller.exe 2012-10-20 08:47 - 2012-10-20 10:14 - 00000000 ___AD C:\Qoobox 2012-10-20 08:47 - 2012-10-20 09:13 - 00000000 ____D C:\Windows\erdnt 2012-10-20 08:47 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe 2012-10-20 08:47 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe 2012-10-20 08:47 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2012-10-20 08:47 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2012-10-20 08:47 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2012-10-20 08:47 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe 2012-10-20 08:47 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe 2012-10-20 08:47 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe 2012-10-20 08:45 - 2012-10-20 08:46 - 04984242 ____R (Swearware) C:\Users\Gwill\Desktop\ComboFix.exe 2012-10-20 06:13 - 2012-10-20 06:13 - 00000565 ____A C:\Users\Gwill\Desktop\MBR.zip 2012-10-20 06:11 - 2012-10-20 06:11 - 00002133 ____A C:\Users\Gwill\Desktop\aswMBR.txt 2012-10-20 06:11 - 2012-10-20 06:11 - 00000512 ____A C:\Users\Gwill\Desktop\MBR.dat 2012-10-20 05:37 - 2012-10-21 05:07 - 00108122 ____A C:\Windows\WindowsUpdate.log 2012-10-20 05:35 - 2012-10-21 04:51 - 00000714 ____A C:\Windows\setupact.log 2012-10-20 05:35 - 2012-10-20 05:35 - 00000000 ____A C:\Windows\setuperr.log 2012-10-20 05:11 - 2012-10-20 05:13 - 04731392 ____A (AVAST Software) C:\Users\Gwill\Desktop\aswMBR.exe 2012-10-20 05:09 - 2012-10-20 05:10 - 00009663 ____A C:\Users\Gwill\Desktop\dds.txt 2012-10-20 05:09 - 2012-10-20 05:10 - 00004247 ____A C:\Users\Gwill\Desktop\attach.txt 2012-10-19 02:31 - 2012-10-19 02:31 - 00687724 ____A (Swearware) C:\Users\Gwill\Desktop\dds.pif 2012-10-19 02:30 - 2012-10-19 02:30 - 00687724 ____R (Swearware) C:\Users\Gwill\Desktop\dds.com 2012-10-19 02:17 - 2012-10-20 10:42 - 00002476 ____A C:\Windows\PFRO.log 2012-10-18 18:24 - 2012-10-18 18:24 - 00004174 ____A C:\Users\Gwill\Desktop\hijackthis.log 2012-10-18 18:22 - 2012-10-18 18:22 - 00388608 ____A (Trend Micro Inc.) C:\Users\Gwill\Desktop\HiJackThis.exe 2012-10-18 17:54 - 2012-10-18 17:54 - 00135221 ____A C:\Users\Gwill\Desktop\bookmark 10.12.htm 2012-10-16 16:55 - 2012-10-16 16:56 - 00002936 ____A C:\Users\Gwill\Documents\cc_20121016_205548.reg 2012-10-14 18:27 - 2012-10-14 18:27 - 00016430 ____A C:\Users\Gwill\Desktop\PASSWORDS.ods 2012-10-14 18:02 - 2012-10-14 18:02 - 01325940 ____A C:\Users\Gwill\Desktop\Apr_6_Rush.wmv 2012-10-05 17:13 - 2012-10-05 17:13 - 00009782 ____A C:\Users\Gwill\Documents\cc_20121005_211257.reg 2012-10-05 09:43 - 2012-10-05 09:45 - 00000000 ____D C:\Users\Gwill\Downloads\tdsskiller (1) 2012-10-05 09:43 - 2012-10-05 09:43 - 02193278 ____A C:\Users\Gwill\Downloads\tdsskiller (1).zip 2012-10-05 09:38 - 2012-10-05 09:38 - 00000000 ____D C:\TDSSKiller_Quarantine 2012-10-05 09:37 - 2012-10-18 17:58 - 00001502 ____A C:\Users\Gwill\Desktop\GooredFix.txt 2012-10-04 15:46 - 2012-10-04 15:46 - 00000000 __SHD C:\Windows\System32\%APPDATA% 2012-10-03 16:19 - 2012-10-20 04:44 - 00000000 ____D C:\Users\Gwill\AppData\Roaming\vlc 2012-10-03 16:19 - 2012-10-03 16:19 - 00000861 ____A C:\Users\Public\Desktop\VLC media player.lnk 2012-10-03 16:18 - 2012-10-03 16:18 - 00000000 ____D C:\Program Files\VideoLAN 2012-10-03 16:15 - 2012-10-03 16:16 - 22617148 ____A C:\Users\Gwill\Downloads\vlc-2.0.3-win32.exe 2012-09-22 03:44 - 2012-09-22 03:44 - 02193278 ____A C:\Users\Gwill\Downloads\tdsskiller.zip 2012-09-22 03:44 - 2012-09-22 03:44 - 00000000 ____D C:\Users\Gwill\Downloads\tdsskiller 2012-09-22 03:02 - 2012-08-23 23:27 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-09-22 03:02 - 2012-08-23 23:03 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-09-22 03:02 - 2012-08-23 22:59 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-09-22 03:02 - 2012-08-23 22:51 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-09-22 03:02 - 2012-08-23 22:51 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-09-22 03:02 - 2012-08-23 22:51 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-09-22 03:02 - 2012-08-23 22:49 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-09-22 03:02 - 2012-08-23 22:48 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-09-22 03:02 - 2012-08-23 22:47 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-09-22 03:02 - 2012-08-23 22:47 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-09-22 03:02 - 2012-08-23 22:47 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-09-22 03:02 - 2012-08-23 22:45 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-09-22 03:02 - 2012-08-23 22:44 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-09-22 03:02 - 2012-08-23 22:44 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-09-22 03:02 - 2012-08-23 22:43 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-09-22 03:02 - 2012-08-23 22:40 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll ==================== 3 Months Modified Files ================== 2012-10-21 05:09 - 2009-11-03 15:37 - 00000880 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2012-10-21 05:09 - 2006-11-02 05:01 - 00032602 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-10-21 05:09 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-10-21 05:09 - 2006-11-02 04:47 - 00003568 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2012-10-21 05:09 - 2006-11-02 04:47 - 00003568 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2012-10-21 05:07 - 2012-10-20 05:37 - 00108122 ____A C:\Windows\WindowsUpdate.log 2012-10-21 04:54 - 2006-11-02 02:33 - 00703214 ____A C:\Windows\System32\PerfStringBackup.INI 2012-10-21 04:51 - 2012-10-20 05:35 - 00000714 ____A C:\Windows\setupact.log 2012-10-20 10:42 - 2012-10-19 02:17 - 00002476 ____A C:\Windows\PFRO.log 2012-10-20 10:10 - 2012-10-20 10:10 - 00001666 ____A C:\Users\Public\Desktop\iTunes.lnk 2012-10-20 09:54 - 2009-11-03 15:37 - 00000884 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2012-10-20 09:47 - 2012-10-20 09:47 - 02213464 ____A (Kaspersky Lab ZAO) C:\Users\Gwill\Desktop\tdsskiller.exe 2012-10-20 09:43 - 2009-01-25 16:35 - 00000419 ____A C:\Windows\BRWMARK.INI 2012-10-20 09:43 - 2009-01-25 16:35 - 00000027 ____A C:\Windows\BRPP2KA.INI 2012-10-20 09:26 - 2012-04-03 11:42 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-10-20 09:09 - 2006-11-02 02:23 - 00000231 ____A C:\Windows\system.ini 2012-10-20 08:46 - 2012-10-20 08:45 - 04984242 ____R (Swearware) C:\Users\Gwill\Desktop\ComboFix.exe 2012-10-20 08:23 - 2008-04-02 16:35 - 00189440 ____A C:\Users\Gwill\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-10-20 06:13 - 2012-10-20 06:13 - 00000565 ____A C:\Users\Gwill\Desktop\MBR.zip 2012-10-20 06:11 - 2012-10-20 06:11 - 00002133 ____A C:\Users\Gwill\Desktop\aswMBR.txt 2012-10-20 06:11 - 2012-10-20 06:11 - 00000512 ____A C:\Users\Gwill\Desktop\MBR.dat 2012-10-20 05:55 - 2006-11-02 04:47 - 00346152 ____A C:\Windows\System32\FNTCACHE.DAT 2012-10-20 05:35 - 2012-10-20 05:35 - 00000000 ____A C:\Windows\setuperr.log 2012-10-20 05:13 - 2012-10-20 05:11 - 04731392 ____A (AVAST Software) C:\Users\Gwill\Desktop\aswMBR.exe 2012-10-20 05:10 - 2012-10-20 05:09 - 00009663 ____A C:\Users\Gwill\Desktop\dds.txt 2012-10-20 05:10 - 2012-10-20 05:09 - 00004247 ____A C:\Users\Gwill\Desktop\attach.txt 2012-10-20 04:57 - 2008-04-02 16:26 - 00087824 ____A C:\Users\Gwill\AppData\Local\GDIPFONTCACHEV1.DAT 2012-10-19 02:31 - 2012-10-19 02:31 - 00687724 ____A (Swearware) C:\Users\Gwill\Desktop\dds.pif 2012-10-19 02:30 - 2012-10-19 02:30 - 00687724 ____R (Swearware) C:\Users\Gwill\Desktop\dds.com 2012-10-18 18:24 - 2012-10-18 18:24 - 00004174 ____A C:\Users\Gwill\Desktop\hijackthis.log 2012-10-18 18:22 - 2012-10-18 18:22 - 00388608 ____A (Trend Micro Inc.) C:\Users\Gwill\Desktop\HiJackThis.exe 2012-10-18 17:58 - 2012-10-05 09:37 - 00001502 ____A C:\Users\Gwill\Desktop\GooredFix.txt 2012-10-18 17:54 - 2012-10-18 17:54 - 00135221 ____A C:\Users\Gwill\Desktop\bookmark 10.12.htm 2012-10-18 12:30 - 2008-04-02 18:32 - 00001752 ____A C:\Users\Gwill\AppData\Roaming\wklnhst.dat 2012-10-16 16:56 - 2012-10-16 16:55 - 00002936 ____A C:\Users\Gwill\Documents\cc_20121016_205548.reg 2012-10-15 12:22 - 2008-08-12 13:31 - 00001356 ____A C:\Users\Gwill\AppData\Local\d3d9caps.dat 2012-10-14 18:27 - 2012-10-14 18:27 - 00016430 ____A C:\Users\Gwill\Desktop\PASSWORDS.ods 2012-10-14 18:02 - 2012-10-14 18:02 - 01325940 ____A C:\Users\Gwill\Desktop\Apr_6_Rush.wmv 2012-10-10 17:28 - 2012-04-03 11:42 - 00696760 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2012-10-10 17:28 - 2011-06-01 09:10 - 00073656 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-10-05 17:13 - 2012-10-05 17:13 - 00009782 ____A C:\Users\Gwill\Documents\cc_20121005_211257.reg 2012-10-05 17:10 - 2012-07-24 03:56 - 00000806 ____A C:\Users\Public\Desktop\CCleaner.lnk 2012-10-05 09:43 - 2012-10-05 09:43 - 02193278 ____A C:\Users\Gwill\Downloads\tdsskiller (1).zip 2012-10-05 09:40 - 2010-10-09 05:30 - 00066560 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\smb.sys 2012-10-03 16:19 - 2012-10-03 16:19 - 00000861 ____A C:\Users\Public\Desktop\VLC media player.lnk 2012-10-03 16:16 - 2012-10-03 16:15 - 22617148 ____A C:\Users\Gwill\Downloads\vlc-2.0.3-win32.exe 2012-09-22 03:44 - 2012-09-22 03:44 - 02193278 ____A C:\Users\Gwill\Downloads\tdsskiller.zip 2012-09-19 15:22 - 2012-09-19 15:22 - 00093672 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge.dll 2012-09-19 15:21 - 2012-09-19 15:22 - 00246760 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2012-09-19 15:21 - 2012-09-19 15:22 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2012-09-19 15:21 - 2012-09-19 15:22 - 00174056 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2012-09-19 15:21 - 2012-06-03 18:09 - 00821736 ____A (Oracle Corporation) C:\Windows\System32\npdeployJava1.dll 2012-09-19 15:21 - 2010-08-14 04:38 - 00746984 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2012-09-12 07:15 - 2006-11-02 02:24 - 62164608 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2012-09-05 14:02 - 2012-09-05 14:02 - 00050688 ____A (Atribune.org) C:\Users\Gwill\Downloads\ATF_Cleaner (1).exe 2012-09-05 14:01 - 2012-09-05 14:01 - 00050688 ____A (Atribune.org) C:\Users\Gwill\Downloads\ATF_Cleaner.exe 2012-08-27 17:57 - 2012-08-27 17:57 - 00128650 ____A C:\Users\Gwill\Desktop\bookmark 8.12.htm 2012-08-27 12:09 - 2012-08-27 12:09 - 00002052 ____A C:\Windows\epplauncher.mif 2012-08-23 23:27 - 2012-09-22 03:02 - 12319744 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-23 23:03 - 2012-09-22 03:02 - 09738240 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-23 22:59 - 2012-09-22 03:02 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-08-23 22:51 - 2012-09-22 03:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-23 22:51 - 2012-09-22 03:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-23 22:51 - 2012-09-22 03:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-23 22:49 - 2012-09-22 03:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-23 22:48 - 2012-09-22 03:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-23 22:47 - 2012-09-22 03:02 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-08-23 22:47 - 2012-09-22 03:02 - 00420864 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2012-08-23 22:47 - 2012-09-22 03:02 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-08-23 22:45 - 2012-09-22 03:02 - 00607744 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2012-08-23 22:44 - 2012-09-22 03:02 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-23 22:44 - 2012-09-22 03:02 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-23 22:43 - 2012-09-22 03:02 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-08-23 22:40 - 2012-09-22 03:02 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-08-21 09:01 - 2012-10-20 10:09 - 00026840 ____A (GEAR Software Inc.) C:\Windows\System32\Drivers\GEARAspiWDM.sys 2012-08-21 09:01 - 2012-03-14 08:25 - 00106928 ____A (GEAR Software Inc.) C:\Windows\System32\GEARAspi.dll 2012-08-20 19:10 - 2012-08-20 19:10 - 00001678 ____A C:\Users\Gwill\Documents\cc_20120820_231027.reg 2012-08-20 02:44 - 2006-11-02 02:22 - 46923776 ____A C:\Windows\System32\config\software_previous 2012-08-20 02:44 - 2006-11-02 02:22 - 45350912 ____A C:\Windows\System32\config\components_previous 2012-08-20 02:44 - 2006-11-02 02:22 - 23330816 ____A C:\Windows\System32\config\system_previous 2012-08-20 02:44 - 2006-11-02 02:22 - 04980736 ____A C:\Windows\System32\config\default_previous 2012-08-20 02:44 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\security_previous 2012-08-20 02:44 - 2006-11-02 02:22 - 00262144 ____A C:\Windows\System32\config\sam_previous 2012-08-16 02:49 - 2010-09-09 06:47 - 00011264 ____A C:\Users\Gwill\Desktop\Fuel Consumption 2010.xlr 2012-07-28 16:58 - 2012-07-28 16:58 - 02136664 ____A (Kaspersky Lab ZAO) C:\Users\Gwill\Downloads\tdsskiller.exe 2012-07-24 04:01 - 2012-07-24 04:01 - 00001456 ____A C:\Users\Gwill\Documents\cc_20120724_080122.reg 2012-07-24 04:01 - 2012-07-24 04:01 - 00000174 ____A C:\Users\Gwill\Documents\cc_20120724_080141.reg 2012-07-24 04:01 - 2012-07-24 04:00 - 00147400 ____A C:\Users\Gwill\Documents\cc_20120724_080049.reg 2012-07-24 03:51 - 2012-07-24 03:51 - 03889704 ____A (Piriform Ltd) C:\Users\Gwill\Downloads\ccsetup320.exe ZeroAccess: C:\Users\Gwill\AppData\Local\{e4547d53-0629-4d44-8f43-a6a348142b53} C:\Users\Gwill\AppData\Local\{e4547d53-0629-4d44-8f43-a6a348142b53}\L C:\Users\Gwill\AppData\Local\{e4547d53-0629-4d44-8f43-a6a348142b53}\U ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\…\.exe: exefile => OK HKLM\…\exefile\DefaultIcon: %1 => OK HKLM\…\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2012-10-05 10:49:51 Restore point made on: 2012-10-12 15:02:13 Restore point made on: 2012-10-13 08:11:56 Restore point made on: 2012-10-20 04:46:06 Restore point made on: 2012-10-20 04:50:40 Restore point made on: 2012-10-20 04:52:02 Restore point made on: 2012-10-20 10:05:00 Restore point made on: 2012-10-20 10:05:49 Restore point made on: 2012-10-21 04:45:15 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 2045.88 MB Available physical RAM: 1780.21 MB Total Pagefile: 1977.55 MB Available Pagefile: 1850.63 MB Total Virtual: 2047.88 MB Available Virtual: 1983.72 MB ==================== Partitions ============================= 1 Drive c: (OS) (Fixed) (Total:455.71 GB) (Free:8.25 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 7 Drive i: () (Removable) (Total:14.9 GB) (Free:14.85 GB) FAT32 8 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:6.07 GB) NTFS Disk ### Status Size Free Dyn Gpt ——– ———- ——- ——- — — Disk 0 Online 466 GB 981 KB Disk 1 No Media 0 B 0 B Disk 2 No Media 0 B 0 B Disk 3 No Media 0 B 0 B Disk 4 No Media 0 B 0 B Disk 5 Online 15 GB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 OEM 47 MB 32 KB Partition 2 Primary 10 GB 48 MB Partition 3 Primary 456 GB 10 GB ========================================================= Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 8 FAT Partition 47 MB Healthy Hidden ========================================================= Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 2 X RECOVERY NTFS Partition 10 GB Healthy Boot ========================================================= Disk: 0 Partition 3 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 4 C OS NTFS Partition 456 GB Healthy ========================================================= Partitions of Disk 5: =============== Partition ### Type Size Offset ————- —————- ——- ——- Partition 1 Primary 15 GB 16 KB ========================================================= Disk: 5 Partition 1 Type : 0C Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ———- — ———– —– ———- ——- ——— ——– * Volume 3 I FAT32 Removable 15 GB Healthy ========================================================= Last Boot: 2012-10-21 04:42 ==================== End Of Log ============================
Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

start
ZeroAccess:
C:\Users\Gwill\AppData\Local\{e4547d53-0629-4d44-8f43-a6a348142b53}
end

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

===================================================

Please run DDS again for a fresh log.

===================================================

On your next reply please post :
FRST Fix log
DDS fresh log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Here are the results; Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 21-10-2012 Ran by [removed] at 2012-10-21 14:37:01 Run:1 Running from I:\ ============================================== C:\Users\Gwill\AppData\Local\{e4547d53-0629-4d44-8f43-a6a348142b53} moved successfully. ==== End of Fixlog ==== DDS (Ver_2012-10-19.01) - NTFS_x86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2 Run by [removed] at 14:40:14 on 2012-10-21 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1155 [GMT -4:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\atiesrxx.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\System32\rundll32.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxps://www.google.com/ dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe uRun: [Apple] rundll32.exe c:\users\gwill\appdata\local\apple\reegpadn.dll,DllUnregisterServer mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:255 uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre7\bin\jp2iexp.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} - hxxp://hnshelby.dyndns.org/UltraHVCamX.cab DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.2.1 TCP: Interfaces\{E393E313-4DFC-443B-8446-CC200B06B290} : DHCPNameServer = 192.168.2.1 LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg . ============= SERVICES / DRIVERS =============== . R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-4-20 176128] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-21 21504] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-4-20 7772160] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-4-20 243712] S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-3 250808] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664] S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2012-8-17 22640] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-6-21 16896] . =============== Created Last 30 ================ . 2012-10-21 17:16:02 ——– d—–w- C:\FRST 2012-10-21 12:53:39 6918632 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{1d2a4979-f459-4013-b079-4d3a4c7a6183}\mpengine.dll 2012-10-21 12:48:23 6918632 ——w- c:\programdata\microsoft\windows defender\definition updates\updates\mpengine.dll 2012-10-20 18:43:16 ——– d-sh–w- C:\$RECYCLE.BIN 2012-10-20 18:14:00 ——– d-s—w- C:\ComboFix 2012-10-20 18:09:52 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-10-20 18:09:02 ——– d—–w- c:\program files\iPod 2012-10-20 18:08:57 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-10-20 18:08:57 ——– d—–w- c:\program files\iTunes 2012-10-20 18:04:14 ——– d—–w- c:\program files\Bonjour 2012-10-20 17:07:13 ——– d—–w- c:\users\gwill\appdata\local\temp 2012-10-20 16:47:44 98816 —-a-w- c:\windows\sed.exe 2012-10-20 16:47:44 256000 —-a-w- c:\windows\PEV.exe 2012-10-20 16:47:44 208896 —-a-w- c:\windows\MBR.exe 2012-10-05 17:38:19 ——– d—–w- C:\TDSSKiller_Quarantine 2012-10-04 23:46:12 ——– d-sh–w- c:\windows\system32\%APPDATA% 2012-10-04 00:18:32 ——– d—–w- c:\program files\VideoLAN . ==================== Find3M ==================== . 2012-10-11 01:28:36 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-11 01:28:36 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-05 17:40:20 66560 —-a-w- c:\windows\system32\drivers\smb.sys 2012-09-19 23:22:01 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-09-19 23:21:52 821736 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-09-19 23:21:52 746984 —-a-w- c:\windows\system32\deployJava1.dll 2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-21 17:01:22 106928 —-a-w- c:\windows\system32\GEARAspi.dll . ============= FINISH: 14:41:28.01 ===============

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI