This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google redirect - Please help [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Let me know if you're still having redirect after running this fix.

Please follow all previous instructions regarding security programs.

Open a new Notepad session
  • Click the Start button, click run
  • in the run box type notepad
  • click ok
  • In the notepad, Click "Format" and be certain that Word Wrap is not checked.
  • Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE

Rootkit::
c:\users\Gwill\AppData\Local\Apple\reegpadn.dll

Registry::
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
Apple =-


In the notepad
  • Click File, Save as…, and set the Save in to your Desktop
  • In the filename box, type (including quotation marks) as the filename: "CFScript.txt"
  • Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.

This will start ComboFix again.Close all browser/windows first.

When finished, it shall produce a log for you. Please post that log, C:\ComboFix.txt, in your next reply.

**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall**

[external image: Posted Image]
I have run through about five searches (tried dozens of search results) and tried some links in e-mail, everything seems to be working and the internet seems to have increased in speed. Incredible!
Here are the results;


ComboFix 12-10-22.01 - Gwill 10/22/2012 12:00:32.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1107 [GMT -4:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Gwill\Desktop\CFScript.txt
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\L\00000004.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\n
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\00000004.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\00000008.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\000000cb.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\80000000.@
c:\$recycle.bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\80000032.@
c:\users\Gwill\ms.exe
.
.
((((((((((((((((((((((((( Files Created from 2012-09-22 to 2012-10-22 )))))))))))))))))))))))))))))))
.
.
2012-10-22 16:07 . 2012-10-22 16:10 ——– d—–w- c:\users\Gwill\AppData\Local\temp
2012-10-22 16:07 . 2012-10-22 16:07 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-10-22 00:17 . 2012-10-22 00:17 ——– d—–w- C:\Apple
2012-10-21 17:16 . 2012-10-21 17:16 ——– d—–w- C:\FRST
2012-10-21 12:53 . 2012-10-12 05:56 6918632 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{1D2A4979-F459-4013-B079-4D3A4C7A6183}\mpengine.dll
2012-10-21 12:45 . 2012-08-24 15:53 172544 —-a-w- c:\windows\system32\wintrust.dll
2012-10-21 12:45 . 2012-06-02 00:02 985088 —-a-w- c:\windows\system32\crypt32.dll
2012-10-21 12:45 . 2012-06-02 00:02 98304 —-a-w- c:\windows\system32\cryptnet.dll
2012-10-21 12:45 . 2012-06-02 00:02 133120 —-a-w- c:\windows\system32\cryptsvc.dll
2012-10-21 12:45 . 2012-09-13 13:28 2048 —-a-w- c:\windows\system32\tzres.dll
2012-10-21 12:45 . 2012-08-29 11:27 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-10-21 12:44 . 2012-08-29 11:27 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-10-20 18:09 . 2012-08-21 17:01 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-10-20 18:09 . 2012-10-20 18:09 ——– d—–w- c:\program files\iPod
2012-10-20 18:08 . 2012-10-20 18:09 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1
2012-10-20 18:08 . 2012-10-20 18:09 ——– d—–w- c:\program files\iTunes
2012-10-20 18:04 . 2012-10-20 18:04 ——– d—–w- c:\program files\Bonjour
2012-10-05 17:38 . 2012-10-05 17:38 ——– d—–w- C:\TDSSKiller_Quarantine
2012-10-04 23:46 . 2012-10-04 23:46 ——– d-sh–w- c:\windows\system32\%APPDATA%
2012-10-04 00:19 . 2012-10-22 10:42 ——– d—–w- c:\users\Gwill\AppData\Roaming\vlc
2012-10-04 00:18 . 2012-10-04 00:18 ——– d—–w- c:\program files\VideoLAN
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-10-11 01:28 . 2012-04-03 19:42 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-10-11 01:28 . 2011-06-01 17:10 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-10-05 17:40 . 2010-10-09 13:30 66560 —-a-w- c:\windows\system32\drivers\smb.sys
2012-09-19 23:22 . 2012-09-19 23:22 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll
2012-09-19 23:21 . 2012-06-04 02:09 821736 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-09-19 23:21 . 2010-08-14 12:38 746984 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-24 06:59 . 2012-09-22 11:02 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51 . 2012-09-22 11:02 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51 . 2012-09-22 11:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47 . 2012-09-22 11:02 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47 . 2012-09-22 11:02 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43 . 2012-09-22 11:02 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-08-21 17:01 . 2012-03-14 16:25 106928 —-a-w- c:\windows\system32\GEARAspi.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2009-04-11 1233920]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Apple"="c:\users\Gwill\AppData\Local\Apple\reegpadn.dll" [2012-10-22 354304]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-17 4907008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-16 81920]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-09-23 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-09-23 8429568]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-09-23 81920]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-25 17920]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2012-09-10 421776]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-11-15 50688]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [x]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [x]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2012-10-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 01:28]
.
2012-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 23:36]
.
2012-10-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 23:36]
.
.
——- Supplementary Scan ——-
.
uStart Page = https://www.google.com/
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = 192.168.2.1
DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} - hxxp://hnshelby.dyndns.org/UltraHVCamX.cab
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-10-22 12:10
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Apple = rundll32.exe c:\users\Gwill\AppData\Local\Apple\reegpadn.dll,DllUnregisterServer?3456789
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020200}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
———————— Other Running Processes ————————
.
c:\windows\system32\atiesrxx.exe
c:\windows\system32\atieclxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\windows\system32\WUDFHost.exe
c:\windows\RtHDVCpl.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
.
**************************************************************************
.
Completion time: 2012-10-22 12:14:23 - machine was rebooted
ComboFix-quarantined-files.txt 2012-10-22 16:14
ComboFix2.txt 2012-10-20 17:14
.
Pre-Run: 14,439,862,272 bytes free
Post-Run: 14,379,966,464 bytes free
.
- - End Of File - - 579AEEED0D54185B4C99BF3A18E3E393
It is still there lol.. seems like we have to nuke it without Windows loading.

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the flashdrive as fixlist.txt

HKU\Gwill\…\Run: [Apple] rundll32.exe C:\Users\Gwill\AppData\Local\Apple\reegpadn.dll,DllUnregisterServer
C:\Users\Gwill\AppData\Local\Apple\reegpadn.dll

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

On Vista or Windows 7: Now please enter System Recovery Options.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.
Here are the results; Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 21-10-2012 Ran by [removed] at 2012-10-23 08:41:06 Run:2 Running from I:\ ============================================== HKEY_USERS\Gwill\Software\Microsoft\Windows\CurrentVersion\Run\\Apple Value deleted successfully. C:\Users\Gwill\AppData\Local\Apple\reegpadn.dll moved successfully. ==== End of Fixlog ====
Conspire, Everything seems to be working fine, Thank you very much. I will make a donation via PayPal. Do you recommend a particular anti-virus program? DDS (Ver_2012-10-19.01) - NTFS_x86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 10.7.2 Run by [removed] at 15:37:44 on 2012-10-23 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2046.1151 [GMT -4:00] . SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes ================ . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\atiesrxx.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\AERTSrv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskeng.exe C:\Windows\Explorer.EXE C:\Windows\system32\WUDFHost.exe C:\Windows\System32\mobsync.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Windows\system32\taskeng.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\Macromed\Flash\FlashUtil32_11_4_402_287_ActiveX.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation . ============== Pseudo HJT Report =============== . uStart Page = hxxps://www.google.com/ dURLSearchHooks: {A3BC75A2-1F87-4686-AA43-5347D756017C} - BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: CBrowserHelperObject Object: {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [RtHDVCpl] RtHDVCpl.exe mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ECenter] c:\dell\e-center\EULALauncher.exe mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe uPolicies-Explorer: NoDriveTypeAutoRun = dword:255 uPolicies-Explorer: NoDrives = dword:0 mPolicies-Explorer: BindDirectlyToPropertySetStorage = dword:0 mPolicies-Explorer: NoDriveTypeAutoRun = dword:255 mPolicies-Explorer: NoDrives = dword:0 mPolicies-System: EnableUIADesktopToggle = dword:0 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre7\bin\jp2iexp.dll . INFO: HKCU has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . . INFO: HKLM has more than 50 listed domains. If you wish to scan all of them, select the 'Force scan all domains' option. . DPF: {3641803B-72A4-4A9A-BA18-F1446F7CCDE4} - hxxp://hnshelby.dyndns.org/UltraHVCamX.cab DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxps://support.dell.com/systemprofiler/SysProExe.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab TCP: NameServer = 192.168.2.1 TCP: Interfaces\{E393E313-4DFC-443B-8446-CC200B06B290} : DHCPNameServer = 192.168.2.1 LSA: Security Packages = kerberos msv1_0 schannel wdigest tspkg . ============= SERVICES / DRIVERS =============== . R2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-4-20 176128] R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-21 21504] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-4-20 7772160] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-4-20 243712] S2 aawservice;Lavasoft Ad-Aware Service;"c:\program files\lavasoft\ad-aware\aawservice.exe" –> c:\program files\lavasoft\ad-aware\aawservice.exe [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-3 250808] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2009-11-3 135664] S3 PCDSRVC{E9D79540-57D5953E-06020200}_0;PCDSRVC{E9D79540-57D5953E-06020200}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc.pkms [2012-8-17 22640] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\drivers\WSDPrint.sys [2008-6-21 16896] . =============== Created Last 30 ================ . 2012-10-23 15:49:08 6918632 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{278e38d7-382d-45a3-b1f2-7cfa7e58c323}\mpengine.dll 2012-10-22 16:14:26 ——– d—–w- c:\users\gwill\appdata\local\temp 2012-10-22 16:10:19 ——– d—–w- C:\$RECYCLE.BIN 2012-10-22 00:17:30 ——– d—–w- C:\Apple 2012-10-21 17:16:02 ——– d—–w- C:\FRST 2012-10-21 12:48:23 6918632 ——w- c:\programdata\microsoft\windows defender\definition updates\updates\mpengine.dll 2012-10-21 12:45:38 172544 —-a-w- c:\windows\system32\wintrust.dll 2012-10-21 12:45:28 985088 —-a-w- c:\windows\system32\crypt32.dll 2012-10-21 12:45:28 98304 —-a-w- c:\windows\system32\cryptnet.dll 2012-10-21 12:45:28 133120 —-a-w- c:\windows\system32\cryptsvc.dll 2012-10-21 12:45:05 2048 —-a-w- c:\windows\system32\tzres.dll 2012-10-21 12:45:00 3602816 —-a-w- c:\windows\system32\ntkrnlpa.exe 2012-10-21 12:44:59 3550080 —-a-w- c:\windows\system32\ntoskrnl.exe 2012-10-20 18:09:52 26840 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2012-10-20 18:09:02 ——– d—–w- c:\program files\iPod 2012-10-20 18:08:57 ——– d—–w- c:\programdata\188F1432-103A-4ffb-80F1-36B633C5C9E1 2012-10-20 18:08:57 ——– d—–w- c:\program files\iTunes 2012-10-20 18:04:14 ——– d—–w- c:\program files\Bonjour 2012-10-20 16:47:44 98816 —-a-w- c:\windows\sed.exe 2012-10-20 16:47:44 256000 —-a-w- c:\windows\PEV.exe 2012-10-20 16:47:44 208896 —-a-w- c:\windows\MBR.exe 2012-10-05 17:38:19 ——– d—–w- C:\TDSSKiller_Quarantine 2012-10-04 23:46:12 ——– d-sh–w- c:\windows\system32\%APPDATA% 2012-10-04 00:18:32 ——– d—–w- c:\program files\VideoLAN . ==================== Find3M ==================== . 2012-10-11 01:28:36 73656 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-10-11 01:28:36 696760 —-a-w- c:\windows\system32\FlashPlayerApp.exe 2012-10-05 17:40:20 66560 —-a-w- c:\windows\system32\drivers\smb.sys 2012-09-19 23:22:01 93672 —-a-w- c:\windows\system32\WindowsAccessBridge.dll 2012-09-19 23:21:52 821736 —-a-w- c:\windows\system32\npdeployJava1.dll 2012-09-19 23:21:52 746984 —-a-w- c:\windows\system32\deployJava1.dll 2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll 2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll 2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl 2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe 2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll 2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb 2012-08-21 17:01:22 106928 —-a-w- c:\windows\system32\GEARAspi.dll . ============= FINISH: 15:38:23.76 ===============

Attachments:

Hello,

We still have a bit more to do before we can start some house keeping.

I'd recommend Microsoft Security Essentials, AVG Free, Avira Free, and Avast! Free.

They all make good AV. It all depends on your own preference. But if you ask me, I'd say MSE being kind to system resources.

I thank you for your intention to make donations. :)

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
===================================================

Go here to run an online scannner from ESET. Windows Vista/Windows 7 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
  • Note: For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is unticked and the Scan Archives option is ticked.
  • Click on Advanced Settings, ensure the options Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file…"
  • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
  • Close the ESET online scan, and let me know how things are now.
===================================================

Malwarebytes' Anti-Malware
Download Malwarebytes' Anti-Malware here and save to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program. (Note to Vista users, please right-click and select Run as Administrator.)
  • At the end, be sure a checkmark is placed next to:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
  • Then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.


===================================================

On your next reply please post :
ESET log
MBAM log


Please STOP and let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Here are the results; C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-18\$e4547d5306294d448f43a6a348142b53\n.vir Win32/Sirefef.EV trojan C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\n.vir Win32/Sirefef.EV trojan C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\00000004.@.vir Win32/Conedex.D trojan C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\00000008.@.vir Win32/Sirefef.FG trojan C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\000000cb.@.vir Win32/Conedex.E trojan C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\80000000.@.vir a variant of Win32/Sirefef.FA trojan C:\Qoobox\Quarantine\C\$Recycle.Bin\S-1-5-21-2861772215-3948250270-1845948433-1000\$e4547d5306294d448f43a6a348142b53\U\80000032.@.vir probably a variant of Win32/Sirefef.FD trojan C:\Qoobox\Quarantine\C\Users\Gwill\ms.exe.vir Win32/Sirefef.EV trojan C:\Qoobox\Quarantine\C\Users\Gwill\AppData\Local\Apple\_reegpadn_.dll.zip Win32/Kryptik.AMNR trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\svc0000\tsk0000.dta Win32/Sirefef.DA trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\zafs0000\tsk0001.dta Win32/Sirefef.EZ trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\zafs0000\tsk0004.dta Win32/Conedex.D trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\zafs0000\tsk0005.dta Win32/Sirefef.FG trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\zafs0000\tsk0006.dta Win32/Conedex.E trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\zafs0000\tsk0007.dta a variant of Win32/Sirefef.FA trojan C:\TDSSKiller_Quarantine\05.10.2012_13.37.22\rtkt0000\zafs0000\tsk0008.dta probably a variant of Win32/Sirefef.FD trojan Malwarebytes Anti-Malware 1.65.1.1000 www.malwarebytes.org Database version: v2012.10.24.04 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Gwill :: GWILL-DESKTOP [administrator] 10/24/2012 8:55:59 AM mbam-log-2012-10-24 (08-55-59).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 200348 Time elapsed: 4 minute(s), 34 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Looking great there. We can now do some clean ups.

You may remove the tools we used on this thread. You can keep MBAM as you wish.

Follow these steps to uninstall Combofix
  • Click START then RUN
  • Now copy/paste the code into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.
Combofix /Uninstall
[external image: Posted Image]

===================================================

Thank you for your patience, and performing all of the procedures requested. I would also like to take this opportunity to apologize for any delay that may have occurred.

————————————————————————————————————–

MICROSOFT UPDATES
It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection.


Passwords
It is good security practice to change your passwords to all your online accounts on a fairly regular basis, this is especially true after an infection. Refer to this Microsoft article
Strong passwords: How to create and use them and consider a password keeper, to keep all your passwords safe.


SPYWARE PREVENTION
This is a good time to set up protection against further attacks. In light of your recent problem, I'm sure you'd like to avoid any future infections. Please read these well written articles:
  • How Did I Get Infected In The First Place? by TonyKlein
  • How to Prevent Malware by miekiemoes
  • PC Safety and Security–What Do I Need?

To help protect your computer in the future I recommend that you get the following free programs if you do not already have them:
  • WOT, Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
  • Green to go
  • Yellow for caution
  • Red to stop

WOT has an add-on available for both Firefox and IE.

  • SpywareBlaster prevents the installation of ActiveX-based malware, blocks cookies, and restricts the actions of "bad" sites. See tutorial here
  • MVPS HOSTS FILE replaces your current HOSTS file with one that will restrict known ad sites from serving you unsolicited advertisements. It basically prevents your computer from connecting to those sites by redirecting the attempted connections to 127.0.0.1, which is the IP of your local computer. See guide here and for Windows Vista here
  • Download Host.zip and Save it to your Desktop.
  • Right-click hosts.zip and select 'Extract all files' or 'Extract files…'.
  • Follow the prompts and click 'Finish'.
  • This will open the newly created hosts folder on your Desktop.
  • Double-click on the included mvps.bat file, this will rename the existing HOSTS file to HOSTS.MVP, then it will copy the included updated HOSTS file to the correct location on your machine.
  • Once updated you should see another prompt that the task was completed.
Follow this list and keep your antivirus program and antispyware programs updated and scan with them on a regular basis. By doing so, your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck.

Do you have any questions or problems to ask? Please do not hesitate to do so.

**Please respond this one more time to ensure it is resolved and close this topic.
Hello Conspire, Thank you very much for your help. You were clear and thorough, and with that, you solved a very difficult problem. You are an asset to this forum. I will follow your advice to prevent future issues. Greg

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI