This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser redirects all over the spectrum [Solved]

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My work laptop, which I brought home for my young son to play video games on, has a browser redirect virus of some kind on it. It takes me to gaming, sports, etc, websites that I don't want to go to. Sometimes I go to sites I want to go to, but most of the time it's to spam sites.

I tried to run Malwarebytes Antimalware, but so far it's found nothing - unusual for it when I know I've got something.

I've included the log of Hijackthis here.

Help!

—

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:34:18 PM, on 2/3/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\CmgShieldSvc.exe
C:\WINDOWS\system32\EMSService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CTLInst\CTLInst.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\DWRCS.exe
C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
C:\Program Files\Hewlett-Packard\Discovery Agent\bin32\discagnt.exe
C:\Windows\system32\suss.exe
C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
C:\Program Files\Hewlett-Packard\Discovery Agent\Plugins\usage\discusge.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\CCM\CcmExec.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe
C:\Program Files\Microsoft Office Communicator\communicator.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
C:\WINDOWS\System32\CMGShieldUI.exe
C:\WINDOWS\system32\EmsServiceHelper.exe
C:\Program Files\Apoint\HidFind.exe
C:\Program Files\Hewlett-Packard\Discovery Agent\Plugins\usage\discfcsn.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Kontiki\KHost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
C:\Program Files\Citrix\ICA Client\PNAMAIN.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll
O2 - BHO: LLIEHlprObj Class - {F757FBBF-10E5-4DDA-BBEA-2357E54BEA2B} - C:\Program Files\Open Text\Livelink Explorer\LLBHO3.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll
O4 - HKLM\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\communicator.exe" /fromrunkey
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
O4 - HKLM\..\Run: [CmgShieldUI] C:\WINDOWS\System32\CMGShieldUI.exe
O4 - HKLM\..\Run: [EmsService] EmsServiceHelper.exe
O4 - HKLM\..\Run: [EDFcsn] C:\Program Files\Hewlett-Packard\Discovery Agent\Plugins\usage\discfcsn.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [kdx] C:\Program Files\Kontiki\KHost.exe -all
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Cisco AnyConnect Secure Mobility Agent for Windows] "C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe" -autolaunched
O4 - HKLM\..\Run: [DameWare MRC Agent] C:\WINDOWS\system32\DWRCST.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
O4 - HKUS\S-1-5-19\..\Run: [Adobe] rundll32.exe "C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll",DllRegisterServer (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Adobe] rundll32.exe "C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll",DllRegisterServer (User 'NETWORK SERVICE')
O4 - Global Startup: Program Neighborhood Agent.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O15 - Trusted Zone: http://forums.adobe.com
O15 - Trusted Zone: *.report3.ccsurvey.com
O15 - Trusted Zone: *.confarchives.com
O15 - Trusted Zone: *.conferencing.com
O15 - Trusted Zone: *.conferencinghub.com
O15 - Trusted Zone: doc-share.corp.intranet
O15 - Trusted Zone: learningcenter.corp.intranet
O15 - Trusted Zone: *.directv.com
O15 - Trusted Zone: *.dstoutput.com
O15 - Trusted Zone: *.eqsalespt.com
O15 - Trusted Zone: *.force.com
O15 - Trusted Zone: *.iconf.net
O15 - Trusted Zone: *.intergies.com
O15 - Trusted Zone: *.kclisi01
O15 - Trusted Zone: *.kclisi02
O15 - Trusted Zone: *.kdnibp04
O15 - Trusted Zone: *.Liveperson.net
O15 - Trusted Zone: *.logmeinrescue.com
O15 - Trusted Zone: *.pramata.com
O15 - Trusted Zone: http://rio2ui.prod.com
O15 - Trusted Zone: rio2ui2.prod.com
O15 - Trusted Zone: http://einstein.qintra.com
O15 - Trusted Zone: qsi.qintra.com
O15 - Trusted Zone: sci.qintra.com
O15 - Trusted Zone: http://twist2.qintra.com
O15 - Trusted Zone: http://*.qtomavmpc025
O15 - Trusted Zone: *.qwestccc.com
O15 - Trusted Zone: *.salesforce.com
O15 - Trusted Zone: *.skillport.com
O15 - Trusted Zone: *.skillwsa.com
O15 - Trusted Zone: *.spw
O15 - Trusted Zone: http://*.ssapps
O15 - Trusted Zone: http://*.ssappsdev
O15 - Trusted Zone: centurylink.teds.com
O15 - Trusted Zone: *.ups.com
O15 - Trusted Zone: http://consultingplusordering.uswc.uswest.com
O15 - Trusted Zone: http://consultingplustraining.uswc.uswest.com
O15 - Trusted Zone: http://qtracker.uswc.uswest.com
O15 - Trusted Zone: *.verizonwireless.com
O15 - Trusted Zone: *.visual.force.com
O15 - Trusted Zone: *.vzwcorp.com
O15 - Trusted Zone: *.whmi.biz
O15 - Trusted Zone: *.confarchives.com (HKLM)
O15 - Trusted Zone: *.conferencing.com (HKLM)
O15 - Trusted Zone: *.directv.com (HKLM)
O15 - Trusted Zone: *.iconf.net (HKLM)
O15 - Trusted Zone: http://rio2ui.prod.com (HKLM)
O15 - Trusted Zone: rio2ui2.prod.com (HKLM)
O15 - Trusted Zone: http://einstein.qintra.com (HKLM)
O15 - Trusted Zone: http://epaycce.ad.qintra.com (HKLM)
O15 - Trusted Zone: qsi.qintra.com (HKLM)
O15 - Trusted Zone: sci.qintra.com (HKLM)
O15 - Trusted Zone: http://twist2.qintra.com (HKLM)
O15 - Trusted Zone: *.ups.com (HKLM)
O15 - Trusted Zone: http://consultingplusordering.uswc.uswest.com (HKLM)
O15 - Trusted Zone: http://consultingplustraining.uswc.uswest.com (HKLM)
O15 - Trusted Zone: http://qtracker.uswc.uswest.com (HKLM)
O16 - DPF: {538793D5-659C-4639-A56C-A179AD87ED44} (VPNWeb Control) - vpnweb.cab
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} (Photo Upload Plugin Class) - http://www.cvsphoto.com/upload/activex/v3_…veX_Control.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = EQ.Intranet
O17 - HKLM\Software\..\Telephony: DomainName = EQ.Intranet
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = EQ.Intranet
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = corp.intranet,dhcp.intranet,ctl.intranet,eq.intranet,ad.qintra.com,qintra.com,us
wc.uswest.com,qwest.net,net.intranet,centurytel.com,cte.net,test.intranet,dev.int
ranet,dev.qintra.com,nnet
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = corp.intranet,dhcp.intranet,ctl.intranet,eq.intranet,ad.qintra.com,qintra.com,us
wc.uswest.com,qwest.net,net.intranet,centurytel.com,cte.net,test.intranet,dev.int
ranet,dev.qintra.com,nnet
O20 - Winlogon Notify: CMGShieldNP - CmgShieldNP.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: CMGShield - CREDANT Technologies, Inc. - C:\WINDOWS\system32\CmgShieldSvc.exe
O23 - Service: CTLInst - Unknown owner - C:\Program Files\CTLInst\CTLInst.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.exe
O23 - Service: EMS - CREDANT Technologies, Inc. - C:\WINDOWS\SYSTEM32\EMSService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\Kontiki\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: HP DDMI Agent (prgnDiscAgent) - Unknown owner - C:\Program Files\Hewlett-Packard\Discovery Agent\bin32\discagnt.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe
O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe
O23 - Service: User Profile Hive Cleanup (UPHClean) - Windows ® Codename Longhorn DDK provider - C:\Program Files\UPHClean\uphclean.exe
O23 - Service: Cisco AnyConnect Secure Mobility Agent (vpnagent) - Cisco Systems, Inc. - C:\Program Files\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
O23 - Service: DW WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 13110 bytes
Welcome to the forum.

Please remove any usb or external drives from the computer before you run this scan!

Please download and run RogueKiller to your desktop.

http://tigzy.geekstogo.com/Tools/RogueKillerX64.exe

Quit all running programs.

For Windows XP, double-click to start.
For Vista or Windows 7, do a right-click on the program, select Run as Administrator to start, & when prompted Allow to run.


Click Scan to scan the system.
When the scan completes > Close out the program > Don't Fix anything!

Don't run any other options, they're not all bad!!!!!!!

Post back the report which should be located on your desktop.

MrC

Please don't run any other scans, download, install or uninstall any programs while I'm working with you.
Please stick with me until I give you the "all clear".


——->Your topic will be closed if you haven't replied within 3 days!<——–

(If I don't respond within 24 hours, please send me a PM)

I tried to run the .exe Roguekiller file after I downloaded it, but I got an error message saying that it is not a valid Win32 application.
Okay, I got it to work this time. Here's the report as you requested. Looks like it found six items, but I didn't fix anything and closed out the program.



RogueKiller V8.4.4 [Feb 4 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : JXD922870 [Admin rights]
Mode : Scan – Date : 02/04/2013 23:24:04
| ARK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 6 ¤¤¤
[RUN][SUSP PATH] HKUS\S-1-5-19[…]\Run : Adobe (rundll32.exe "C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll",DllRegisterServer) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-20[…]\Run : Adobe (rundll32.exe "C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll",DllRegisterServer) -> FOUND
[HJ] HKLM\[…]\Security Center : AntiVirusDisableNotify (1) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowMyPics (0) -> FOUND
[HJ SMENU] HKCU\[…]\Advanced : Start_ShowMyMusic (0) -> FOUND
[HJ DESK] HKLM\[…]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[12] : NtAlertResumeThread @ 0x805D4C0C -> HOOKED (Unknown @ 0x8A596C30)
SSDT[13] : NtAlertThread @ 0x805D4BBC -> HOOKED (Unknown @ 0x8A3C7BD0)
SSDT[17] : NtAllocateVirtualMemory @ 0x805A8AEE -> HOOKED (Unknown @ 0x8A322A80)
SSDT[31] : NtConnectPort @ 0x805A4604 -> HOOKED (Unknown @ 0x8A7016C0)
SSDT[43] : NtCreateMutant @ 0x806176DE -> HOOKED (Unknown @ 0x8A4C6C80)
SSDT[53] : NtCreateThread @ 0x805D1068 -> HOOKED (Unknown @ 0x8A6FBDF8)
SSDT[83] : NtFreeVirtualMemory @ 0x805B2FE6 -> HOOKED (Unknown @ 0x8A511D28)
SSDT[89] : NtImpersonateAnonymousToken @ 0x805F9288 -> HOOKED (Unknown @ 0x8A595938)
SSDT[91] : NtImpersonateThread @ 0x805D7890 -> HOOKED (Unknown @ 0x8A595B78)
SSDT[108] : NtMapViewOfSection @ 0x805B206E -> HOOKED (Unknown @ 0x8A6EED78)
SSDT[114] : NtOpenEvent @ 0x8060F09C -> HOOKED (Unknown @ 0x8A5952F8)
SSDT[123] : NtOpenProcessToken @ 0x805EDF56 -> HOOKED (Unknown @ 0x8A4A3A78)
SSDT[129] : NtOpenThreadToken @ 0x805EDF74 -> HOOKED (Unknown @ 0x8A32BAA8)
SSDT[143] : NtQueryDefaultLocale @ 0x80610D46 -> HOOKED (\SystemRoot\SYSTEM32\Drivers\SysPlant.sys @ 0xA85A2720)
SSDT[206] : NtResumeThread @ 0x805D4A48 -> HOOKED (Unknown @ 0x8A5E5E90)
SSDT[213] : NtSetContextThread @ 0x805D2C4A -> HOOKED (Unknown @ 0x8A4A7A78)
SSDT[228] : NtSetInformationProcess @ 0x805CDED0 -> HOOKED (Unknown @ 0x8A324A98)
SSDT[229] : NtSetInformationThread @ 0x805CC154 -> HOOKED (Unknown @ 0x8A39FB58)
SSDT[253] : NtSuspendProcess @ 0x805D4B10 -> HOOKED (Unknown @ 0x8A594BA0)
SSDT[254] : NtSuspendThread @ 0x805D4982 -> HOOKED (Unknown @ 0x8A527090)
SSDT[257] : NtTerminateProcess @ 0x805D2308 -> HOOKED (Unknown @ 0x8A4FD348)
SSDT[258] : NtTerminateThread @ 0x805D2502 -> HOOKED (Unknown @ 0x8A4A1A78)
SSDT[267] : NtUnmapViewOfSection @ 0x805B2E7C -> HOOKED (Unknown @ 0x8A4A4A78)
SSDT[277] : NtWriteVirtualMemory @ 0x805B4400 -> HOOKED (Unknown @ 0x8A338A80)

¤¤¤ HOSTS File: ¤¤¤
–> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD1600BEKT-00PVMT0 +++++
— User —
[MBR] 1bd8dcc0b0c07f38fbdc03a67834ef23
[BSP] 18b70d9c9645f3508b581b9ff370a325 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 152616 Mo
User = LL1 … OK!
User = LL2 … OK!

Finished : << RKreport[1]_S_02042013_02d2324.txt >>
RKreport[1]_S_02042013_02d2324.txt
Run RogueKiller again and click Scan
When the scan completes > click on the Registry tab
Put a check next to all of these and uncheck the rest: (if found)

[RUN][SUSP PATH] HKUS\S-1-5-19[…]\Run : Adobe (rundll32.exe "C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll",DllRegisterServer) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-20[…]\Run : Adobe (rundll32.exe "C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll",DllRegisterServer) -> FOUND


Now click Delete on the right hand column under Options

Delete this file if found:

C:\Documents and Settings\JXD922870\Local Settings\Application Data\Amazon\Adobe\lcrtaaj.dll

———————————————————-

Please create a new system restore point before running Malwarebytes Anti-Rootkit if you can.

Download Malwarebytes Anti-Rootkit from HERE
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder….. mbar-log.txt and system-log.txt


~~~~~~~~~~~~~~~~~~~~~~~

Note:
If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
Internet access
Windows Update
Windows Firewall

If there are additional problems with your system, such as any of those listed above or other system issues, then run the fixdamage tool included with Malwarebytes Anti-Rootkit and reboot.
Verify that your system is now functioning normally.


MrC
So far so good. Here are the two logs. Malwarebytes Anti-Rootkit BETA 1.01.0.1017 www.malwarebytes.org Database version: v2013.02.05.11 Windows XP Service Pack 3 x86 NTFS Internet Explorer 8.0.6001.18702 JXD922870 :: EQ221543 [administrator] 2/5/2013 8:53:41 PM mbar-log-2013-02-05 (20-53-41).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 30880 Time elapsed: 38 minute(s), 38 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) — ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1017 © Malwarebytes Corporation 2011-2012 OS version: 5.1.2600 Windows XP Service Pack 3 x86 Account is Administrative Internet Explorer version: 8.0.6001.18702 Java version: 1.6.0_30 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 1.664000 GHz Memory total: 3210788864, free: 2263023616 ———— Kernel report ———— 02/05/2013 19:18:19 ———— Loaded modules ———– \WINDOWS\system32\ntkrnlpa.exe \WINDOWS\system32\hal.dll \WINDOWS\system32\KDCOM.DLL \WINDOWS\system32\BOOTVID.dll ACPI.sys \WINDOWS\system32\DRIVERS\WMILIB.SYS pci.sys isapnp.sys CmgHiber.sys \WINDOWS\system32\DRIVERS\CmgCrypt.SYS compbatt.sys \WINDOWS\system32\DRIVERS\BATTC.SYS pciide.sys \WINDOWS\system32\DRIVERS\PCIIDEX.SYS intelide.sys pcmcia.sys MountMgr.sys ftdisk.sys dmload.sys dmio.sys PartMgr.sys VolSnap.sys atapi.sys disk.sys \WINDOWS\system32\DRIVERS\CLASSPNP.SYS fltMgr.sys CMGShCEF.sys sr.sys CmgShREG.sys DLACDBHM.SYS DRVMCDB.SYS PxHelp20.sys KSecDD.sys Ntfs.sys NDIS.sys Mup.sys CmgPCS.sys \SystemRoot\system32\DRIVERS\smsmdm.sys \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\igxpmp32.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\bcmwl5.sys \SystemRoot\system32\DRIVERS\b57xp32.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\serial.sys \SystemRoot\system32\DRIVERS\serenum.sys \SystemRoot\system32\DRIVERS\imapi.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\redbook.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\DamewareMini.sys \SystemRoot\system32\DRIVERS\dne2000.sys \SystemRoot\system32\DRIVERS\dwvkbd.sys \SystemRoot\system32\DRIVERS\audstub.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\psched.sys \SystemRoot\system32\DRIVERS\msgpc.sys \SystemRoot\system32\DRIVERS\ptilink.sys \SystemRoot\system32\DRIVERS\raspti.sys \SystemRoot\system32\DRIVERS\rdpdr.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\teefer2.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\update.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\system32\DRIVERS\omci.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\sthda.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\DRIVERS\HSXHWAZL.sys \SystemRoot\system32\DRIVERS\HSX_DPV.sys \SystemRoot\system32\DRIVERS\HSX_CNXT.sys \SystemRoot\System32\Drivers\Modem.SYS \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\Drivers\i2omgmt.SYS \SystemRoot\System32\Drivers\Fs_Rec.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\Drivers\DLARTL_M.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\Drivers\mnmdd.SYS \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\rasacd.sys \SystemRoot\system32\DRIVERS\ipsec.sys \SystemRoot\system32\DRIVERS\tcpip.sys \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys \SystemRoot\System32\Drivers\SYMTDI.SYS \SystemRoot\system32\DRIVERS\wanarp.sys \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS \SystemRoot\system32\DRIVERS\netbt.sys \SystemRoot\System32\drivers\afd.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\SYSTEM32\Drivers\SysPlant.sys \SystemRoot\System32\Drivers\SRTSPX.SYS \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\System32\Drivers\Fips.SYS \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys \??\C:\Program Files\CTLInst\CTLInst_.sys \SystemRoot\System32\Drivers\Cdfs.SYS \SystemRoot\System32\Drivers\oz776.sys \SystemRoot\System32\Drivers\SMCLIB.SYS \SystemRoot\System32\Drivers\dump_atapi.sys \SystemRoot\System32\Drivers\dump_WMILIB.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\watchdog.sys \SystemRoot\System32\drivers\dxg.sys \SystemRoot\System32\drivers\dxgthk.sys \SystemRoot\System32\igxpgd32.dll \SystemRoot\System32\igxprd32.dll \SystemRoot\System32\igxpdv32.DLL \SystemRoot\System32\igxpdx32.DLL \SystemRoot\System32\ATMFD.DLL \SystemRoot\System32\Drivers\DRVNDDM.SYS \SystemRoot\System32\Drivers\DLADResM.SYS \SystemRoot\System32\Drivers\DLAIFS_M.SYS \SystemRoot\System32\Drivers\DLAOPIOM.SYS \SystemRoot\System32\Drivers\DLAPoolM.SYS \SystemRoot\System32\Drivers\DLABMFSM.SYS \SystemRoot\System32\Drivers\DLABOIOM.SYS \SystemRoot\System32\Drivers\DLAUDFAM.SYS \SystemRoot\System32\Drivers\DLAUDF_M.SYS \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\mrxdav.sys \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys \SystemRoot\system32\DRIVERS\mdmxsdk.sys \SystemRoot\system32\DRIVERS\srv.sys \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys \SystemRoot\System32\Drivers\HTTP.sys \SystemRoot\System32\Drivers\SRTSP.SYS \SystemRoot\System32\Drivers\TDTCP.SYS \SystemRoot\System32\Drivers\RDPWD.SYS \SystemRoot\system32\drivers\wdmaud.sys \SystemRoot\system32\drivers\sysaudio.sys \SystemRoot\System32\Drivers\SYMREDRV.SYS \??\C:\WINDOWS\system32\CCM\prepdrv.sys \SystemRoot\System32\Drivers\Fastfat.SYS \??\C:\WINDOWS\system32\drivers\WpsHelper.sys \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20130205.003\NAVEX15.SYS \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20130205.003\NAVENG.SYS \??\C:\WINDOWS\system32\drivers\TrueSight.sys \SystemRoot\system32\drivers\kmixer.sys \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys \Windows\system32\ntdll.dll ———– End ———– <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff8abc7ab8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-3\ Lower Device Object: 0xffffffff8ace8d98 Lower Device Driver Name: \Driver\atapi\ Driver name found: atapi Initialization returned 0x0 Load Function returned 0x0 Downloaded database version: v2013.02.05.11 Downloaded database version: v2013.01.23.01 Initializing… Done! <<<2>>> Device number: 0, partition: 1 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff8abc7ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffff8acade08, DeviceName: Unknown, DriverName: \Driver\PartMgr\ DevicePointer: 0xffffffff8abc7970, DeviceName: Unknown, DriverName: \Driver\CmgHiber\ DevicePointer: 0xffffffff8abc7ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff8abc9f18, DeviceName: \Device\0000009d\, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff8ace8d98, DeviceName: \Device\Ide\IdeDeviceP0T0L0-3\, DriverName: \Driver\atapi\ ———— End ———- Upper DeviceData: 0xffffffffe65fd3c0, 0xffffffff8abc7ab8, 0xffffffff874276a0 Lower DeviceData: 0xffffffffe68d8618, 0xffffffff8ace8d98, 0xffffffff89574ce8 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\WINDOWS\system32\drivers… Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: F287A88E Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 312558592 Partition file system is NTFS Partition is bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 160041885696 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-312561808-312581808)… Done! Performing system, memory and registry scan… Infected: HKLM\SOFTWARE\MICROSOFT\SECURITY CENTER|AntiVirusDisableNotify –> [PUM.Disabled.SecurityCenter] Done! Scan finished Creating System Restore point… Scheduling clean up… <<<2>>> Device number: 0, partition: 1 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Removal successful. No system shutdown is required. ======================================= ————————————— Malwarebytes Anti-Rootkit BETA 1.01.0.1017 © Malwarebytes Corporation 2011-2012 OS version: 5.1.2600 Windows XP Service Pack 3 x86 Account is Administrative Internet Explorer version: 8.0.6001.18702 Java version: 1.6.0_30 File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 1.664000 GHz Memory total: 3210788864, free: 2178023424 ———— Kernel report ———— 02/05/2013 20:14:09 ———— Loaded modules ———– \WINDOWS\system32\ntkrnlpa.exe \WINDOWS\system32\hal.dll \WINDOWS\system32\KDCOM.DLL \WINDOWS\system32\BOOTVID.dll ACPI.sys \WINDOWS\system32\DRIVERS\WMILIB.SYS pci.sys isapnp.sys CmgHiber.sys \WINDOWS\system32\DRIVERS\CmgCrypt.SYS compbatt.sys \WINDOWS\system32\DRIVERS\BATTC.SYS pciide.sys \WINDOWS\system32\DRIVERS\PCIIDEX.SYS intelide.sys pcmcia.sys MountMgr.sys ftdisk.sys dmload.sys dmio.sys PartMgr.sys VolSnap.sys atapi.sys disk.sys \WINDOWS\system32\DRIVERS\CLASSPNP.SYS fltMgr.sys CMGShCEF.sys sr.sys CmgShREG.sys DLACDBHM.SYS DRVMCDB.SYS PxHelp20.sys KSecDD.sys Ntfs.sys NDIS.sys Mup.sys CmgPCS.sys \SystemRoot\system32\DRIVERS\smsmdm.sys \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\igxpmp32.sys \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\bcmwl5.sys \SystemRoot\system32\DRIVERS\b57xp32.sys \SystemRoot\system32\DRIVERS\usbuhci.sys \SystemRoot\system32\DRIVERS\USBPORT.SYS \SystemRoot\system32\DRIVERS\usbehci.sys \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\serial.sys \SystemRoot\system32\DRIVERS\serenum.sys \SystemRoot\system32\DRIVERS\imapi.sys \SystemRoot\system32\DRIVERS\cdrom.sys \SystemRoot\system32\DRIVERS\redbook.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\DamewareMini.sys \SystemRoot\system32\DRIVERS\dne2000.sys \SystemRoot\system32\DRIVERS\dwvkbd.sys \SystemRoot\system32\DRIVERS\audstub.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\DRIVERS\psched.sys \SystemRoot\system32\DRIVERS\msgpc.sys \SystemRoot\system32\DRIVERS\ptilink.sys \SystemRoot\system32\DRIVERS\raspti.sys \SystemRoot\system32\DRIVERS\rdpdr.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\teefer2.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\update.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \SystemRoot\system32\DRIVERS\omci.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\drivers\sthda.sys \SystemRoot\system32\drivers\portcls.sys \SystemRoot\system32\drivers\drmk.sys \SystemRoot\system32\DRIVERS\HSXHWAZL.sys \SystemRoot\system32\DRIVERS\HSX_DPV.sys \SystemRoot\system32\DRIVERS\HSX_CNXT.sys \SystemRoot\System32\Drivers\Modem.SYS \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\System32\Drivers\i2omgmt.SYS \SystemRoot\System32\Drivers\Fs_Rec.SYS \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\Drivers\DLARTL_M.SYS \SystemRoot\system32\DRIVERS\HIDPARSE.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\Drivers\mnmdd.SYS \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\rasacd.sys \SystemRoot\system32\DRIVERS\ipsec.sys \SystemRoot\system32\DRIVERS\tcpip.sys \??\C:\WINDOWS\system32\drivers\wpsdrvnt.sys \SystemRoot\System32\Drivers\SYMTDI.SYS \SystemRoot\system32\DRIVERS\wanarp.sys \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS \SystemRoot\system32\DRIVERS\netbt.sys \SystemRoot\System32\drivers\afd.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\SYSTEM32\Drivers\SysPlant.sys \SystemRoot\System32\Drivers\SRTSPX.SYS \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\System32\Drivers\Fips.SYS \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys \??\C:\Program Files\CTLInst\CTLInst_.sys \SystemRoot\System32\Drivers\Cdfs.SYS \SystemRoot\System32\Drivers\oz776.sys \SystemRoot\System32\Drivers\SMCLIB.SYS \SystemRoot\System32\Drivers\dump_atapi.sys \SystemRoot\System32\Drivers\dump_WMILIB.SYS \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\watchdog.sys \SystemRoot\System32\drivers\dxg.sys \SystemRoot\System32\drivers\dxgthk.sys \SystemRoot\System32\igxpgd32.dll \SystemRoot\System32\igxprd32.dll \SystemRoot\System32\igxpdv32.DLL \SystemRoot\System32\igxpdx32.DLL \SystemRoot\System32\ATMFD.DLL \SystemRoot\System32\Drivers\DRVNDDM.SYS \SystemRoot\System32\Drivers\DLADResM.SYS \SystemRoot\System32\Drivers\DLAIFS_M.SYS \SystemRoot\System32\Drivers\DLAOPIOM.SYS \SystemRoot\System32\Drivers\DLAPoolM.SYS \SystemRoot\System32\Drivers\DLABMFSM.SYS \SystemRoot\System32\Drivers\DLABOIOM.SYS \SystemRoot\System32\Drivers\DLAUDFAM.SYS \SystemRoot\System32\Drivers\DLAUDF_M.SYS \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\mrxdav.sys \??\C:\WINDOWS\system32\Drivers\CVPNDRVA.sys \SystemRoot\system32\DRIVERS\mdmxsdk.sys \SystemRoot\system32\DRIVERS\srv.sys \??\C:\WINDOWS\system32\Drivers\uphcleanhlp.sys \SystemRoot\System32\Drivers\HTTP.sys \SystemRoot\System32\Drivers\SRTSP.SYS \SystemRoot\System32\Drivers\TDTCP.SYS \SystemRoot\System32\Drivers\RDPWD.SYS \SystemRoot\system32\drivers\wdmaud.sys \SystemRoot\system32\drivers\sysaudio.sys \SystemRoot\System32\Drivers\SYMREDRV.SYS \??\C:\WINDOWS\system32\CCM\prepdrv.sys \SystemRoot\System32\Drivers\Fastfat.SYS \??\C:\WINDOWS\system32\drivers\WpsHelper.sys \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20130205.003\NAVEX15.SYS \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20130205.003\NAVENG.SYS \??\C:\WINDOWS\system32\drivers\TrueSight.sys \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys \SystemRoot\system32\drivers\kmixer.sys \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys \Windows\system32\ntdll.dll ———– End ———– <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xffffffff8abc7ab8 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IdeDeviceP0T0L0-3\ Lower Device Object: 0xffffffff8ace8d98 Lower Device Driver Name: \Driver\atapi\ Device already Exists: 0xffffffff89574ce8 Initializing… Done! <<<2>>> Device number: 0, partition: 1 Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffffffff8abc7ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ ——— Disk Stack —— DevicePointer: 0xffffffff8acade08, DeviceName: Unknown, DriverName: \Driver\PartMgr\ DevicePointer: 0xffffffff8abc7970, DeviceName: Unknown, DriverName: \Driver\CmgHiber\ DevicePointer: 0xffffffff8abc7ab8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xffffffff8abc9f18, DeviceName: \Device\0000009d\, DriverName: \Driver\ACPI\ DevicePointer: 0xffffffff8ace8d98, DeviceName: \Device\Ide\IdeDeviceP0T0L0-3\, DriverName: \Driver\atapi\ ———— End ———- Upper DeviceData: 0xffffffffea3e7350, 0xffffffff8abc7ab8, 0xffffffff874276a0 Lower DeviceData: 0xffffffffe142f818, 0xffffffff8ace8d98, 0xffffffff89574ce8 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning directory: C:\WINDOWS\system32\drivers… Done! Drive 0 Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: F287A88E Partition information: Partition 0 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 2048 Numsec = 312558592 Partition file system is NTFS Partition is bootable Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 160041885696 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-2047-312561808-312581808)… Done! Performing system, memory and registry scan… Done! Scan finished =======================================
Next…………..

Please download and run ComboFix.

The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.

Give it at least 30-45 minutes to finish if needed.

Please include the C:\ComboFix.txt in your next reply for further review.

———->NOTE<———-

If you get the message Illegal operation attempted on registry key that has been marked for deletion after you run ComboFix….please reboot the computer, this should resolve the problem. You may have to do this several times if needed.

MrC
I hope to follow these directions after work today when I'm able to take this laptop home again. I'll post the results afterward. Thanks for being patient.
Well, good news and and bad news. Bad new is that I can't disable one of the security programs required to run Combofix because it's a work laptop. Good news is that the redirecting problem I had seems to have disappeared. :>)) If it continues I"ll have to do something, but for now I hope to be fixed. Thanks again!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI