letsee
Topic Starter
LDTate (or other moderator):
It seems others have had this same problem lately. I followed what you suggested for someone else and used ComboFix and it seemed to fix the issue, but I want to be sure there isn't anything more I should do to clean things up. I didn't do anything other than running ComboFix (I didn't do anything with notepad or cmd line things you mentioned to someone). Previously, anytime I used any search engine such as yahoo or google I was getting results that are to the wrong sites (ad sites or other search type things). Now it seems to be fixed. Here is my ComboFix log. Thank you!
ComboFix 09-01-19.05 - bfmn 2009-01-20 11:49:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.530 [GMT -8:00]
Running from: F:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\wdmaud.sys
.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.
2009-01-20 10:56 . 2009-01-20 10:57 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-20 10:56 . 2009-01-20 10:56 d——– c:\documents and settings\bfortman\Application Data\Malwarebytes
2009-01-20 10:56 . 2009-01-20 10:56 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-20 10:56 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-20 10:56 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-16 17:52 . 2009-01-16 17:52 d——– c:\program files\Trend Micro
2009-01-16 15:44 . 2009-01-16 15:47 d——– C:\test
2009-01-16 15:08 . 2009-01-16 15:08 d——– c:\windows\Sun
2008-12-22 10:13 . 2009-01-13 17:36 69 –a—— c:\windows\NeroDigital.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-16 23:51 ——— d—–w c:\program files\Windows Desktop Search
2008-12-24 01:49 ——— d—–w c:\documents and settings\bfortman\Application Data\AdobeUM
2008-12-23 19:42 ——— d—–w c:\program files\Common Files\Adobe
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-10 18:11 ——— d—–w c:\program files\IrfanView
2008-12-09 22:57 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-09 22:57 ——— d—a-w c:\program files\Canon
2008-12-09 22:56 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-08 17:24 ——— d—–w c:\documents and settings\bfortman\Application Data\FileMaker
2008-12-08 17:23 ——— d—–w c:\program files\FileMaker
2008-12-05 23:31 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-05 22:39 ——— d—–w c:\documents and settings\bfortman\Application Data\Windows Search
2008-12-05 22:32 ——— d—–w c:\program files\MIKSOFT
2008-12-05 22:30 ——— d—–w c:\program files\Java
2008-12-05 22:14 ——— d—–w c:\documents and settings\administrator\Application Data\Windows Desktop Search
2008-12-05 21:55 ——— d—–w c:\documents and settings\Owner\Application Data\Windows Desktop Search
2008-12-05 21:53 ——— d—–w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-05 21:26 ——— d—–w c:\program files\Creative
2008-12-05 21:22 ——— d—–w c:\program files\SigmaTel
2008-12-05 21:18 ——— d—–w c:\program files\AMD
2008-12-05 21:17 ——— d—–w c:\program files\Common Files\Java
2008-12-05 21:15 5 —-a-w c:\windows\system32\drivers\DELL_DIM_E521.MRK
2008-12-05 21:15 5 —-a-w c:\windows\system32\drivers\1028_DELL_DIM_E521.MRK
2008-12-05 21:14 ——— d—–w c:\program files\Broadcom
2008-12-05 21:07 ——— d—–w c:\program files\Eset
2008-12-05 21:07 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2008-12-05 21:06 ——— d—–w c:\program files\RealVNC
2008-12-05 20:45 ——— d—–w c:\program files\Analog Devices
2008-12-05 12:36 3,328 —-a-w c:\windows\system32\drivers\pciide.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2005-08-31 1658592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe" [2007-11-09 1274600]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe" [2007-11-09 884696]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-11-09 136472]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-05 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-05 137752]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-05 136600]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2006-08-23 c:\windows\system32\nwiz.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-02-20 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= wdmaud.sys
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-02-20 33800]
R3 shwMirror;shwMirror;c:\windows\system32\drivers\shwMirror.sys [2006-08-29 3584]
R4 ekrn;Eset Service;c:\program files\Eset\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-01-20 38496]
.
.
——- Supplementary Scan ——-
.
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\bfortman\Application Data\Mozilla\Firefox\Profiles\3okjpcqt.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 11:58:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(812)
c:\windows\system32\relog_ap.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\rundll32.exe
c:\program files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
.
**************************************************************************
.
Completion time: 2009-01-20 11:59:22 - machine was rebooted [bfortman]
ComboFix-quarantined-files.txt 2009-01-20 19:59:20
Pre-Run: 105,552,703,488 bytes free
Post-Run: 106,128,818,176 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
148 — E O F — 2009-01-14 11:01:38
It seems others have had this same problem lately. I followed what you suggested for someone else and used ComboFix and it seemed to fix the issue, but I want to be sure there isn't anything more I should do to clean things up. I didn't do anything other than running ComboFix (I didn't do anything with notepad or cmd line things you mentioned to someone). Previously, anytime I used any search engine such as yahoo or google I was getting results that are to the wrong sites (ad sites or other search type things). Now it seems to be fixed. Here is my ComboFix log. Thank you!
ComboFix 09-01-19.05 - bfmn 2009-01-20 11:49:50.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.530 [GMT -8:00]
Running from: F:\ComboFix.exe
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\wdmaud.sys
.
((((((((((((((((((((((((( Files Created from 2008-12-20 to 2009-01-20 )))))))))))))))))))))))))))))))
.
2009-01-20 10:56 . 2009-01-20 10:57 d——– c:\program files\Malwarebytes' Anti-Malware
2009-01-20 10:56 . 2009-01-20 10:56 d——– c:\documents and settings\bfortman\Application Data\Malwarebytes
2009-01-20 10:56 . 2009-01-20 10:56 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-20 10:56 . 2009-01-14 16:11 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-20 10:56 . 2009-01-14 16:11 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-01-16 17:52 . 2009-01-16 17:52 d——– c:\program files\Trend Micro
2009-01-16 15:44 . 2009-01-16 15:47 d——– C:\test
2009-01-16 15:08 . 2009-01-16 15:08 d——– c:\windows\Sun
2008-12-22 10:13 . 2009-01-13 17:36 69 –a—— c:\windows\NeroDigital.ini
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-16 23:51 ——— d—–w c:\program files\Windows Desktop Search
2008-12-24 01:49 ——— d—–w c:\documents and settings\bfortman\Application Data\AdobeUM
2008-12-23 19:42 ——— d—–w c:\program files\Common Files\Adobe
2008-12-11 10:57 333,952 —-a-w c:\windows\system32\drivers\srv.sys
2008-12-10 18:11 ——— d—–w c:\program files\IrfanView
2008-12-09 22:57 ——— d–h–w c:\program files\InstallShield Installation Information
2008-12-09 22:57 ——— d—a-w c:\program files\Canon
2008-12-09 22:56 ——— d—–w c:\program files\Common Files\InstallShield
2008-12-08 17:24 ——— d—–w c:\documents and settings\bfortman\Application Data\FileMaker
2008-12-08 17:23 ——— d—–w c:\program files\FileMaker
2008-12-05 23:31 ——— d—–w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-12-05 22:39 ——— d—–w c:\documents and settings\bfortman\Application Data\Windows Search
2008-12-05 22:32 ——— d—–w c:\program files\MIKSOFT
2008-12-05 22:30 ——— d—–w c:\program files\Java
2008-12-05 22:14 ——— d—–w c:\documents and settings\administrator\Application Data\Windows Desktop Search
2008-12-05 21:55 ——— d—–w c:\documents and settings\Owner\Application Data\Windows Desktop Search
2008-12-05 21:53 ——— d—–w c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-12-05 21:26 ——— d—–w c:\program files\Creative
2008-12-05 21:22 ——— d—–w c:\program files\SigmaTel
2008-12-05 21:18 ——— d—–w c:\program files\AMD
2008-12-05 21:17 ——— d—–w c:\program files\Common Files\Java
2008-12-05 21:15 5 —-a-w c:\windows\system32\drivers\DELL_DIM_E521.MRK
2008-12-05 21:15 5 —-a-w c:\windows\system32\drivers\1028_DELL_DIM_E521.MRK
2008-12-05 21:14 ——— d—–w c:\program files\Broadcom
2008-12-05 21:07 ——— d—–w c:\program files\Eset
2008-12-05 21:07 ——— d—–w c:\documents and settings\All Users\Application Data\ESET
2008-12-05 21:06 ——— d—–w c:\program files\RealVNC
2008-12-05 20:45 ——— d—–w c:\program files\Analog Devices
2008-12-05 12:36 3,328 —-a-w c:\windows\system32\drivers\pciide.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2005-08-31 1658592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"TrueImageMonitor.exe"="c:\program files\Acronis\TrueImageEchoWorkstation\TrueImageMonitor.exe" [2007-11-09 1274600]
"AcronisTimounterMonitor"="c:\program files\Acronis\TrueImageEchoWorkstation\TimounterMonitor.exe" [2007-11-09 884696]
"Acronis Scheduler2 Service"="c:\program files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-11-09 136472]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-06-05 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-06-05 162328]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-06-05 137752]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-05 136600]
"CTSVolFE.exe"="c:\program files\Creative\Mixer\CTSVolFE.exe" [2005-02-23 57344]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-26 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2006-08-23 c:\windows\system32\nwiz.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-27 c:\windows\stsystra.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2008-02-20 25214]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= wdmaud.sys
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-02-20 33800]
R3 shwMirror;shwMirror;c:\windows\system32\drivers\shwMirror.sys [2006-08-29 3584]
R4 ekrn;Eset Service;c:\program files\Eset\ESET NOD32 Antivirus\ekrn.exe [2008-02-20 472320]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-01-20 38496]
.
.
——- Supplementary Scan ——-
.
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\bfortman\Application Data\Mozilla\Firefox\Profiles\3okjpcqt.default\
FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-20 11:58:16
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
- - - - - - - > 'lsass.exe'(812)
c:\windows\system32\relog_ap.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\Acronis\Schedule2\schedul2.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\RealVNC\VNC4\winvnc4.exe
c:\windows\system32\rundll32.exe
c:\program files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
.
**************************************************************************
.
Completion time: 2009-01-20 11:59:22 - machine was rebooted [bfortman]
ComboFix-quarantined-files.txt 2009-01-20 19:59:20
Pre-Run: 105,552,703,488 bytes free
Post-Run: 106,128,818,176 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect /usepmtimer
148 — E O F — 2009-01-14 11:01:38