This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Bogus Google search results

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I do a search on Google, or any big-name search engine for that matter, the results that pop up look normal except that the URL addresses redirect to phony sites like info.com and hotjobs.com. Happens in both Firefox and Internet Explorer.

Nothing I've tried has worked. So far I have run Ad-Aware, Spybot, Spyware Doctor, Malwarebytes' Anti-Malware, AVG, CWShredder, AboutBuster, SpSeHjFix, and an online virus scan from Trend Micro. My logs from Anti-Malware, SpSeHjFix, AVG, and AboutBuster came back clean, no infections.

Any help would be greatly appreciated. I've already wasted several hours trying to fix this problem.

Here is my log for HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:59:37 PM, on 1/1/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\msg32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\WINDOWS\system32\SNDVOL32.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [EW Message Server] msg32.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

–
End of file - 6908 bytes
Hi, and Welcome to WhatTheTech :)

My name is jpshortstuff. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research, so please be patient and I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through the instructions before starting to follow them to make sure you understand everything you have to do.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Apologies in the delay in a response. We are overwhelmed with logs at the moment and there aren't enough helpers to go around. If you still require help, please do the following:

Please download DDS and save it to your desktop.
  • Disable any script blocking protection
  • Double click dds.scr to run the tool.
  • When done, DDS.txt will open.
  • Click Yes at the next prompt for Optional Scan.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
Please describe how your computer is behaving at the moment, listing any symptoms and problems that you are experiencing.

Thanks.
Thanks for helping me. I thought my thread had been forgotten. My symptoms are still the same: A regular search on Google, Yahoo, or MSN returns what appear to be normal search results, but when I click on the links I'm redirected to bogus websites. Here is the DDS.txt report: DDS (Ver_09-01-07.01) - NTFSx86 Run by [removed] at 16:17:06.45 on Sat 01/17/2009 Internet Explorer: 6.0.2900.2180 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.423 [GMT -6:00] AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\crypserv.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\WLTRAY.exe C:\WINDOWS\stsystra.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe C:\WINDOWS\system32\msg32.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\ATI Technologies\ATI.ACE\cli.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\SNDVOL32.EXE C:\Program Files\Winamp\winamp.exe C:\Program Files\Last.fm\LastFM.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\logon.scr C:\Program Files\Adobe\Audition 1.5\Audition.exe C:\Documents and Settings\Jason\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ mDefault_Page_URL = hxxp://www.dell.com mStart Page = hxxp://www.dell.com uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: GigagetIEHelper Class: {111caa23-6f4f-42ac-8555-b48c1d87bbab} - c:\windows\system32\gigagetbho_v10.dll BHO: BitComet Helper: {39f7e362-828a-4b5a-bcaf-5b79bfdfea60} - c:\program files\bitcomet\tools\BitCometBHO_1.2.2.28.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\progra~1\mi1933~1\office12\GRA8E1~1.DLL BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_04\bin\ssv.dll TB: DAEMON Tools Toolbar: {32099aac-c132-4136-9e9a-4e364a424e17} - c:\program files\daemon tools toolbar\DTToolbar.dll TB: {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - No File TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [Broadcom Wireless Manager UI] c:\windows\system32\WLTRAY.exe mRun: [SigmatelSysTrayApp] stsystra.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [ATICCC] "c:\program files\ati technologies\ati.ace\cli.exe" runtime -Delay mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [EW Message Server] msg32.exe IE: &D&ownload &with BitComet - c:\program files\bitcomet\BitComet.exe/AddLink.htm IE: &D&ownload all video with BitComet - c:\program files\bitcomet\BitComet.exe/AddVideo.htm IE: &D&ownload all with BitComet - c:\program files\bitcomet\BitComet.exe/AddAllLink.htm IE: &Download All by Gigaget - c:\program files\giganology\gigaget\getallurl.htm IE: &Download by Gigaget - c:\program files\giganology\gigaget\geturl.htm IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000 IE: {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} IE: {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://c:\program files\bitcomet\tools\BitCometBHO_1.2.2.28.dll/206 IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0_04\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\mi1933~1\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL LSP: c:\program files\common files\pc tools\lsp\PCTLsp.dll Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\progra~1\mi1933~1\office12\GR99D3~1.DLL Notify: AtiExtEvent - Ati2evxx.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\progra~1\mi1933~1\office12\GRA8E1~1.DLL ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\jason\applic~1\mozilla\firefox\profiles\mi4qt930.default\ FF - prefs.js: browser.startup.homepage - www.google.com FF - component: c:\documents and settings\jason\application data\mozilla\firefox\profiles\mi4qt930.default\extensions\[removed]\components\coolirisstub.dll FF - component: c:\documents and settings\jason\application data\mozilla\firefox\profiles\mi4qt930.default\extensions\[removed]\platform\winnt_x86-msvc\components\ubiquity.dll FF - plugin: c:\documents and settings\jason\application data\mozilla\firefox\profiles\mi4qt930.default\extensions\[removed]\platform\winnt_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\program files\mozilla firefox\plugins\NPTURNMED.dll FF - plugin: c:\program files\quicktime\plugins\npqtplugin8.dll FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll ============= SERVICES / DRIVERS =============== R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2008-12-31 160792] R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-10-29 33792] R3 EWAVE;EWAVE;c:\windows\system32\drivers\ew.sys [2008-12-23 1447040] R3 FILESPY;FILESPY;c:\windows\system32\drivers\filespy.sys [2008-12-23 26992] R3 NSTATION;NSTATION;c:\windows\system32\drivers\nstation.sys [2008-12-23 18944] S3 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2008-12-31 40840] S3 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2008-12-31 66952] S3 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2008-12-31 81288] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2008-12-31 356920] S3 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2008-12-31 1079176] S4 aawservice;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\aawservice.exe [2008-9-10 611664] =============== Created Last 30 ================ 2009-01-15 21:38 –d—– C:\Family.Guy.S06E07.PDTV.XviD-XOR 2009-01-01 15:34 57,344 a——- C:\SpSeHjfix112.exe 2009-01-01 14:49 –d—– c:\program files\CCleaner 2008-12-31 18:01 15,504 a——- c:\windows\system32\drivers\mbam.sys 2008-12-31 18:01 38,496 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-31 18:01 –d—– c:\program files\Malwarebytes' Anti-Malware 2008-12-31 17:41 160,792 a——- c:\windows\system32\drivers\pctfw2.sys 2008-12-31 17:41 81,288 a——- c:\windows\system32\drivers\iksyssec.sys 2008-12-31 17:41 66,952 a——- c:\windows\system32\drivers\iksysflt.sys 2008-12-31 17:41 40,840 a——- c:\windows\system32\drivers\ikfilesec.sys 2008-12-31 17:41 29,576 a——- c:\windows\system32\drivers\kcom.sys 2008-12-31 17:41 –d—– c:\program files\Spyware Doctor 2008-12-31 17:41 –d—– c:\docume~1\jason\applic~1\PC Tools 2008-12-31 17:41 –d—– c:\docume~1\alluse~1\applic~1\PC Tools 2008-12-31 01:05 –d—– C:\fixwareout 2008-12-27 11:51 –d—– c:\docume~1\jason\applic~1\Malwarebytes 2008-12-27 11:51 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2008-12-26 16:14 –d—– c:\program files\Lavasoft 2008-12-26 16:13 –d—– c:\program files\common files\Wise Installation Wizard 2008-12-26 13:10 –d—– c:\program files\Spybot - Search & Destroy 2008-12-26 13:10 –d—– c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy 2008-12-24 18:13 6,742 a——- C:\scope 2008-12-24 17:13 –d—– c:\program files\Digital Guitar Tuner 2.3 2008-12-24 17:01 –d—– c:\program files\Digidesign 2008-12-24 17:01 –d—– c:\program files\Garritan Personal Orchestra 2008-12-23 15:15 230 a——- C:\scope.dbg 2008-12-23 15:15 –d—– C:\g3LicenseBackup 2008-12-23 14:55 1,447,040 a——- c:\windows\system32\drivers\ew.sys 2008-12-23 14:55 26,992 a——- c:\windows\system32\drivers\filespy.sys 2008-12-23 14:55 233,920 a——- c:\windows\system32\drivers\nmippexp.sys 2008-12-23 14:55 37,472 a——- c:\windows\system32\drivers\gp2mpm.sys 2008-12-23 14:55 18,944 a——- c:\windows\system32\drivers\nstation.sys 2008-12-21 18:29 –d—– c:\program files\common files\PC Tools ==================== Find3M ==================== 2009-01-16 01:27 4,294 a——- c:\docume~1\jason\applic~1\wklnhst.dat 2008-12-17 17:43 604 a—h— c:\program files\STLL Notifier 2006-05-03 03:06 163,328 —shr– c:\windows\system32\flvDX.dll 2007-02-21 04:47 31,232 —shr– c:\windows\system32\msfDX.dll 2008-03-16 06:30 216,064 —shr– c:\windows\system32\nbDX.dll ============= FINISH: 16:17:26.09 ===============

Attachments:

Hi :)

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Post that log back here.

Download the GMER Rootkit Scanner. Unzip it to your Desktop.

Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

Double-click gmer.exe. The program will begin to run.

**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<— ROOKIT" entries unless advised!

If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked … leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 11.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6 Update 11, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u11-windowsi586.exe to install the newest version.
Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
  • Please post this log in your next reply.
Please describe any changes to your computer's behaviour after running MalwareBytes'.

Thanks.
Sorry for getting back to you so late. I was busy yesterday and didn't get around to doing all these scans until late last night.

After running MalwareBytes' I don't see any difference in my computer or the specific redirection problem I'm having.

Malwarebytes' Anti-Malware log:

Malwarebytes' Anti-Malware 1.31
Database version: 1587
Windows 5.1.2600 Service Pack 2

1/18/2009 7:43:24 PM
mbam-log-2009-01-18 (19-43-24).txt

Scan type: Full Scan (C:\|)
Objects scanned: 172610
Time elapsed: 1 hour(s), 0 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


=============================================================================




GMER Rootkit Scanner log:

GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2009-01-18 21:37:30
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.14 —-

SSDT sphx.sys ZwCreateKey [0xF74110E0]
SSDT sphx.sys ZwEnumerateKey [0xF742FCA2]
SSDT sphx.sys ZwEnumerateValueKey [0xF7430030]
SSDT sphx.sys ZwOpenKey [0xF74110C0]
SSDT sphx.sys ZwQueryKey [0xF7430108]
SSDT sphx.sys ZwQueryValueKey [0xF742FF88]
SSDT sphx.sys ZwSetValueKey [0xF743019A]

INT 0x62 ? 867D8BF8
INT 0x82 ? 867D8BF8
INT 0x84 ? 86522BF8
INT 0x94 ? 86522BF8
INT 0xB4 ? 86522BF8

—- Kernel code sections - GMER 1.0.14 —-

? sphx.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload F6B7168E 5 Bytes JMP 865221D8
.text a13kc9v6.SYS F6A70386 35 Bytes [ 00, 00, 00, 00, 00, 00, 20, … ]
.text a13kc9v6.SYS F6A703AA 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, … ]
.text a13kc9v6.SYS F6A703C4 3 Bytes [ 00, 70, 02 ]
.text a13kc9v6.SYS F6A703C9 1 Byte [ 2E ]
.text a13kc9v6.SYS F6A703CB 9 Bytes [ 00, 00, 5A, 02, 00, 00, 00, … ]
.text …

—- Kernel IAT/EAT - GMER 1.0.14 —-

IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F7412040] sphx.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F741213C] sphx.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74120BE] sphx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74127FC] sphx.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74126D2] sphx.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F7422048] sphx.sys
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!KfAcquireSpinLock] 4B8BDF8B
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!READ_PORT_UCHAR] 8D3F0304
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!KeGetCurrentIrql] CB033043
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!KfRaiseIrql] 0673C13B
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!KfLowerIrql] C13B0003
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!HalGetInterruptVector] 8366FA72
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!HalTranslateBusAddress] 75000E7B
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!KeStallExecutionProcessor] 0B7D80E3
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!KfReleaseSpinLock] 307B8D00
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!READ_PORT_BUFFER_USHORT] 00AA840F
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!READ_PORT_USHORT] 83660000
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!WRITE_PORT_BUFFER_USHORT] 6A000E7A
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[HAL.dll!WRITE_PORT_UCHAR] C6647400
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[WMILIB.SYS!WmiSystemControl] 4F8B0200
IAT \SystemRoot\System32\Drivers\a13kc9v6.SYS[WMILIB.SYS!WmiCompleteRequest] 968D5140

—- Devices - GMER 1.0.14 —-

Device \FileSystem\Ntfs \Ntfs 867D71F8

AttachedDevice \FileSystem\Ntfs \Ntfs FILESPY.sys (TASCAM kernel file spy/TASCAM)
AttachedDevice \Driver\Tcpip \Device\Ip pctfw2.sys (PC Tools TDI Driver/PC Tools)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 SynTP.sys (Synaptics Touchpad Driver/Synaptics, Inc.)

Device \Driver\sptd \Device\1439180012 sphx.sys
Device \Driver\usbuhci \Device\USBPDO-0 86520500
Device \Driver\usbuhci \Device\USBPDO-1 86520500
Device \Driver\usbuhci \Device\USBPDO-2 86520500
Device \Driver\usbuhci \Device\USBPDO-3 86520500
Device \Driver\usbehci \Device\USBPDO-4 864ED1F8

AttachedDevice \Driver\Tcpip \Device\Tcp pctfw2.sys (PC Tools TDI Driver/PC Tools)

Device \Driver\Ftdisk \Device\HarddiskVolume1 867691F8
Device \Driver\Ftdisk \Device\HarddiskVolume2 867691F8
Device \Driver\Cdrom \Device\CdRom0 8645E500
Device \Driver\Cdrom \Device\CdRom1 8645E500
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 867D81F8
Device \Driver\atapi \Device\Ide\IdePort0 867D81F8
Device \Driver\atapi \Device\Ide\IdePort1 867D81F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e 867D81F8
Device \Driver\Ftdisk \Device\HarddiskVolume3 867691F8
Device \Driver\Ftdisk \Device\HarddiskVolume4 867691F8
Device \Driver\NetBT \Device\NetBt_Wins_Export 863BC500
Device \Driver\NetBT \Device\NetbiosSmb 863BC500
Device \Driver\NetBT \Device\NetBT_Tcpip_{42FC76AF-8185-4C78-94B2-0F2A0C551C2D} 863BC500
Device \Driver\PCI_PNP7512 \Device\0000004f sphx.sys

AttachedDevice \Driver\Tcpip \Device\Udp pctfw2.sys (PC Tools TDI Driver/PC Tools)
AttachedDevice \Driver\Tcpip \Device\RawIp pctfw2.sys (PC Tools TDI Driver/PC Tools)

Device \Driver\usbuhci \Device\USBFDO-0 86520500
Device \Driver\usbuhci \Device\USBFDO-1 86520500
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 86253500
Device \Driver\usbuhci \Device\USBFDO-2 86520500
Device \FileSystem\MRxSmb \Device\LanmanRedirector 86253500
Device \Driver\usbuhci \Device\USBFDO-3 86520500
Device \Driver\usbehci \Device\USBFDO-4 864ED1F8
Device \Driver\Ftdisk \Device\FtControl 867691F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{E6476A22-8AEF-4F4F-9A6B-D21EE2C614A0} 863BC500
Device \Driver\a13kc9v6 \Device\Scsi\a13kc9v61Port2Path0Target0Lun0 863AB368
Device \Driver\a13kc9v6 \Device\Scsi\a13kc9v61 863AB368
Device \FileSystem\Fastfat \Fat 862C7500
Device \FileSystem\Fastfat \Fat BA39E1F9
Device \FileSystem\Fs_Rec \FileSystem\UdfsCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatCdRomRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\CdfsRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\FatDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Fs_Rec \FileSystem\UdfsDiskRecognizer tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)
Device \FileSystem\Cdfs \Cdfs 862B4500
Device \FileSystem\Cdfs \Cdfs tfsnifs.sys (Drive Letter Access Component/Sonic Solutions)

—- Threads - GMER 1.0.14 —-

Thread 4:2120 EB8AE150

—- Registry - GMER 1.0.14 —-

Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x67 0x70 0x3A 0x5B …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF7 0x8A 0x8A 0x5A …
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x68 0x85 0x91 0x85 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x67 0x70 0x3A 0x5B …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001@khjeh 0xF7 0x8A 0x8A 0x5A …
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40
Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40@khjeh 0x68 0x85 0x91 0x85 …

—- EOF - GMER 1.0.14 —-

=============================================================================




Kapersky scan log:

——————————————————————————–
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, January 19, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, January 19, 2009 01:27:51
Records in database: 1644659
——————————————————————————–

Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\

Scan statistics:
Files scanned: 112030
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 03:10:01


File name / Threat name / Threats count
C:\WINDOWS\system32\wdmaud.sys Infected: Rootkit.Win32.Agent.fwt 1

The selected area was scanned.
Hi :)

Sorry for getting back to you so late. I was busy yesterday and didn't get around to doing all these scans until late last night.

No worries, we are all busy.


Download ComboFix by sUBs from here or here

Note: If you already have a copy of ComboFix on your system it is essential that you delete it before downloading this copy.

**Save it to your desktop**

We need to disable one or more of your security programs so that they do not interfere with ComboFix.

Please disable SpywareDoctor, you should be able to do this via its icon in the system tray. For more information see here:
http://forums.whatthetech.com/How_Disable_…ams_t96260.html

Double click on ComboFix.exe & follow the prompts. If you are prompted to install the Recovery Console I recommend you go ahead and hit yes.
When finished, it shall produce a log for you. Please save that log to post in your next reply along with a fresh HJT log

Notes:
  • Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
  • Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you - please let me know.
  • ComboFix disconnects your machine from the internet when it runs. This connection should be automatically restored when ComboFix completes its run. If ComboFix runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Thanks.
Wow, it worked! Problem solved! I get authentic search results from search engines and the computer is running just fine. Everything seems to be in order. Thanks a ton for helping me, jpshortstuff. I really appreciate it. I had pretty much resigned myself to the fact that I was going to have to live with this problem forever before you helped out. I know you guys tend to suggest follow-up procedures after the removal process, so I'll keep checking back on this thread to see if you have any further instructions. Thanks again. :notworthy:
Oops! Totally forgot to include those logs in my post.

ComboFix log:

ComboFix 09-01-19.03 - Jason 2009-01-19 19:58:15.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.664 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\wdmaud.sys

.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.

2009-01-18 21:45 . 2009-01-18 21:45 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-18 21:45 . 2009-01-18 21:45 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-18 19:50 . 2009-01-18 19:50 250 –a—— c:\windows\gmer.ini
2009-01-15 21:38 . 2007-11-25 21:44 d——– C:\Family.Guy.S06E07.PDTV.XviD-XOR
2009-01-01 17:42 . 2009-01-01 17:42 d——– c:\program files\ERUNT
2009-01-01 15:34 . 2009-01-01 15:34 57,344 –a—— C:\SpSeHjfix112.exe
2009-01-01 14:49 . 2009-01-01 14:49 d——– c:\program files\CCleaner
2008-12-31 18:01 . 2008-12-31 18:01 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-31 18:01 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-31 18:01 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-31 17:41 . 2009-01-19 19:29 d——– c:\program files\Spyware Doctor
2008-12-31 01:31 . 2008-12-31 04:19 d——– c:\windows\BDOSCAN8
2008-12-31 01:05 . 2009-01-01 15:19 d——– C:\fixwareout
2008-12-27 11:51 . 2008-12-27 11:51 d——– c:\documents and settings\Jason\Application Data\Malwarebytes
2008-12-27 11:51 . 2008-12-27 11:51 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-26 16:14 . 2008-12-26 16:14 d——– c:\program files\Lavasoft
2008-12-26 16:13 . 2008-12-26 16:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-12-26 13:10 . 2008-12-28 13:52 d——– c:\program files\Spybot - Search & Destroy
2008-12-26 13:10 . 2008-12-28 13:52 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-24 18:13 . 2009-01-18 18:43 7,746 –a—— C:\scope
2008-12-24 17:13 . 2008-12-24 17:13 d——– c:\program files\Digital Guitar Tuner 2.3
2008-12-24 17:01 . 2008-12-24 19:37 d——– c:\program files\Garritan Personal Orchestra
2008-12-24 17:01 . 2008-12-24 17:01 d——– c:\program files\Digidesign
2008-12-23 16:27 . 2008-04-02 19:30 d——– c:\documents and settings\Administrator\Application Data\InstallShield
2008-12-23 16:27 . 2008-04-02 19:40 d–h—– c:\documents and settings\Administrator\Application Data\Gtek
2008-12-23 16:27 . 2008-04-02 19:45 d——– c:\documents and settings\Administrator\Application Data\ATI
2008-12-23 16:27 . 2009-01-01 20:08 d——– c:\documents and settings\Administrator
2008-12-23 15:15 . 2008-12-23 15:15 d——– C:\g3LicenseBackup
2008-12-23 15:15 . 2008-12-24 16:17 230 –a—— C:\scope.dbg
2008-12-23 14:55 . 2006-12-10 01:08 1,447,040 –a—— c:\windows\system32\drivers\ew.sys
2008-12-23 14:55 . 2006-12-10 01:08 233,920 –a—— c:\windows\system32\drivers\nmippexp.sys
2008-12-23 14:55 . 2006-12-10 01:08 37,472 –a—— c:\windows\system32\drivers\gp2mpm.sys
2008-12-23 14:55 . 2006-12-10 01:08 26,992 –a—— c:\windows\system32\drivers\filespy.sys
2008-12-23 14:55 . 2006-12-10 01:08 18,944 –a—— c:\windows\system32\drivers\nstation.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-20 01:29 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-19 03:45 ——— d—–w c:\program files\Java
2009-01-19 01:48 ——— d—–w c:\program files\Zoom Player
2009-01-16 07:27 4,294 —-a-w c:\documents and settings\Jason\Application Data\wklnhst.dat
2009-01-16 00:48 ——— d—–w c:\program files\Native Instruments
2009-01-13 19:09 ——— d—–w c:\program files\Matroska Pack
2009-01-07 20:21 ——— d—–w c:\documents and settings\Jason\Application Data\Move Networks
2008-12-26 22:14 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-24 07:07 ——— d—–w c:\documents and settings\Jason\Application Data\Sibelius Software
2008-12-24 07:06 ——— d—–w c:\program files\Sibelius Software
2008-12-18 20:03 ——— d—–w c:\program files\Smart Projects
2008-12-18 01:22 ——— d—–w c:\program files\Vstplugins
2008-12-18 01:22 ——— d—–w c:\program files\Common Files\Digidesign
2008-12-17 23:43 604 —ha-w c:\program files\STLL Notifier
2008-12-17 23:43 ——— d—–w c:\documents and settings\All Users\Application Data\Sibelius Software
2008-12-15 01:01 ——— d—–w c:\program files\Tale of Tales
2008-12-03 09:07 ——— d—–w c:\program files\Diet Analysis Plus 8.0
2008-12-01 23:23 ——— d—–w c:\documents and settings\Jason\Application Data\OpenOffice.org2
2008-12-01 06:08 ——— d—–w c:\documents and settings\Jason\Application Data\Thomson Learning
2008-11-28 02:19 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-28 02:15 ——— d—–w c:\program files\Netflix
2006-05-03 09:06 163,328 –sh–r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 –sh–r c:\windows\system32\msfDX.dll
2008-03-16 12:30 216,064 –sh–r c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-18 136600]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"midi"= gmidi.dll
"MIDI2"= MYokeNT.DLL
"aux2"= wdmaud.sys

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
–a—— 2004-02-19 05:23 61440 c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
–a—— 2008-08-08 06:11 490952 c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
–a—— 2007-02-20 11:29 1191936 c:\program files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2006-08-28 20:57 395776 c:\program files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a—— 2006-10-27 00:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
–a—— 2005-10-22 23:00 385024 c:\program files\Syncrosoft\POS\H2O\cledx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
——— 2003-09-10 01:24 20480 c:\program files\NetWaiting\netwaiting.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
——— 2007-05-02 17:16 184320 c:\program files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EW Message Server]
–a—— 2006-12-10 01:08 45056 c:\windows\system32\msg32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wltrysvc"=3 (0x3)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"aawservice"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"PCTAVSvc"=2 (0x2)
"gusvc"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24162:TCP"= 24162:TCP:BitComet 24162 TCP
"24162:UDP"= 24162:UDP:BitComet 24162 UDP

R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-10-29 33792]
S3 EWAVE;EWAVE;c:\windows\system32\drivers\ew.sys [2008-12-23 1447040]
S3 FILESPY;FILESPY;c:\windows\system32\drivers\filespy.sys [2008-12-23 26992]
S3 NSTATION;NSTATION;c:\windows\system32\drivers\nstation.sys [2008-12-23 18944]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
MSConfigStartUp-IS CfgWiz - c:\program files\Norton Internet Security\cfgwiz.exe
MSConfigStartUp-PCTAVApp - c:\program files\PC Tools AntiVirus\PCTAV.exe
MSConfigStartUp-SSC_UserPrompt - c:\program files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
MSConfigStartUp-SunJavaUpdateSched - c:\program files\Java\jre1.6.0_04\bin\jusched.exe
MSConfigStartUp-TkBellExe - c:\program files\Common Files\Real\Update_OB\realsched.exe
MSConfigStartUp-URLLSTCK - c:\program files\Norton Internet Security\UrlLstCk.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyOverride = *.local
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Download All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\platform\WINNT_x86-msvc\components\ubiquity.dll
FF - plugin: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-19 19:59:51
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4278838382-2642953312-2933363751-1006\Software\Microsoft\Multimedia\D$@€ù‡©*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(872)
c:\windows\system32\MYokeNT.DLL
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(928)
c:\windows\system32\MYokeNT.DLL
.
Completion time: 2009-01-19 20:01:56
ComboFix-quarantined-files.txt 2009-01-20 02:01:53

Pre-Run: 26,940,039,168 bytes free
Post-Run: 27,199,041,536 bytes free

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

226

===================================================


HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:34:18 PM, on 1/20/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\logon.scr
C:\WINDOWS\system32\SNDVOL32.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 7078 bytes
Hi :)

A couple of things to clean up, and we also want a sample of one of those files.

Please go to this site:
http://www.bleepingcomputer.com/submit-malware.php?channel=8

In the "link to topic" field paste this in:
http://forums.whatthetech.com/Bogus_Google_search_results_t98541.html&view=findpost&p=520910

Browse to this file and hit open:
C:\QooBox\C\Windows\system32\wdmaud.sys.vir (or similar)

Then hit "Send File".


1. Please open Notepad
  • Click Start , then Run
  • Type notepad.exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:

File::
C:\SpSeHjfix112.exe

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"="wdmaud.drv"

3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
Is the computer running fine now?

Thanks.
PC is still running smoothly. :thumbup:

ComboFix log:

ComboFix 09-01-21.04 - Jason 2009-01-22 18:16:15.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1022.657 [GMT -6:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Jason\Desktop\CFScript.txt
* Created a new restore point

FILE ::
C:\SpSeHjfix112.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\SpSeHjfix112.exe

.
((((((((((((((((((((((((( Files Created from 2008-12-23 to 2009-01-23 )))))))))))))))))))))))))))))))
.

2009-01-22 01:44 . 2009-01-22 02:06 d——– C:\AVIMux
2009-01-19 22:15 . 2009-01-19 22:22 d——– c:\program files\DC++
2009-01-18 21:45 . 2009-01-18 21:45 410,984 –a—— c:\windows\system32\deploytk.dll
2009-01-18 21:45 . 2009-01-18 21:45 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-01-18 19:50 . 2009-01-18 19:50 250 –a—— c:\windows\gmer.ini
2009-01-15 21:38 . 2007-11-25 21:44 d——– C:\Family.Guy.S06E07.PDTV.XviD-XOR
2009-01-01 17:42 . 2009-01-01 17:42 d——– c:\program files\ERUNT
2009-01-01 14:49 . 2009-01-01 14:49 d——– c:\program files\CCleaner
2008-12-31 18:01 . 2008-12-31 18:01 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-31 18:01 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-31 18:01 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-31 17:41 . 2009-01-19 19:29 d——– c:\program files\Spyware Doctor
2008-12-31 01:31 . 2008-12-31 04:19 d——– c:\windows\BDOSCAN8
2008-12-31 01:05 . 2009-01-01 15:19 d——– C:\fixwareout
2008-12-27 11:51 . 2008-12-27 11:51 d——– c:\documents and settings\Jason\Application Data\Malwarebytes
2008-12-27 11:51 . 2008-12-27 11:51 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-26 16:14 . 2008-12-26 16:14 d——– c:\program files\Lavasoft
2008-12-26 16:13 . 2008-12-26 16:13 d——– c:\program files\Common Files\Wise Installation Wizard
2008-12-26 13:10 . 2008-12-28 13:52 d——– c:\program files\Spybot - Search & Destroy
2008-12-26 13:10 . 2008-12-28 13:52 d——– c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-24 18:13 . 2009-01-18 18:43 7,746 –a—— C:\scope
2008-12-24 17:13 . 2008-12-24 17:13 d——– c:\program files\Digital Guitar Tuner 2.3
2008-12-24 17:01 . 2008-12-24 19:37 d——– c:\program files\Garritan Personal Orchestra
2008-12-24 17:01 . 2008-12-24 17:01 d——– c:\program files\Digidesign
2008-12-23 16:27 . 2008-04-02 19:30 d——– c:\documents and settings\Administrator\Application Data\InstallShield
2008-12-23 16:27 . 2008-04-02 19:40 d–h—– c:\documents and settings\Administrator\Application Data\Gtek
2008-12-23 16:27 . 2008-04-02 19:45 d——– c:\documents and settings\Administrator\Application Data\ATI
2008-12-23 16:27 . 2009-01-01 20:08 d——– c:\documents and settings\Administrator
2008-12-23 15:15 . 2008-12-23 15:15 d——– C:\g3LicenseBackup
2008-12-23 15:15 . 2008-12-24 16:17 230 –a—— C:\scope.dbg
2008-12-23 14:55 . 2006-12-10 01:08 1,447,040 –a—— c:\windows\system32\drivers\ew.sys
2008-12-23 14:55 . 2006-12-10 01:08 233,920 –a—— c:\windows\system32\drivers\nmippexp.sys
2008-12-23 14:55 . 2006-12-10 01:08 37,472 –a—— c:\windows\system32\drivers\gp2mpm.sys
2008-12-23 14:55 . 2006-12-10 01:08 26,992 –a—— c:\windows\system32\drivers\filespy.sys
2008-12-23 14:55 . 2006-12-10 01:08 18,944 –a—— c:\windows\system32\drivers\nstation.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-22 07:42 ——— d—–w c:\program files\Zoom Player
2009-01-20 23:05 ——— d—–w c:\program files\Native Instruments
2009-01-20 19:27 ——— d—–w c:\program files\7-Zip
2009-01-20 01:29 ——— d—a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-19 03:45 ——— d—–w c:\program files\Java
2009-01-16 07:27 4,294 —-a-w c:\documents and settings\Jason\Application Data\wklnhst.dat
2009-01-13 19:09 ——— d—–w c:\program files\Matroska Pack
2009-01-07 20:21 ——— d—–w c:\documents and settings\Jason\Application Data\Move Networks
2008-12-26 22:14 ——— d—–w c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-24 07:07 ——— d—–w c:\documents and settings\Jason\Application Data\Sibelius Software
2008-12-24 07:06 ——— d—–w c:\program files\Sibelius Software
2008-12-18 20:03 ——— d—–w c:\program files\Smart Projects
2008-12-18 01:22 ——— d—–w c:\program files\Vstplugins
2008-12-18 01:22 ——— d—–w c:\program files\Common Files\Digidesign
2008-12-17 23:43 604 —ha-w c:\program files\STLL Notifier
2008-12-17 23:43 ——— d—–w c:\documents and settings\All Users\Application Data\Sibelius Software
2008-12-15 01:01 ——— d—–w c:\program files\Tale of Tales
2008-12-03 09:07 ——— d—–w c:\program files\Diet Analysis Plus 8.0
2008-12-01 23:23 ——— d—–w c:\documents and settings\Jason\Application Data\OpenOffice.org2
2008-12-01 06:08 ——— d—–w c:\documents and settings\Jason\Application Data\Thomson Learning
2008-11-28 02:19 ——— d—–w c:\program files\Windows Media Connect 2
2008-11-28 02:15 ——— d—–w c:\program files\Netflix
2006-05-03 09:06 163,328 –sh–r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 –sh–r c:\windows\system32\msfDX.dll
2008-03-16 12:30 216,064 –sh–r c:\windows\system32\nbDX.dll
.

((((((((((((((((((((((((((((( snapshot@2009-01-19_20.00.36.90 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-23 00:07:32 16,384 —-atw c:\windows\Temp\Perflib_Perfdata_784.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-22 1392640]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-18 136600]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"midi"= gmidi.dll
"MIDI2"= MYokeNT.DLL

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=c:\windows\pss\Adobe Gamma.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Jason^Start Menu^Programs^Startup^OpenOffice.org 2.4.lnk]
path=c:\documents and settings\Jason\Start Menu\Programs\Startup\OpenOffice.org 2.4.lnk
backup=c:\windows\pss\OpenOffice.org 2.4.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BuildBU]
–a—— 2004-02-19 05:23 61440 c:\dell\bldbubg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
–a—— 2008-08-08 06:11 490952 c:\program files\DAEMON Tools Lite\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
–a—— 2007-02-20 11:29 1191936 c:\program files\Dell\QuickSet\quickset.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
–a—— 2006-08-28 20:57 395776 c:\program files\Dell Support\DSAgnt.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
–a—— 2006-10-27 00:47 31016 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H2O]
–a—— 2005-10-22 23:00 385024 c:\program files\Syncrosoft\POS\H2O\cledx.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
——— 2003-09-10 01:24 20480 c:\program files\NetWaiting\netwaiting.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
–a—— 2004-10-13 10:24 1694208 c:\program files\Messenger\msmsgs.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
——— 2007-05-02 17:16 184320 c:\program files\Dell\MediaDirect\PCMService.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-05-27 09:50 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EW Message Server]
–a—— 2006-12-10 01:08 45056 c:\windows\system32\msg32.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"wltrysvc"=3 (0x3)
"avg8wd"=2 (0x2)
"avg8emc"=2 (0x2)
"Adobe LM Service"=3 (0x3)
"aawservice"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"PCTAVSvc"=2 (0x2)
"gusvc"=3 (0x3)
"sdCoreService"=3 (0x3)
"sdAuxService"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"c:\\Program Files\\Giganology\\Gigaget\\Gigaget.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24162:TCP"= 24162:TCP:BitComet 24162 TCP
"24162:UDP"= 24162:UDP:BitComet 24162 UDP

R3 CLEDX;Team H2O CLEDX service;c:\windows\system32\drivers\cledx.sys [2008-10-29 33792]
S3 EWAVE;EWAVE;c:\windows\system32\drivers\ew.sys [2008-12-23 1447040]
S3 FILESPY;FILESPY;c:\windows\system32\drivers\filespy.sys [2008-12-23 26992]
S3 NSTATION;NSTATION;c:\windows\system32\drivers\nstation.sys [2008-12-23 18944]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.com/
mStart Page = hxxp://www.dell.com
uInternet Connection Wizard,ShellNext = hxxp://www.dell.com/
uInternet Settings,ProxyOverride = *.local
IE: &D;&ownload; &with; BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D;&ownload; all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D;&ownload; all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Download; All by Gigaget - c:\program files\Giganology\Gigaget\getallurl.htm
IE: &Download; by Gigaget - c:\program files\Giganology\Gigaget\geturl.htm
IE: E&xport; to Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\
FF - prefs.js: browser.startup.homepage - www.google.com
FF - component: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\components\coolirisstub.dll
FF - component: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\platform\WINNT_x86-msvc\components\ubiquity.dll
FF - plugin: c:\documents and settings\Jason\Application Data\Mozilla\Firefox\Profiles\mi4qt930.default\extensions\[removed]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-22 18:19:59
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-4278838382-2642953312-2933363751-1006\Software\Microsoft\Multimedia\D$@€ù‡©*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(868)
c:\windows\system32\MYokeNT.DLL
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(924)
c:\windows\system32\MYokeNT.DLL
.
Completion time: 2009-01-22 18:21:39
ComboFix-quarantined-files.txt 2009-01-23 00:21:26
ComboFix2.txt 2009-01-20 02:01:57

Pre-Run: 25,000,722,432 bytes free
Post-Run: 25,181,515,776 bytes free

218

===================================================================



HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:17:29 AM, on 1/23/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\crypserv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: GigagetIEHelper - {111CAA23-6F4F-42AC-8555-B48C1D87BBAB} - C:\WINDOWS\system32\gigagetbho_v10.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MI1933~1\Office12\GRA8E1~1.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D;&ownload; &with; BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D;&ownload; all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D;&ownload; all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Download; All by Gigaget - C:\Program Files\Giganology\Gigaget\getallurl.htm
O8 - Extra context menu item: &Download; by Gigaget - C:\Program Files\Giganology\Gigaget\geturl.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MI1933~1\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/…tiveXPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MI1933~1\Office12\GR99D3~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Crypkey License - CrypKey (Canada) Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

–
End of file - 6980 bytes
Hi Nift

Log looks good :thumbup:


Click Start >> Run, and then type ComboFix /u and hit enter.
You can now delete any other tools I had you download and use, unless you wish to keep them.


Make sure you have re-enabled Spyware Doctor.


Now that your system appears to be clean, theres just a few steps I'd like you to take to prevent any future infections.
  • You need to upgrade to Windows XP Service Pack 3. Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install Windows XP - Service Pack 3.

  • Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis.

  • You don't appear to be running any third party Firewall software.

    Install a firewall! Without a firewall you are very susceptible to being hacked, and people could gain access to your computer. If you don't have a firewall I strongly recommend you download ONE of the following:
    1) Comodo
    2) Agnitum
    3) Sunbelt/Kerio

  • Use Mozilla Firefox or Opera as your internet browser.
    These are more secure than Internet Explorer and can be downloaded for free from here:
    Download Mozilla FireFox
    Download Opera
    Alternatively, update Internet Explorer to version 7.

  • Make sure you update your Anti-Virus software regularly, new viruses are being developed all the time.

  • Some more programs that it would be useful to have [OPTIONAL but RECOMMENDED]:

    Download Spybot Search and Destroy 1.5 from here
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.

    SpywareBlaster is another real-time scanner that prevents most spyware from even being installed.
    Freely available: Download SpywareBlaster

    Download and install the free version of WinPatrol. This program protects your computer in a variety of ways and will work well with your existing security software. Have a look at this tutorial to help you get started with the program.
Also, please read this great article by Tony Klein: So How Did I Get Infected In First Place

Glad we could be of assistance.

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Stay Clean!

jpshortstuff
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI